PapstFlo2 | 01.05.2014 15:12 | Sorry war kurzfristig im Urlaub Code:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetesets_scanner_update returned -1 esets_gle=12
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=7b32daad04fd73439e104074a238f539
# engine=18048
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-27 08:59:45
# local_time=2014-04-27 10:59:45 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7600 NT
# compatibility_mode=1799 16775165 100 96 42099 264055675 34811 0
# compatibility_mode=5893 16776574 100 94 34161133 151038056 0 0
# scanned=409553
# found=1
# cleaned=0
# scan_time=37214
sh=5EF3F0C240B8DFB01E2D924FB1715ED2FD9AE678 ft=1 fh=46e30b14d57bf709 vn="Variante von Win32/AdWare.SpeedingUpMyPC.G Anwendung" ac=I fn="C:\Users\Lender\AppData\Local\Temp\is1590112554\5131432_stp.EXE" Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.04.2014
Suchlauf-Zeit: 21:02:20
Logdatei: dasd.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.10.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7
CPU: x64
Dateisystem: NTFS
Benutzer: Lender
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 299690
Verstrichene Zeit: 37 Min, 51 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 29
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, In Quarantäne, [4db3a15f2fd137c92d2ce56122e0936d],
PUP.Optional.WebSparkle.A, HKLM\SOFTWARE\WOW6432NODE\WebSparkle, In Quarantäne, [10f0de2209f72ad684f62f7382813cc4],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 3
Spyware.Zbot.VXGen, C:\Users\Lender\AppData\Roaming\Yboge\miyh.exe, In Quarantäne, [a55be61adb252cd47b56ea78cc35b24e],
PUP.Optional.MySearchDial.A, C:\Users\Lender\AppData\Local\Temp\is5177938\mysearchdial.dll, In Quarantäne, [6f91926e629eb64acba02e1e00011ae6],
PUP.Optional.MySearchDial.A, C:\Users\Lender\AppData\Local\Google\Chrome\User Data\Default\preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_14_ie&cd=2XzuyEtN2Y1L1QzuzztDtC0FtDtBzy0A0F0C0E0Czyzzzz0DtN0D0Tzu0SzztByDtN1L2XzutBtFtCzztFzztFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByEyEyB0AtG0E0A0DyCtGyDyDtByBtGyByDyB0FtGyD0FyC0ByE0Czyzz0B0A0B0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyD0DtA0AyE0FtAtGtD0B0AtDtGzyyByBtBtGzz0CyByEtGtCyCzy0EtByEtDtCyDyByC0F2Q&cr=1793561018&ir=", "hxxp://www.google.com/" ],), Ersetzt,[b24ea45c6f911ee252db7eca699b8e72]
Physische Sektoren: 0
(No malicious items detected)
(end) |