![]() |
"websearches" und andere Schädlinge (Logfile) Hi, ich nutze dieses Forum gerade zum ersten Mal.. Ich habe meinen neuen Laptop noch nicht lang, jedoch nach dem Download handelsüblicher Software von eigentlich seriösen Seiten (dachte ich) haben mir einige Überraschungen beschert und ich bin schockiert, wieviele Funde Malwarebytes mir anzeigt. "Websearches" hab ich schon als solches erkannt und konnte es auch nicht in der Systemsteuerung löschen, jedoch bin ich wirklich überfragt, was ich damit jetzt anfange. Kann mir jemand helfen, wie ich weiter vorgehen soll? Lieben Dank. Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 26.01.2015 Scan Time: 19:36:52 Logfile: Administrator: Yes Version: 2.00.4.1028 Malware Database: v2015.01.26.07 Rootkit Database: v2015.01.14.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8.1 CPU: x64 File System: NTFS User: Janina Scan Type: Threat Scan Result: Completed Objects Scanned: 327950 Time Elapsed: 11 min, 26 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 1 PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, 1740, , [e81726d59dec64d2fde85cabc04220e0] Modules: 2 PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, , [bd427586a3e6c076f553cfad9b68bb45], Registry Keys: 17 PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, , [e81726d59dec64d2fde85cabc04220e0], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKU\S-1-5-21-2879392512-1592893863-600582413-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.SupTab.A, HKU\S-1-5-21-2879392512-1592893863-600582413-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [33cc966560294beb924d8260d0340bf5], PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, , [c13e7a81a5e449edae990676010250b0], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [e51a6d8e0a7f1620181817e0e81c1fe1], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, , [bd42c83348413ef842b55b5959aa07f9], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [e21d36c50089ab8ba33c0ed427dd5ea2], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [8778a15a6e1b191de14142503dc6847c], PUP.Optional.Qone8, HKU\S-1-5-21-2879392512-1592893863-600582413-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [42bd27d415748caaf3ebb52d59ab6c94], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\webssearches uninstall, , [c837fa01692084b263685becac571de3], Registry Values: 1 PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cvs, , [8778a15a6e1b191de14142503dc6847c] Registry Data: 14 PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[827d2ccfaddc1e18153f019b8a7b1be5] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}),,[44bb30cbddac48ee1443d6c620e5be42] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[7d82c833fd8cce682c2a910ba560f50b] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[09f60eed3356e74f2632504cad58f10f] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}),,[df20be3da5e40e2816ba8f0a01049d63] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[8c739f5c96f31d19f0640d8f9075857b] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}),,[44bbf803e8a18bab0156a7f5bb4a57a9] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[4cb3c8333a4f44f291c50993f4112bd5] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[f9069a613f4a270f03559dffb1544db3] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1421841988&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}),,[09f6e01b6e1b2511daf6c1d89a6b59a7] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[dc231ddedcad06301d18e8beef167a86] PUP.Optional.WebsSearches, HKU\S-1-5-21-2879392512-1592893863-600582413-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=dspp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=dspp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}),,[41be09f2cebbf73f9938abeec63f53ad] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2879392512-1592893863-600582413-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hppp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT),,[55aa708b4e3b023410e3901663a2ae52] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2879392512-1592893863-600582413-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=dspp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=dspp&ts=1421842025&from=cvs&uid=TOSHIBAXMQ01ABF050_84B6P3BXTXX84B6P3BXT&q={searchTerms}),,[f20d8b70107946f0a42ecacf28dd43bd] Folders: 34 PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\log, , [c837fa01692084b263685becac571de3], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [55aaf00b4d3ccf67e3295108778c9f61], PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, , [b44bed0e2b5ebb7b294061152ad9e21e], PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, , [b44bed0e2b5ebb7b294061152ad9e21e], Files: 108 PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, , [e81726d59dec64d2fde85cabc04220e0], PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, , [52ad1ae1820721155efa37c12dd5738d], PUP.Optional.WindowsProtectManger.A, C:\Users\Janina\AppData\Local\Temp\~dl4DAE\~dljyb\tmp\wpm_v20.0.0.1714.exe, , [45ba609bd0b98bab437a5b0b13ed1ee2], PUP.Optional.XTab.A, C:\Users\Janina\AppData\Local\Temp\~dl4DAE\~dljyb\tmp\XTab_v4.0.exe, , [3ec13dbe8900c76ff3f2c74062a0d729], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowserAction.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\HPNotify.exe, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\install.data, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\searchProvider.xml, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\arrow.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo_hover.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_logo.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo2.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather\0.png, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ie8.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, , [bd427586a3e6c076f553cfad9b68bb45], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\363.json, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\MessageBox.xml, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\uninstallDlg2.xml, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\UninstallManager.exe, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\bg.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\bg1.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\bk_shadow.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\button.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\button1.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\checkbox.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\checkbox_select.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\checked.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\close.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\loading_bg.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\loading_light.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\min.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\scrollbar.bmp, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\Thumbs.db, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\unchecked.png, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\code1.jpg, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\code2.jpg, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\code3.jpg, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\code4.jpg, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\code5.jpg, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\code6.jpg, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\images\code\Thumbs.db, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\log\UninstallManager_2015-01-21[13-08-48-820].log, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\log\UninstallManager_2015-01-21[13-09-15-063].log, , [c837fa01692084b263685becac571de3], PUP.Optional.WebsSearches.A, C:\Users\Janina\AppData\Roaming\webssearches\log\UninstallManager_2015-01-21[13-09-24-383].log, , [c837fa01692084b263685becac571de3], PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, , [b44bed0e2b5ebb7b294061152ad9e21e], Physical Sectors: 0 (No malicious items detected) (end) |
Hi, ich habe dein Thema in Arbeit und melde mich gleich bei dir Bitte alle Tools als Administrator ausführen... Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
alles klar, der scan ist durch und die FRST.txt lautet: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 |
und Addition.txt:FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01 |
Hi, dann fangen wir mal mit deinstallieren von Programmen an... Schritt 1: Lade Dir bitte von hier ![]()
Schritt 2: Adware bereinigen Downloade Dir bitte ![]()
Schritt 3: Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 4: erstelle ein neues FRST Logfile und poste es hier |
JRT.txt: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 8.1 x64 Ran by Janina on 26.01.2015 at 21:22:03,91 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 26.01.2015 at 21:25:22,98 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 --- --- --- |
das Adwcleaner Logfile fehlt mir noch |
sorry, das ist wohl untergegangen. hier nun also:AdwCleaner Logfile: Code: # AdwCleaner v4.109 - Bericht erstellt am 26/01/2015 um 21:10:05 |
Hi, sry dass ich erst heute zum Antworten komme ... Schritt 1: Lade dir ![]()
Schritt 2: Downloade Dir bitte ![]()
Schritt 3: ESET Online Scanner
Schritt 4: Erstelle ein neues FRST Logfile und poste es hier |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:06 Uhr. |
Copyright ©2000-2025, Trojaner-Board