|
Log-Analyse und Auswertung: Explorer springt ständig einfach so auf Startseite (Google)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.04.2014, 12:32 | #31 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Explorer springt ständig einfach so auf Startseite (Google) Unauffällig. Mach mal neue Kontrollscans mit MBAM und ESET bitte. MBAM neu installieren!! Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
13.04.2014, 22:24 | #32 |
| Explorer springt ständig einfach so auf Startseite (Google)Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 13.04.2014 Suchlauf-Zeit: 20:38:51 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.13.05 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 CPU: x64 Dateisystem: NTFS Benutzer: Schmidt Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 258356 Verstrichene Zeit: 17 Min, 59 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=29f091d43a40c9499bb352df7c5d00c8 # engine=17868 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-13 09:18:48 # local_time=2014-04-13 11:18:48 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=774 16777213 85 91 2009145 174133800 0 0 # compatibility_mode=5893 16776573 100 94 41283 149053778 0 0 # scanned=346877 # found=3 # cleaned=0 # scan_time=8724 sh=C4D1524A1FDE692A6B16CB10D2098BE41B4047EF ft=1 fh=51dfcfebcc7e2b28 vn="Win32/Hoax.ArchSMS.KC application" ac=I fn="C:\Daten30112012\2012-11-30_F\Irregular\00009287\~installer_adobe_flash_player_(firefox,_mozilla,_netscape_&_opera)_10_" sh=C4D1524A1FDE692A6B16CB10D2098BE41B4047EF ft=1 fh=51dfcfebcc7e2b28 vn="Win32/Hoax.ArchSMS.KC application" ac=I fn="C:\Daten30112012\2012-11-30_F\Irregular\00009288\~installer_adobe_flash_player_(firefox,_mozilla,_netscape_&_opera)_10_" sh=C4D1524A1FDE692A6B16CB10D2098BE41B4047EF ft=1 fh=51dfcfebcc7e2b28 vn="Win32/Hoax.ArchSMS.KC application" ac=I fn="C:\Daten30112012\2012-11-30_F\Irregular\00009289\~installer_adobe_flash_player_(firefox,_mozilla,_netscape_&_opera)_10_" |
13.04.2014, 23:26 | #33 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Explorer springt ständig einfach so auf Startseite (Google) Das hier schon probiert? => http://www.trojaner-board.de/126216-...tml#post946713
__________________
__________________ |
14.04.2014, 22:14 | #34 |
| Explorer springt ständig einfach so auf Startseite (Google)Code:
ATTFilter System Variables -------------------------------------------------------------------------------- OS: Windows 7 Home Premium OS Architecture: 64-bit OS Version: 6.1.7600 OS Service Pack: Computer Name: SCHMIDT-VAIO Windows Drive: C:\ Windows Path: C:\Windows Current Profile: C:\Users\Schmidt Current Profile SID: S-1-5-21-1372838556-1785058425-1914248320-1000 Current Profile Classes: S-1-5-21-1372838556-1785058425-1914248320-1000_Classes Profiles Location: C:\Users Profiles Location 2: C:\Windows\ServiceProfiles Local Settings AppData: C:\Users\Schmidt\AppData\Local -------------------------------------------------------------------------------- System Information -------------------------------------------------------------------------------- System Up Time: 0 Days 00:08:17 Process Count: 94 Commit Total: 2,19 GB Commit Limit: 7,71 GB Commit Peak: 2,29 GB Handle Count: 33544 Kernel Total: 332,25 MB Kernel Paged: 246,75 MB Kernel Non Paged: 85,50 MB System Cache: 1,72 GB Thread Count: 1144 -------------------------------------------------------------------------------- Memory Before Cleaning with CleanMem -------------------------------------------------------------------------------- Memory Total: 3,86 GB Memory Used: 1,72 GB(44,6906%) Memory Avail.: 2,13 GB -------------------------------------------------------------------------------- Cleaning Memory Before Starting Repairs... Memory After Cleaning with CleanMem -------------------------------------------------------------------------------- Memory Total: 3,86 GB Memory Used: 1,42 GB(36,7438%) Memory Avail.: 2,44 GB -------------------------------------------------------------------------------- Starting Repairs... Start (14.04.2014 22:04:52) Running Repair Under System Account 01 - Reset Registry Permissions 01/03 HKEY_CURRENT_USER & Sub Keys Start (14.04.2014 22:04:55) Running Repair Under Current User Account Done (14.04.2014 22:05:02) 01 - Reset Registry Permissions 02/03 HKEY_LOCAL_MACHINE & Sub Keys Start (14.04.2014 22:05:02) Running Repair Under System Account Done (14.04.2014 22:07:31) 01 - Reset Registry Permissions 03/03 HKEY_CLASSES_ROOT & Sub Keys Start (14.04.2014 22:07:31) Running Repair Under System Account Done (14.04.2014 22:08:46) 02 - Reset File Permissions: C: C: & Sub Folders Start (14.04.2014 22:08:46) Running Repair Under System Account Done (14.04.2014 22:22:07) 02 - Reset File Permissions: All Profiles C:\Users & Sub Folders Start (14.04.2014 22:22:07) Running Repair Under System Account Done (14.04.2014 22:22:26) 02 - Reset File Permissions: Current Profile C:\Users\Schmidt & Sub Folders Start (14.04.2014 22:22:26) Running Repair Under System Account Done (14.04.2014 22:22:35) 02 - Reset File Permissions: Cleanup Repairing Restricted Folders Permissions To Avoid Infinite Loops Start (14.04.2014 22:22:35) Running Repair Under System Account Processing ACL of: <\\?\C:\Documents and Settings> SetACL finished successfully. Processing ACL of: <\\?\C:\ProgramData\Application Data> SetACL finished successfully. Processing ACL of: <\\?\C:\ProgramData\Desktop> SetACL finished successfully. Processing ACL of: <\\?\C:\ProgramData\Documents> SetACL finished successfully. Processing ACL of: <\\?\C:\ProgramData\Favorites> SetACL finished successfully. Processing ACL of: <\\?\C:\ProgramData\Start Menu> SetACL finished successfully. Processing ACL of: <\\?\C:\ProgramData\Templates> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\All Users\Application Data> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\All Users\Desktop> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\All Users\Documents> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\All Users\Favorites> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\All Users\Start Menu> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\All Users\Templates> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default User> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Application Data> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Cookies> Reading the SD from <\\?\C:\Users\Default\Cookies> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Default\Local Settings> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\My Documents> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\NetHood> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\PrintHood> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Recent> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\SendTo> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Start Menu> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Templates> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\AppData\Local\Application Data> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\AppData\Local\History> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\AppData\Local\Temporary Internet Files> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Documents\My Music> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Documents\My Pictures> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Default\Documents\My Videos> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Public\Documents\My Music> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Public\Documents\My Pictures> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Public\Documents\My Videos> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Schmidt\Application Data> Reading the SD from <\\?\C:\Users\Schmidt\Application Data> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\Cookies> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Schmidt\Local Settings> Reading the SD from <\\?\C:\Users\Schmidt\Local Settings> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\My Documents> Reading the SD from <\\?\C:\Users\Schmidt\My Documents> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\NetHood> Reading the SD from <\\?\C:\Users\Schmidt\NetHood> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\PrintHood> Reading the SD from <\\?\C:\Users\Schmidt\PrintHood> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\Recent> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Schmidt\SendTo> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Schmidt\Start Menu> Reading the SD from <\\?\C:\Users\Schmidt\Start Menu> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\Templates> Reading the SD from <\\?\C:\Users\Schmidt\Templates> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\AppData\Local\Application Data> Reading the SD from <\\?\C:\Users\Schmidt\AppData\Local\Application Data> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\AppData\Local\History> Reading the SD from <\\?\C:\Users\Schmidt\AppData\Local\History> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\AppData\Local\Temporary Internet Files> SetACL finished successfully. Processing ACL of: <\\?\C:\Users\Schmidt\Documents\My Music> Reading the SD from <\\?\C:\Users\Schmidt\Documents\My Music> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\Documents\My Pictures> Reading the SD from <\\?\C:\Users\Schmidt\Documents\My Pictures> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Processing ACL of: <\\?\C:\Users\Schmidt\Documents\My Videos> Reading the SD from <\\?\C:\Users\Schmidt\Documents\My Videos> failed with: Das System kann die angegebene Datei nicht finden. SetACL finished with error(s): SetACL error message: The call to GetNamedSecurityInfo () failed Operating system error message: Das System kann die angegebene Datei nicht finden. Done (14.04.2014 22:22:39) 03 - Register System Files Start (14.04.2014 22:22:39) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:23:34) 04 - Repair WMI Start (14.04.2014 22:23:34) Starting Security Center So We Can Export The Security Info. Exporting Antivirus Info... avast! Antivirus Exported. Exporting AntiSpyware Info... avast! Antivirus Exported. Windows Defender Exported. Spybot - Search and Destroy Exported. Exporting 3rd Party Firewall Info... No Firewall Products Reported. Running Repair Under Current User Account Done (14.04.2014 22:30:22) 05 - Repair Windows Firewall Start (14.04.2014 22:30:22) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:30:56) 06 - Repair Internet Explorer Start (14.04.2014 22:30:56) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:31:40) 07 - Repair MDAC/MS Jet Start (14.04.2014 22:31:40) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:31:57) 08 - Repair Hosts File Start (14.04.2014 22:31:57) Running Repair Under System Account Done (14.04.2014 22:32:00) 09 - Remove Policies Set By Infections Start (14.04.2014 22:32:00) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:32:04) 10 - Repair Start Menu Icons Removed By Infections Start (14.04.2014 22:32:04) Running Repair Under System Account Done (14.04.2014 22:32:07) 11 - Repair Icons Start (14.04.2014 22:32:07) Running Repair Under Current User Account Done (14.04.2014 22:32:09) 12 - Repair Winsock & DNS Cache Start (14.04.2014 22:32:09) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:32:35) 13 - Remove Temp Files Start (14.04.2014 22:32:35) Running Repair Under System Account Done (14.04.2014 22:32:37) 14 - Repair Proxy Settings Start (14.04.2014 22:32:37) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:32:42) 15 - Unhide Non System Files Start (14.04.2014 22:32:42) C:\ - Total Files Unhidden: 509 - Check Unhidden_Files.txt for list of files unhidden Done (14.04.2014 22:37:17) 16 - Repair Windows Updates Start (14.04.2014 22:37:17) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:37:44) 17 - Repair CD/DVD Missing/Not Working Start (14.04.2014 22:37:44) iTunes not found, not applying UpperFilters iTunes Reg Key Done (14.04.2014 22:37:44) 18 - Repair Volume Shadow Copy Service Start (14.04.2014 22:37:44) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:37:53) 19 - Repair Windows Sidebar/Gadgets Start (14.04.2014 22:37:53) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:37:59) 20 - Repair MSI (Windows Installer) Start (14.04.2014 22:37:59) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:12) 21 - Repair Windows Snipping Tool Start (14.04.2014 22:38:12) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:17) 22.01 - Repair bat Association Start (14.04.2014 22:38:17) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:21) 22.02 - Repair cmd Association Start (14.04.2014 22:38:21) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:26) 22.03 - Repair com Association Start (14.04.2014 22:38:26) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:31) 22.04 - Repair Directory Association Start (14.04.2014 22:38:31) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:36) 22.05 - Repair Drive Association Start (14.04.2014 22:38:36) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:41) 22.06 - Repair exe Association Start (14.04.2014 22:38:41) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:45) 22.07 - Repair Folder Association Start (14.04.2014 22:38:45) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:50) 22.08 - Repair inf Association Start (14.04.2014 22:38:50) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:38:55) 22.09 - Repair lnk (Shortcuts) Association Start (14.04.2014 22:38:55) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:39:00) 22.10 - Repair msc Association Start (14.04.2014 22:39:00) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:39:05) 22.11 - Repair reg Association Start (14.04.2014 22:39:05) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:39:09) 22.12 - Repair scr Association Start (14.04.2014 22:39:10) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:39:14) 23 - Repair Windows Safe Mode Start (14.04.2014 22:39:14) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:39:19) 24 - Repair Print Spooler Start (14.04.2014 22:39:19) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:39:34) 25 - Restore Important Windows Services Start (14.04.2014 22:39:34) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:40:00) 26 - Set Windows Services To Default Startup Start (14.04.2014 22:40:00) Running Repair Under Current User Account Running Repair Under System Account Done (14.04.2014 22:40:11) Skipping Repair. Repair is for Windows v6.2 (Windows 8 & Newer) or higher. Current version: 6.1 Skipping Repair. Repair is for Windows v6.2 (Windows 8 & Newer) or higher. Current version: 6.1 Cleaning up empty logs... All Selected Repairs Done. Done (14.04.2014 22:40:11) Total Repair Time: 00:35:21 ...YOU MUST RESTART YOUR SYSTEM... Running Repair Under Current User Account |
15.04.2014, 10:07 | #35 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Explorer springt ständig einfach so auf Startseite (Google) In den Logs sieht man aber nichts. Erstell dir mal über die Systemsteuerung ein neues Benutzerkonto, log dich damit mal ein und teste.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.04.2014, 19:39 | #36 |
| Explorer springt ständig einfach so auf Startseite (Google) The same Scheisse... kann irgendeine "putzige" tastenkombi dahinterstecken? häufig springt der explorer, wenn ich schreibe (oder es versuche) mausklicks sind nicht ganz so schlimm, da springt der net so oft. |
15.04.2014, 22:35 | #37 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Explorer springt ständig einfach so auf Startseite (Google) Ist das ein Notebook? Wenn nicht, andere Tastatur und Maus mal anschließen. Ansonsten kann ich dich nur noch hier an unsere Hardware-Ecke verweisen => Netzwerk und Hardware - Trojaner-Board
__________________ Logfiles bitte immer in CODE-Tags posten |
20.04.2014, 10:20 | #38 |
| Explorer springt ständig einfach so auf Startseite (Google) jo es ist ein Notebook. Guti dann wende ich mich mal dahin, des Rätsels Lösung muss doch mal gefunden werden. Danke dir |