Hallo
Malwarebytes hat das wohl in quarantäne geschoben. Habe hier mal ein suchlaufprotokoll vom 8.7.2015. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 08.07.2015
Suchlaufzeit: 19:39
Protokolldatei: mbm_funde.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.07.08.05
Rootkit-Datenbank: v2015.07.07.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Sascha
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 344722
Abgelaufene Zeit: 31 Min., 6 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 32
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1826FBEA-D11E-4923-B713-6119FCBFB598}, In Quarantäne, [0d48a33cc8c274c2dee3fd9c8e77649c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86A0A86B-07B4-4E3F-9A36-AB3E9E303196}, In Quarantäne, [7cd93ca3008a88ae4679d6c3a26302fe],
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}, In Quarantäne, [c392805f0684c472ce467122eb1a55ab],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsProtectManger, In Quarantäne, [77de36a97218ae88f2c11a16f311728e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1826FBEA-D11E-4923-B713-6119FCBFB598}, In Quarantäne, [be97b8273f4b47effdc41584a362e917],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86A0A86B-07B4-4E3F-9A36-AB3E9E303196}, In Quarantäne, [2b2a27b89eec55e1c5fab6e3f80dd32d],
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}, In Quarantäne, [fc5913cc29613bfbad67880bc5409769],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [1f36845b6f1b320473be0b7c0afb956b],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [b69f538cc1c9f1455ad8681f8382837d],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, In Quarantäne, [be97449bf397bb7bdabe821c91745aa6],
PUP.Optional.ReMarkit.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Re-markit, In Quarantäne, [9db82bb404867eb8dc605fc2788c38c8],
PUP.Optional.FreeSoftToday.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\freesofttoday, In Quarantäne, [25300fd0b8d20d29998f0f77e81d6c94],
PUP.Optional.AnyProtect.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\ANYPROTECT, In Quarantäne, [3c1996494f3bb086ce75118da3621fe1],
PUP.Optional.ReMarkit.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\APPDATALOW\SOFTWARE\Re-markit, In Quarantäne, [8ec717c8ef9bf73fcf6dfe23cd37eb15],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1826FBEA-D11E-4923-B713-6119FCBFB598}, In Quarantäne, [8cc9a03fc3c75cda1ea03861aa5bed13],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21108A98-DECC-49B5-B7F3-D31A96C9BCDF}, In Quarantäne, [6ee7e6f94347e4522a948217887dca36],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A5F99DB-E6C1-4819-9D4F-B646AC45ABC3}, In Quarantäne, [cc89e8f7f9913afc3d80bfdaec1934cc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4A2B3F81-1E30-4D91-B71A-69536F15DEE3}, In Quarantäne, [3e17bd22a2e8072f6855a7f2e91cac54],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5170267F-5330-4783-8FB6-9DC6539C1292}, In Quarantäne, [a5b0ba25286293a3c7f6d5c454b1f20e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{615643CD-2398-489A-8B17-64B9E84D355E}, In Quarantäne, [0451538cf39768ce3f7e8514c540be42],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86A0A86B-07B4-4E3F-9A36-AB3E9E303196}, In Quarantäne, [0f4668774743df570daf0b8ebb4aee12],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6F6ADB7-9547-4807-9814-69247ED4FE84}, In Quarantäne, [23320fd06723b185c4fa4e4bc73e55ab],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD779D17-2F6C-4EF5-A143-BC6ADFD21AE9}, In Quarantäne, [8acb9847a1e96dc9c4fa82174eb7d729],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8E4BBC1-5176-493D-B98A-5D5C4E497CC5}, In Quarantäne, [f85de0ff0783d75f54697524b2531ce4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BBDE8EA3-E840-4B5B-9BD6-E37AE940B12F}, In Quarantäne, [b5a024bbb6d4be786a545b3e23e248b8],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D252E128-1E20-48A3-BA49-B785A23DC255}, In Quarantäne, [80d5a9361971bd795766cbce21e4748c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4DE3402-7B1B-4D57-9434-6A6993D52885}, In Quarantäne, [10457a657e0c989ec3fa7920907524dc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D5069AC5-2D7F-4A38-81A6-9622EED9CB24}, In Quarantäne, [470eebf4c9c189ad94297425808560a0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5271F3D-3D45-43F2-B384-C0CDBB5951C3}, In Quarantäne, [bd984d92fb8f22146658495029dc0cf4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9C3ED71-AFAF-43C6-BA72-9AA4A4478BE7}, In Quarantäne, [2a2bbf20f694ff3717a6c0d94abbc838],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC27E14A-8859-4D09-BE3D-1F64CEBB3892}, In Quarantäne, [282d26b9642665d110aec4d570953ac6],
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}, In Quarantäne, [81d48d522664bf77fa19cfc46c9941bf],
Registrierungswerte: 31
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1826fbea-d11e-4923-b713-6119fcbfb598}|AppName, video MediaPlayer-codedownloader.exe, In Quarantäne, [0d48a33cc8c274c2dee3fd9c8e77649c]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86a0a86b-07b4-4e3f-9a36-ab3e9e303196}|AppName, video MediaPlayer-bg.exe, In Quarantäne, [7cd93ca3008a88ae4679d6c3a26302fe]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|DisplayName, default-search.net, In Quarantäne, [c392805f0684c472ce467122eb1a55ab]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|URL, hxxp://www.default-search.net/search?sid=492&aid=103&itype=a&ver=12791&tm=384&src=ds&p={searchTerms}, In Quarantäne, [4e0724bbe0aa72c450c4ccc74db86997]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|SuggestionsURL_JSON, hxxp://www.default-search.net?sid=492&aid=103&itype=a&ver=12791&tm=384&src=ds&p={searchTerms}&ft=json, In Quarantäne, [b99c12cdfa90cc6a0c08474c4abb46ba]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1826fbea-d11e-4923-b713-6119fcbfb598}|AppName, video MediaPlayer-codedownloader.exe, In Quarantäne, [be97b8273f4b47effdc41584a362e917]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86a0a86b-07b4-4e3f-9a36-ab3e9e303196}|AppName, video MediaPlayer-bg.exe, In Quarantäne, [2b2a27b89eec55e1c5fab6e3f80dd32d]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|DisplayName, default-search.net, In Quarantäne, [fc5913cc29613bfbad67880bc5409769]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|URL, hxxp://www.default-search.net/search?sid=492&aid=103&itype=a&ver=12791&tm=384&src=ds&p={searchTerms}, In Quarantäne, [4213627daddd9c9ad440c6cd6b9a4eb2]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|SuggestionsURL_JSON, hxxp://www.default-search.net?sid=492&aid=103&itype=a&ver=12791&tm=384&src=ds&p={searchTerms}&ft=json, In Quarantäne, [1c39607fd5b522149d77c9ca9b6a5ba5]
PUP.Optional.AnyProtect.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\ANYPROTECT|IsSilent, 0, In Quarantäne, [3c1996494f3bb086ce75118da3621fe1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1826fbea-d11e-4923-b713-6119fcbfb598}|AppName, video MediaPlayer-codedownloader.exe, In Quarantäne, [8cc9a03fc3c75cda1ea03861aa5bed13]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21108A98-DECC-49B5-B7F3-D31A96C9BCDF}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-codedownloader.exe, In Quarantäne, [6ee7e6f94347e4522a948217887dca36]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A5F99DB-E6C1-4819-9D4F-B646AC45ABC3}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [cc89e8f7f9913afc3d80bfdaec1934cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4A2B3F81-1E30-4D91-B71A-69536F15DEE3}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [3e17bd22a2e8072f6855a7f2e91cac54]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5170267F-5330-4783-8FB6-9DC6539C1292}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [a5b0ba25286293a3c7f6d5c454b1f20e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{615643CD-2398-489A-8B17-64B9E84D355E}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [0451538cf39768ce3f7e8514c540be42]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86a0a86b-07b4-4e3f-9a36-ab3e9e303196}|AppName, video MediaPlayer-bg.exe, In Quarantäne, [0f4668774743df570daf0b8ebb4aee12]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6F6ADB7-9547-4807-9814-69247ED4FE84}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-codedownloader.exe, In Quarantäne, [23320fd06723b185c4fa4e4bc73e55ab]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD779D17-2F6C-4EF5-A143-BC6ADFD21AE9}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-codedownloader.exe, In Quarantäne, [8acb9847a1e96dc9c4fa82174eb7d729]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8E4BBC1-5176-493D-B98A-5D5C4E497CC5}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [f85de0ff0783d75f54697524b2531ce4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BBDE8EA3-E840-4B5B-9BD6-E37AE940B12F}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-codedownloader.exe, In Quarantäne, [b5a024bbb6d4be786a545b3e23e248b8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D252E128-1E20-48A3-BA49-B785A23DC255}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [80d5a9361971bd795766cbce21e4748c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4DE3402-7B1B-4D57-9434-6A6993D52885}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [10457a657e0c989ec3fa7920907524dc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D5069AC5-2D7F-4A38-81A6-9622EED9CB24}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [470eebf4c9c189ad94297425808560a0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5271F3D-3D45-43F2-B384-C0CDBB5951C3}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-codedownloader.exe, In Quarantäne, [bd984d92fb8f22146658495029dc0cf4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9C3ED71-AFAF-43C6-BA72-9AA4A4478BE7}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-buttonutil.exe, In Quarantäne, [2a2bbf20f694ff3717a6c0d94abbc838]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC27E14A-8859-4D09-BE3D-1F64CEBB3892}|AppName, d5da2132-5fc4-4df1-9e78-5533f7681ac1-2.exe-codedownloader.exe, In Quarantäne, [282d26b9642665d110aec4d570953ac6]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|DisplayName, default-search.net, In Quarantäne, [81d48d522664bf77fa19cfc46c9941bf]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|URL, hxxp://www.default-search.net/search?sid=492&aid=103&itype=a&ver=12791&tm=384&src=ds&p={searchTerms}, In Quarantäne, [371e835cb4d6a69042d1930048bda858]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2721694102-2595870871-535589134-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|SuggestionsURL_JSON, hxxp://www.default-search.net?sid=492&aid=103&itype=a&ver=12791&tm=384&src=ds&p={searchTerms}&ft=json, In Quarantäne, [480d9f406129c57128ebf69dda2b01ff]
Registrierungsdaten: 2
PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1403194784&from=tugs&uid=ST3250310AS_6RYB8ZY5XXXX6RYB8ZY5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1403194784&from=tugs&uid=ST3250310AS_6RYB8ZY5XXXX6RYB8ZY5&q={searchTerms}),Ersetzt,[13427867fc8e4aec66e481cc020433cd]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1403194784&from=tugs&uid=ST3250310AS_6RYB8ZY5XXXX6RYB8ZY5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1403194784&from=tugs&uid=ST3250310AS_6RYB8ZY5XXXX6RYB8ZY5&q={searchTerms}),Ersetzt,[064f1ac54347f244bc8ec588d333db25]
Ordner: 17
PUP.Optional.GlobalUpdate.A, C:\Users\Sascha\AppData\Local\Temp\comh.267533, In Quarantäne, [4d08f2edbad03ef83474c61a39ca8f71],
PUP.Optional.Linkury.A, C:\Users\Sascha\AppData\Local\PennyBee, In Quarantäne, [4510825d2862c96d1acdfde7e122817f],
PUP.Optional.Linkury.A, C:\Users\Sascha\AppData\Local\PennyBee\pennybee, In Quarantäne, [4510825d2862c96d1acdfde7e122817f],
PUP.Optional.Linkury.A, C:\Users\Sascha\AppData\Local\PennyBee\pennybee\1.3.8.3, In Quarantäne, [4510825d2862c96d1acdfde7e122817f],
PUP.Optional.GenesisOffers, C:\Users\Sascha\AppData\Local\Genesis_06191619, In Quarantäne, [97beaf30395171c5d4662abb32d19f61],
PUP.Optional.NewPlayer.A, C:\Users\Sascha\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha, In Quarantäne, [6ce9b52aff8ba096c4838d674bb89e62],
PUP.Optional.NewPlayer.A, C:\Users\Sascha\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha\2.1.1.9, In Quarantäne, [6ce9b52aff8ba096c4838d674bb89e62],
PUP.Optional.YellowCabs.A, C:\Program Files (x86)\yellow cabs, In Quarantäne, [084d07d8f793340293100eedd2312ed2],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfhphepmmghimompopllneamgdbelkdd\19222.7775.6961_0, In Quarantäne, [f75e5f809af0f541e061f5a2f80eaf51],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfhphepmmghimompopllneamgdbelkdd\19222.7775.6961_0\chrome, In Quarantäne, [f75e5f809af0f541e061f5a2f80eaf51],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfhphepmmghimompopllneamgdbelkdd\19222.7775.6961_0\chrome\content, In Quarantäne, [f75e5f809af0f541e061f5a2f80eaf51],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfhphepmmghimompopllneamgdbelkdd, In Quarantäne, [f75e5f809af0f541e061f5a2f80eaf51],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\chrome, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\chrome\content, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\defaults, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\defaults\preferences, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
Dateien: 28
PUP.Optional.CrossRider.A, C:\Users\Sascha\AppData\Roaming\7AShARRx7Qggldh9Vw2TYc.exe, In Quarantäne, [6ee7f2edd3b7f4421aeb77e0d92746ba],
PUP.Optional.WinterWeb.A, C:\Users\Sascha\AppData\Roaming\ukUlD69JtYDqUAUbrFvIa.exe, In Quarantäne, [7cd9f8e7bccea690ba9342ffc541ac54],
PUP.Optional.PricePeep.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, In Quarantäne, [72e3637c1278e94d10476999f50f47b9],
PUP.Optional.PricePeep.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, In Quarantäne, [262f756aabdf60d63522de248c7857a9],
PUP.Optional.Updating.A, C:\Windows\System32\Tasks\yellow_cabs_updating_service, In Quarantäne, [163f508f82080333970035cedc282ad6],
PUP.Optional.Updating.A, C:\Windows\Tasks\yellow_cabs_updating_service.job, In Quarantäne, [6ee7bc23a3e77cbaecacad56e81ce917],
PUP.Optional.Notification.A, C:\Windows\Tasks\yellow_cabs_notification_service.job, In Quarantäne, [9cb99f40484266d0b709758e8d77a060],
PUP.Optional.Notification.A, C:\Windows\System32\Tasks\yellow_cabs_notification_service, In Quarantäne, [2431409f5832999d06bbe22108fc7a86],
PUP.Optional.Trovi.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\searchplugins\search_engine_trovi.xml, In Quarantäne, [a9ace5fafa90340272d5ad5bcf3531cf],
PUP.Optional.SelectNGo.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage, In Quarantäne, [8ec7e3fc1a7057df360f3dd38e761ce4],
PUP.Optional.SelectNGo.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal, In Quarantäne, [ea6bb22d13779c9aad988789e2227c84],
PUP.Optional.SelectNGo.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [173e97486723f244c5c8de5a9d670ef2],
PUP.Optional.SelectNGo.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [3025c11e6f1b80b691fc75c3b64ed030],
PUP.Optional.ShoppingGate.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_inst.shoppingate.info_0.localstorage, In Quarantäne, [7fd6e8f7157566d011de0f2b6b99b64a],
PUP.Optional.ShoppingGate.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_inst.shoppingate.info_0.localstorage-journal, In Quarantäne, [69ecaa35c4c6af878669ca70ba4a8f71],
PUP.Optional.VBates, C:\Windows\System32\Tasks\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2, In Quarantäne, [97befce34f3ba6908f69dbaae71e0af6],
PUP.Optional.Linkury.A, C:\Users\Sascha\AppData\Local\PennyBee\pennybee\1.3.8.3\app.ini, In Quarantäne, [4510825d2862c96d1acdfde7e122817f],
PUP.Optional.Linkury.A, C:\Users\Sascha\AppData\Local\PennyBee\pennybee\1.3.8.3\chrmXtn.dll, In Quarantäne, [4510825d2862c96d1acdfde7e122817f],
PUP.Optional.Linkury.A, C:\Users\Sascha\AppData\Local\PennyBee\pennybee\1.3.8.3\pennybee.exe, In Quarantäne, [4510825d2862c96d1acdfde7e122817f],
PUP.Optional.GenesisOffers, C:\Users\Sascha\AppData\Local\Genesis_06191619\genesis_06191619.gdb, In Quarantäne, [97beaf30395171c5d4662abb32d19f61],
PUP.Optional.GenesisOffers, C:\Users\Sascha\AppData\Local\Genesis_06191619\genesis_06191619.gss, In Quarantäne, [97beaf30395171c5d4662abb32d19f61],
PUP.Optional.NewPlayer.A, C:\Users\Sascha\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha\2.1.1.9\user.config, In Quarantäne, [6ce9b52aff8ba096c4838d674bb89e62],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfhphepmmghimompopllneamgdbelkdd\19222.7775.6961_0\manifest.json, In Quarantäne, [f75e5f809af0f541e061f5a2f80eaf51],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfhphepmmghimompopllneamgdbelkdd\19222.7775.6961_0\chrome\content\main.js, In Quarantäne, [f75e5f809af0f541e061f5a2f80eaf51],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\chrome.manifest, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\install.rdf, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\chrome\content\browser.xul, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
PUP.Optional.YellowCabs.A, C:\Users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\blba04aw.default\extensions\OB86Y@gmail.com\chrome\content\main.js, In Quarantäne, [470e815eec9e3bfb9cbebcdb20e6a759],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) |