Hallo Deathkid535
hier das Logfile: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 02.01.2017
Suchlaufzeit: 18:59
Protokolldatei: test1.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2017.01.02.03
Rootkit-Datenbank: v2016.11.20.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: *********
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 397316
Abgelaufene Zeit: 12 Min., 22 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe, 1872, Löschen bei Neustart, [8f8ca7d001a7c076bfdca7c45ba59c64]
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 17
PUP.Optional.SnapDo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [bb60077000a840f639e24c1cd82a40c0],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Amazon 1Button App Service, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\TYPELIB\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\INTERFACE\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\INTERFACE\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.SoftMedia, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\POWERPACK, In Quarantäne, [9d7e7afd01a7e65036c0d9baa9578080],
PUP.Optional.Linkury, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\SMARTBAR, In Quarantäne, [73a86413a800dc5a490503478a79fa06],
Registrierungswerte: 4
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [39e22552763287afb9219023a260eb15]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [51ca0b6c317782b4e5f5ddd634ce9769]
PUP.Optional.SoftMedia, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\POWERPACK|guid, 0c80f0ee304741d0b127faa7316db298, In Quarantäne, [9d7e7afd01a7e65036c0d9baa9578080]
PUP.Optional.Linkury, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\SMARTBAR|publisher, YahooSM, In Quarantäne, [73a86413a800dc5a490503478a79fa06]
Registrierungsdaten: 5
PUP.Optional.HelperBar, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}),Ersetzt,[3be03047c7e19f971e95657b16ed6b95]
PUP.Optional.HelperBar, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}),Ersetzt,[ca515a1d00a84beb6c47f9e7d72c4cb4]
PUP.Optional.HelperBar, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}),Ersetzt,[79a282f521874fe7555ffee244bfa25e]
PUP.Optional.HelperBar, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}),Ersetzt,[8e8d85f2921667cfded61fc1e41fb050]
PUP.Optional.HelperBar, HKU\S-1-5-21-1140464604-2781806460-1298829599-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q={searchTerms}),Ersetzt,[fd1e7601347478be3382f0f0cf34728e]
Ordner: 6
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp, Löschen bei Neustart, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\*********\AppData\Roaming\Auslogics\Disk Defrag, In Quarantäne, [59c20f68a3053afc335c5a531ee2f50b],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\*********\AppData\Roaming\Auslogics\Disk Defrag\Reports, In Quarantäne, [59c20f68a3053afc335c5a531ee2f50b],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
Dateien: 16
PUP.Optional.InstallCore, C:\Users\*********\OneDrive\SetupCamStudio_v2.7.4.exe, In Quarantäne, [b06b50273870b48216726b22ca3738c8],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI818B.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [55c62354891f78be910d933dc13fbe42],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIBAF4.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [98835324acfc4beb5e40339d966ae41c],
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe, Löschen bei Neustart, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE64.dll, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE64.dll, In Quarantäne, [8f8ca7d001a7c076bfdca7c45ba59c64],
PUP.Optional.WebSearch, C:\Users\*********\AppData\Roaming\Mozilla\Firefox\Profiles\ied2kk72.default\searchplugins\Web Search.xml, In Quarantäne, [9a8174034464b1857aa88bd10300bf41],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\*********\AppData\Roaming\Auslogics\Disk Defrag\DD_ExclusionsList.dat, In Quarantäne, [59c20f68a3053afc335c5a531ee2f50b],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\*********\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.html, In Quarantäne, [59c20f68a3053afc335c5a531ee2f50b],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\*********\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.xml, In Quarantäne, [59c20f68a3053afc335c5a531ee2f50b],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.Yontoo, C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll, In Quarantäne, [44d79ed97632b48222cc098f9a68c23e],
PUP.Optional.HelperBar, C:\Users\*********\AppData\Roaming\Mozilla\Firefox\Profiles\ied2kk72.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82Ku2hxa_0MSjagS5fguROCNnmwiCOb5GtEqahCg9ajadGXi20F_HTXWlD4ubU9L0TdJELonYO13wwjAWvtq_SUigtzEkytzqUKsCRl6VZXRGjZkKD5CggtsKXCYVtf9FC5b0IRpGkZD_sru7a3yMaKhpk_1fcr7qIKozg,,&q=");), Ersetzt,[a7745c1b862254e22801aa492ed57e82]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) |