superzocker | 03.10.2017 11:38 | Berichte Malwarebytes: Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 19.09.17
Scan-Zeit: 23:35
Protokolldatei: 77615f0a-9d82-11e7-8740-a01d48fb08bb.json
Administrator: Ja
-Softwaredaten-
Version: 3.2.2.2029
Komponentenversion: 1.0.188
Version des Aktualisierungspakets: 1.0.2845
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: HP-ENVY-j105\Lukas
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 449201
Erkannte Bedrohungen: 60
In die Quarantäne verschobene Bedrohungen: 54
Abgelaufene Zeit: 29 Min., 26 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 16
PUP.Optional.SettingsManager, HKU\S-1-5-21-3922937922-1857203726-1302306953-501\SOFTWARE\SmdmF, Löschen bei Neustart, [6655], [242949],1.0.2845
PUP.Optional.Conduit, HKU\S-1-5-21-3922937922-1857203726-1302306953-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Löschen bei Neustart, [570], [236865],1.0.2845
PUP.Optional.Conduit, HKU\S-1-5-21-3922937922-1857203726-1302306953-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Löschen bei Neustart, [570], [236865],1.0.2845
PUP.Optional.Conduit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [570], [236865],1.0.2845
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [570], [236865],1.0.2845
PUP.Optional.Conduit, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, [570], [236865],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, Löschen bei Neustart, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.FreeSoftToday, HKLM\SOFTWARE\WOW6432NODE\FrEeSoFtOdAy, In Quarantäne, [3367], [238538],1.0.2845
PUP.Optional.SettingsManager, HKLM\SOFTWARE\WOW6432NODE\SmdmF, In Quarantäne, [6655], [242950],1.0.2845
PUP.Optional.Revizer.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\BlockAndSurf Update, In Quarantäne, [8992], [250933],1.0.2845
PUP.Optional.Revizer.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, In Quarantäne, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\BlockAndSurf_wd, In Quarantäne, [8992], [250933],1.0.2845
PUP.Optional.FastStart, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [11346], [238267],1.0.2845
Registrierungswert: 30
Backdoor.SpyNet, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|HKCU, In Quarantäne, [254], [198951],1.0.2845
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [8996], [-1],0.0.0
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [8996], [-1],0.0.0
PUP.Optional.Conduit, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [570], [236865],1.0.2845
PUP.Optional.Conduit, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURL, In Quarantäne, [570], [236865],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|DISPLAYNAME, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|URL, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|SUGGESTIONSURL_JSON, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|FAVICONPATH, In Quarantäne, [8903], [253585],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|DISPLAYNAME, In Quarantäne, [10048], [237681],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|DISPLAYNAME, In Quarantäne, [10048], [237681],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|URL, In Quarantäne, [10048], [237681],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|URL, In Quarantäne, [10048], [237681],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|SUGGESTIONSURL_JSON, In Quarantäne, [10048], [237681],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|SUGGESTIONSURL_JSON, In Quarantäne, [10048], [237681],1.0.2845
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|FAVICONPATH, In Quarantäne, [8903], [253597],1.0.2845
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|FAVICONPATH, In Quarantäne, [8903], [253597],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|DISPLAYNAME, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|URL, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, HKU\S-1-5-21-3922937922-1857203726-1302306953-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}|SUGGESTIONSURL_JSON, In Quarantäne, [10048], [237679],1.0.2845
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Entfernung fehlgeschlagen, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, In Quarantäne, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Entfernung fehlgeschlagen, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Entfernung fehlgeschlagen, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Entfernung fehlgeschlagen, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Entfernung fehlgeschlagen, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Entfernung fehlgeschlagen, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, In Quarantäne, [8992], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, In Quarantäne, [8992], [-1],0.0.0
PUP.Optional.FastStart, HKU\S-1-5-21-3922937922-1857203726-1302306953-1002\SOFTWARE\MOZILLA\EXTENDS|APPID, In Quarantäne, [11346], [238267],1.0.2845
Registrierungsdaten: 1
PUP.Optional.HelperBar, HKU\S-1-5-21-3922937922-1857203726-1302306953-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, Ersetzt, [11445], [293091],1.0.2845
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 2
PUP.Optional.FreeSoftwareToday, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\FREESOFTODAY, In Quarantäne, [11377], [177296],1.0.2845
PUP.Optional.DataMngr.AppFlsh, C:\USERS\GAST\APPDATA\LOCALLOW\DATAMNGR, In Quarantäne, [8996], [181454],1.0.2845
Datei: 11
Backdoor.SpyNet, C:\USERS\LUKAS\APPDATA\ROAMING\INSTALL\SVCHOST.EXE, In Quarantäne, [254], [198951],1.0.2845
PUP.Optional.FreeSoftwareToday, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy\Freesofttoday.lnk, In Quarantäne, [11377], [177296],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\BROWSER\SEARCHPLUGINS\DEFAULT-SEARCH.XML, In Quarantäne, [10048], [237677],1.0.2845
PUP.Optional.WebInstr, C:\WINDOWS\SYSTEM32\DRIVERS\Msft_Kernel_webinstr_01009.Wdf, In Quarantäne, [14363], [244814],1.0.2845
PUP.Optional.DataMngr.AppFlsh, C:\Users\Gast\AppData\LocalLow\DataMngr\{99BB1406-1CFB-488C-90D1-2D978E04F707}64, In Quarantäne, [8996], [181454],1.0.2845
PUP.Optional.Conduit, C:\USERS\LUKAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RFRYVURN.DEFAULT\PREFS.JS, Ersetzt, [570], [301520],1.0.2845
PUP.Optional.DefaultSearch.ShrtCln, C:\USERS\LUKAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RFRYVURN.DEFAULT\PREFS.JS, Ersetzt, [10048], [301536],1.0.2845
PUP.Optional.DownloadGuide, C:\$RECYCLE.BIN\S-1-5-21-3922937922-1857203726-1302306953-1002\$RJTS2MW.EXE, In Quarantäne, [182], [100902],1.0.2845
PUP.Optional.DownloadSponsor, C:\USERS\LUKAS\APPDATA\LOCAL\TEMP\DMR\DMR_72.EXE, In Quarantäne, [515], [373684],1.0.2845
PUP.Optional.SpeedingUpMyPC, C:\USERS\LUKAS\APPDATA\LOCAL\TEMP\IS45637729\21980965_STP.EXE, In Quarantäne, [910], [331684],1.0.2845
PUP.Optional.DownloadGuide, C:\USERS\LUKAS\DOWNLOADS\KORACCOUNT_CB-DL-MANAGER.EXE, In Quarantäne, [182], [100902],1.0.2845
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) |