Hier noch das entzippte Malwarebytes-Log von kodela
Code
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 02.04.2015
Suchlauf-Zeit: 23:00:55
Logdatei: Malwarebytes Anti-Malware.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: Konrad
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 465180
Verstrichene Zeit: 39 Min, 16 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 4
PUP.Optional.Booster.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{22134214}, , [eb8e0e358109a294335302cfb44f12ee],
PUP.Optional.Wajam.A, HKU\S-1-5-21-64654561-3677154570-2514109428-1000\SOFTWARE\WajIEnhance, , [ff7a77cc3c4e4ceafeac2a8831d27987],
PUP.Optional.IStart.A, HKU\S-1-5-21-64654561-3677154570-2514109428-1000\SOFTWARE\MOZILLA\EXTENDS, , [db9ef54eb3d79a9c72ab4e5890731fe1],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WaNetworkEnhance, , [582192b15238181e96bee78209faf010],
Registrierungswerte: 3
PUP.Optional.SearchEngine.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|searchengine@gmail.com, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com, , [ceab3310e1a9e056fe7470c70cf913ed]
PUP.Optional.IStart.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|istart_ffnt@gmail.com, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\istart_ffnt@gmail.com, , [5821152e3654280e00528124e61d09f7]
PUP.Optional.IStart.A, HKU\S-1-5-21-64654561-3677154570-2514109428-1000\SOFTWARE\MOZILLA\EXTENDS|appid, istart_ffnt@gmail.com, , [db9ef54eb3d79a9c72ab4e5890731fe1]
Registrierungsdaten: 2
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[adcce75c860487af7129845df70e30d0]
PUP.Optional.Trovi.A, HKU\S-1-5-21-64654561-3677154570-2514109428-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.trovi.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M7210B23B-E3E7-4836-8F6D-3411ADE5E9AB&SearchSource=55&CUI=&UM=8&UP=SP99AFCFDD-B3C8-4EBC-B11C-E9997A7E0D6B&D=040115&SSPV=, Gut: (www.google.com), Schlecht: (http://www.trovi.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M7210B23B-E3E7-4836-8F6D-3411ADE5E9AB&SearchSource=55&CUI=&UM=8&UP=SP99AFCFDD-B3C8-4EBC-B11C-E9997A7E0D6B&D=040115&SSPV=),,[a8d164df39515bdbc24b30a764a19b65]
Ordner: 31
PUP.Optional.XTab.A, C:\Program Files\XTab, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\image, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\en-US, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-419, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-ES, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-BE, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CA, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CH, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-FR, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-LU, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-CH, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-IT, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pl, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt-BR, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru-MO, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\tr-TR, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\vi-VI, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-CN, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-TW, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.Wajam.A, C:\Program Files\Wajam, , [582192b15238181e96bee78209faf010],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome\content, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome\skin, , [225762e1d1b96fc7524d277a55aee51b],
Dateien: 78
PUP.Optional.BrowserWatch, C:\Program Files\XTab\BrowerWatchCH.dll, , [f68395aeb0da94a265973c31a45c05fb],
PUP.Optional.BrowserWatch, C:\Program Files\XTab\BrowerWatchFF.dll, , [f98052f12664e84e7587e48935cb29d7],
PUP.Optional.ELEX, C:\Program Files\XTab\HPNotify.exe, , [d2a7b39061290b2bdb368ea1ab57fc04],
PUP.Optional.XTab.A, C:\Program Files\XTab\ProtectService.exe, , [c6b3a1a2f79320164d0437d761a1b54b],
PUP.Optional.SupTab.A, C:\Program Files\XTab\SupTab.dll, , [2d4c81c24743fd39a32968cd16eaf30d],
PUP.Optional.Softonic.A, C:\Users\Rudi\AppData\Local\Temp\aZw9y57u.exe.part, , [4039b2916525cb6bfbffd4763ac741bf],
PUP.Optional.Bandoo, C:\Users\Rudi\AppData\Local\Temp\Ngsd9pqS.exe.part, , [681141027c0e7eb83c64959f956c06fa],
PUP.Optional.Trovi.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\searchplugins\trovi.xml, , [4a2f81c299f1c5710009adf7dd26d42c],
PUP.Optional.XTab.A, C:\Program Files\XTab\uninstall.exe, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\BrowserAction.dll, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\CmdShell.exe, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\conf, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\ffsearch_toolbar!1.0.0.1025.xpi, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\IeWatchDog.dll, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcp110.dll, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\msvcr110.dll, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\searchProvider.xml, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\about.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\about_bk.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\btn.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\btn_apply.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\close.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\conf.xml, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\conf_back.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\input_bk.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\logo.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\main.xml, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\radio_1.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\radio_2.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\rigth_arrow.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\skin\settings.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\data.html, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\indexIE.html, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\indexIE8.html, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\main.css, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\ver.txt, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\google_trends.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\icon128.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\icon16.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\icon48.png, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\loading.gif, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\img\logo32.ico, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\common.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\ga.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\jquery-1.11.0.min.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\jquery.autocomplete.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\js.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\library.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\xagainit-ie8.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\js\xagainit2.0.js, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\en-US\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-419\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\es-ES\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-BE\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CA\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-CH\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-FR\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\fr-LU\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-CH\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\it-IT\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pl\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\pt-BR\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\ru-MO\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\tr-TR\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\vi-VI\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-CN\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.XTab.A, C:\Program Files\XTab\web\_locales\zh-TW\messages.json, , [0e6b271c09812610647a436dc63df20e],
PUP.Optional.IStartSurf.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\searchplugins\istartsurf.xml, , [b9c04201c4c6ea4c502cdbee788b6997],
PUP.Optional.Wajam.A, C:\Program Files\Wajam\uninstall.exe, , [582192b15238181e96bee78209faf010],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome.manifest, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\install.rdf, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome\content\toolbar.js, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome\content\toolbar.xul, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.SearchEngine.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\extensions\searchengine@gmail.com\chrome\skin\icon.png, , [225762e1d1b96fc7524d277a55aee51b],
PUP.Optional.QuickStart.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), ,[45342a19bbcf290da526f627d2345ca4]
PUP.Optional.IStartSurf.A, C:\Users\Konrad\AppData\Roaming\Mozilla\Firefox\Profiles\f4k8j7io.default\search.json, Gut: (), Schlecht: (istartsurf), ,[9cddc1824545a195028dcd4ec83e7888]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
Alles anzeigen