LeMatjoe | 31.08.2015 18:44 | 1. mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 31.08.2015
Suchlaufzeit: 18:47
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.31.02
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Matze
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 454672
Abgelaufene Zeit: 24 Min., 10 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 13
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.exe, 2744, Löschen bei Neustart, [e876cb441576e6503361870cca3b60a0]
PUP.Optional.StrongSignal.SID, C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe, 2904, Löschen bei Neustart, [2a34a867513a6fc74252bdd60bfa5ba5]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\4\Plugin.exe, 7708, Löschen bei Neustart, [a1bd12fde5a6191db7dd058ea5606a96]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7\Plugin.exe, 7716, Löschen bei Neustart, [4c1247c8117ad462d8bc920114f1e41c]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7\Plugin.exe, 804, Löschen bei Neustart, [4c1247c8117ad462d8bc920114f1e41c]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\6\Plugin.exe, 7752, Löschen bei Neustart, [8dd19f7002894beb8b094b4808fd20e0]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\8\Plugin.exe, 7840, Löschen bei Neustart, [0a54de3186051d19deb663301ee7718f]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\2\Plugin.exe, 7852, Löschen bei Neustart, [b9a51af5048794a2ccc8c6cd39ccd42c]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3\Plugin.exe, 1736, Löschen bei Neustart, [eb7333dc315a39fd6e26bed57b8ab749]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3\Plugin.exe, 1292, Löschen bei Neustart, [eb7333dc315a39fd6e26bed57b8ab749]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12\Plugin.exe, 6000, Löschen bei Neustart, [e5797e9164272511caca4e4553b221df]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12\Plugin.exe, 6872, Löschen bei Neustart, [e5797e9164272511caca4e4553b221df]
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\5\Plugin.exe, 6416, Löschen bei Neustart, [9bc3ee219fecb58194005043c63f837d]
Module: 2
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{631966DF-0759-4807-B0D4-FB0E901A5172}.dll, Löschen bei Neustart, [6ef0de318506d95d761e03909c6912ee],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{631966DF-0759-4807-B0D4-FB0E901A5172}.dll, Löschen bei Neustart, [6ef0de318506d95d761e03909c6912ee],
Registrierungsschlüssel: 27
PUP.Optional.StrongSignal.SID, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr StrongSignal, In Quarantäne, [e876cb441576e6503361870cca3b60a0],
PUP.Optional.StrongSignal.SID, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr StrongSignal, In Quarantäne, [2a34a867513a6fc74252bdd60bfa5ba5],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{c723a437-2eaf-466d-a95b-3fa0966bf88c}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\CLASSES\TYPELIB\{e806ac01-e7a5-4949-af7c-7e6e5775035b}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\CLASSES\INTERFACE\{BA6EB888-8424-4C93-8E71-6050C714CFBE}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BA6EB888-8424-4C93-8E71-6050C714CFBE}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{BA6EB888-8424-4C93-8E71-6050C714CFBE}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{e806ac01-e7a5-4949-af7c-7e6e5775035b}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{e806ac01-e7a5-4949-af7c-7e6e5775035b}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C723A437-2EAF-466D-A95B-3FA0966BF88C}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C723A437-2EAF-466D-A95B-3FA0966BF88C}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C723A437-2EAF-466D-A95B-3FA0966BF88C}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.StrongSignal, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C723A437-2EAF-466D-A95B-3FA0966BF88C}, In Quarantäne, [a8b613fc503bae8812e0b12aec169c64],
PUP.Optional.BDYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [63fb7d92761502346ca73a4246be6e92],
PUP.Optional.PlusHD, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Plus-HD-2.2-chromeinstaller, Löschen bei Neustart, [4c12e8275e2da492f84ddccae51fbf41],
PUP.Optional.PlusHD, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Plus-HD-2.2-codedownloader, Löschen bei Neustart, [b6a8f9167912360049fc614516ee4db3],
PUP.Optional.PlusHD, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Plus-HD-2.2-enabler, Löschen bei Neustart, [99c528e70b8065d14afb7531e91bfd03],
PUP.Optional.PlusHD, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Plus-HD-2.2-firefoxinstaller, Löschen bei Neustart, [223c60afcdbe2b0baa9bacfadc2819e7],
PUP.Optional.PlusHD, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Plus-HD-2.2-updater, Löschen bei Neustart, [05596da291fa211572d3822433d19c64],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\nmhostct3317892, In Quarantäne, [fe60799622696ec8b58b879935ceed13],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51016081-ACD8-424E-B1BF-B46BB804DD18}, In Quarantäne, [c49a57b82566ee48623eb9cf877db749],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5685A025-FC81-4F3C-8364-A1F6E74991B8}, In Quarantäne, [72ec020da9e259dd970afb8d15ef8d73],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A27E18A-FA10-43A4-8CA4-7BD4457A5210}, In Quarantäne, [d38b9d72c2c9de58f5ad394f4db72fd1],
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\nmhostct3317892, In Quarantäne, [f06e64ab95f6a98de7548c94a261c838],
PUP.Optional.BDYahoo, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [322cf41b7417a591f919fc80ad5756aa],
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CHCT3317892, In Quarantäne, [500e2ce3bccff244f250204fb450da26],
PUP.Optional.ProductSetup, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\PRODUCTSETUP, In Quarantäne, [b9a5818e3259b284fc125a4ebe4620e0],
Registrierungswerte: 9
PUP.Optional.BDYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bir-is__alt__ddc_dss_bd_com&p={searchTerms}, In Quarantäne, [63fb7d92761502346ca73a4246be6e92]
PUP.Optional.Binkiland, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Binkiland\\, In Quarantäne, [f7676ba41e6dbb7bb839116b60a444bc]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51016081-acd8-424e-b1bf-b46bb804dd18}|AppName, Plus-HD-2.2-bg.exe, In Quarantäne, [c49a57b82566ee48623eb9cf877db749]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5685a025-fc81-4f3c-8364-a1f6e74991b8}|AppName, Plus-HD-2.2-buttonutil.exe, In Quarantäne, [72ec020da9e259dd970afb8d15ef8d73]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6a27e18a-fa10-43a4-8ca4-7bd4457a5210}|AppName, Plus-HD-2.2-codedownloader.exe, In Quarantäne, [d38b9d72c2c9de58f5ad394f4db72fd1]
PUP.Optional.PluginContainer, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr StrongSignal|ImagePath, "C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.exe", In Quarantäne, [fc6224eb1378b87efccc891c2ada7d83]
PUP.Optional.Updater, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr StrongSignal|ImagePath, "C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe", In Quarantäne, [6cf28887701bd561653ca71163a11ee2]
PUP.Optional.BDYahoo, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bir-is__alt__ddc_dss_bd_com&p={searchTerms}, In Quarantäne, [322cf41b7417a591f919fc80ad5756aa]
PUP.Optional.ProductSetup, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\PRODUCTSETUP|tb, 0Z1B1L2Z1S, In Quarantäne, [b9a5818e3259b284fc125a4ebe4620e0]
Registrierungsdaten: 2
PUP.Optional.BDYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-is__alt__ddc_dsssyc_bd_com, Gut: (www.google.com), Schlecht: (hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-is__alt__ddc_dsssyc_bd_com),Ersetzt,[e5791bf418737eb88a368bd225e0758b]
PUP.Optional.BDYahoo, HKU\S-1-5-21-2192875699-102566734-3842833272-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-is__alt__ddc_dsssyc_bd_com, Gut: (www.google.com), Schlecht: (hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-is__alt__ddc_dsssyc_bd_com),Ersetzt,[a3bb7996c6c5092d407e322b44c1b848]
Ordner: 28
PUP.Optional.CrossRider, C:\Users\Matze\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0, In Quarantäne, [7ce2759a1774280efa18eb14b54d5ea2],
PUP.Optional.CrossRider, C:\Users\Matze\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo, In Quarantäne, [5d01000faedd47efa229639f5ca7ee12],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugincontainer, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12\resources, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12bak\resources, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\2, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\2bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\4, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\4bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\5, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\5bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\6, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\6bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7bak\resources, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\8, Löschen bei Neustart, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\8bak, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce, Löschen bei Neustart, [1c42917e6c1f41f5fc8239e1649ffc04],
PUP.Optional.StrongSignal, C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater, In Quarantäne, [1c42917e6c1f41f5fc8239e1649ffc04],
PUP.Optional.StrongSignal, C:\Program Files (x86)\Strong Signal, In Quarantäne, [cb9364abb6d5b383a7d85dbd27dca45c],
PUP.Optional.StrongSignal, C:\Program Files (x86)\Strong Signal\Extensions, In Quarantäne, [cb9364abb6d5b383a7d85dbd27dca45c],
Dateien: 37
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.exe, Löschen bei Neustart, [e876cb441576e6503361870cca3b60a0],
PUP.Optional.StrongSignal.SID, C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe, Löschen bei Neustart, [2a34a867513a6fc74252bdd60bfa5ba5],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\4\Plugin.exe, Löschen bei Neustart, [a1bd12fde5a6191db7dd058ea5606a96],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7\Plugin.exe, Löschen bei Neustart, [4c1247c8117ad462d8bc920114f1e41c],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\6\Plugin.exe, Löschen bei Neustart, [8dd19f7002894beb8b094b4808fd20e0],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\8\Plugin.exe, Löschen bei Neustart, [0a54de3186051d19deb663301ee7718f],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\2\Plugin.exe, Löschen bei Neustart, [b9a51af5048794a2ccc8c6cd39ccd42c],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3\Plugin.exe, Löschen bei Neustart, [eb7333dc315a39fd6e26bed57b8ab749],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12\Plugin.exe, Löschen bei Neustart, [e5797e9164272511caca4e4553b221df],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\5\Plugin.exe, Löschen bei Neustart, [9bc3ee219fecb58194005043c63f837d],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{631966DF-0759-4807-B0D4-FB0E901A5172}.dll, Löschen bei Neustart, [6ef0de318506d95d761e03909c6912ee],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.bak, In Quarantäne, [c49a759a8efd61d5751f722175902ed2],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12\resources\plugin.dll, In Quarantäne, [81ddee21c9c285b1583c5e355da8fd03],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12bak\Plugin.exe, In Quarantäne, [fd61a26d7417de584054fb982cd96f91],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\12bak\resources\plugin.dll, In Quarantäne, [1b4362ad8efde056abe9a8eb7293d62a],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\2bak\Plugin.exe, In Quarantäne, [fe60c54ac7c47db963316c270cf95ba5],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3bak\Plugin.exe, In Quarantäne, [86d851bed1ba79bd7123682b8a7b37c9],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\4bak\Plugin.exe, In Quarantäne, [0d5161ae4645d95d355f494a759047b9],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\5bak\Plugin.exe, In Quarantäne, [b2acac639af1092d4252672c31d40df3],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\6bak\Plugin.exe, In Quarantäne, [5905f6199ceffb3bade77320b451eb15],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7bak\Plugin.exe, In Quarantäne, [302ea36ce6a5082e0f85c8cbb05546ba],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7bak\resources\38.0.5.dll, In Quarantäne, [f46a818eec9f43f3296b71226b9a12ee],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7bak\resources\39.0.0.dll, In Quarantäne, [3a2414fb810a7cba95ffafe40df801ff],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\7bak\resources\40.0.0.dll, In Quarantäne, [0d51b7580e7df93d7321bbd849bc16ea],
PUP.Optional.StrongSignal.SID, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\8bak\Plugin.exe, In Quarantäne, [1d41a9662a61c076ccc80c871de8c739],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{0767EB8F-6638-4A33-8284-81A4806A3E02}.dll, In Quarantäne, [76e86da2f398fc3a4b49840f7a8b45bb],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{9900CC63-4993-4022-9B2D-70BF547AA163}.dll, In Quarantäne, [3d21ae61d0bb31058d07642f4bbadb25],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{C50FBA65-6B8D-41CE-8F31-7D0EED1D3550}.dll, In Quarantäne, [63fbd63979128da9bdd75e35af567c84],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{EA5A3CA1-0792-4ED1-8A95-4FA304576EFC}.dll, In Quarantäne, [3c22769974170f27a4f02a6953b2bb45],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{F0327218-17C0-4C72-A915-F30B3D137C9D}.dll, In Quarantäne, [213da6696d1ea294088cd8bb7a8b59a7],
PUP.Optional.StrongSignal.SID, C:\Users\Matze\AppData\Local\Temp\{F451472C-8437-4802-BAE8-12728994EF3B}.dll, In Quarantäne, [e579bb5452392115761ec0d32bda9967],
PUP.Optional.Binkiland, C:\Users\Matze\AppData\LocalLow\Microsoft\Internet Explorer\Services\FavIcon.icoWSE_Binkiland, In Quarantäne, [67f7f817cbc04cea9f469ae27f859070],
PUP.Optional.VBates, C:\Windows\Tasks\VStart{A37B472A-8335-449F-9568-43ECC2907F06}.job, In Quarantäne, [0559a06f0982ee483cc2467240c4926e],
PUP.Optional.StrongSignal, C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\temp, In Quarantäne, [c39b7798157658decab381999b6847b9],
PUP.Optional.StrongSignal, C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.bak, In Quarantäne, [1c42917e6c1f41f5fc8239e1649ffc04],
PUP.Optional.StrongSignal, C:\Program Files (x86)\Strong Signal\Extensions\jbcofnecjbmbfebcimaigbbbaeppghip.crx, In Quarantäne, [cb9364abb6d5b383a7d85dbd27dca45c],
PUP.Optional.BDYahoo, C:\Users\Matze\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Gut: ("session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/restorebrowser/"]}}), Schlecht: ("session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":["https://www.google.de/"],"urls_to_restore_on_startup":["hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bcr-is__alt__ddc_dsssyc_bd_com"]},"software_reporter":{"prompt_reason":0,"prompt_version":"3.21.0"}}), Ersetzt,[bda18788216a5dd9a4c4990213f2b848]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) 2.AdwCleaner Code:
# AdwCleaner v5.004 - Bericht erstellt 31/08/2015 um 19:24:31
# Aktualisiert 26/08/2015 von Xplode
# Datenbank : 2015-08-30.1 [Server]
# Betriebssystem : Windows 10 Home (x64)
# Benutzername : Matze - MATZE-PC
# Gestarted von : C:\Users\Matze\Desktop\AdwCleaner_5.004.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
***** [ Dateien ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [Plus-HD-2.2-bg.exe]
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B853E835-9F24-4F4B-B55C-E554D15CCCD2}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E104B9E4-01BA-4AAF-9957-6A525CC5451A}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E104B9E4-01BA-4AAF-9957-6A525CC5451A}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\StrongSignal
***** [ Internetbrowser ] *****
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C12].txt - [1281 Bytes] ########## 3.JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.9 (08.27.2015:1)
OS: Windows 10 Home x64
Ran by Matze on 31.08.2015 at 19:32:45,47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\EgisUpdate
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update ResultsAlpha
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util ResultsAlpha
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{1182A412-A32A-4867-A1B3-A3FDD24D2588}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{2D5DDBA1-EC8F-4928-A46C-0055C6361271}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{370F8818-D5C4-41FA-9DDC-C5D6F9DAEB21}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{4D95428A-1C58-45FC-BE6E-0B6AAD76CFAF}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{71408567-1F8F-4089-89C7-C1A270CB2FDB}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{80715DBF-CC54-4293-918E-0F1230C92D91}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{988560B5-EC35-477D-A2C7-7B683F0935B1}
Successfully deleted: [Empty Folder] C:\Users\Matze\Appdata\Local\{AB7D5F6B-7E50-476D-AB39-6BE4F601128E}
Successfully deleted: [Folder] C:\Users\Matze\Documents\add-in express
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\ai_recyclebin
~~~ Chrome
[C:\Users\Matze\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Matze\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Matze\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Matze\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.08.2015 at 19:41:00,26
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |