desertstorm | 02.08.2015 19:15 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 02.08.2015
Suchlaufzeit: 19:21
Protokolldatei: mbam1.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.02.03
Rootkit-Datenbank: v2015.07.30.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Rina
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 419946
Abgelaufene Zeit: 35 Min., 39 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\Got.exe, 3280, Löschen bei Neustart, [2ddee1235c2f8fa7a7cc4f795fa2e917]
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\ojhemcb4.exe, 3416, Löschen bei Neustart, [0efd06fe880315218f3bc9b4768fb14f]
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 26
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{08EB8942-B397-4841-8F03-8D4965E4BC33}, In Quarantäne, [eb2050b4e1aaef4745779508a0649f61],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AF4AB12-1B14-4E07-9B5B-151502DEBC70}, In Quarantäne, [cc3fe71d2e5d85b16558bbe2bb4934cc],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7A9C09AA-AE3C-486C-978B-8CDB556E7378}, In Quarantäne, [cb40fd073a5155e108b6237ab351639d],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{08EB8942-B397-4841-8F03-8D4965E4BC33}, In Quarantäne, [7a919074c9c226102498465752b2f10f],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AFAC3EC-6B87-4D58-B035-7396EE93605E}, In Quarantäne, [7d8ef70d7a115cda704eddc0be461ae6],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6874FADE-02C8-4181-831A-FC7486CF1D74}, In Quarantäne, [8a810ff5b3d847efb888dac2b2526997],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AF4AB12-1B14-4E07-9B5B-151502DEBC70}, In Quarantäne, [0efdf60e216adc5a7e3fd3caa55f7b85],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{717DB90D-3BD6-46CE-A446-3FD60F041378}, In Quarantäne, [eb208c78a8e3b482b5075c411aea3ec2],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7A9C09AA-AE3C-486C-978B-8CDB556E7378}, In Quarantäne, [dd2eb45096f50a2cd2ec326b6e96639d],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D155215E-DA72-4958-9A73-9C966CF67BC1}, In Quarantäne, [4bc0e2222a61f83e9429abf2b054e020],
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH, In Quarantäne, [28e3ac58206b0f27cdeedccc9f65e719],
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4337450E-75DA-4E0C-83AF-A9169B8CEB4C}, In Quarantäne, [34d73dc7890272c4808cbbee6c98867a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{08EB8942-B397-4841-8F03-8D4965E4BC33}, In Quarantäne, [67a462a2cdbe4cea9326cdd09a6acd33],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12D3A8EE-90BA-40E4-B026-A25A5CF46C10}, In Quarantäne, [d635e024f4978aacc1fa8419af55629e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{450FF880-9801-4A47-9FD8-5EEA7BC2DC18}, In Quarantäne, [7893bb49cac1eb4b6159eab3c93be11f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45E6D6F5-79E0-40E1-8C79-8A649513F1E7}, In Quarantäne, [14f71be9f497af8705b50c91ab591ae6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AF4AB12-1B14-4E07-9B5B-151502DEBC70}, In Quarantäne, [53b862a26a2178beba00fda003017789],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6BA1F70A-3797-45A7-AB65-FAB01769324E}, In Quarantäne, [62a917edb6d5c274d2e946577094d12f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73B8F307-3C70-4ACF-B6C1-2F5CD1E818AB}, In Quarantäne, [0a013acaf19a64d273481b8272925aa6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7A9C09AA-AE3C-486C-978B-8CDB556E7378}, In Quarantäne, [b556c34193f887afc5f6ddc0ff052fd1],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0C14F1B-43E2-435E-BB74-D43587C8309B}, In Quarantäne, [46c51be96724af877b400e8f37cd53ad],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4F729D2-9B58-4A15-81AA-B3FA86798BB9}, In Quarantäne, [b556c63e6724270fead07b227391748c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D69E2957-58E0-489B-B878-716A4512A8FB}, In Quarantäne, [789383817b10b77f2e8cb6e7af55837d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EDBFD9F9-59A0-4B76-84FB-AA54D03C122E}, In Quarantäne, [5facb94b2665e74f5466b4e9f1134eb2],
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{IELNKSRCH}, In Quarantäne, [9a714bb96b20e056f1471bf6b64de818],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, In Quarantäne, [da314db7f19af0463a6031e66e957c84],
Registrierungswerte: 35
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{08eb8942-b397-4841-8f03-8d4965e4bc33}|AppName, Plus-HD-2.5-bg.exe, In Quarantäne, [eb2050b4e1aaef4745779508a0649f61]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6af4ab12-1b14-4e07-9b5b-151502debc70}|AppName, Plus-HD-2.5-buttonutil.exe, In Quarantäne, [cc3fe71d2e5d85b16558bbe2bb4934cc]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7a9c09aa-ae3c-486c-978b-8cdb556e7378}|AppName, Plus-HD-2.5-codedownloader.exe, In Quarantäne, [cb40fd073a5155e108b6237ab351639d]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{08eb8942-b397-4841-8f03-8d4965e4bc33}|AppName, Plus-HD-2.5-bg.exe, In Quarantäne, [7a919074c9c226102498465752b2f10f]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1afac3ec-6b87-4d58-b035-7396ee93605e}|AppName, Plus-HD-2.4-codedownloader.exe, In Quarantäne, [7d8ef70d7a115cda704eddc0be461ae6]
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6874fade-02c8-4181-831a-fc7486cf1d74}|AppPath, C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin, In Quarantäne, [8a810ff5b3d847efb888dac2b2526997]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6af4ab12-1b14-4e07-9b5b-151502debc70}|AppName, Plus-HD-2.5-buttonutil.exe, In Quarantäne, [0efdf60e216adc5a7e3fd3caa55f7b85]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{717db90d-3bd6-46ce-a446-3fd60f041378}|AppName, Plus-HD-2.4-bg.exe, In Quarantäne, [eb208c78a8e3b482b5075c411aea3ec2]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7a9c09aa-ae3c-486c-978b-8cdb556e7378}|AppName, Plus-HD-2.5-codedownloader.exe, In Quarantäne, [dd2eb45096f50a2cd2ec326b6e96639d]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{d155215e-da72-4958-9a73-9c966cf67bc1}|AppName, Plus-HD-2.4-buttonutil.exe, In Quarantäne, [4bc0e2222a61f83e9429abf2b054e020]
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|DisplayName, Search the web, In Quarantäne, [28e3ac58206b0f27cdeedccc9f65e719]
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|URL, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, In Quarantäne, [0704d133f695d561407c02a6ca3ace32]
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, In Quarantäne, [d833b351810add59655816920cf8b947]
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4337450E-75DA-4E0C-83AF-A9169B8CEB4C}|Publisher, Linkury, In Quarantäne, [34d73dc7890272c4808cbbee6c98867a]
PUP.Optional.Linkury.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\ENVIRONMENT|SNP, hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D?publisher=APSFCovus&co=DE&userid=8b127689-beb4-7425-5a9c-ab7de401359f&searchtype=sc&installDate=25.07.2015&barcodeid=50036012&channelid=12, In Quarantäne, [54b73cc893f849edc04adecb1de7c63a]
PUP.Optional.Linkury.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\ENVIRONMENT|SNF, C:\ProgramData\Gots\snp.sc, In Quarantäne, [fb1000040c7ffe38f8113673986c827e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{08eb8942-b397-4841-8f03-8d4965e4bc33}|AppName, Plus-HD-2.5-bg.exe, In Quarantäne, [67a462a2cdbe4cea9326cdd09a6acd33]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12D3A8EE-90BA-40E4-B026-A25A5CF46C10}|AppName, Plus-HD-2.5-enabler.exe-codedownloader.exe, In Quarantäne, [d635e024f4978aacc1fa8419af55629e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{450FF880-9801-4A47-9FD8-5EEA7BC2DC18}|AppName, Plus-HD-2.5-enabler.exe-buttonutil.exe, In Quarantäne, [7893bb49cac1eb4b6159eab3c93be11f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45E6D6F5-79E0-40E1-8C79-8A649513F1E7}|AppName, Plus-HD-2.5-enabler.exe-buttonutil.exe, In Quarantäne, [14f71be9f497af8705b50c91ab591ae6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6af4ab12-1b14-4e07-9b5b-151502debc70}|AppName, Plus-HD-2.5-buttonutil.exe, In Quarantäne, [53b862a26a2178beba00fda003017789]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6BA1F70A-3797-45A7-AB65-FAB01769324E}|AppName, Plus-HD-2.5-enabler.exe-codedownloader.exe, In Quarantäne, [62a917edb6d5c274d2e946577094d12f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73B8F307-3C70-4ACF-B6C1-2F5CD1E818AB}|AppName, Plus-HD-2.5-enabler.exe-codedownloader.exe, In Quarantäne, [0a013acaf19a64d273481b8272925aa6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7a9c09aa-ae3c-486c-978b-8cdb556e7378}|AppName, Plus-HD-2.5-codedownloader.exe, In Quarantäne, [b556c34193f887afc5f6ddc0ff052fd1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0C14F1B-43E2-435E-BB74-D43587C8309B}|AppName, Plus-HD-2.5-enabler.exe-codedownloader.exe, In Quarantäne, [46c51be96724af877b400e8f37cd53ad]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4F729D2-9B58-4A15-81AA-B3FA86798BB9}|AppName, Plus-HD-2.5-enabler.exe-buttonutil.exe, In Quarantäne, [b556c63e6724270fead07b227391748c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D69E2957-58E0-489B-B878-716A4512A8FB}|AppName, Plus-HD-2.5-enabler.exe-buttonutil.exe, In Quarantäne, [789383817b10b77f2e8cb6e7af55837d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EDBFD9F9-59A0-4B76-84FB-AA54D03C122E}|AppName, Plus-HD-2.5-enabler.exe-buttonutil.exe, In Quarantäne, [5facb94b2665e74f5466b4e9f1134eb2]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|DisplayName, Search the web, In Quarantäne, [9a714bb96b20e056f1471bf6b64de818]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|URL, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, In Quarantäne, [e12a41c3d8b32b0b6158713755af28d8]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}|TopResultURLFallback, hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites1202&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDtCyEtDyDtDtD0DtA0DyBtN0D0Tzu0SyBtBtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=2037166292&ir=, In Quarantäne, [da314db7f19af0463a6031e66e957c84]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}|FaviconURL, hxxp://start.mysearchdial.com/favicon.ico, In Quarantäne, [22e935cfc4c784b2efabc35461a2e719]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}|FaviconURLFallback, hxxp://start.mysearchdial.com/favicon.ico, In Quarantäne, [789308fc315a3ef8c7d36ea9d330b947]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, Mysearchdial, In Quarantäne, [f8137b894e3dc274f6a421f6c43f26da]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, In Quarantäne, [0dfe3bc9ff8c5fd7b6048e1a19eb52ae]
Registrierungsdaten: 7
PUP.Optional.Linkury.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\ProgramData\Got\lynbq344.dll, Gut: (), Schlecht: (C:\ProgramData\Got\lynbq344.dll),Ersetzt,[da31eb190b8068ce6ae4117848ba8a76]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}),Ersetzt,[56b5996b0d7ebb7be64efa4d09fc9868]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uBljIyw0OjJalBPWrl-tCGj5p8ETyG0adxlYjhl23rHFZY6glMBqcLnF1NLKDjR_bl_tBxhYtSXezCg,,, Gut: (www.google.com), Schlecht: (hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uBljIyw0OjJalBPWrl-tCGj5p8ETyG0adxlYjhl23rHFZY6glMBqcLnF1NLKDjR_bl_tBxhYtSXezCg,,),Ersetzt,[3ad1da2a88037db9c86db19639cc9f61]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}),Ersetzt,[7f8c3fc5bad185b1d460cd7a1bea1ae6]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SearchAssistant, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}),Ersetzt,[719a3dc73b50a78f062e9ea928dd0af6]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-2548127686-2624113823-3198731659-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEM9dHz4Mno2NLTKaJBUV7i2NKt2ovXVnPqEmkr21qvkUIYNxya8mCJDZQ5P8O_vD4PaaT-f6lpzr1uCrJOJPhWQNtb8B3XaULK074z116iaJq3nt4BkqCDv2mHq2mU14GFkL398QZkhZ51TdxUpFhiCRhZFQ,,&q={searchTerms}),Ersetzt,[c3486e96c6c5b5812d091e29788d8080]
PUP.Optional.Linkury.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\ProgramData\Got\xqsbcbnh.dll, Gut: (), Schlecht: (C:\ProgramData\Got\xqsbcbnh.dll),Ersetzt,[0efd06fe880315218f3bc9b4768fb14f]
Ordner: 5
PUP.Optional.DownloadProtect.A, C:\Windows\Installer\{5F112FA8-C378-493C-8784-5B58B1D535D1}, In Quarantäne, [3ad129db5b3037ff5ef90908fc070bf5],
PUP.Optional.Linkury.ShrtCln, C:\ProgramData\Gots, In Quarantäne, [8289eb19f992c0764586bbc216ef1de3],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got, Löschen bei Neustart, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\ondemand, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\temp, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
Dateien: 32
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\Got.exe, Löschen bei Neustart, [2ddee1235c2f8fa7a7cc4f795fa2e917],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\lynbq344.dll, In Quarantäne, [da31eb190b8068ce6ae4117848ba8a76],
PUP.Optional.DownloadProtect.A, C:\Windows\Installer\{5F112FA8-C378-493C-8784-5B58B1D535D1}\cbcphlbllajcopgdndggjbpjeoejdgbhlrx, In Quarantäne, [3ad129db5b3037ff5ef90908fc070bf5],
PUP.Optional.DownloadProtect.A, C:\Windows\Installer\{5F112FA8-C378-493C-8784-5B58B1D535D1}\xbcphlbllajcopgdndggjbpjeoejdgbhlml, In Quarantäne, [3ad129db5b3037ff5ef90908fc070bf5],
PUP.Optional.Linkury.ShrtCln, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\findit.xml, In Quarantäne, [19f258ac8308ab8b8f3e88f5cd389967],
PUP.Optional.Linkury.ShrtCln, C:\ProgramData\Gots\ff.HP, In Quarantäne, [8289eb19f992c0764586bbc216ef1de3],
PUP.Optional.Linkury.ShrtCln, C:\ProgramData\Gots\ff.NT, In Quarantäne, [8289eb19f992c0764586bbc216ef1de3],
PUP.Optional.Linkury.ShrtCln, C:\ProgramData\Gots\snp.sc, In Quarantäne, [8289eb19f992c0764586bbc216ef1de3],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\Timers.xml, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\1ty2libj.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\conf.config, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\Config.xml, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\ewkvgs0m.exe, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\ewkvgs0m.exe.config, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\Got.dll, Löschen bei Neustart, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\Got.exe.config, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\hnpagpnt.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\l43cfhmk.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\ojhemcb4.exe, Löschen bei Neustart, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\ojhemcb4.exe.config, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\szijmhxp.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\u3yx3wjt.exe, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\u3yx3wjt.exe.config, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\uninstall.exe, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\wlyg1fpt.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\wy1zztj5.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\xqsbcbnh.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\xwqx0s0i.exe, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\xwqx0s0i.exe.config, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.PrxySvrRST, C:\ProgramData\Got\yrjbxoln.dll, In Quarantäne, [0efd06fe880315218f3bc9b4768fb14f],
PUP.Optional.Linkury.ShrtCln, C:\Users\Rina\AppData\Roaming\Mozilla\Firefox\Profiles\tgrse5pb.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "C:\ProgramData\Gots\ff.NT");), Ersetzt,[a06b778d5f2cbd79c8b577095aab08f8]
PUP.Optional.Linkury.ShrtCln, C:\Users\Rina\AppData\Roaming\Mozilla\Firefox\Profiles\tgrse5pb.default\prefs.js, Gut: (browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (browser.startup.homepage", "C:\ProgramData\Gots\ff.HP), Ersetzt,[0efdb153fb901521e59095ede91c5ea2]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 02.08.2015 19:20, SYSTEM, RINA-PC, Manual, Remediation Database, 2015.7.20.1, 2015.7.28.1,
Update, 02.08.2015 19:20, SYSTEM, RINA-PC, Manual, Rootkit Database, 2015.7.22.1, 2015.7.30.1,
Update, 02.08.2015 19:20, SYSTEM, RINA-PC, Manual, AKA IP Database, 2015.7.15.1, 2015.7.29.1,
Update, 02.08.2015 19:20, SYSTEM, RINA-PC, Manual, AKA Domain Database, 2015.7.25.5, 2015.7.31.1,
Update, 02.08.2015 19:20, SYSTEM, RINA-PC, Manual, Malware Database, 2015.7.25.3, 2015.8.2.3,
Scan, 02.08.2015 19:58, SYSTEM, RINA-PC, Manual, Start: 02.08.2015 19:21, Dauer: 35 Min. 39 Sek., Bedrohungssuchlauf, Abgeschlossen, 0 Malware-Erkennung, 107 Nicht-Malware-Erkennungen,
Error, 02.08.2015 20:01, SYSTEM, RINA-PC, Protection, IsLicensed, 13,
Protection, 02.08.2015 20:01, SYSTEM, RINA-PC, Protection, Malware Protection, Stopping,
Protection, 02.08.2015 20:01, SYSTEM, RINA-PC, Protection, Malware Protection, Stopped,
(end) |