Guten Tag Matthias, Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 03.12.20
Scan-Zeit: 16:26
Protokolldatei: e5acffb6-357b-11eb-b3ec-704d7b85adae.json
-Softwaredaten-
Version: 4.2.3.96
Komponentenversion: 1.0.1122
Version des Aktualisierungspakets: 1.0.33814
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19041.630)
CPU: x64
Dateisystem: NTFS
Benutzer: DESKTOP-HRMFF6U\Tom
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 402524
Erkannte Bedrohungen: 29
In die Quarantäne verschobene Bedrohungen: 29
Abgelaufene Zeit: 3 Min., 18 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 13
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Startfenster-Replace.de, In Quarantäne, 494, 350112, , , , , ,
PUP.Optional.WebDiscoverBrowser, HKU\S-1-5-21-3451750051-380284315-2914928687-1003\SOFTWARE\WebDiscoverBrowser, In Quarantäne, 1741, 253912, 1.0.33814, , ame, , ,
PUP.Optional.SearchManager, HKU\S-1-5-21-3451750051-380284315-2914928687-1003\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\icmgebopaejnjlncllgmcenbbflikfjd, In Quarantäne, 441, 521971, 1.0.33814, , ame, , ,
Adware.KeenValue, HKLM\SOFTWARE\WOW6432NODE\Updater, In Quarantäne, 6953, 212959, 1.0.33814, , ame, , ,
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\AM, In Quarantäne, 3395, 401432, 1.0.33814, , ame, , ,
PUP.Optional.eSupportUndeletePlus, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\ESUPPORT.COM\UndeletePlus, In Quarantäne, 3035, 355410, 1.0.33814, , ame, , ,
PUP.Optional.Conduit, HKU\S-1-5-21-3451750051-380284315-2914928687-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, 193, 236865, , , , , ,
PUP.Optional.Conduit, HKU\S-1-5-21-3451750051-380284315-2914928687-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, 193, 236865, , , , , ,
PUP.Optional.Conduit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, 193, 236865, , , , , ,
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, 193, 236865, , , , , ,
PUP.Optional.Conduit, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, 193, 236865, 1.0.33814, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, In Quarantäne, 494, 350115, 1.0.33814, , ame, , ,
PUP.Optional.StartFenster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Startfenster-Replace.exe, In Quarantäne, 494, 350115, 1.0.33814, , ame, , ,
Registrierungswert: 4
PUP.Optional.WinYahoo, HKU\S-1-5-21-3451750051-380284315-2914928687-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, In Quarantäne, 240, 311488, 1.0.33814, , ame, , ,
PUP.Optional.StartFenster.ShrtCln, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\AM|STARTFENSTER-REPLACE, In Quarantäne, 3395, 401432, 1.0.33814, , ame, , ,
PUP.Optional.Conduit, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, 193, 236865, 1.0.33814, , ame, , ,
PUP.Optional.Conduit, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURL, In Quarantäne, 193, 236865, 1.0.33814, , ame, , ,
Registrierungsdaten: 1
PUP.Optional.Conduit, HKU\S-1-5-21-3451750051-380284315-2914928687-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, 193, 293058, 1.0.33814, , ame, , ,
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
PUP.Optional.StartFenster, C:\PROGRAM FILES (X86)\STARTFENSTER-REPLACE, In Quarantäne, 494, 350112, 1.0.33814, , ame, , ,
PUP.Optional.StartFenster.ShrtCln, C:\USERS\TOM_ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTFENSTER-REPLACE, In Quarantäne, 3395, 401566, 1.0.33814, , ame, , ,
PUP.Optional.Spigot.Generic, C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4EKS1494.DEFAULT\BROWSER-EXTENSION-DATA\web@fd9b3d8a-1178-45ab-92a8-a172d0b7c32e, In Quarantäne, 199, 662625, 1.0.33814, , ame, , ,
Datei: 8
PUP.Optional.StartFenster, C:\PROGRAM FILES (X86)\STARTFENSTER-REPLACE\LOGO.ICO, In Quarantäne, 494, 350112, 1.0.33814, , ame, , BDCF63C89B22A44CDF5B1BE184714A26, C333C15AC24C7820F8E613E6878F1823514E15618CBBFE16161405CDE5270A39
PUP.Optional.StartFenster, C:\Program Files (x86)\Startfenster-Replace\uninstall.exe, In Quarantäne, 494, 350112, , , , , 56F998A44AAE1BF48DB4CE759517E31B, BC8DE31C4DE56F0421100BB5AC080F8A40CD47E7849723583D30378653327818
PUP.Optional.SearchManager, C:\USERS\VINCENT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NIU7SHOJ.DEFAULT\EXTENSIONS\{24436206-088D-4A1A-8D0E-CF93CA7A2D23}.XPI, In Quarantäne, 441, 733885, 1.0.33814, , ame, , E9BCE1FC758D9AFCFA92592D427312DA, 8A09ACBCD0CC91A846AB8E2513AF8C160D4F7C6B342B60121EB20628A1328B18
PUP.Optional.Spigot.Generic, C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4EKS1494.DEFAULT\EXTENSIONS\web@fd9b3d8a-1178-45ab-92a8-a172d0b7c32e.xpi, In Quarantäne, 199, 662624, 1.0.33814, , ame, , A9B894B4D518452B7522FCBA4CEF0673, 90AE7D0A96109274FA54EE0E53D47442DCA5F08674633960A4A299ABDB075911
PUP.Optional.StartFenster.ShrtCln, C:\Users\Tom_Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startfenster-Replace\Software deinstallieren.lnk, In Quarantäne, 3395, 401566, , , , , 0A944014F0EBD04BC6386FF32E5DE927, 3FC9D0B6D7B7AAF7FDCC87450F1C58FA350741DCB74212A1F4EC58AD89423C36
PUP.Optional.StartFenster.ShrtCln, C:\Users\Tom_Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startfenster-Replace\Startfenster.lnk, In Quarantäne, 3395, 401566, , , , , 1F0FFCD941BEC47D7D9186C34F6C97B4, 116B1FDBB69A3731B244036A455D252140D75F4C09D1BA9F74AA404EBEB1F1D0
PUP.Optional.Spigot.Generic, C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\4eks1494.default\browser-extension-data\web@fd9b3d8a-1178-45ab-92a8-a172d0b7c32e\storage.js, In Quarantäne, 199, 662625, , , , , E9C7F12032B73FEE5DAC2E520D9AC60A, 21D271A57088C03F4C55ADB8FD086CB34B06BD2008F1F2C05738963A29A74CCD
PUP.Optional.Conduit, C:\USERS\TOM_ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IYJ5BKBT.DEFAULT\PREFS.JS, Ersetzt, 193, 301520, 1.0.33814, , ame, , 5EC0434210134476D036A110840945A2, 8013D1D55EE47F1389225E045FF77B21A2754084E06CD44AA2D2B393E886EBE6
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) AdwCleaner brachte jedoch folgenden Schirm:
gefundene Elemente: 17 Abbrechen Quarantäne verschieben
In Quarantäne verschieben? Code:
# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-11-23.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-03-2020
# Duration: 00:00:01
# OS: Windows 10 Pro
# Cleaned: 17
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\Users\Tom_Admin\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG
Deleted C:\Users\Tom_Admin\AppData\Roaming\Lavasoft\Web Companion
***** [ Files ] *****
Deleted C:\Users\Tom_Admin\AppData\Roaming\Mozilla\Firefox\Profiles\iyj5bkbt.default\searchplugins\bing-lavasoft.xml
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Conduit
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Updater
Deleted HKLM\System\Setup\FirstBoot\Services\WCAssistantService
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\.DEFAULT\Software\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted HKU\S-1-5-18\SOFTWARE\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
Deleted Adaware Secure
Deleted Adaware Secure
Deleted Bing Default Search
Deleted Bing Default Search
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2903 octets] - [03/12/2020 16:37:20]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## Code:
RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) von Adlice Software
Mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Betriebssystem : Windows 10 (10.0.19041) 64 bits
Gestartet in : Normaler Modus
Benutzer : Tom [Administrator]
Gestartet von : C:\Users\Tom\Desktop\RogueKiller64.exe
Signaturen : 20201203_095755, Treiber : Geladen
Modus : Standard-Scan, Scannen -- Datum : 2020/12/03 16:48:30 (Dauer : 00:05:11)
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Prozesse ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Prozessmodule ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Dienste ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts-Datei ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Dateien ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Webbrowser ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Anti-Rootkit : 0 (Driver: Geladen) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ |