Fumacilla | 24.01.2019 18:25 | Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 24.01.19
Scan-Zeit: 16:50
Protokolldatei: d41b2cf8-1fef-11e9-8f6d-d8fb5ee54fd2.json
-Softwaredaten-
Version: 3.6.1.2711
Komponentenversion: 1.0.527
Version des Aktualisierungspakets: 1.0.8950
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 15063.1387)
CPU: x64
Dateisystem: NTFS
Benutzer: PC_SADGOOFY\SadGoofy
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 348601
Erkannte Bedrohungen: 55
In die Quarantäne verschobene Bedrohungen: 55
Abgelaufene Zeit: 1 Min., 11 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 2
PUP.Optional.InterStat, HKU\S-1-5-21-3599508002-3039248163-508909186-1001_Classes\APPLICATIONS\interstat.exe, In Quarantäne, [1139], [261503],1.0.8950
PUP.Optional.UltimateShoppingSearch, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\eiibddcohpjhajbnfkpboacmohommppp, In Quarantäne, [390], [405203],1.0.8950
Registrierungswert: 3
PUP.Optional.Webbar, HKU\S-1-5-21-3599508002-3039248163-508909186-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|WINWB.EXE, In Quarantäne, [691], [613803],1.0.8950
PUP.Optional.UltimateShoppingSearch, HKU\S-1-5-21-3599508002-3039248163-508909186-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|EIIBDDCOHPJHAJBNFKPBOACMOHOMMPPP, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|@ULTIMATESHOPPINGSEARCH, In Quarantäne, [390], [379681],1.0.8950
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 18
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\bootstrap\css, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\bootstrap\js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\bootstrap, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\jquery, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_locales\de, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_locales\en, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_metadata, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_locales, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\content, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\popup, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\css, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\USERS\STEVEN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Extensions\EIIBDDCOHPJHAJBNFKPBOACMOHOMMPPP, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.GreatDealz, C:\Users\Steven\AppData\Roaming\Mozilla\Firefox\Profiles\x66rr2qa.default\jetpack\@greatdealz\simple-storage, In Quarantäne, [1968], [379670],1.0.8950
PUP.Optional.GreatDealz, C:\USERS\STEVEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X66RR2QA.DEFAULT\JETPACK\@GREATDEALZ, In Quarantäne, [1968], [379670],1.0.8950
Datei: 32
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\content\pxl2.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\css\main.css, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\128x128.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\16x16.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\48x48.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\96x96.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\icon.ico, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\icon128.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\icon16.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\icon32.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\icon48.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\icon64.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\search-icon-old.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\img\search-icon.png, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\bootstrap\css\bootstrap.min.css, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\bootstrap\js\bootstrap.min.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\jquery\jquery.min.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\lib\sdk-1.1.min.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\background.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\chnl.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\global.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\js\main.js, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\popup\popup.html, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_locales\de\messages.json, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_locales\en\messages.json, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\_metadata\verified_contents.json, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\background.html, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\manifest.json, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\Users\Steven\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiibddcohpjhajbnfkpboacmohommppp\1.2.1_0\tab.html, In Quarantäne, [390], [405203],1.0.8950
PUP.Optional.UltimateShoppingSearch, C:\USERS\STEVEN\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Ersetzt, [390], [405203],1.0.8950
PUP.Optional.GreatDealz, C:\Users\Steven\AppData\Roaming\Mozilla\Firefox\Profiles\x66rr2qa.default\jetpack\@greatdealz\simple-storage\store.json, In Quarantäne, [1968], [379670],1.0.8950
PUP.Optional.Conduit, C:\USERS\STEVEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X66RR2QA.DEFAULT\PREFS.JS, Ersetzt, [215], [301520],1.0.8950
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) Code:
16:57:15 # product=EOS
# version=8
# esetonlinescanner_deu.exe=3.0.17.0
# country="Germany"
# lang=1031
16:58:43 Updating
16:58:43 Update Init
16:58:44 Update Download
17:00:41 esets_scanner_reload returned 0
17:00:41 g_uiModuleBuild: 40163
17:00:41 Update Finalize
17:00:41 Call m_esets_charon_send
17:00:41 Call m_esets_charon_destroy
17:00:42 Updated modules version: 40163
17:00:50 Call m_esets_charon_setup_create
17:00:50 Call m_esets_charon_create
17:00:50 m_esets_charon_create OK
17:00:50 Call m_esets_charon_start_send_thread
17:00:50 Call m_esets_charon_setup_set
17:00:50 m_esets_charon_setup_set OK
17:00:51 Scanner engine: 40163
18:18:04 # product=EOS
# version=8
# flags=0
# av=0
# fw=7
# admin=1
# esetonlinescanner_deu.exe=3.0.17.0
# EOSSerial=28dac7c6e05e8a47acefdeb1877c5bcf
# engine=40163
# end=finished
# bannerClicked=0
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# sfx_checked=true
# utc_time=2019-01-24 17:18:04
# local_time=2019-01-24 18:18:04 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=10.0.15063 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 8873 58483280 0 0
# scanned=503027
# found=4
# cleaned=4
# scan_time=4545
# flow=2019-01-24 16:57:21|scr|eula|2019-01-24 16:57:23|scr|welcome|2019-01-24 16:57:24|promo|eis|2019-01-24 16:57:38|scr|consents|2019-01-24 16:57:53|scr|scan_type|2019-01-24 16:58:02|scr|pua|2019-01-24 16:58:43|scr|updating|2019-01-24 17:00:42|scr|scanning|2019-01-24 18:16:29|scr|all_cleaned|2019-01-24 18:17:13|click|save_report|2019-01-24 18:17:30|scr|periodic_offer|2019-01-24 18:17:43|scr|periodic_activated|2019-01-24 18:17:53|scr|upsell|2019-01-24 18:18:00|scr|thanks
# periodic=0,1
# stats_enabled=0
# scan_type=2
sh=3220FEAF23C1E282661B504D8320F29C51822720 ft=1 fh=0000000000023d50 vn="Variante von Win32/Techsnab.AR potenziell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\Quarantine\v1\20190118.133021\16\SoftUpgrade\softup.exe#7206CA1DDB7DB897"
sh=6E2C12E4BA78DC4E291BC3C5B2C7637ABA00501C ft=1 fh=000000000009f538 vn="Variante von Win32/Techsnab.AS potenziell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Steven\AppData\Local\Microsoft\Windows\INetCache\IE\LW8SK6DZ\scinst[1].exe"
sh=6E2C12E4BA78DC4E291BC3C5B2C7637ABA00501C ft=1 fh=000000000009f538 vn="Variante von Win32/Techsnab.AS potenziell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Steven\AppData\Roaming\ServiceControl\svcctl.exe"
sh=B3F52C95B87B58CA44827F6403A3998C914B5EB2 ft=1 fh=00000000001125d0 vn="Variante von Win32/DownloadAssistant.C potenziell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="E:\Wichtige Sachen\Programme\Audacity_Setup.exe"
18:18:05 Call m_esets_charon_send
18:18:05 Call m_esets_charon_destroy Code:
Results of screen317's Security Check version 1.009
x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Windows Defender
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Adobe Flash Player 32.0.0.114
Google Chrome (71.0.3578.98)
Google Chrome (SetupMetrics...) ````````Process Check: objlist.exe by Laurent````````
Windows Defender MSMpEng.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamtray.exe
Windows Defender MSASCuiL.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |