MBAM Log - wirklich Schadeinträge? Hallo,
habe auf dem relativ neuen Laptop meines Opas eine MBAM-Überprüfung gestartet.
Er hat ziemlich viel gefunden, allerdeings auch Einträge die meineserachtens völlig normale uninfizierte Dateien sind (zB TeamViewer Insaller).
Könnt ihr mir sagen was ich mit den gefundenen Objekten machen soll?
Möchte nicht einfach so Registry-Einträge löschen wenns eventuell falsch ist ...
Vielen Dank im Voraus Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 14.08.2014
Scan Time: 20:36:34
Logfile: MBAM.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.14.09
Rootkit Database: v2014.08.04.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Kurt
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 386153
Time Elapsed: 16 min, 52 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1292, , [bcc586401566e353205682df6c95946c]
Modules: 0
(No malicious items detected)
Registry Keys: 27
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, , [bcc586401566e353205682df6c95946c],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, , [3a4702c41f5cf244478306a070924bb5],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, , [3a4702c41f5cf244478306a070924bb5],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [3a4702c41f5cf244478306a070924bb5],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [3a4702c41f5cf244478306a070924bb5],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, , [3a4702c41f5cf244478306a070924bb5],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [4041ad192f4cfc3a6562b8ee0002d12f],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, , [4041ad192f4cfc3a6562b8ee0002d12f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, , [b4cdd7ef5c1f85b1791bb9eaa35f9769],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, , [c4bdae18b4c7c86ee5b0d1d21de529d7],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, , [f58ce3e3bdbe3bfb1a0f079c33cf5ca4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [4a37f4d2fa81f93d84dfa0ce986a9868],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gw64, , [651c16b01a61a393da11657b21e1758b],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64, , [5d24d5f1bbc09e980cdf1ac61fe3d828],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{c8905eec-9eab-447c-84a8-9e864d454523}Gw64, , [ea97cdf9f08b84b2797290509d6522de],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, , [3f42d8eefc7f84b29d24cd3e867dc937],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent, , [2a579f27611ab18598570f263cc86d93],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\DatamngrCoordinator.exe, , [265bf4d281fa5bdb2805647f8b77639d],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, , [275a02c4fb80ed49e2df59b23fc4cf31],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsProtectManger, , [61208a3c5328f442f85fcb1b10f20cf4],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, , [90f1ac1ab2c975c16d0b36ff8b7932ce],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent, , [c1c00cba94e7c76f648b2015976db54b],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\DatamngrCoordinator.exe, , [453cb90d5328f73f2706ebf89f630bf5],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [2d54349289f2290d3a925eac82814db3],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [047dad197209fa3c25bd1a06c83c8f71],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, , [5b2609bd55264fe7bd560a00aa59728e],
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, , [d6abcafcd0abc76f03fe5c80857d34cc],
Registry Values: 3
PUP.Optional.InstallCore.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, , [047dad197209fa3c25bd1a06c83c8f71]
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, , [5b2609bd55264fe7bd560a00aa59728e]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, IrsSF, , [d6abcafcd0abc76f03fe5c80857d34cc]
Registry Data: 7
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404068121&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WX11E83FX113FX113&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404068121&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WX11E83FX113FX113&q={searchTerms}),,[9ee310b65724f442f4b05878739147b9]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1404068121&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WX11E83FX113FX113&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404068121&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WX11E83FX113FX113&q={searchTerms}),,[6b16d3f3d1aa4ee87311566fd62ef808]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}),,[ff825f67f883de581d428343ba4aab55]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}),,[0b76685e7a011f17fe60b01622e2c33d]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}),,[39489a2c49322c0af26f30969f658080]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}),,[265b8f371c5f63d3ce944b7bb94b5aa6]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-743632298-2465268506-2955620433-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HYnEq6CImE5NvBzDGGAoN4IYnvfOeHlpRaPODw1VaLV52Ng82BpWUEqtsTATHDMIPIfLW6ziROBhVyZleV3aQFIslrmMLfzGRiNuAqBIuoEUtC3KpNdRhiIRBJV-N60qa9ktQbGywu8dHU0N-41ByQ,&q={searchTerms}),,[a6db05c1463551e55508a91d669e57a9]
Folders: 4
Rogue.Multiple, C:\ProgramData\374311380, , [0e73f8ce8bf0b5815ea7d4d3f70b59a7],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [61205a6cdd9ed4622d45f2da32d0916f],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [61205a6cdd9ed4622d45f2da32d0916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [9ae7d6f0c1ba23137596bc193ac8cf31],
Files: 20
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, , [bcc586401566e353205682df6c95946c],
PUP.Optional.Conduit.A, C:\Users\Kurt\AppData\Local\Temp\nsx7921.exe, , [8100bc0a9cdf1c1aec787e0f27dad22e],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\installer_adobe_flash_player_German (1).exe, , [a1e0c105d0abaa8c27bb6834de23fa06],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\installer_adobe_flash_player_German.exe, , [e79ab6104e2ddf578939fcc2c1438c74],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\openoffice_setup (1).exe, , [6b167056a2d95ed809e0259b768e04fc],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\openoffice_setup (2).exe, , [334eae187902fd39e5042e9251b33ac6],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\openoffice_setup (3).exe, , [255c9c2a0675bf776d7c507029db5ca4],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\openoffice_setup.exe, , [85fc6a5c7704be78ba2f1aa654b0c33d],
PUP.Optional.OutBrowse, C:\Users\Kurt\Downloads\Skype.exe, , [d8a981458cef78be7fea11840cf58d73],
PUP.Optional.Firseria, C:\Users\Kurt\Downloads\TeamViewer.exe, , [9ce5279ff08b3501d10151a58f7524dc],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\windows-media-player-download_setup (1).exe, , [1f6206c04b300135e702635d19ebc23e],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\windows-media-player-download_setup (2).exe, , [3b463195adcedb5bb039d9e7ed170af6],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\windows-media-player-download_setup (3).exe, , [f988d8eedc9f93a34f9a02be7490cf31],
PUP.Optional.InstallCore, C:\Users\Kurt\Downloads\windows-media-player-download_setup.exe, , [b1d0c7ff09729c9a45a400c0ab596d93],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gw64.sys, , [651c16b01a61a393da11657b21e1758b],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64.sys, , [5d24d5f1bbc09e980cdf1ac61fe3d828],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{c8905eec-9eab-447c-84a8-9e864d454523}Gw64.sys, , [ea97cdf9f08b84b2797290509d6522de],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [61205a6cdd9ed4622d45f2da32d0916f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, , [9ae7d6f0c1ba23137596bc193ac8cf31],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, , [9ae7d6f0c1ba23137596bc193ac8cf31],
Physical Sectors: 0
(No malicious items detected)
(end) |