Ständig PUP.Optional.BonanzaDeals.A Hallo Leute,
ich habe heute das Scannen mit folgenden Programmen, in folgender Reihenfolge durchgeführt.
1.) Malwarebytes Anti Malware
2.) AdwCleaner
3.) Junkware Removal Tool
Ich habe dieses Forum leider zu spät gefunden, sonst hätte ich gar nicht erst auf eigene Faust gehandelt.
Logs sind ebenfalls in dieser Reihenfolge gepostet Zitat:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.04.2014
Suchlauf-Zeit: 17:58:24
Logdatei: Malwarebytes.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.03.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Ralf
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 249940
Verstrichene Zeit: 8 Min, 43 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 142
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\APPID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}, In Quarantäne, [22ce4dd81b60181e1d44c08239c9cc34],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\APPID\{D34F391D-4CB7-467F-A543-F583857C63B0}, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D34F391D-4CB7-467F-A543-F583857C63B0}, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D34F391D-4CB7-467F-A543-F583857C63B0}, In Quarantäne, [b7392df80c6f1b1b11547ac8d32f0ef2],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{118E1BF6-6279-432F-A285-373A77B90C7A}, In Quarantäne, [9f51ea3badce49ed035562e0f40ee719],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [9f51ea3badce49ed035562e0f40ee719],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc, In Quarantäne, [9f51ea3badce49ed035562e0f40ee719],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc, In Quarantäne, [9f51ea3badce49ed035562e0f40ee719],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [9f51ea3badce49ed035562e0f40ee719],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}, In Quarantäne, [da16e63fccaf8caac3968db522e09769],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [da16e63fccaf8caac3968db522e09769],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher, In Quarantäne, [da16e63fccaf8caac3968db522e09769],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher, In Quarantäne, [da16e63fccaf8caac3968db522e09769],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [da16e63fccaf8caac3968db522e09769],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1CC8D970-F626-4F19-815F-890032BB6606}, In Quarantäne, [27c9ac790f6c8ea8a9b13e04d929d22e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [27c9ac790f6c8ea8a9b13e04d929d22e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine, In Quarantäne, [27c9ac790f6c8ea8a9b13e04d929d22e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine, In Quarantäne, [27c9ac790f6c8ea8a9b13e04d929d22e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [27c9ac790f6c8ea8a9b13e04d929d22e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, In Quarantäne, [89670d184d2eba7c1b401c265da56d93],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.OneClickCtrl.9, In Quarantäne, [89670d184d2eba7c1b401c265da56d93],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.OneClickCtrl.9, In Quarantäne, [89670d184d2eba7c1b401c265da56d93],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, In Quarantäne, [89670d184d2eba7c1b401c265da56d93],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, In Quarantäne, [89670d184d2eba7c1b401c265da56d93],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{33BAF587-9647-4281-A34F-F4830CDC1B9F}, In Quarantäne, [a848fc290873f83e13497ec450b216ea],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [a848fc290873f83e13497ec450b216ea],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine, In Quarantäne, [a848fc290873f83e13497ec450b216ea],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine, In Quarantäne, [a848fc290873f83e13497ec450b216ea],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [a848fc290873f83e13497ec450b216ea],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33BAF587-9647-4281-A34F-F4830CDC1B9F}, In Quarantäne, [a848fc290873f83e13497ec450b216ea],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}, In Quarantäne, [5f91b570f6855fd75b028bb7ac564db3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6802463D-636F-41FE-9924-4CAD56906590}, In Quarantäne, [da165acbaecd0135520c0b374bb7fa06],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [da165acbaecd0135520c0b374bb7fa06],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [da165acbaecd0135520c0b374bb7fa06],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [da165acbaecd0135520c0b374bb7fa06],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [da165acbaecd0135520c0b374bb7fa06],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{806785D0-375F-4C2C-92E3-B8EE65D28E83}, In Quarantäne, [2dc3a184ff7cda5c72ed85bd13ef1ce4],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{840A13FF-B464-4782-9C96-AAF3092E55DD}, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\esrv.searchgolESrvc.1, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\esrv.searchgolESrvc, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.searchgolESrvc, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.searchgolESrvc.1, In Quarantäne, [7e7231f4cab1cc6a58ec9ca6bf43738d],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{944661E7-67B9-4DF7-BFF2-05388C166D34}, In Quarantäne, [c42cb96c6b108da9d18f281acc36f808],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass.1, In Quarantäne, [c42cb96c6b108da9d18f281acc36f808],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass, In Quarantäne, [c42cb96c6b108da9d18f281acc36f808],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass, In Quarantäne, [c42cb96c6b108da9d18f281acc36f808],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass.1, In Quarantäne, [c42cb96c6b108da9d18f281acc36f808],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}, In Quarantäne, [539d2500b2c92a0cc49e81c153af8c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreClass.1, In Quarantäne, [539d2500b2c92a0cc49e81c153af8c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreClass, In Quarantäne, [539d2500b2c92a0cc49e81c153af8c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreClass, In Quarantäne, [539d2500b2c92a0cc49e81c153af8c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreClass.1, In Quarantäne, [539d2500b2c92a0cc49e81c153af8c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B71934E5-6B93-448D-9D32-CBAA5150C5D8}, In Quarantäne, [727e3ee76516d95d5310340ea75b59a7],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [727e3ee76516d95d5310340ea75b59a7],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [727e3ee76516d95d5310340ea75b59a7],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [727e3ee76516d95d5310340ea75b59a7],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [727e3ee76516d95d5310340ea75b59a7],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, In Quarantäne, [7c74e93c6f0c3afc8fd5af93c43e6997],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.Update3WebControl.3, In Quarantäne, [7c74e93c6f0c3afc8fd5af93c43e6997],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.Update3WebControl.3, In Quarantäne, [7c74e93c6f0c3afc8fd5af93c43e6997],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, In Quarantäne, [7c74e93c6f0c3afc8fd5af93c43e6997],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, In Quarantäne, [7c74e93c6f0c3afc8fd5af93c43e6997],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D8E43B96-EB46-4820-92B7-232AEB735685}, In Quarantäne, [13dd1d082952e155f94a063cb84af30d],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E970727E-0508-4BEB-8B72-BBA9D0D047C7}, In Quarantäne, [8070b86dabd039fddc8aa39f2cd64fb1],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [8070b86dabd039fddc8aa39f2cd64fb1],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync, In Quarantäne, [8070b86dabd039fddc8aa39f2cd64fb1],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync, In Quarantäne, [8070b86dabd039fddc8aa39f2cd64fb1],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [8070b86dabd039fddc8aa39f2cd64fb1],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{EBF1F869-D2F0-4D31-A877-386C853A9C3D}, In Quarantäne, [09e760c58af1989e046399a9649e7090],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [09e760c58af1989e046399a9649e7090],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine, In Quarantäne, [09e760c58af1989e046399a9649e7090],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine, In Quarantäne, [09e760c58af1989e046399a9649e7090],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [09e760c58af1989e046399a9649e7090],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}, In Quarantäne, [ec049d882556bb7be484c47e5ea42bd5],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F904AC50-215C-42AB-A532-77E9FDBA9B19}, In Quarantäne, [d91760c5c2b956e054154df522e0f010],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [d91760c5c2b956e054154df522e0f010],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback, In Quarantäne, [d91760c5c2b956e054154df522e0f010],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback, In Quarantäne, [d91760c5c2b956e054154df522e0f010],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [d91760c5c2b956e054154df522e0f010],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{105F25A9-C42F-48A6-998D-0494E8AE336A}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3860D897-7DCD-473C-9744-B21DB133AB20}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4B62762D-AA67-4312-A5BF-91BCB7A4720A}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{506DD7C6-B05D-43CE-81FF-AA05E11DBDFD}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6D3C9858-2674-46E1-9112-107340758481}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79C9FA6C-352A-49BA-89BA-85077BC35DC3}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{909112FE-C4A2-4990-A499-E58867D55B15}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9BEEB5A2-8B02-465A-904D-FE5A447F59EB}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B618C19D-A418-4586-80C6-09DBDA9C748E}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B68B00A0-95B9-4162-BA45-7A1113317DA9}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BFE45A8B-650C-4E99-A3F4-CC6A2874893B}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E413D78F-283C-45F1-9992-8EF7D55A4933}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E7C2FDF1-1635-41B4-8207-C1684B6807D7}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F9F5A267-FA5A-4CA3-8BE5-4C1EEAD01011}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3860D897-7DCD-473C-9744-B21DB133AB20}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4B62762D-AA67-4312-A5BF-91BCB7A4720A}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{506DD7C6-B05D-43CE-81FF-AA05E11DBDFD}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6D3C9858-2674-46E1-9112-107340758481}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79C9FA6C-352A-49BA-89BA-85077BC35DC3}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{909112FE-C4A2-4990-A499-E58867D55B15}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9BEEB5A2-8B02-465A-904D-FE5A447F59EB}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B618C19D-A418-4586-80C6-09DBDA9C748E}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B68B00A0-95B9-4162-BA45-7A1113317DA9}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BFE45A8B-650C-4E99-A3F4-CC6A2874893B}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E413D78F-283C-45F1-9992-8EF7D55A4933}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7C2FDF1-1635-41B4-8207-C1684B6807D7}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F9F5A267-FA5A-4CA3-8BE5-4C1EEAD01011}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{105F25A9-C42F-48A6-998D-0494E8AE336A}, In Quarantäne, [24ccba6b2457bc7ae85a7bc742c001ff],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\searchgol.searchgoldskBnd, In Quarantäne, [0ee23de8e89334028db3b88a3ac8a957],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\searchgol.searchgoldskBnd.1, In Quarantäne, [6f81b174f487c571e45c7ec4b84a34cc],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\searchgol.searchgoldskBnd, In Quarantäne, [6f81b174f487c571e45c7ec4b84a34cc],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\searchgol.searchgoldskBnd.1, In Quarantäne, [6f81b174f487c571e45c7ec4b84a34cc],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\searchgol.searchgolHlpr, In Quarantäne, [4ea28a9b0d6e9a9c55ec4af8857d916f],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\searchgol.searchgolHlpr.1, In Quarantäne, [767af035c1ba191dea57a39f34ce05fb],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\searchgol.searchgolHlpr, In Quarantäne, [767af035c1ba191dea57a39f34ce05fb],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\searchgol.searchgolHlpr.1, In Quarantäne, [767af035c1ba191dea57a39f34ce05fb],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\searchgol.searchgolappCore, In Quarantäne, [c729a87dc9b22e08e4395c2ed2311ee2],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\searchgol.searchgolappCore.1, In Quarantäne, [2ec29392a3d85cdaaf6e91f91fe4fb05],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\APPID\BonanzaDealsLive.exe, In Quarantäne, [628ec16490eb3ef8d12f08835da627d9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\BonanzaDealsLive.exe, In Quarantäne, [609034f196e5003622e4860506fdec14],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\BonanzaDealsLive, In Quarantäne, [12de6cb974070c2a13f22d5e54af33cd],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\searchgol.searchgolappCore, In Quarantäne, [10e0ae772a51ef47e934a1e9679c857b],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\searchgol.searchgolappCore.1, In Quarantäne, [e40c9a8b98e340f635e833575aa9a65a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\BonanzaDealsLive.exe, In Quarantäne, [bc349095aecd360052ae7417b053ca36],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\aipfmkinhleccnodemkoofnnofpbbpac, In Quarantäne, [a34dbf66176410261d0282082ed54ab6],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\BonanzaDealsLive.exe, In Quarantäne, [fef222032556de58f80e94f758ab45bb],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.bdupdater.com/BonanzaDealsLive Update;version=3, In Quarantäne, [4fa10f16b3c8ad8926e1206b0cf758a8],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.bdupdater.com/BonanzaDealsLive Update;version=9, In Quarantäne, [01ef38ed5c1f90a67493f6959f6411ef],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-1816362267-1726252312-946737307-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, In Quarantäne, [30c0fc29d9a2340229da77143ec54ab6],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1816362267-1726252312-946737307-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [fbf5b372097291a5820db7b5927050b0],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1816362267-1726252312-946737307-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [7d73da4ba1daf73fc60b186a4db6946c],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1816362267-1726252312-946737307-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [7d73da4ba1daf73fc60b186a4db6946c]
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[1fd13fe6c0bbf046d1254ac8e32127d9]
Ordner: 0
(No malicious items detected)
Dateien: 3
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [7a7629fcbbc0a690f4526df92ad8ca36],
PUP.Optional.BonanzaDeals.A, C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job, In Quarantäne, [ea06cd58dba050e6b04f66244eb526da],
PUP.Optional.BonanzaDeals.A, C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job, In Quarantäne, [717f71b495e6181eb34c5832f60d29d7],
Physische Sektoren: 0
(No malicious items detected)
(end)
|
2.
AdwCleaner Logfile: Code:
# AdwCleaner v3.023 - Bericht erstellt am 03/04/2014 um 18:05:28
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Ralf
# Gestartet von : C:\Users\Ralf\Downloads\adwcleaner3023.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it!
Ordner Gelöscht : C:\Program Files (x86)\BonanzaDeals
Ordner Gelöscht : C:\Users\Ralf\AppData\Roaming\Systweak
Datei Gelöscht : C:\Windows\Tasks\digitalsite.job
Datei Gelöscht : C:\Windows\System32\Tasks\digitalsite
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4277F7CF-0000-46CF-BA49-D624465C4BAB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9448AC19-EB62-46D5-B7DA-B059A7DB466A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16843
-\\ Mozilla Firefox v27.0.1 (de)
[ Datei : C:\Users\Ralf\AppData\Roaming\Mozilla\Firefox\Profiles\viwta3ee.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [12539 octets] - [02/10/2013 20:06:41]
AdwCleaner[R1].txt - [949 octets] - [02/10/2013 20:12:12]
AdwCleaner[R2].txt - [2279 octets] - [03/04/2014 18:04:00]
AdwCleaner[S0].txt - [9810 octets] - [02/10/2013 20:07:23]
AdwCleaner[S1].txt - [2056 octets] - [03/04/2014 18:05:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2116 octets] ########## --- --- ---
3.) Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 8 x64
Ran by Ralf on 03.04.2014 at 18:17:03,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\Ralf\AppData\Roaming\mozilla\firefox\profiles\viwta3ee.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.04.2014 at 18:19:48,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| |