Bootluder | 11.04.2015 09:29 | Windows 7 "beschädigt" nach Bereinigung mit MWB Antimalware Hallo Leutz,
ich habe ein Problem auf dem Notebook eines Bekannten (Win7 HP). Ich sollte das Windows auf Schad- bzw. Nerv-Software überprüfen und das erste Tool meiner Wahl in so einem Fall ist immer Malwarebytes Antimalware - das hat, zumindest als Erst-Reinigungstool, immer gut funktioniert. Nun tauchte aber nach der Bereinigung zum ersten Mal ein Problem auf, das vor der Bereinigung nicht bestand: Der Aufgabenplanungsdienst wollte nicht mehr starten, was sich durch diverse Fehlermeldungen nach dem Neustart sofort bemerkbar machte.
Ich habe dann das Protokoll von Malwarebytes Antimalware durchgeschaut, konnte aber nichts Signifikantes entdecken. Erst nach dem Restore aller von Antimalware durchgeführten Änderungen startete der Aufgabenplanungsdienst wieder normal.
Nun steh ich etwas auf dem Schlauch - könnt ihr mir helfen?
Hier mal das Log von Antimalware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 11.04.2015
Scan Time: 09:29:22
Logfile: mwb.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.04.11.01
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: <Benutzer>
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 399257
Time Elapsed: 14 min, 5 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.exe, 3700, , [143972f9800abe78698b298d4db67f81]
Modules: 8
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMediaCrt.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, , [143972f9800abe78698b298d4db67f81],
Registry Keys: 37
PUP.Optional.Ask.A, HKLM\SOFTWARE\CLASSES\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, HKLM\SOFTWARE\CLASSES\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}\INPROCSERVER32, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.InboxToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, , [ff4e1754f6945fd7d19a6ccee91aa060],
PUP.Optional.InboxToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, , [60ed6209a3e730063740d89c28db28d8],
PUP.Optional.MyFreeCodec.A, HKLM\SOFTWARE\WOW6432NODE\Myfree Codec, , [f05d0f5c8406ed49eb1ac68e22e32ed2],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, , [c08dce9d9ceea393a3bbd13134d0fb05],
PUP.Optional.MyFreeCodec.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Myfree Codec, , [bf8e6cff3753c76f1ce8252fa95c728e],
PUP.Optional.Wajam.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WajIEnhance, , [79d41c4fcebc87af9353537bbe45e21e],
PUP.Optional.Wajam.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WIntEnhance, , [8cc12b407a10999d0f0f8a4054af9070],
PUP.Optional.FastStart.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, , [7ad31f4c682292a48ef9b22d946f8f71],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\webssearches uninstall, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.SecurityUtility.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ColorMedia, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, , [143972f9800abe78698b298d4db67f81],
Registry Values: 6
PUP.Optional.Ask.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{4F524A2D-5350-4500-76A7-7A786E7484D7}, 0, , [8ac375f6b2d852e4b42d2a0e63a0e719]
PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{4F524A2D-5350-4500-76A7-7A786E7484D7}, 0, , [8ac375f6b2d852e4b42d2a0e63a0e719]
PUP.Optional.Ask.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [4efff47738529e98845d38006f944fb1],
PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [301d02696d1db0861ec3eb4df80bfe02],
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\<Benutzer>\AppData\Roaming\Mozilla\Firefox\Profiles\1ocg63p2.default\extensions\faststartff@gmail.com, , [b09d016a593161d53872231f13f29967]
PUP.Optional.FastStart.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, , [7ad31f4c682292a48ef9b22d946f8f71]
Registry Data: 16
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (firefox.exe), Bad: ("C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[a2abc5a6f39785b1b2db8b6bef16f50b]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[f9545912503abb7ba7e78e68d82d936d]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[ca8316553a50f640eb9317dd26df8977]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[292475f6f39793a3fc8226ce09fc14ec]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[99b49fcc9bef2c0ac4ba05ef05002fd1]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[0845a2c9563448ee94eaa94bc24356aa]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[c9848be029616acc9f94b947ed19aa56]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (firefox.exe), Bad: ("C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[8bc23536ddadc76f3a53fbfbe124649c]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[7bd2b5b6aae041f5107e48ae39ccfb05]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[77d64f1c6c1e52e47b0341b30afb18e8]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[6be28be0e0aa51e5ee90b73df70e7888]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[cc81204b573387afb1cd1bd95ea723dd]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[7ad3a7c4206a989ed4aa05ef966ff010]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[68e568039cee4de9d36090707a8c2ad6]
PUP.Optional.WebsSearches, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[ca83c6a5573341f5c5baed0708fdff01]
PUP.Optional.WebsSearches, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[eb62bbb0d4b687af56293cb817ee0df3]
Folders: 4
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility, , [143972f9800abe78698b298d4db67f81],
Files: 57
PUP.Optional.Ask.A, C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.Ask.A, C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll, , [8ac375f6b2d852e4b42d2a0e63a0e719],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage, , [103dff6c34566cca62cadaf1e2213ec2],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage-journal, , [321bf2793357270f56d6edde4cb72fd1],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, , [73da94d71d6d54e25a32390f56afd62a],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, , [62eb98d31d6dc076305dc68232d359a7],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, , [252894d788022412a6e7fc4c94715ea2],
PUP.Optional.Winsock.Hijack, C:\Windows\SysWOW64\ColorMedia.dll, , [25282d3e305a8aac97a3302110f5de22],
PUP.Optional.Winsock.Hijack, C:\Windows\System32\ColorMedia64.dll, , [d37a12596b1f15218fac6ee3fb0a26da],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\458.json, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\MessageBox.xml, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\uninstallDlg2.xml, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\UninstallManager.exe, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\bg.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\bg1.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\bk_shadow.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\button.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\button1.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\checkbox.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\checkbox_select.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\checked.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\close.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\loading_bg.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\loading_light.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\min.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\scrollbar.bmp, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\Thumbs.db, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\unchecked.png, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code1.jpg, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code2.jpg, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code3.jpg, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code4.jpg, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code5.jpg, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code6.jpg, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\Thumbs.db, , [1637f477fd8d65d1aca8494448bb21df],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.exe, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.tlb, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia64.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMediaCrt.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssckbi.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssdbm3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RfndNSIS.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.exe, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.ini, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia64.exe, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\softokn3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\sqlite3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ssl3.dll, , [143972f9800abe78698b298d4db67f81],
PUP.Optional.QuickStart.A, C:\Users\<Benutzer>\AppData\Roaming\Mozilla\Firefox\Profiles\1ocg63p2.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), ,[f15cc4a796f47db97dab4ef0ef175ca4]
Physical Sectors: 0
(No malicious items detected)
(end) |