Huhu Cosinus, hier die beiden Logs: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.12.2014
Suchlauf-Zeit: 18:44:38
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.29.06
Rootkit Datenbank: v2014.12.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: clara
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 323612
Verstrichene Zeit: 31 Min, 51 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.ZombieInvasion.A, C:\ProgramData\cDQBHoBttZ\UtnhMyWMJup.exe, 1300, Löschen bei Neustart, [e8b2c8a01666c96ddb55eada827f6799]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 7
PUP.Optional.ZombieInvasion.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UtnhMyWMJup, In Quarantäne, [e8b2c8a01666c96ddb55eada827f6799],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQPro-Video 1.6V25.12, In Quarantäne, [7f1b88e088f4dd59972e78ee946fc937],
PUP.Optional.SpeedCheck.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C33D4E60-E1C5-033A-C8F1-64C5CC10DEE8}, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{41F6B857-4B38-6055-C1B1-39C5183CF1AE}, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{41F6B857-4B38-6055-C1B1-39C5183CF1AE}, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C33D4E60-E1C5-033A-C8F1-64C5CC10DEE8}, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\04C531DB-853E-E614-F2C7-24EF6EC541F0, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 3
PUP.Optional.ZombieInvasion.A, C:\Users\clara\AppData\Local\ZombieInvasion, In Quarantäne, [fd9d7bed3448d75fcd2887c51ae9e719],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\x64, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
Dateien: 20
PUP.Optional.ZombieInvasion.A, C:\ProgramData\cDQBHoBttZ\UtnhMyWMJup.exe, Löschen bei Neustart, [e8b2c8a01666c96ddb55eada827f6799],
PUP.Optional.ZombieInvasion.A, C:\ProgramData\cDQBHoBttZ\dat\eOiahLV.exe, Löschen bei Neustart, [d4c6a4c486f6e452a48c0eb6e918be42],
PUP.Optional.ZombieInvasion.A, C:\ProgramData\cDQBHoBttZ\dat\PigiNvTVzlj.exe, Löschen bei Neustart, [8d0d3434205c023460d01ea6a25f6a96],
PUP.Optional.CrossRider.A, C:\Users\clara\AppData\Roaming\HUDYW.exe, In Quarantäne, [6d2d1454324ab1854ddf3c791de84cb4],
PUP.Optional.WebInstrNew.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNewH_01009.Wdf, In Quarantäne, [6832dd8b90ecc86ebe776af4ee158080],
PUP.Optional.ZombieInvasion.A, C:\Users\clara\AppData\Local\ZombieInvasion\data2.dat, In Quarantäne, [fd9d7bed3448d75fcd2887c51ae9e719],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\184.crx, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\184.dat, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\184.dll, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\184.xpi, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\184_x64.dll, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\i6SpeedCheckv60.dll, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\i6SpeedCheckv60.exe, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\SpeedCheck.exe, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\sqlite3.dll, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\Uninstall.exe, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\x64\TandemRunner.exe, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\x64\WdfCoInstaller01009.dll, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\x64\webinstr.inf, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
PUP.Optional.SpeedCheck.A, C:\Program Files (x86)\ver2SpeedCheck\x64\webinstrNewH.sys, In Quarantäne, [fb9f2d3b3d3fd561ffab49077192768a],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=53b6dde09e4b3746a1b75d96580b9803
# engine=21746
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-12-29 07:47:56
# local_time=2014-12-29 08:47:56 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='McAfee Anti-Virus and Anti-Spyware'
# compatibility_mode=5129 16777214 100 97 7390 106268692 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 14459442 24699244 0 0
# scanned=51859
# found=21
# cleaned=0
# scan_time=991
sh=9A29621DAC829144D9648B534CB5A0B24C21AA76 ft=1 fh=e533b0cb5e03e94e vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_40\gamesdesktop_widget.exe.vir"
sh=84FF48621208C926E8FCC3DAD23B33A0504CEE6B ft=1 fh=f88e52f2d1553095 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_de_40\gmsd_de_40.exe.vir"
sh=ABC74FC0E2C9926AD2BDC8F253CF9BFE7634337B ft=1 fh=a5b228525a72745c vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\257662b9-45e5-45c1-8746-c22cab96b03f-2.exe.vir"
sh=F4306F0DC8F0A9E285BC578A3EA676AC8078A74A ft=1 fh=f8b6630c8b034593 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\257662b9-45e5-45c1-8746-c22cab96b03f-5.exe.vir"
sh=CF4EDC859CF53ACCFC041DA2DCE75DF7AB50D05C ft=1 fh=f06d588d78b33649 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\HQPro-Video 1.6V25.12-bg.exe.vir"
sh=E5BE30FCE1C7A142E43D1375DF72E1982B950C42 ft=1 fh=c99e79ec5ad960f2 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\HQPro-Video 1.6V25.12-bho.dll.vir"
sh=95AC3217D56009671F3FA61B4C93C0E84E5DEB1B ft=1 fh=b021642527a208c4 vn="Variante von Win64/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\HQPro-Video 1.6V25.12-bho64.dll.vir"
sh=6D4C083F1DF2CE16E4E9C1284BD9F6F0AF693244 ft=1 fh=827a0e2471614d2a vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\HQPro-Video 1.6V25.12-codedownloader.exe.vir"
sh=094325942AE2CBCABE368B849E11218D9FF977A0 ft=1 fh=d5057df6fe52dba6 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\Uninstall.exe.vir"
sh=08DBD4916BC490C40D8F195C465EA7689EE1F423 ft=1 fh=b68e2a02e9333dfb vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQPro-Video 1.6V25.12\utils.exe.vir"
sh=FC3A455F0FB2672BC95CB6935C777FC86FD76978 ft=1 fh=0b3b4934b4c0b40c vn="Variante von Win32/Verti.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir"
sh=1AB0980D6216415031DFBDF8E56ECD479BE5F777 ft=1 fh=05efd1e59785f63e vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Super Optimizer\SuperOptimizer.exe.vir"
sh=10F18DE8B9AD7C7AC9EA32E9827044DEF0B28ECA ft=1 fh=5a1ff9e78156c197 vn="Variante von Win32/Adware.SpeedingUpMyPC.C Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Super Optimizer\SupOptSmartScan.exe.vir"
sh=C115266B0C7A676829C24F39D20F318DEF49CB0B ft=1 fh=2ebe1483bccc99eb vn="Variante von Win32/Adware.MultiPlug.DX Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Super Optimizer\SupOptStats.dll.vir"
sh=EDB6E1477166B32FE95301005E15A4EEB8BCF137 ft=1 fh=d29cf5027c7fc6c4 vn="Variante von MSIL/Adware.PullUpdate.H Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Browser\prompt.exe.vir"
sh=C7BE330F0743652C69C7A35BC02359864360B3D3 ft=1 fh=6c649a255e4ff0ed vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\clara\AppData\Local\gmsd_de_40\upgmsd_de_40.exe.vir"
sh=7CF39BFD4EF811C8A77D142D86D246E07A0D7EC9 ft=1 fh=a76414b4498f1245 vn="Variante von Win32/Agent.WGA Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\rcore.exe.vir"
sh=25BF1DFA50FFBDF257C329E552F1364AE03A1114 ft=1 fh=aab52fd58d33a0a0 vn="Variante von Win32/SpeedingUpMyPC Anwendung" ac=I fn="C:\Program Files (x86)\Optimizer Pro 3.16\OptimizerPro.exe"
sh=3A84B84CFE06C1B56EAF42D6496F6C47D08236BC ft=1 fh=2dd01d348029c59a vn="Variante von Win32/Adware.MultiPlug.DX Anwendung" ac=I fn="C:\Program Files (x86)\Optimizer Pro 3.16\OptProMon.dll"
sh=834026FD3DA8BE2ECFF157D6EAD5F8C19F7DAFFB ft=1 fh=12533f92b1b45599 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\ProgramData\cDQBHoBttZ\dat\OpRAuzI.dll"
sh=23D536B1E3332F2C8DB7A1B69E2E4C223556D074 ft=1 fh=8d7eda0b728f2714 vn="Variante von MSIL/Adware.PullUpdate.K.gen Anwendung" ac=I fn="C:\ProgramData\cDQBHoBttZ\dat\XbZVboCHK.dll"
ZOMBIE-INVASION ?!?? |