Valentin_S | 03.09.2019 17:26 | Malware bytes Code:
# -------------------------------
# Malwarebytes AdwCleaner 7.4.0.0
# -------------------------------
# Build: 07-23-2019
# Database: 2019-07-22.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-03-2019
# Duration: 00:00:01
# OS: Windows 10 Pro
# Cleaned: 1
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
No malicious registry entries cleaned.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Prefetch
[+] Delete Tracing Keys
[+] Reset Chromium Policies
[+] Reset IE Policies
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [15643 octets] - [03/09/2019 15:00:13]
AdwCleaner[S01].txt - [6754 octets] - [03/09/2019 15:45:06]
AdwCleaner[C01].txt - [6021 octets] - [03/09/2019 15:45:38]
AdwCleaner[S02].txt - [1848 octets] - [03/09/2019 15:49:42]
AdwCleaner[C02].txt - [2053 octets] - [03/09/2019 15:50:07]
AdwCleaner[S03].txt - [1970 octets] - [03/09/2019 15:51:35]
AdwCleaner[S04].txt - [2136 octets] - [03/09/2019 15:54:04]
AdwCleaner[C04].txt - [2283 octets] - [03/09/2019 15:54:39]
AdwCleaner[S05].txt - [2153 octets] - [03/09/2019 15:56:21]
AdwCleaner[S06].txt - [2030 octets] - [03/09/2019 16:00:08]
AdwCleaner[S07].txt - [2048 octets] - [03/09/2019 16:01:31]
AdwCleaner[C07].txt - [2249 octets] - [03/09/2019 16:01:54]
AdwCleaner[S08].txt - [2170 octets] - [03/09/2019 16:05:25]
AdwCleaner[C08].txt - [2371 octets] - [03/09/2019 16:05:53]
AdwCleaner[S09].txt - [2253 octets] - [03/09/2019 16:26:21]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C09].txt ########## Code:
16:29:57 # product=EOS
# version=8
# ESETOnlineScanner_DEU.exe=3.1.10.0
# country="Germany"
# lang=1031
16:30:52 Updating
16:30:52 Update Init
16:30:54 Update Download
16:31:45 esets_scanner_reload returned 0
16:31:45 g_uiModuleBuild: 42642
16:31:45 Update Finalize
16:31:45 Call m_esets_charon_send
16:31:45 Call m_esets_charon_destroy
16:31:45 Updated modules version: 42642
16:31:54 Call m_esets_charon_setup_create
16:31:54 Call m_esets_charon_create
16:31:54 m_esets_charon_create OK
16:31:54 Call m_esets_charon_start_send_thread
16:31:54 Call m_esets_charon_setup_set
16:31:54 m_esets_charon_setup_set OK
16:31:54 Scanner engine: 42642
18:16:03 # product=EOS
# version=8
# flags=0
# av=0
# fw=7
# admin=1
# ESETOnlineScanner_DEU.exe=3.1.10.0
# EOSSerial=ecf30ebd6f21eb43bdd8801d47f8bbb7
# engine=42642
# end=finished
# bannerClicked=1
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# sfx_checked=true
# utc_time=2019-09-03 16:16:03
# local_time=2019-09-03 18:16:03 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=10.0.18362 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 88 7155 14560326 0 0
# scanned=906164
# found=4
# cleaned=4
# scan_time=6192
# scan_type=2
# flow=2019-09-03 16:30:00|scr|eula|2019-09-03 16:30:01|promo|eis|2019-09-03 16:30:03|scr|welcome|2019-09-03 16:30:10|scr|consents|2019-09-03 16:30:33|scr|scan_type|2019-09-03 16:30:37|scr|pua|2019-09-03 16:30:52|scr|updating|2019-09-03 16:31:45|scr|scanning|2019-09-03 18:08:22|click|3|2019-09-03 18:14:58|scr|all_cleaned|2019-09-03 18:15:45|scr|periodic_offer|2019-09-03 18:15:55|scr|upsell|2019-09-03 18:16:01|scr|thanks
# periodic=0,0
# stats_enabled=1
sh=6938EDD54D99A2C99A2B498BB9DD10B99C98FEB4 ft=1 fh=000000000014a610 vn="Variante von Win32/DownloadSponsor.C potenziell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\$Recycle.Bin\S-1-5-21-2497879537-3860396562-624288794-1000\$REUKGWX.exe"
sh=9E4355D5DB680A1FABCC70EFC5307BEFAD3AD60C ft=1 fh=000000000000b448 vn="Variante von Win64/Adware.Bandoo.A Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\AdwCleaner\Quarantine\v1\20190903.150216\5\Movies App\Datamngr\x64\setmgrc3.cfg#C79DB00F17D3FA6A"
sh=E1609323C34E2C9CA58F9205F5E989B61768F3E0 ft=0 fh=00000000000002d9 vn="JS/Toolbar.Crossrider.AK potenziell unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Program Files (x86)\Cinema_Plus-6.1cV12.08\bgNova.html"
sh=D0D2DF4D1A2B476CA821DA92989A0FDA93E4580E ft=1 fh=0000000000016d98 vn="Variante von Win32/Bundled.Toolbar.Ask.M potenziell unsichere Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Windows\Installer\MSIE9AB.tmp"
18:16:04 Call m_esets_charon_send
18:16:04 Call m_esets_charon_destroy Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 03.09.19
Scan-Zeit: 18:17
Protokolldatei: 569349a2-ce66-11e9-ac8b-4ccc6a0317cc.json
-Softwaredaten-
Version: 3.8.3.2965
Komponentenversion: 1.0.613
Version des Aktualisierungspakets: 1.0.12309
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 18362.329)
CPU: x64
Dateisystem: NTFS
Benutzer: GAMING-PC\Valentin
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 466015
Erkannte Bedrohungen: 33
In die Quarantäne verschobene Bedrohungen: 33
Abgelaufene Zeit: 2 Min., 48 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{256BB536-1859-40A4-8CBE-130A53214205}, In Quarantäne, [3], [253595],1.0.12309
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B641032-F8B7-44C0-AE73-F022D1250357}, In Quarantäne, [3], [253595],1.0.12309
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C5C34589-78B7-4C4C-B027-C1503302FDB8}, In Quarantäne, [3], [253595],1.0.12309
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\${dtUserElevationPolicyID}, In Quarantäne, [55], [253616],1.0.12309
Registrierungswert: 6
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{256BB536-1859-40A4-8CBE-130A53214205}|APPPATH, In Quarantäne, [3], [253595],1.0.12309
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [3], [-1],0.0.0
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, [3], [-1],0.0.0
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B641032-F8B7-44C0-AE73-F022D1250357}|APPPATH, In Quarantäne, [3], [253595],1.0.12309
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C5C34589-78B7-4C4C-B027-C1503302FDB8}|APPPATH, In Quarantäne, [3], [253595],1.0.12309
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{99079a25-328f-4bd4-be04-00955acaa0a7}, In Quarantäne, [1589], [161090],1.0.12309
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 7
PUP.Optional.SuperOptimizer, C:\PROGRAMDATA\{2f19c514-e57f-41bc-2f19-9c514e571453}, In Quarantäne, [1569], [243661],1.0.12309
PUP.Optional.CinemaPlus, C:\PROGRAM FILES (X86)\Cinema_Plus-6.1cV12.08, In Quarantäne, [1914], [176049],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\USERS\FRANK\APPDATA\LOCAL\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.OneSoftPerDay, C:\Users\Frank\AppData\Local\ospd_us_013010058\ospd_us_013010058\1.10, In Quarantäne, [2644], [178759],1.0.12309
PUP.Optional.OneSoftPerDay, C:\Users\Frank\AppData\Local\ospd_us_013010058\ospd_us_013010058, In Quarantäne, [2644], [178759],1.0.12309
PUP.Optional.OneSoftPerDay, C:\USERS\FRANK\APPDATA\LOCAL\ospd_us_013010058, In Quarantäne, [2644], [178759],1.0.12309
PUP.Optional.DataMngr.AppFlsh, C:\USERS\FRANK\APPDATA\LOCALLOW\DATAMNGR, In Quarantäne, [55], [181454],1.0.12309
Datei: 16
PUP.Optional.SuperOptimizer, C:\PROGRAMDATA\{2f19c514-e57f-41bc-2f19-9c514e571453}\hqghumeaylnlf.dat, In Quarantäne, [1569], [243661],1.0.12309
PUP.Optional.SuperOptimizer, C:\ProgramData\{2f19c514-e57f-41bc-2f19-9c514e571453}\d1c0a83f5c0c05c6, In Quarantäne, [1569], [243661],1.0.12309
PUP.Optional.SuperOptimizer, C:\ProgramData\{2f19c514-e57f-41bc-2f19-9c514e571453}\d1c0a83f5c0c05c6.lock, In Quarantäne, [1569], [243661],1.0.12309
PUP.Optional.SuperOptimizer, C:\ProgramData\{2f19c514-e57f-41bc-2f19-9c514e571453}\e6607ec6a57c0e96, In Quarantäne, [1569], [243661],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\USERS\FRANK\APPDATA\LOCAL\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\fami, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\Users\Frank\AppData\Local\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\config.dat, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\Users\Frank\AppData\Local\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\info.dat, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\Users\Frank\AppData\Local\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\install.log, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\Users\Frank\AppData\Local\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\STTL.DAT, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\Users\Frank\AppData\Local\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\TTL.DAT, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.WinYahoo.TskLnk, C:\Users\Frank\AppData\Local\{C3CAF596-E762-992E-8AFA-BCC6AE92405E}\uninst.dat, In Quarantäne, [806], [484244],1.0.12309
PUP.Optional.OneSoftPerDay, C:\Users\Frank\AppData\Local\ospd_us_013010058\ospd_us_013010058\1.10\cnf.cyl, In Quarantäne, [2644], [178759],1.0.12309
PUP.Optional.OneSoftPerDay, C:\Users\Frank\AppData\Local\ospd_us_013010058\upospd_us_013010058.cyl, In Quarantäne, [2644], [178759],1.0.12309
PUP.Optional.OneSoftPerDay, C:\Users\Frank\AppData\Local\ospd_us_013010058\user_profil.cyp, In Quarantäne, [2644], [178759],1.0.12309
PUP.Optional.DataMngr.AppFlsh, C:\Users\Frank\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}, In Quarantäne, [55], [181454],1.0.12309
PUP.Optional.Cassiopesa, C:\USERS\FRANK\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\SECURE PREFERENCES, Ersetzt, [283], [302990],1.0.12309
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) |