Phil1337 | 30.05.2014 15:17 | malwarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 30.05.2014
Scan Time: 09:16:48
Logfile: log.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.05.30.05
Rootkit Database: v2014.05.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Phillipê
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 339664
Time Elapsed: 6 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 25
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, Quarantined, [711cd285c2b9cf6752f231352ed4f50b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, Quarantined, [711cd285c2b9cf6752f231352ed4f50b],
PUP.Optional.ConduitTB.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{30F9B915-B755-4826-820B-08FBA6BD249D}, Quarantined, [aae3e2752c4f9a9c99ec75ba36ccb24e],
PUP.Optional.ConduitTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{30F9B915-B755-4826-820B-08FBA6BD249D}, Quarantined, [aae3e2752c4f9a9c99ec75ba36ccb24e],
PUP.Optional.ConduitTB.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{30F9B915-B755-4826-820B-08FBA6BD249D}, Quarantined, [aae3e2752c4f9a9c99ec75ba36ccb24e],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{64182481-4F71-486B-A045-B233BD0DA8FC}, Quarantined, [830a83d4a3d892a4629d1b1430d2b749],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{64182481-4F71-486B-A045-B233BD0DA8FC}, Quarantined, [830a83d4a3d892a4629d1b1430d2b749],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}, Quarantined, [1578f36422599e98e61a6fc1bf43916f],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}, Quarantined, [1578f36422599e98e61a6fc1bf43916f],
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DSite, Quarantined, [8a039abd0e6db383d4eb4de5fd042dd3],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, Quarantined, [8a03be994f2c72c492312864778ba060],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\facemoods.com, Quarantined, [850872e585f644f2e9358d1060a2c23e],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ihflimipbcaljfnojhhknppphnnciiif, Quarantined, [6a233324443792a445d8712c42c0ca36],
PUP.Optional.Gophoto.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pfmopbbadnfoelckkcmjjeaaegjpjjbk, Quarantined, [761770e7e398b77f67499e27b44fe917],
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, Quarantined, [f29b75e21f5cce6885ec426638caa45c],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Quarantined, [3a53391eadcef83e79d5c7fb0af9a759],
PUP.Optional.BabylonToolBar.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BabylonToolbar, Quarantined, [8b024e09bcbf2511bfe81ca88c773fc1],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, Quarantined, [e0ad63f489f200360fc20bb5fc07f20e],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\facemoods.com, Quarantined, [3c510255ee8d2c0afa259508e61c02fe],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, Quarantined, [6b22a5b232491422a2ade5c040c2ca36],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [dcb1d87f2b5091a573827b4520e3b14f],
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [4845d1864c2f181e983a0c9e669c45bb],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [d8b54e09b7c41f17a8dbf7a259a9916f],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\facemoods.com, Quarantined, [404d084fe19a86b02cf356474cb67e82],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1406149438-3228825593-328108524-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, Quarantined, [b3daaea99be0c6705af52e77f2107d83],
Registry Values: 4
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}, facemoods Toolbar, Quarantined, [1578f36422599e98e61a6fc1bf43916f]
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}, Quarantined, [ddb088cfc6b5a59159a71c1414eef709],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0M1S1H1K2U, Quarantined, [dcb1d87f2b5091a573827b4520e3b14f]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, SnapdoOCYB, Quarantined, [4845d1864c2f181e983a0c9e669c45bb]
Registry Data: 6
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://start.facemoods.com/?a=ddr&s={searchTerms}&f=4, Good: (www.google.com), Bad: (hxxp://start.facemoods.com/?a=ddr&s={searchTerms}&f=4),Replaced,[bad3dc7b3a41a98d21091a443aca6e92]
PUP.Optional.Snapdo, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013),Replaced,[c5c831264635c96db228baa262a24eb2]
PUP.Optional.StartPage, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www1.delta-search.com/?affID=119816&babsrc=HP_ss&mntrId=8EC600FFE8A7A881, Good: (hxxp://www.google.com), Bad: (hxxp://www1.delta-search.com/?affID=119816&babsrc=HP_ss&mntrId=8EC600FFE8A7A881),Replaced,[a0ed58ff87f4280e5c90f06c8e76bf41]
PUP.Optional.Snapdo, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013),Replaced,[810c2235512ae45235a4fa62de26ac54]
PUP.Optional.Snapdo, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013),Replaced,[434acf88a1da6bcbca1299c3b54fe719]
PUP.Optional.Snapdo, HKU\S-1-5-21-1406149438-3228825593-328108524-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=3954ebe6-4511-499e-b334-12b942b293da&searchtype=ds&q={searchTerms}&installDate=14/04/2013),Replaced,[5a3395c22358191de2fb065634d0639d]
Folders: 10
PUP.Optional.Updater, C:\Users\Phillipê\AppData\Roaming\DIGITALSITES\UPDATEPROC, Quarantined, [4746e86f88f36cca2d046a416d957e82],
PUP.Optional.HDVidCodec.A, C:\Users\Phillipê\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HDVIDCODEC.COM, Quarantined, [117cd186c1ba6dc902da348db35012ee],
PUP.Optional.Gophoto.A, C:\Program Files (x86)\Gophoto.it, Quarantined, [8409391ef18a9f97e7c8873e83805ea2],
PUP.Optional.DealPly.A, C:\Users\Phillipê\AppData\Roaming\DealPly, Quarantined, [791487d0493256e0917a4e2bd230837d],
PUP.Optional.DealPly.A, C:\Users\Phillipê\AppData\Roaming\DealPly\UpdateProc, Quarantined, [791487d0493256e0917a4e2bd230837d],
PUP.Optional.OpenCandy, C:\Users\Phillipê\AppData\Roaming\OPENCANDY, Quarantined, [cfbe2a2daccf6acc50f20c6d20e21ce4],
PUP.Optional.OpenCandy, C:\Users\Phillipê\AppData\Roaming\OPENCANDY\9ABC59DFC98F4921A9DF7200B7610E42, Quarantined, [cfbe2a2daccf6acc50f20c6d20e21ce4],
PUP.Optional.Babylon.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\extensions\FFXTLBR@BABYLON.COM, Quarantined, [781534236615fd3957623c429a686898],
PUP.Optional.Babylon.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\extensions\FFXTLBR@BABYLON.COM\defaults, Quarantined, [781534236615fd3957623c429a686898],
PUP.Optional.Babylon.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\extensions\FFXTLBR@BABYLON.COM\defaults\preferences, Quarantined, [781534236615fd3957623c429a686898],
Files: 36
PUP.Optional.DigitalSites.A, C:\Users\Phillipê\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe, Quarantined, [8a039abd0e6db383d4eb4de5fd042dd3],
PUP.Optional.TornTV.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\extensions\TORNTV@TORNTV.COM.XPI, Quarantined, [b2db4215d7a42f076922543d9a68e31d],
PUP.Optional.GoPhoto.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\extensions\GOPHOTO@GOPHOTO.IT.XPI, Quarantined, [028bfc5b93e8989ee8112171ba485da3],
PUP.Optional.Conduit.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\searchplugins\conduit.xml, Quarantined, [d7b670e7e596290d9374d7c9639f03fd],
PUP.Optional.Delta.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\searchplugins\delta.xml, Quarantined, [7e0f42151c5f0e285fb5ccd4dd258080],
PUP.Optional.Updater, C:\Users\Phillipê\AppData\Roaming\DigitalSites\UpdateProc\UPDATETASK.EXE, Quarantined, [4746e86f88f36cca2d046a416d957e82],
PUP.Optional.Updater, C:\Users\Phillipê\AppData\Roaming\DigitalSites\UpdateProc\config.dat, Quarantined, [4746e86f88f36cca2d046a416d957e82],
PUP.Optional.Updater, C:\Users\Phillipê\AppData\Roaming\DigitalSites\UpdateProc\info.dat, Quarantined, [4746e86f88f36cca2d046a416d957e82],
PUP.Optional.Updater, C:\Users\Phillipê\AppData\Roaming\DigitalSites\UpdateProc\STTL.DAT, Quarantined, [4746e86f88f36cca2d046a416d957e82],
PUP.Optional.Updater, C:\Users\Phillipê\AppData\Roaming\DigitalSites\UpdateProc\TTL.DAT, Quarantined, [4746e86f88f36cca2d046a416d957e82],
PUP.Optional.HDVidCodec.A, C:\Users\Phillipê\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\HDVIDCODEC.LNK, Quarantined, [117cd186c1ba6dc902da348db35012ee],
PUP.Optional.HDVidCodec.A, C:\Users\Phillipê\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\Uninstall.lnk, Quarantined, [117cd186c1ba6dc902da348db35012ee],
PUP.Optional.BrowserDefender.A, C:\Users\Phillipê\AppData\Local\Google\Chrome\User Data\Default\Local Storage\CHROME-EXTENSION_EOONCJEJNPPFJJKLAPAAMHCDMJBILMDE_0.LOCALSTORAGE, Quarantined, [1f6ef4633a41340250de21a3e41f5da3],
PUP.Optional.Gophoto.A, C:\Program Files (x86)\Gophoto.it\GOPHOTOIT14.CRX, Quarantined, [8409391ef18a9f97e7c8873e83805ea2],
PUP.Optional.DealPly.A, C:\Users\Phillipê\AppData\Roaming\DealPly\UpdateProc\config.dat, Quarantined, [791487d0493256e0917a4e2bd230837d],
PUP.Optional.DealPly.A, C:\Users\Phillipê\AppData\Roaming\DealPly\UpdateProc\info.dat, Quarantined, [791487d0493256e0917a4e2bd230837d],
PUP.Optional.DealPly.A, C:\Users\Phillipê\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe, Quarantined, [791487d0493256e0917a4e2bd230837d],
PUP.Optional.OpenCandy, C:\Users\Phillipê\AppData\Roaming\OpenCandy\9ABC59DFC98F4921A9DF7200B7610E42\3708.ico, Quarantined, [cfbe2a2daccf6acc50f20c6d20e21ce4],
PUP.Optional.OpenCandy, C:\Users\Phillipê\AppData\Roaming\OpenCandy\9ABC59DFC98F4921A9DF7200B7610E42\EBB77268-338F-4C6A-8590-AD88FED26F4A, Quarantined, [cfbe2a2daccf6acc50f20c6d20e21ce4],
PUP.Optional.OpenCandy, C:\Users\Phillipê\AppData\Roaming\OpenCandy\9ABC59DFC98F4921A9DF7200B7610E42\Installer.exe, Quarantined, [cfbe2a2daccf6acc50f20c6d20e21ce4],
PUP.Optional.OpenCandy, C:\Users\Phillipê\AppData\Roaming\OpenCandy\9ABC59DFC98F4921A9DF7200B7610E42\OCBrowserHelper_1.0.6.124.exe, Quarantined, [cfbe2a2daccf6acc50f20c6d20e21ce4],
PUP.Optional.Babylon.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\extensions\ffxtlbr@babylon.com\defaults\preferences\babylon.js, Quarantined, [781534236615fd3957623c429a686898],
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods._xpiupdate", true);), Replaced,[d3ba2a2d2853a4921f408109778d5da3]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.aflt", "_#ddr");), Replaced,[a2eb95c284f7e551b4ab2e5ca75db050]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");), Replaced,[573665f28bf064d29ac50684af5530d0]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.firstRun", false);), Replaced,[b4d9fb5cc1ba89ad104fbdcdee165ba5]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.first_time", false);), Replaced,[78152532354654e2a0bf8a00f311946c]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.id", "_#b0ffe46e51be4461b098796deac5badd");), Replaced,[9cf112453e3db086055a09813cc8b64a]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.instlDay", "_#15205");), Replaced,[8a03f06795e662d43926f79320e4c739]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.lastActv", "18");), Replaced,[dfae6aed9ddeea4ca5ba7e0c63a120e0]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");), Replaced,[305d1443a4d750e6ff607119659f4eb2]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.sid", "_#b0ffe46e51be4461b098796deac5badd");), Replaced,[840951068eed1026fb64fb8f58ac728e]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.update", "_#v1.4.0");), Replaced,[88056ee9d1aaa98d005f6e1cf80caa56]
PUP.Optional.FaceMoods.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");), Replaced,[ace182d5ef8cc670a8b7e6a419eb38c8]
PUP.Optional.Conduit.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}");), Replaced,[2568055217641d194f6f296107fd6799]
PUP.Optional.Conduit.A, C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\prefs.js, Good: (), Bad: (user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");), Replaced,[38554215a3d8dc5a0ab5830760a4ae52]
Physical Sectors: 0
(No malicious items detected)
(end) Emsisoft Code:
Emsisoft Anti-Malware - Version 8.1
Letztes Update: 30.05.2014 09:38:29
Benutzerkonto: Dröhnkiste-C35D\Phillipê
Scan Einstellungen:
Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\, F:\
PUPs-Erkennung: An
Archiv Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus
Scan Beginn: 30.05.2014 09:39:01
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it! gefunden: Application.AdStart (A)
C:\Users\Phillipê\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\torntv.com gefunden: Application.AdStart (A)
C:\Users\Phillipê\AppData\Roaming\babylon gefunden: Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\drivercure gefunden: Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\dsite gefunden: Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\dvdvideosoftiehelpers gefunden: Application.AppInstall (A)
C:\ProgramData\babylon gefunden: Application.AppInstall (A)
C:\Users\Phillipê\AppData\Local\vghd gefunden: Application.AppInstall (A)
C:\Program Files (x86)\daemon tools toolbar gefunden: Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\Extensions\engine@conduit.com gefunden: Application.FireExt (A)
C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\Extensions\{acaa314b-eeba-48e4-ad47-84e31c44796c} gefunden: Application.FireExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} gefunden: Application.AdReg (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\CLASSES\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CONDUIT.ENGINE gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\DTTOOLBAR.TOOLBANDOBJ gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\DTTOOLBAR.TOOLBANDOBJ.1 gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{09C554C3-109B-483C-A06B-F14172F1A947} gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} gefunden: Application.BHO (A)
Value: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-501\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS -> LFIND@NIJADSOFT.NET gefunden: Application.FireExt (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\SOFTONIC gefunden: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\BABYLON gefunden: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DAEMON TOOLS TOOLBAR gefunden: Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SYSTWEAK gefunden: Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\PARTYGAMING gefunden: Application.Win32.CasOnline (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-501\SOFTWARE\PARTYGAMING gefunden: Application.Win32.CasOnline (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-501\SOFTWARE\CONDUIT gefunden: Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\DSITEPRODUCTS gefunden: Application.Win32.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5} gefunden: Application.Win32.WSearch (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\YAHOOPARTNERTOOLBAR gefunden: Application.Win32.YTool (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PROD.CAP gefunden: Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\AU__RASAPI32 gefunden: Application.Win32.InstallExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\AU__RASMANCS gefunden: Application.Win32.InstallExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\MYBABYLONTB_RASAPI32 gefunden: Application.Win32.InstallExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\MYBABYLONTB_RASMANCS gefunden: Application.Win32.InstallExt (A)
D:\Mafia2\Mafia II\pc\Mafia 2 Crackfix.exe gefunden: Trojan.Generic.4653231 (B)
F:\DL\Bulletstorm\Bulletstorm Install\SKIDROW\Binaries\Win32\SKIDROW.dll gefunden: Trojan.Generic.5482034 (B)
F:\DL\Bulletstorm\Bulletstorm.Proper-SKIDROW\SKIDROW\Binaries\Win32\SKIDROW.dll gefunden: Trojan.Generic.5482034 (B)
F:\DL\Bulletstorm\Bulletstorm.Proper-SKIDROW\sr-bustp.rar -> SKIDROW\Binaries\Win32\SKIDROW.dll gefunden: Trojan.Generic.5482034 (B)
F:\DL\Kane.and.Lynch.2.Dog.Days-RELOADED\steambackup.exe gefunden: Trojan.Generic.5338659 (B)
F:\Spiele\Bulletstorm\Binaries\Win32\SKIDROW.dll gefunden: Trojan.Generic.5482034 (B)
F:\Spiele\Call of Duty 8 - Modern Warfare 3\COD8.MW3.SP.Crack.Only-3DM.rar -> iw5sp.exe gefunden: Trojan.Generic.7446411 (B)
F:\Spiele\Grand Theft Auto IV\LaunchGTAIV.exe gefunden: Riskware.Win32.HackTool (A)
Gescannt 446375
Gefunden 43
Scan Ende: 30.05.2014 11:38:49
Scan Zeit: 1:59:48
F:\Spiele\Grand Theft Auto IV\LaunchGTAIV.exe Quarantäne Riskware.Win32.HackTool (A)
F:\Spiele\Call of Duty 8 - Modern Warfare 3\COD8.MW3.SP.Crack.Only-3DM.rar Quarantäne Trojan.Generic.7446411 (B)
F:\DL\Kane.and.Lynch.2.Dog.Days-RELOADED\steambackup.exe Quarantäne Trojan.Generic.5338659 (B)
F:\DL\Bulletstorm\Bulletstorm Install\SKIDROW\Binaries\Win32\SKIDROW.dll Quarantäne Trojan.Generic.5482034 (B)
F:\DL\Bulletstorm\Bulletstorm.Proper-SKIDROW\SKIDROW\Binaries\Win32\SKIDROW.dll Quarantäne Trojan.Generic.5482034 (B)
F:\DL\Bulletstorm\Bulletstorm.Proper-SKIDROW\sr-bustp.rar Quarantäne Trojan.Generic.5482034 (B)
F:\Spiele\Bulletstorm\Binaries\Win32\SKIDROW.dll Quarantäne Trojan.Generic.5482034 (B)
D:\Mafia2\Mafia II\pc\Mafia 2 Crackfix.exe Quarantäne Trojan.Generic.4653231 (B)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\AU__RASAPI32 Quarantäne Application.Win32.InstallExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\AU__RASMANCS Quarantäne Application.Win32.InstallExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\MYBABYLONTB_RASAPI32 Quarantäne Application.Win32.InstallExt (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\MYBABYLONTB_RASMANCS Quarantäne Application.Win32.InstallExt (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\YAHOOPARTNERTOOLBAR Quarantäne Application.Win32.YTool (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Quarantäne Application.Win32.WSearch (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\DSITEPRODUCTS Quarantäne Application.Win32.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\PARTYGAMING Quarantäne Application.Win32.CasOnline (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-501\SOFTWARE\PARTYGAMING Quarantäne Application.Win32.CasOnline (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-1000\SOFTWARE\SOFTONIC Quarantäne Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\BABYLON Quarantäne Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DAEMON TOOLS TOOLBAR Quarantäne Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SYSTWEAK Quarantäne Application.InstallAd (A)
Key: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-501\SOFTWARE\CONDUIT Quarantäne Application.InstallAd (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Quarantäne Application.BHO (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Quarantäne Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Quarantäne Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CONDUIT.ENGINE Quarantäne Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\DTTOOLBAR.TOOLBANDOBJ Quarantäne Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\DTTOOLBAR.TOOLBANDOBJ.1 Quarantäne Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{09C554C3-109B-483C-A06B-F14172F1A947} Quarantäne Application.AdReg (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\PROD.CAP Quarantäne Application.AdReg (A)
C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\Extensions\engine@conduit.com Quarantäne Application.FireExt (A)
C:\Users\Phillipê\AppData\Roaming\Mozilla\Firefox\Profiles\wqm2l6e1.default\Extensions\{acaa314b-eeba-48e4-ad47-84e31c44796c} Quarantäne Application.FireExt (A)
Value: HKEY_USERS\S-1-5-21-1406149438-3228825593-328108524-501\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS -> LFIND@NIJADSOFT.NET Quarantäne Application.FireExt (A)
C:\Users\Phillipê\AppData\Roaming\babylon Quarantäne Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\drivercure Quarantäne Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\dsite Quarantäne Application.AppInstall (A)
C:\Users\Phillipê\AppData\Roaming\dvdvideosoftiehelpers Quarantäne Application.AppInstall (A)
C:\ProgramData\babylon Quarantäne Application.AppInstall (A)
C:\Users\Phillipê\AppData\Local\vghd Quarantäne Application.AppInstall (A)
C:\Program Files (x86)\daemon tools toolbar Quarantäne Application.AppInstall (A)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it! Quarantäne Application.AdStart (A)
C:\Users\Phillipê\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\torntv.com Quarantäne Application.AdStart (A)
Quarantäne 42 |