Hallo und Danke!
Habe leider Probleme mit FSRT. Startet als Admin, doch nichts geschieht. Die erste Meldung bleibt stehen ewig und Fenster lässt sich nicht SChließen. Nur mit Taskmanager.:twak:
Ich nutzte keine Virenscanner oder so, KiSi 2014 ist ausgeschaltet. Wirkt aber mglw. trotzdem beschränkend auf Kommandozeilen-Ausführung. Windows Total Protection Tool ist an.
Werde Farbars nochmal testen über USBStick beim Hochfahren.
Gruß AWK
Ergebnisse der anderen Scanner:
ESET: Code:
C:\ProgramData\InternetUpdater\InternetUpdaterService.exe a variant of MSIL/Adware.PullUpdate.A application
C:\ProgramData\Updater\Uninstall.exe a variant of MSIL/Adware.PullUpdate.A application
C:\Sandbox\Andreas\DefaultBox\user\all\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application
C:\Sandbox\Andreas\DefaultBox\user\all\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application
C:\Sandbox\Andreas\DefaultBox\user\current\AppData\Local\Temp\YontooSetup-Silent.exe Win32/Adware.Yontoo application
C:\Sandbox\Andreas\DefaultBox\user\current\AppData\Local\Temp\YontooLayers\background.html JS/Adware.Yontoo.B application
C:\Sandbox\Andreas\DefaultBox\user\current\AppData\Local\Temp\YontooLayers\yl.js JS/Adware.Yontoo.A application
C:\Users\All Users\InternetUpdater\InternetUpdaterService.exe a variant of MSIL/Adware.PullUpdate.A application
C:\Users\All Users\Updater\Uninstall.exe a variant of MSIL/Adware.PullUpdate.A application
C:\Users\Andreas\AppData\Local\Temp\sdDfLhN1.exe.part Win32/Adware.1ClickDownload.AM application
C:\Users\Andreas\AppData\Local\Temp\tbsTMP.exe multiple threats
C:\Users\Andreas\AppData\Local\Temp\{E66453AB-7A72-489F-93FA-459B0E04AC0C}\setup.exe multiple threats
C:\Users\Andreas\Downloads\kleine_haie_1080bps.mp4.exe Win32/Adware.MediaFinder.B application
C:\Users\Andreas\Local Settings\Temp\sdDfLhN1.exe.part Win32/Adware.1ClickDownload.AM application
C:\Users\Andreas\Local Settings\Temp\tbsTMP.exe multiple threats
C:\Users\Andreas\Local Settings\Temp\{E66453AB-7A72-489F-93FA-459B0E04AC0C}\setup.exe multiple threats mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 16.04.2014
Scan Time: 23:27:40
Logfile: 2014-04-16 mbam log.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.16.10
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Andreas
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 393676
Time Elapsed: 26 min, 18 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.InternetUpdaterService.A, C:\ProgramData\InternetUpdater\InternetUpdaterService.exe, 2088, , [17f3c06bee8ddf57ec7d2f1b98692ed2]
Modules: 0
(No malicious items detected)
Registry Keys: 12
PUP.Optional.InternetUpdaterService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\InternetUpdater, , [17f3c06bee8ddf57ec7d2f1b98692ed2],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, , [3fcbbf6c473440f672eac4529a6822de],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, , [ad5d73b8c9b256e082a8d244738fde22],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.InternetUpdater.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\InternetUpdater, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.Websteroids.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Websteroids, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM, , [f91152d92c4f8aac6f82d5be946fbd43],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [c44644e76417b482c41ef377a85a8779],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, , [a36731fa9ae18ea826ca97fc1de644bc],
Registry Values: 8
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM|simapp_id, 1590556208227549183, , [f91152d92c4f8aac6f82d5be946fbd43]
PUP.Optional.InternetUpdater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\INTERNETUPDATER|ImagePath, "C:\ProgramData\InternetUpdater\InternetUpdaterService.exe", , [7595be6d9fdcef47b4c804799e648878]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\Updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 1590556208227549183, , [a36731fa9ae18ea826ca97fc1de644bc]
Registry Data: 2
Windows.Tool.Disabled, HKLM\SOFTWARE\POLICIES\MICROSOFT\WINDOWS NT\SYSTEMRESTORE|DisableConfig, 1, Good: (0), Bad: (1),,[c7439a91e59655e19c0de43f44c030d0]
PUM.Hijack.CMDPrompt, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\SYSTEM|DisableCMD, 1, Good: (0), Bad: (1),,[fe0ca289ea91ad891ad12af6ff0506fa]
Folders: 16
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome\content, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\IE, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Conduit.A, C:\Users\Andreas\AppData\Local\Temp\CT3323737, , [0a00f833f5866ec817bcaab37e84d62a],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\ChromeHelper, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\FirefoxHelper, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\IeHelper, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome\content, , [e624e6450b70be7846514e158e74a15f],
Files: 69
PUP.Optional.InternetUpdaterService.A, C:\ProgramData\InternetUpdater\InternetUpdaterService.exe, , [17f3c06bee8ddf57ec7d2f1b98692ed2],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe, , [11f9e74476052e0848e184b8f40c6b95],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe, , [8d7d79b227543df9f7321c20ff018977],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\IeHelper\IeHelper.exe, , [6f9b56d5d1aa4cea76b31824996730d0],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsgE9FB.exe, , [b05a6bc0ed8e1521e01b849f3ec350b0],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsrA119.exe, , [0208d754f78437ffb5461013ca3757a9],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nst63AB.exe, , [b951fa315f1c74c2db204dd66c956997],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsw9B1F.exe, , [65a5a685a9d2d363b54652d1ab569769],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nswEE50.exe, , [d931e942bdbe58de92696cb7857c20e0],
PUP.Optional.Conduit.A, C:\Users\Andreas\AppData\Local\Temp\SPSetup.exe, , [56b4de4d5d1edf574d9d0e0aa061d030],
PUP.Optional.AdLyrics, C:\Users\Andreas\AppData\Local\Temp\tbsTMP.exe, , [7199c06b047747ef380cb35842bfe41c],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsb96F9.exe, , [9476b97282f968ce4fac7fa48f7206fa],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsbF218.exe, , [fd0d0229730867cf8f6c061d60a1f50b],
PUP.Optional.Somoto.A, C:\Users\Andreas\AppData\Local\Temp\HWzKBmCC.exe.part, , [e12962c9c8b376c0070096a207f93bc5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsaA3A2.exe, , [33d742e983f8d95d38c327fc06fba060],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsaC9B9.exe, , [0bff86a595e6013550abe24129d8da26],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsb568.exe, , [51b9f6357506db5bad4ea87bf011cb35],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsdA26B.exe, , [957533f81e5d89adcb30ed369b66ed13],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nst59E8.exe, , [14f6f03b6516c3738f6c37eca0619868],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nstC009.exe, , [a06aae7d5e1d043240bbda49a35eab55],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsv263A.exe, , [07032dfe8af17abce91277acc23f5fa1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsv9EF1.exe, , [7595ca618cef5bdb55a6be655da44fb1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsvA113.exe, , [f31757d4e29947efb14ae04322df936d],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsvCCF4.exe, , [a367b7745526f541d2298b98e51c9070],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsz6CCF.exe, , [18f2939857241125b84326fdf011956b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsg3212.exe, , [da300625324948eeac4fa57ec14008f8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsg8BEF.exe, , [a466fa31e09ba393d922de45d03160a0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsgB565.exe, , [b65434f7d1aa0f2713e86bb80af79b65],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsk743F.exe, , [9f6b0328205b41f54caff231f20fb54b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsk9A20.exe, , [9278b17a72092610639867bce918c53b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nskA8C7.exe, , [08022506ff7c72c435c6111234cd8977],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsl3608.exe, , [ac5e8c9f760541f575861d06fc05ed13],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nso5DBF.exe, , [47c31c0fec8f64d2d62535ee9f6248b8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nspA934.exe, , [9476d457176474c23dbe9e85837ea45c],
PUP.Optional.Bundlore, C:\Users\Andreas\Downloads\setup (1).exe, , [8a80270447347bbbb0969e83ba46de22],
PUP.Adware.Agent, C:\Users\Andreas\Downloads\kleine_haie_1080bps.mp4.exe, , [45c513184734c86e336237d00df304fc],
PUP.Optional.InstallIQ.A, C:\Users\Andreas\Downloads\frzfonts.exe, , [37d374b70d6ea393578265abf40dd927],
PUP.Optional.OpenCandy, C:\Users\Andreas\Downloads\MyPhoneExplorer_Setup_1.8.4.exe, , [4ac0bc6f12696acc91ef0f3a33d112ee],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\InternetUpdater.ico, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\app.dat, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\data.dat, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\InternetUpdaterService.exe.config, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\Uninstall.exe, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\app.dat, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Uninstall.exe, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Websteroids.ico, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\common.crx, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\announce.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\background.html, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\common.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\contentscript.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon128.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon16.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon48.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\iframecontentscript.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\manifest.json, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome.manifest, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\install.rdf, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome\content\main.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome\content\overlay.xul, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\IE\common.dll, , [5cae161592e9eb4b36593c42d32fa45c],
Worm.AutoIT, C:\Win\names.txt, , [d33746e58dee87afac7809b89d658c74],
Trojan.Agent, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62],
PUP.Optional.Conduit.A, C:\Users\Andreas\AppData\Local\Temp\CT3323737\ddt.csf, , [0a00f833f5866ec817bcaab37e84d62a],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome.manifest, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\install.rdf, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome\content\main.js, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome\content\overlay.xul, , [e624e6450b70be7846514e158e74a15f],
Physical Sectors: 0
(No malicious items detected)
(end) ADW CLeaner: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 16.04.2014
Scan Time: 23:27:40
Logfile: 2014-04-16 mbam log.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.16.10
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Andreas
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 393676
Time Elapsed: 26 min, 18 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.InternetUpdaterService.A, C:\ProgramData\InternetUpdater\InternetUpdaterService.exe, 2088, , [17f3c06bee8ddf57ec7d2f1b98692ed2]
Modules: 0
(No malicious items detected)
Registry Keys: 12
PUP.Optional.InternetUpdaterService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\InternetUpdater, , [17f3c06bee8ddf57ec7d2f1b98692ed2],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, , [3fcbbf6c473440f672eac4529a6822de],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, , [ad5d73b8c9b256e082a8d244738fde22],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.MoodTube.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}, , [cb3f34f7c8b32610ea8c11031ee4c739],
PUP.Optional.InternetUpdater.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\InternetUpdater, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.Websteroids.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Websteroids, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM, , [f91152d92c4f8aac6f82d5be946fbd43],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [c44644e76417b482c41ef377a85a8779],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, , [a36731fa9ae18ea826ca97fc1de644bc],
Registry Values: 8
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM|simapp_id, 1590556208227549183, , [f91152d92c4f8aac6f82d5be946fbd43]
PUP.Optional.InternetUpdater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\INTERNETUPDATER|ImagePath, "C:\ProgramData\InternetUpdater\InternetUpdaterService.exe", , [7595be6d9fdcef47b4c804799e648878]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\Updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
Trojan.Agent, HKU\S-1-5-21-1624768357-4126066135-592724133-1010-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 1590556208227549183, , [a36731fa9ae18ea826ca97fc1de644bc]
Registry Data: 2
Windows.Tool.Disabled, HKLM\SOFTWARE\POLICIES\MICROSOFT\WINDOWS NT\SYSTEMRESTORE|DisableConfig, 1, Good: (0), Bad: (1),,[c7439a91e59655e19c0de43f44c030d0]
PUM.Hijack.CMDPrompt, HKU\S-1-5-21-1624768357-4126066135-592724133-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\SYSTEM|DisableCMD, 1, Good: (0), Bad: (1),,[fe0ca289ea91ad891ad12af6ff0506fa]
Folders: 16
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome\content, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\IE, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Conduit.A, C:\Users\Andreas\AppData\Local\Temp\CT3323737, , [0a00f833f5866ec817bcaab37e84d62a],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\ChromeHelper, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\FirefoxHelper, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\IeHelper, , [bb4f2902d5a61d1916881b43936fea16],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome\content, , [e624e6450b70be7846514e158e74a15f],
Files: 69
PUP.Optional.InternetUpdaterService.A, C:\ProgramData\InternetUpdater\InternetUpdaterService.exe, , [17f3c06bee8ddf57ec7d2f1b98692ed2],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe, , [11f9e74476052e0848e184b8f40c6b95],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe, , [8d7d79b227543df9f7321c20ff018977],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\IeHelper\IeHelper.exe, , [6f9b56d5d1aa4cea76b31824996730d0],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsgE9FB.exe, , [b05a6bc0ed8e1521e01b849f3ec350b0],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsrA119.exe, , [0208d754f78437ffb5461013ca3757a9],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nst63AB.exe, , [b951fa315f1c74c2db204dd66c956997],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsw9B1F.exe, , [65a5a685a9d2d363b54652d1ab569769],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nswEE50.exe, , [d931e942bdbe58de92696cb7857c20e0],
PUP.Optional.Conduit.A, C:\Users\Andreas\AppData\Local\Temp\SPSetup.exe, , [56b4de4d5d1edf574d9d0e0aa061d030],
PUP.Optional.AdLyrics, C:\Users\Andreas\AppData\Local\Temp\tbsTMP.exe, , [7199c06b047747ef380cb35842bfe41c],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsb96F9.exe, , [9476b97282f968ce4fac7fa48f7206fa],
PUP.Optional.SearchProtect.A, C:\Users\Andreas\AppData\Local\Temp\nsbF218.exe, , [fd0d0229730867cf8f6c061d60a1f50b],
PUP.Optional.Somoto.A, C:\Users\Andreas\AppData\Local\Temp\HWzKBmCC.exe.part, , [e12962c9c8b376c0070096a207f93bc5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsaA3A2.exe, , [33d742e983f8d95d38c327fc06fba060],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsaC9B9.exe, , [0bff86a595e6013550abe24129d8da26],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsb568.exe, , [51b9f6357506db5bad4ea87bf011cb35],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsdA26B.exe, , [957533f81e5d89adcb30ed369b66ed13],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nst59E8.exe, , [14f6f03b6516c3738f6c37eca0619868],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nstC009.exe, , [a06aae7d5e1d043240bbda49a35eab55],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsv263A.exe, , [07032dfe8af17abce91277acc23f5fa1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsv9EF1.exe, , [7595ca618cef5bdb55a6be655da44fb1],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsvA113.exe, , [f31757d4e29947efb14ae04322df936d],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsvCCF4.exe, , [a367b7745526f541d2298b98e51c9070],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsz6CCF.exe, , [18f2939857241125b84326fdf011956b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsg3212.exe, , [da300625324948eeac4fa57ec14008f8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsg8BEF.exe, , [a466fa31e09ba393d922de45d03160a0],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsgB565.exe, , [b65434f7d1aa0f2713e86bb80af79b65],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsk743F.exe, , [9f6b0328205b41f54caff231f20fb54b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsk9A20.exe, , [9278b17a72092610639867bce918c53b],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nskA8C7.exe, , [08022506ff7c72c435c6111234cd8977],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsl3608.exe, , [ac5e8c9f760541f575861d06fc05ed13],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nso5DBF.exe, , [47c31c0fec8f64d2d62535ee9f6248b8],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nspA934.exe, , [9476d457176474c23dbe9e85837ea45c],
PUP.Optional.Bundlore, C:\Users\Andreas\Downloads\setup (1).exe, , [8a80270447347bbbb0969e83ba46de22],
PUP.Adware.Agent, C:\Users\Andreas\Downloads\kleine_haie_1080bps.mp4.exe, , [45c513184734c86e336237d00df304fc],
PUP.Optional.InstallIQ.A, C:\Users\Andreas\Downloads\frzfonts.exe, , [37d374b70d6ea393578265abf40dd927],
PUP.Optional.OpenCandy, C:\Users\Andreas\Downloads\MyPhoneExplorer_Setup_1.8.4.exe, , [4ac0bc6f12696acc91ef0f3a33d112ee],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\InternetUpdater.ico, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\app.dat, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\data.dat, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\InternetUpdaterService.exe.config, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.InternetUpdater.A, C:\ProgramData\InternetUpdater\Uninstall.exe, , [cf3b07240d6edd59e398cfae51b19070],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\app.dat, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Uninstall.exe, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Websteroids.ico, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\common.crx, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\announce.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\background.html, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\common.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\contentscript.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon128.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon16.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\icon48.png, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\iframecontentscript.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Chrome\unzip\manifest.json, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome.manifest, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\install.rdf, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome\content\main.js, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\Firefox\chrome\content\overlay.xul, , [5cae161592e9eb4b36593c42d32fa45c],
PUP.Optional.Websteroids.A, C:\ProgramData\Websteroids\IE\common.dll, , [5cae161592e9eb4b36593c42d32fa45c],
Worm.AutoIT, C:\Win\names.txt, , [d33746e58dee87afac7809b89d658c74],
Trojan.Agent, C:\ProgramData\Updater\updater.exe, , [a8623dee3249b086f9cb217e996a9e62],
PUP.Optional.Conduit.A, C:\Users\Andreas\AppData\Local\Temp\CT3323737\ddt.csf, , [0a00f833f5866ec817bcaab37e84d62a],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome.manifest, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\install.rdf, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome\content\main.js, , [e624e6450b70be7846514e158e74a15f],
PUP.Optional.Websteroids.A, C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qccujxhm.default\extensions\support@websteroidsapp.com\chrome\content\overlay.xul, , [e624e6450b70be7846514e158e74a15f],
Physical Sectors: 0
(No malicious items detected)
(end) |