ich habe jetzt Malware ausgeführt. Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 06.05.17
Scan-Zeit: 13:20
Protokolldatei: Malware.txt
Administrator: Ja
-Softwaredaten-
Version: 3.0.6.1469
Komponentenversion: 1.0.103
Version des Aktualisierungspakets: 1.0.1713
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: MAX1\Lutz
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 667038
Abgelaufene Zeit: 1 Min., 22 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 7
PUP.Optional.WebSteroids, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [5818], [169013],1.0.1713
PUP.Optional.CrossAd, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Virtual Mart, In Quarantäne, [774], [258196],1.0.1713
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE, In Quarantäne, [9351], [239345],1.0.1713
PUP.Optional.SmileysWeLove, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\fjbbjfdilbioabojmcplalojlmdngbjl, In Quarantäne, [7412], [243213],1.0.1713
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE, In Quarantäne, [9351], [239345],1.0.1713
PUP.Optional.CleanBrowser, HKLM\SOFTWARE\WOW6432NODE\Clean Browser, In Quarantäne, [1497], [236596],1.0.1713
PUP.Optional.Infonaut, HKLM\SOFTWARE\WOW6432NODE\Infonaut_1.10.0.14, In Quarantäne, [12023], [239521],1.0.1713
Registrierungswert: 2
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE|DEBUGGER, In Quarantäne, [9351], [239345],1.0.1713
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE|DEBUGGER, In Quarantäne, [9351], [239345],1.0.1713
Registrierungsdaten: 2
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [14049], [292819],1.0.1713
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [14049], [292819],1.0.1713
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 21
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\CanvasFramework, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\AppFramework, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\PROGRAM FILES (X86)\Clean Browser, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\CanvasFramework, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\AppFramework, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework-ui, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\USERS\LUTZ\APPDATA\LOCAL\Clean Browser, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\zo5azs8h.default\jetpack\@C88E6AE462306619BA2DBD89699AE5CBC88E\simple-storage, In Quarantäne, [9191], [175230],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZO5AZS8H.DEFAULT\JETPACK\@C88E6AE462306619BA2DBD89699AE5CBC88E, In Quarantäne, [9191], [175230],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\{B5E5BF6E-89AA-960E-3A7E-B06ECF19AE7E}, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component2, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\LOCAL\VIRTUAL MART, In Quarantäne, [9335], [301775],1.0.1713
Datei: 48
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\bottom-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\bottom-middle.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\bottom-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\middle-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\middle-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-bottom.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-top.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\top-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\top-middle.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\top-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\context_menu_item_handler.html, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\notification.html, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\button.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon100.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon128.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon32.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon48.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\background.html, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\config.xml, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\extension_info.json, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework-ui\contentNotification.tmpl, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework-ui\contentNotificationStyle.tmpl, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\button.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon100.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon128.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon32.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon48.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\background.html, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\chrome.manifest, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\extension_info.json, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\install.rdf, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\icon.ico, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\info.xml, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\zo5azs8h.default\jetpack\@C88E6AE462306619BA2DBD89699AE5CBC88E\simple-storage\store.json, In Quarantäne, [9191], [175230],1.0.1713
PUP.Optional.Komodia.WnskRST, C:\WINDOWS\SYSTEM32\ZDENGINE64.DLL.XTH, In Quarantäne, [1293], [106355],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\LOCAL\VIRTUAL MART\COMPONENT\CONFIG.JSON, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\hello.js, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\manifest.json, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\scriptTagContext.js, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\tmp_bg.js, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\uconfig.json, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component2\plugin, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\{B5E5BF6E-89AA-960E-3A7E-B06ECF19AE7E}\c.dat, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.FireFoxHijack, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DEFAULTS\PREF\!C88E6AE462306619BA2DBD89699AE5CBC88E.js, In Quarantäne, [15389], [255361],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\zo5azs8h.default\EXTENSIONS\@C88E6AE462306619BA2DBD89699AE5CBC88E.xpi, In Quarantäne, [9335], [184242],1.0.1713
PUP.Optional.ASK, C:\WINDOWS\INSTALLER\AF88A6B.MSI, In Quarantäne, [507], [113867],1.0.1713
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end)
hier die Eset Log-Datei. Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=5ca4483085e8584b84d51ba8b46e781d
# end=init
# utc_time=2017-05-06 11:50:10
# local_time=2017-05-06 01:50:10 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 33293
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=5ca4483085e8584b84d51ba8b46e781d
# end=updated
# utc_time=2017-05-06 11:55:39
# local_time=2017-05-06 01:55:39 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=5ca4483085e8584b84d51ba8b46e781d
# engine=33293
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-05-06 04:53:53
# local_time=2017-05-06 06:53:53 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1313 16777213 100 100 19616 27020167 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 2138835 25420247 0 0
# scanned=1158571
# found=22
# cleaned=0
# scan_time=17894
sh=7785A52571E33004F672F377702283F4A9EDA3EF ft=1 fh=cdc63b8e611b185a vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\tmhkspcpyycdxgbgcjusamjvzcxoompi.back"
sh=9434D1A5D56479988254608D5289E1E9D488DC54 ft=1 fh=c2a767356ec8b23d vn="Variante von Win64/BubbleSound.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ehubopdtuzssqqlbgubvypnigylxmdbi\Spacesoundpro.exe"
sh=6CD8F4D8CEDA7C26BA7BACAFE1DC4BB7E15CF4F3 ft=1 fh=3f2051e5689d0e4e vn="Variante von Win32/RiskWare.Komodia.P Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\poz.exe"
sh=84BE5BD91D0C71E48742CC73142BDE2CA660577E ft=1 fh=e2502c2849e93514 vn="Variante von Win64/Packed.Komodia.F verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\ZDDLL64.dll"
sh=5682BC51CFAB8600C36F2DB618C9B85073E0CE0B ft=1 fh=4779d45bd322e98f vn="Variante von Win64/Packed.Komodia.D verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\ZDDLL64.exe"
sh=2DA3E222C6F2386EC3EB3B94CC6A1499B0606400 ft=1 fh=633b179028a128f6 vn="Variante von Win64/Packed.Komodia.C verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\zdengine64.dll"
sh=F10A2DD02135A33B20BE9B83371573F9238C0441 ft=1 fh=a60e2c886c049a59 vn="Variante von Win32/RiskWare.Komodia.P Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\zdinstaller.exe"
sh=7C6956D60DBAB5B221531B3C455CA220A94DF88D ft=1 fh=7902e2018bdb389f vn="Variante von Win32/RiskWare.Komodia.S Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\zdwfp.sys"
sh=B79587C2FE2F383E0C7C7123EDBBC7782340655B ft=1 fh=51c2ef72891b8b1c vn="Variante von Win64/Riskware.Komodia.G Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\zdwfp64.sys"
sh=AA2847BF0F8700990FCCFA42B4036C3577073812 ft=1 fh=f01ad64cc016282d vn="Variante von Win64/Packed.Komodia.D verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\jklzqsnpgvnzubhqzmmmsugeoqntprfu\ziengine64.exe"
sh=D62E826B13E242DC0BABCAD05E3A4613795A024F ft=0 fh=0000000000000000 vn="Win32/Toolbar.TNT2.I eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\ffsearch_toolbar!1.0.0.1025.xpi"
sh=1C88A7C4FD5E9BBE5F558AB731149EC1E59A67AC ft=0 fh=0000000000000000 vn="Win32/Toolbar.TNT2.I eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\ffsearch_toolbar!1.0.0.1031.xpi"
sh=8AD8391DD5AAEDBF813263C06374FD02FCBE84A0 ft=0 fh=0000000000000000 vn="JS/Agent.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\indexIE.html"
sh=C5779D3352BC1A01648363E79F3A4D4E0AC89DC0 ft=0 fh=0000000000000000 vn="JS/Lightning.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\js\common.js"
sh=3F837F566A8BDD89CCF1DA6B16F0006CFF1333DE ft=0 fh=0000000000000000 vn="JS/Lightning.B eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\js\jquery.autocomplete.js"
sh=DDA025668542C1D4F800A7EB06C800783DB4108E ft=0 fh=0000000000000000 vn="JS/Lightning.C eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\js\js.js"
sh=AD3CF293BE50515DB4A093EB10D9C1C6AA6D847E ft=0 fh=0000000000000000 vn="JS/Lightning.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\js\xagainit-ie8.js"
sh=3AEB3F19AB22354A6AAA0D231805325B4A3277DC ft=0 fh=0000000000000000 vn="JS/Lightning.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\js\xagainit.js"
sh=283A16F1BAC5672FC3F607AA4F75EDE1C8DB2CE2 ft=0 fh=0000000000000000 vn="JS/Lightning.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nkozabbqpegydbdkrolfzfzkidmgkjzo\web\js\xagainit2.0.js"
sh=43A9EA62FD1AC014F8F1E59AE3B54D6009DFDB9C ft=1 fh=a80f954449119bd9 vn="Variante von Win32/Downloader.Agent.BK eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ojdrmhgaxmugvnuoxbqlyycekgyfdbaa\Fast_Support.exe"
sh=DAFB9B854523B4C96892DF99C83F50C50998DE33 ft=1 fh=f218c7aa065f98c7 vn="Variante von Win32/DownloadGuide.C eventuell unerwünschte Anwendung" ac=I fn="E:\Temp\Downloads\Sketchup\google-sketchup.exe"
sh=1E9E2141B3F44DE4EADBF619EE203B97E4DC5611 ft=1 fh=5efced8b62b089e2 vn="Win32/DownloadGuide.J eventuell unerwünschte Anwendung" ac=I fn="F:\Temp\Download_c\PDF-DWG\aide-pdf-to-dxf-converter-11.0-setup.exe"
Hier der Security check checkup.txt Code:
Results of screen317's Security Check version 1.009
x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Kaspersky Internet Security
Windows Defender
Malwarebytes
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
TuneUp Utilities 2014
TuneUp Utilities 2014 (de-DE)
TuneUp Utilities 2014
Mozilla Firefox (53.0)
Mozilla Thunderbird (45.8.0) ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamtray.exe
Kaspersky Lab Kaspersky Internet Security 17.0.0 avp.exe
Kaspersky Lab Kaspersky Internet Security 17.0.0 avpui.exe
Kaspersky Lab Kaspersky Secure Connection 1.0 ksde.exe
Kaspersky Lab Kaspersky Secure Connection 1.0 ksdeui.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: % ````````````````````End of Log``````````````````````
|