![]() |
|
Plagegeister aller Art und deren Bekämpfung: ALLES voller Werbung (und wer weiß was sonst noch)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() ALLES voller Werbung (und wer weiß was sonst noch) Hallo liebe Trojaner-Helden, seid ein paar Tagen ist in sämtlichen Browsern (Internet Explorern sowie Chrome) alles voller Werbung. Pop-Ups, unterstrichene Wörter mit Pseudo-Links, und Werbe-Einblendungen. Ich habe schon alles versucht: Kapersky Rettung, Anitbytes Malware mehrfach drüber laufen lassen. Nichts scheint zu helfen. Nun habe ich auch die hier im Forum beschriebene Anleitung befolgt (dds und adwcleaner) und die unten geposteten Logs erhalten - könnt ihr mich retten? Ich wäre Euch unendlich dankbar, Vielen Dank und viele Grüße Heiner Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 05/01/2014 um 01:31:43 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : dsh - DSH-PC # Gestartet von : C:\Users\dsh\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** [!] Ordner Gelöscht : C:\ProgramData\boost_interprocess [!] Ordner Gelöscht : C:\ProgramData\Computer Updater [!] Ordner Gelöscht : C:\ProgramData\Tarma Installer [!] Ordner Gelöscht : C:\ProgramData\w3i [!] Ordner Gelöscht : C:\Program Files\Ask.com [!] Ordner Gelöscht : C:\Program Files\Freeze.com [!] Ordner Gelöscht : C:\Program Files\GamesBar [!] Ordner Gelöscht : C:\Program Files\Mobogenie [!] Ordner Gelöscht : C:\Program Files\Show-Password [!] Ordner Gelöscht : C:\Program Files\w3i [!] Ordner Gelöscht : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe} Ordner Gelöscht : C:\Users\dsh\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\dsh\AppData\Local\filetypeassistant Ordner Gelöscht : C:\Users\dsh\AppData\Local\iLivid Ordner Gelöscht : C:\Users\dsh\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\dsh\AppData\Local\Wajam Ordner Gelöscht : C:\Users\dsh\AppData\Local\Temp\AskSearch Ordner Gelöscht : C:\Users\dsh\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\dsh\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\dsh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl Datei Gelöscht : C:\END Datei Gelöscht : C:\Users\dsh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk Datei Gelöscht : C:\Users\dsh\Desktop\iLivid.lnk Datei Gelöscht : C:\Users\dsh\Desktop\Play Free Games.lnk Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829}] Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [happylyrics@hpyproductions.net] Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\wajam.com Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchEngineProtection] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasmancs Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\ilivid Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\HappyLyrics Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\NetAssistant 3.8.3 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\dsh\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R].txt - [16523 octets] - [05/01/2014 01:29:45] AdwCleaner[S].txt - [5892 octets] - [05/01/2014 01:31:43] ########## EOF - C:\AdwCleaner\AdwCleaner[S].txt - [5951 octets] ########## Code:
ATTFilter . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 28.12.2009 16:20:55 System Uptime: 05.01.2014 01:34:19 (0 hours ago) . Motherboard: ASUSTeK Computer INC. | | M4A785TD-V EVO Processor: AMD Phenom(tm) II X4 925 Processor | AM3 | 2800/200mhz . ==== Disk Partitions ========================= . A: is FIXED (NTFS) - 466 GiB total, 398,997 GiB free. C: is FIXED (NTFS) - 144 GiB total, 61,374 GiB free. D: is FIXED (NTFS) - 5 GiB total, 5,351 GiB free. E: is CDROM () K: is Removable M: is FIXED (FAT32) - 466 GiB total, 50,515 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP720: 29.12.2013 08:48:51 - Installed SpyHunter RP721: 29.12.2013 10:17:37 - Removed SpyHunter RP722: 30.12.2013 13:23:49 - Herrnhuter Losungen wird installiert RP724: 04.01.2014 17:04:33 - Configured Microsoft Office Home and Student 2007 . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Adobe AIR Adobe Download Assistant Adobe Flash Player 10 Plugin Adobe Flash Player 11 ActiveX Adobe Reader X (10.1.8) - Deutsch Apple Application Support Apple Mobile Device Support Apple Software Update Architektur Designer 2010 1.1.0.5 Ask Toolbar ATI AVIVO Codecs Avira Free Antivirus Avira SearchFree Toolbar plus Web Protection Updater Bing Bar BMW M3 Challenge Bonjour CameraHelperMsi Canon Easy-PhotoPrint EX Canon Easy-WebPrint EX Canon MG5200 series Benutzerregistrierung Canon MG5200 series MP Drivers Canon MP Navigator EX 4.0 Canon My Printer Canon Solution Menu EX Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center HydraVision Full Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CD-LabelPrint CDBurnerXP CHIPDRIVE MyKey Creatix V.9X DSP Data Fax Modem CrystalDiskInfo 5.4.2 D3DX10 DirectX for Managed Code Update (Summer 2004) entrusted Toolbar EPU-4 Engine erLT File Type Assistant Final Media Player 2012 FTDI USB Serial Converter Drivers GamesBar (W) Google Chrome Google Earth Google Talk (remove only) Google Toolbar for Internet Explorer Google Update Helper Google+ Auto Backup Herrnhuter Losungen HydraVision iCloud InstallIQ Updater iTunes Junk Mail filter update Logitech Webcam-Software Logitech Webcam Software-Treiberpaket LWS Facebook LWS Gallery LWS Help_main LWS Launcher LWS Motion Detection LWS Pictures And Video LWS Twitter LWS Video Mask Maker LWS VideoEffects LWS Webcam Software LWS WLM Plugin LWS YouTube Plugin Mesh Runtime Messenger Companion Micrografx Designer 9.0 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (German) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (German) 2007 Microsoft Office Outlook 2007 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (German) 2007 Microsoft Office PowerPoint MUI (German) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proof (Italian) 2007 Microsoft Office Proofing (German) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (German) 2007 Microsoft Office Word MUI (German) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Works 4 Converter MiniTool Partition Wizard Home Edition 8.1.1 MobileMe Control Panel MSVC80_x86_v2 MSVC90_x86 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NAVIGON Fresh 3.4.1 NetAssistant Nokia Connectivity Cable Driver Nokia Ovi Suite Nokia Ovi Suite Software Updater Nokia Software Updater NVIDIA 3D Vision Treiber 311.06 NVIDIA Display Control Panel NVIDIA Grafiktreiber 311.06 NVIDIA Install Application NVIDIA Stereoscopic 3D Driver NVIDIA Systemsteuerung 311.06 NVIDIA Update 1.11.3 NVIDIA Update Components Ovi Desktop Sync Engine OviMPlatform PC Connectivity Solution Picasa 3 PL-2303 Vista Driver Installer Platform PrintKey2000 PVSonyDll QuickTime Realtek 8136 8168 8169 Ethernet Driver Realtek AC'97 Audio RegistryReviver Safari SCR3xxx Smart Card Reader Search Protect by conduit Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2817641) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office Outlook 2007 (KB2825644) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition Show-Password Skype™ 6.11 Spelling Dictionaries Support For Adobe Reader 9 StarMoney StarMoney Business 4.0 StarMoney Business 5.0 StarMoney Business 6.0 Surf & E-Mail-Stick System 3060 System Requirements Lab t@x 2011 t@x 2013 TeamViewer 8 UltraISO Premium V9.6 Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition VIA Plattform-Geräte-Manager WD Drive Manager (x86) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Fotogalerie Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX control for remote connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Yahoo Community Smartbar Yahoo Community Smartbar Engine Yahoo! Software Update Yahoo! Toolbar . ==== End Of File =========================== Code:
ATTFilter DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 11.0.9600.16428 Run by admin at 1:43:07 on 2014-01-05 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3327.1979 [GMT 1:00] . AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\atiesrxx.exe C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe C:\Windows\system32\AUDIODG.EXE C:\Windows\System32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Microsoft\BingBar\7.3.124.0\BBSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\StarMoney Business 4.0\ouservice\StarMoneyOnlineUpdate.exe C:\Program Files\StarMoney Business 5.0\ouservice\StarMoneyOnlineUpdate.exe C:\Program Files\StarMoney Business 6.0\ouservice\StarMoneyOnlineUpdate.exe C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\sppsvc.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\atieclxx.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe C:\Windows\SOUNDMAN.EXE C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE C:\Program Files\CHIPDRIVE\CHIPDRIVE MyKey\MyKey\MyKey.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\StarMoney Business 6.0\offlagent7\offlagent.exe C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Buhl finance\tax Steuersoftware 2013\taxaktuell.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\CHIPDRIVE\CHIPDRIVE MyKey\MyKey\scmsok.exe C:\Windows\system32\PrintIsolationHost.exe C:\Program Files\Skype\Updater\Updater.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\svchost.exe -k SDRSVC . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Bar = hxxp://www.google.com/ie uSearch Page = hxxp://www.google.com uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mURLSearchHooks: {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - <orphaned> BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: GamesBar (W): {2e94b700-eafb-4c9e-a696-77200aa3f89b} - c:\program files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Show-Password: {96304e6d-bcec-4bca-b49b-ae3b4d54afec} - c:\program files\show-password\150.dll BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\microsoft\bingbar\7.3.124.0\BingExt.dll BHO: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: NetAssistant: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - c:\program files\freeze.com\netassistant\NetAssistant.dll BHO: {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - <orphaned> BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: GamesBar (W): {2e94b700-eafb-4c9e-a696-77200aa3f89b} - c:\program files\gamesagogo_w3i\encyclopediabritannicagamesbarX.dll TB: Yahoo Community Smartbar (by Linkury): {ae07101b-46d4-4a98-af68-0333ea26e113} - TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\microsoft\bingbar\7.3.124.0\BingExt.dll EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun mRun: [SoundMan] SOUNDMAN.EXE mRun: [WD Drive Manager] c:\program files\western digital\wd drive manager\WDBtnMgrUI.exe mRun: [StarMoneyRunEntry] "c:\program files\starmoney business 4.0\app\oflagent.exe" mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup mRun: [HDAudDeck] c:\program files\via\viaudioi\vdeck\VDeck.exe -r mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [CanonSolutionMenuEx] c:\program files\canon\solution menu ex\CNSEMAIN.EXE /logon mRun: [SMB50StarMoneyRunEntry] "c:\program files\starmoney business 5.0\app\oflagent.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MyKey] c:\program files\chipdrive\chipdrive mykey\mykey\MyKey.exe mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SMB60StarMoneyRunEntry] "c:\program files\starmoney business 6.0\app\oflagent.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [mobilegeni daemon] c:\program files\mobogenie\DaemonProcess.exe StartupFolder: c:\users\admin\appdata\roaming\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\ereg\eReg.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\t@xakt~1.lnk - c:\program files\buhl finance\tax steuersoftware 2013\taxaktuell.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Nach Microsoft E&xel exportieren - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} LSP: c:\program files\avira\antivir desktop\avsda.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.2.1 TCP: Interfaces\{B1DCD31E-3CA5-4FA2-978A-246B644ABACB} : DHCPNameServer = 192.168.2.1 TCP: Interfaces\{FC5E29D2-DD0C-4359-A9C5-22FB4F661872} : DHCPNameServer = 192.168.2.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - <orphaned> mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.63\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome . ============= SERVICES / DRIVERS =============== . R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-10-29 37352] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-5-5 172032] R2 AntiVirSchedulerService;Avira Planer;c:\program files\avira\antivir desktop\sched.exe [2012-10-29 440376] R2 AntiVirService;Avira Echtzeit-Scanner;c:\program files\avira\antivir desktop\avguard.exe [2012-10-29 440376] R2 AntiVirWebService;Avira Browser-Schutz;c:\program files\avira\antivir desktop\avwebgrd.exe [2012-10-29 1011768] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-10-29 90400] R2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.3.124.0\BBSvc.EXE [2013-12-16 193696] R2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-9-5 171680] R2 StarMoney Business 4.0 OnlineUpdate;StarMoney Business 4.0 OnlineUpdate;c:\program files\starmoney business 4.0\ouservice\StarMoneyOnlineUpdate.exe [2011-11-10 554160] R2 StarMoney Business 5.0 OnlineUpdate;StarMoney Business 5.0 OnlineUpdate;c:\program files\starmoney business 5.0\ouservice\StarMoneyOnlineUpdate.exe [2013-2-13 699680] R2 StarMoney Business 6.0 OnlineUpdate;StarMoney Business 6.0 OnlineUpdate;c:\program files\starmoney business 6.0\ouservice\StarMoneyOnlineUpdate.exe [2013-10-30 663184] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-1-18 383264] R2 TeamViewer8;TeamViewer 8;c:\program files\teamviewer\version8\TeamViewer_Service.exe [2012-12-15 5087584] R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848] R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-5-16 102400] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-5-26 167936] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-5-26 1077760] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-16 11520] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.3.124.0\SeaPort.EXE [2013-12-16 247968] S3 ctxS51;Creatix V.9X DSP Data Fax Modem;c:\windows\system32\drivers\ctxS51.sys [2006-5-1 1903646] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-6-4 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840] S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2013-12-11 108032] S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\system32\drivers\Ph3xIB32.sys [2009-6-10 1311232] S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2013-12-28 15688] S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2013-12-28 10320] S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [2011-6-16 59520] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-26 52224] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] . =============== Created Last 30 ================ . 2014-01-05 00:29:39 -------- d-----w- C:\AdwCleaner 2014-01-05 00:16:07 -------- d-----w- c:\program files\UltraISO 2014-01-05 00:16:07 -------- d-----w- c:\program files\common files\EZB Systems 2013-12-29 07:49:36 -------- d-----w- c:\program files\Enigma Software Group 2013-12-29 07:48:39 -------- d-----w- c:\windows\220FB0354744483A9A0B41DF77061583.TMP 2013-12-29 07:48:38 -------- d-----w- c:\program files\common files\Wise Installation Wizard 2013-12-28 16:22:16 2881848 ----a-w- c:\windows\system32\pwNative.exe 2013-12-28 16:22:16 15688 ------w- c:\windows\system32\pwdrvio.sys 2013-12-28 16:22:15 10320 ------w- c:\windows\system32\pwdspio.sys 2013-12-28 16:22:00 -------- d-----w- c:\program files\MiniTool Partition Wizard Home Edition 8.1.1 2013-12-28 16:16:15 -------- d-----w- c:\users\admin\appdata\roaming\Malwarebytes 2013-12-28 16:16:03 -------- d-----w- c:\programdata\Malwarebytes 2013-12-28 16:14:52 743248 ----a-w- c:\windows\system32\msvcp100d.dll 2013-12-28 16:14:52 1498960 ----a-w- c:\windows\system32\msvcr100d.dll 2013-12-28 16:14:52 -------- d-----w- c:\program files\Malwarebytes Anti-Exploit 2013-12-26 11:59:46 -------- d-----w- c:\program files\Show-Password 2013-12-26 11:59:45 -------- d-----w- c:\users\admin\appdata\local\cache 2013-12-26 11:59:44 -------- d-----w- c:\users\admin\appdata\local\Mobogenie 2013-12-26 11:59:08 -------- d-----w- c:\program files\Mobogenie 2013-12-26 11:58:42 -------- d-----w- c:\program files\Free M4a to MP3 Converter 2013-12-26 11:58:27 -------- d-----w- c:\users\admin\appdata\local\Programs 2013-12-23 19:32:50 4558848 ----a-w- c:\windows\system32\GPhotos.scr 2013-12-23 16:41:50 822272 ----a-w- c:\windows\system32\LUCA.DLL 2013-12-23 16:41:48 -------- d-----w- c:\program files\Simons & Voss 2013-12-23 16:41:21 304128 ----a-w- c:\windows\unin0407.exe 2013-12-23 16:36:58 51821 ----a-w- c:\windows\system32\ftserui2.dll 2013-12-23 16:36:58 36864 ----a-w- c:\windows\system32\FTLang.dll 2013-12-23 16:36:57 57404 ----a-w- c:\windows\system32\drivers\ftser2k.sys 2013-12-23 16:35:12 414208 ----a-w- c:\windows\system32\ftdiunin.exe 2013-12-23 16:35:12 24209 ----a-w- c:\windows\system32\drivers\ftdibus.sys 2013-12-11 17:26:45 12625408 ----a-w- c:\windows\system32\wmploc.DLL 2013-12-11 17:26:44 164864 ----a-w- c:\program files\windows media player\wmplayer.exe 2013-12-11 08:29:36 301568 ----a-w- c:\windows\system32\msieftp.dll 2013-12-11 08:29:34 159232 ----a-w- c:\windows\system32\imagehlp.dll 2013-12-11 08:29:33 417792 ----a-w- c:\windows\system32\WMPhoto.dll 2013-12-11 08:29:33 163840 ----a-w- c:\windows\system32\scrrun.dll 2013-12-11 08:29:33 141824 ----a-w- c:\windows\system32\wscript.exe 2013-12-11 08:29:33 126976 ----a-w- c:\windows\system32\cscript.exe 2013-12-11 08:29:33 121856 ----a-w- c:\windows\system32\wshom.ocx 2013-12-11 08:29:31 2048 ----a-w- c:\windows\system32\tzres.dll 2013-12-11 08:29:28 81408 ----a-w- c:\windows\system32\drivers\drmk.sys 2013-12-11 08:29:28 2349056 ----a-w- c:\windows\system32\win32k.sys 2013-12-11 08:29:28 177152 ----a-w- c:\windows\system32\drivers\portcls.sys . ==================== Find3M ==================== . 2013-12-17 14:30:23 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-12-17 14:30:23 69240 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-12-10 18:23:44 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-12-10 18:23:44 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-11-26 09:23:02 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 09:22:11 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 08:53:56 61952 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 08:52:26 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 08:29:55 112128 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 08:29:52 108032 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 08:28:16 553472 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:16:12 4243968 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 07:32:06 1928192 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 06:33:33 1820160 ----a-w- c:\windows\system32\wininet.dll 2013-10-12 02:03:08 656896 ----a-w- c:\windows\system32\nshwfp.dll 2013-10-12 02:01:41 679424 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-10-12 02:01:25 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2013-10-07 13:15:43 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys . ============= FINISH: 1:44:42,61 =============== |
Themen zu ALLES voller Werbung (und wer weiß was sonst noch) |
appdatalow, bingbar, browser, computer, converter, defender, desktop, email, error, excel, firefox, flash player, google, home, installation, internet, internet explorer, linkury, malware, mozilla, mp3, pop-ups, preferences, registrierungsdatenbank, server, smartbar, software, svchost.exe, tarma, temp, usb, werbung, windows |