|
Plagegeister aller Art und deren Bekämpfung: Windows Version Installer 2011-2014Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.05.2014, 10:56 | #1 |
| Windows Version Installer 2011-2014 Hallo. In Anlehnung an diesen Thread: http://www.trojaner-board.de/152464-...va-update.html möchte ich darauf verweisen, dass ich wohl das gleiche Problem habe. Ich habe mir ein neues Notebook gekauft und einige Sachen installiert. Leider ist bei mir wohl auch der Virus/Trojaner "Windows Version Installer 2011-2014" drauf gekommen. Ich bin nun mal den Anweisungen aus dem oben genannten Thread nachgegangen und habe mir FRST runtergeladen und einen Scan durchgeführt. Die Logs sind im Anhang zu sehen (da hier sonst zu viele Zeichen). Ich möchte noch anmerken, dass auch ich keinerlei technische Erfahrungen im Umgang mit dem PC habe. |
03.05.2014, 12:03 | #2 |
/// TB-Ausbilder | Windows Version Installer 2011-2014Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Schritt 4 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu einen Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden zwei Logdateien erzeugt. Poste mir diese. Bitte poste mit deiner nächsten Antwort
|
03.05.2014, 17:58 | #3 |
| Windows Version Installer 2011-2014 Vielen Dank!
__________________Hier dann die Logfiles. Da Text mit den Logfiles wieder zu lang, im Anhang angefügt (außer zoek). zoek-resuls: Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 14-April-2014 Tool run by Admin on 03.05.2014 at 17:37:06.13. Microsoft Windows 8 6.2.9200 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Admin\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 03.05.2014 17:38:08 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5t3f3u7y.default\prefs.js: Added to C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5t3f3u7y.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5t3f3u7y.default user.js not found ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 3); ---- Lines aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916 removed from prefs.js ---- user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.active", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbar", "NA"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbarenhanced", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb.was_copied", "true"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet_FF25_FIX", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb.was_copied", "true"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet_FF25_FIX", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.backgroundver", 2); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.certdomaininstaller", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.changeprevious", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.expiration", "Fri Feb 01 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.value", "1398980926"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.load_balancer.expiration", "Fri May 02 20 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.load_balancer.value", "%22%7B%20%5C%22Sta user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.previous_page.expiration", "Fri Feb 01 20 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.previous_page.value", "%22https%3A//www.f user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.user_id.expiration", "Fri Feb 01 2030 00: user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.user_id.value", "%22145b9c2d9653ac956004f user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.description", "Turn YouTube videos to High Defin user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.domain", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.enablesearch", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.homepage", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.iframe", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationTime", 1398980926); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.expiration", "Fr user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.value", "%7B%22s user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledUrls.expir user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledUrls.value user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.e user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.v user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.ex user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.va user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_appVer.expiration", "Fri Fe user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_appVer.value", "41"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_lastVersion.expiration", "F user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_lastVersion.value", "1"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_meta.expiration", "Fri Feb user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_meta.value", "%7B%7D"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_nextCheck.expiration", "Fri user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_nextCheck.value", "true"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_queue.expiration", "Fri Feb user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_queue.value", "%7B%7D"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.expiration user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.value", "% user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastDailyReport", "1398980930482"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastUpdate", "1398980930144"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.manifesturl", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.name", "Plus-HD-9.11"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.newtab", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.opensearch", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsurl", "hxxp://js.clientdemostack.com/plug user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsversion", 35); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.publisher", "Plus HDC"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.searchstatus", 0); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.setnewtab", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.thankyou", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.updateinterval", 360); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.ver", 41); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.apps", "52916"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.bic", "145b9c2d9653ac956004fa127cdb6174"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.cid", 52916); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.FilesValidatorDueTime", "1398980984827"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.firstrun", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.hadappinstalled", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.installationdate", 1398980926); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.modetype", "production"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.reportInstall", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.statsDailyCounter", 1); ---- Lines {21EAF666-26B3-4a3c-ABD0-CA2F5A326744} modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}\":{\"descriptor\":\"C:\\\\ ---- FireFox user.js and prefs.js backups ---- prefs__1748_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~3\SetStretch.VBS deleted C:\PROGRA~3\WPM deleted C:\PROGRA~3\Package Cache deleted C:\Users\Admin\AppData\Local\nskF09B.tmp deleted C:\Users\Admin\AppData\Local\cache deleted C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5t3f3u7y.default\jetpack deleted C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5t3f3u7y.default\extensions\staged deleted C:\Users\Admin\AppData\Local\AnyProtectScannerSetup.exe deleted ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\5t3f3u7y.default 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 9FD6A1990289B9290563CA069CB74EF9 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll - Shockwave Flash F554963777089664140E1BECD25ACC0B - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll - PDF-XChange Viewer ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== Nothing found to reset ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-9.11 deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}_is1 deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2L5YFD7B will be deleted at reboot C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1UISSWC will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\5t3f3u7y.default\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=84 folders=22 9785144 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Admin\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Admin\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2L5YFD7B" not found "C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q1UISSWC" not found ==== EOF on 03.05.2014 at 18:29:21.67 ====================== |
04.05.2014, 11:07 | #4 |
/// TB-Ausbilder | Windows Version Installer 2011-2014 Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss daran räumen wir auf und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start HKLM\...\Run: [V-bates] => C:\Program Files\V-bates\notifier.exe C:\Program Files\V-bates GroupPolicy: Group Policy on Chrome detected <======= ATTENTION S2 Mext Guard; "C:\Program Files\V-bates\guardsvc.exe" [X] S2 vosr; C:\Users\Admin\AppData\Roaming\VOPackage\VOsrv.exe [X] C:\Users\Admin\AppData\Roaming\VOPackage C:\Program Files (x86)\webget C:\Program Files (x86)\SparPilotAddon C:\ProgramData\SetStretch.exe Task: {0875969F-04D5-45BA-A85F-BA42EE254C95} - System32\Tasks\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2 => C:\Program Files\V-bates\startsc.bat Task: {629D2416-1488-4D79-8C98-8B6CD367B97F} - \bb29c660-518d-4277-aa04-223e6257b86c-5 No Task File <==== ATTENTION Task: {6527198D-A63B-425D-BA51-20D3A2904C85} - \bb29c660-518d-4277-aa04-223e6257b86c-3 No Task File <==== ATTENTION Task: {6FFF9264-DFBB-40FD-BE58-FCA8EDC1B6B4} - \SomotoUpdateCheckerAutoStart No Task File <==== ATTENTION Task: {71FCFB1D-E464-4A57-9094-39B7F72CC908} - \bb29c660-518d-4277-aa04-223e6257b86c-4 No Task File <==== ATTENTION Task: {F12F811D-D8E8-4CC7-AC7B-AB174011CF9C} - System32\Tasks\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF} => C:\Program Files\V-bates\PrefHelper.exe Task: C:\Windows\Tasks\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF}.job => C:\Program Files\V-bates\PrefHelper.exe end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
04.05.2014, 19:00 | #5 |
| Windows Version Installer 2011-2014 FRST: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-05-2014 Ran by Admin at 2014-05-04 18:00:34 Run:1 Running from C:\Users\Admin\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start HKLM\...\Run: [V-bates] => C:\Program Files\V-bates\notifier.exe C:\Program Files\V-bates GroupPolicy: Group Policy on Chrome detected <======= ATTENTION S2 Mext Guard; "C:\Program Files\V-bates\guardsvc.exe" [X] S2 vosr; C:\Users\Admin\AppData\Roaming\VOPackage\VOsrv.exe [X] C:\Users\Admin\AppData\Roaming\VOPackage C:\Program Files (x86)\webget C:\Program Files (x86)\SparPilotAddon C:\ProgramData\SetStretch.exe Task: {0875969F-04D5-45BA-A85F-BA42EE254C95} - System32\Tasks\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2 => C:\Program Files\V-bates\startsc.bat Task: {629D2416-1488-4D79-8C98-8B6CD367B97F} - \bb29c660-518d-4277-aa04-223e6257b86c-5 No Task File <==== ATTENTION Task: {6527198D-A63B-425D-BA51-20D3A2904C85} - \bb29c660-518d-4277-aa04-223e6257b86c-3 No Task File <==== ATTENTION Task: {6FFF9264-DFBB-40FD-BE58-FCA8EDC1B6B4} - \SomotoUpdateCheckerAutoStart No Task File <==== ATTENTION Task: {71FCFB1D-E464-4A57-9094-39B7F72CC908} - \bb29c660-518d-4277-aa04-223e6257b86c-4 No Task File <==== ATTENTION Task: {F12F811D-D8E8-4CC7-AC7B-AB174011CF9C} - System32\Tasks\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF} => C:\Program Files\V-bates\PrefHelper.exe Task: C:\Windows\Tasks\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF}.job => C:\Program Files\V-bates\PrefHelper.exe end ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\V-bates => Value deleted successfully. "C:\Program Files\V-bates" => File/Directory not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. Mext Guard => Service deleted successfully. vosr => Service deleted successfully. "C:\Users\Admin\AppData\Roaming\VOPackage" => File/Directory not found. C:\Program Files (x86)\webget => Moved successfully. C:\Program Files (x86)\SparPilotAddon => Moved successfully. C:\ProgramData\SetStretch.exe => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0875969F-04D5-45BA-A85F-BA42EE254C95} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0875969F-04D5-45BA-A85F-BA42EE254C95} => Key deleted successfully. C:\Windows\System32\Tasks\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{629D2416-1488-4D79-8C98-8B6CD367B97F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{629D2416-1488-4D79-8C98-8B6CD367B97F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bb29c660-518d-4277-aa04-223e6257b86c-5 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6527198D-A63B-425D-BA51-20D3A2904C85} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6527198D-A63B-425D-BA51-20D3A2904C85} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bb29c660-518d-4277-aa04-223e6257b86c-3 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6FFF9264-DFBB-40FD-BE58-FCA8EDC1B6B4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FFF9264-DFBB-40FD-BE58-FCA8EDC1B6B4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71FCFB1D-E464-4A57-9094-39B7F72CC908} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71FCFB1D-E464-4A57-9094-39B7F72CC908} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bb29c660-518d-4277-aa04-223e6257b86c-4 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F12F811D-D8E8-4CC7-AC7B-AB174011CF9C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F12F811D-D8E8-4CC7-AC7B-AB174011CF9C} => Key deleted successfully. C:\Windows\System32\Tasks\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF} => Key deleted successfully. C:\Windows\Tasks\FF Watcher {FF7B035B-9A0D-4567-97CC-F647319693DF}.job => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=cd5ab9f891df02498f620db2ca3d1a5e # engine=18129 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-04 05:35:22 # local_time=2014-05-04 07:35:22 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode=1799 16775165 100 94 6575 5907258 0 0 # compatibility_mode=5893 16776574 100 94 90786 32261427 0 0 # scanned=249535 # found=0 # cleaned=0 # scan_time=4871 Code:
ATTFilter Results of screen317's Security Check version 0.99.82 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Java 7 Update 55 Adobe Flash Player 13.0.0.206 Adobe Reader 10.1.9 Adobe Reader out of Date! Mozilla Firefox (29.0) ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
05.05.2014, 14:03 | #6 |
/// TB-Ausbilder | Windows Version Installer 2011-2014 Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Die Reihenfolge ist hier entscheidend.
Schritt 2 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
05.05.2014, 14:55 | #7 |
| Windows Version Installer 2011-2014 Vielen Dank für die schnelle Hilfe! Sollte es noch mal Probleme geben (na hoffentlich nicht ...), melde ich mich hier sicher wieder. |
06.05.2014, 13:16 | #8 |
/// TB-Ausbilder | Windows Version Installer 2011-2014 Ich bin froh, dass wir helfen konnten In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Themen zu Windows Version Installer 2011-2014 |
anhang, ebook, erfahrungen, gekauft, gen, installer, installier, keinerlei, merke, neues, notebook, problem, runtergeladen, sache, sachen, scan, technische, thread, umgang, version, verweise, verweisen, virus/trojaner, windows, windows version installer, zeichen |