Achilles_ | 10.11.2017 10:47 | Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Datum des Schutzereignisses: 09.11.17
Uhrzeit des Schutzereignisses: 20:14
Protokolldatei: 3d65f37e-c582-11e7-a23b-001a7dda7111.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3216
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: System
-Einzelheiten zu blockierter Schadsoftware-
Datei: 1
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\IObit\Advanced SystemCare\BrowserCleaner.exe, In Quarantäne, [1218], [396386],1.0.3216
(end) Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Datum des Schutzereignisses: 09.11.17
Uhrzeit des Schutzereignisses: 20:11
Protokolldatei: cca59b4e-c581-11e7-bfb7-001a7dda7111.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3216
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: System
-Einzelheiten zu blockierter Schadsoftware-
Datei: 1
PUP.Optional.ByteFence, C:\Program Files\ByteFence\ByteFence.exe, In Quarantäne, [634], [389016],1.0.3216
(end) Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 09.11.17
Scan-Zeit: 20:27
Protokolldatei: 17249831-c584-11e7-b618-001a7dda7111.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3216
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Ducan-PC\Ducan
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 319430
Erkannte Bedrohungen: 3
In die Quarantäne verschobene Bedrohungen: 3
Abgelaufene Zeit: 2 Min., 41 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswert: 2
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [236], [-1],0.0.0
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 1
PUP.Optional.Linkury.ACMB1, C:\USERS\DUCAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SVI6S7DZ.DEFAULT\PREFS.JS, Ersetzt, [236], [302805],1.0.3216
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 09.11.17
Scan-Zeit: 20:06
Protokolldatei: 17b7b3d4-c581-11e7-9749-001a7dda7111.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3216
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Ducan-PC\Ducan
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 319659
Erkannte Bedrohungen: 155
In die Quarantäne verschobene Bedrohungen: 155
Abgelaufene Zeit: 4 Min., 17 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 7
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, In Quarantäne, [1218], [398206],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCESERVICE.EXE, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.ChipDe, C:\PROGRAM FILES (X86)\CHIP DIGITAL GMBH\CHIP1CLICK\CHIP 1-CLICK INSTALLER.EXE, In Quarantäne, [9250], [449637],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, In Quarantäne, [634], [390139],1.0.3216
Modul: 8
Trojan.Adservice, C:\USERS\DUCAN\APPDATA\LOCAL\ADSERVICE\ADSERVICE.DLL, In Quarantäne, [8559], [403904],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, In Quarantäne, [1218], [398206],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCESERVICE.EXE, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.ChipDe, C:\PROGRAM FILES (X86)\CHIP DIGITAL GMBH\CHIP1CLICK\CHIP 1-CLICK INSTALLER.EXE, In Quarantäne, [9250], [449637],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, In Quarantäne, [634], [390139],1.0.3216
Registrierungsschlüssel: 34
PUP.Optional.MirageISO, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vtuiso, In Quarantäne, [9029], [443703],1.0.3216
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{15F57FDF-0575-F0B0-5681-6E115E2DF8AC}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2E30D57-910A-402A-A335-05339F993E65}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B2E30D57-910A-402A-A335-05339F993E65}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [63], [182758],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [63], [182758],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, [63], [182758],1.0.3216
Adware.Linkury, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\backlh, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Powered forim, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{439327F6-FF97-4531-99C1-E7D250F3336D}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{439327F6-FF97-4531-99C1-E7D250F3336D}, In Quarantäne, [535], [-1],0.0.0
Adware.RunBooster, HKLM\SOFTWARE\RunBooster, In Quarantäne, [1586], [368690],1.0.3216
PUP.Optional.InstallCore, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\csastats, In Quarantäne, [2], [260986],1.0.3216
PUP.Optional.YeaDesktop, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\YeaDesktop, In Quarantäne, [1558], [391400],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}, In Quarantäne, [236], [259987],1.0.3216
PUP.Optional.ProductSetup, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\PRODUCTSETUP, In Quarantäne, [14419], [242047],1.0.3216
Adware.Adservice, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdsService, In Quarantäne, [8792], [419365],1.0.3216
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdvancedSystemCareService10, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ByteFenceService, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\mtQuoteex, In Quarantäne, [236], [260625],1.0.3216
PUP.Optional.ChipDe, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\chip1click, In Quarantäne, [9250], [449637],1.0.3216
Adware.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{115F0A5B-0AA7-4D7C-9A01-6A58AA4DD0F0}, In Quarantäne, [1274], [430377],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{439327F6-FF97-4531-99C1-E7D250F3336D}, In Quarantäne, [63], [308967],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{68DFF0E5-8886-42CD-BF15-FDCA33C4E5C2}, In Quarantäne, [634], [389376],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ByteFence, In Quarantäne, [634], [389375],1.0.3216
Adware.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\FreeAntiVirus, In Quarantäne, [1274], [430378],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Powered forim, In Quarantäne, [63], [308968],1.0.3216
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch, In Quarantäne, [319], [259314],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Quoteex_RASAPI32, In Quarantäne, [236], [260623],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Quoteex_RASMANCS, In Quarantäne, [236], [260623],1.0.3216
PUP.Optional.YeaDesktop, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\YeaDesktop_RASAPI32, In Quarantäne, [1558], [409418],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe, In Quarantäne, [236], [260624],1.0.3216
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RTOP, In Quarantäne, [634], [390139],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ByteFence, In Quarantäne, [634], [389016],1.0.3216
Registrierungswert: 23
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\ENVIRONMENT|SNF, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [63], [182758],1.0.3216
PUP.Optional.YeaDesktop, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|YeaDesktop, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.WinYahoo, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [63], [182757],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, In Quarantäne, [236], [259988],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\ENVIRONMENT|SNP, In Quarantäne, [236], [259518],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\ENVIRONMENT|SNF, In Quarantäne, [236], [259517],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|URL, In Quarantäne, [236], [259987],1.0.3216
PUP.Optional.AdvancedSystemCare, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ADVANCED SYSTEMCARE 10, In Quarantäne, [1218], [380353],1.0.3216
PUP.Optional.ProductSetup, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\PRODUCTSETUP|TB, In Quarantäne, [14419], [242047],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [63], [182758],1.0.3216
Adware.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{115F0A5B-0AA7-4D7C-9A01-6A58AA4DD0F0}|PATH, In Quarantäne, [1274], [430377],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{439327F6-FF97-4531-99C1-E7D250F3336D}|PATH, In Quarantäne, [63], [308967],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{68DFF0E5-8886-42CD-BF15-FDCA33C4E5C2}|PATH, In Quarantäne, [634], [389376],1.0.3216
PUP.Optional.Linkury, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|DISPLAYNAME, In Quarantäne, [319], [259313],1.0.3216
Adware.Linkury, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BACKLH|IMAGEPATH, In Quarantäne, [2041], [379533],1.0.3216
PUP.Optional.YeaDesktop.ClnShrt, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|YEADESKTOP.EXE, In Quarantäne, [1385], [396226],1.0.3216
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|DISPLAYNAME, In Quarantäne, [319], [259314],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|URL, In Quarantäne, [236], [259989],1.0.3216
Adware.DealPly.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|TAGEHI, In Quarantäne, [2624], [367966],1.0.3216
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RTOP|IMAGEPATH, In Quarantäne, [634], [390139],1.0.3216
Registrierungsdaten: 9
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, [63], [293461],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH PAGE, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH BAR, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCHASSISTANT, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [319], [293476],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, [63], [293461],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|DEFAULT_SEARCH_URL, Ersetzt, [236], [293486],1.0.3216
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [319], [293477],1.0.3216
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 9
PUP.Optional.MirageISO, C:\USERS\PUBLIC\DOCUMENTS\XMUPDATE, In Quarantäne, [9029], [443706],1.0.3216
Trojan.Adservice, C:\USERS\DUCAN\APPDATA\LOCAL\ADSERVICE, In Quarantäne, [8559], [403904],1.0.3216
PUP.Optional.YeaDesktop, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\YEADESKTOP, In Quarantäne, [1558], [391395],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\PROGRAM FILES (X86)\YEADESKTOP, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X64, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X86, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\PROGRAMDATA\LOGIC CRAMBLE, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\PROGRAMDATA\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}, In Quarantäne, [535], [453921],1.0.3216
Datei: 65
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\MAIN.DAT, In Quarantäne, [1930], [442900],1.0.3216
PUP.Optional.MirageISO, C:\WINDOWS\SYSTEM32\DRIVERS\VTUISO.SYS, In Quarantäne, [9029], [443703],1.0.3216
PUP.Optional.MirageISO, C:\USERS\PUBLIC\DOCUMENTS\XMUPDATE\CONF.DB, In Quarantäne, [9029], [443706],1.0.3216
PUP.Optional.Linkury.ACMB1, C:\WINDOWS\SYSWOW64\FINDIT.XML, In Quarantäne, [236], [259512],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\USERS\DUCAN\APPDATA\LOCAL\wincy\updtask.exe, In Quarantäne, [535], [455998],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\{15F57FDF-0575-F0B0-5681-6E115E2DF8AC}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Powered forim, In Quarantäne, [63], [308969],1.0.3216
Trojan.Adservice, C:\USERS\DUCAN\APPDATA\LOCAL\ADSERVICE\ADSERVICE.DLL, In Quarantäne, [8559], [403904],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC10_PerformanceMonitor, In Quarantäne, [1218], [380341],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC10_SkipUac_Ducan, In Quarantäne, [1218], [380341],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\USERS\DUCAN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\Advanced SystemCare 10.lnk, In Quarantäne, [1218], [380340],1.0.3216
Adware.Linkury.Generic, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\PO.DB, In Quarantäne, [1930], [418250],1.0.3216
PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\Uninstall YeaDesktop.lnk, In Quarantäne, [1558], [391395],1.0.3216
PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\YeaDesktop.lnk, In Quarantäne, [1558], [391395],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\apphoverbk.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedHover.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedNormal.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedPressed.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\config.xml, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\HelpTool.dll, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\Setup.exe, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\unins000.dat, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\unins000.exe, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\PO.DB, In Quarantäne, [1930], [412180],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X64\SQLite.Interop.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X86\SQLite.Interop.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\Config.json, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe.config, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.Linq.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.xml, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.ByteFence, C:\WINDOWS\SYSTEM32\TASKS\ByteFence, In Quarantäne, [634], [388721],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, In Quarantäne, [1218], [398206],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\UNINSTALL_TEMP.ICO, In Quarantäne, [1930], [404862],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\PROGRAMDATA\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}\mofa.txt, In Quarantäne, [535], [453921],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\ProgramData\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}\hdat1, In Quarantäne, [535], [453921],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\ProgramData\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}\hdat2, In Quarantäne, [535], [453921],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Powered forim, In Quarantäne, [535], [-1],0.0.0
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\NOAH.DAT, In Quarantäne, [1930], [404865],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\MD.XML, In Quarantäne, [1930], [404866],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, In Quarantäne, [1218], [380353],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\Rankkaying.tst, In Quarantäne, [1930], [404871],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\Techit.tst, In Quarantäne, [1930], [404871],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\AGENT.DAT, In Quarantäne, [1930], [404872],1.0.3216
Adware.StartPage, C:\WINDOWS\SYSTEM32\TASKS\FREEANTIVIRUS, In Quarantäne, [1274], [430379],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCESERVICE.EXE, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.ChipDe, C:\PROGRAM FILES (X86)\CHIP DIGITAL GMBH\CHIP1CLICK\CHIP 1-CLICK INSTALLER.EXE, In Quarantäne, [9250], [449637],1.0.3216
Adware.DealPly.Generic, C:\USERS\DUCAN\APPDATA\ROAMING\TAFEBOH, In Quarantäne, [2624], [367966],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, In Quarantäne, [634], [390139],1.0.3216
PUP.Optional.Linkury.ACMB1, C:\USERS\DUCAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SVI6S7DZ.DEFAULT\PREFS.JS, Ersetzt, [236], [302805],1.0.3216
Hijack.HostFile, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, In Quarantäne, [327], [438434],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\CONFIG.XML, In Quarantäne, [1930], [404859],1.0.3216
Adware.Linkury.TskLnk, C:\USERS\DUCAN\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, In Quarantäne, [3940], [444923],1.0.3216
Adware.Linkury.TskLnk, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, In Quarantäne, [3940], [444922],1.0.3216
HackTool.WinActivator, C:\USERS\DUCAN\APPDATA\ROAMING\MICROSOFT\WINDOWS LOADER\WINDOWS LOADER.EXE, In Quarantäne, [1928], [352889],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCE.EXE, In Quarantäne, [634], [389016],1.0.3216
RiskWare.BitCoinMiner, C:\PROGRAM FILES (X86)\KMSPICO 10.2.2 FINAL\WIN32.EXE, In Quarantäne, [94], [424914],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\UNINSTALL.EXE, In Quarantäne, [634], [389016],1.0.3216
PUP.Optional.InstallCore, C:\PROGRAM FILES (X86)\KMSPICO 10.2.2 FINAL\KMSPICO_PATCH.EXE, In Quarantäne, [2], [386655],1.0.3216
Adware.Linkury, C:\USERS\DUCAN\APPDATA\LOCAL\RANKKAYING.EXE, In Quarantäne, [2041], [448342],1.0.3216
Adware.Linkury, C:\USERS\DUCAN\APPDATA\LOCAL\TECHIT.EXE, In Quarantäne, [2041], [448342],1.0.3216
PUP.Optional.LogicHandler, C:\USERS\DUCAN\APPDATA\LOCAL\STRONGKAYSOFT.BIN, In Quarantäne, [3694], [24306],1.0.3216
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 09.11.17
Scan-Zeit: 20:06
Protokolldatei: 17b7b3d4-c581-11e7-9749-001a7dda7111.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3216
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Ducan-PC\Ducan
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 319659
Erkannte Bedrohungen: 155
In die Quarantäne verschobene Bedrohungen: 155
Abgelaufene Zeit: 4 Min., 17 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 7
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, In Quarantäne, [1218], [398206],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCESERVICE.EXE, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.ChipDe, C:\PROGRAM FILES (X86)\CHIP DIGITAL GMBH\CHIP1CLICK\CHIP 1-CLICK INSTALLER.EXE, In Quarantäne, [9250], [449637],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, In Quarantäne, [634], [390139],1.0.3216
Modul: 8
Trojan.Adservice, C:\USERS\DUCAN\APPDATA\LOCAL\ADSERVICE\ADSERVICE.DLL, In Quarantäne, [8559], [403904],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, In Quarantäne, [1218], [398206],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCESERVICE.EXE, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.ChipDe, C:\PROGRAM FILES (X86)\CHIP DIGITAL GMBH\CHIP1CLICK\CHIP 1-CLICK INSTALLER.EXE, In Quarantäne, [9250], [449637],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, In Quarantäne, [634], [390139],1.0.3216
Registrierungsschlüssel: 34
PUP.Optional.MirageISO, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vtuiso, In Quarantäne, [9029], [443703],1.0.3216
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{15F57FDF-0575-F0B0-5681-6E115E2DF8AC}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2E30D57-910A-402A-A335-05339F993E65}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B2E30D57-910A-402A-A335-05339F993E65}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [63], [182758],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [63], [182758],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, [63], [182758],1.0.3216
Adware.Linkury, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\backlh, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Powered forim, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{439327F6-FF97-4531-99C1-E7D250F3336D}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{439327F6-FF97-4531-99C1-E7D250F3336D}, In Quarantäne, [535], [-1],0.0.0
Adware.RunBooster, HKLM\SOFTWARE\RunBooster, In Quarantäne, [1586], [368690],1.0.3216
PUP.Optional.InstallCore, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\csastats, In Quarantäne, [2], [260986],1.0.3216
PUP.Optional.YeaDesktop, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\YeaDesktop, In Quarantäne, [1558], [391400],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}, In Quarantäne, [236], [259987],1.0.3216
PUP.Optional.ProductSetup, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\PRODUCTSETUP, In Quarantäne, [14419], [242047],1.0.3216
Adware.Adservice, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdsService, In Quarantäne, [8792], [419365],1.0.3216
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdvancedSystemCareService10, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ByteFenceService, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\mtQuoteex, In Quarantäne, [236], [260625],1.0.3216
PUP.Optional.ChipDe, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\chip1click, In Quarantäne, [9250], [449637],1.0.3216
Adware.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{115F0A5B-0AA7-4D7C-9A01-6A58AA4DD0F0}, In Quarantäne, [1274], [430377],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{439327F6-FF97-4531-99C1-E7D250F3336D}, In Quarantäne, [63], [308967],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{68DFF0E5-8886-42CD-BF15-FDCA33C4E5C2}, In Quarantäne, [634], [389376],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ByteFence, In Quarantäne, [634], [389375],1.0.3216
Adware.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\FreeAntiVirus, In Quarantäne, [1274], [430378],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Powered forim, In Quarantäne, [63], [308968],1.0.3216
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch, In Quarantäne, [319], [259314],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Quoteex_RASAPI32, In Quarantäne, [236], [260623],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Quoteex_RASMANCS, In Quarantäne, [236], [260623],1.0.3216
PUP.Optional.YeaDesktop, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\YeaDesktop_RASAPI32, In Quarantäne, [1558], [409418],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe, In Quarantäne, [236], [260624],1.0.3216
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RTOP, In Quarantäne, [634], [390139],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ByteFence, In Quarantäne, [634], [389016],1.0.3216
Registrierungswert: 23
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\ENVIRONMENT|SNF, In Quarantäne, [236], [-1],0.0.0
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [63], [182758],1.0.3216
PUP.Optional.YeaDesktop, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|YeaDesktop, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.WinYahoo, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [63], [182757],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, In Quarantäne, [236], [259988],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\ENVIRONMENT|SNP, In Quarantäne, [236], [259518],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\ENVIRONMENT|SNF, In Quarantäne, [236], [259517],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|URL, In Quarantäne, [236], [259987],1.0.3216
PUP.Optional.AdvancedSystemCare, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ADVANCED SYSTEMCARE 10, In Quarantäne, [1218], [380353],1.0.3216
PUP.Optional.ProductSetup, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\PRODUCTSETUP|TB, In Quarantäne, [14419], [242047],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [63], [182758],1.0.3216
Adware.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{115F0A5B-0AA7-4D7C-9A01-6A58AA4DD0F0}|PATH, In Quarantäne, [1274], [430377],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{439327F6-FF97-4531-99C1-E7D250F3336D}|PATH, In Quarantäne, [63], [308967],1.0.3216
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{68DFF0E5-8886-42CD-BF15-FDCA33C4E5C2}|PATH, In Quarantäne, [634], [389376],1.0.3216
PUP.Optional.Linkury, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|DISPLAYNAME, In Quarantäne, [319], [259313],1.0.3216
Adware.Linkury, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BACKLH|IMAGEPATH, In Quarantäne, [2041], [379533],1.0.3216
PUP.Optional.YeaDesktop.ClnShrt, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|YEADESKTOP.EXE, In Quarantäne, [1385], [396226],1.0.3216
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|DISPLAYNAME, In Quarantäne, [319], [259314],1.0.3216
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|URL, In Quarantäne, [236], [259989],1.0.3216
Adware.DealPly.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|TAGEHI, In Quarantäne, [2624], [367966],1.0.3216
PUP.Optional.ByteFence, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RTOP|IMAGEPATH, In Quarantäne, [634], [390139],1.0.3216
Registrierungsdaten: 9
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, [63], [293461],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH PAGE, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH BAR, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCHASSISTANT, Ersetzt, [236], [293485],1.0.3216
PUP.Optional.Linkury, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [319], [293476],1.0.3216
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, [63], [293461],1.0.3216
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3995871139-2760561661-3120862767-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|DEFAULT_SEARCH_URL, Ersetzt, [236], [293486],1.0.3216
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [319], [293477],1.0.3216
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 9
PUP.Optional.MirageISO, C:\USERS\PUBLIC\DOCUMENTS\XMUPDATE, In Quarantäne, [9029], [443706],1.0.3216
Trojan.Adservice, C:\USERS\DUCAN\APPDATA\LOCAL\ADSERVICE, In Quarantäne, [8559], [403904],1.0.3216
PUP.Optional.YeaDesktop, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\YEADESKTOP, In Quarantäne, [1558], [391395],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\PROGRAM FILES (X86)\YEADESKTOP, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X64, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X86, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\PROGRAMDATA\LOGIC CRAMBLE, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\PROGRAMDATA\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}, In Quarantäne, [535], [453921],1.0.3216
Datei: 65
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\MAIN.DAT, In Quarantäne, [1930], [442900],1.0.3216
PUP.Optional.MirageISO, C:\WINDOWS\SYSTEM32\DRIVERS\VTUISO.SYS, In Quarantäne, [9029], [443703],1.0.3216
PUP.Optional.MirageISO, C:\USERS\PUBLIC\DOCUMENTS\XMUPDATE\CONF.DB, In Quarantäne, [9029], [443706],1.0.3216
PUP.Optional.Linkury.ACMB1, C:\WINDOWS\SYSWOW64\FINDIT.XML, In Quarantäne, [236], [259512],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\USERS\DUCAN\APPDATA\LOCAL\wincy\updtask.exe, In Quarantäne, [535], [455998],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\{15F57FDF-0575-F0B0-5681-6E115E2DF8AC}, In Quarantäne, [535], [-1],0.0.0
PUP.Optional.WinYahoo, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Powered forim, In Quarantäne, [63], [308969],1.0.3216
Trojan.Adservice, C:\USERS\DUCAN\APPDATA\LOCAL\ADSERVICE\ADSERVICE.DLL, In Quarantäne, [8559], [403904],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC10_PerformanceMonitor, In Quarantäne, [1218], [380341],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC10_SkipUac_Ducan, In Quarantäne, [1218], [380341],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\USERS\DUCAN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\Advanced SystemCare 10.lnk, In Quarantäne, [1218], [380340],1.0.3216
Adware.Linkury.Generic, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\PO.DB, In Quarantäne, [1930], [418250],1.0.3216
PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\Uninstall YeaDesktop.lnk, In Quarantäne, [1558], [391395],1.0.3216
PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\YeaDesktop.lnk, In Quarantäne, [1558], [391395],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\apphoverbk.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedHover.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedNormal.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedPressed.png, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\config.xml, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\HelpTool.dll, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\Setup.exe, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\unins000.dat, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\unins000.exe, In Quarantäne, [1558], [391396],1.0.3216
PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, In Quarantäne, [1558], [391396],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\PO.DB, In Quarantäne, [1930], [412180],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X64\SQLite.Interop.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\X86\SQLite.Interop.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\Config.json, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe.config, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.Linq.dll, In Quarantäne, [2041], [431817],1.0.3216
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.xml, In Quarantäne, [2041], [431817],1.0.3216
PUP.Optional.ByteFence, C:\WINDOWS\SYSTEM32\TASKS\ByteFence, In Quarantäne, [634], [388721],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, In Quarantäne, [1218], [398206],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\UNINSTALL_TEMP.ICO, In Quarantäne, [1930], [404862],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\PROGRAMDATA\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}\mofa.txt, In Quarantäne, [535], [453921],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\ProgramData\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}\hdat1, In Quarantäne, [535], [453921],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\ProgramData\{19ECDC8F-93AE-5649-1568-C80B8F2A43C5}\hdat2, In Quarantäne, [535], [453921],1.0.3216
PUP.Optional.WinYahoo.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Powered forim, In Quarantäne, [535], [-1],0.0.0
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\NOAH.DAT, In Quarantäne, [1930], [404865],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\MD.XML, In Quarantäne, [1930], [404866],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, In Quarantäne, [1218], [380353],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\Rankkaying.tst, In Quarantäne, [1930], [404871],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\Techit.tst, In Quarantäne, [1930], [404871],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\AGENT.DAT, In Quarantäne, [1930], [404872],1.0.3216
Adware.StartPage, C:\WINDOWS\SYSTEM32\TASKS\FREEANTIVIRUS, In Quarantäne, [1274], [430379],1.0.3216
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, In Quarantäne, [1218], [380352],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCESERVICE.EXE, In Quarantäne, [634], [388726],1.0.3216
PUP.Optional.ChipDe, C:\PROGRAM FILES (X86)\CHIP DIGITAL GMBH\CHIP1CLICK\CHIP 1-CLICK INSTALLER.EXE, In Quarantäne, [9250], [449637],1.0.3216
Adware.DealPly.Generic, C:\USERS\DUCAN\APPDATA\ROAMING\TAFEBOH, In Quarantäne, [2624], [367966],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\RTOP\BIN\RTOP_SVC.EXE, In Quarantäne, [634], [390139],1.0.3216
PUP.Optional.Linkury.ACMB1, C:\USERS\DUCAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SVI6S7DZ.DEFAULT\PREFS.JS, Ersetzt, [236], [302805],1.0.3216
Hijack.HostFile, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, In Quarantäne, [327], [438434],1.0.3216
Adware.Linkury.Generic, C:\USERS\DUCAN\APPDATA\LOCAL\CONFIG.XML, In Quarantäne, [1930], [404859],1.0.3216
Adware.Linkury.TskLnk, C:\USERS\DUCAN\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, In Quarantäne, [3940], [444923],1.0.3216
Adware.Linkury.TskLnk, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, In Quarantäne, [3940], [444922],1.0.3216
HackTool.WinActivator, C:\USERS\DUCAN\APPDATA\ROAMING\MICROSOFT\WINDOWS LOADER\WINDOWS LOADER.EXE, In Quarantäne, [1928], [352889],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\BYTEFENCE.EXE, In Quarantäne, [634], [389016],1.0.3216
RiskWare.BitCoinMiner, C:\PROGRAM FILES (X86)\KMSPICO 10.2.2 FINAL\WIN32.EXE, In Quarantäne, [94], [424914],1.0.3216
PUP.Optional.ByteFence, C:\PROGRAM FILES\BYTEFENCE\UNINSTALL.EXE, In Quarantäne, [634], [389016],1.0.3216
PUP.Optional.InstallCore, C:\PROGRAM FILES (X86)\KMSPICO 10.2.2 FINAL\KMSPICO_PATCH.EXE, In Quarantäne, [2], [386655],1.0.3216
Adware.Linkury, C:\USERS\DUCAN\APPDATA\LOCAL\RANKKAYING.EXE, In Quarantäne, [2041], [448342],1.0.3216
Adware.Linkury, C:\USERS\DUCAN\APPDATA\LOCAL\TECHIT.EXE, In Quarantäne, [2041], [448342],1.0.3216
PUP.Optional.LogicHandler, C:\USERS\DUCAN\APPDATA\LOCAL\STRONGKAYSOFT.BIN, In Quarantäne, [3694], [24306],1.0.3216
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) So das sind nun alle Berichte die ich bei Malwarebytes gefunden habe
Hoffe das passt jetzt
Mfg
Achilles_ |