SP4RK1NG | 31.10.2014 12:43 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 31.10.2014
Scan Time: 12:10:45
Logfile: qwfasf.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.09.19.05
Rootkit Database: v2014.10.22.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: acer
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 341617
Time Elapsed: 27 min, 34 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 19
Adware.GamePlayLab, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110011221158}, , [dba6d41b7209d16532d0d8c69e6442be],
Adware.GamePlayLab, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110011221158}, , [dba6d41b7209d16532d0d8c69e6442be],
Adware.GamePlayLab, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110011221158}, , [dba6d41b7209d16532d0d8c69e6442be],
Adware.GamePlayLab, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110011221158}, , [dba6d41b7209d16532d0d8c69e6442be],
Adware.GamePlayLab, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110011221158}, , [dba6d41b7209d16532d0d8c69e6442be],
PUP.Optional.Wajam.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, , [afd29f50fd7e36007c5b701f53af32ce],
PUP.Optional.Wajam.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, , [afd29f50fd7e36007c5b701f53af32ce],
PUP.Optional.Yontoo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, , [2e5318d797e411259b8e0d7dad558b75],
PUP.Optional.Yontoo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, , [2e5318d797e411259b8e0d7dad558b75],
PUP.Optional.DealKeeper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Deal Keeper, , [166b32bd4f2cc5719dc07d93ee15a957],
PUP.Optional.DealKeeper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Deal Keeper, , [9fe25c934c2f74c2d18d9d736f946c94],
PUP.Optional.IWantThis.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\I Want This, , [740d06e9bbc0d75f939d65c3fb08758b],
PUP.Optional.MoviesToolBar.A, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\koyotesoftmoviestoolbarha, , [0f721dd2cbb0cd69e480c1789b68748c],
PUP.Optional.FastStart.A, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, , [8af7717ef388c571655550b58e7555ab],
PUP.Optional.DealPly.A, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje, , [cbb6ec033f3c75c1a95e2df1fe05f50b],
PUP.Optional.MoviesToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{e5d4f4fd-a039-4670-8354-633c30a5f54e}, , [8bf64ea17efdc076c5cd90794eb7b050],
PUP.Optional.MoviesToolBar.A, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E5D4F4FD-A039-4670-8354-633C30A5F54E}, , [8bf64ea17efdc076c5cd90794eb7b050],
PUP.Optional.MoviesToolBar.A, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E5D4F4FD-A039-4670-8354-633C30A5F54E}, , [8bf64ea17efdc076c5cd90794eb7b050],
PUP.Optional.MoviesToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5D4F4FD-A039-4670-8354-633C30A5F54E}, , [8bf64ea17efdc076c5cd90794eb7b050],
Registry Values: 2
PUP.Optional.FastStart.A, HKU\S-1-5-21-3090159671-3938598571-1968455546-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, , [8af7717ef388c571655550b58e7555ab]
PUP.Optional.MoviesToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{E5D4F4FD-A039-4670-8354-633C30A5F54E}, Movies Toolbar (Dist. by Koyote-Lab, Inc.), , [8bf64ea17efdc076c5cd90794eb7b050]
Registry Data: 0
(No malicious items detected)
Folders: 6
PUP.Optional.Conduit.A, C:\Users\acer\AppData\Local\Temp\CT3202918, , [94ed25ca067566d0a4aaa92d21e17c84],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Roaming\FunmoodsChat\UpdateProc, , [0b76ae41abd0ce68db3827b611f1cd33],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk, , [532edf10c3b831056f79776756acb848],
PUP.Optional.MoviesToolbar.A, C:\Users\acer\AppData\Local\koyotesoftmoviestoolbarha, , [176a42ad007b03331c614a9c42c040c0],
PUP.Optional.MoviesToolbar.A, C:\Users\acer\AppData\Local\koyotesoftmoviestoolbarha\GC, , [176a42ad007b03331c614a9c42c040c0],
Files: 54
PUP.Optional.Koyote.A, C:\Program Files (x86)\Free Easy CD DVD Burner\Uninstall.exe, , [b8c95b946a1173c3851867e9be43a957],
PUP.Optional.SearchProtect.A, C:\Users\acer\AppData\Local\Temp\nsaBB1C.exe, , [3a477a75eb905adcab480d2c61a06f91],
PUP.Optional.Iminent.A, C:\Users\acer\AppData\Local\Temp\IminentSetup.exe, , [2d541ad5403ba393fb3af34b28d918e8],
PUP.Optional.SearchProtect.A, C:\Users\acer\AppData\Local\Temp\nskC1C1.exe, , [275ac42bfe7d9b9bec0773c6e918fe02],
PUP.Optional.SearchProtect.A, C:\Users\acer\AppData\Local\Temp\nsp1A96.exe, , [b9c83eb1eb90b383b83b66d37c859d63],
PUP.Optional.SearchProtect.A, C:\Users\acer\AppData\Local\Temp\nsp1E3F.exe, , [71108b6448337abc579c56e326db53ad],
PUP.Optional.SearchProtect.A, C:\Users\acer\AppData\Local\Temp\nsq6C41.exe, , [b8c98c63d4a7d66040b3be7bb9485ba5],
PUP.Optional.SearchProtect.A, C:\Users\acer\AppData\Local\Temp\nsv16BF.exe, , [176a727d95e637ff757e50e916eb24dc],
Adware.Korad, C:\Users\acer\AppData\Local\Temp\nspBA9A.tmp\basicstarter.exe, , [621fc52a522948eefe7748f8b34e629e],
PUP.Optional.OpenCandy, C:\Users\acer\AppData\Local\Temp\is-SLOM1.tmp\OCSetupHlp.dll, , [7f026c83fd7e38fe79aaef3cd43109f7],
PUP.Optional.Dealply, C:\Users\acer\AppData\Local\Temp\is1590112554\dealply.exe, , [1170cf204239112566915bcf4eb735cb],
PUP.Optional.IWantThis.A, C:\Users\acer\AppData\Local\Temp\is1590112554\IWantThis_ROW.exe, , [9ee36d82d8a3dd59d60ec3d2ea17926e],
PUP.Optional.Babylon.A, C:\Users\acer\AppData\Local\Temp\is1590112554\MyBabylonTB.exe, , [1f62a7485e1d3204797e5ec0b44c13ed],
PUP.Optional.Wajam.A, C:\Users\acer\AppData\Local\Temp\is1590112554\Wajam.exe, , [364b935c245793a339f0440341bfb947],
PUP.Optional.MoviesToolbar.A, C:\Windows\Temp\e942428e\SetupDataMngr_Koyote.exe, , [621fc9265922da5c4bf48e9aa55ce917],
PUP.Optional.SweetPacks.A, C:\Users\acer\AppData\Local\Temp\BundleSweetIMSetup.exe, , [e49d836ca9d2df577a7ce82821e241bf],
PUP.Optional.Delta.A, C:\Users\acer\AppData\Local\Temp\DeltaTB.exe, , [a2dfe00f562561d5b641f11f2ad904fc],
PUP.Optional.Babylon.A, C:\Users\acer\AppData\Local\Temp\MybabylonTB.exe, , [4f3208e790eb62d44eaaf51bf50e738d],
PUP.Optional.FunMoods.A, C:\Windows\System32\Tasks\Funmoods Chat, , [a2df618e4d2edf57b57ca3713ac9e51b],
PUP.Optional.FunMoods.A, C:\Windows\Tasks\Funmoods Chat.job, , [5031df108eed3afcbc76e52fb74c17e9],
PUP.Optional.Superfish.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [b2cf08e793e83ef87238ee320af9d22e],
PUP.Optional.Superfish.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [1170a14e5625bc7a3971e7397a8901ff],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mpfapcdfbbledbojijcbcclmlieaoogk_0.localstorage-journal, , [f68baf40f883ab8b63c7df495ba8f808],
PUP.Optional.Wajam.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpmbfleldcgkldadpdinhjjopdfpjfjp_0.localstorage, , [e79ad11e39422a0ca74481a98281a759],
PUP.Optional.Wajam.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpmbfleldcgkldadpdinhjjopdfpjfjp_0.localstorage-journal, , [96ebe30c552662d4d81337f31ce749b7],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Local\funmoods_2.3.1.crx, , [bcc5c72886f57fb7d567dd8e9b69639d],
PUP.Optional.Funmoods.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage-journal, , [38496c836f0c1422a239b2b908fc8878],
PUP.Optional.Conduit.A, C:\Users\acer\AppData\Local\Temp\CT3202918\CT3202918.txt, , [94ed25ca067566d0a4aaa92d21e17c84],
PUP.Optional.Conduit.A, C:\Users\acer\AppData\Local\Temp\CT3202918\initData.json, , [94ed25ca067566d0a4aaa92d21e17c84],
PUP.Optional.Conduit.A, C:\Users\acer\AppData\Local\Temp\CT3202918\manifest.json, , [94ed25ca067566d0a4aaa92d21e17c84],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha\apnuserid.dat, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha\appid.dat, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha\geodata.xml, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha\setupCfg.xml, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha\sysid.dat, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.MoviesToolBar.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\koyotesoftmoviestoolbarha\trackid.dat, , [730e5e91ea915dd992effbe015edb34d],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Roaming\FunmoodsChat\UpdateProc\config.dat, , [0b76ae41abd0ce68db3827b611f1cd33],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Roaming\FunmoodsChat\UpdateProc\info.dat, , [0b76ae41abd0ce68db3827b611f1cd33],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Roaming\FunmoodsChat\UpdateProc\src.dat, , [0b76ae41abd0ce68db3827b611f1cd33],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Roaming\FunmoodsChat\UpdateProc\STTL.DAT, , [0b76ae41abd0ce68db3827b611f1cd33],
PUP.Optional.FunMoods.A, C:\Users\acer\AppData\Roaming\FunmoodsChat\UpdateProc\TTL.DAT, , [0b76ae41abd0ce68db3827b611f1cd33],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\001887.ldb, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\001898.ldb, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\001903.ldb, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\001918.ldb, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\001919.log, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\CURRENT, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\LOCK, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\LOG, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\LOG.old, , [532edf10c3b831056f79776756acb848],
PUP.Optional.CrossRider.A, C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mpfapcdfbbledbojijcbcclmlieaoogk\MANIFEST-001917, , [532edf10c3b831056f79776756acb848],
PUP.Optional.MoviesToolbar.A, C:\Users\acer\AppData\Local\koyotesoftmoviestoolbarha\GC\toolbar.crx, , [176a42ad007b03331c614a9c42c040c0],
PUP.Optional.SweetPage.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "hxxp://www.sweet-page.com/newtab/?type=nt&ts=1411906429&from=cor&uid=TOSHIBAXMQ01ABD032_91HFB6QYBXX91HFB6QYB");), ,[0a7719d61b6085b134c048f160a56997]
PUP.Optional.SweetPage.A, C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\mo5qape1.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://www.sweet-page.com/?type=hp&ts=1411906429&from=cor&uid=TOSHIBAXMQ01ABD032_91HFB6QYBXX91HFB6QYB");), ,[88f988673a4174c2fafb58e1ab5a6f91]
Physical Sectors: 0
(No malicious items detected)
(end) Soll ich das bereinigen? |