Malwarebytes Anti-Malware
www.malwarebytes.org
Date : 27.06.2016
Suchlaufzeit: 22:40
Version: 2.2.1.1043
Malware-Datenbank: v2016.06.27.06
Rootkit-Datenbank: v2016.05.27.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Registrierungsschlüssel: 12
PUP.Optional.HohoSearch, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ArhCntservice, , [29c932cf257549edcd955f87728fd12f],
PUP.Optional.HohoSearch, HKLM\SOFTWARE\CLASSES\CLSID\{98C066AB-D735-4339-9E52-A34875141B56}, , [a151778a9604d4628b7de3b4ae5420e0],
Trojan.ProxyHijacker, HKLM\SOFTWARE\CLASSES\Nexus_7_root_toolkit_v.1.5.DynamicNS, , [43af15eca7f334027214148140c2b848],
Trojan.ProxyHijacker, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Nexus_7_root_toolkit_v.1.5.DynamicNS, , [16dc13eedfbb1d194c3a5e37c9398d73],
Trojan.ProxyHijacker, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Nexus_7_root_toolkit_v.1.5.DynamicNS, , [16dc13eedfbb1d194c3a5e37c9398d73],
PUP.Optional.Komodia.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5CA6199E-204C-480A-AF55-DE1F4C1CC751}, , [658d2ed3683238febc3d5e9aa162cf31],
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EB8450D9-9FFD-4E8F-97FC-20EE36546DBD}, , [569ccb36bfdb6fc791be14eb47bc6e92],
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Arahick Controls, , [6b8730d17f1b72c46fe124db956eb749],
PUP.Optional.Komodia.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\rde3028, , [559d09f8881248ee39c1ea0eea19bb45],
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, , [2dc527dadfbb2a0c48c2a05de22110f0],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\mtSilsolis, , [c230a75a7f1bd36328884da81be808f8],
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3482407538-2142533698-2377789723-1001\SOFTWARE\mtSilsolis, , [7a788879306aa294503d2aca14ef01ff],
Registrierungswerte: 5
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT|help,
http://d2ucfwpxlh3zh3.cloudfront.ne...6D37E4C6C7D1586893F0315&ptid=isr&mode=loadmex, , [d31faf5229713df9f08ef50aee15cc34]
PUP.Optional.Komodia.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5CA6199E-204C-480A-AF55-DE1F4C1CC751}|Path, \rde3028, , [658d2ed3683238febc3d5e9aa162cf31]
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EB8450D9-9FFD-4E8F-97FC-20EE36546DBD}|Path, \Arahick Controls, , [569ccb36bfdb6fc791be14eb47bc6e92]
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp,
http://d2ucfwpxlh3zh3.cloudfront.ne...37E4C6C7D1586893F0315&ptid=isr&mode=ffsengext, , [2dc527dadfbb2a0c48c2a05de22110f0]
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab,
http://d2ucfwpxlh3zh3.cloudfront.ne...37E4C6C7D1586893F0315&ptid=isr&mode=ffsengext, , [2ac8e31e514975c16c9e43ba3bc88d73]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 4
PUP.Optional.FastWeb, C:\Program Files (x86)\FastWeb, , [6e842cd50298e94d802c37904eb4ed13],
PUP.Optional.HohoSearch, C:\Program Files (x86)\Bodekmuocult, , [3eb412ef45551d194cef30980200f40c],
PUP.Optional.HohoSearch, C:\Program Files (x86)\Arahick, , [cd25a25f6d2d74c20c387355966ce41c],
PUP.Optional.HohoSearch, C:\Program Files (x86)\Arkosshocult, , [5999946d6238270f0c396365cb37fc04],
Dateien: 12
PUP.Optional.HohoSearch, C:\Program Files (x86)\Arahick\ArhCntservice.html5, , [29c932cf257549edcd955f87728fd12f],
PUP.Optional.HohoSearch, C:\Program Files (x86)\Arahick\ArhCnttask.exe, , [de14d42dd4c6d6604a1884628b7628d8],
PUP.Optional.OpenCandy, C:\$Recycle.Bin\S-1-5-21-3482407538-2142533698-2377789723-1001\$RO8XA37.exe, , [8f6391707327c0761a9471fcd52f6f91],
PUP.Optional.DownloadGuide, C:\$Recycle.Bin\S-1-5-21-3482407538-2142533698-2377789723-1001\$R1K43VX.crdownload, , [985a926fe0ba092d06238abfb34d14ec],
PUP.Optional.Wajam, C:\Users\Matijas\AppData\Local\Temp\25AE7258-DC16-4F0A-A4FF-808B3478761C\s2s_install.exe, , [f5fda25f71297abcdf0e432b3dc7916f],
PUP.Optional.Komodia, C:\Windows\Temp\zdengine.log, , [0ee416eb63370f27f090e30a9a69926e],
PUP.Optional.GsearchFinder, C:\Users\Matijas\AppData\Roaming\Profiles\st7njx15.default\extensions\@A3592ADB-854A-443A-854E-EB92130D470D.xpi, , [648e946d2c6eeb4b2dba01fbd330e818],
PUP.Optional.GsearchFinder, C:\Users\Matijas\AppData\Roaming\Profiles\yzzfdyu4.default\extensions\@A3592ADB-854A-443A-854E-EB92130D470D.xpi, , [ed0546bb108a3204a83fc23a867d4fb1],
PUP.Optional.HohoSearch, C:\Windows\System32\Tasks\Arahick Controls, , [f4fe03fe8713bb7b3b128a7516eda759],
PUP.Optional.FastWeb, C:\Program Files (x86)\FastWeb\config_ns1.dat, , [6e842cd50298e94d802c37904eb4ed13],
PUP.Optional.HohoSearch, C:\Users\Matijas\AppData\Roaming\Profiles\st7njx15.default\searchplugins\98m5wb3j.xml, , [747e2ed3623893a34573891324e0f60a],
PUP.Optional.HohoSearch, C:\Users\Matijas\AppData\Roaming\Profiles\yzzfdyu4.default\searchplugins\98m5wb3j.xml, , [ee04cc351189c571c9efd2ca2dd73cc4],
(end)
here you go