CLamantius | 05.09.2015 19:22 | mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 05.09.2015
Suchlaufzeit: 19:50
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.09.05.05
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Ismael
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 394662
Abgelaufene Zeit: 5 Min., 52 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 48
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\TYPELIB\{A336F17E-321F-43FA-9BE6-873BBDFF418E}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\INTERFACE\{2704C5CE-6D55-4E23-9B0F-CFE24AA97234}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\INTERFACE\{970836ED-AE00-478D-BDF1-90D17713D3A2}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\INTERFACE\{B3321940-9C27-4ABD-9AEF-F93D0B6E1238}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\INTERFACE\{B985E3F1-6AB3-49C6-B4BE-DB354176C4DF}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2704C5CE-6D55-4E23-9B0F-CFE24AA97234}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{970836ED-AE00-478D-BDF1-90D17713D3A2}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B3321940-9C27-4ABD-9AEF-F93D0B6E1238}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B985E3F1-6AB3-49C6-B4BE-DB354176C4DF}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2704C5CE-6D55-4E23-9B0F-CFE24AA97234}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{970836ED-AE00-478D-BDF1-90D17713D3A2}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B3321940-9C27-4ABD-9AEF-F93D0B6E1238}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B985E3F1-6AB3-49C6-B4BE-DB354176C4DF}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A336F17E-321F-43FA-9BE6-873BBDFF418E}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A336F17E-321F-43FA-9BE6-873BBDFF418E}, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\TYPELIB\{330ED369-73D2-49BC-AC43-1E21602F742D}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\INTERFACE\{0B079ECD-60E4-40B9-9FAC-4ECC98AB8786}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\INTERFACE\{3967CDA8-3EAB-4115-84F1-C29A9C5FB484}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\INTERFACE\{9F5974D4-08A9-4422-9F36-76103BEE67A1}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\INTERFACE\{B0030E0C-349C-4EB5-AD5E-847B43C0D844}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0B079ECD-60E4-40B9-9FAC-4ECC98AB8786}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3967CDA8-3EAB-4115-84F1-C29A9C5FB484}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9F5974D4-08A9-4422-9F36-76103BEE67A1}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B0030E0C-349C-4EB5-AD5E-847B43C0D844}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0B079ECD-60E4-40B9-9FAC-4ECC98AB8786}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3967CDA8-3EAB-4115-84F1-C29A9C5FB484}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{9F5974D4-08A9-4422-9F36-76103BEE67A1}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B0030E0C-349C-4EB5-AD5E-847B43C0D844}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{330ED369-73D2-49BC-AC43-1E21602F742D}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{330ED369-73D2-49BC-AC43-1E21602F742D}, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\TYPELIB\{A1965763-A486-4E1E-B574-19E44B3842E8}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\INTERFACE\{9CABED0D-99E4-457C-A192-D528B389F53C}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\INTERFACE\{CED50656-D422-418C-8A20-A0F455842FA5}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\INTERFACE\{D8B5D394-6974-40D4-9DFB-DAAD64E422D6}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\INTERFACE\{ED2A17AC-87A9-4640-9DE9-07AB5B63E902}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9CABED0D-99E4-457C-A192-D528B389F53C}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{CED50656-D422-418C-8A20-A0F455842FA5}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D8B5D394-6974-40D4-9DFB-DAAD64E422D6}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{ED2A17AC-87A9-4640-9DE9-07AB5B63E902}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{9CABED0D-99E4-457C-A192-D528B389F53C}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{CED50656-D422-418C-8A20-A0F455842FA5}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{D8B5D394-6974-40D4-9DFB-DAAD64E422D6}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{ED2A17AC-87A9-4640-9DE9-07AB5B63E902}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A1965763-A486-4E1E-B574-19E44B3842E8}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A1965763-A486-4E1E-B574-19E44B3842E8}, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [d9704fdd7d0e44f29120323c7c88ae52],
PUP.Optional.InstallBrain, HKLM\SOFTWARE\WOW6432NODE\InstallIQ, In Quarantäne, [9eabb874860561d5d708bbdaf4107a86],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [83c6c6667c0f5cda8b26ed8116ee629e],
Registrierungswerte: 2
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [d9704fdd7d0e44f29120323c7c88ae52]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [83c6c6667c0f5cda8b26ed8116ee629e]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 16
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.CheapMe, C:\Program Files (x86)\CheaPMee, In Quarantäne, [ac9d6dbf95f6b4828690a5dbe61e2dd3],
PUP.Optional.DownSave, C:\Program Files (x86)\DownSavoe, In Quarantäne, [ec5d83a92962ab8b3c2e06840400df21],
PUP.Optional.DownSave, C:\Program Files (x86)\DownSavvE, In Quarantäne, [63e616168605b38386e496f4778dab55],
PUP.Optional.GreatSave4U, C:\Program Files (x86)\GreaetSAve4Ua, In Quarantäne, [1336e844404b999d1a7bbed3ac58738d],
PUP.Optional.GreatSave4U, C:\Program Files (x86)\GreiatSavie4U, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.Happy2Save, C:\Program Files (x86)\Hoappey2Suave, In Quarantäne, [56f33cf04f3c0036b833b4dda460ad53],
PUP.Optional.Happy2Save, C:\Program Files (x86)\Huaappy22Save, In Quarantäne, [8fba31fb16754cea6e7d5e3352b26c94],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf\110, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp\1.1, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.ShopDrop, C:\Program Files (x86)\ShhopDrOp, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, C:\Program Files (x86)\SHopDreOp, In Quarantäne, [60e99498fb906dc9d9ecaa0314f0847c],
PUP.Optional.WhiteCoupon, C:\Program Files (x86)\WhiteCouppoN, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, In Quarantäne, [1a2f3bf1ccbfda5c7da60bec52b039c7],
Dateien: 63
Worm.Zhelatin, C:\Windows\System32\fsvk.exe.exe, In Quarantäne, [1c2d4ddf721976c066ed4c3ab84b946c],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\24e65afa53034dc8bcdb3599597de8b3.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\5ba3ff2d19c3f782649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\77e15c34faa6fcadbcdb3599597de8b3.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\24e88a37d2d9c836649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\25f68afcfdcc762a649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\28ffb307da9e37a9649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\35555c15a234937f649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\4775d99c57b1799e649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\4feba7a46853ce31bcdb3599597de8b3.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\509988526bee90c2649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\8299aeb44b557f91649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\9056980660156c5c649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\954accd1ef18255b649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\963a03e3172e9e7a649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\a4be4e28c0601c05649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\af0c9ff59bf040b6649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\bba61a27e9bcb9d0649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\c5dda88116364677649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\c964044650c9e4ef649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\d1b823d8a4cc4149649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\dd632212936319c2649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\eddc3f6e3bd42cbebcdb3599597de8b3.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\f7610c3afe2bbcd1649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\fe9396fa739170eb649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\610c92036204ce19649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\6757e794ec36f69e649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\67bb49a1cb4906ed649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\67c9553d6b57f65c649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\6d731089f6835f77649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\720f743a776772be649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\724359274a36321c649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\10180179805306874962\725ccee15bdf5c66649092430e78973d.ini, In Quarantäne, [222757d5cdbeb97de7a9512035cfde22],
PUP.Optional.CheapMe, C:\Program Files (x86)\CheaPMee\m0fOqRLslIobCq.tlb, In Quarantäne, [ac9d6dbf95f6b4828690a5dbe61e2dd3],
PUP.Optional.CheapMe, C:\Program Files (x86)\CheaPMee\m0fOqRLslIobCq.dat, In Quarantäne, [ac9d6dbf95f6b4828690a5dbe61e2dd3],
PUP.Optional.DownSave, C:\Program Files (x86)\DownSavoe\kLXRZed6mvALBd.tlb, In Quarantäne, [ec5d83a92962ab8b3c2e06840400df21],
PUP.Optional.DownSave, C:\Program Files (x86)\DownSavoe\kLXRZed6mvALBd.dat, In Quarantäne, [ec5d83a92962ab8b3c2e06840400df21],
PUP.Optional.DownSave, C:\Program Files (x86)\DownSavvE\wdO6Oi3pxm0U6G.tlb, In Quarantäne, [63e616168605b38386e496f4778dab55],
PUP.Optional.DownSave, C:\Program Files (x86)\DownSavvE\wdO6Oi3pxm0U6G.dat, In Quarantäne, [63e616168605b38386e496f4778dab55],
PUP.Optional.GreatSave4U, C:\Program Files (x86)\GreaetSAve4Ua\XJ9uFghmK9eDNq.tlb, In Quarantäne, [1336e844404b999d1a7bbed3ac58738d],
PUP.Optional.GreatSave4U, C:\Program Files (x86)\GreaetSAve4Ua\XJ9uFghmK9eDNq.dat, In Quarantäne, [1336e844404b999d1a7bbed3ac58738d],
PUP.Optional.GreatSave4U, C:\Program Files (x86)\GreiatSavie4U\t7jOHgBOlAICcQ.tlb, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.GreatSave4U, C:\Program Files (x86)\GreiatSavie4U\t7jOHgBOlAICcQ.dat, In Quarantäne, [0b3eb07c711a73c3a6f0bad7e321cd33],
PUP.Optional.Happy2Save, C:\Program Files (x86)\Hoappey2Suave\9GCRJzwwuFDWWC.tlb, In Quarantäne, [56f33cf04f3c0036b833b4dda460ad53],
PUP.Optional.Happy2Save, C:\Program Files (x86)\Hoappey2Suave\9GCRJzwwuFDWWC.dat, In Quarantäne, [56f33cf04f3c0036b833b4dda460ad53],
PUP.Optional.Happy2Save, C:\Program Files (x86)\Huaappy22Save\rqCXXj6b5G9Psg.tlb, In Quarantäne, [8fba31fb16754cea6e7d5e3352b26c94],
PUP.Optional.Happy2Save, C:\Program Files (x86)\Huaappy22Save\rqCXXj6b5G9Psg.dat, In Quarantäne, [8fba31fb16754cea6e7d5e3352b26c94],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf\110\lsdb.js, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf\110\background.html, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf\110\content.js, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf\110\jmuhi7tlN.js, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbnfdljglikamcdljmffmhfionigapkf\110\manifest.json, In Quarantäne, [fe4b98948cff3cfa5956f8a7877d46ba],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp\1.1\lsdb.js, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp\1.1\background.html, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp\1.1\content.js, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp\1.1\manifest.json, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.MultiPlug, C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Extensions\helbdicochoikmmbkbmnkhdbbojaaicp\1.1\x.js, In Quarantäne, [bf8af5378dfef3439b140699f70da25e],
PUP.Optional.ShopDrop, C:\Program Files (x86)\ShhopDrOp\yRFXhKJ3VElcAy.tlb, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, C:\Program Files (x86)\ShhopDrOp\yRFXhKJ3VElcAy.dat, In Quarantäne, [4900200c117ac76fe4e15e4f0afae719],
PUP.Optional.ShopDrop, C:\Program Files (x86)\SHopDreOp\iZ6gP1LDH6RI2r.tlb, In Quarantäne, [60e99498fb906dc9d9ecaa0314f0847c],
PUP.Optional.ShopDrop, C:\Program Files (x86)\SHopDreOp\iZ6gP1LDH6RI2r.dat, In Quarantäne, [60e99498fb906dc9d9ecaa0314f0847c],
PUP.Optional.WhiteCoupon, C:\Program Files (x86)\WhiteCouppoN\J5C0wb2eFULd5X.tlb, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
PUP.Optional.WhiteCoupon, C:\Program Files (x86)\WhiteCouppoN\J5C0wb2eFULd5X.dat, In Quarantäne, [d277a5875f2cdd5941d0b209fd075fa1],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) AdwCleaner[C1].txt Code:
# AdwCleaner v5.005 - Bericht erstellt am 05/09/2015 um 20:05:27
# Aktualisiert am 31/08/2015 von Xplode
# Datenbank : 2015-09-04.4 [Server]
# Betriebssystem : Windows 10 Home (x64)
# Benutzername : Ismael - ISMAEL-PC
# Gestartet von : C:\Users\Ismael\Downloads\AdwCleaner_5.005.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Program Files (x86)\SustainerPlus
[-] Ordner Gelöscht : C:\Program Files (x86)\CheaapME
[-] Ordner Gelöscht : C:\Program Files (x86)\GreatSuaveu4eU
[-] Ordner Gelöscht : C:\Program Files (x86)\ShoppDroPP
[-] Ordner Gelöscht : C:\Program Files (x86)\HowToSimplified
[-] Ordner Gelöscht : C:\ProgramData\apn
[-] Ordner Gelöscht : C:\ProgramData\738a36e400001d53
[-] Ordner Gelöscht : C:\ProgramData\{2da04bb5-ae6f-d3bc-2da0-04bb5ae62ed6}
[-] Ordner Gelöscht : C:\ProgramData\{9f4261e0-2bb2-cd6c-9f42-261e02bb8780}
[-] Ordner Gelöscht : C:\ProgramData\{d2bac945-acb4-2153-d2ba-ac945acb2516}
[-] Ordner Gelöscht : C:\ProgramData\{d8c6fbdc-b0b4-2193-d8c6-6fbdcb0bef72}
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
[-] Datei Gelöscht : C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
[-] Datei Gelöscht : C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.movshare.net_0.localstorage
[-] Datei Gelöscht : C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.movshare.net_0.localstorage-journal
[-] Datei Gelöscht : C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.reimageplus.com_0.localstorage
[-] Datei Gelöscht : C:\Users\Ismael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.reimageplus.com_0.localstorage-journal
[-] Datei Gelöscht : C:\WINDOWS\Reimage.ini
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\85068159-e7b8-1da9-cb09-fbc018da270d
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\ea494277-2f11-c0d1-a50d-18b431ff26e9
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92B989D7-D747-4BA3-A01E-B4D46EA6F5C1}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{BD601133-B03F-4C73-B593-DB2322CBD22E}
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[-] Schlüssel Gelöscht : HKCU\Software\Reimage
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E957849A-94AC-6F46-4623-C31474E3C170}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C206CC20-60D6-8D02-746E-4465CC40B2F6}
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\OCS
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\Reimage
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
***** [ Internetbrowser ] *****
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4370 Bytes] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 10 Home x64
Ran by Ismael on 05.09.2015 at 20:12:47,84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Ismael\Appdata\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped
[C:\Users\Ismael\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Ismael\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
ajopnjidmegmdimjlfnijceegpefgped
[C:\Users\Ismael\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Ismael\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
ajopnjidmegmdimjlfnijceegpefgped
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.09.2015 at 20:13:53,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |