![]() |
Durch Biet-o-matic jetzt statt google startseite jetzt webssearches Hallo, wollte mir Biet-o-matic kostenfrei runterladen, mein avast warnte mich, trotzdem kommt jetzt nach aufrufen der startseite nicht google sondern: hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974 Was kann ich tun? |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2014 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-12-2014 |
Lade Dir bitte von hier ![]()
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 18.12.2014 Suchlauf-Zeit: 21:27:24 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2014.12.18.05 Rootkit Datenbank: v2014.12.14.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Renchen72 Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 360179 Verstrichene Zeit: 18 Min, 31 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 628, Löschen bei Neustart, [f7563a2a0577a690ac66b7095ea38977] Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 9 PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [f7563a2a0577a690ac66b7095ea38977], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [222b96ce453758de0628923aef1528d8], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [28252d373f3dfb3b9a48d1b8a0633ec2], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [cc8178ece7950b2bd006eacd28dca759], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [84c9d58f0973f244e1e38cda32d16c94], PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [2f1e1e46f48867cf021784d821e29e62], PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [e86592d27507b58141d928341ee5e21e], PUP.Optional.Qone8, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [0647f272532932044b8ad3e4cc389b65], PUP.Optional.FastStart.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [69e4eb79fe7ec3739474a2c24fb427d9], Registrierungswerte: 3 PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Renchen72\AppData\Roaming\Mozilla\Firefox\Profiles\l8ruh2za.default-1402728366372\extensions\faststartff@gmail.com, In Quarantäne, [212c79eb057788ae6fd929a28a7a7a86] PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [84c9d58f0973f244e1e38cda32d16c94] PUP.Optional.FastStart.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [69e4eb79fe7ec3739474a2c24fb427d9] Registrierungsdaten: 15 PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[a8a5491b027a74c2d6b43138e124a060] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[9bb27aeade9e6dc97417cd9c91740bf5] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[9db0f56fb2ca5cda532fa0c942c32dd3] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[c38ab6ae2458a195e39d8adf0bfa0ef2] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[3c11b2b289f3bb7b5a2ad297ce378c74] PUP.Optional.WebSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[74d9df85d3a9c47207967ef78a7b3ac6] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[7bd202624d2f66d0abdf99d061a45fa1] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[81ccc2a29ce0a096800bf1783cc9eb15] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[f35af272374594a2aed4bbae1fe65fa1] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[53fad68e3844a195f987c8a19a6b8a76] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[9cb18cd892ea86b0651fed7ca36235cb] PUP.Optional.WebSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[ea635d079fddbb7b633a175e36cfa25e] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[0449c99b116b9e987b28f67d18eda759] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[73da382c9be16bcb1174da8fcd385ba5] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[56f7ea7ae99356e0fa87b6b308fd3dc3] Ordner: 27 PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [48053d271765c472c58066d1d42f19e7], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [48053d271765c472c58066d1d42f19e7], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], Dateien: 50 PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [f7563a2a0577a690ac66b7095ea38977], PUP.Optional.DownloadGuide, C:\$Recycle.Bin\S-1-5-21-3133595154-2642610443-1825705747-1001\$R3X1DM4.exe, In Quarantäne, [c08dacb8ceaea294e0dcd3251be65fa1], PUP.Optional.SupTab.A, C:\Users\Renchen72\AppData\Local\Temp\~dl7126\~dljyb\tmp\SupTab_v5.8.8.777_noblank.exe, In Quarantäne, [e6679dc795e7171f2abf84dcba46d927], PUP.Optional.WindowsProtectManger.A, C:\Users\Renchen72\AppData\Local\Temp\~dl7126\~dljyb\tmp\wpm_v20.0.0.1277_.exe, In Quarantäne, [103d065e43396dc9759d2799c140a858], PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [470683e1ed8f1620f9eb078252b12dd3], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [48053d271765c472c58066d1d42f19e7], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 18.12.2014 Suchlauf-Zeit: 21:27:24 Logdatei: mbam1.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2014.12.18.05 Rootkit Datenbank: v2014.12.14.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Renchen72 Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 360179 Verstrichene Zeit: 18 Min, 31 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 628, Löschen bei Neustart, [f7563a2a0577a690ac66b7095ea38977] Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 9 PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [f7563a2a0577a690ac66b7095ea38977], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [222b96ce453758de0628923aef1528d8], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [28252d373f3dfb3b9a48d1b8a0633ec2], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [cc8178ece7950b2bd006eacd28dca759], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [84c9d58f0973f244e1e38cda32d16c94], PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [2f1e1e46f48867cf021784d821e29e62], PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [e86592d27507b58141d928341ee5e21e], PUP.Optional.Qone8, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [0647f272532932044b8ad3e4cc389b65], PUP.Optional.FastStart.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [69e4eb79fe7ec3739474a2c24fb427d9], Registrierungswerte: 3 PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Renchen72\AppData\Roaming\Mozilla\Firefox\Profiles\l8ruh2za.default-1402728366372\extensions\faststartff@gmail.com, In Quarantäne, [212c79eb057788ae6fd929a28a7a7a86] PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [84c9d58f0973f244e1e38cda32d16c94] PUP.Optional.FastStart.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [69e4eb79fe7ec3739474a2c24fb427d9] Registrierungsdaten: 15 PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[a8a5491b027a74c2d6b43138e124a060] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[9bb27aeade9e6dc97417cd9c91740bf5] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[9db0f56fb2ca5cda532fa0c942c32dd3] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[c38ab6ae2458a195e39d8adf0bfa0ef2] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[3c11b2b289f3bb7b5a2ad297ce378c74] PUP.Optional.WebSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[74d9df85d3a9c47207967ef78a7b3ac6] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[7bd202624d2f66d0abdf99d061a45fa1] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[81ccc2a29ce0a096800bf1783cc9eb15] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[f35af272374594a2aed4bbae1fe65fa1] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[53fad68e3844a195f987c8a19a6b8a76] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[9cb18cd892ea86b0651fed7ca36235cb] PUP.Optional.WebSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974&q={searchTerms}),Ersetzt,[ea635d079fddbb7b633a175e36cfa25e] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[0449c99b116b9e987b28f67d18eda759] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[73da382c9be16bcb1174da8fcd385ba5] PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3133595154-2642610443-1825705747-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418767969&from=cvs&uid=WDCXWD5000BPKT-75PK4T0_WD-WXJ1A81M1974M1974),Ersetzt,[56f7ea7ae99356e0fa87b6b308fd3dc3] Ordner: 27 PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [48053d271765c472c58066d1d42f19e7], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [48053d271765c472c58066d1d42f19e7], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], Dateien: 50 PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [f7563a2a0577a690ac66b7095ea38977], PUP.Optional.DownloadGuide, C:\$Recycle.Bin\S-1-5-21-3133595154-2642610443-1825705747-1001\$R3X1DM4.exe, In Quarantäne, [c08dacb8ceaea294e0dcd3251be65fa1], PUP.Optional.SupTab.A, C:\Users\Renchen72\AppData\Local\Temp\~dl7126\~dljyb\tmp\SupTab_v5.8.8.777_noblank.exe, In Quarantäne, [e6679dc795e7171f2abf84dcba46d927], PUP.Optional.WindowsProtectManger.A, C:\Users\Renchen72\AppData\Local\Temp\~dl7126\~dljyb\tmp\wpm_v20.0.0.1277_.exe, In Quarantäne, [103d065e43396dc9759d2799c140a858], PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [470683e1ed8f1620f9eb078252b12dd3], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [48053d271765c472c58066d1d42f19e7], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [5df0e77d0a722e08fe5351ecc04317e9], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end)AdwCleaner Logfile: Code: # AdwCleaner v4.105 - Bericht erstellt am 18/12/2014 um 21:57:37 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows 8.1 Pro x64 Ran by Renchen72 on 18.12.2014 at 22:01:37,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{449D0D6E-2412-4E61-B68F-1CB625CD9E52} Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52} Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{449D0D6E-2412-4E61-B68F-1CB625CD9E52} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\pcdr" Successfully deleted: [Folder] "C:\Users\Renchen72\AppData\Roaming\pcdr" ~~~ FireFox Emptied folder: C:\Users\Renchen72\AppData\Roaming\mozilla\firefox\profiles\l8ruh2za.default-1402728366372\minidumps [23 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18.12.2014 at 22:09:06,18 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2014 |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=a549ec4d5d412a47b5483f23585cc11e # engine=21638 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-12-20 08:36:56 # local_time=2014-12-20 09:36:56 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 92 660369 183485106 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 3199583 43945909 0 0 # scanned=232708 # found=4 # cleaned=0 # scan_time=41249 sh=A82C9997BED4FAF04183B6900595DFF29782D979 ft=1 fh=cb8f9c5cda147f68 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\RENCHE~1\AppData\Local\Temp\Security Systems\Setup.exe.vir" sh=24EACADAF8910146B00A3B6146FAD19E11BFF03B ft=1 fh=5e1dc8d93e2d8e01 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-egypt.exe" sh=34D77A23AA7C7648948E4BFAB31F33F517A785DC ft=1 fh=11cdaad78b073df2 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-japan.exe" sh=E5A3C100D2D0FD94482783AF2B2FF94CDFC9923F ft=1 fh=a0ddd0619a504a2e vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe" Results of screen317's Security Check version 0.99.93 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 16.0.0.235 Adobe Reader XI Mozilla Firefox (34.0.5) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2014 |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Program Files (x86)\FreeTime Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Hallo, irgendwie geht das nicht, es kommt folgender fehlertext: Error9878 (File"C:\Users\Renchen\Downloads\FRST64.exe") Error in Expressions Was soll ich tun? |
FRST löschen und neu laden :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:45 Uhr. |
Copyright ©2000-2025, Trojaner-Board