![]() |
Avast und Antimalware melden div. bedrohliche Objekte zb in sysapcrt.dll Hallo Forum, gestern meldete Avast eine Reihe von bedrohlichen Objekten, die ich aber nicht reparieren oder löschen konnte (systemk.dll etc.). Habe nun Malwarebytes durchlaufen lassen und dieses liefert eine sehr lange Liste. Kenne mich nicht so gut aus, was nun zu tun ist. Alles in Quarantäne? Weiß jemand, worum es sich handelt? Bitte Euch um Hilfe! Markus ------------------------------------------------------ Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 21.05.2014 Suchlauf-Zeit: 06:37:17 Logdatei: vir.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.05.20.06 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Fuhrmann Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 283022 Verstrichene Zeit: 11 Std, 51 Min, 36 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 3 PUP.Optional.SystemK.A, C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe, 2988, , [fda94d064b3026109d381b60e1206f91] PUP.Optional.SystemK.A, C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe, 1108, , [fda94d064b3026109d381b60e1206f91] PUP.Optional.SystemK.A, C:\Program Files (x86)\Settings Manager\systemk\systemku.exe, 4440, , [2284bd9677043600ddf88cefc041f60a] Module: 0 (No malicious items detected) Registrierungsschlüssel: 38 PUP.Optional.SystemK.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SystemkService, , [fda94d064b3026109d381b60e1206f91], PUP.Optional.SystemK.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\F06DEFF2-5B9C-490D-910F-35D3A91196222, , [d1d5c98ab6c5999d6372cdae827f7e82], PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\Linkey.Linkey, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Linkey.Linkey, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKU\S-1-5-21-2433529201-776013581-942875397-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKU\S-1-5-21-2433529201-776013581-942875397-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{726E90BE-DC22-4965-B215-E0784DC26F47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4613B1C1-FBC0-43C3-A4B9-B1D6CD360BB3}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4613B1C1-FBC0-43C3-A4B9-B1D6CD360BB3}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{726E90BE-DC22-4965-B215-E0784DC26F47}, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}\INPROCSERVER32, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\APPID\{6A7CD9EC-D8BD-4340-BCD0-77C09A282921}, , [198d83d05f1c54e21200ff2bd23052ae], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{6A7CD9EC-D8BD-4340-BCD0-77C09A282921}, , [198d83d05f1c54e21200ff2bd23052ae], PUP.Optional.Linkey.A, HKU\S-1-5-21-2433529201-776013581-942875397-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Linkey, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Linkey.A, HKLM\SOFTWARE\LINKEY, , [386e1a391f5c013522862171877baa56], PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\LINKEY, , [3e68d2817cff96a0adfb7022e61c39c7], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK\General, , [1a8cf75c6a11e056f631335f71913dc3], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK, , [14926ce7bdbe78be49dfc9c9da281be5], PUP.Optional.Conduit.A, HKU\S-1-5-21-2433529201-776013581-942875397-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, , [acfad97ae69554e250d7803b5ba8bf41], PUP.Optional.Softonic.A, HKU\S-1-5-21-2433529201-776013581-942875397-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [9a0c351e89f2989e0927b8d616ecb64a], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\SettingsManagerIEHelper.DNSGuard, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\SettingsManagerIEHelper.DNSGuard.1, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SettingsManagerIEHelper.DNSGuard, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SettingsManagerIEHelper.DNSGuard.1, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKU\S-1-5-21-2433529201-776013581-942875397-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{54739D49-AC03-4C57-9264-C5195596B3A1}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA760BA8-5862-4BC5-9263-4452CBC0B264}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA760BA8-5862-4BC5-9263-4452CBC0B264}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B}, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Settings Manager, , [a2049eb55d1e9b9be350136706fc28d8], Registrierungswerte: 3 PUP.Optional.Linkey.A, HKLM\SOFTWARE\LINKEY|ie_jsurl, hxxp://app.linkeyproject.com/popup/IE/background.js, , [386e1a391f5c013522862171877baa56] PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\LINKEY|ie_jsurl, hxxp://app.linkeyproject.com/popup/IE/background.js, , [3e68d2817cff96a0adfb7022e61c39c7] PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK|browser, ie ff cr, , [14926ce7bdbe78be49dfc9c9da281be5] Registrierungsdaten: 0 (No malicious items detected) Ordner: 18 PUP.Optional.SystemK.A, C:\ProgramData\systemk, , [bee831226d0e6dc9a8277b15e61c837d], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\ChromeExtension, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\IEExtension, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.OpenCandy, C:\Users\Fuhrmann\AppData\Roaming\OpenCandy, , [9d09292a85f61a1c998f690af60cd62a], PUP.Optional.OpenCandy, C:\Users\Fuhrmann\AppData\Roaming\OpenCandy\86EAD3B6219E49CF91EBB8999BAC147D, , [9d09292a85f61a1c998f690af60cd62a], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\xpi, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\xpi\defaults, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\xpi\defaults\preferences, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE, , [3b6ba3b05f1cbf77e2d1a1d22bd704fc], PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE\CT1703539, , [3b6ba3b05f1cbf77e2d1a1d22bd704fc], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\content, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\content\js, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64, , [a2049eb55d1e9b9be350136706fc28d8], Dateien: 111 PUP.Optional.SystemK.A, C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe, , [fda94d064b3026109d381b60e1206f91], PUP.Optional.SystemK.A, C:\Program Files (x86)\Settings Manager\systemk\systemku.exe, , [2284bd9677043600ddf88cefc041f60a], PUP.Optional.SystemK.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg, , [d1d5c98ab6c5999d6372cdae827f7e82], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\IEExtension\iedll64.dll, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\IEExtension\iedll.dll, , [4f57d47fc4b7a591a416c6a4cc35a45c], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\SPStub.exe, , [555160f34536a492fc7d9d7fe819e41c], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\DLG_\requirements\SPIdentifier.exe, , [980eb89b3c3f68ceaf9e14f8fc057987], PUP.Optional.AztecMedia.A, C:\Users\Fuhrmann\AppData\Local\Temp\nshEB48.tmp\Helper.dll, , [6b3b292ad9a2f4421944d76de123f808], PUP.Optional.AztecMedia.A, C:\Users\Fuhrmann\AppData\Local\Temp\nshEB48.tmp\Starter.exe, , [71351e352e4dc67063ebb292c53f14ec], PUP.Optional.AztecMedia.A, C:\Users\Fuhrmann\AppData\Local\Temp\nsnC996.tmp\Helper.dll, , [cfd74e0592e937ffd98455ef956fd729], PUP.Optional.AztecMedia.A, C:\Users\Fuhrmann\AppData\Local\Temp\nsnC996.tmp\Starter.exe, , [436357fc017a44f2a0ae68dc13f1eb15], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\ctbe.exe, , [00a6124102793cfaa3e289953ac6f709], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\ffLogic.exe, , [3b6b90c36c0f52e479000616ed14ce32], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\ieLogic.exe, , [6e3896bd6e0d4cea42371efe1be6fc04], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\spff.exe, , [7f27054e54277db9b8c1b26ada2731cf], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\statisticsStub.exe, , [297db59e8bf0b87e6c92f115bc45cf31], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\stub.exe, , [b4f2a8ab03784de912ca8995f10fed13], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\is-4NBSR.tmp\IsoBuster_toolbar.exe, , [e5c174df2457e3533171e43a2ad624dc], PUP.Optional.Softonic.A, C:\Users\Fuhrmann\Downloads\SoftonicDownloader_fuer_tubebox.exe, , [9e08a9aa73088bab659b48d834cd3ec2], PUP.Optional.Bandoo, C:\Users\Fuhrmann\Downloads\iLividSetupV1.exe, , [3670044f94e745f1c2df23e6758c5ba5], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\Downloads\ExtremeFlashPlayer.exe, , [119558fbb8c32c0a96d12e0f38c827d9], PUP.Optional.Breitschopp, C:\Users\Fuhrmann\Downloads\tubebox_5.0(1).exe, , [2680d67d483389ad9dae211c25dfd030], PUP.Optional.Breitschopp, C:\Users\Fuhrmann\Downloads\tubebox_5.0.exe, , [dfc7f55e5229b383af9c7dc04db735cb], PUP.Optional.SystemK.A, C:\ProgramData\systemk\general.cfg, , [bee831226d0e6dc9a8277b15e61c837d], PUP.Optional.SystemK.A, C:\ProgramData\systemk\coordinator.cfg, , [bee831226d0e6dc9a8277b15e61c837d], PUP.Optional.SystemK.A, C:\ProgramData\systemk\S-1-5-21-2433529201-776013581-942875397-1000.cfg, , [bee831226d0e6dc9a8277b15e61c837d], PUP.Optional.DefaultSearch.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\searchplugins\default-search.xml, , [7135db78b1ca360007171c7669997987], PUP.Optional.DefaultSearch.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml, , [b6f00251b4c72412da45266c34ceb14f], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\log.log, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\Helper.dll, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\Uninstall.exe, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\ChromeExtension\ChromeExtension.crx, , [881ec88be398f640dfc61082c042e31d], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\searchplugins\conduit.xml, , [9f07a7ac1d5eda5c40789afa8b77bd43], PUP.Optional.OpenCandy, C:\Users\Fuhrmann\AppData\Roaming\OpenCandy\86EAD3B6219E49CF91EBB8999BAC147D\2877.ico, , [9d09292a85f61a1c998f690af60cd62a], PUP.Optional.OpenCandy, C:\Users\Fuhrmann\AppData\Roaming\OpenCandy\86EAD3B6219E49CF91EBB8999BAC147D\AVG923_p1v3.exe, , [9d09292a85f61a1c998f690af60cd62a], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\chromeid.txt, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\conduit.xml, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\CT1703539.xpi, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\setup.ini.txt, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\version.txt, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\xpi\install.rdf, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Local\Temp\ct1703539\xpi\defaults\preferences\defaults.js, , [04a24e0533489d99bce3e291d42e827e], PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE\CT1703539\UninstallerUI.exe, , [3b6ba3b05f1cbf77e2d1a1d22bd704fc], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\chrome.manifest, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\install.rdf, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\content\button.css, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\content\overlay.xul, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\content\js\common.js, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\content\js\LinkeyManager.js, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\bright_green_19_19.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\default_19_19.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\hard_green_19_19.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\icon.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\icon64.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\orange_19_19.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\red_19_19.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.Linkey.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\extensions\extension@linkeyproject.com\skin\yellow_19_19.png, , [30765bf8fb800a2caa5dbebc1be741bf], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\del_DM_DLL_nsc1984.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\del_DM_EXE_nsc1984.exe, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\del_mg_nsc1984.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\favicon.ico, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\Helper.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\Internet Explorer Settings.exe, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\syskldr.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\syskldr_u.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemk.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkbho.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemkbho.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkChrome.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkmgrc1.cfg, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\tbicon.exe, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trz5906.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trz6B7E.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trz6CB7.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trz6CD7.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trz6D07.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trz6DD3.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trzABF3.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\trzABF4.tmp, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\Uninstall.exe, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\del_DM_LL_nsc1984.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\del_DM_LL_nsi22C8.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\Internet Explorer Settings.exe, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\syskldr.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\syskldr_u.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemk.dll, , [a2049eb55d1e9b9be350136706fc28d8], PUP.Optional.DefaultSearch.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=318&src=ds&p=");), ,[4b5be1726d0eb97d0e3ec8b4df259e62] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.aflt", "babsst");), ,[aff7fe55cbb00432cb9624588c789b65] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.babTrack", "affID=107763");), ,[2086d182562563d36ef398e4fe0620e0] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.bbDpng", 30);), ,[1d895bf8a7d4ad891b46225ad82c2ad6] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltLng", "en");), ,[2e78153e9dde7eb80a57e29ab64ed927] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltSrch", true);), ,[c9dd3e1597e42a0c055c413bef1551af] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.hmpg", true);), ,[3e68fd56017afe387ee34f2dfc0815eb] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.id", "1456237b000000000000002710f26480");), ,[6541ea69ee8d082e5d0403799a6a9c64] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlDay", "15246");), ,[6b3b8ec599e2aa8cabb6e399689c0af6] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlRef", "sst");), ,[4b5be370eb90092dfc6590ec6a9ab848] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=1456237b000000000000002710f26480&tlver=1.4.35.10&affID=107763");), ,[fda93023d9a2a78f540dbac2c73d6b95] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastDP", 30);), ,[5a4ccf848deedd59134ef6869272ca36] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.4.35.101:43:20");), ,[9214f162bac143f382df5a2255af07f9] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTab", true);), ,[fcaa5af986f5a88e035e5d1f6c98b24e] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_ss&affID=107763&mntrId=1456237b000000000000002710f26480");), ,[aafc153e84f777bf6cf5e69641c3db25] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");), ,[cbdb470cf4878fa7aeb37c00bf45c33d] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prtnrId", "babylon");), ,[dacc084bfc7f7db9332ea4d852b207f9] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.smplGrp", "none");), ,[f4b2a4afaccf6dc9263bbbc15ba93cc4] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.srcExt", "ss");), ,[b9ed77dc6a11f3434120502c8e7642be] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.srchPrvdr", "Search the web (Babylon)");), ,[73331b38e09b3402ed7499e3887c7090] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrId", "base");), ,[aafc69eaeb90290d0b563b4153b19868] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsn", "1.4.35.10");), ,[f7afbc970a71ec4aa1c0a8d41aeaa35d] PUP.Optional.Babylon.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsnTs", "1.4.35.101:43:20");), ,[b2f4aba892e9ba7c273aa2dae51f17e9] PUP.Optional.Conduit.A, C:\Users\Fuhrmann\AppData\Roaming\Mozilla\Firefox\Profiles\6jan9tz3.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1703539&CUI=UN35270952459756389&UM=2&SearchSource=3&q={searchTerms}");), ,[b2f4183b0576a88edaecf4888084f60a] Physische Sektoren: 0 (No malicious items detected) (end) |
hi, ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST.txt FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014 --- --- --- --- --- --- --- --- --- --- --- --- Addition.txt Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-05-2014 sysapcrt.dll jedll.dll etc. Was ist das? Als Hersteller der infizierten DLLs wird genannt: PUP.Optional.Linkey.A PUP.Optional.SystemK.A etc Hat jemand einen Hinweis? |
Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Scan mit Combofix
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 17:27 Uhr. |
Copyright ©2000-2025, Trojaner-Board