Bekomme seit heute Morgen öfter die Meldung von Avast: Win32:Evo-gen [susp]. Hab das löschen lassen, aber nach dem Neustart kam das wieder. Jetzt mal
Code:
Alles auswählen Aufklappen ATTFilter
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 30.01.2015
Scan Time: 10:39:28
Logfile:
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.30.03
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Kalle
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 333736
Time Elapsed: 4 min, 22 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 9
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, , [6a21d22b573263d3670420a7847d629e],
PUP.Optional.ClickCaption.A, HKLM\SOFTWARE\WOW6432NODE\ClickCaption_1.10.0.4, , [7e0d8776dbae4beb548a6f1a9e6514ec],
PUP.Optional.MyStart.A, HKLM\SOFTWARE\WOW6432NODE\mystarttb, , [6a216f8ed7b268ceeea0f1a7f80bf808],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [0b8037c64247f343c42c3bc030d458a8],
PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\vi-viewSoftware, , [6229fc019aefa98db7085230fb08639d],
PUP.Optional.ClickCaption.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ccnfd_1_10_0_4, , [1a71db225138ad8946961b6e25de47b9],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [c5c61ae320697db9e72e5834f01345bb],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1820279603-2735648936-400300262-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [880315e80386c175a7598046020129d7],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1820279603-2735648936-400300262-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [55366796a2e7cb6baa6ab8241be98a76],
Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1820279603-2735648936-400300262-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, , [55366796a2e7cb6baa6ab8241be98a76]
Registry Data: 4
PUP.Optional.ViView.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}),,[02893fbeb7d277bf189d3a64cd38c838]
PUP.Optional.ViView.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}),,[47443ac32f5a1f1721927b23f213c739]
PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}),,[127955a85c2d1a1ca411a8f608fd8a76]
PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1418394890&from=cor&uid=WDCXWD10EADX-22TDHB0_WD-WCAV5T78794487944&q={searchTerms}),,[eaa13ebf92f763d39e15edb14cb9f30d]
Folders: 4
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [593298654f3a0432c2950d508e759a66],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [593298654f3a0432c2950d508e759a66],
PUP.Optional.ViView.A, C:\Users\Kalle\AppData\Roaming\vi-view, , [6625a855cfba9a9c408f23560cf7dc24],
PUP.Optional.ViView.A, C:\Users\Kalle\AppData\Roaming\vi-view\log, , [6625a855cfba9a9c408f23560cf7dc24],
Files: 15
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, , [6a21d22b573263d3670420a7847d629e],
PUP.Optional.Bunndle, C:\Program Files\CamStudio 2.7\BunndleOfferManager.exe, , [bbd013ea9ced4cea3c2b3a2318e8768a],
PUP.Optional.WindowsProtectManger.A, C:\Users\Kalle\AppData\Local\Temp\~dl827A\~dljyb\tmp\wpm_v20.0.0.1277_.exe, , [a5e64cb155340f27e487c6011be60ef2],
PUP.Optional.ClickCaption.A, C:\Users\Kalle\AppData\Local\Temp\is1901864539\5C7BB6F5_stp\clickcaption-setup-1.10.0.4.exe, , [ec9f54a93158f442552126c7748d41bf],
PUP.Optional.MyStart.A, C:\Users\Kalle\AppData\Local\Temp\mystart-manifest.xml, , [bfcc0af34346bf77a3fa0b850bf822de],
PUP.Optional.MyStart.A, C:\Users\Kalle\AppData\Local\Temp\mystart-toolbar.xml, , [62298a733b4e50e6ced0e2ae33d0de22],
PUP.Optional.Vitruvian.A, C:\Users\Kalle\AppData\Local\Temp\vitruvian-installer-install-v0003, , [4c3f3dc098f1999d6adff70e907514ec],
PUP.Optional.Vitruvian.A, C:\Users\Kalle\AppData\Local\Temp\vitruvian-installer-processes-v0002, , [7d0e20dd3d4cbd79fe4b48bdd134649c],
PUP.Optional.Vitruvian.A, C:\Users\Kalle\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, , [bfcc78851f6a1d194ffa9c69f51046ba],
PUP.Optional.Vitruvian.A, C:\Users\Kalle\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002, , [96f5e91405841d194405798c19ecb947],
PUP.Optional.Vitruvian.A, C:\Users\Kalle\AppData\Local\Temp\vitruvian-installer-uninstall-v0002, , [404b807d3b4e0d2949008d787a8bef11],
PUP.Optional.Vitruvian.A, C:\Users\Kalle\AppData\Local\Temp\vitruvian-installer-vmdetect-v0001, , [c1ca07f6791079bdd2779e67858002fe],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [593298654f3a0432c2950d508e759a66],
PUP.Optional.ViView.A, C:\Users\Kalle\AppData\Roaming\vi-view\UninstallManager.exe, , [6625a855cfba9a9c408f23560cf7dc24],
PUP.Optional.ViView.A, C:\Users\Kalle\AppData\Roaming\vi-view\log\UninstallManager_2014-12-12[17-15-21-694].log, , [6625a855cfba9a9c408f23560cf7dc24],
Physical Sectors: 0
(No malicious items detected)
(end)
Danke schon mal.