![]() |
|
Plagegeister aller Art und deren Bekämpfung: Internetbrowser (Keine Rückmeldung)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Internetbrowser (Keine Rückmeldung) Hallo, Ich habe seit einiger Zeit ein Problem mit meinem Internetbrowser. Nach kurzer Zeit friert das Fenster ein und in der Fensterleiste erscheint (Keine Rückmeldung). Das Problem wurde mit der Zeit immer schlimmer,es tritt immer häufiger hintereinander auf. Manchmal frieren dann auch andere Programme ein, z.B. Windows Mediaplayer oder Dateiordner. Der Windows Task-Manager lässt sich dann auch nicht öffnen. Die Festplatte wurde fragmentiert und das Betriebssystem neu installiert, ohne Erfolg. Ich verwende Windows 7 64Bit. dds.txt: [CODE].DDS Logfile: Code:
ATTFilter DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 Run by Janine at 12:05:50 on 2012-04-15 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3957.2121 [GMT 2:00] . AV: Kaspersky Internet Security *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Internet Security *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security *Enabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe C:\Windows\system32\LogonUI.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\taskmgr.exe C:\Users\Janine\AppData\Local\Temp\Temp1_ComputerRepairFree.zip\ComputerRepairFree.exe C:\Users\Janine\AppData\Local\Temp\Temp1_ComputerRepairFree.zip\ComputerRepairFree.exe C:\Users\Janine\AppData\Local\Temp\Temp2_ComputerRepairFree.zip\ComputerRepairFree.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtblfs.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . mWinlogon: Userinit=userinit.exe BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{39B8109D-6A06-4B44-92F6-BD79D24A902F} : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{878C1AE1-BBBC-4A84-B486-EFC9161D9904} : DhcpNameServer = 192.168.1.1 {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} {E33CF602-D945-461A-83F0-819F76A199F8} mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" . ============= SERVICES / DRIVERS =============== . R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?] R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 202296] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?] R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?] R3 RTL8167;Realtek 8167 NT-Treiber;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-1 253088] S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?] S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?] . =============== Created Last 30 ================ . 2012-04-15 09:48:31 8766112 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2012-04-13 17:11:51 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe 2012-04-13 17:11:51 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-04-13 17:11:51 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-04-13 17:10:03 81408 ----a-w- C:\Windows\System32\imagehlp.dll 2012-04-13 17:10:03 5120 ----a-w- C:\Windows\SysWow64\wmi.dll 2012-04-13 17:10:03 5120 ----a-w- C:\Windows\System32\wmi.dll 2012-04-13 17:10:03 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys 2012-04-13 17:10:03 220672 ----a-w- C:\Windows\System32\wintrust.dll 2012-04-13 17:10:03 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll 2012-04-13 17:10:03 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll 2012-04-13 13:12:01 -------- d-----w- C:\Users\Janine\AppData\Roaming\Malwarebytes 2012-04-13 13:11:52 -------- d-----w- C:\ProgramData\Malwarebytes 2012-04-13 12:37:20 -------- d-----w- C:\ProgramData\Kaspersky Lab 2012-04-13 12:37:20 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab 2012-04-13 12:11:56 64512 ----a-w- C:\Windows\SysWow64\devobj.dll 2012-04-13 12:10:51 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2012-04-13 12:10:43 8669240 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3E860304-1FDD-4300-A7DD-840AEBCB9DC6}\mpengine.dll 2012-04-13 12:10:23 77312 ----a-w- C:\Windows\System32\packager.dll 2012-04-13 12:10:23 67072 ----a-w- C:\Windows\SysWow64\packager.dll 2012-04-13 12:01:31 -------- d-----w- C:\Users\Janine\AppData\Local\Mozilla 2012-04-11 10:31:12 224768 ----a-w- C:\Windows\System32\drivers\CtAudDrv.sys 2012-04-11 10:31:12 172704 ----a-w- C:\Windows\System32\drivers\CtClsFlt.sys 2012-04-11 10:31:08 -------- d-----w- C:\Program Files (x86)\Creative Live! Cam 2012-04-11 10:17:56 74 --sh--r- C:\Windows\CT4CET.bin 2012-04-11 10:17:40 -------- d-----w- C:\Program Files (x86)\Common Files\Reallusion 2012-04-11 10:17:11 -------- d-----w- C:\Program Files (x86)\Creative 2012-04-11 10:16:40 -------- d-----w- C:\Program Files (x86)\Dell Webcam 2012-04-11 10:16:14 729088 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll 2012-04-11 10:16:14 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll 2012-04-11 10:16:14 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe 2012-04-11 10:16:14 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll 2012-04-11 10:16:14 266240 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll 2012-04-11 10:16:14 192512 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll 2012-04-11 10:16:14 188548 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll 2012-04-11 10:16:13 311428 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll 2012-04-01 17:44:51 -------- d-----w- C:\Program Files (x86)\Cisco 2012-04-01 17:38:57 -------- d-----w- C:\Windows\Panther 2012-04-01 17:32:07 -------- d-----w- C:\Windows\System32\appmgmt 2012-04-01 17:08:07 1114624 ----a-w- C:\Windows\System32\BCMLogon.dll 2012-04-01 17:08:00 6656 ----a-w- C:\Windows\System32\bcmwlrc.dll 2012-04-01 17:04:39 7347200 ----a-w- C:\Windows\System32\RTSUSTORicon.dll 2012-04-01 17:04:39 351744 ----a-w- C:\Windows\System32\RtsUStor.dll 2012-04-01 17:04:39 220672 ----a-w- C:\Windows\System32\drivers\RtsUStor.sys 2012-04-01 17:04:39 -------- d-----w- C:\Program Files (x86)\Realtek 2012-04-01 17:04:35 -------- d-----w- C:\dell 2012-04-01 17:03:02 45056 ----a-r- C:\Users\Janine\AppData\Roaming\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe 2012-04-01 17:03:01 -------- d-----w- C:\Windows\SysWow64\vmm32 2012-04-01 17:02:43 -------- d-sh--w- C:\Windows\Installer 2012-04-01 17:01:37 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-04-01 17:01:37 418464 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-04-01 16:57:11 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe 2012-04-01 16:57:11 77312 ----a-w- C:\Windows\System32\rdpwsx.dll 2012-04-01 16:57:11 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll 2012-04-01 16:57:06 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll 2012-04-01 16:57:06 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-04-01 16:57:06 1031680 ----a-w- C:\Windows\System32\rdpcore.dll 2012-04-01 16:57:05 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys 2012-04-01 16:50:03 -------- d-----w- C:\Users\Janine\AppData\Local\Diagnostics 2012-04-01 16:42:20 0 ----a-w- C:\Windows\ativpsrm.bin . ==================== Find3M ==================== . 2012-02-28 06:39:37 1188864 ----a-w- C:\Windows\System32\wininet.dll 2012-02-28 05:38:52 981504 ----a-w- C:\Windows\SysWow64\wininet.dll 2012-02-28 04:31:38 1638912 ----a-w- C:\Windows\System32\mshtml.tlb 2012-02-28 03:52:27 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2012-02-23 08:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe 2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll 2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll 2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys . ============= FINISH: 12:08:01,10 =============== attach.txt: Code:
ATTFilter . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume2 Install Date: 01.04.2012 18:47:23 System Uptime: 15.04.2012 11:19:00 (1 hours ago) . Motherboard: Dell Inc. | | 0M9XW4 Processor: Intel(R) Core(TM) i3 CPU M 330 @ 2.13GHz | U2E1 | 2133/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 397 GiB total, 375,923 GiB free. D: is FIXED (NTFS) - 59 GiB total, 48,029 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP3: 01.04.2012 18:57:13 - Windows Update RP4: 01.04.2012 19:02:47 - Installed Dell Resource CD. RP5: 01.04.2012 19:04:40 - Installiert Realtek USB 2.0 Card Reader RP6: 01.04.2012 19:19:53 - Installed Bluetooth Software RP7: 01.04.2012 19:31:00 - Removed WIDCOMM Bluetooth Software RP8: 11.04.2012 12:16:21 - Installiert Integrated Webcam RP9: 11.04.2012 12:17:26 - Installiert Live! Cam Avatar Creator RP10: 11.04.2012 12:30:57 - Installiert Integrated Webcam RP11: 11.04.2012 12:32:04 - Installiert Live! Cam Avatar Creator RP12: 13.04.2012 14:10:25 - Windows Update RP13: 13.04.2012 19:08:29 - Windows Update . ==== Installed Programs ====================== . Advanced Audio FX Engine Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Dell Resource CD Dell Webcam Central Kaspersky Internet Security 2012 Live! Cam Avatar Creator Realtek USB 2.0 Card Reader . ==== End Of File =========================== Geändert von NiniQ (15.04.2012 um 13:17 Uhr) |
Themen zu Internetbrowser (Keine Rückmeldung) |
adobe flash player, browser, cdrom, cpu, defender, explorer, festplatte, flash player, generic, kaspersky, keine rückmeldung, neu, problem, programme, realtek, security, svchost.exe, task-manager, temp, usb 2.0, webcam, windows, windows media player, wireless, wmp |