Ich hatte den Virus vor gut 1 Jahr, und danach wurden auf Anleitung mit ComboFix alle Log-Dateien und Scan-Programme gelöscht. Ich habe jetzt nochmal mam durchlaufen lassen und das ist herausgekommen: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 25.10.2015
Suchlaufzeit: 22:16
Protokolldatei:
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.10.25.03
Rootkit-Datenbank: v2015.10.23.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Paul
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 563989
Abgelaufene Zeit: 1 Std., 3 Min., 0 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.InstallCore, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\ICSW1.14, , [a582a2b95d2ef83eec10b2b348bbaf51],
PUP.Optional.CrossRider, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2CA9342A-2AA3-4C32-A768-B7412BBF65AA}, , [b374c299c9c2fa3cd816381f26ddf10f],
PUP.Optional.CrossRider, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF67060A-69F4-432F-99E0-F267F29BFEE7}, , [ef384e0d47445adc0edf94c317ecf60a],
PUP.Optional.ProductSetup, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\PRODUCTSETUP, , [7daa3427dcaf0f270680f38347bc4cb4],
Registrierungswerte: 3
PUP.Optional.CrossRider, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2CA9342A-2AA3-4C32-A768-B7412BBF65AA}|AppName, Plus-HD-4.8-enabler.exe-codedownloader.exe, , [b374c299c9c2fa3cd816381f26ddf10f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF67060A-69F4-432F-99E0-F267F29BFEE7}|AppName, Plus-HD-4.8-enabler.exe-buttonutil.exe, , [ef384e0d47445adc0edf94c317ecf60a]
PUP.Optional.ProductSetup, HKU\S-1-5-21-1518553307-3788296194-4095220867-1000\SOFTWARE\PRODUCTSETUP|tb, 0D2Y1I1B1P2Y, , [7daa3427dcaf0f270680f38347bc4cb4]
Registrierungsdaten: 1
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {ielnksrch}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({ielnksrch}),,[6bbcff5c5e2d0b2bbc5648ea64a08779]
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 34
HackTool.GamesCheat.Gen, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08\5ccd2c07c24e0a10b8a919ca16c0943d137cfb18, , [f334f5660784cd69ddf5b191ec187a86],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08\44fc0142b24d654989aad58892a2fbcaeba2ea25, , [83a471ea4c3f8ea8973918317d877d83],
PUP.Optional.MultiPlug, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08\5d8d8a4fa2b3ba433639a0cd3c5dc83c92bc4a81, , [3becea7117743bfb7cf127e151b05ba5],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08\ab343584c45b9bf60fb9ebbca00d34dc5a11e493, , [2ef9aead4a4186b028a89faac73d45bb],
PUP.Optional.BundleInstaller, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08\9164c91e51c8ec24b15c34c16ca5d85735a7b46e, , [97906bf0791240f6934e2b03d12fef11],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-194046\44fc0142b24d654989aad58892a2fbcaeba2ea25, , [6eb996c5b8d3ae88933d232619ebe020],
HackTool.GamesCheat.Gen, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-194046\5ccd2c07c24e0a10b8a919ca16c0943d137cfb18, , [6cbb48136328ab8b547ed96921e332ce],
PUP.Optional.MultiPlug, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-194046\5d8d8a4fa2b3ba433639a0cd3c5dc83c92bc4a81, , [e64152096f1c0630472660a844bdb947],
PUP.Optional.BundleInstaller, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-194046\9164c91e51c8ec24b15c34c16ca5d85735a7b46e, , [39ee1d3ec3c8fa3c845d89a52fd1659b],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-194046\ab343584c45b9bf60fb9ebbca00d34dc5a11e493, , [be690358a5e65adcb61abe8b6b997e82],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-203643\44fc0142b24d654989aad58892a2fbcaeba2ea25, , [9d8a70eb068536003c94fe4b8480728e],
HackTool.GamesCheat.Gen, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-203643\5ccd2c07c24e0a10b8a919ca16c0943d137cfb18, , [55d286d590fb89ad7a582e149d679f61],
PUP.Optional.MultiPlug, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-203643\5d8d8a4fa2b3ba433639a0cd3c5dc83c92bc4a81, , [5fc81546fd8e2c0abcb15cac0cf5c33d],
PUP.Optional.BundleInstaller, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-203643\9164c91e51c8ec24b15c34c16ca5d85735a7b46e, , [a681a6b5ec9f33038e535ed0a65a2cd4],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-203643\ab343584c45b9bf60fb9ebbca00d34dc5a11e493, , [bc6b1546513a62d427a965e4778da25e],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-205257\44fc0142b24d654989aad58892a2fbcaeba2ea25, , [a4835803b1da38fea12f0e3b976d3ec2],
HackTool.GamesCheat.Gen, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-205257\5ccd2c07c24e0a10b8a919ca16c0943d137cfb18, , [f4336dee95f6f442874b4ff3739139c7],
PUP.Optional.MultiPlug, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-205257\5d8d8a4fa2b3ba433639a0cd3c5dc83c92bc4a81, , [30f7a9b28803a096482566a2e61b31cf],
PUP.Optional.BundleInstaller, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-205257\9164c91e51c8ec24b15c34c16ca5d85735a7b46e, , [889f302b3c4f55e14d9463cbd62a857b],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-205257\ab343584c45b9bf60fb9ebbca00d34dc5a11e493, , [8b9cfe5d593232040cc4dd6c35cfe31d],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-211706\44fc0142b24d654989aad58892a2fbcaeba2ea25, , [58cf471424673600be126cdd58ac669a],
HackTool.GamesCheat.Gen, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-211706\5ccd2c07c24e0a10b8a919ca16c0943d137cfb18, , [2dfa4c0f97f4a88eac269ea439cb6e92],
PUP.Optional.MultiPlug, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-211706\5d8d8a4fa2b3ba433639a0cd3c5dc83c92bc4a81, , [70b78ecdbccf40f60c6171978b76ea16],
PUP.Optional.BundleInstaller, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-211706\9164c91e51c8ec24b15c34c16ca5d85735a7b46e, , [012619421279db5bcf1266c869977d83],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-211706\ab343584c45b9bf60fb9ebbca00d34dc5a11e493, , [b27561fad2b92b0b4987b495dd27cf31],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-214134\44fc0142b24d654989aad58892a2fbcaeba2ea25, , [70b7b2a90982e84e1ab6034625df34cc],
HackTool.GamesCheat.Gen, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-214134\5ccd2c07c24e0a10b8a919ca16c0943d137cfb18, , [c265ea7197f4e84e01d14101808459a7],
PUP.Optional.MultiPlug, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-214134\5d8d8a4fa2b3ba433639a0cd3c5dc83c92bc4a81, , [949389d289021224c7a6996f788955ab],
PUP.Optional.BundleInstaller, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-214134\9164c91e51c8ec24b15c34c16ca5d85735a7b46e, , [63c46af1d2b9013507daa28cd030eb15],
PUP.Optional.Firseria, C:\Users\Paul\AppData\Roaming\Apple Computer\MobileSync\Backup\0a9ea77c06489015f495bfba661a6b18e4939c08-20151015-214134\ab343584c45b9bf60fb9ebbca00d34dc5a11e493, , [54d39dbeddae7eb83898ba8f30d43cc4],
PUP.Optional.InstallCore, C:\Users\Paul\Desktop\installer.zip, , [8a9d025923684ee8fa22144b43bec13f],
PUP.Optional.InstallCore, C:\Users\Paul\AppData\Local\Temp\Rar$DIa0.986\SMB3SetupES.exe, , [ad7ade7df19a54e2b06c0758aa5739c7],
PUP.Optional.Linkury.ShrtCln, C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\vqr73kky.default\searchplugins\findit.xml, , [51d62d2eb2d9b97d29495aeb9d6602fe],
PUP.Optional.Linkury.ShrtCln, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\findit.xml, , [01265efd6b20fa3c571c291c2cd731cf],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) erstaunlich viel, ich habe das jetzt auch über das Tool entfernt. |