![]() |
|
Plagegeister aller Art und deren Bekämpfung: Play Now Radio / Pup.Optional.Conduit eingefangen , AntiVirus Programm nicht mehr aktivierbarWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Play Now Radio / Pup.Optional.Conduit eingefangen , AntiVirus Programm nicht mehr aktivierbar Hallo Ich habe auf den Rechner meiner Eltern am Dienstag versehentlich Play now Radio installiert und unter anderen den Plagegeist Pup.Optional.Conduit Malbytewire hat bei ersten Suchlauf folgendes gefunden Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 02.04.2014 Scan Time: 17:23:15 Logfile: antiMalware020414.txt Administrator: Yes Version: 2.00.0.1000 Malware Database: v2014.04.02.05 Rootkit Database: v2014.03.27.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Chameleon: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: User Scan Type: Threat Scan Result: Completed Objects Scanned: 297728 Time Elapsed: 6 min, 8 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Shuriken: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 3 PUP.Optional.Conduit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, , [602d94910f6c42f40a502cea0bf69a66], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURREN TVERSION\UNINSTALL\SearchProtect, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-22194152-1285576544-1255116705-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [4746d35236452016d8cb2161cd36bf41], Registry Values: 0 (No malicious items detected) Registry Data: 3 PUP.Optional.Conduit.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64 Loader.dll, Good: (), Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC6 4Loader.dll),,[fa931e07f289bb7b8dcd080e07fa57a9] PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32 Loader.dll, Good: (), Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC3 2Loader.dll),,[8a035dc84a312c0a5a0050c6e31e5aa6] PUP.Optional.Conduit.A, HKU\S-1-5-21-22194152-1285576544-1255116705-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=...F2B36864&SSPV=, Good: (hxxp://www.google.com), Bad: (hxxp://search.conduit.com/?gd=&ctid=...F2B36864&SSPV=),,[4e3f57ce225910261a6e7097af55b14f] Folders: 18 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, , [038a03220f6c48ee265abad17a892fd1], Files: 85 PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, , [602d94910f6c42f40a502cea0bf69a66], PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, , [9cf1cd58e794be786feb3ed805fcb24e], PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, , [deafa5802952d165ea707b9b8f72857b], PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader .dll, , [fa931e07f289bb7b8dcd080e07fa57a9], PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader .dll, , [8a035dc84a312c0a5a0050c6e31e5aa6], PUP.Optional.OneClickDownloader.A, C:\$Recycle.Bin\S-1-5-21-22194152-1285576544-1255116705-1001\$R1WPMFW.exe, , [e3aa7aab0774aa8cd44e67cde12032ce], PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nsy1643.exe, , [800d79aca5d63ff7f377d15060a1b44c], PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nsi1374.exe, , [5a3369bc2c4fa19528428f924fb258a8], PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nsn43BB.exe, , [f7969590f18a102662087ca5bd441ae6], PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nst469A.exe, , [84091d081566db5bc9a1869be81903fd], PUP.Optional.Conduit.A, C:\Users\User\AppData\Local\Temp\uttE4A7.tmp.exe, , [632ab07574074aec63333ada936e43bd], PUP.Optional.Conduit.A, C:\Users\User\AppData\Local\Temp\nsc3E9\SpSetup.ex e, , [e5a825005b20c2740b4f0f0710f13ac6], PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\searchplugins\conduit-search.xml, , [157836ef4932b77fb11eca958b776799], PUP.Optional.GoPhoto.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\searchplugins\gophotoit.xml, , [2d60f2330774092d4ab3243bba484bb5], PUP.Optional.Montiera, C:\Users\User\Desktop\Play Now Radio.lnk, , [bdd0b66f9ae1270f74bd441f9c66827e], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe , , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png , , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.p ng, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS .png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall. png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.pn g, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png , , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_che cked.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def .png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js , , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.m in.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js , , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults .js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protecti on.css, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protecti on.html, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protecti on.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaul ts.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protec tionDS.css, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protec tionDS.html, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protec tionDS.js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.j s, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.c ss, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.h tml, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.j s, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults. js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall .css, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall .html, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall .js, , [038a03220f6c48ee265abad17a892fd1], PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=MD 67C4DD1-896D-483A-98A2-B7CB0E1E04CD&SearchSource=55&CUI=&UM=5&UP=SP7A83F2 4B-214A-4F43-96CE-DDFCF2B36864&SSPV="), ,[d2bb061fe299fe386ce2ae8deb19db25] PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "hxxp://search.conduit.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=MD 67C4DD1-896D-483A-98A2-B7CB0E1E04CD&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5 &UP=SP7A83F24B-214A-4F43-96CE-DDFCF2B36864"), ,[ade0d5501368d1657315fd3e33d11be5] Physical Sectors: 0 (No malicious items detected) (end) ruft man das Programm auf steht dort die Fehlermeldung "Keine aktive Komponente vorhanden" Zudem hängen glaube Ich auch die Probleme beim Anspeicher mit Libri Office zusammen. Genauer Wortlaut kann ich erst nachher posten. Ich poste dann auch einen neueren Malbyteware Bericht. Anne |
Themen zu Play Now Radio / Pup.Optional.Conduit eingefangen , AntiVirus Programm nicht mehr aktivierbar |
antimalware, antivirus, avg, avg antivirus, desktop, explorer, fehlermeldung, folge, hängen, install.exe, internet explorer, malwarebytes, mozilla, nicht mehr, probleme, programm, pup.optional.1clickdownload.a, pup.optional.conduit.a, pup.optional.gophoto.a, pup.optional.montiera, pup.optional.searchprotect.a, software, system, windows |