HtHNightwolf | 26.05.2015 10:15 | OfficeScan: Log momentan nicht exportierbar.
ESET: LOg gelöscht, ich scanne gerade neu und reiche es ein, sobald es fertig ist.
MBAM am Tag 1 (Erster Scan nach Befall, 18.05.2015): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.05.2015
Suchlauf-Zeit: 09:27:21
Logdatei: maleware18.05.15.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.17.03
Rootkit Datenbank: v2015.05.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ts
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 623445
Verstrichene Zeit: 59 Min, 57 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 51
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{BB7256DD-EBA9-480B-8441-A00388C2BEC3}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0D7562AE-8EF6-416d-A838-AB665251703A}, In Quarantäne, [6255e5af49418bab9407f8606b98c53b],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kpionmjnkbpcdpcflammlgllecmejgjj, In Quarantäne, [288f544092f866d087a09459897a7b85],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{231047C5-F7E9-45BE-9EFD-6E9BB6D59A9F}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{82443621-A29A-473E-8335-F5C958A7A4CA}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{231047C5-F7E9-45BE-9EFD-6E9BB6D59A9F}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{82443621-A29A-473E-8335-F5C958A7A4CA}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{231047C5-F7E9-45BE-9EFD-6E9BB6D59A9F}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{82443621-A29A-473E-8335-F5C958A7A4CA}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\IEhelperActiveX.IEhelperLabel.1, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\IEhelperActiveX.IEhelperLabel, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IEhelperActiveX.IEhelperLabel, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\IEhelperActiveX.IEhelperLabel, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IEhelperActiveX.IEhelperLabel.1, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\IEhelperActiveX.IEhelperLabel.1, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A1B48071-416D-474E-A13B-BE5456E7FC31}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A1B48071-416D-474E-A13B-BE5456E7FC31}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\MyNewsBar.IE5Bar.1, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\MyNewsBar.IE5Bar, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\MyNewsBar.IE5Bar, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\MyNewsBar.IE5Bar, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\MyNewsBar.IE5Bar.1, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\MyNewsBar.IE5Bar.1, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C876A2AD-D4BA-11D3-9D38-D0D087C500CC}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C876A2AD-D4BA-11D3-9D38-D0D087C500CC}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C876A2AD-D4BA-11D3-9D38-D0D087C500CC}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\vShare.tv plugin, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
Registrierungswerte: 4
Trojan.FakeAV, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|standard-contact, C:\Users\ts2\AppData\Local\Standard-juice\standard-age.exe, In Quarantäne, [6e49b2e27e0c9c9ad27a0f4852b043bd]
Trojan.FakeAV, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|standard-contact, C:\Users\ts2\AppData\Local\Standard-juice\standard-age.exe, In Quarantäne, [6e49b2e27e0c9c9ad27a0f4852b043bd]
PUP.Optional.BarLchr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, VShareTB, In Quarantäne, [f4c32272b0daed49681f00528380669a]
PUP.Optional.VShareRedir, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}, In Quarantäne, [8037593b5d2dec4acaa17def42c116ea],
Registrierungsdaten: 1
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://start.facemoods.com/?a=cpx&s={searchTerms}&f=4, Gut: (www.google.com), Schlecht: (hxxp://start.facemoods.com/?a=cpx&s={searchTerms}&f=4),Ersetzt,[a017afe5800a0c2a91526db2ae586997]
Ordner: 3
PUP.Optional.vShare.A, C:\Users\ts2\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj, In Quarantäne, [6a4dc6cee0aaf244507ae1e515ee45bb],
PUP.Optional.vShare.A, C:\Users\ts2\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0, In Quarantäne, [6a4dc6cee0aaf244507ae1e515ee45bb],
PUP.Optional.vShare.A, C:\Program Files (x86)\vShare.tv plugin, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
Dateien: 13
Trojan.FakeAV, C:\Users\ts2\AppData\Local\Standard-juice\standard-age.exe, Löschen bei Neustart, [6e49b2e27e0c9c9ad27a0f4852b043bd],
PUP.Optional.BarLchr.A, C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll, In Quarantäne, [f4c32272b0daed49681f00528380669a],
PUP.Optional.StartSear.A, C:\Users\ts2\AppData\Roaming\Mozilla\Firefox\Profiles\ksumi1tn.default\searchplugins\startsear.xml, In Quarantäne, [5c5bfb990e7c11251bfa02f735ce32ce],
PUP.Optional.FaceMoods.A, C:\Users\ts2\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ihflimipbcaljfnojhhknppphnnciiif_0.localstorage, In Quarantäne, [3a7d197b2862c274818aff19ad57bc44],
PUP.Optional.vShare.A, C:\Users\ts2\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll, In Quarantäne, [6a4dc6cee0aaf244507ae1e515ee45bb],
PUP.Optional.vShare.A, C:\Users\ts2\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\manifest.json, In Quarantäne, [6a4dc6cee0aaf244507ae1e515ee45bb],
PUP.Optional.vShare.A, C:\Program Files (x86)\vShare.tv plugin\IEhelperActiveX.dll, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, C:\Program Files (x86)\vShare.tv plugin\MyNewsBar.dll, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, C:\Program Files (x86)\vShare.tv plugin\uninst.exe, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.vShare.A, C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx, In Quarantäne, [3f78563eafdb6dc90bda9a2c7093dd23],
PUP.Optional.FaceMoods.A, C:\Users\ts2\AppData\Roaming\Mozilla\Firefox\Profiles\ksumi1tn.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.aflt", "_#cpx");), Ersetzt,[e5d21084f2980432213f75ebef17fa06]
PUP.Optional.FaceMoods.A, C:\Users\ts2\AppData\Roaming\Mozilla\Firefox\Profiles\ksumi1tn.default\prefs.js, Gut: (), Schlecht: (erences
/* Do not edit this file.
*
* If yo), Ersetzt,[922540547d0dc076f070fe623dc95ba5]
PUP.Optional.FaceMoods.A, C:\Users\ts2\AppData\Roaming\Mozilla\Firefox\Profiles\ksumi1tn.default\prefs.js, Gut: (), Schlecht: (ences
/* Do not edit this file.
*
* If you), Ersetzt,[b3043262ff8bcb6b4a161b45d630b050]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
MBAM am Freitag (22.05.2015): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.05.2015
Suchlauf-Zeit: 09:00:25
Logdatei: maleware22.05.15.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.21.04
Rootkit Datenbank: v2015.05.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ts
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 624721
Verstrichene Zeit: 1 Std, 12 Min, 44 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 4
Trojan.Dropper.FAVGen, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|bench-pain, C:\Users\ts2\AppData\Local\Bench-closet\bench-introduce.exe, In Quarantäne, [67e1d1c5d3b7fb3b193181dd0af8718f]
Trojan.Dropper.FAVGen, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|bench-pain, C:\Users\ts2\AppData\Local\Bench-closet\bench-introduce.exe, In Quarantäne, [67e1d1c5d3b7fb3b193181dd0af8718f]
Trojan.Dropper.FAVGen, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|standard-contact, C:\Users\ts2\AppData\Roaming\Standard-fly\standardauthor.exe, In Quarantäne, [33159bfb701a1224e7a0f46a738fa060]
Trojan.Dropper.FAVGen, HKU\S-1-5-21-2516187649-2465164387-518761543-1193\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|standard-contact, C:\Users\ts2\AppData\Roaming\Standard-fly\standardauthor.exe, In Quarantäne, [33159bfb701a1224e7a0f46a738fa060]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 2
Trojan.Dropper.FAVGen, C:\Users\ts2\AppData\Local\Bench-closet\bench-introduce.exe, In Quarantäne, [67e1d1c5d3b7fb3b193181dd0af8718f],
Trojan.Dropper.FAVGen, C:\Users\ts2\AppData\Roaming\Standard-fly\standardauthor.exe, In Quarantäne, [33159bfb701a1224e7a0f46a738fa060],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) MBAM heute ist sauber, das Log erspare ich uns.
Rkill findet täglich: Code:
Rkill 2.7.0 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
hxxp://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 05/26/2015 08:53:29 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\SysWOW64\HsMgr.exe (PID: 3052) [WD-HEUR]
* C:\Windows\system\HsMgr64.exe (PID: 384) [WD-HEUR]
* C:\Windows\SysWOW64\32ELOZIP.EXE (PID: 4664) [WD-HEUR]
3 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* Windows-Firewall (MpsSvc) is not Running.
Startup Type set to: Disabled
* Windows-Firewallautorisierungstreiber (mpsdrv) is not Running.
Startup Type set to: Manual
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* No issues found.
Program finished at: 05/26/2015 08:58:45 AM
Execution time: 0 hours(s), 5 minute(s), and 16 seconds(s) |