| ![]() C:\Program Files(x86)\HomeTab\TBUpdater.dll Hallo zusammen ! Ich bin leider erst jetzt auf das Board hier gestoßen nachdem mir mein Computer langsam vorkam und ich schon einiges unternommen hatte. Unter den Programmen fiel mir ein Programm Sing Along auf. Daraufhin führte ich einen Scan mit adwcleaner durch und mit Malwarebytes danach.......lezteres fand dann 8 infizierte Dateiobjekte der Registrierung erst nachdem diese in Quarantäne waren tauchte oben genannte RunDLL -Meldung beim Neustart auf ......nach dem Bestätigen der Meldung ..... läuft alles scheinbar normal Wer kann helfen bitte ...... |
Hi,
__________________Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden ).
__________________ |
OTL Logfile:
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() C:\Program Files(x86)\HomeTab\TBUpdater.dll Verschieb OTL einfach auf den Desktop ![]() Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
und ein frisches OTL log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
ATTFilter # AdwCleaner v2.303 - Datei am 21/06/2013 um 15:51:40 erstellt # Aktualisiert am 08/06/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : Armin Winkler - ARMINWINKLER-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Armin Winkler\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gefunden : C:\Users\Armin Winkler\AppData\LocalLow\SimplyTech ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16611 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v21.0 (de) Datei : C:\Users\Armin Winkler\AppData\Roaming\Mozilla\Firefox\Profiles\3eyhrmke.default\prefs.js [OK] Die Datei ist sauber. Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\q3u0jch7.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [29107 octets] - [19/06/2013 18:39:46] AdwCleaner[R2].txt - [29168 octets] - [19/06/2013 18:40:15] AdwCleaner[R3].txt - [1268 octets] - [19/06/2013 21:07:21] AdwCleaner[R4].txt - [1127 octets] - [21/06/2013 15:51:40] AdwCleaner[S1].txt - [29403 octets] - [19/06/2013 18:40:43] AdwCleaner[S2].txt - [1330 octets] - [19/06/2013 21:07:58] ########## EOF - C:\AdwCleaner[R4].txt - [1308 octets] ########## Code:
ATTFilter # AdwCleaner v2.303 - Datei am 21/06/2013 um 15:52:17 erstellt # Aktualisiert am 08/06/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : Armin Winkler - ARMINWINKLER-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Armin Winkler\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Users\Armin Winkler\AppData\LocalLow\SimplyTech ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16611 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v21.0 (de) Datei : C:\Users\Armin Winkler\AppData\Roaming\Mozilla\Firefox\Profiles\3eyhrmke.default\prefs.js [OK] Die Datei ist sauber. Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\q3u0jch7.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [29107 octets] - [19/06/2013 18:39:46] AdwCleaner[R2].txt - [29168 octets] - [19/06/2013 18:40:15] AdwCleaner[R3].txt - [1268 octets] - [19/06/2013 21:07:21] AdwCleaner[R4].txt - [1377 octets] - [21/06/2013 15:51:40] AdwCleaner[S1].txt - [29403 octets] - [19/06/2013 18:40:43] AdwCleaner[S2].txt - [1330 octets] - [19/06/2013 21:07:58] AdwCleaner[S3].txt - [1310 octets] - [21/06/2013 15:52:17] ########## EOF - C:\AdwCleaner[S3].txt - [1370 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Professional x64 Ran by Armin Winkler on 21.06.2013 at 16:01:02,82 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5019CE81-A7E1-48FF-B149-91480AA9A388} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{5019CE81-A7E1-48FF-B149-91480AA9A388} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Armin Winkler\appdata\locallow\simplytech" Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{00BBE50B-FAC8-4949-8045-2F9E80B3D9B2} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{0422CF15-23A3-468C-A393-DD7256485F99} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{0D907C02-B80E-4B65-B558-1F8093D0BFA4} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{103F231C-7249-4A8D-BD9B-21F349E8B083} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{1050E93B-94D1-4B4E-9CEC-678388562642} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{183BBE6A-F8C1-4114-AE74-15E4BDFB3D07} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{19A41ED9-E77E-4E8A-8C9B-030F5250EB0C} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{235B12C9-DEB8-4D70-A51B-42D2ED336A7A} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{247DC548-35FD-471C-9092-C1CBF062F9A3} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{253D2809-62BF-4115-8788-E94EB34CCB3C} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{2598D128-0566-499A-A834-F2E8DF8B38DB} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{2D53B6B0-73EA-4737-97E6-CCECB9CF7395} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{357FEE61-EBAE-49B5-A0E4-96421F11E04A} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{3B269463-EA02-4DF8-8C48-C9542BE41F98} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{46610575-5BAD-4897-9641-9167797DCFA7} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{4D4EC701-D165-41D8-83DD-45C3FB2997F7} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{4ED04526-0D46-4F72-B2B8-FE1D8C1F3585} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{50ED2EF1-0D3D-4663-AF7C-58CB6F3311D0} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{5694B8B3-ECC2-497F-A0F2-794A35437681} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{5C7EA98D-8E2C-4454-A07B-D51144618743} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{6194E6CA-F7F8-46EF-AF63-DDA00AA9E629} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{67BC6E87-1B58-41A8-B318-A7F9B5E24DC9} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{7A0A0118-FFF8-4D4B-8627-540C196B2CFD} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{7D9228A7-2440-4E17-AD56-0BC30B9956DD} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{8C32EFA2-1D8F-4B3D-934D-60A9E30816E4} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{A2E813AD-304E-4AD7-AE9B-06E44044446F} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{C11D2DAE-7EFE-47C1-A0A7-886972E3C16C} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{C47B2914-8234-4DDF-966E-81093318AEFB} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{C5059F61-9B4D-406A-8E57-5AA1DF9A9DE0} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{C8C72DED-A61D-4462-8FF5-D490193F5054} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{CC10578B-2C12-455A-A21C-D629223D1181} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{D8F93DDA-5741-40A9-84C8-86D93F074F5F} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{DD290E86-B4DF-495C-B279-A693E47C7886} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{DE223ACC-32A8-4825-8AE2-9042D5B14AED} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{EBB6347E-B520-4D05-BF72-9BF6810C348C} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{FECB2EDF-94D5-4731-A2C3-BA5B0719A52B} Successfully deleted: [Empty Folder] C:\Users\Armin Winkler\appdata\local\{FF46BF7A-BC69-42AA-A44B-CADA3F1C02F8} ~~~ FireFox Successfully deleted the following from C:\Users\Armin Winkler\AppData\Roaming\mozilla\firefox\profiles\3eyhrmke.default\prefs.js user_pref("iminent.webbooster.scripts.minibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar"); user_pref("iminent.webbooster.scripts.minibar.Services.BHPCode", "01"); user_pref("iminent.webbooster.scripts.minibar.Services.DefaultEvent", "000"); user_pref("iminent.webbooster.scripts.minibar.Services.DefaultWebSite", "000"); user_pref("iminent.webbooster.scripts.minibar.Services.IminentClientCode", "11"); user_pref("iminent.webbooster.scripts.minibar.Services.SmartFavCode", "02"); user_pref("iminent.webbooster.scripts.minibar.ShowThankyouPixel", "0"); user_pref("iminent.webbooster.scripts.minibar.displayFavLinks", "1"); user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent102", "1370701953204"); user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent140", "1370695505498"); user_pref("iminent.webbooster.scripts.sslminibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar"); user_pref("iminent.webbooster.scripts.sslminibar.Services.BHPCode", "01"); user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultEvent", "000"); user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultWebSite", "000"); user_pref("iminent.webbooster.scripts.sslminibar.Services.IminentClientCode", "11"); user_pref("iminent.webbooster.scripts.sslminibar.Services.SmartFavCode", "02"); user_pref("iminent.webbooster.scripts.sslminibar.ShowThankyouPixel", "0"); user_pref("iminent.webbooster.scripts.sslminibar.displayFavLinks", "1"); user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent102", "1370896603034"); user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent109", "1371581881137"); user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent111", "1371581881142"); user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent112", "1371588541407"); user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent122", "1371581881148"); Emptied folder: C:\Users\Armin Winkler\AppData\Roaming\mozilla\firefox\profiles\3eyhrmke.default\minidumps [38 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.06.2013 at 16:06:22,83 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 16:15 on 21/06/2013 by Armin Winkler Administrator - Elevation successful ========== filefind ========== Searching for "*Browser Updater*" C:\Windows\System32\Tasks\Browser Updater\Browser Updater --a---- 4054 bytes [21:01 06/06/2013] [21:01 06/06/2013] 0900A8491C88A4C78EEEBA61DD9D39CC Searching for " " No files found. -= EOF =- Code:
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() C:\Program Files(x86)\HomeTab\TBUpdater.dll Ich wette um nen Kasten Bier nach dem nächsten Neustart ist sie weg ![]() Fixen mit OTL
ATTFilter :files C:\Windows\System32\Tasks\Browser Updater
__________________ --> C:\Program Files(x86)\HomeTab\TBUpdater.dll |
| ![]() C:\Program Files(x86)\HomeTab\TBUpdater.dllCode:
ATTFilter ========== FILES ========== File\Folder C:\Windows\System32\Tasks\Browser Updater not found. OTL by OldTimer - Version log created on 06222013_003118 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() C:\Program Files(x86)\HomeTab\TBUpdater.dll Warum hat OTL da immer nen Bug? navigiere in Windows Explorer zu dem Ordner C:\Windows\System32\Tasks\Browser Updater und lösche ihn. reboote, Meldung müsste dann weg sein.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
