Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 09.02.2017
Suchlaufzeit: 14:09
Protokolldatei: malwarebytes.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2017.02.09.03
Rootkit-Datenbank: v2016.11.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: pc
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 373044
Abgelaufene Zeit: 1 Std., 20 Min., 49 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 27
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, , [b433bfe11197a69038a63939d22e9b65],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, , [b433bfe11197a69038a63939d22e9b65],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, , [b433bfe11197a69038a63939d22e9b65],
PUP.Optional.Reimage, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10ECCE17-29B5-4880-A8F5-EAD298611484}, , [f1f6564a990fc1756317500c2ed2a25e],
PUP.Optional.VLCUpdaterDE, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VLC Updater, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Startfenster-Replace.de, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\REI_AxControl.DLL, , [97503769a80057df22f182d30cf4a858],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, , [56913e62337547ef4b9cfb7901ff827e],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\REI_AxControl.DLL, , [9b4c208024842f079182d085956b6c94],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, , [20c70b9522867db9e601e88cc43cd030],
PUP.Optional.SpyHunter, HKLM\SOFTWARE\ENIGMASOFTWAREGROUP\SpyHunter, , [1bccc0e06e3a72c46012dd900df3fc04],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05A30DB2-1D4D-4B6E-8307-4374BABCCEA7}, , [6e79247cd7d12b0be0b32645b64dbc44],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D9E1F3D-E2EF-432E-A8EA-EEBF21419C78}, , [f7f0346c6345b5812e67c6a59b68c43c],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509E6558-F4B2-4FF7-9CE0-2160232EF0E5}, , [579060404d5bce68deb645262bd815eb],
PUP.Optional.Trovi, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32LDR , , [c225f6aa4860072f5b9def94cb3815eb],
PUP.Optional.StartFenster, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, , [da0d069a565269cd07cebc02db25926e],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\REI_AxControl.DLL, , [19ce2d733672c4724cc7282dc63a659b],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, , [ba2d7d2391172c0a3daa373d08f814ec],
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\djhangopedggnlnicpbjklghlckmndge, , [6087d2ce7533cc6a6befc7f09d6340c0],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509E6558-F4B2-4FF7-9CE0-2160232EF0E5}, , [8e5980207b2dda5c464e1952d330e818],
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, , [4b9cbfe1bdeb8babce073e809f61f20e],
PUP.Optional.ASK, HKU\.DEFAULT\SOFTWARE\AskPartnerNetwork, , [2bbcecb4c0e8af872ac61c9d689824dc],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, , [d017920edfc9e155a67f9e3836ccc33d],
PUP.Optional.Reimage, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\LOCAL APPWIZARD-GENERATED APPLICATIONS\Reimage - Windows Problem Relief., , [5295930dffa968cec453a7c525dbe917],
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05A30DB2-1D4D-4B6E-8307-4374BABCCEA7}, , [2abd514f8820092dbac4c3a8f50e31cf],
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D9E1F3D-E2EF-432E-A8EA-EEBF21419C78}, , [26c1455b159378be057b630829da9868],
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509E6558-F4B2-4FF7-9CE0-2160232EF0E5}, , [edfaf1af9a0ec4724d32204be51ee21e],
Registrierungswerte: 15
PUP.Optional.VLCUpdaterDE, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|VLC Updater, C:\Program Files (x86)\VLC Updater\vlc-updater.exe /silent /wait 120, , [71767c244e5a84b2d11cc2e48d73e31d]
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, , [56913e62337547ef4b9cfb7901ff827e]
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, , [20c70b9522867db9e601e88cc43cd030]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05a30db2-1d4d-4b6e-8307-4374babccea7}|AppName, Plus-HD-5.5-bg.exe, , [6e79247cd7d12b0be0b32645b64dbc44]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1d9e1f3d-e2ef-432e-a8ea-eebf21419c78}|AppName, Plus-HD-5.5-codedownloader.exe, , [f7f0346c6345b5812e67c6a59b68c43c]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509e6558-f4b2-4ff7-9ce0-2160232ef0e5}|AppName, Plus-HD-5.5-buttonutil.exe, , [579060404d5bce68deb645262bd815eb]
PUP.Optional.Trovi, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32Ldr |{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130811775649434986, , [c225f6aa4860072f5b9def94cb3815eb]
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, , [ba2d7d2391172c0a3daa373d08f814ec]
PUP.Optional.Astromenda, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Astromenda\\, , [3bac5d43dfc949ed80421a4a7f843bc5]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509e6558-f4b2-4ff7-9ce0-2160232ef0e5}|AppName, Plus-HD-5.5-buttonutil.exe, , [8e5980207b2dda5c464e1952d330e818]
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|Plus-HD-5.5-bg.exe, 8000, , [c225326e07a1d1659ffad8e1f01359a7]
PUP.Optional.VLCUpdaterDE, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VLC UPDATER|URLInfoAbout, hxxp://www.vlc-updater.de/?from=about, , [e7007828b8f08ea896afb7f013ed2cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05a30db2-1d4d-4b6e-8307-4374babccea7}|AppName, Plus-HD-5.5-bg.exe, , [2abd514f8820092dbac4c3a8f50e31cf]
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1d9e1f3d-e2ef-432e-a8ea-eebf21419c78}|AppName, Plus-HD-5.5-codedownloader.exe, , [26c1455b159378be057b630829da9868]
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509e6558-f4b2-4ff7-9ce0-2160232ef0e5}|AppName, Plus-HD-5.5-buttonutil.exe, , [edfaf1af9a0ec4724d32204be51ee21e]
Registrierungsdaten: 1
PUP.Optional.Conduit, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177, Gut: (www.google.com), Schlecht: (hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177),,[07e0dbc5357378bea5ec26e4bf4523dd]
Ordner: 7
PUP.Optional.VLCUpdaterDE, C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC Updater, , [9750f6aa4d5bf93dea208f16748cfe02],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.StartFenster, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster Symbol, , [cc1befb1b5f30135f8c93d8115eb9070],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\Log, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster Symbol, , [be29c0e0ddcbe056c6effdcdc23e8b75],
Dateien: 22
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\vlc-updater.exe, , [71767c244e5a84b2d11cc2e48d73e31d],
PUP.Optional.VLCUpdaterDE, C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC Updater\Software deinstallieren.lnk, , [9750f6aa4d5bf93dea208f16748cfe02],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\setup.ico, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\uninstall.exe, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\vlc.ico, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.StartFenster.ShrtCln, C:\Users\pc\Favorites\Startfenster.lnk, , [b730752bb0f83afc59f708af8878738d],
PUP.Optional.StartFenster.ShrtCln, C:\ProgramData\Microsoft\Windows\Start Menu\Startfenster.lnk, , [a93ec9d7b6f22e08de730daa9e62fe02],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Mozilla\Extensions\startfensterde-0.0.1-an+fx-linux.xpi, , [a34479272484bb7b5b00338427d9aa56],
PUP.Optional.StartFenster.ShrtCln, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk, , [ebfc693768401c1aeae301b7728eb749],
PUP.Optional.StartFenster.ShrtCln, C:\Users\pc\Favorites\Links\Startfenster.lnk, , [a1466040bdeb1f1701d06b4dee125fa1],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster Symbol.lnk, , [e205128ea8001b1bca5a338b31cf5ca4],
PUP.Optional.StartFenster, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster Symbol\Startfenster.lnk, , [cc1befb1b5f30135f8c93d8115eb9070],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\logo.ico, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\uninstall.exe, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.GoodGame, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GoodGame.lnk, , [6f78019f396f3bfb0d3a03c088781ce4],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk, , [8e59f2ae288078be7d2f844509f7e51b],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Startfenster.lnk, , [ab3c1789278146f0fff328a2699754ac],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\gil.dat, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\gas.dat, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140918_050344.log, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster Symbol\logo.ico, , [be29c0e0ddcbe056c6effdcdc23e8b75],
PUP.Optional.Conduit, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rpwyd2zo.default-1411303491127\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177");), ,[73741888921671c58d5dbd5fc0445aa6]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 09.02.2017
Suchlaufzeit: 14:09
Protokolldatei: malwarebytes2.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2017.02.09.03
Rootkit-Datenbank: v2016.11.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: pc
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 373044
Abgelaufene Zeit: 1 Std., 20 Min., 49 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 27
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, , [b433bfe11197a69038a63939d22e9b65],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, , [b433bfe11197a69038a63939d22e9b65],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, , [b433bfe11197a69038a63939d22e9b65],
PUP.Optional.Reimage, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10ECCE17-29B5-4880-A8F5-EAD298611484}, , [f1f6564a990fc1756317500c2ed2a25e],
PUP.Optional.VLCUpdaterDE, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VLC Updater, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Startfenster-Replace.de, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\REI_AxControl.DLL, , [97503769a80057df22f182d30cf4a858],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, , [56913e62337547ef4b9cfb7901ff827e],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\REI_AxControl.DLL, , [9b4c208024842f079182d085956b6c94],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, , [20c70b9522867db9e601e88cc43cd030],
PUP.Optional.SpyHunter, HKLM\SOFTWARE\ENIGMASOFTWAREGROUP\SpyHunter, , [1bccc0e06e3a72c46012dd900df3fc04],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05A30DB2-1D4D-4B6E-8307-4374BABCCEA7}, , [6e79247cd7d12b0be0b32645b64dbc44],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D9E1F3D-E2EF-432E-A8EA-EEBF21419C78}, , [f7f0346c6345b5812e67c6a59b68c43c],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509E6558-F4B2-4FF7-9CE0-2160232EF0E5}, , [579060404d5bce68deb645262bd815eb],
PUP.Optional.Trovi, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32LDR , , [c225f6aa4860072f5b9def94cb3815eb],
PUP.Optional.StartFenster, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, , [da0d069a565269cd07cebc02db25926e],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\REI_AxControl.DLL, , [19ce2d733672c4724cc7282dc63a659b],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, , [ba2d7d2391172c0a3daa373d08f814ec],
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\djhangopedggnlnicpbjklghlckmndge, , [6087d2ce7533cc6a6befc7f09d6340c0],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509E6558-F4B2-4FF7-9CE0-2160232EF0E5}, , [8e5980207b2dda5c464e1952d330e818],
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, , [4b9cbfe1bdeb8babce073e809f61f20e],
PUP.Optional.ASK, HKU\.DEFAULT\SOFTWARE\AskPartnerNetwork, , [2bbcecb4c0e8af872ac61c9d689824dc],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, , [d017920edfc9e155a67f9e3836ccc33d],
PUP.Optional.Reimage, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\LOCAL APPWIZARD-GENERATED APPLICATIONS\Reimage - Windows Problem Relief., , [5295930dffa968cec453a7c525dbe917],
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05A30DB2-1D4D-4B6E-8307-4374BABCCEA7}, , [2abd514f8820092dbac4c3a8f50e31cf],
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1D9E1F3D-E2EF-432E-A8EA-EEBF21419C78}, , [26c1455b159378be057b630829da9868],
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509E6558-F4B2-4FF7-9CE0-2160232EF0E5}, , [edfaf1af9a0ec4724d32204be51ee21e],
Registrierungswerte: 15
PUP.Optional.VLCUpdaterDE, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|VLC Updater, C:\Program Files (x86)\VLC Updater\vlc-updater.exe /silent /wait 120, , [71767c244e5a84b2d11cc2e48d73e31d]
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, , [56913e62337547ef4b9cfb7901ff827e]
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, , [20c70b9522867db9e601e88cc43cd030]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05a30db2-1d4d-4b6e-8307-4374babccea7}|AppName, Plus-HD-5.5-bg.exe, , [6e79247cd7d12b0be0b32645b64dbc44]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1d9e1f3d-e2ef-432e-a8ea-eebf21419c78}|AppName, Plus-HD-5.5-codedownloader.exe, , [f7f0346c6345b5812e67c6a59b68c43c]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509e6558-f4b2-4ff7-9ce0-2160232ef0e5}|AppName, Plus-HD-5.5-buttonutil.exe, , [579060404d5bce68deb645262bd815eb]
PUP.Optional.Trovi, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32Ldr |{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130811775649434986, , [c225f6aa4860072f5b9def94cb3815eb]
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, , [ba2d7d2391172c0a3daa373d08f814ec]
PUP.Optional.Astromenda, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Astromenda\\, , [3bac5d43dfc949ed80421a4a7f843bc5]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509e6558-f4b2-4ff7-9ce0-2160232ef0e5}|AppName, Plus-HD-5.5-buttonutil.exe, , [8e5980207b2dda5c464e1952d330e818]
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|Plus-HD-5.5-bg.exe, 8000, , [c225326e07a1d1659ffad8e1f01359a7]
PUP.Optional.VLCUpdaterDE, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VLC UPDATER|URLInfoAbout, hxxp://www.vlc-updater.de/?from=about, , [e7007828b8f08ea896afb7f013ed2cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05a30db2-1d4d-4b6e-8307-4374babccea7}|AppName, Plus-HD-5.5-bg.exe, , [2abd514f8820092dbac4c3a8f50e31cf]
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1d9e1f3d-e2ef-432e-a8ea-eebf21419c78}|AppName, Plus-HD-5.5-codedownloader.exe, , [26c1455b159378be057b630829da9868]
PUP.Optional.CrossRider, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{509e6558-f4b2-4ff7-9ce0-2160232ef0e5}|AppName, Plus-HD-5.5-buttonutil.exe, , [edfaf1af9a0ec4724d32204be51ee21e]
Registrierungsdaten: 1
PUP.Optional.Conduit, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177, Gut: (www.google.com), Schlecht: (hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177),,[07e0dbc5357378bea5ec26e4bf4523dd]
Ordner: 7
PUP.Optional.VLCUpdaterDE, C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC Updater, , [9750f6aa4d5bf93dea208f16748cfe02],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.StartFenster, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster Symbol, , [cc1befb1b5f30135f8c93d8115eb9070],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\Log, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster Symbol, , [be29c0e0ddcbe056c6effdcdc23e8b75],
Dateien: 22
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\vlc-updater.exe, , [71767c244e5a84b2d11cc2e48d73e31d],
PUP.Optional.VLCUpdaterDE, C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VLC Updater\Software deinstallieren.lnk, , [9750f6aa4d5bf93dea208f16748cfe02],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\setup.ico, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\uninstall.exe, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.VLCUpdaterDE, C:\Program Files (x86)\VLC Updater\vlc.ico, , [a64180208c1c9a9cd5809b0c5aa6748c],
PUP.Optional.StartFenster.ShrtCln, C:\Users\pc\Favorites\Startfenster.lnk, , [b730752bb0f83afc59f708af8878738d],
PUP.Optional.StartFenster.ShrtCln, C:\ProgramData\Microsoft\Windows\Start Menu\Startfenster.lnk, , [a93ec9d7b6f22e08de730daa9e62fe02],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Mozilla\Extensions\startfensterde-0.0.1-an+fx-linux.xpi, , [a34479272484bb7b5b00338427d9aa56],
PUP.Optional.StartFenster.ShrtCln, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk, , [ebfc693768401c1aeae301b7728eb749],
PUP.Optional.StartFenster.ShrtCln, C:\Users\pc\Favorites\Links\Startfenster.lnk, , [a1466040bdeb1f1701d06b4dee125fa1],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster Symbol.lnk, , [e205128ea8001b1bca5a338b31cf5ca4],
PUP.Optional.StartFenster, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startfenster Symbol\Startfenster.lnk, , [cc1befb1b5f30135f8c93d8115eb9070],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\logo.ico, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\uninstall.exe, , [01e6356b9d0b36000299f4cbe31dbe42],
PUP.Optional.GoodGame, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GoodGame.lnk, , [6f78019f396f3bfb0d3a03c088781ce4],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk, , [8e59f2ae288078be7d2f844509f7e51b],
PUP.Optional.StartFenster, C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Startfenster.lnk, , [ab3c1789278146f0fff328a2699754ac],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\gil.dat, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\gas.dat, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140918_050344.log, , [47a00799317782b44af3442daf51cc34],
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster Symbol\logo.ico, , [be29c0e0ddcbe056c6effdcdc23e8b75],
PUP.Optional.Conduit, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rpwyd2zo.default-1411303491127\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177");), ,[73741888921671c58d5dbd5fc0445aa6]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 10.02.2017
Suchlaufzeit: 09:47
Protokolldatei: malwarebytes.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2017.02.10.01
Rootkit-Datenbank: v2016.11.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: pc
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 407332
Abgelaufene Zeit: 24 Min., 49 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 1
PUP.Optional.Conduit, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000.BAK\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [4aff70317038be78e12d8ddd63a0649c],
Registrierungswerte: 1
PUP.Optional.Conduit, HKU\S-1-5-21-3981403820-1071516951-1015314759-1000.bak\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.bing.com/search?pc=COSP&ptag=D031316-AF69C3D636C&form=CONBDF&conlogo=CT3335177&q={searchTerms}, , [4aff70317038be78e12d8ddd63a0649c]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 1
PUP.Optional.Conduit, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rpwyd2zo.default-1411303491127\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.bing.com/?pc=COSP&ptag=D031316-AF69C3D636C&form=CONMHP&conlogo=CT3335177");), ,[3d0c3d64cbdd1f17684af528f311eb15]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) |