Melbourne | 19.10.2015 09:57 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 19.10.2015
Suchlaufzeit: 10:16
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.10.19.01
Rootkit-Datenbank: v2015.10.16.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Aral-Shop
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 389012
Abgelaufene Zeit: 7 Min., 5 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 36
PUP.Optional.Salus.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\Salus, In Quarantäne, [e4e9d68285065adc6c2ec7c24bb70af6],
PUP.Optional.Salus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Salus, In Quarantäne, [11bc045496f53bfb34632a3406fd718f],
PUP.Optional.Salus.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Salus, In Quarantäne, [913c95c3cbc041f569651d6c4eb48d73],
PUP.Optional.PlumoWeb, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update PlumoWeb, In Quarantäne, [824b3d1b1477d066b6d06724bd46738d],
PUP.Optional.BrowsersApp, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Browsers+Apps+1.1, In Quarantäne, [7756d088276468ce6f5f5015b84be61a],
PUP.Optional.CrossRider, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\HD-Quality-v3V06.10, In Quarantäne, [d3fa5ff93e4dc76f3f1f393417ec758b],
PUP.Optional.CrossRider, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, In Quarantäne, [e9e428304c3f20160852d89549baa858],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{166A11B0-1779-4E16-89EC-54DFA0417E2E}, In Quarantäne, [1cb128305437cc6a55340767c73c9b65],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{176C106F-E995-441B-A446-6E1AFA267AB3}, In Quarantäne, [6a6393c5e0abf244a8e1541ad52efb05],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19080C26-930C-47DC-A5DA-1C68D65910BD}, In Quarantäne, [ac21d7819dee8aac91f8aac444bf8878],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D6200FB-1A3B-43AB-B9B0-384EFCF6C930}, In Quarantäne, [577690c8fc8f1224acde511de41f0ef2],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2381AA14-5689-47C5-AB74-E575FD989489}, In Quarantäne, [7a5328301a715dd97316a7c7e71c21df],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{26973CC7-2319-4227-A992-2FBDD3373814}, In Quarantäne, [eedf2434bccf22145138016dc142d62a],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32977798-247B-4B1B-B88E-158FAF105AC6}, In Quarantäne, [07c6b6a20883e353a9e1a4ca06fdc43c],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{35F2B93E-51E3-44C4-A6CD-5AE1E24BBEB2}, In Quarantäne, [7459acac2d5e8fa72763442a45be2ed2],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{363AB0B9-7CDC-41B9-B2B4-BCDF22547B5B}, In Quarantäne, [bc110c4cf596c96d0782cca2679c8779],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37DDEE7C-69D4-4F0C-A318-B7C2797CE2DD}, In Quarantäne, [f8d5c6924744b77facddc6a8b74cb44c],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C5EF01B-B985-48A0-B838-65F1CEDCBDBA}, In Quarantäne, [07c646122c5f86b097f30e603ac9f907],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{478721BB-41E7-4EB4-BB29-FD89A2CB63AC}, In Quarantäne, [c00dd8803853d85e3158274734cff20e],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59AF06EE-E4D1-45CD-933C-148BF71E1453}, In Quarantäne, [6d60b7a1206b1c1a4a40f67817ec8080],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5CE500DC-24F0-4001-961E-881688C03FD8}, In Quarantäne, [5b72b1a7ec9fc670d1b8195532d16e92],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6417782E-9C08-4CB0-88BA-588CE3D31DE9}, In Quarantäne, [2ca13e1a711af244c2c8fb73778c4eb2],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AE7F552-B006-4BAF-B15C-70B867E57FC9}, In Quarantäne, [14b9c098335880b61c6eb2bc946f53ad],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C155D1E-5AB0-49B5-837C-C7D9EBF5E943}, In Quarantäne, [933a91c7d8b37db91178412db84b2cd4],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73351CDC-6CB2-4A6D-86B1-5425E6AD10A1}, In Quarantäne, [dbf270e8e4a7cc6a6f1ad8963dc647b9],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{964F3BF5-A07B-4269-87D6-B57320EDEEB1}, In Quarantäne, [c30a11471f6ca2944a40f678b053718f],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE74DCD-B3DE-447C-8B8E-DA729A56E376}, In Quarantäne, [fbd205535239191d3c4d630bca391ae6],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A4F9A4AD-F8DE-488B-A11A-11A63EFDAB7D}, In Quarantäne, [57765efaf8932214d6b44d21ae553cc4],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AE548CBB-1827-4153-A7CC-B24157F73E8F}, In Quarantäne, [dcf1193f5c2f11252e5c561810f3a759],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE77F15C-A3D5-432B-B83C-ED18E022E314}, In Quarantäne, [339aea6e4249082e4742ef7f8f74c040],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7D54BA1-E851-43D5-A3AD-55144D8496DB}, In Quarantäne, [eae36fe9cbc0ab8b4049254956adce32],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8078819-38A5-4C70-81D1-8E7D44317819}, In Quarantäne, [715c4612cfbcf73f1a70fb73d52e33cd],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EAB98F1E-9B73-4B32-A0EA-4CCD224FA255}, In Quarantäne, [d7f6dd7b9fec83b392f8d49a3ac9837d],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBDCF61C-6790-492E-BD6E-5B38E08A68F0}, In Quarantäne, [64690a4e4a4153e387024e20649f07f9],
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FCB4ABF3-9E0F-4CA1-BC3C-B19083AC9CB6}, In Quarantäne, [d0fdb8a06427fd39f49585e9f50e9d63],
PUP.Optional.FastStart, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [5e6f6debf9922a0c13c943303bc80ef2],
Registrierungswerte: 30
PUP.Optional.SpeedItUp.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{30CD3668-32CE-DBFB-FA36-13792B87731B}, C:\Program Files (x86)\ver7SpeeditUp\179.xpi, In Quarantäne, [04c90850f29939fd82e468eb897a23dd]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{166A11B0-1779-4E16-89EC-54DFA0417E2E}|AppName, 4a3061d6-9f04-4dcc-8690-b45f9e01d86c-2.exe-buttonutil.exe, In Quarantäne, [1cb128305437cc6a55340767c73c9b65]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{176C106F-E995-441B-A446-6E1AFA267AB3}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [6a6393c5e0abf244a8e1541ad52efb05]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19080C26-930C-47DC-A5DA-1C68D65910BD}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [ac21d7819dee8aac91f8aac444bf8878]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D6200FB-1A3B-43AB-B9B0-384EFCF6C930}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [577690c8fc8f1224acde511de41f0ef2]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2381AA14-5689-47C5-AB74-E575FD989489}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [7a5328301a715dd97316a7c7e71c21df]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{26973CC7-2319-4227-A992-2FBDD3373814}|AppName, 4a3061d6-9f04-4dcc-8690-b45f9e01d86c-2.exe-buttonutil.exe, In Quarantäne, [eedf2434bccf22145138016dc142d62a]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32977798-247B-4B1B-B88E-158FAF105AC6}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [07c6b6a20883e353a9e1a4ca06fdc43c]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{35F2B93E-51E3-44C4-A6CD-5AE1E24BBEB2}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [7459acac2d5e8fa72763442a45be2ed2]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{363AB0B9-7CDC-41B9-B2B4-BCDF22547B5B}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [bc110c4cf596c96d0782cca2679c8779]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37DDEE7C-69D4-4F0C-A318-B7C2797CE2DD}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [f8d5c6924744b77facddc6a8b74cb44c]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C5EF01B-B985-48A0-B838-65F1CEDCBDBA}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [07c646122c5f86b097f30e603ac9f907]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{478721BB-41E7-4EB4-BB29-FD89A2CB63AC}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [c00dd8803853d85e3158274734cff20e]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59AF06EE-E4D1-45CD-933C-148BF71E1453}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [6d60b7a1206b1c1a4a40f67817ec8080]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5CE500DC-24F0-4001-961E-881688C03FD8}|AppName, 4a3061d6-9f04-4dcc-8690-b45f9e01d86c-2.exe-buttonutil.exe, In Quarantäne, [5b72b1a7ec9fc670d1b8195532d16e92]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6417782E-9C08-4CB0-88BA-588CE3D31DE9}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [2ca13e1a711af244c2c8fb73778c4eb2]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AE7F552-B006-4BAF-B15C-70B867E57FC9}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [14b9c098335880b61c6eb2bc946f53ad]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C155D1E-5AB0-49B5-837C-C7D9EBF5E943}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [933a91c7d8b37db91178412db84b2cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73351CDC-6CB2-4A6D-86B1-5425E6AD10A1}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [dbf270e8e4a7cc6a6f1ad8963dc647b9]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{964F3BF5-A07B-4269-87D6-B57320EDEEB1}|AppName, 4a3061d6-9f04-4dcc-8690-b45f9e01d86c-2.exe-codedownloader.exe, In Quarantäne, [c30a11471f6ca2944a40f678b053718f]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE74DCD-B3DE-447C-8B8E-DA729A56E376}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [fbd205535239191d3c4d630bca391ae6]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A4F9A4AD-F8DE-488B-A11A-11A63EFDAB7D}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [57765efaf8932214d6b44d21ae553cc4]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AE548CBB-1827-4153-A7CC-B24157F73E8F}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [dcf1193f5c2f11252e5c561810f3a759]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE77F15C-A3D5-432B-B83C-ED18E022E314}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [339aea6e4249082e4742ef7f8f74c040]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7D54BA1-E851-43D5-A3AD-55144D8496DB}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [eae36fe9cbc0ab8b4049254956adce32]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8078819-38A5-4C70-81D1-8E7D44317819}|AppName, 4a3061d6-9f04-4dcc-8690-b45f9e01d86c-2.exe-codedownloader.exe, In Quarantäne, [715c4612cfbcf73f1a70fb73d52e33cd]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EAB98F1E-9B73-4B32-A0EA-4CCD224FA255}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-codedownloader.exe, In Quarantäne, [d7f6dd7b9fec83b392f8d49a3ac9837d]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBDCF61C-6790-492E-BD6E-5B38E08A68F0}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [64690a4e4a4153e387024e20649f07f9]
PUP.Optional.CrossRider, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FCB4ABF3-9E0F-4CA1-BC3C-B19083AC9CB6}|AppName, 56e4aefe-6fe9-422d-bf50-bc2b476cfc1e-2.exe-buttonutil.exe, In Quarantäne, [d0fdb8a06427fd39f49585e9f50e9d63]
PUP.Optional.FastStart, HKU\S-1-5-21-2486542249-1089485429-714676662-1001\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [5e6f6debf9922a0c13c943303bc80ef2]
Registrierungsdaten: 1
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{A66A12CF-2AEC-4556-AF2A-112BB8947B7B}|NameServer, 5.135.12.56,199.203.35.78, Gut: (), Schlecht: (5.135.12.56,199.203.35.78),Ersetzt,[6667dc7c0e7d3ef8c1a6cb7e5ba9728e]
Ordner: 3
PUP.Optional.SpeedItUp.PrxySvrRST, C:\Program Files (x86)\ver7SpeeditUp, In Quarantäne, [5a73eb6d573464d2e424b298768c53ad],
PUP.Optional.FastPlayer, C:\Users\Aral-Shop\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q, In Quarantäne, [bc11e177bccf81b5840fc49a956d21df],
PUP.Optional.FastPlayer, C:\Users\Aral-Shop\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q\1.0.0.2, In Quarantäne, [bc11e177bccf81b5840fc49a956d21df],
Dateien: 8
PUP.Optional.SnapDo, C:\Windows\Installer\fe780.msi, In Quarantäne, [18b54d0bd3b849ed6f25acb0b15031cf],
PUP.Optional.OmigaPlus.ShrtCln, C:\Users\Aral-Shop\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.omiga-plus.com_0.localstorage, In Quarantäne, [418c4c0c573442f4545d85fedc269e62],
PUP.Optional.OmigaPlus.ShrtCln, C:\Users\Aral-Shop\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.omiga-plus.com_0.localstorage-journal, In Quarantäne, [cffec2961675e84ebef3275c8a788e72],
PUP.Optional.ISearch.ShrtCln, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\omiga-plus.xml, In Quarantäne, [3a93c7916e1d92a40a0ce560cf347d83],
PUP.Optional.WebInstr, C:\Windows\System32\drivers\Msft_Kernel_webinstrNew_01009.Wdf, In Quarantäne, [dbf267f193f8b87ebd08f2aea2618080],
PUP.Optional.SpeedItUp.PrxySvrRST, C:\Program Files (x86)\ver7SpeeditUp\Sqlite3.dll, In Quarantäne, [5a73eb6d573464d2e424b298768c53ad],
PUP.Optional.FastPlayer, C:\Users\Aral-Shop\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q\1.0.0.2\user.config, In Quarantäne, [bc11e177bccf81b5840fc49a956d21df],
PUP.Optional.OmigaPlus, C:\Users\Aral-Shop\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Gut: ("session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/restorebrowser/"]}}), Schlecht: ("session":{"restore_on_startup":4,"startup_urls":["hxxp://isearch.omiga-plus.com/?type=hp&ts=1412697863&from=tugs&uid=ST1000DM003-1CH162_S1DH0PZBXXXXS1DH0PZB"]},"sync":{"remaining_rollback_tries":0}}), Ersetzt,[ba1308504546d462b01a7ff223e15fa1]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) AdwCleaner Logfile: Code:
# AdwCleaner v5.014 - Bericht erstellt am 19/10/2015 um 10:54:36
# Aktualisiert am 18/10/2015 von Xplode
# Datenbank : 2015-10-18.5 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Aral-Shop - ARAL-SHOP-PC
# Gestartet von : C:\Users\Aral-Shop\Downloads\adwcleaner_5.014.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Program Files (x86)\VideoViewer
[-] Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoViewer
[-] Ordner Gelöscht : C:\Users\Aral-Shop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoViewer
[-] Ordner Gelöscht : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\globalUpdate
[-] Ordner Gelöscht : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\XTRM Group Ltd
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Windows\Reimage.ini
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
[-] Task Gelöscht : Reimage Reminder
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Speedup_umh]
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00004}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00005}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00006}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00007}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00008}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00009}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000A}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000B}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000C}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000D}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000E}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0BF85F37-ECD3-462C-8F41-902FD170F42E}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0ED2BF70-D5F2-4C89-BC03-DD3E771D5388}
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Schlüssel Gelöscht : HKU\.DEFAULT\Software\AppDataLow\Software\SpeeditUp
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[-] Schlüssel Gelöscht : HKCU\Software\StormWatch
[-] Schlüssel Gelöscht : HKCU\Software\Reg\Clean
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Reg\Clean
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\OCS
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\StormWatch
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\Reg\Clean
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
[!] Schlüssel Nicht Gelöscht : HKU\.DEFAULT\Software\AppDataLow\Software\SpeeditUp
[!] Schlüssel Nicht Gelöscht : HKU\S-1-5-18\Software\AppDataLow\Software\SpeeditUp
***** [ Internetbrowser ] *****
[-] [C:\Users\Aral-Shop\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Gelöscht : omiga-plus
[-] [C:\Users\Aral-Shop\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Gelöscht : hxxp://isearch.omiga-plus.com/?type=hp&ts=1412697863&from=tugs&uid=ST1000DM003-1CH162_S1DH0PZBXXXXS1DH0PZB
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [5021 Bytes] ########## --- --- --- |