![]() |
|
Log-Analyse und Auswertung: SpywarebefallWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #11 |
![]() ![]() | ![]() SpywarebefallCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 08-12-2013 03 Ran by Riehmer at 2013-12-09 14:30:24 Run:1 Running from C:\Users\Riehmer\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start FF Extension: No Name - C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} FF Extension: No Name - C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} FF Extension: No Name - C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} FF Extension: No Name - C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209} S3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [167264 2011-11-10] () C:\Program Files\AVG\AVG10\Toolbar Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1415058074-704485446-1059558982-1000\Software\AVG Secure Search" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56D5B21A-BA79-4CEC-86C4-C89A044E38EB}" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9E5E0B8B-C666-4A3C-81C5-50E5C0C39856}" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE428D7A-801B-4ED8-A2E6-0479FC06944C}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63EDCDD3-8AFC-4358-A90F-F7FB8F5C64FF}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD5843ED-13C4-4EFF-ACE9-56CEE22BC087}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Search.BrowserWndAPI" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Search.PugiObj" /f Reg: reg delete "HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar" /f Reg: reg delete "HKEY_USERS\.DEFAULT\Software\AVG Secure Search" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Classes\Applications\DriverCure.exe" /f Reg: reg delete "HKEY_USERS\.DEFAULT\Software\ParetoLogic" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1415058074-704485446-1059558982-1000\Software\Complitly" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk" /f end ***************** C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Moved successfully. C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} => Moved successfully. C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} => Moved successfully. C:\Users\Riehmer\AppData\Roaming\Mozilla\Firefox\Profiles\a3m6s5vt.default\Extensions\{af6ac4f2-9825-4fb6-a600-92bc5361f209} => Moved successfully. AVG Security Toolbar Service => Service deleted successfully. C:\Program Files\AVG\AVG10\Toolbar => Moved successfully. ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1415058074-704485446-1059558982-1000\Software\AVG Secure Search" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56D5B21A-BA79-4CEC-86C4-C89A044E38EB}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9E5E0B8B-C666-4A3C-81C5-50E5C0C39856}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE428D7A-801B-4ED8-A2E6-0479FC06944C}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63EDCDD3-8AFC-4358-A90F-F7FB8F5C64FF}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD5843ED-13C4-4EFF-ACE9-56CEE22BC087}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Search.BrowserWndAPI" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Search.PugiObj" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_USERS\.DEFAULT\Software\AVG Secure Search" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Classes\Applications\DriverCure.exe" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_USERS\.DEFAULT\Software\ParetoLogic" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1415058074-704485446-1059558982-1000\Software\Complitly" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ==== End of Fixlog ==== Code:
ATTFilter
Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0e4f19c248e5ef47b55daaf084e8ea30 # engine=16196 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-12-09 03:52:53 # local_time=2013-12-09 04:52:53 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=5892 16776574 100 100 3792316 224137101 0 0 # scanned=169929 # found=0 # cleaned=0 # scan_time=7539 Code:
ATTFilter Results of screen317's Security Check version 0.99.76 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` AVG AntiVirus Free Edition 2014 Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2009 Adobe Flash Player 11.9.900.117 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (3.6.28) Firefox out of Date! Google Chrome 30.0.1599.101 Google Chrome 31.0.1650.57 ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe AVG avgrsx.exe AVG avgnsx.exe AVG avgemc.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
Themen zu Spywarebefall |
32 bit, adblock, adobe, adobe flash player, autorun, avg, avg security toolbar, browser, converter, defender, explorer, festplatte, festplatte voll, firefox, flash player, format, home, install.exe, logfile, malwarebytes, microsoft, packard bell, photoshop, plug-in, realtek, registry, scan, secure, secure search, security, seiten, software, vista, vtoolbarupdater |