Hallo! MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 02.05.2014
Suchlauf-Zeit: 15:05:12
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.02.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: apehead
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 279078
Verstrichene Zeit: 20 Min, 24 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Deaktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 6
PUP.Optional.Snapdo, HKU\S-1-5-21-2382558792-2255420357-3472741635-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013),Ersetzt,[679907f9916fdb25141c77c011f3946c]
PUP.Optional.Snapdo, HKU\S-1-5-21-2382558792-2255420357-3472741635-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=hp&installDate=02/08/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=hp&installDate=02/08/2013),Ersetzt,[2bd5d32d59a7d729d55c93a452b237c9]
PUP.Optional.Snapdo, HKU\S-1-5-21-2382558792-2255420357-3472741635-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013),Ersetzt,[3fc12bd5a15ff8089a954ceba3617c84]
PUP.Optional.Snapdo, HKU\S-1-5-21-2382558792-2255420357-3472741635-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013),Ersetzt,[ea16ce3246ba1de34be70a2dcc382ed2]
PUP.Optional.Snapdo, HKU\S-1-5-21-2382558792-2255420357-3472741635-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013),Ersetzt,[39c7da26b05003fd072c71c615ef40c0]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2382558792-2255420357-3472741635-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=1ca80c6b-251b-4165-acb9-3e3d209cc3fd&searchtype=ds&q={searchTerms}&installDate=02/08/2013),Ersetzt,[e41c48b8946c6d937a4f35f861a36e92]
Ordner: 5
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3297265, In Quarantäne, [c838837dc63a3ac670151057857d2fd1],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3297861, In Quarantäne, [3cc4bf41956bd42c5b2a97d057ab9e62],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3311333, In Quarantäne, [15eb9b6530d04ab6c1c4b9aec042bb45],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3288691, In Quarantäne, [08f8d12faf51be42c2c393d4748e1de3],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\mam-ct3325521, In Quarantäne, [5ea258a8936d2ad696126ffea55d7c84],
Dateien: 33
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\sp-downloader.exe, In Quarantäne, [bd43f808b44c60a04c45061369986799],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\SSStub_Somo_ValueApps.exe, In Quarantäne, [728ee21e6d93a65a2869958421e053ad],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\dlLogic.exe, In Quarantäne, [eb15c53b20e037c9ea2ed43046bb38c8],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nshE113.exe, In Quarantäne, [907057a9b44c9f61570ff82eb54cbe42],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nshE3D2.exe, In Quarantäne, [4cb4d9272ed205fb52145acc857c33cd],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nsnA539.exe, In Quarantäne, [c43c3bc548b8ce32590d1016c33e9868],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nssC019.exe, In Quarantäne, [7f81d7293bc5986871f511153fc2d12f],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nssDE2C.exe, In Quarantäne, [3bc5e31d1be5c43c25418d9955acc739],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nswF7D4.exe, In Quarantäne, [eb152ad6a45c4fb10b5bb175e61b9070],
PUP.Optional.BSDownloader, C:\Users\apehead\AppData\Local\Temp\ab0GuIDq.exe.part, In Quarantäne, [cf31ed1324dcad531f3bb46a9b65af51],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nsb1759.exe, In Quarantäne, [fc046799b64a30d005612204a958669a],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nsbFA64.exe, In Quarantäne, [0df320e016eaee12fe681f070cf5768a],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nscBDE6.exe, In Quarantäne, [b64a44bcdd23d22e94d2ca5c07fa8779],
PUP.Optional.SearchProtect.A, C:\Users\apehead\AppData\Local\Temp\nsg1A85.exe, In Quarantäne, [936d748c6c94907016501610ea17bc44],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3297265\ism.exe, In Quarantäne, [50b0619fea16f010112469b647b9f808],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3311333\sl.exe, In Quarantäne, [7090df219e62f10fa2b1a88f926eca36],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\mam-ct3325521\ctbe.exe, In Quarantäne, [629e0ff13bc5dd231a390d2ad9279769],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\mam-ct3325521\mamstub.exe, In Quarantäne, [9a66b749a65a5fa1a17772920ff2f60a],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\mam-ct3325521\mam_ff.exe, In Quarantäne, [837db64adc24ee1252023403af510df3],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\mam-ct3325521\mam_ie.exe, In Quarantäne, [946c36cabe42f80842e32f3742bf7b85],
PUP.Optional.Babylon.A, C:\Users\apehead\AppData\Local\Temp\E367DC5D-BAB0-7891-9647-22DC5F68123A\Latest\ccp.exe, In Quarantäne, [b74939c70cf4b14fa77ce539c63a2cd4],
PUP.Optional.Babylon.A, C:\Users\apehead\AppData\Local\Temp\E367DC5D-BAB0-7891-9647-22DC5F68123A\Latest\CrxInstaller.dll, In Quarantäne, [6e92ee128779847c7f9d42d47a87d22e],
PUP.Optional.Delta, C:\Users\apehead\AppData\Local\Temp\E367DC5D-BAB0-7891-9647-22DC5F68123A\Latest\MyDeltaTB.exe, In Quarantäne, [e31dc13f5fa1c43c3fcae2243ac7d828],
PUP.Optional.Babylon.A, C:\Users\apehead\AppData\Local\Temp\E367DC5D-BAB0-7891-9647-22DC5F68123A\Latest\Setup.exe, In Quarantäne, [49b75ca4ce32867a65c9c856c33d29d7],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\nslAEC2\SpSetup.exe, In Quarantäne, [817f728e699703fdf263ae6dfc054cb4],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\nssA4F9\SpSetup.exe, In Quarantäne, [02fea45ccc347a868fc6f2296c95ea16],
PUP.Optional.Delta.A, C:\Users\apehead\AppData\Local\Temp\is1070216317\DeltaTB.exe, In Quarantäne, [b8488779e91741bfa9c251b3cd34d927],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3297861\chromeid.txt, In Quarantäne, [3cc4bf41956bd42c5b2a97d057ab9e62],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3297861\setup.ini.txt, In Quarantäne, [3cc4bf41956bd42c5b2a97d057ab9e62],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3311333\chromeid.txt, In Quarantäne, [15eb9b6530d04ab6c1c4b9aec042bb45],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3311333\setup.ini.txt, In Quarantäne, [15eb9b6530d04ab6c1c4b9aec042bb45],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3288691\chromeid.txt, In Quarantäne, [08f8d12faf51be42c2c393d4748e1de3],
PUP.Optional.Conduit.A, C:\Users\apehead\AppData\Local\Temp\ct3288691\setup.ini.txt, In Quarantäne, [08f8d12faf51be42c2c393d4748e1de3],
Physische Sektoren: 0
(No malicious items detected)
(end) Mit ESET habe ich leider das Problem, dass kein Log da ist. Habe das Programm über 2 Stunden laufen lassen und als ich wieder am PC war, war kein Log da. Er hatte allerdings gemeldet "Keine Bedrohungen gefunden".
LG |