Fressbacke | 26.08.2015 18:34 | Danke schon mal für die schnelle Antwort!
Ich werde mal suchen, was an logfiles gespeichert wurde - Meldungen gab es gar nicht bis zum gezielten Durchlauf von Malwarebytes. Nur bestimmte Seiten wurden mit Werbefensterchen zugemüllt, die Startseite nicht verändert.
Kaspersky hat sich nie gerührt.
Dauert allerdings noch ein wenig, erst muss mein Katerchen zum Doc.
So, hier mal das Log von Malwarebytes. Es wurden vorher keinerlei andere Versuche der Entfernung, also auch nicht über Systemsteuerung oder Browserreset gemacht. Der Scan wurde umfangreich fündig. Danach wurden alle Browser resetet, dann Adw und JRT - CCleaner durfte auch mal laufen. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 25.08.2015
Suchlaufzeit: 21:06
Protokolldatei: Mwbyt.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.25.05
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Ralf
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 410057
Abgelaufene Zeit: 10 Min., 1 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 10
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugincontainer.exe, 9164, Löschen bei Neustart, [6d9c3ecffd8eaa8c0efb5c33de27af51]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12\Plugin.exe, 6736, Löschen bei Neustart, [01080409830872c41ced98f765a01ae6]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12\Plugin.exe, 9864, Löschen bei Neustart, [01080409830872c41ced98f765a01ae6]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\8\Plugin.exe, 9008, Löschen bei Neustart, [16f336d75b306accfb0e008ff90cda26]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\3\Plugin.exe, 5520, Löschen bei Neustart, [76931bf2bccf3bfbe326751a36cffd03]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\3\Plugin.exe, 9880, Löschen bei Neustart, [76931bf2bccf3bfbe326751a36cffd03]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\5\Plugin.exe, 7372, Löschen bei Neustart, [a96095785e2d5fd769a0e9a6c93c54ac]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\4\Plugin.exe, 6816, Löschen bei Neustart, [7990030a5b301d19f11890ff9e67b848]
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\10\Plugin.exe, 5564, Löschen bei Neustart, [ea1fa865860562d452b7414e1beac23e]
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Common Files\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\updater.exe, 3784, Löschen bei Neustart, [dd2c5bb29af1e3537594fe9149bc8977]
Module: 4
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{218E8E29-14B9-4E3C-B63A-872C2FE139E3}.dll, Löschen bei Neustart, [f6133dd02863ea4cc7426a253dc8de22],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{218E8E29-14B9-4E3C-B63A-872C2FE139E3}.dll, Löschen bei Neustart, [f6133dd02863ea4cc7426a253dc8de22],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{ACEDD856-97FF-4691-95FC-D29EB3C4B06F}.dll, Löschen bei Neustart, [19f051bc404b84b2df2a305fc144c23e],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{ACEDD856-97FF-4691-95FC-D29EB3C4B06F}.dll, Löschen bei Neustart, [19f051bc404b84b2df2a305fc144c23e],
Registrierungsschlüssel: 5
PUP.Optional.GreatFind.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr GreatFind, In Quarantäne, [6d9c3ecffd8eaa8c0efb5c33de27af51],
PUP.Optional.GreatFind.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr GreatFind, In Quarantäne, [dd2c5bb29af1e3537594fe9149bc8977],
PUP.Optional.GreatFind.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Great Find, In Quarantäne, [6c9d12fbe7a49a9cf4150e81d92c718f],
PUP.Optional.GreatFind.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{cfd32d46-7d3f-483f-bace-7172aec5592d}, In Quarantäne, [6c9d12fbe7a49a9cf4150e81d92c718f],
PUP.Optional.GreatFind.A, HKLM\SOFTWARE\WOW6432NODE\GreatFind, In Quarantäne, [6f9ad03d9bf01620b0b62e817c88e719],
Registrierungswerte: 2
PUP.Optional.PluginContainer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr GreatFind|ImagePath, "C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugincontainer.exe", In Quarantäne, [fe0b1cf18308c3730d0fdcd5b74dab55]
PUP.Optional.Updater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr GreatFind|ImagePath, "C:\Program Files (x86)\Common Files\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\updater.exe", In Quarantäne, [080165a8b3d8d75f8896b10052b2dc24]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 23
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugincontainer, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\10, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\10bak, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12\resources, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12bak, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12bak\resources, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\3, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\3bak, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\4, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\4bak, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\5, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\5bak, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\7, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\7\resources, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\8, Löschen bei Neustart, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\8bak, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Common Files\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc, Löschen bei Neustart, [ea1fa964e1aa88aeab87bc5dc24127d9],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Common Files\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\updater, In Quarantäne, [ea1fa964e1aa88aeab87bc5dc24127d9],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Great Find, In Quarantäne, [9970d13ceba06ec854df67b21ce74eb2],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Great Find\Extensions, In Quarantäne, [9970d13ceba06ec854df67b21ce74eb2],
Dateien: 91
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{218E8E29-14B9-4E3C-B63A-872C2FE139E3}.dll, Löschen bei Neustart, [f6133dd02863ea4cc7426a253dc8de22],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{ACEDD856-97FF-4691-95FC-D29EB3C4B06F}.dll, Löschen bei Neustart, [19f051bc404b84b2df2a305fc144c23e],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugincontainer.exe, Löschen bei Neustart, [6d9c3ecffd8eaa8c0efb5c33de27af51],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12\Plugin.exe, Löschen bei Neustart, [01080409830872c41ced98f765a01ae6],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\8\Plugin.exe, Löschen bei Neustart, [16f336d75b306accfb0e008ff90cda26],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\3\Plugin.exe, Löschen bei Neustart, [76931bf2bccf3bfbe326751a36cffd03],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\5\Plugin.exe, Löschen bei Neustart, [a96095785e2d5fd769a0e9a6c93c54ac],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\4\Plugin.exe, Löschen bei Neustart, [7990030a5b301d19f11890ff9e67b848],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\10\Plugin.exe, Löschen bei Neustart, [ea1fa865860562d452b7414e1beac23e],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Common Files\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\updater.exe, Löschen bei Neustart, [dd2c5bb29af1e3537594fe9149bc8977],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugincontainer.bak, In Quarantäne, [29e00508dab172c418f17e1130d5639d],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\10bak\Plugin.exe, In Quarantäne, [97729776dcaf89ad0bfe0a855aab19e7],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12\resources\plugin.dll, In Quarantäne, [4dbc6aa34c3f5fd7a069652ad53053ad],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12bak\Plugin.exe, In Quarantäne, [ee1b45c85c2fab8bc7423857c342ef11],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\12bak\resources\plugin.dll, In Quarantäne, [6a9fc24b850665d1b059860950b5b14f],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\3bak\Plugin.exe, In Quarantäne, [a2678a8318739d99be4bf897f60fef11],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\4bak\Plugin.exe, In Quarantäne, [2bde927b7b1070c674950a8528dd837d],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\5bak\Plugin.exe, In Quarantäne, [7594b15cb3d8ef47f6132a6558ad926e],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\7\Plugin.exe, In Quarantäne, [18f1c548701be84e18f1a1eeea1be51b],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\7\resources\38.0.5.dll, In Quarantäne, [5faa9d703952af87b9507b147392d030],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\7\resources\39.0.0.dll, In Quarantäne, [c7423dd0d9b20630c148f897ee17d62a],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\7\resources\40.0.0.dll, In Quarantäne, [7792fb12f09b1e1867a2eda2e61f9d63],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\plugins\8bak\Plugin.exe, In Quarantäne, [88815cb1aedd0432b3561976010419e7],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Roaming\RHEng\560E1537295F4FA7A54DD4F0CBF2EF16\setup.exe, In Quarantäne, [ff0a7b928209df570cfd494648bd6799],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Roaming\RHEng\711E31614BED46EA804B99E8866ABDC4\setup.exe, In Quarantäne, [2bde2ae3305bf24445c4385736cfb24e],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Great Find\Uninstaller.exe, In Quarantäne, [6c9d12fbe7a49a9cf4150e81d92c718f],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{03A163CB-9386-4AF0-B463-45EF7274BFF0}.dll, In Quarantäne, [70993dd0d0bb65d16f9a0d821ee77090],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{6E3E9227-6F0D-4656-9EDD-59D14CA97DB0}.dll, In Quarantäne, [82871eefcebd072f97722b64ce37867a],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{E5362818-8D87-464B-83A7-22325956B032}.dll, In Quarantäne, [3acfdf2ecebd81b5f6138e01f90cdd23],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{74326F94-E11F-4080-8F93-BDBBA313747B}.dll, In Quarantäne, [42c77b92f7948baba1684d42778ea15f],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{790A40DD-10DA-4779-BE35-7343012096F2}.xpi, In Quarantäne, [18f1927bee9df04623e65e69f20f27d9],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{79EC062F-C60C-4469-BE47-7035D373DDDF}.dll, In Quarantäne, [7495eb227e0dc373ca3f721dcc3931cf],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{7B9BA5D7-BE3E-4658-A3D5-CE66DEDCC938}.xpi, In Quarantäne, [16f3a36a35560b2bce3bbd0ac33eca36],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{7BB72667-C332-4C44-980E-A8B641BBC6B5}.dll, In Quarantäne, [15f4f11cc1caf83e56b35d32ce3741bf],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{7BBF6E5F-60D3-4C79-8A5F-CA8A4A872011}.xpi, In Quarantäne, [32d79776850694a255b48b3ce61b05fb],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{7D91D607-8366-46AE-AC63-A742E009FBAD}.dll, In Quarantäne, [1beedc31315acd698386f79803024fb1],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{877CCD3A-C083-45F9-A377-8BE95D1FEA5E}.xpi, In Quarantäne, [bd4c79943e4d68cef3167a4de31e46ba],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{8990AF03-9FA0-4A45-A14F-44F83C9EA507}.dll, In Quarantäne, [96731df0e0abf3432cdd820db64f817f],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{91A833B9-2B96-471A-B079-05427BD57CC9}.dll, In Quarantäne, [2bde8d806625a88e9376583725e02cd4],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{CE03F442-1766-4A6B-85AA-E937E1E6D542}.dll, In Quarantäne, [947565a898f3999d7198602f26df8a76],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{D40650DA-F5AB-4DB8-BC1B-93038BA7A6DD}.dll, In Quarantäne, [749505086b201b1b07021c73e71e01ff],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{D85D85A6-5293-44DC-AF5F-1E0A0B792F42}.dll, In Quarantäne, [30d97d90d0bb3afc2bde028d52b350b0],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{DABED004-055A-46A8-9A02-57D53E113539}.dll, In Quarantäne, [b25739d4d6b501357099dab5af569967],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{DD31B590-CE00-4933-A8B5-559D24F3E483}.dll, In Quarantäne, [5cadd03d1c6fb581df2abed1699c5ba5],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{E1C3D233-1525-4A96-8552-80909EEF1E8B}.dll, In Quarantäne, [3ecb33da4942ed4964a5127d3cc904fc],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{E4F0053C-5C99-4556-8171-BD6555296D75}.dll, In Quarantäne, [b059818ca1ea221454b5b8d712f35fa1],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{E5095038-2C76-4D76-8389-4E7A3917CDFD}.xpi, In Quarantäne, [1eeb7e8f1d6e0e2821e88a3dc83948b8],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{37D712B2-13E6-4E94-9907-060AE66F5B35}.dll, In Quarantäne, [7297c34ae2a9af87d1384d42cf36669a],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{39F9588C-B855-4B14-8929-1E5AA3FCD3BE}.dll, In Quarantäne, [12f7739a7c0f52e421e8800f7491b050],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{3A5A1AD1-5D75-4833-9C6D-689C7B17D0E0}.dll, In Quarantäne, [fb0e3fcecbc03ef80dfcade2a065f40c],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{3CC0B8CB-0A52-4F2C-9176-9E42C0E922A1}.dll, In Quarantäne, [61a8d83548436ccad732bed1bf469e62],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{3E885772-6EE8-496D-86CE-DF76BF2F4B28}.xpi, In Quarantäne, [4cbd60ad404b40f61ced3196b74a956b],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{4575E309-20EB-4A6D-9622-6A4F0208D433}.xpi, In Quarantäne, [ae5b35d86823f145d7322c9b18e9e020],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{51D6CD58-38D5-4B67-89DB-9787DECBCB68}.dll, In Quarantäne, [6c9ddc316427e353fd0c1b7423e240c0],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{532C68B1-73BC-4972-BC37-73163DCE6536}.dll, In Quarantäne, [7f8a8a835833b97d19f0434cb154dc24],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{5702205C-3B80-4B8B-8552-A376A34516F0}.dll, In Quarantäne, [47c2709d127953e329e0f8979471a65a],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{6391F18C-DBBF-47C9-98CE-31A4B63F7493}.dll, In Quarantäne, [e72225e8dbb0b185cf3acfc01aeb3ec2],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{665C3950-4CDA-4CD8-997C-E20F3B189F79}.xpi, In Quarantäne, [d53439d4098282b46b9ea5226899ae52],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{6C34BD0D-8C23-4834-9209-940B4076E5C7}.dll, In Quarantäne, [0cfd7499f299c571e227e1ae29dcc838],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{6D4D0DE2-96C8-43C4-B923-D1E38D75224A}.dll, In Quarantäne, [95748b820b80e056c841aee130d57f81],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{9CD4514D-0D7B-463B-B7CC-CF577C93C64C}.dll, In Quarantäne, [90797499ccbf979f9178c6c9b154f907],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{A3887DF4-4BC1-4EF3-9F66-636C9F3A6324}.dll, In Quarantäne, [fb0e1bf258337abc47c2444b59ac3ac6],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{AB5BBBC9-1725-43AB-A6B5-43C13B91C89D}.dll, In Quarantäne, [9673c74691fa231358b192fdf90c20e0],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{B3006673-8DE5-48CD-8709-D950F1C66C02}.xpi, In Quarantäne, [2edbda33e6a55dd97e8bf4d304fdc53b],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{B5492A3E-9980-41B6-A5A9-B7BCFD889E01}.xpi, In Quarantäne, [e7228d80048703337099ddeaa160d12f],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{B67BEB46-5606-423B-8013-6FA2465F746E}.dll, In Quarantäne, [2bdedb32fb90f14528e11778b253f30d],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{BFD684C7-97A9-43C4-B487-5AC657BD6E94}.dll, In Quarantäne, [16f33fce028995a170998a052dd8f20e],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{CCEDC56E-B959-4AE5-B0A4-28A1C15361F3}.dll, In Quarantäne, [eb1e13fa5338a393d03998f746bfe818],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{EC9069B0-6741-4245-A617-57918F06CC01}.dll, In Quarantäne, [41c86ca1612a41f562a76b248a7b9e62],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{F24F8695-81A9-47CF-AD61-E6BDF922CBB4}.dll, In Quarantäne, [b950dc3153381c1a7792058a8481ee12],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{F40A5431-9212-4F0B-9867-6346F1C20470}.dll, In Quarantäne, [9277c7463a517fb7ef1a5c33ef16d030],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{FD323D75-6106-456E-952D-4AD33BEFF306}.dll, In Quarantäne, [5cad33dafc8f64d22bdef69956afb54b],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{0F3AD98A-6AA2-4BC6-A947-2D521CFDD5E9}.dll, In Quarantäne, [7e8b44c9c5c6d95d68a18d02947152ae],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{1370A2DC-597E-42DF-ACB6-E305607002C1}.dll, In Quarantäne, [ea1f000d34575fd78584810e26df7987],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{1C4C20A2-D596-41E0-9611-0055F710E2C3}.xpi, In Quarantäne, [78917b922a618caa3acf04c37d84cf31],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{206F4E0F-AF67-46D7-8369-011EEA21C862}.dll, In Quarantäne, [8b7ea8650b8047effd0c95fa3cc9f808],
PUP.Optional.Yontoo.Gen, C:\Users\Ralf\AppData\Local\Temp\{240D447F-E30F-441A-BCC8-B1EEC9BBBA75}.xpi, In Quarantäne, [2bde0ffed3b8280e0cfde6e1ae5324dc],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{2DBDA368-942A-4423-82CB-E82EFC2C3FC4}.dll, In Quarantäne, [bc4dcd402467e84edb2e751a768f20e0],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Temp\{30F12C82-9CE7-445C-8928-8C9D2ED7EB03}.dll, In Quarantäne, [8a7f48c5aedd58deb9504a4564a1649c],
PUP.Optional.PastaLeads.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nps.pastaleads.com_0.localstorage, Löschen bei Neustart, [5dac937a3358a5914af6b873f21112ee],
PUP.Optional.PastaLeads.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nps.pastaleads.com_0.localstorage-journal, Löschen bei Neustart, [a564a06dbfccd6607ac61a1155ae2ad6],
PUP.Optional.BoostSaves.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Löschen bei Neustart, [74958588b2d96fc7614fa493e41f8977],
PUP.Optional.BoostSaves.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Löschen bei Neustart, [cf3a907dc8c3c86e149c96a1b54e3dc3],
PUP.Optional.Boost.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Löschen bei Neustart, [dd2cd439345766d038522627748f857b],
PUP.Optional.Boost.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, Löschen bei Neustart, [40c90c0195f687afe1a9183554afc43c],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_greatfind-a.akamaihd.net_0.localstorage, Löschen bei Neustart, [14f5e429f992b185550f555a22e28b75],
PUP.Optional.GreatFind.A, C:\Users\Ralf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_greatfind-a.akamaihd.net_0.localstorage-journal, Löschen bei Neustart, [ee1b6aa33f4cf64095cfd7d8d72d1ce4],
PUP.Optional.GreatFind.A, C:\ProgramData\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\temp, In Quarantäne, [64a537d665264cea3ff251c8f90a8c74],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Common Files\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc\updater.bak, In Quarantäne, [ea1fa964e1aa88aeab87bc5dc24127d9],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Great Find\7za.exe, In Quarantäne, [9970d13ceba06ec854df67b21ce74eb2],
PUP.Optional.GreatFind.A, C:\Program Files (x86)\Great Find\Extensions\{fcefe1dd-0baf-4b61-89e2-cb91a9b96dfe}.xpi, In Quarantäne, [9970d13ceba06ec854df67b21ce74eb2],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Das JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 8.1 x64
Ran by Ralf on 25.08.2015 at 23:16:57,30
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
~~~ Files
Successfully deleted: [File] C:\Users\Ralf\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.boostsaves.com_0.localstorage
Successfully deleted: [File] C:\Users\Ralf\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.boostsaves.com_0.localstorage-journal
Successfully deleted: [File] C:\Users\Ralf\Appdata\Local\google\chrome\user data\default\local storage\hxxps_static.boostsaves.com_0.localstorage
Successfully deleted: [File] C:\Users\Ralf\Appdata\Local\google\chrome\user data\default\local storage\hxxps_static.boostsaves.com_0.localstorage-journal
Successfully deleted: [File] C:\WINDOWS\SysWOW64\RENE6B.tmp
~~~ Folders
~~~ Chrome
[C:\Users\Ralf\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Ralf\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Ralf\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Ralf\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.08.2015 at 23:21:12,72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vom Adw habe ich leider keines.
FRST mache ich nun - folgt :) |