DiabolusXXX | 20.05.2014 16:15 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 20.05.2014
Scan Time: 15:37:09
Logfile: log1.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.05.20.04
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Tobias
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 377268
Time Elapsed: 8 min, 10 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 14
PUP.Optional.SimpleNewTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5C2DD58F-613F-4580-8AC0-F10D760AF938}, Quarantined, [d9cbdc77295271c59d219691c939fb05],
PUP.Optional.SimpleNewTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B47A69DE-9B38-4EC0-996E-99F90C0F8CA5}, Quarantined, [d9cbdc77295271c59d219691c939fb05],
PUP.Optional.SimpleNewTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B47A69DE-9B38-4EC0-996E-99F90C0F8CA5}, Quarantined, [d9cbdc77295271c59d219691c939fb05],
PUP.Optional.SimpleNewTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{5C2DD58F-613F-4580-8AC0-F10D760AF938}, Quarantined, [d9cbdc77295271c59d219691c939fb05],
PUP.Optional.SimpleNewTab.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5C2DD58F-613F-4580-8AC0-F10D760AF938}, Quarantined, [d9cbdc77295271c59d219691c939fb05],
PUP.Optional.SimpleNewTab.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5C2DD58F-613F-4580-8AC0-F10D760AF938}, Quarantined, [d9cbdc77295271c59d219691c939fb05],
PUP.Optional.SimpleNewTab.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{59F39B89-94C3-44C5-B903-9A6B85C32921}, Quarantined, [931155fe6f0c6fc71ca32afd6f9304fc],
PUP.Optional.OfferMosquito, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82B16A3D-F03E-4565-A532-666B219C9A53}, Quarantined, [daca6be8017aef47aa084ce079890cf4],
PUP.Optional.SimpleNewTab.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SimpleNewTab, Quarantined, [acf8e86b6f0c37ff20b9b0d5bc46768a],
PUP.Optional.AlexaTB.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars, Quarantined, [772ddf74cead78beddfd2b90cf34c33d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [1c88421112692d099ba34a55cb3711ef],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [fba96ee55229e25401457d3804ff926e],
PUP.Optional.Softonic.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [11931c3745364beb2ca8c0cdd52d639d],
PUP.Optional.AmazonTB.A, HKU\S-1-5-21-91668819-312498841-480008626-1013-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ALEXA INTERNET\ALEXA9\Amazon, Quarantined, [7a2a2a295e1d88ae439a92298e753fc1],
Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-91668819-312498841-480008626-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0H1L1J1L1S1R1N, Quarantined, [fba96ee55229e25401457d3804ff926e]
Registry Data: 0
(No malicious items detected)
Folders: 12
PUP.Optional.OpenCandy, C:\Users\Tobias\AppData\Roaming\OpenCandy, Quarantined, [b9eb0b48accfcf67fcfc086a9d6532ce],
PUP.Optional.OpenCandy, C:\Users\Tobias\AppData\Roaming\OpenCandy\0373762C29274D58992B118262C8F55A, Quarantined, [b9eb0b48accfcf67fcfc086a9d6532ce],
PUP.Optional.OpenCandy, C:\Users\Tobias\AppData\Roaming\OpenCandy\0F2010D181D341E98DF3ABB80E65696F, Quarantined, [b9eb0b48accfcf67fcfc086a9d6532ce],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\simple_new_tab, Quarantined, [762ea9aad2a902347fcce89a669ca45c],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\simple_new_tab\htmls, Quarantined, [762ea9aad2a902347fcce89a669ca45c],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Roaming\OfferMosquito, Quarantined, [34707ad97506221475d798ea10f2a55b],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\sams, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\ext_offermosquito, Quarantined, [0e9690c32f4ca294e669641e9b67ce32],
Files: 79
PUP.Optional.Searchprotect, C:\Users\Tobias\AppData\Roaming\OpenCandy\0373762C29274D58992B118262C8F55A\INTERNALWRAPPER.exe, Quarantined, [80247dd61764191d6c09d14ad829f50b],
PUP.Optional.OpenCandy.A, C:\Users\Tobias\AppData\Roaming\OpenCandy\0373762C29274D58992B118262C8F55A\LatestDLMgr.exe, Quarantined, [c4e0f85bd1aaaa8cf15c54b8e21fcc34],
PUP.Optional.OpenCandy.A, C:\Users\Tobias\AppData\Roaming\OpenCandy\0F2010D181D341E98DF3ABB80E65696F\LatestDLMgr.exe, Quarantined, [d0d4e0738af12e082c2137d57091ad53],
PUP.Optional.ToolBarInstaller.A, C:\Users\Tobias\AppData\Local\Temp\BuenoSearchTB.exe, Quarantined, [e9bb7bd888f3d2641472fd25000415eb],
PUP.Optional.BuenoSearch.A, C:\Users\Tobias\AppData\Local\Temp\~nsu.tmp\Au_.exe, Quarantined, [13916be896e573c3f848f97eb34e04fc],
PUP.Optional.Softonic.A, C:\Users\Tobias\Downloads\SoftonicDownloader_fuer_kindle-for-pc.exe, Quarantined, [30740e456813c670bf379f8029d89070],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\extensions\om@offermosquito.com.xpi, Quarantined, [089c9db6245777bf17c54e37768c1ae6],
PUP.Optional.AmazonTB.A, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\extensions\abb@amazon.com.xpi, Quarantined, [faaaee65403bc96dbb742272719115eb],
PUP.Optional.BuenoSearch.A, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\searchplugins\buenosearch.xml, Quarantined, [cfd5084bcfac9f973c147d17db27b848],
PUP.Optional.OpenCandy, C:\Users\Tobias\AppData\Roaming\OpenCandy\0373762C29274D58992B118262C8F55A\Amazon_CB_ALL_p1v6.exe, Quarantined, [b9eb0b48accfcf67fcfc086a9d6532ce],
PUP.Optional.OpenCandy, C:\Users\Tobias\AppData\Roaming\OpenCandy\0F2010D181D341E98DF3ABB80E65696F\TuneUpUtilities2013-2200218-p3v0.exe, Quarantined, [b9eb0b48accfcf67fcfc086a9d6532ce],
PUP.Optional.OpenCandy, C:\Users\Tobias\AppData\Roaming\OpenCandy\0F2010D181D341E98DF3ABB80E65696F\TuneUpUtilities2013-2200218_de-DE.exe, Quarantined, [b9eb0b48accfcf67fcfc086a9d6532ce],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0\manifest.json, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0\newtab.js, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0\options.html, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0\options.js, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0\snt.html, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmgkeimkiojpjcoiiipekfjaopchhjga\1.0.0_0\snt.js, Quarantined, [c9dbb59efa810f2790baa3df69996a96],
PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\simple_new_tab\htmls\index.html, Quarantined, [762ea9aad2a902347fcce89a669ca45c],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\ads.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\contextualClickProcessor.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\country.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\deferredXhr.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\dependencies.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\icon.png, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\main.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\manifest.json, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\ping.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\pingurl.txt, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\rmPopup.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\sams.json, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\sss.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\tracking.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\utils.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\sams\background.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\2.4_0\sams\content.js, Quarantined, [64404b08ee8dca6caca294eecd357090],
PUP.Optional.OfferMosquito.A, C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\ext_offermosquito\ext_offermosquito.crx, Quarantined, [0e9690c32f4ca294e669641e9b67ce32],
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false);), Replaced,[04a072e1c4b758de4391b5c716eed12f]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.aflt", "babsst");), Replaced,[9b099ab9522954e2d2029be1679db44c]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");), Replaced,[4460054ec5b622149b3977059371c63a]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.autoRvrt", "false");), Replaced,[7d278ac9accf58de24b0522adc282ed2]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.dfltLng", "en");), Replaced,[6b395ff4b0cb72c46074cbb128dcf50b]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.excTlbr", false);), Replaced,[574d55fe601b9a9cc3114c30ed17b848]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.ffxUnstlRst", true);), Replaced,[8a1a272c5b202f0730a4d2aa5da78080]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.id", "e02b1f4300000000000000ff054c7f0a");), Replaced,[079db99a7ffcb1857d57f3892cd860a0]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlDay", "16135");), Replaced,[04a0e46f2457b1856074fb814bb9916f]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlRef", "sst");), Replaced,[40642d267a010e28864eceae26de0af6]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.newTab", false);), Replaced,[fda72330b8c34aec27ade29a9a6a9a66]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prdct", "buenosearch");), Replaced,[7034361db5c684b233a1a5d746be6d93]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prtnrId", "buenosearch");), Replaced,[71335ff46d0ea492775d1c6015efd828]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.rvrt", "false");), Replaced,[e9bb0e45fe7d171f61737b012ada6d93]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.smplGrp", "none");), Replaced,[c5dfd18277042016874d3a4247bdb749]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=E02B00FF054C7F0A&affID=128491&tsp=5178");), Replaced,[e8bcf65dc7b473c39f353e3e29db738d]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrId", "base");), Replaced,[a1033320f18aca6c7d5782fa4cb8946c]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=E02B00FF054C7F0A&affID=128491&tsp=5178");), Replaced,[5a4aea69a1da3bfb4e865428b054bd43]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7");), Replaced,[b5ef8dc6cab1072f5c781d5fbd4734cc]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.715:53:27");), Replaced,[ccd82a29ea91bf7733a1780417edb848]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7");), Replaced,[881cf0639cdf61d51bb9502ccc3857a9]
PUP.Optional.BuenoSearch.A, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=E02B00FF054C7F0A&affID=128491&tsp=5178");), Replaced,[cfd554ffdd9e92a44f86fe7d0bf97e82]
PUP.Optional.BuenoSearch.A, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=E02B00FF054C7F0A&affID=128491&tsp=5178");), Replaced,[b3f1193a8fec65d1e4f13f3c6a9a0cf4]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.id", "e02b1f4300000000000000ff054c7f0a");), Replaced,[752fc98a97e451e5b61dfc804eb60bf5]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");), Replaced,[8e16e271f3881c1a8c470676eb19c838]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlDay", "16135");), Replaced,[c6de8ec547345dd9379cf884ce36ad53]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7");), Replaced,[9212242f8cef2a0c0fc4cfadca3abf41]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7");), Replaced,[e8bc3023e99296a08350681421e330d0]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.715:53:27");), Replaced,[594b8fc495e655e1c31093e970948c74]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.prtnrId", "buenosearch");), Replaced,[d6ce054e413a3204ede6c6b6887c966a]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.prdct", "buenosearch");), Replaced,[8f157ad96e0d53e308cb90ecae56fe02]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.aflt", "babsst");), Replaced,[0a9a1d365e1dfa3c0bc8b1cbf014be42]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.smplGrp", "none");), Replaced,[396ba7ac9cdfda5c5c774339a55f6898]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrId", "base");), Replaced,[7c28a9aa512af73fe8ebfd7f3ec69967]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlRef", "sst");), Replaced,[861e60f37b00d660963d3745f2123ac6]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.dfltLng", "en");), Replaced,[ffa575dede9d5dd9b2213b419e6629d7]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.excTlbr", false);), Replaced,[6242d380b1cad75f785b5e1ed133e719]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.ffxUnstlRst", true);), Replaced,[dfc54b087dfee84e2fa44537b2521be5]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false);), Replaced,[089cd281f685c96da33057251fe59769]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.autoRvrt", "false");), Replaced,[2e76a5ae007b191dac27a5d7ef15ed13]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.rvrt", "false");), Replaced,[a7fdf95aa8d341f53c97f88415ef56aa]
PUP.Optional.BuenoSearch, C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\501byysu.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.newTab", false);), Replaced,[c1e398bb0972f343b023a0dc30d418e8]
Physical Sectors: 0
(No malicious items detected)
(end)
Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 20.05.2014 15:28:37, SYSTEM, BÃ?RO, Protection, Malware Protection, Starting,
Protection, 20.05.2014 15:28:37, SYSTEM, BÃ?RO, Protection, Malware Protection, Started,
Protection, 20.05.2014 15:28:37, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Starting,
Protection, 20.05.2014 15:28:38, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Started,
Update, 20.05.2014 15:28:43, SYSTEM, BÃ?RO, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 20.05.2014 15:28:50, SYSTEM, BÃ?RO, Manual, Malware Database, 2014.3.4.9, 2014.5.20.4,
Protection, 20.05.2014 15:28:51, SYSTEM, BÃ?RO, Protection, Refresh, Starting,
Protection, 20.05.2014 15:28:51, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Stopping,
Protection, 20.05.2014 15:28:52, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Stopped,
Protection, 20.05.2014 15:28:54, SYSTEM, BÃ?RO, Protection, Refresh, Success,
Protection, 20.05.2014 15:28:54, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Starting,
Protection, 20.05.2014 15:28:54, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Started,
Detection, 20.05.2014 15:29:11, SYSTEM, BÃ?RO, Protection, Malware Protection, File, PUP.Optional.SimpleNewTab.A, C:\Users\Tobias\AppData\Local\simple_new_tab\simple_new_tab.dll, Quarantine, [f9abf85b423970c61635473b09f9df21]
Protection, 20.05.2014 15:39:28, SYSTEM, BÃ?RO, Protection, Malware Protection, Starting,
Protection, 20.05.2014 15:39:28, SYSTEM, BÃ?RO, Protection, Malware Protection, Started,
Protection, 20.05.2014 15:39:28, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Starting,
Protection, 20.05.2014 15:40:24, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Started,
Update, 20.05.2014 16:58:59, SYSTEM, BÃ?RO, Scheduler, Malware Database, 2014.5.20.4, 2014.5.20.5,
Protection, 20.05.2014 16:59:01, SYSTEM, BÃ?RO, Protection, Refresh, Starting,
Protection, 20.05.2014 16:59:01, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Stopping,
Protection, 20.05.2014 16:59:02, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Stopped,
Protection, 20.05.2014 16:59:06, SYSTEM, BÃ?RO, Protection, Refresh, Success,
Protection, 20.05.2014 16:59:06, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Starting,
Protection, 20.05.2014 16:59:06, SYSTEM, BÃ?RO, Protection, Malicious Website Protection, Started,
(end)
Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 20.05.2014
Scan Time: 16:31:06
Logfile: log3.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.05.20.04
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Tobias
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 377365
Time Elapsed: 6 min, 31 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
Ich hoffe du meintest diese sonst musst du genauer werden (Laie!):kloppen: |