Pusi Puu | 16.11.2022 13:03 | MBAM: Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 16.11.22
Scan-Zeit: 12:48
Protokolldatei: a8447342-65a4-11ed-b4cf-00d861a155b2.json
-Softwaredaten-
Version: 4.5.17.221
Komponentenversion: 1.0.1806
Version des Aktualisierungspakets: 1.0.62364
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19045.2251)
CPU: x64
Dateisystem: NTFS
Benutzer: Mean-Machine\Anwender
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 302901
Erkannte Bedrohungen: 34
In die Quarantäne verschobene Bedrohungen: 34
Abgelaufene Zeit: 1 Min., 49 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.WinYahoo, HKU\S-1-5-21-1577740540-671938675-3438131953-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}, In Quarantäne, 203, 254682, 1.0.62364, , ame, , ,
PUP.Optional.SearchHijacker, HKLM\SOFTWARE\MICROSOFT\EDGE\EXTENSIONS\MECKCKFJNFNIMLOMKEMNHCOONJFPBCOH, In Quarantäne, 321, 912315, , , , , ,
PUP.Optional.SearchHijacker, HKU\S-1-5-21-1577740540-671938675-3438131953-1000\SOFTWARE\MICROSOFT\EDGE\EXTENSIONS\MECKCKFJNFNIMLOMKEMNHCOONJFPBCOH, In Quarantäne, 321, 912315, , , , , ,
PUP.Optional.SearchHijacker, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\EDGE\EXTENSIONS\meckckfjnfnimlomkemnhcoonjfpbcoh, In Quarantäne, 321, 912315, 1.0.62364, , ame, , ,
Registrierungswert: 2
PUP.Optional.WinYahoo, HKU\S-1-5-21-1577740540-671938675-3438131953-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|URL, In Quarantäne, 203, 254682, 1.0.62364, , ame, , ,
PUP.Optional.SearchHijacker, HKU\S-1-5-21-1577740540-671938675-3438131953-1000\SOFTWARE\MICROSOFT\EDGE\PREFERENCEMACS\Default\extensions.settings|MECKCKFJNFNIMLOMKEMNHCOONJFPBCOH, In Quarantäne, 321, 912315, , , , , ,
Registrierungsdaten: 1
PUP.Optional.WinYahoo, HKU\S-1-5-21-1577740540-671938675-3438131953-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, 203, 707485, 1.0.62364, , ame, , ,
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
PUP.Optional.SearchHijacker, C:\USERS\ANWENDER\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Extensions\MECKCKFJNFNIMLOMKEMNHCOONJFPBCOH, In Quarantäne, 321, 912315, , , , , ,
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove, In Quarantäne, 936, 542290, , , , , ,
PUP.Optional.WinYahoo.TskLnk, C:\USERS\ANWENDER\APPDATA\LOCAL\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}, In Quarantäne, 936, 542290, 1.0.62364, , ame, , ,
Datei: 24
PUP.Optional.SearchHijacker, C:\USERS\ANWENDER\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Secure Preferences, Ersetzt, 321, 912315, , , , , 461777EE4D89DE9E1AB11BAB71E3D10A, BE895DBF60BF4116C642D8F70103C36921069BCA0F0A015FFF968D664ABB993D
PUP.Optional.SearchManager.BITSRST, C:\USERS\ANWENDER\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\DEFAULT\EXTENSIONS\MECKCKFJNFNIMLOMKEMNHCOONJFPBCOH\10.1.4.70_1\RESPONSECONFIG.JSON, In Quarantäne, 245, 626727, 1.0.62364, , ame, , E2E264F970E768BD23EB5C9715CD0670, E4546429C867FD77A986717FCDACCAA0E4058A35C59122FB610A28AAF1E8C5D1
PUP.Optional.WinYahoo.TskLnk, C:\USERS\ANWENDER\APPDATA\LOCAL\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HOWTOREMOVE\HOWTOREMOVE.HTML, In Quarantäne, 936, 542290, 1.0.62364, , ame, , 92A56BD431B8EC678C73844C916017CA, 47BFA64B49B9ABF0C2DCA4F400E0137E1C29211CE6ED4196EDE1560149D13FF2
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\chromium-min.jpg, In Quarantäne, 936, 542290, , , , , 63BC75E5CF5CBA301C0A333A493C1E6C, AECF7E9F8EA60035CF8E255B99ADDBC4739C357BC9773273B682B06073AE2BBC
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\control panel-min-min.JPG, In Quarantäne, 936, 542290, , , , , D3317C08A7FD5C68AF7607B56365D7EF, E0DF11EDFC606871F3FA3E825D0A346D895CF2246372E1919F3F6B6F823855EA
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\down.png, In Quarantäne, 936, 542290, , , , , BD28C167E200A3B28D65FAD11067F767, 782AEE35F1473A0818E85C7888276AB1A92A2C6650420A6914C11D4A87017959
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\ff menu.JPG, In Quarantäne, 936, 542290, , , , , 0ACF64A62398FD3E28C0F776E080E02E, A7E228427AFE421EE317EECF714464E5ED346B2032C98F4076B01EB61D92F11F
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\ff search engine-min.png, In Quarantäne, 936, 542290, , , , , 98167327578F423AD62775F9C0DA1C08, 95E4B167F0173DB00F6BCDDE9864CC2E5DDED171506F8AB8E7B9F7863D913680
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\hp-min ff.png, In Quarantäne, 936, 542290, , , , , AFE6FD269F10B4FB4055028CE2E0F70C, F0403DEBED00E906EE26EFE1463A63347D5B7CD6EB60BB38AE0E3C3460F71693
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\hp-min ie.png, In Quarantäne, 936, 542290, , , , , C76F780F7CDEDA6D63A72E00719EAE53, 0A53A6F7C61B73B40061A401ED4C5D1E520C1D1DEC270617C5C25C8EE64A95C6
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\search engine.gif, In Quarantäne, 936, 542290, , , , , D2665D24334093AFB3D3E64E22346AC4, E5CA26785BDB836C3C234A67E991BF1C70D4E87CAA75EC43747619E64DECAA57
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\setup pages.gif, In Quarantäne, 936, 542290, , , , , D8957AB88B51AC3D91DB06AC96369BE4, 6BB5388E49AAB90AB7C85A736EAABDEB9A78CDCCA4D7A4138B00DBC1C657C8D5
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\sp-min.png, In Quarantäne, 936, 542290, , , , , C4A8846B0AAC9BEF78F6A001514ECFF5, 4E9A05BDB43137235913F0BBB1F21C35DF34E62D33F2A4F4FC9C0F15FA1346E3
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\start-min.jpg, In Quarantäne, 936, 542290, , , , , 7A52610FBA6935C9ACF2A2F38CA86F6A, 677001B0CFD9F6C824E422C5EBBC5C042ABB0CF156990064DD3170CF6F3379C8
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\HowToRemove\up.png, In Quarantäne, 936, 542290, , , , , 45B1D3F523A38E29419DC26AE6BDD253, 892E25F7363B1C4EFA5FFACD5F4CDADD01833F49EF5CEF335676D84DA871EBA0
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\laconef, In Quarantäne, 936, 542290, , , , , F45B4692FF1D6D2CCB9223D8339C8E2A, F1210F85446863E8DED182F1C6FF3FAD83420A54D5E78638AC828A7C6C45C845
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\timita, In Quarantäne, 936, 542290, , , , , 181B8B9347E234BBEB175A6198A0D25F, 53397BBFD387B2B5DD52FA824832622E1E45E7976D6E25E77035E26FB4F374F3
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\uninst.exe, In Quarantäne, 936, 542290, , , , , 4ED777A5428F68EFA0A9D84FEB06D056, 59EE7AA430827FED2DCE7D0765AA95560094D864A811AB3611E30EA1B2CB4293
PUP.Optional.WinYahoo.TskLnk, C:\Users\Anwender\AppData\Local\{CBF0FDAC-EF58-9114-82C0-B4FCA6A84864}\uninstp.dat, In Quarantäne, 936, 542290, , , , , 07376496354D1F307EAE3E332D8D814A, C1C44F3888FE65C23FDD411D834F92D9B2C839431DB702BFF94C0FDBB9F3B6EB
Adware.WinYahoo, C:\PROGRAMDATA\ZZDGA\NINIWIC_270415_S4_1.EXE, In Quarantäne, 751, 718433, 1.0.62364, 86EDBBD56BB0F68FF0C31988, dds, 02038149, F4E7CC722D26DC5E61C43C2570C4EA92, F47E0B00BD1A9D9FD7CB24DC1587216A0A54B9E84080D6A65D3D286CF10A5C81
Adware.InstallCore, C:\USERS\ANWENDER\DOWNLOADS\ADOBE_FLASH_PLAYER_1993324768.EXE, In Quarantäne, 481, 845509, 1.0.62364, E75DEE78B889657D616EF64D, dds, 02038149, 54C53DD11D9C09610748F69CB6971FD2, F12A98D384058DC2CE9B1B6DF77FD8E323915480054A9C8AF86E538174230D29
Adware.InstallCore, C:\USERS\ANWENDER\DOWNLOADS\CR_DOWNLOADER_FUER_PROJECT64_2184029674.EXE, In Quarantäne, 481, 845509, 1.0.62364, 276E4DD76AB8E954D992053D, dds, 02038149, 0CD11AEB07E5300341ECE5788153FF49, CA1FFD7F67000632DC4D6617196D8EF2D562D47786D048A4569535A18074B81B
Adware.InstallCore, C:\USERS\ANWENDER\DOWNLOADS\ADOBE_FLASH_PLAYER_2151221308.EXE, In Quarantäne, 481, 845509, 1.0.62364, E75DEE78B889657D616EF64D, dds, 02038149, 54C53DD11D9C09610748F69CB6971FD2, F12A98D384058DC2CE9B1B6DF77FD8E323915480054A9C8AF86E538174230D29
Adware.InstallCore, C:\USERS\ANWENDER\DOWNLOADS\ADOBE_FLASH_PLAYER_3461104809.EXE, In Quarantäne, 481, 845509, 1.0.62364, E75DEE78B889657D616EF64D, dds, 02038149, 54C53DD11D9C09610748F69CB6971FD2, F12A98D384058DC2CE9B1B6DF77FD8E323915480054A9C8AF86E538174230D29
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) RK Code:
Program : RogueKiller Anti-Malware
Version : 15.6.3.0
x64 : Yes
Program Date : Nov 15 2022
Location : C:\Users\Anwender\AppData\Local\Temp\scoped_dir13832_1281236509\RogueKiller_portable64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19045) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : Anwender
User is Admin : Yes
Date : 2022/11/16 12:00:37
Type : Removal
Aborted : No
Scan Mode : Standard
Duration : 249
Found items : 5
Total scanned : 72180
Signatures Version : 20221116_093222
Truesight Driver : Yes
Updates Count : 7
************************* Warnings *************************
************************* Removal *************************
[Suspicious.Path (Potenziell bösartig)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{131180DE-CA4F-44D2-B6B3-8DE8E5E8783B}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe -- [%localappdata%\programs\crewlink\crewlink.exe] -> Gelöscht
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{131180DE-CA4F-44D2-B6B3-8DE8E5E8783B}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe
[+] value : [%localappdata%\programs\crewlink\crewlink.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 0
[+] status : 3
[+] status_str : Gelöscht
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potenziell bösartig)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{73477402-CB21-48DE-BE1B-9C447E6078E2}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe -- [%localappdata%\programs\crewlink\crewlink.exe] -> Gelöscht
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{73477402-CB21-48DE-BE1B-9C447E6078E2}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe
[+] value : [%localappdata%\programs\crewlink\crewlink.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 1
[+] status : 3
[+] status_str : Gelöscht
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potenziell bösartig)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{5F2BD7E1-5256-4B70-844B-DAD2DC3CE06B}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe -- [%localappdata%\programs\crewlink\crewlink.exe] -> Gelöscht
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{5F2BD7E1-5256-4B70-844B-DAD2DC3CE06B}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe
[+] value : [%localappdata%\programs\crewlink\crewlink.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 2
[+] status : 3
[+] status_str : Gelöscht
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potenziell bösartig)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{B8F988B0-4770-4EA5-8956-EBCE1CD5FB68}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe -- [%localappdata%\programs\crewlink\crewlink.exe] -> Gelöscht
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{B8F988B0-4770-4EA5-8956-EBCE1CD5FB68}C:\users\anwender\appdata\local\programs\crewlink\crewlink.exe
[+] value : [%localappdata%\programs\crewlink\crewlink.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 3
[+] status : 3
[+] status_str : Gelöscht
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[PUP.SearchManager (Potenziell bösartig)] Search Manager -- {24436206-088d-4a1a-8d0e-cf93ca7a2d23} -> Gelöscht
[+] scan_what : 1
[+] vendors : PUP.SearchManager
[+] Name : Search Manager
[+] value : {24436206-088d-4a1a-8d0e-cf93ca7a2d23}
[+] Type : Browser
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 4
[+] status : 3
[+] status_str : Gelöscht
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0 |