Dominik H. | 13.08.2015 18:05 | Leider taucht Yahoo weiterhin auf, wenn ein neuer Tab gestartet wird. :heulen:
Hier die Daten:
Malwarebytes: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 13.08.2015
Suchlaufzeit: 18:29
Protokolldatei: malware.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.13.05
Rootkit-Datenbank: v2015.08.06.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: user
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 365158
Abgelaufene Zeit: 13 Min., 55 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 12
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [f8616c9c35561c1a570601953ac8d62a],
PUP.Optional.MoreResultsHub.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A8345A32-3B31-410A-BFBF-F2FDB81BA019}, In Quarantäne, [adacfd0b731855e17e5298f8867c37c9],
PUP.Optional.MoreResultsHub.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A8345A32-3B31-410A-BFBF-F2FDB81BA019}, In Quarantäne, [adacfd0b731855e17e5298f8867c37c9],
PUP.Optional.BDYahoo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [eb6e897f2c5fc86ead5f4668c63e8e72],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [26331fe9cbc0b18552b21096b84c2ad6],
PUP.Optional.SuperOptimizer.C, HKLM\SOFTWARE\WOW6432NODE\{1146AC44-2F03-4431-B4FD-889BC837521F}, In Quarantäne, [3227ea1e5e2d4ee849904463a06434cc],
PUP.Optional.SuperOptimizer.C, HKLM\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C}, In Quarantäne, [75e445c35833dc5affdb6542ab59c739],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [5207de2ae1aa69cd90743a6cfb09d030],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, In Quarantäne, [04555dab74172a0c85536d3aa55f3ec2],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, In Quarantäne, [69f0d335bad1e6509f395156838132ce],
PUP.Optional.BDYahoo.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [4019ef1917746ec8a06b06a88b7907f9],
PUP.Optional.OptimizerPro.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\OPTIMIZER PRO, In Quarantäne, [4118d03884078fa7b601297c8d77dc24],
Registrierungswerte: 8
PUP.Optional.BDYahoo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bir-sm-rhb-30__alt__ddc_dss_bd_com&p={searchTerms}, In Quarantäne, [eb6e897f2c5fc86ead5f4668c63e8e72]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [26331fe9cbc0b18552b21096b84c2ad6]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [5207de2ae1aa69cd90743a6cfb09d030]
PUP.Optional.Trovi.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M7F092E0D-6A76-417A-AB83-06E7737A94DE&SearchSource=58&CUI=&UM=6&UP=SPD92F3851-3728-4B6F-A727-7F5255D9E2C7&q={searchTerms}&SSPV=, In Quarantäne, [5cfd0efa6922152166431a8253b116ea]
PUP.Optional.Conduit.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|SuggestionsURL_JSON, hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [f168f117ef9c61d5d8016db147bc1ee2]
PUP.Optional.Trovi.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|DisplayName, Trovi search, In Quarantäne, [b1a8ee1ae0ab092dc0e96a3209fb4bb5]
PUP.Optional.BDYahoo.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bir-sm-rhb-30__alt__ddc_dss_bd_com&p={searchTerms}, In Quarantäne, [4019ef1917746ec8a06b06a88b7907f9]
PUP.Optional.OptimizerPro.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\OPTIMIZER PRO|AdsBuyNowURL, hxxp://www.safeshopgate.com/r?s=121001227&g=90561C13-D3A0-A44D-2A89-EB8079783DBB, In Quarantäne, [4118d03884078fa7b601297c8d77dc24]
Registrierungsdaten: 2
PUP.Optional.BDYahoo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-sm-rhb-30__alt__ddc_dsssyc_bd_com, Gut: (www.google.com), Schlecht: (hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-sm-rhb-30__alt__ddc_dsssyc_bd_com),Ersetzt,[cc8d719785066dc962944e03b94c3ac6]
PUP.Optional.BDYahoo.A, HKU\S-1-5-21-3705937506-1407253618-1579061599-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-sm-rhb-30__alt__ddc_dsssyc_bd_com, Gut: (www.google.com), Schlecht: (hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-sm-rhb-30__alt__ddc_dsssyc_bd_com),Ersetzt,[cc8d25e3880356e08f65d47d020349b7]
Ordner: 7
PUP.Optional.OptimizerPro.A, C:\Users\user\Documents\Optimizer Pro, In Quarantäne, [d287b5532566122445701a8bf90bb54b],
PUP.Optional.MultiPlug.F, C:\ProgramData\6708d192f77ba67d, In Quarantäne, [f861ed1bb4d7e84ea401a30c64a0dd23],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy, In Quarantäne, [e2774cbcf7942c0a8189b330847ee11f],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy\389C5056004E425482D74ED6B9852AD7, In Quarantäne, [e2774cbcf7942c0a8189b330847ee11f],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy\EFBC1A4CC9AF4CE6B7650E062B13DD11, In Quarantäne, [e2774cbcf7942c0a8189b330847ee11f],
PUP.Optional.CoolSaleCoupon.A, C:\ProgramData\CoolSaLeCoupOn, In Quarantäne, [5108ef19c9c2eb4b653e8674c53d768a],
PUP.Optional.CoolSaleCoupon.A, C:\Program Files (x86)\CoolSaLeCoupOn, In Quarantäne, [3b1eca3ef09b3303b9eb7783719110f0],
Dateien: 18
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Roaming\OpenCandy\EFBC1A4CC9AF4CE6B7650E062B13DD11\sp-downloader.exe, In Quarantäne, [2237af59018ae056f36a220705fc639d],
PUP.Optional.DownloadGuide.A, C:\Users\user\Downloads\OfficialCnCTiberianSun_CB-DL-Manager.exe, In Quarantäne, [c49550b866250333c5075a4f52af44bc],
PUP.Optional.Downloader, C:\Users\user\Downloads\TeamSpeak 3 32 Bit - CHIP-Installer.exe, In Quarantäne, [bb9e5dab4a410f27cb364008dc24ec14],
PUP.Optional.OptimizerPro.A, C:\Users\user\Documents\Optimizer Pro\CookiesException.txt, In Quarantäne, [d287b5532566122445701a8bf90bb54b],
PUP.Optional.MultiPlug.F, C:\ProgramData\6708d192f77ba67d\{0C516764-8CFC-C2FE-7BB0-A50A646E4DCD}.20140823154351, In Quarantäne, [f861ed1bb4d7e84ea401a30c64a0dd23],
PUP.Optional.MultiPlug.F, C:\ProgramData\6708d192f77ba67d\34e2e82387c90a766dc80c7d1f986c8c.ini, In Quarantäne, [f861ed1bb4d7e84ea401a30c64a0dd23],
PUP.Optional.MultiPlug.F, C:\ProgramData\6708d192f77ba67d\391d8035b5bee6216dc80c7d1f986c8c.ini, In Quarantäne, [f861ed1bb4d7e84ea401a30c64a0dd23],
PUP.Optional.MultiPlug.F, C:\ProgramData\6708d192f77ba67d\b6a46afacac9d2f26dc80c7d1f986c8c.ini, In Quarantäne, [f861ed1bb4d7e84ea401a30c64a0dd23],
PUP.Optional.MultiPlug.F, C:\ProgramData\6708d192f77ba67d\c6fe71eb0df193216dc80c7d1f986c8c.ini, In Quarantäne, [f861ed1bb4d7e84ea401a30c64a0dd23],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy\389C5056004E425482D74ED6B9852AD7\OptimizerPro.exe, In Quarantäne, [e2774cbcf7942c0a8189b330847ee11f],
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2dz2xpoy.default-1414599074507\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://de.search.yahoo.com/?fr=hp-ddc-bd-tab&type=bl-bfr-sm-rhb-30__alt__ddc_dsssyctab_bd_com");), Ersetzt,[3f1a6e9af497a78f3335e5a68f7648b8]
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2dz2xpoy.default-1414599074507\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bfr-sm-rhb-30__alt__ddc_dss_bd_com&p={searchTerms}");), Ersetzt,[5bfe12f62b60cd690c5d1f6cdd281ee2]
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2dz2xpoy.default-1414599074507\searchplugins\yahoo-search.xml, In Quarantäne, [dc7d4eba7714092d8ec36b1dea1bb947],
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2dz2xpoy.default-1414599074507\searchplugins\yahoo.xml, In Quarantäne, [ea6fbc4c07847abcd423c1c574915ba5],
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\g2mr5o1m.default-1413196550790\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://de.search.yahoo.com/?fr=hp-ddc-bd-tab&type=bl-bfr-sm-rhb-30__alt__ddc_dsssyctab_bd_com");), Ersetzt,[51080cfcb4d71c1af96ff99220e5b848]
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\g2mr5o1m.default-1413196550790\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bfr-sm-rhb-30__alt__ddc_dss_bd_com&p={searchTerms}");), Ersetzt,[c59460a89deeac8ac0a95e2d27deb14f]
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\g2mr5o1m.default-1413196550790\prefs.js, Gut: (browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (browser.startup.homepage", "hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=bl), Ersetzt,[44157e8a5f2ce6502d926d1fe124639d]
PUP.Optional.BDYahoo.A, C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\g2mr5o1m.default-1413196550790\searchplugins\yahoo.xml, In Quarantäne, [0e4b25e35635ca6c985f1571a75e1fe1],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) AdwCleaner: Code:
# AdwCleaner v4.208 - Logfile created 13/08/2015 at 18:50:05
# Updated 09/07/2015 by Xplode
# Database : 2015-08-12.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : user - USER-PC
# Running from : C:\Users\user\Desktop\AdwCleaner_4.208.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SereneScreen
Folder Deleted : C:\Program Files (x86)\SereneScreen
Folder Deleted : C:\Program Files (x86)\Optimizer Pro
File Deleted : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2dz2xpoy.default-1414599074507\foxydeal.sqlite
File Deleted : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2dz2xpoy.default-1414599074507\user.js
File Deleted : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\g2mr5o1m.default-1413196550790\user.js
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\SereneScreen
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\SereneScreen
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17909
-\\ Mozilla Firefox v38.0.5 (x86 de)
-\\ Google Chrome v
[C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
[C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
*************************
AdwCleaner[R0].txt - [3461 bytes] - [13/08/2015 18:49:23]
AdwCleaner[S0].txt - [3188 bytes] - [13/08/2015 18:50:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3247 bytes] ########## Junkware Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 7 Professional x64
Ran by user on 13.08.2015 at 18:54:51,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\2dz2xpoy.default-1414599074507\minidumps [9 files]
~~~ Chrome
[C:\Users\user\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\user\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\user\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\user\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.08.2015 at 18:59:27,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Grüße
Dominik |