Ich bin eigentlich jemand der sehr wenig installiert und de-installiert. Bei so vielen Neu-Installationen von Programmen würde es mich nicht wundern wenn anschließen immer weniger geht. Zumal die Pakete immer kostenlos sind und man nie weiß was da alles nebenbei installiert wird.
Wenn das man gut geht ....
Werde es aber dennoch machen, da ich jeden Strohhalm nutzen möchte um den Mist endlich wieder weg zu bekommen. Allerdings würde mich interessieren woher der Schitt eigentlich kam, um den erneuten Befall zu verhindern.
Aber das kommt hoffentlich später.
Nachtrag: Wie lange läuft die Anti Malare Geschichte normalerweise ?
eiert jetzt schon über 3 Std am unberührten PC und man sieht und hört nix.
Ist das noch normal ?
Durchsuchte Objekte immer noch bei "0".
Hab es einfach abgebrochen und noch mal neu gestartet.
Nun läuft es und findet auch Dinge.
Log kommt wenn es durch ist.
--> Bei der Anti Malware-Oberfläche gab es keinen "Aktionen anwenden" Button oder ähnliches in den Menüfuhrung. Ich habe 134 Treffer.
Die Textdatei habe ich exportiert und packe sie als Code hier rein. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 17.08.2015
Suchlaufzeit: 15:01
Protokolldatei: Anti_Malware_Ergebnis_Bedrohungssuchlauf.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.17.05
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ewo
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 421662
Abgelaufene Zeit: 28 Min., 33 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 5
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Ejemidvlf.exe, 3308, , [34b5a663355690a6f363bbf5da2ac739]
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Ejemidvlf64.exe, 3316, , [2dbcc643abe00432bb9c614f62a2e21e]
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Weekfqwb.exe, 1292, , [f5f4f712bad17bbbf766cae643c148b8]
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Upbgbeie.exe, 1804, , [4e9b0108f39889ade27909a7798b659b]
PUP.Optional.Shopperz.A, C:\Program Files\daugava\csrcc.exe, 1316, , [f4f555b4abe02313f7651c94ab5951af]
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 42
PUP.Optional.Cherimoya.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cherimoya, , [2bbe41c8d6b565d1bcbf5136e91c936d],
PUP.Optional.StartPage.A, HKU\S-1-5-21-1345375173-2365957825-3748903027-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, , [06e32ddc58332f0714814354b74bec14],
PUP.Optional.StartPage.A, HKU\S-1-5-21-1345375173-2365957825-3748903027-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{336D0C35-8A85-403A-B9D2-65C292C39087}, , [06e32ddc58332f0714814354b74bec14],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, , [1ecbfc0da2e93402aa101cb349b98a76],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, , [0adfcf3a8a017db9bffc913ef210b14f],
Rootkit.Agent.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cherimoya, , [648516f3b6d50c2a2e6eec41e320bf41],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\daugava, , [0adf5faa6526ae88e86c6947e81cdd23],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SweetIM, , [5b8e1ced5b30e254f0860928e71c5fa1],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, , [06e369a0345791a50e1793c40bf80df3],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Cawlez, , [46a38584ff8c5adc68ed466a08fc51af],
PUP.Optional.OpenCandy.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunAsStandardUser, , [dc0dd9300685ce68c0d30e0af80b758b],
PUP.Optional.OpenCandy.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunOnce, , [4a9f4dbcd0bbf343c3d08296669d8878],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F179B4AA-3249-4E0E-A45A-8519D6BCD424}_IS1, , [74759e6bf79447efdc7cb2fe5ca851af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\daugava, , [24c5dd2cfe8dd2644410347cd0344bb5],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SweetIM, , [e10827e2018afd390e682e031de6e21e],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, , [e801c049d3b8e74f00252a2d37ccdc24],
PUP.Optional.Shopperz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\daugava Updater, , [f5f4f712bad17bbbf766cae643c148b8],
PUP.Optional.Shopperz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\65F825DE-0ADC-4791-A1E5-209AA6F7EA76, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6265CAFB-2688-4AED-A8CD-9B1E7B451C85}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59B83B12-7660-4FED-9E5F-DD67B4B8264C}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{CA83D815-E9CB-4790-9363-AAE02A9DB18E}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59B83B12-7660-4FED-9E5F-DD67B4B8264C}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{CA83D815-E9CB-4790-9363-AAE02A9DB18E}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{59B83B12-7660-4FED-9E5F-DD67B4B8264C}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{CA83D815-E9CB-4790-9363-AAE02A9DB18E}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6265CAFB-2688-4AED-A8CD-9B1E7B451C85}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{6265CAFB-2688-4AED-A8CD-9B1E7B451C85}, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CSRCC, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{14EF423E-3EE8-44AE-9337-07AC3F27B744}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A9582D7B-F24A-441D-9D26-450D58F3CD17}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A9582D7B-F24A-441D-9D26-450D58F3CD17}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A9582D7B-F24A-441D-9D26-450D58F3CD17}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{14EF423E-3EE8-44AE-9337-07AC3F27B744}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{14EF423E-3EE8-44AE-9337-07AC3F27B744}, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, , [e00905044a418bab7c0298857b880af6],
PUP.Optional.Incredibar.A, HKU\S-1-5-18\SOFTWARE\Incredibar.com, , [35b4bb4e5833f73f185374d2f90a8e72],
PUP.Optional.SweetIM.A, HKU\S-1-5-18\SOFTWARE\SweetIM, , [777224e50b80d066373ed65b857e5aa6],
PUP.Optional.InstallBrain.A, HKU\S-1-5-18\SOFTWARE\WNLT, , [f9f00ffa3f4cd0665f83e09d8f75817f],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1345375173-2365957825-3748903027-1000\SOFTWARE\SweetIM, , [30b955b436553105c1b459d86a997e82],
Registrierungswerte: 20
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, , [06e32ddc58332f0714814354b74bec14]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, , [06e32ddc58332f0714814354b74bec14]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, , [24c5e3261f6c9c9ad2c3cccb6e94718f],
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, , [ffea8980395264d28114395e946e27d9],
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, , [04e500090c7f53e3d2ed55eb976cbc44]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|daugava, C:\Program Files\daugava\Ejemidvlf.exe, , [34b5a663355690a6f363bbf5da2ac739]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|daugava64, C:\Program Files\daugava\Ejemidvlf64.exe, , [2dbcc643abe00432bb9c614f62a2e21e]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|Inno Setup: App Path, C:\Program Files\daugava, , [74759e6bf79447efdc7cb2fe5ca851af]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|InstallLocation, C:\Program Files\daugava\, , [0bdea7623b50e353e47499178084d22e]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|Inno Setup: Icon Group, daugava, , [f8f1c346eaa1a88ef95f78389b69d42c]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|DisplayName, daugava 2.0.0.701, , [8c5dd13843480630c890cde3e321748c]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|UninstallString, "C:\Program Files\daugava\unins000.exe", , [6a7f27e2701bdf574f092c84e51fbc44]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|QuietUninstallString, "C:\Program Files\daugava\unins000.exe" /SILENT, , [70791eeb02894ee8acac09a76a9af10f]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1|Publisher, daugava, , [46a39a6fdab1d95d0652713f6c9809f7]
PUP.Optional.WebAssistant.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\Web Assistant\Firefox, , [6f7a4bbea4e7181ea130e83461a2e11f]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, , [fbeea960b8d3dd593e81d36dd92a3ec2]
PUP.Optional.WebAssistant.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\Web Assistant\Firefox, , [ae3b48c17417b680ac256eaed72cba46]
PUP.Optional.Shopperz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\65f825de-0adc-4791-a1e5-209aa6f7ea76|ImagePath, "C:\Program Files\daugava\Upbgbeie.exe", , [4e9b0108f39889ade27909a7798b659b]
PUP.Optional.Shopperz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CSRCC|ImagePath, "C:\Program Files\daugava\csrcc.exe", , [f4f555b4abe02313f7651c94ab5951af]
PUP.Optional.InstallBrain.A, HKU\S-1-5-18\SOFTWARE\WNLT|URL, MYSTART, , [f9f00ffa3f4cd0665f83e09d8f75817f]
Registrierungsdaten: 4
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms}),,[12d74abfbdce053183b1d57441c4946c]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1345375173-2365957825-3748903027-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}),,[68811fea5338e84e290ff85145c00af6]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1345375173-2365957825-3748903027-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}),,[7574de2b7912fe382e0aa1a8ca3b0bf5]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1345375173-2365957825-3748903027-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=eea41cfa-c007-46a4-9fa1-ef6fcc065fda&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}),,[8663ea1f67246cca13222c1dcb3ad828]
Ordner: 21
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\10A6FCC1F7204154A26ECADF3B7E3CC4, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\3F382C7A50C3451DA8F237608DA9DCBA, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\8FEE8C7B4E324D24851471BCAEB16DE5, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.Babylon.A, C:\Users\ewo\AppData\LocalLow\BabylonToolbar, , [19d0c148e0ab191d8a3104eda55d46ba],
PUP.Optional.Babylon.A, C:\Users\ewo\AppData\LocalLow\BabylonToolbar\BabylonToolbar, , [19d0c148e0ab191d8a3104eda55d46ba],
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, , [8c5d89802e5d033325841201f90a9e62],
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub\ORJ-SPE, , [8c5d89802e5d033325841201f90a9e62],
PUP.Optional.Shopperz.A, C:\Program Files\daugava, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content\libraries, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content\resources, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\locale, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\locale\en-US, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\skin, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\defaults, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\defaults\preferences, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\libraries, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\resources, , [f2f719f0c7c420165cec48ce3ec54cb4],
Dateien: 42
PUP.Optional.Cherimoya.A, C:\Windows\System32\drivers\cherimoya.sys, , [2bbe41c8d6b565d1bcbf5136e91c936d],
Rootkit.Agent.A, C:\Windows\System32\drivers\cherimoya.sys, , [648516f3b6d50c2a2e6eec41e320bf41],
PUP.Optional.Shopperz.A, C:\Windows\System32\Tasks\Cawlez, , [975222e76f1c73c34709d1df0ef69d63],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Ejemidvlf.exe, , [34b5a663355690a6f363bbf5da2ac739],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Ejemidvlf64.exe, , [2dbcc643abe00432bb9c614f62a2e21e],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Weekfqwb.exe, , [f5f4f712bad17bbbf766cae643c148b8],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Upbgbeie.exe, , [4e9b0108f39889ade27909a7798b659b],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\csrcc.exe, , [f4f555b4abe02313f7651c94ab5951af],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\10A6FCC1F7204154A26ECADF3B7E3CC4\IESwitch_p1v1.exe, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\3F382C7A50C3451DA8F237608DA9DCBA\2533.ico, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\3F382C7A50C3451DA8F237608DA9DCBA\EBB77268-338F-4C6A-8590-AD88FED26F4A, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\3F382C7A50C3451DA8F237608DA9DCBA\Installer.exe, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\3F382C7A50C3451DA8F237608DA9DCBA\OCBrowserHelper_1.0.3.85.dll, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.OpenCandy, C:\Users\ewo\AppData\Roaming\OpenCandy\8FEE8C7B4E324D24851471BCAEB16DE5\TuneUpUtilities2013-2200218_de-DE.exe, , [b336ca3fb9d277bff6a98f5581816898],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Dpfvedc.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Dpfvedc64.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Eqxlolnp.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Esrqqdf.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Esrqqdf64.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\gcpum.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Irosioe.bat, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\nfregdrv64.exe, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\tree.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Tuugvuiog.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Tuugvuiog64.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\unins000.dat, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\unins000.exe, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Wqzaon.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Wqzaon64.dll, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome.manifest, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\icon.png, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\install.rdf, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}.xpi, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content\main.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content\main.xul, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content\libraries\DataExchangeScript.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\content\resources\LocalScript.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\locale\en-US\overlay.dtd, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\chrome\skin\overlay.css, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\Firefox\defaults\preferences\defaults.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\libraries\DataExchangeScript.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
PUP.Optional.Shopperz.A, C:\Program Files\daugava\resources\LocalScript.js, , [f2f719f0c7c420165cec48ce3ec54cb4],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Habe mal nachgelesen "Auswahl entfernen" bringt den gefunden Teil in die Quarantäne.
Das hat auch soweit geklappt.
Rechner Neustart und ih WUnder...die Popups sind erstmal nicht wie üblich sofort da.
Ich werde es mal beobachten und melde mich sobald es wieder auftritt.
ODER, sollte ich weiteres machen bevor ich mich jetzt wieder der Normalität widme und meinen Rechner dafür nutze wofür ich ihn habe nämlich zum arbeiten :rolleyes:
Ich warte also erstmal auf deine Antwort um dann ggf. weiters zu machen um Sauber zu sein und zu bleiben.
Großes Danke-Schön erstmal auf jeden Fall. |