|
Plagegeister aller Art und deren Bekämpfung: Ständig massenhafte Funde von Malware usw jedes Programm sagt was anderes und nichts entfernt richtig DRINGEND HILFE!!! Bitte ;(Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.05.2015, 02:44 | #1 |
| Ständig massenhafte Funde von Malware usw jedes Programm sagt was anderes und nichts entfernt richtig DRINGEND HILFE!!! Bitte ;( Ich habe andauernd merkwürdige Programme auf meinem Leptop und neue Tool Erweiterungen die ich löschen muss. Ich bekomme häufig Meldungen über Funde die ich mir auf Seiten geholt haben soll die ich noch nie besucht habe... Ich habe nun zuletzt ein Scan mit Malwarebytes laufen lassen und diese Liste erhalten... Hoffe ihr könnt damit was anfangen und mir helfen ._. ich verzweifel mit meinem Leppi... Ich nutze des weiteren Onlinebanking und habe seither angst mich da einzuloggen.. zurecht?? Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 08.05.2015 Suchlauf-Zeit: 03:16:35 Logdatei: Administrator: Ja Version: 2.01.6.1022 Malware Datenbank: v2015.05.07.05 Rootkit Datenbank: v2015.04.21.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8 CPU: x64 Dateisystem: NTFS Benutzer: Meins Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 379400 Verstrichene Zeit: 20 Min, 11 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1528, , [9a37c6ca2e5c37ff2d92b9cfa958be42] Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 45 PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, , [9a37c6ca2e5c37ff2d92b9cfa958be42], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\esrv.mysearchdialESrvc, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc.1, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\esrv.mysearchdialESrvc.1, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, , [0ec31a764248ed49844847407291b44c], PUP.Optional.MySearchDial.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, , [ad24c0d06327e155efa3dc720df6ce32], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, , [ad24c0d06327e155efa3dc720df6ce32], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pflphaooapbgpeakohlggbpidpppgdff, , [428f8010a9e17db9f70039e6f21247b9], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MySearchDial, , [ad24dab68dfd75c10dc50b4600057b85], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, , [448dd8b8602a90a67ec37281e81bd030], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, , [1fb2e6aa8efc48ee269112ff9173b947], PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, , [aa27b7d96f1b6dc9c19ecc4660a4e719], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pflphaooapbgpeakohlggbpidpppgdff, , [f4dd781898f215219661ca5594705da3], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [b02118782f5b8fa76cd413e0b251d32d], PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\RegClean Pro, , [29a8c9c7c2c8f73ff2267983d82bca36], PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, , [e2ef95fbe3a7d660d09c0def46bd2dd3], PUP.Optional.FindRight.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update FindRight, , [0ac7b7d9a0eaf4423a409188ff052dd3], PUP.Optional.Webget.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update webget, , [bc15365af2984cea20773cce8282d927], PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginService, , [9041315ff595290d2dd51ccaf60deb15], PUP.Optional.Feven.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Freeven Pro 1.3, , [e2ef6b25b7d31a1c28ca70915ca81be5], PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, , [ca073c54d4b6cc6a936a64acdb298878], PUP.Optional.CrossRider.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [b21fbfd135553afc97d54007996c1fe1], PUP.Optional.MySearchDial.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pflphaooapbgpeakohlggbpidpppgdff, , [9041e6aa0288979f768062bd966eb947], PUP.Optional.InstallCore.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [a62b711fd1b993a3a9e8b16c37cdfa06], PUP.Optional.InstallCore.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\INSTALLCORE, , [c40d17798bffd660f962969dfc09e719], PUP.Optional.RegCleanerPro.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\SYSTWEAK\RegClean Pro, , [854cc4cc95f5fd39678c54e41aeb12ee], PUP.Optional.SystemSpeedup, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\SYSTWEAK\ssd, , [c1100c84a3e774c2a8c3837934cf3ac6], Registrierungswerte: 8 PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|DisplayName, Mysearchdial, , [547d3957f199b5818bbda32e7b88d62a] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|URL, hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1Cz utCyEtDtAtDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0 D0AtG0E0FtDzytG0CyC0AtAtG0FyByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=, , [4e83711f9ceec96d48003e933fc4b947] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|TopResultURLFallback, hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1Cz utCyEtDtAtDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0 D0AtG0E0FtDzytG0CyC0AtAtG0FyByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=, , [3b9693fd92f848ee5bedaf227390bb45] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|FaviconPath, C:\Program Files (x86)\Mysearchdial\1.8.29.0\FavIcon.ico, , [4b86612f6723cb6b2721ca0773904fb1] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Mysearchdial, , [15bc3b55e3a7d26446025a7743c0817f] PUP.Optional.MySearchDial.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Mysearchdial\1.8.29.0\, , [f4ddd2be3f4bd85e01ec9f2f5ea5827e] PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, tugs, , [b02118782f5b8fa76cd413e0b251d32d] PUP.Optional.InstallCore.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\INSTALLCORE|tb, 0S1S1N0A, , [c40d17798bffd660f962969dfc09e719] Registrierungsdaten: 13 PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}),,[ca07850b43473afc2d6bb158ce38ab55] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421),,[a9286a265b2f0432dfb972979a6c07f9] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1QtN1L1G1B1V 1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0F yByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1QtN1L1G1B1V 1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0F yByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=),,[9b36484891f9bc7ac704ed270402916f] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}),,[557cfe923258a096b8e0c643b551649c] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[c01139573357a294a3a6d63f74920cf4] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|Tabs, hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SyBzyyEtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu 2StD0F0DtByByB0EzytG0CzzzztCtGtCtAyEtDtGtA0AtAtDtGtBzztC0DtD0EzyyB0FtC0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0FyByCyBtGtC yEyCtA0CtD0FzzyE0AyByC2Q&cr=1887115019&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SyBzyyEtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu 2StD0F0DtByByB0EzytG0CzzzztCtGtCtAyEtDtGtA0AtAtDtGtBzztC0DtD0EzyyB0FtC0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0FyByCyBtGtC yEyCtA0CtD0FzzyE0AyByC2Q&cr=1887115019&ir=),,[854cff91454581b57e2f26e5897d24dc] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}),,[5b7628686f1b0b2b574110f96c9ad927] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421),,[537e97f9dfabd95defa97e8bae58c33d] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1QtN1L1G1B1V 1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0F yByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1QtN1L1G1B1V 1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0F yByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=),,[fad7aee2eaa0e650b219a86ce71faf51] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421&q={searchTerms}),,[68698907d8b265d1bddb6b9e53b34db3] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[d100b1df2c5e0b2bd376080d37cf7c84] PUP.Optional.MySearchDial.A, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1QtN1L1G1B1V 1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0F yByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites02_14_19_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0C0BtC0B0C0B0FyCyDyEtN0D0Tzu0SzzyDyBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1QtN1L1G1B1V 1N2Y1L1Qzu2StD0F0Bzz0CtCyCyDtGzytB0F0FtGzz0C0AyEtG0A0A0FyEtGyB0DzzyCyE0DtC0A0FtDyB0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0BtC0AyC0E0D0AtG0E0FtDzytG0CyC0AtAtG0F yByCyBtGtCyEyCtA0CtD0FzzyE0AyByC2Q&cr=679549733&ir=),,[973aaee2a6e49b9b3892ff15fb0b619f] PUP.Optional.WebsSearches, HKU\S-1-5-21-345688048-2949484767-3191919062-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397233947&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TXJ9KCC02421),,[59786a26a4e678be2a6ffe0ba75f1fe1] Ordner: 25 PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja\130, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf\115, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\lipcffnmogpihfpjpikknpblpomfmnnm\1.7, , [428f6c2497f336000c0d9dc503029769], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\lipcffnmogpihfpjpikknpblpomfmnnm, , [428f6c2497f336000c0d9dc503029769], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\llogbnampjmjogikhikoogpgcbmclcbp\1.7, , [19b894fc0b7f072fe63309599e67ba46], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\llogbnampjmjogikhikoogpgcbmclcbp, , [19b894fc0b7f072fe63309599e67ba46], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pncenobphaelkncgajdodigdkggdjlfi\4.31, , [ba17424edcae48ee24f5105217ee1de3], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pncenobphaelkncgajdodigdkggdjlfi, , [ba17424edcae48ee24f5105217ee1de3], PUP.Optional.MySearchDial.A, C:\Users\Meins\AppData\Roaming\mysearchdial, , [9e335c341c6ec373c78c6f2da75c3bc5], PUP.Optional.MySearchDial.A, C:\Users\Meins\AppData\Roaming\mysearchdial\UpdateProc, , [9e335c341c6ec373c78c6f2da75c3bc5], PUP.Optional.OpenCandy, C:\Users\Meins\AppData\Roaming\OpenCandy, , [9f32d0c0ed9d55e1e4780696e1220cf4], PUP.Optional.OpenCandy, C:\Users\Meins\AppData\Roaming\OpenCandy\5DB1F4950EB54A1AAEF88E249549A5A6, , [9f32d0c0ed9d55e1e4780696e1220cf4], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro\Version 6.1, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, , [4a876a266e1cef47c3f05f3fc043ae52], PUP.Optional.SystemSpeedup, C:\Users\Meins\AppData\Roaming\systweak\ssd, , [6b66751b0882a294966a644cf0134ab6], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Users\Meins\AppData\Roaming\SupTab, , [ce03d1bf3a50a69054c32d86cf3415eb], PUP.Optional.NewPlayer.A, C:\Users\Meins\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha, , [c011018f4149d3636931e7ddbc47926e], PUP.Optional.NewPlayer.A, C:\Users\Meins\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha\2.1.1.5, , [c011018f4149d3636931e7ddbc47926e], Dateien: 56 PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, , [9a37c6ca2e5c37ff2d92b9cfa958be42], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, , [458cdfb16f1bc96de2039fb3ed16619f], PUP.Optional.MultiPlug.A, C:\ProgramData\LUckyoCouappoN\ieLZh6.exe, , [20b1aee26723e254b955aad355acda26], PUP.Optional.SupTab.A, C:\Users\Meins\AppData\Roaming\SupTab\SupTab.dll, , [6071eea259319c9acfcaa98e88782cd4], PUP.Optional.MultiPlug.Uns, C:\$Recycle.Bin\S-1-5-21-345688048-2949484767-3191919062-1002\$RWBJNYL.exe, , [23aea0f0eb9f280ea77d1c2a1ae954ac], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\AEQRDD.tmp\simpLoupe.exe, , [428f0e826228cc6ad2b003309e647f81], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\CXMAHB.tmp\tinAmREB0n7Bja.exe, , [b61bdfb154361422226078bb62a0857b], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\EEYPCI.tmp\Flickr Reference.exe, , [6b66058bbbcfe5511d65b77c1de5659b], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\GEICVA.tmp\Kmne5J0BZxACbv.exe, , [6869a9e7b4d69a9c186a2b089e644eb2], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\GXOBQY.tmp\Pn3eFnWSvpgdif.exe, , [cf02563a9ded221495ed51e2f80a669a], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\MQGCGG.tmp\ics1rcHHE8hSJY.exe, , [bd14058bcbbffe382e54e05345bd34cc], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\WSRJTT.tmp\daeaLster.exe, , [cf028808acde66d02c569c9708fa956b], PUP.Optional.Multiplug.A, C:\Users\Meins\AppData\Local\Temp\ZIXUEO.tmp\KinggCOaupoon.exe, , [2ba62c642a600e28b0d22d065ea4e21e], PUP.Optional.RegCleanPro.A, C:\Windows\System32\Tasks\RegClean Pro_DEFAULT, , [6071f8980585cf67e3fdb34bce35fc04], PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, , [ac254b45e9a1a88e775cee31c0447090], Trojan.Dropper, C:\Users\Meins\update.exe, , [775a0c8498f247efb7b73d3f659f857b], PUP.Optional.RegCleanPro.A, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, , [448d513f4644f145cf2f77ba19ecb050], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja\130\lsdb.js, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja\130\background.html, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja\130\content.js, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja\130\Jjt3nG4.js, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\eikggpcplejfnlenbhgbephlmelcghja\130\manifest.json, , [eae7533d79115cdab663342e12f3ed13], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf\115\lsdb.js, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf\115\background.html, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf\115\content.js, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf\115\Izv4S.js, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlclonbfddfdlnenaohkjplemaljjhgf\115\manifest.json, , [6f62b7d91e6ce05627f2233f7095fd03], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\lipcffnmogpihfpjpikknpblpomfmnnm\1.7\lsdb.js, , [428f6c2497f336000c0d9dc503029769], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\lipcffnmogpihfpjpikknpblpomfmnnm\1.7\content.js, , [428f6c2497f336000c0d9dc503029769], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\lipcffnmogpihfpjpikknpblpomfmnnm\1.7\gOFpC8fda0.js, , [428f6c2497f336000c0d9dc503029769], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\llogbnampjmjogikhikoogpgcbmclcbp\1.7\lsdb.js, , [19b894fc0b7f072fe63309599e67ba46], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\llogbnampjmjogikhikoogpgcbmclcbp\1.7\content.js, , [19b894fc0b7f072fe63309599e67ba46], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\llogbnampjmjogikhikoogpgcbmclcbp\1.7\zcSo.js, , [19b894fc0b7f072fe63309599e67ba46], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pncenobphaelkncgajdodigdkggdjlfi\4.31\lsdb.js, , [ba17424edcae48ee24f5105217ee1de3], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pncenobphaelkncgajdodigdkggdjlfi\4.31\content.js, , [ba17424edcae48ee24f5105217ee1de3], PUP.Optional.MultiPlug.A, C:\Users\Zwei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pncenobphaelkncgajdodigdkggdjlfi\4.31\oyEw6eMKw.js, , [ba17424edcae48ee24f5105217ee1de3], PUP.Optional.MySearchDial.A, C:\Users\Meins\AppData\Roaming\mysearchdial\UpdateProc\UPDATE~1.EXE.vir, , [9e335c341c6ec373c78c6f2da75c3bc5], PUP.Optional.OpenCandy, C:\Users\Meins\AppData\Roaming\OpenCandy\5DB1F4950EB54A1AAEF88E249549A5A6\TuneUpUtilities2013-2200217_de-DE.exe, , [9f32d0c0ed9d55e1e4780696e1220cf4], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro\Version 6.1\1393973516.reg, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro\Version 6.1\ExcludeList.rcp, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro\Version 6.1\rcpupdate.ini, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro\Version 6.1\results.rcp, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.RegCleanerPro.A, C:\Users\Meins\AppData\Roaming\systweak\RegClean Pro\Version 6.1\TempHLList.rcp, , [c40dcfc1d4b631059d2b3b6137ccec14], PUP.Optional.SystemSpeedup, C:\Users\Meins\AppData\Roaming\systweak\ssd\SSDPTstub.exe, , [6b66751b0882a294966a644cf0134ab6], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, , [a130d9b75e2cf3431ff7a310df24b848], PUP.Optional.NewPlayer.A, C:\Users\Meins\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha\2.1.1.5\user.config, , [c011018f4149d3636931e7ddbc47926e], Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) |
08.05.2015, 05:50 | #2 |
/// the machine /// TB-Ausbilder | Ständig massenhafte Funde von Malware usw jedes Programm sagt was anderes und nichts entfernt richtig DRINGEND HILFE!!! Bitte ;( hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
Themen zu Ständig massenhafte Funde von Malware usw jedes Programm sagt was anderes und nichts entfernt richtig DRINGEND HILFE!!! Bitte ;( |
dringend, ebanking, explorer, google, hilfe!, ics, install.exe, internet, internet explorer, löschen, malware, malwarebytes, microsoft, neue, programm, programme, roaming, scan, schutz, seite, seiten, service.exe, software, system32, temp, update, windows |