weiterhin ein großes dankeschön für deine hilfe, schrauber!
hier die mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.05.2015
Suchlauf-Zeit: 09:41:40
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.22.06
Rootkit Datenbank: v2015.05.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Sören
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 393519
Verstrichene Zeit: 30 Min, 25 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 7
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\shopperz, In Quarantäne, [842a98fe8208a98d0f53b13b06fd56aa],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\shopperz, In Quarantäne, [b4fa8c0ad1b99d99d8002cb230d3ed13],
PUP.Optional.HDVideoCodec.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kpkbnefaikfaeadgidhpoanckoiaheli, In Quarantäne, [afff791d11793ff70d0a3faca16229d7],
PUP.Optional.Shopperz.A, HKU\S-1-5-18\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [b9f5cbcb0783310552b2b72c19ea09f7],
PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [e2cc1f7711798caa3aca4e95956ed42c],
PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [8826375f8505162064a05c879f646b95],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5081D2D4-1637-404c-B74F-50526718257D}_is1, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 14
PUP.Optional.HDVidCodec.A, C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com, In Quarantäne, [812d9303a2e83ff7651168d9ef16dd23],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content\libraries, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content\resources, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\locale, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\locale\en-US, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\skin, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\defaults, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\defaults\preferences, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\libraries, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\resources, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
Dateien: 31
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\garrus.dll, In Quarantäne, [ad015d39e9a18da9a334540ef61018e8],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\gcpum.dll, In Quarantäne, [f1bdecaa2c5ebc7a6c6b74eeb551d729],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\kasumi32.dll, In Quarantäne, [9618e0b63555be78a0371949976f29d7],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\kasumi64.dll, In Quarantäne, [a30bb7df4c3e221490474b17d92dd927],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\krios.dll, In Quarantäne, [c6e83a5ce3a76ec88255372bef1711ef],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\liara.dll, In Quarantäne, [9c124f47662461d5c7107be7e5217c84],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\liara64.dll, In Quarantäne, [7c32b5e103879b9bb0270d555da9da26],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\nfregdrv64.exe, In Quarantäne, [842ab2e4602aaa8cd106402231d5936d],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\tsoni.dll, In Quarantäne, [5e507422ed9d95a182556af8bb4b39c7],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\tsoni64.dll, In Quarantäne, [5f4f34629af08fa76572c89ac64010f0],
PUP.Optional.Shopperz.A, C:\Windows\System32\Tasks\gtaUpt, In Quarantäne, [4866d1c590fa56e0d44e9c48a95acc34],
PUP.Optional.HDVidCodec.A, C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\nd54beis.default\extensions\hdvc@hdvc.com.xpi, In Quarantäne, [7a34a1f56c1e2115db11eb040af9669a],
PUP.Optional.HDVidCodec.A, C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\HDVidCodec.lnk, In Quarantäne, [812d9303a2e83ff7651168d9ef16dd23],
PUP.Optional.HDVidCodec.A, C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\Uninstall.lnk, In Quarantäne, [812d9303a2e83ff7651168d9ef16dd23],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\tree.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\unins000.dat, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\unins000.exe, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\zaeed.bat, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome.manifest, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\icon.png, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\install.rdf, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\{5081D2D4-1637-404c-B74F-50526718257D}.xpi, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content\main.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content\main.xul, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content\libraries\DataExchangeScript.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\content\resources\LocalScript.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\locale\en-US\overlay.dtd, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\chrome\skin\overlay.css, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\Firefox\defaults\preferences\defaults.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\libraries\DataExchangeScript.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\resources\LocalScript.js, In Quarantäne, [9d1156405337c670fa34557cdb283fc1],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
hier die adwcleaner.txt Code:
# AdwCleaner v4.205 - Bericht erstellt 24/05/2015 um 10:47:51
# Aktualisiert 21/05/2015 von Xplode
# Datenbank : 2015-05-21.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Sören - SÖREN-LAPTOP
# Gestarted von : C:\Users\Sören\Desktop\adwcleaner_4.205.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\Trymedia
Ordner Gelöscht : C:\Program Files (x86)\Convertor
Ordner Gelöscht : C:\Program Files (x86)\Winsta
Ordner Gelöscht : C:\Users\SREN~1\AppData\Local\Temp\Video Converter
Ordner Gelöscht : C:\Users\Sören\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Datei Gelöscht : C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\nd54beis.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : Convertor
Task Gelöscht : gtaUpt
Task Gelöscht : WinKit
Task Gelöscht : Winsta Update
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CF50C82-4C4B-43E9-B1B2-15CB1BD0C193}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gelöscht : HKLM\SOFTWARE\Trymedia Systems
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
-\\ Mozilla Firefox v38.0.1 (x86 de)
-\\ Google Chrome v43.0.2357.65
*************************
AdwCleaner[R0].txt - [2509 Bytes] - [24/05/2015 10:31:04]
AdwCleaner[S0].txt - [2375 Bytes] - [24/05/2015 10:47:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2434 Bytes] ##########
und hier die jrt.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.8 (05.23.2015:2)
OS: Windows 7 Home Premium x64
Ran by S”ren on 24.05.2015 at 11:29:56,46
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{0A97B850-2878-40EC-81DE-859A3F36D2DF}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{3F5D07B7-B7E8-4350-B358-7E5C2D97DF75}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{5655F8CE-7ACD-4279-BDD0-98F90E846931}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{60F06CD7-6E19-4636-88C6-97D639400446}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{82838B63-E9F1-4B03-AF76-D34F33EF9DAA}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{86E77544-5935-4161-BCE2-0A8E0575BFEC}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{87763A16-B14C-4B55-8204-5FD34ED8C517}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{A19D0678-193C-49AE-9305-BF4DDED98659}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{B1265250-B0D4-4A13-A4C5-3C669628B861}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{CE396559-E459-4227-A7D8-384B5A67D8DA}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{DAB64A27-4614-4499-A72F-B14742E6AA46}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{E2626B57-D68C-4E7C-B1C1-4CD710DA7685}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{E6B0558C-C913-4BE8-BB95-6834D7ABA4D9}
Successfully deleted: [Empty Folder] C:\Users\S”ren\appdata\local\{FC086C3B-AD06-4D44-BAFD-27E361B3566A}
Successfully deleted: [Folder] C:\Users\S”ren\AppData\Roaming\pdfconvert
~~~ FireFox
Emptied folder: C:\Users\S”ren\AppData\Roaming\mozilla\firefox\profiles\nd54beis.default\minidumps [640 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\S”ren\appdata\local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.05.2015 at 11:33:11,58
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |