|
Plagegeister aller Art und deren Bekämpfung: updownlinkg.comWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.04.2014, 09:14 | #1 | |
| updownlinkg.com Hallo Jungs und Mädels ich habe seit tagen dieses kleine Problem. Es geht immer wieder eine seite auf und fordert mich auf java zu installieren Zitat:
Geändert von tce (19.04.2014 um 09:24 Uhr) |
19.04.2014, 09:36 | #2 |
/// the machine /// TB-Ausbilder | updownlinkg.com hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
19.04.2014, 15:07 | #3 |
| updownlinkg.com Habe ich versucht mit FRST 64-Bit, da ich einen 64 bit habe. Aber der läuft nicht durch macht einen error.
__________________Siehe bild Ich spamme ungerne jetzz, aber hat einer eine lösung für mein problem oder muss ich meinen PC neu Konfigurieren. Also Plat machen. |
20.04.2014, 17:55 | #4 |
/// the machine /// TB-Ausbilder | updownlinkg.com Ich sehe keinen Error, nur dass er gerade dabei ist die Eventviewer Einträge zu lesen. Mach mal den Haken raus bei Addition.txt und scanne nochmal.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.04.2014, 19:42 | #5 | |
| updownlinkg.com So jetzt habe ich es noch mal gemacht Zitat:
|
20.04.2014, 19:43 | #6 | |
| updownlinkg.com zweite hälfte Zitat:
|
21.04.2014, 20:12 | #7 |
/// the machine /// TB-Ausbilder | updownlinkg.comSo funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.04.2014, 21:22 | #8 |
| updownlinkg.comCode:
ATTFilter ComboFix 14-04-20.01 - Tce 21.04.2014 22:08:42.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6135.3061 [GMT 2:00] ausgeführt von:: c:\users\Tce\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Tce\AppData\Local\nsnB740.tmp c:\users\Tce\AppData\Local\Temp\nsv8629.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-21 bis 2014-04-21 )))))))))))))))))))))))))))))) . . 2014-04-21 20:14 . 2014-04-21 20:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-19 15:01 . 2014-04-19 15:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B165C49-67B7-4551-9425-CF8CBEF363FF}\offreg.dll 2014-04-19 08:53 . 2014-04-20 18:38 -------- d-----w- C:\FRST 2014-04-18 12:41 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B165C49-67B7-4551-9425-CF8CBEF363FF}\mpengine.dll 2014-04-14 12:06 . 2014-04-14 12:06 -------- d-----w- c:\program files (x86)\Common Files\logishrd 2014-04-14 12:06 . 2014-04-14 12:06 -------- d-----w- c:\program files\Common Files\logishrd 2014-04-12 22:41 . 2014-04-12 22:41 -------- d-----w- c:\users\Tce\oxwell 2014-04-09 15:25 . 2005-08-30 10:02 24576 ------w- c:\windows\SysWow64\Ulead Photo Explorer 86.scr 2014-04-09 15:23 . 2006-07-22 17:37 49152 ------w- c:\windows\SysWow64\INETWH32.dll 2014-04-09 15:23 . 1999-10-15 10:50 1056768 ------w- c:\windows\SysWow64\ROBOEX32.DLL 2014-04-09 15:23 . 2014-04-09 15:25 -------- d-----w- c:\program files (x86)\Common Files\Ulead Systems 2014-04-09 15:22 . 2002-12-02 13:22 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe 2014-04-08 23:49 . 2014-04-09 00:01 -------- d-----w- c:\users\Tce\ersatz 2014-04-08 23:19 . 2014-04-12 23:42 -------- d-----w- c:\users\Tce\templat_top 2014-04-06 11:03 . 2014-04-06 11:03 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2014-04-06 08:35 . 2014-04-06 08:35 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-04-06 01:46 . 2014-04-14 16:35 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-04-06 01:45 . 2014-04-06 01:45 -------- d-----w- c:\programdata\Malwarebytes 2014-04-06 01:33 . 2014-04-06 01:33 -------- d-----w- c:\windows\ERUNT 2014-04-06 01:28 . 2014-04-16 08:55 -------- d-----w- C:\AdwCleaner 2014-04-06 00:39 . 2014-04-06 00:58 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-04-05 23:29 . 2014-04-06 00:27 -------- d-----w- c:\program files (x86)\Uninstaller 2014-04-05 23:29 . 2008-04-07 03:38 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll 2014-04-05 22:36 . 2014-04-05 22:36 -------- d-----w- c:\users\Tce\AppData\Roaming\Avira 2014-04-05 22:35 . 2014-02-25 09:41 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2014-04-05 22:35 . 2014-02-25 09:41 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-04-05 22:35 . 2014-02-25 09:41 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-04-05 22:35 . 2014-04-05 22:35 -------- d-----w- c:\programdata\Avira 2014-04-05 21:37 . 2014-04-05 21:37 -------- d-----w- c:\programdata\FLEXnet 2014-04-05 08:48 . 2014-04-12 14:19 -------- d-----w- c:\program files (x86)\WinSCP 2014-04-05 08:47 . 2014-04-05 08:47 -------- d-----w- c:\users\Tce\AppData\Local\Programs 2014-04-05 07:25 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll 2014-04-05 07:25 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll 2014-04-05 07:10 . 2014-04-05 07:10 -------- d-----w- c:\users\Tce\AppData\Local\NVIDIA 2014-04-05 07:01 . 2014-04-11 01:04 -------- d-----w- c:\windows\system32\MRT 2014-04-05 07:00 . 2014-03-04 11:32 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2014-04-05 07:00 . 2014-03-04 13:05 3649185 ----a-w- c:\windows\system32\nvcoproc.bin 2014-04-05 06:58 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll 2014-04-05 06:58 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll 2014-04-05 06:58 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll 2014-04-05 06:58 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll 2014-04-04 12:29 . 2014-04-04 12:29 -------- d-----w- c:\program files (x86)\Hewlett-Packard 2014-04-04 12:29 . 2014-04-11 13:47 -------- d-----w- c:\users\Tce\AppData\Roaming\HpUpdate 2014-04-04 12:29 . 2012-10-17 02:31 741480 ------w- c:\windows\system32\HPDiscoPM5912.dll 2014-04-04 12:28 . 2014-04-04 12:29 -------- d-----w- c:\program files (x86)\HP 2014-04-04 12:28 . 2014-04-04 12:28 -------- d-----w- c:\programdata\HP 2014-04-04 12:28 . 2014-04-04 12:28 -------- d-----w- c:\program files\HP 2014-04-04 12:28 . 2014-04-04 12:32 -------- d-----w- c:\users\Tce\AppData\Local\HP 2014-04-04 12:24 . 2014-04-04 12:24 -------- d-----w- c:\users\Tce\AppData\Local\ElevatedDiagnostics 2014-04-03 19:32 . 2014-04-03 19:32 -------- d-----w- c:\users\Tce\AppData\Roaming\vlc 2014-04-03 19:31 . 2014-04-03 19:31 -------- d-----w- c:\program files (x86)\VideoLAN 2014-04-03 10:04 . 2014-04-03 10:04 -------- d-----w- c:\users\Tce\AppData\Local\AviraSpeedup 2014-04-03 09:51 . 2014-04-05 22:36 -------- d-----w- c:\program files (x86)\Avira 2014-03-27 15:24 . 2014-03-27 15:24 -------- d-----w- c:\users\Tce\config . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-21 08:24 . 2014-03-14 07:45 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-04-21 08:24 . 2014-03-14 07:45 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-03-31 07:35 . 2014-03-14 20:40 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-03-21 02:04 . 2014-03-21 02:04 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2014-03-21 02:04 . 2014-03-21 02:04 942592 ----a-w- c:\windows\system32\jsIntl.dll 2014-03-21 02:04 . 2014-03-21 02:04 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2014-03-21 02:04 . 2014-03-21 02:04 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2014-03-21 02:04 . 2014-03-21 02:04 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2014-03-21 02:04 . 2014-03-21 02:04 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-03-21 02:04 . 2014-03-21 02:04 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-03-21 02:04 . 2014-03-21 02:04 81408 ----a-w- c:\windows\system32\icardie.dll 2014-03-21 02:04 . 2014-03-21 02:04 774144 ----a-w- c:\windows\system32\jscript.dll 2014-03-21 02:04 . 2014-03-21 02:04 77312 ----a-w- c:\windows\system32\tdc.ocx 2014-03-21 02:04 . 2014-03-21 02:04 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2014-03-21 02:04 . 2014-03-21 02:04 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2014-03-21 02:04 . 2014-03-21 02:04 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2014-03-21 02:04 . 2014-03-21 02:04 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2014-03-21 02:04 . 2014-03-21 02:04 62464 ----a-w- c:\windows\system32\pngfilt.dll 2014-03-21 02:04 . 2014-03-21 02:04 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-03-21 02:04 . 2014-03-21 02:04 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2014-03-21 02:04 . 2014-03-21 02:04 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2014-03-21 02:04 . 2014-03-21 02:04 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2014-03-21 02:04 . 2014-03-21 02:04 48640 ----a-w- c:\windows\system32\mshtmler.dll 2014-03-21 02:04 . 2014-03-21 02:04 48128 ----a-w- c:\windows\system32\imgutil.dll 2014-03-21 02:04 . 2014-03-21 02:04 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2014-03-21 02:04 . 2014-03-21 02:04 413696 ----a-w- c:\windows\system32\html.iec 2014-03-21 02:04 . 2014-03-21 02:04 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-03-21 02:04 . 2014-03-21 02:04 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2014-03-21 02:04 . 2014-03-21 02:04 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-03-21 02:04 . 2014-03-21 02:04 337408 ----a-w- c:\windows\SysWow64\html.iec 2014-03-21 02:04 . 2014-03-21 02:04 30208 ----a-w- c:\windows\system32\licmgr10.dll 2014-03-21 02:04 . 2014-03-21 02:04 296960 ----a-w- c:\windows\system32\dxtrans.dll 2014-03-21 02:04 . 2014-03-21 02:04 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2014-03-21 02:04 . 2014-03-21 02:04 247808 ----a-w- c:\windows\system32\msls31.dll 2014-03-21 02:04 . 2014-03-21 02:04 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2014-03-21 02:04 . 2014-03-21 02:04 243200 ----a-w- c:\windows\system32\webcheck.dll 2014-03-21 02:04 . 2014-03-21 02:04 235520 ----a-w- c:\windows\system32\url.dll 2014-03-21 02:04 . 2014-03-21 02:04 235008 ----a-w- c:\windows\system32\elshyph.dll 2014-03-21 02:04 . 2014-03-21 02:04 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2014-03-21 02:04 . 2014-03-21 02:04 167424 ----a-w- c:\windows\system32\iexpress.exe 2014-03-21 02:04 . 2014-03-21 02:04 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2014-03-21 02:04 . 2014-03-21 02:04 147968 ----a-w- c:\windows\system32\occache.dll 2014-03-21 02:04 . 2014-03-21 02:04 143872 ----a-w- c:\windows\system32\wextract.exe 2014-03-21 02:04 . 2014-03-21 02:04 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2014-03-21 02:04 . 2014-03-21 02:04 13824 ----a-w- c:\windows\system32\mshta.exe 2014-03-21 02:04 . 2014-03-21 02:04 135680 ----a-w- c:\windows\system32\iepeers.dll 2014-03-21 02:04 . 2014-03-21 02:04 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2014-03-21 02:04 . 2014-03-21 02:04 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2014-03-21 02:04 . 2014-03-21 02:04 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2014-03-21 02:04 . 2014-03-21 02:04 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-03-21 02:04 . 2014-03-21 02:04 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2014-03-21 02:04 . 2014-03-21 02:04 105984 ----a-w- c:\windows\system32\iesysprep.dll 2014-03-21 02:04 . 2014-03-21 02:04 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-03-21 02:04 . 2014-03-21 02:04 101376 ----a-w- c:\windows\system32\inseng.dll 2014-03-20 21:03 . 2010-08-26 09:11 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll 2014-03-20 21:03 . 2010-08-26 09:11 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2014-03-20 21:03 . 2014-03-20 21:03 947808 ----a-w- c:\windows\system32\nvumdshimx.dll 2014-03-20 21:03 . 2014-03-20 21:03 832936 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2014-03-20 21:03 . 2014-03-20 21:03 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll 2014-03-20 21:03 . 2014-03-20 21:03 11589272 ----a-w- c:\windows\system32\nvopencl.dll 2014-03-20 21:02 . 2014-03-20 21:02 31474976 ----a-w- c:\windows\system32\nvoglv64.dll 2014-03-20 21:02 . 2014-03-20 21:02 353504 ----a-w- c:\windows\system32\nvoglshim64.dll 2014-03-20 21:02 . 2014-03-20 21:02 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll 2014-03-20 21:02 . 2014-03-20 21:02 23716640 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2014-03-20 21:02 . 2014-03-20 21:02 12708128 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2014-03-20 21:02 . 2014-03-20 21:02 892704 ----a-w- c:\windows\system32\NvIFR64.dll 2014-03-20 21:02 . 2014-03-20 21:02 863064 ----a-w- c:\windows\SysWow64\NvIFR.dll 2014-03-20 21:02 . 2014-03-20 21:02 174296 ----a-w- c:\windows\system32\nvinitx.dll 2014-03-20 21:02 . 2014-03-20 21:02 148016 ----a-w- c:\windows\SysWow64\nvinit.dll 2014-03-20 21:02 . 2014-03-20 21:02 877856 ----a-w- c:\windows\system32\NvFBC64.dll 2014-03-20 21:02 . 2014-03-20 21:02 846168 ----a-w- c:\windows\SysWow64\NvFBC.dll 2014-03-20 21:02 . 2014-03-20 21:02 1885472 ----a-w- c:\windows\system32\nvdispco6433523.dll 2014-03-20 21:02 . 2014-03-20 21:02 1516488 ----a-w- c:\windows\system32\nvdispgenco6433523.dll 2014-03-20 21:02 . 2014-03-20 21:02 3143456 ----a-w- c:\windows\system32\nvcuvid.dll 2014-03-20 21:02 . 2014-03-20 21:02 17755424 ----a-w- c:\windows\system32\nvd3dumx.dll 2014-03-20 21:02 . 2010-08-26 09:10 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2014-03-20 21:02 . 2014-03-20 21:02 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll 2014-03-20 21:02 . 2014-03-20 21:02 2958792 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2014-03-20 21:02 . 2014-03-20 21:02 2783008 ----a-w- c:\windows\system32\nvcuvenc.dll 2014-03-20 21:02 . 2014-03-20 21:02 2411976 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2014-03-20 21:02 . 2014-03-20 21:02 11636176 ----a-w- c:\windows\system32\nvcuda.dll 2014-03-20 21:02 . 2014-03-20 21:02 17561544 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2014-03-20 21:02 . 2014-03-20 21:02 25255256 ----a-w- c:\windows\system32\nvcompiler.dll 2014-03-20 21:02 . 2010-08-26 09:10 3093280 ----a-w- c:\windows\system32\nvapi64.dll 2014-03-20 21:02 . 2014-03-20 21:02 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll 2014-03-20 02:11 . 2014-03-20 02:11 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2014-03-20 02:11 . 2014-03-20 02:11 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2014-03-20 02:11 . 2014-03-20 02:11 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2014-03-20 02:11 . 2014-03-20 02:11 363008 ----a-w- c:\windows\system32\dxgi.dll 2014-03-20 02:11 . 2014-03-20 02:11 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-03-20 02:11 . 2014-03-20 02:11 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A18A516C-AA41-46A9-92DB-60208917E442}] 2013-12-11 14:49 184400 ----a-w- c:\program files (x86)\Avira\Internet Explorer\avira32.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-11 39408] "HP Officejet Pro 8600 (NET)"="c:\program files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe" [2012-10-17 2573416] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Hotkey Utility"="c:\program files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe" [2010-08-04 611872] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-25 689744] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376] "Ulead AutoDetector v2"="c:\program files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "AviraSpeedup"="c:\program files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" [2014-04-03 5085416] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Photo Frame.lnk - c:\program files (x86)\Northstar\Photo Frame\Photo Frame.exe [2010-5-11 93568] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 vosr;Service Component of VO;c:\users\Tce\AppData\Roaming\VOPackage\VOsrv.exe;c:\users\Tce\AppData\Roaming\VOPackage\VOsrv.exe [x] R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 EraserUtilDrv11312;EraserUtilDrv11312;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11312.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11312.sys [x] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 UPnPService;UPnPService;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [x] S2 USBS3S4Detection;USBS3S4Detection;c:\oem\USBDECTION\USBS3S4Detection.exe;c:\oem\USBDECTION\USBS3S4Detection.exe [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-10 18:04 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-14 08:24] . 2014-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-13 18:47] . 2014-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-13 18:47] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-09 10060320] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-03-20 1797064] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\acaptuser64.dll . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://google.de/ uLocal Page = c:\windows\system32\blank.htm mDefault_Search_URL = hxxp://www.google.com mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Tce\AppData\Roaming\Mozilla\Firefox\Profiles\qeubepd2.default\ FF - prefs.js: browser.search.selectedEngine - Web Search (powered by Google) FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - prefs.js: keyword.URL - hxxp://search.toolbars.alexa.com/?ver=alxf-2.19&src=ab&aid=viw8j1sZQw00qN&q= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1934781817-2233350501-3576918985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1934781817-2233350501-3576918985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-21 22:17:13 ComboFix-quarantined-files.txt 2014-04-21 20:17 . Vor Suchlauf: 10 Verzeichnis(se), 393.403.760.640 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 394.279.129.088 Bytes frei . - - End Of File - - B83F049F1CA3B5BDC523C8C5FD388E33 A36C5E4F47E84449FF07ED3517B43A31 |
22.04.2014, 13:51 | #9 |
/// the machine /// TB-Ausbilder | updownlinkg.com Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu updownlinkg.com |
immer wieder, installiere, java, jungs, kleine, runter, seite, tagen |