Alles so durchgeführt wie besprochen.
Scans haben noch einige PUP's gefunden....
Die Logdateien:
mbam Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 17.11.21
Scan-Zeit: 21:27
Protokolldatei: cabf4912-47e4-11ec-9355-5404a63f67ec.json
-Softwaredaten-
Version: 4.4.10.144
Komponentenversion: 1.0.1499
Version des Aktualisierungspakets: 1.0.47298
Lizenz: Kostenlos
-Systemdaten-
Betriebssystem: Windows 10 (Build 19041.1348)
CPU: x64
Dateisystem: NTFS
Benutzer: Silke*****-PC\Silke *****
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 327123
Erkannte Bedrohungen: 12
In die Quarantäne verschobene Bedrohungen: 12
Abgelaufene Zeit: 24 Min., 48 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.Conduit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, 186, 236865, , , , , ,
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, 186, 236865, , , , , ,
PUP.Optional.Conduit, HKU\S-1-5-21-1930512678-1335690401-17082022-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, 186, 236865, 1.0.47298, , ame, , ,
Registrierungswert: 2
PUP.Optional.Conduit, HKU\S-1-5-21-1930512678-1335690401-17082022-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, 186, 236865, 1.0.47298, , ame, , ,
PUP.Optional.Conduit, HKU\S-1-5-21-1930512678-1335690401-17082022-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURL, In Quarantäne, 186, 236865, 1.0.47298, , ame, , ,
Registrierungsdaten: 1
PUP.Optional.Conduit, HKU\S-1-5-21-1930512678-1335690401-17082022-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, 186, 293058, 1.0.47298, , ame, , ,
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 6
PUP.Optional.MyFireSearch, C:\USERS\SILKE *****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LX6SOG8Y.DEFAULT\SEARCHPLUGINS\MY FIREFOX SEARCH.XML, In Quarantäne, 372, 910806, 1.0.47298, , ame, , BE2095A2893BF611ADD491B38BC9EB57, 55E1195E6DB7A6E197A0A8425827794AFE878F207BCB0426D1F5ED774BBD902B
PUP.Optional.MyFireSearch, C:\USERS\SILKE *****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LX6SOG8Y.DEFAULT\PREFS.JS, Ersetzt, 372, 914864, 1.0.47298, , ame, , 8D8331F00743CF0BE345D984403DB929, 80B80A950853078FF54AF8893CCE6C09E267AC81246BDFE194A9C8F53B575C96
PUP.Optional.MyFireSearch, C:\USERS\SILKE *****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LX6SOG8Y.DEFAULT\PREFS.JS, Ersetzt, 372, 914865, 1.0.47298, , ame, , 8D8331F00743CF0BE345D984403DB929, 80B80A950853078FF54AF8893CCE6C09E267AC81246BDFE194A9C8F53B575C96
PUP.Optional.MyFireSearch, C:\USERS\SILKE *****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LX6SOG8Y.DEFAULT\PREFS.JS, Ersetzt, 372, 914866, 1.0.47298, , ame, , 8D8331F00743CF0BE345D984403DB929, 80B80A950853078FF54AF8893CCE6C09E267AC81246BDFE194A9C8F53B575C96
PUP.Optional.MyFireSearch, C:\USERS\SILKE *****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LX6SOG8Y.DEFAULT\PREFS.JS, Ersetzt, 372, 914867, 1.0.47298, , ame, , 8D8331F00743CF0BE345D984403DB929, 80B80A950853078FF54AF8893CCE6C09E267AC81246BDFE194A9C8F53B575C96
PUP.Optional.MyFireSearch, C:\USERS\SILKE *****\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LX6SOG8Y.DEFAULT\PREFS.JS, Ersetzt, 372, 914868, 1.0.47298, , ame, , 8D8331F00743CF0BE345D984403DB929, 80B80A950853078FF54AF8893CCE6C09E267AC81246BDFE194A9C8F53B575C96
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) AdwCleaner Code:
# -------------------------------
# Malwarebytes AdwCleaner 8.3.0.0
# -------------------------------
# Build: 06-29-2021
# Database: 2021-10-26.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 11-17-2021
# Duration: 00:00:33
# OS: Windows 10 Pro
# Cleaned: 73
# Awaiting reboot:1
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\ProgramData\Partner
Deleted C:\Users\Silke *****\AppData\LocalLow\HPAppData
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Plants Vs Zombies
Deleted HKLM\System\Setup\FirstBoot\Services\WCAssistantService
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\.DEFAULT\Software\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted HKU\S-1-5-18\SOFTWARE\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
Deleted My Firefox Search
Deleted My Firefox Search
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.ASUSFancyStart Folder C:\ASUS.DAT
Deleted Preinstalled.ASUSFancyStart Folder C:\Program Files (x86)\ASUS\FANCYSTART
Deleted Preinstalled.ASUSFancyStart Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\BOOKWORM DELUXE
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\COOKING DASH
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\GAMECONSOLE
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\GOVERNOR OF POKER
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\HOTEL DASH SUITE SUCCESS
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\JEWEL QUEST 3
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\LUXOR 3
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\MAHJONGG DIMENSIONS
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\PLANTS VS ZOMBIES
Deleted Preinstalled.ASUSGames Folder C:\Program Files (x86)\ASUS\GAME PARK\WORLD OF GOO
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Bookworm Deluxe
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Cooking Dash
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Governor of Poker
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Hotel Dash Suite Success
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Jewel Quest 3
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Luxor 3
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Mahjongg dimensions
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\World of Goo
Deleted Preinstalled.ASUSGames Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1
Deleted Preinstalled.ASUSLiveUpdate Folder C:\Program Files (x86)\ASUS\ASUS LIVE UPDATE
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A20791B-5738-4C6E-A355-236BDDFAE8A1}
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Live Update
Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
Deleted Preinstalled.ASUSLiveUpdate Task C:\Windows\System32\Tasks\ASUS LIVE UPDATE
Deleted Preinstalled.ASUSProductRegistration Folder C:\Program Files (x86)\ASUS\APRP
Deleted Preinstalled.ASUSProductRegistration Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|ASUSPRP
Deleted Preinstalled.ASUSProductRegistration Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|ASUSPRP
Deleted Preinstalled.ASUSSplendid Folder C:\Program Files (x86)\ASUS\SPLENDID
Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F646E87D-D108-42A1-9CE4-93CACE83123B}
Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACMON
Deleted Preinstalled.ASUSSplendid Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0969AF05-4FF6-4C00-9406-43599238DE0D}
Deleted Preinstalled.ASUSSplendid Task C:\Windows\System32\Tasks\ACMON
Deleted Preinstalled.ASUSVibe Folder C:\Program Files (x86)\ASUS\ASUSVIBE
Deleted Preinstalled.ASUSVibe Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\ASUSVIBE
Deleted Preinstalled.ASUSVibe Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Asus Vibe2.0
Deleted Preinstalled.ASUSVirtualCamera Folder C:\Program Files (x86)\ASUS\VIRTUALCAMERA
Deleted Preinstalled.ASUSVirtualCamera Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
Deleted Preinstalled.ASUSWebStorage Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\ASUS WEBSTORAGE
Deleted Preinstalled.ASUSWebStorage Registry HKLM\Software\Classes\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}
Deleted Preinstalled.ASUSWebStorage Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|ASUSWebStorage
Deleted Preinstalled.ASUSWebStorage Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|ASUSWebStorage
Deleted Preinstalled.ASUSWebStorage Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\ASUS WebStorage
Deleted Preinstalled.CyberLinkLabelPrint Folder C:\Program Files (x86)\CYBERLINK\LABELPRINT
Deleted Preinstalled.CyberLinkLabelPrint Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|UpdateLBPShortCut
Deleted Preinstalled.CyberLinkLabelPrint Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|UpdateLBPShortCut
Deleted Preinstalled.CyberLinkLabelPrint Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}
Deleted Preinstalled.CyberLinkLabelPrint Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243}
Deleted Preinstalled.HPCleanFLC File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\CLMLServer
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|UpdateP2GoShortCut
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|UpdateP2GoShortCut
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{40BF1E83-20EB-11D8-97C5-0009C5020658}
Needs Reboot Preinstalled.ASUSWebStorage Folder C:\Program Files (x86)\ASUS\ASUS WEBSTORAGE
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
***** Reboot Required to Complete *****
***** [ Folders ] *****
Cleaning failed C:\Program Files (x86)\ASUS\ASUS WEBSTORAGE
*************************
AdwCleaner[S00].txt - [9393 octets] - [17/11/2021 22:00:05]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## RogueKiller Code:
Program : RogueKiller Anti-Malware
Version : 15.1.3.0
x64 : Yes
Program Date : Nov 9 2021
Location : C:\Users\Silke *****\Desktop\RogueKiller_portable64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19041) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : Silke *****
User is Admin : Yes
Date : 2021/11/17 21:58:09
Type : Scan
Aborted : No
Scan Mode : Standard
Duration : 2697
Found items : 1
Total scanned : 88768
Signatures Version : 20210423_062556
Truesight Driver : Yes
Updates Count : 0
************************* Warnings *************************
************************* Updates *************************
************************* Processes *************************
************************* Modules *************************
************************* Services *************************
************************* Scheduled Tasks *************************
************************* Registry *************************
>>>>>> XX - Software
└── [PUP.Gen1 (Potenziell bösartig)] (X64) HKEY_USERS\S-1-5-21-1930512678-1335690401-17082022-1000\Software\OCS -- N/A -> Gefunden
************************* WMI *************************
************************* Hosts File *************************
is_too_big : No
hosts_file_path : C:\Windows\System32\drivers\etc\hosts
************************* Filesystem *************************
************************* Web Browsers *************************
************************* Antirootkit ************************* |