sani1008 | 19.08.2014 07:29 | Virenbefall laut Malwarebytes Hey!
Ich habe vor ca. einer Woche meinen PC wegen einem Virus neu aufgesetzt. Da Malwarebytes jetzt schon wieder Malware gefunden hab dachte ich mir ihr könntet mir ihr evtl. bei der Entfernung helfen. Hier mal der Malwarebytes Log: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.08.2014
Suchlauf-Zeit: 08:22:08
Logdatei: log.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.19.03
Rootkit Datenbank: v2014.08.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Anton Sauer
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 280462
Verstrichene Zeit: 2 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 5
PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, , [c6a99335daa1cc6a92651b7ccd34bb45],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-645361177-2524832617-178552483-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [93dc23a5a8d369cd419f650737cbd927],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, , [afc0b81017642b0b43fd00ec1ce6ea16],
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, , [5f107553cead979ff58744a1a65cc838],
Registrierungswerte: 2
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, , [afc0b81017642b0b43fd00ec1ce6ea16]
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\Windows\system32\drivers\SPPD.sys, , [5f107553cead979ff58744a1a65cc838]
Registrierungsdaten: 3
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll),,[ee8116b25f1c5adc8b6cd1c6d0313fc1]
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll),,[422d4f79a4d7b77faf48c5d2fd04ed13]
PUP.Optional.Trovi.A, HKU\S-1-5-21-645361177-2524832617-178552483-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M4F6E58A8-FF77-47DC-9658-158FC79FF32C&SearchSource=55&CUI=&UM=6&UP=SPBC51B106-160F-43D8-9855-0095717ED64A&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M4F6E58A8-FF77-47DC-9658-158FC79FF32C&SearchSource=55&CUI=&UM=6&UP=SPBC51B106-160F-43D8-9855-0095717ED64A&SSPV=),,[5b14b018f08ba69089b8aa2133d11de3]
Ordner: 23
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\SearchProtect, , [acc3c305cdaea591172df4db986a2ed2],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\SearchProtect\SearchProtect, , [acc3c305cdaea591172df4db986a2ed2],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\SearchProtect\SearchProtect\rep, , [acc3c305cdaea591172df4db986a2ed2],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\SearchProtect\SearchProtect\STG, , [acc3c305cdaea591172df4db986a2ed2],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\SearchProtect\UI, , [acc3c305cdaea591172df4db986a2ed2],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\SearchProtect\UI\rep, , [acc3c305cdaea591172df4db986a2ed2],
Dateien: 79
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, , [c6a99335daa1cc6a92651b7ccd34bb45],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, , [3d324b7d047773c330c7ddba58a97e82],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, , [9ed17454abd052e4896ee4b33cc5a45c],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll, , [ee8116b25f1c5adc8b6cd1c6d0313fc1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, , [422d4f79a4d7b77faf48c5d2fd04ed13],
PUP.Optional.SearchProtect.A, C:\Users\Anton Sauer\AppData\Local\Temp\nsa6DEF.tmp, , [ff7087416e0dfe3816e1e9aee21f0ff1],
PUP.Optional.Conduit.A, C:\Users\Anton Sauer\AppData\Local\Temp\nsq1BAC.exe, , [e788c503611a69cd59775d30da27f709],
PUP.Optional.Conduit.A, C:\Users\Anton Sauer\AppData\Local\Temp\nsq41C4.exe, , [d9969d2b2457280e10c0038a798819e7],
PUP.Optional.Conduit.A, C:\Users\Anton Sauer\AppData\Local\Temp\sp-downloader.exe, , [89e66167215a6bcb66b3e04815ec8c74],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\SPVCLdr64.dll, , [9cd356723a41bc7a04f39ef944bd718f],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, , [8ce3deea24579c9a826e3bf4719306fa],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, , [8ce3deea24579c9a826e3bf471 Ich sage dann mal:dankeschoen: im Voraus
Gruss |