Alphazaboo | 06.01.2015 13:03 | Der MBAM-log wurde gespeichert, danach wollte MBAM neustarten und seit da an komm ich im normalen Modus nicht mehr als Admin rein.
Also abgesichert geht noch und als Gast geht auch, aber als Admin ist das Bild gelb und es passiert nichts mehr.
Und der log den ich gepostet habe ist das was MBAM mir erstellt hat und abgespeichert... Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 04.01.2015
Suchlauf-Zeit: 20:39:36
Logdatei: mbamlog 2.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.04.12
Rootkit Datenbank: v2014.12.30.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Kraul
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 434881
Verstrichene Zeit: 30 Min, 35 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 70
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [313b4ca74e3bc373163089909b68bc44],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [313b4ca74e3bc373163089909b68bc44],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}, In Quarantäne, [7eeecf24cbbeae88286930b653afc43c],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [cba1e0132465af8770d634e49370ed13],
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [cba1e0132465af8770d634e49370ed13],
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [cba1e0132465af8770d634e49370ed13],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [4b2140b34742a096f253cb4dd82b728e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}, In Quarantäne, [4b2140b34742a096f253cb4dd82b728e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [4b2140b34742a096f253cb4dd82b728e],
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [4b2140b34742a096f253cb4dd82b728e],
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [4b2140b34742a096f253cb4dd82b728e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, In Quarantäne, [2e3ee60d4c3d4aec143140d98d767e82],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [105cf201c9c0ff37aa3029b6956d3ec2],
PUP.Optional.SweetPacks.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EEE6C360-6118-11DC-9C72-001320C79847}, Löschen bei Neustart, [76f6dc1797f22a0ca12ded2fb44fae52],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EEE6C360-6118-11DC-9C72-001320C79847}, In Quarantäne, [76f6dc1797f22a0ca12ded2fb44fae52],
PUP.Optional.Iminent.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}, In Quarantäne, [0a62c62d92f775c14b8e57888979817f],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}, In Quarantäne, [501c45aee3a6af87c179a1785ea5e51b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [44283bb86f1a0a2ce5a7a8717d865fa1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [b3b920d3474251e5fc91a376669daa56],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [0c6000f38cfd38fe33d812831ee58e72],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [d09cfcf76d1cfe389785d3d58a79c33d],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SweetIM, In Quarantäne, [c2aa9a59b6d3e74f7392fe6727dc966a],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\DELTA\DELTA\Instl, In Quarantäne, [0468b83b8603ca6c5700477be2228f71],
PUP.Optional.Movie2kDownloader.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\blaofbhgbmeikidhlkmjhbkbfohpgekf, In Quarantäne, [33390ae96524ea4cbb6199ce1de603fd],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [fd6feb08ef9aef4767a4f79e758e24dc],
PUP.Optional.Perion.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jifflliplgeajjdhmkcfnngfpgbjonjg, In Quarantäne, [0a62896a9dec38fe2971a2d236cd37c9],
PUP.Optional.SweetIM.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SweetIM, Löschen bei Neustart, [5319f4ffd0b9d3630afae77e4ab93cc4],
PUP.Optional.InstallBrain.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT, Löschen bei Neustart, [9ad2688b3c4d003695aad4f0d62ef709],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Löschen bei Neustart, [0b61b14291f812245c39348ad430a65a],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SweetIM, Löschen bei Neustart, [3d2f6a892663df573cc8adb8d0338d73],
PUP.Optional.Conduit.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, Löschen bei Neustart, [d79541b29beead8987342e3b28db23dd],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, Löschen bei Neustart, [d597bb38880154e2282ff971af54e719],
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA, Löschen bei Neustart, [a8c4e90ac5c4da5ce4e1b407b94b59a7],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [9cd00ae9c0c9979fc97e6756fb09c13f],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Löschen bei Neustart, [006cd221ccbd4ceae783caf6bb49926e],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, In Quarantäne, [92da866d494015215dc77a43ab599c64],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [81eb43b0a1e8a195f72cba034bb9ed13],
PUP.Optional.Iminent.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, In Quarantäne, [eb813bb83f4ab68063ba84248380f30d],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SweetIM, In Quarantäne, [472541b25336f640c242cb9a996a4bb5],
PUP.Optional.Conduit.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, In Quarantäne, [0f5d7f748dfc1a1c308be485e1226f91],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [d09c2fc41772fc3a1641a8c242c1b050],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, In Quarantäne, [c6a6658e46435dd9e684cdf3f1131be5],
PUP.Optional.InstallBrain.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT, In Quarantäne, [9bd110e3f594989ea09f537140c45aa6],
Registrierungswerte: 18
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{82E1477C-B154-48D3-9891-33D83C26BCD3}, Delta Toolbar, In Quarantäne, [cba1e0132465af8770d634e49370ed13]
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1}, In Quarantäne, [fd6fdb186d1c0e28c0a7756dc141ae52],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1}, øË?Ã?ëöüâ?F¼;ê¼rqî±, In Quarantäne, [fd6fdb186d1c0e28c0a7756dc141ae52]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [dd8f47ace3a61323a89e997f679c27d9],
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [a1cb5f94345537ffb6c7f6e9b64c1de3],
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [a1cb5f94345537ffb6c7f6e9b64c1de3]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [a1cb5f94345537ffb6c7f6e9b64c1de3]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [254748abbecb93a36914736ccb3750b0],
PUP.Optional.Incredibar, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [d993d41f7712aa8c01a0a32534d0f10f]
PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [511b6c870683c1754c5577510cf849b7]
PUP.Optional.InstallBrain.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT|URL, MYSTART, Löschen bei Neustart, [9ad2688b3c4d003695aad4f0d62ef709]
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|tlbrSrchUrl, Löschen bei Neustart, [a8c4e90ac5c4da5ce4e1b407b94b59a7],
PUP.Optional.Delta.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|lastB, hxxp://www2.delta-search.com/?affID=121299&tt=050412_30b&babsrc=HP_ss&mntrId=20B474DE2B6FEAD2, Löschen bei Neustart, [7cf0d023e6a37fb73ed5ad179c68e41c]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1J1RtGtDtH1S1P1FtI0QtG1R, Löschen bei Neustart, [9cd00ae9c0c9979fc97e6756fb09c13f]
PUP.BProtector, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://www2.delta-search.com/?affID=121299&tt=050412_30b&babsrc=HP_ss&mntrId=20B474DE2B6FEAD2, Löschen bei Neustart, [58148e65f49521154adbd0ed83810000]
PUP.BProtector, HKU\S-1-5-21-1910688198-3369152459-1835389315-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [88e40ae99decf6402501ba03d62e8b75]
PUP.BProtector, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, In Quarantäne, [e488767d642501352ef8e9d40103847c],
PUP.Optional.InstallBrain.A, HKU\S-1-5-21-1910688198-3369152459-1835389315-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT|URL, MYSTART, In Quarantäne, [9bd110e3f594989ea09f537140c45aa6]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 9
PUP.Optional.Delta.A, C:\Users\Kraul\AppData\Roaming\Delta, In Quarantäne, [bcb0658e2c5d9e9876507942877d9769],
PUP.Optional.Iminent.A, C:\Users\Gast\AppData\Roaming\Iminent\Mediator, In Quarantäne, [fc7001f297f2ff373ec655d88182758b],
PUP.Optional.Iminent.A, C:\Users\Gast\AppData\Roaming\Iminent\Mediator\Datas, In Quarantäne, [fc7001f297f2ff373ec655d88182758b],
PUP.Optional.Datamngr.A, C:\Users\Kraul\AppData\LocalLow\DataMngr, In Quarantäne, [511b05ee4d3c94a28de30a298c77619f],
PUP.Optional.SearchQu.A, C:\Users\Kraul\AppData\LocalLow\searchquband, In Quarantäne, [a0ccf9fa0188fa3c00d768d645be22de],
PUP.Optional.SpecialSavings.A, C:\Users\Kraul\AppData\Roaming\SpecialSavings, In Quarantäne, [0369f9fa3851f83e997a92ad2bd8c13f],
PUP.Optional.IBUpdater.A, C:\ProgramData\IBUpdaterService, In Quarantäne, [da928b68aedb0333bcfaf455bc47a55b],
PUP.Optional.Perion.A, C:\Program Files (x86)\Perion, In Quarantäne, [6efe34bfcabf8aac6278aba7db28c838],
PUP.Optional.Perion.A, C:\Program Files (x86)\Perion\NewTab, In Quarantäne, [6efe34bfcabf8aac6278aba7db28c838],
Dateien: 13
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.16.16\deltaTlbr.dll, In Quarantäne, [cba1e0132465af8770d634e49370ed13],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.16.16\bh\delta.dll, In Quarantäne, [4b2140b34742a096f253cb4dd82b728e],
PUP.Optional.BabSolution.A, C:\Users\Kraul\AppData\Roaming\BabSolution\Shared\BUSolution.dll, In Quarantäne, [8ddfaa4917729c9a0aaf41ebaa5740c0],
PUP.BundleInstaller.VG, C:\Program Files (x86)\vGrabber-software\Uninstall.exe, In Quarantäne, [44288b68aadf4de92f6835740ff129d7],
PUP.Optional.Babylon.A, C:\Windows\System32\Tasks\EPUpdater, In Quarantäne, [1458f4ffabde94a20ad5ccb89b6818e8],
PUP.Optional.Delta.A, C:\Users\Kraul\AppData\Roaming\Delta\sqlite3.dll, In Quarantäne, [bcb0658e2c5d9e9876507942877d9769],
PUP.Optional.Iminent.A, C:\Users\Gast\AppData\Roaming\Iminent\Mediator\Datas\globalcache.dat, In Quarantäne, [fc7001f297f2ff373ec655d88182758b],
PUP.Optional.Iminent.A, C:\Users\Gast\AppData\Roaming\Iminent\Mediator\Datas\user.dat, In Quarantäne, [fc7001f297f2ff373ec655d88182758b],
PUP.Optional.Datamngr.A, C:\Users\Kraul\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}, In Quarantäne, [511b05ee4d3c94a28de30a298c77619f],
PUP.Optional.SpecialSavings.A, C:\Users\Kraul\AppData\Roaming\SpecialSavings\SpecialSavings.crx, In Quarantäne, [0369f9fa3851f83e997a92ad2bd8c13f],
PUP.Optional.IBUpdater.A, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [da928b68aedb0333bcfaf455bc47a55b],
PUP.Optional.Perion.A, C:\Program Files (x86)\Perion\NewTab\data.txt, In Quarantäne, [6efe34bfcabf8aac6278aba7db28c838],
PUP.Optional.Perion.A, C:\Program Files (x86)\Perion\NewTab\newTab.crx, In Quarantäne, [6efe34bfcabf8aac6278aba7db28c838],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Sooo... habe jetzt Malware den Autostart untersagt und siehe da!
Ich komme jetzt wieder als admin im normalmodus rein... |