1. Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 03.05.19
Scan-Zeit: 15:58
Protokolldatei: 7decef88-6dab-11e9-859c-1c872cb4af6b.json
-Softwaredaten-
Version: 3.7.1.2839
Komponentenversion: 1.0.586
Version des Aktualisierungspakets: 1.0.10448
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 17134.706)
CPU: x64
Dateisystem: NTFS
Benutzer: KERSTIN\Kerstin
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 316628
Erkannte Bedrohungen: 15
In die Quarantäne verschobene Bedrohungen: 15
Abgelaufene Zeit: 10 Min., 21 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 2
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-3230699985-1636215559-2569924934-1001\CONSOLE\TASKENG.EXE, In Quarantäne, [6334], [425125],1.0.10448
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-3230699985-1636215559-2569924934-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE, In Quarantäne, [6334], [425124],1.0.10448
Registrierungswert: 3
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-3230699985-1636215559-2569924934-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_WINDOWSPOWERSHELL_V1.0_POWERSHELL.EXE|WINDOWPOSITION, In Quarantäne, [6334], [425126],1.0.10448
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-3230699985-1636215559-2569924934-1001\CONSOLE\TASKENG.EXE|WINDOWPOSITION, In Quarantäne, [6334], [425125],1.0.10448
PUP.Optional.PSScriptLoad.ACMB3, HKU\S-1-5-21-3230699985-1636215559-2569924934-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE|WINDOWPOSITION, In Quarantäne, [6334], [425124],1.0.10448
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 10
PUP.Optional.NewTabTV, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_search.searchnewtabtv.com_0.localstorage, In Quarantäne, [334], [359416],1.0.10448
PUP.Optional.NewTabTV, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_search.searchnewtabtv.com_0.localstorage-journal, In Quarantäne, [334], [359416],1.0.10448
PUP.Optional.AdNetworkPerformance, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_www.adnetworkperformance.com_0.localstorage, In Quarantäne, [4200], [443437],1.0.10448
PUP.Optional.AdNetworkPerformance, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_www.adnetworkperformance.com_0.localstorage-journal, In Quarantäne, [4200], [443437],1.0.10448
PUP.Optional.CrossRider, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_cds.j4c2z9p8.hwcdn.net_0.localstorage, In Quarantäne, [441], [443425],1.0.10448
PUP.Optional.CrossRider, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_cds.j4c2z9p8.hwcdn.net_0.localstorage-journal, In Quarantäne, [441], [443425],1.0.10448
PUP.Optional.OnClickAds, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_onclickads.net_0.localstorage, In Quarantäne, [4937], [443429],1.0.10448
PUP.Optional.OnClickAds, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_onclickads.net_0.localstorage-journal, In Quarantäne, [4937], [443429],1.0.10448
PUP.Optional.CrossRider, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, In Quarantäne, [441], [443427],1.0.10448
PUP.Optional.CrossRider, C:\USERS\KERSTIN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, In Quarantäne, [441], [443427],1.0.10448
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) 2. Code:
16:20:17 # product=EOS
# version=8
# esetonlinescanner_deu (1).exe=3.0.17.0
# country="Germany"
# lang=1031
16:21:18 CmlLineScanner cannot load dll:C:\Users\Kerstin\AppData\Local\ESET\ESETOnlineScanner\esets_apiW Das angegebene Modul wurde nicht gefunden.
16:21:18 # product=EOS
# version=8
# esetonlinescanner_deu (1).exe=3.0.17.0
# country="Germany"
# lang=1031
16:21:48 CmlLineScanner cannot load dll:C:\Users\Kerstin\AppData\Local\ESET\ESETOnlineScanner\esets_apiW Das angegebene Modul wurde nicht gefunden.
16:21:48 # product=EOS
# version=8
# esetonlinescanner_deu.exe=3.0.17.0
# country="Germany"
# lang=1031
16:22:17 Updating
16:22:17 Update Init
16:22:19 Update Download
16:23:46 esets_scanner_reload returned 0
16:23:46 g_uiModuleBuild: 41265
16:23:46 Update Finalize
16:23:46 Call m_esets_charon_send
16:23:46 Call m_esets_charon_destroy
16:23:47 Updated modules version: 41265
16:23:58 Scanner engine: 41265
20:12:55 Call m_esets_charon_send
20:12:55 Call m_esets_charon_destroy 3. Code:
Results of screen317's Security Check version 1.009
x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Windows Defender
Malwarebytes
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
Mozilla Firefox (44.0.2)
Google Chrome (74.0.3729.131)
Google Chrome (plugins...)
Google Chrome (SetupMetrics...) ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamtray.exe
Windows Defender MSASCuiL.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |