1. Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 20.11.17
Scan-Zeit: 23:38
Protokolldatei: 79eec3b0-ce43-11e7-be74-00262da52ded.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3306
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Kitty-PC\Kitty
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 321640
Erkannte Bedrohungen: 19
In die Quarantäne verschobene Bedrohungen: 19
Abgelaufene Zeit: 3 Min., 28 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 2
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [9158], [245665],1.0.3306
PUP.Optional.WebsSearches.ShrtCln, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [2777], [356193],1.0.3306
Registrierungswert: 4
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}|URL, In Quarantäne, [9158], [245665],1.0.3306
PUP.Optional.WebsSearches.ShrtCln, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DISPLAYNAME, In Quarantäne, [2777], [356193],1.0.3306
PUP.Optional.WebsSearches.ShrtCln, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, In Quarantäne, [2777], [356193],1.0.3306
PUP.Optional.FastStart, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|FASTSTARTFF@GMAIL.COM, In Quarantäne, [11709], [238268],1.0.3306
Registrierungsdaten: 8
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH PAGE, Ersetzt, [9158], [293089],1.0.3306
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH BAR, Ersetzt, [9158], [293089],1.0.3306
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [13741], [292819],1.0.3306
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, Ersetzt, [9158], [293091],1.0.3306
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|DEFAULT_SEARCH_URL, Ersetzt, [9158], [293090],1.0.3306
PUP.Optional.HelperBar, HKU\S-1-5-21-1366920193-2963973678-553920610-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SEARCHASSISTANT, Ersetzt, [9158], [293090],1.0.3306
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [13741], [292819],1.0.3306
PUP.Optional.HelperBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, Ersetzt, [9158], [293092],1.0.3306
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 5
PUP.Optional.WebsSearches, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\BROWSER\SEARCHPLUGINS\webssearches.xml, In Quarantäne, [12599], [185004],1.0.3306
PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\183529201.CFG, In Quarantäne, [1157], [345408],1.0.3306
PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DEFAULTS\PREF\183529201.JS, In Quarantäne, [1157], [330892],1.0.3306
PUP.Optional.SnapDo, C:\WINDOWS\INSTALLER\AF33B49.MSI, In Quarantäne, [6711], [77242],1.0.3306
PUP.Optional.Downloader, C:\USERS\KITTY\DOWNLOADS\IPHONE PC SUITE - CHIP-INSTALLER.EXE, In Quarantäne, [708], [5886],1.0.3306
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end)
2. Code:
19:58:51 # product=EOS
# version=8
# flags=0
# esetonlinescanner_deu(1).exe=2.0.19.0
# EOSSerial=ef6c62a06eb0174c956dcbccf8957033
# end=init
# utc_time=2017-11-21 18:58:51
# local_time=2017-11-21 19:58:51 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
19:58:58 # product=EOS
# version=8
# flags=0
# esetonlinescanner_deu(1).exe=2.0.19.0
# EOSSerial=ef6c62a06eb0174c956dcbccf8957033
# end=init
# utc_time=2017-11-21 18:58:57
# local_time=2017-11-21 19:58:57 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
19:59:17 Call m_esets_charon_setup_create
19:59:17 Call m_esets_charon_create
19:59:17 m_esets_charon_create OK
19:59:17 Call m_esets_charon_start_send_thread
19:59:17 Call m_esets_charon_setup_set
19:59:17 m_esets_charon_setup_set OK
19:59:17 Updating
19:59:17 Update Init
19:59:31 Call m_esets_charon_setup_create
19:59:31 Call m_esets_charon_create
19:59:31 m_esets_charon_setup_set ERROR
19:59:31 Update Download
20:00:07 esets_scanner_reload returned 0
20:00:07 g_uiModuleBuild: 35475
20:00:07 Update Finalize
20:00:07 Call m_esets_charon_send
20:00:07 Call m_esets_charon_destroy
20:00:07 Updated modules version: 35475
20:00:21 Call m_esets_charon_setup_create
20:00:21 Call m_esets_charon_create
20:00:21 m_esets_charon_setup_set ERROR
20:00:21 Scanner engine: 35475
22:14:20 # product=EOS
# version=8
# flags=0
# esetonlinescanner_deu(1).exe=2.0.19.0
# EOSSerial=ef6c62a06eb0174c956dcbccf8957033
# engine=35475
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# sfx_checked=true
# utc_time=2017-11-21 21:14:19
# local_time=2017-11-21 22:14:19 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 117938088 262928709 0 0
# scanned=2
# found=9
# cleaned=0
# scan_time=8050
sh=949202BF44466CA0BDABEBD42CCD6B8294E14D78 ft=1 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kitty\Downloads\Battle Painters - CHIP-Installer.exe"
sh=CFEB770DB59DD441C699C678C0F841AAD80C7F90 ft=1 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kitty\Downloads\Elcomsoft Phone Breaker - CHIP-Installer.exe"
sh=21D980DE2113056DA554C2EEAAD6656D15E82D35 ft=1 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kitty\Downloads\iPhone Backup Extractor - CHIP-Installer.exe"
sh=DC144C1BA98FAB0FB5322827FC619F9C1433311B ft=1 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kitty\Downloads\PC Inspector File Recovery - CHIP-Installer.exe"
sh=416F855004A41E0C6943F60E34CD0212A7ABBC0D ft=1 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kitty\Downloads\PDF24 Creator - CHIP-Installer.exe"
sh=B158BEACEED50B6C62A4AA05C475A1D0BAD816ED ft=1 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Kitty\Downloads\VLC media player 64 Bit - CHIP-Installer.exe"
sh=44341AC3075A630346D44C97F22FE3B8DB90A2C8 ft=1 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.G eventuell unerwünschte Anwendung" ac=I fn="C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll"
sh=925A0BAB5160A2463684131985BF453F59282D4C ft=1 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.G eventuell unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSID6DA.tmp-\FiddlerCore.dll"
sh=C0F749DFE4A392E2F5AA7E0E4A192FBC23F395F2 ft=1 fh=0000000000000000 vn="Variante von MSIL/Toolbar.Linkury.AQ eventuell unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSID6DA.tmp-\sipb.dll"
22:16:55 Call m_esets_charon_send
22:16:55 Call m_esets_charon_destroy
3. Code:
Results of screen317's Security Check version 1.009
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Malwarebytes
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
Adobe Flash Player 27.0.0.187
Mozilla Thunderbird 17.0.2 Thunderbird out of Date! ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamtray.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |