Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: nach firefox update / portaldosites in jedem neuen tap

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 27.05.2014, 11:35   #1
schrauber
/// the machine
/// TB-Ausbilder
 

nach firefox update / portaldosites in jedem neuen tap - Standard

nach firefox update / portaldosites in jedem neuen tap




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 29.05.2014, 10:28   #2
MaKenobby
 
nach firefox update / portaldosites in jedem neuen tap - Standard

nach firefox update / portaldosites in jedem neuen tap



Zitat:
Zitat von schrauber Beitrag anzeigen
Noch Probleme?
Sieht nicht so aus

und hier die gewünschten Logfiles.

Eset:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=92e2e47536e5a44ab26633612dce0cd2
# engine=18453
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-05-29 08:54:59
# local_time=2014-05-29 10:54:59 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 17752278 152983549 0 0
# scanned=289056
# found=1
# cleaned=0
# scan_time=4701
sh=BD7191934AD2B1159ABFD20C26A0EF8E870015EC ft=1 fh=3d9a72fb821c127c vn="Variante von Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Spiele (Programme)\Farm_Up\Farm_Up.exe"
         
Security Check
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.83  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
AVG AntiVirus Free Edition 2014   
 Antivirus out of date!  
`````````Anti-malware/Other Utilities Check:````````` 
  Adobe Flash Player 12.0.0.43 Flash Player out of Date!  
 Adobe Reader XI  
 Mozilla Firefox (29.0.1) 
 Mozilla Thunderbird (24.5.0) 
````````Process Check: objlist.exe by Laurent````````  
 AVG avgwdsvc.exe 
 Online Games Manager ogmservice.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
und das neue FRST

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Martina (administrator) on MARTINA-PC on 29-05-2014 11:16:33
Running from C:\Users\Martina\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-690356491-1174369309-2236414189-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {FC739C94-F44E-4EBA-9B70-87AB45DFD999} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS
SearchScopes: HKLM-x32 - {FC739C94-F44E-4EBA-9B70-87AB45DFD999} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MASBJS
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\..\Interfaces\{0F245E3B-7DC2-4299-BED7-9089C5A77AA1}: [NameServer]62.109.121.2 62.109.121.1
Tcpip\..\Interfaces\{441E04CD-6116-4027-919E-D2D34375EACE}: [NameServer]8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1

FireFox:
========
FF ProfilePath: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default
FF Homepage: about:blank
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2013-12-25]
FF Extension: Noia 4 Theme Manager - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\Noia4Options@ArisT2.xpi [2013-11-03]
FF Extension: Noia Fox options - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2013-11-03]
FF Extension: Personas Plus - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\personas@christopher.beard.xpi [2013-11-03]
FF Extension: No Name - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2013-11-03]
FF Extension: AniWeather - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2013-11-03]
FF Extension: KOLOBOK Smiles - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{5CEFD22F-9A9E-4544-9BFC-C4F2FBCA87D6}.xpi [2013-11-03]
FF Extension: eCleaner - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi [2013-11-03]
FF Extension: Ecosia - The search engine that plants trees - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2013-11-03]
FF Extension: Adblock Plus - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-03]
FF Extension: BetterPrivacy - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-12-09]
FF Extension: Extended Statusbar - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\wcyk0en5.default\Extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi [2013-11-03]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION

==================== Services (Whitelisted) =================

S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.)

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-11-16] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-11-16] ()
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 DIRECTIO; \??\UNC\srv1c027.wds8.intern\reminst\Test\BitPro64\DirectIo.sys [X]
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-29 11:16 - 2014-05-29 11:16 - 00009341 _____ () C:\Users\Martina\Desktop\FRST.txt
2014-05-29 11:15 - 2014-05-29 11:15 - 00000835 _____ () C:\Users\Martina\Desktop\checkup.txt
2014-05-29 11:04 - 2014-05-29 11:04 - 00854367 _____ () C:\Users\Martina\Desktop\SecurityCheck.exe
2014-05-26 12:12 - 2014-05-26 12:12 - 00000000 ____D () C:\BigFishCache
2014-05-26 10:46 - 2014-05-26 10:46 - 00000000 ____D () C:\Users\Martina\Desktop\FRST-OlderVersion
2014-05-26 10:32 - 2014-05-26 10:32 - 00001936 _____ () C:\Users\Martina\Malw. Suchlauf Protokoll.txt
2014-05-26 10:24 - 2014-05-26 10:28 - 00000000 ____D () C:\AdwCleaner
2014-05-26 10:06 - 2014-05-26 10:29 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-26 10:06 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-26 10:06 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-26 10:06 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-22 22:23 - 2014-05-22 22:23 - 00001800 _____ () C:\Users\Public\Desktop\ANNO 1503.lnk
2014-05-22 22:20 - 2014-05-22 22:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ANNO 1503 GOLD
2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\cerasus.media
2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\ProgramData\cerasus.media
2014-05-21 23:42 - 2014-05-21 23:42 - 00000961 _____ () C:\Users\Public\Desktop\MahJongg - Ancient Mayas.lnk
2014-05-21 23:42 - 2014-05-21 23:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\freundin-Games
2014-05-21 09:32 - 2014-05-21 09:43 - 00000000 ____D () C:\Qoobox
2014-05-21 09:32 - 2014-05-21 09:42 - 00000000 ____D () C:\Windows\erdnt
2014-05-21 09:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-21 09:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-21 09:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-21 09:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-21 09:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-21 09:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-21 09:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-21 09:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-20 10:23 - 2014-05-29 11:16 - 00000000 ____D () C:\Users\Martina\Desktop\Neuer Ordner
2014-05-20 09:52 - 2014-05-29 11:16 - 00000000 ____D () C:\FRST
2014-05-20 09:51 - 2014-05-26 10:46 - 02066944 _____ (Farbar) C:\Users\Martina\Desktop\FRST64.exe
2014-05-20 07:38 - 2014-05-20 07:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-17 15:52 - 2014-05-17 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tradewinds Caravans
2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Farm Up
2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Farm Up
2014-05-16 19:48 - 2014-05-16 19:48 - 00001743 _____ () C:\Users\Public\Desktop\The Snow Fable.lnk
2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Snow Fable
2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Snow Fable
2014-05-15 18:42 - 2014-05-15 18:42 - 00001888 _____ () C:\Users\Martina\Desktop\Mystika 2 - The Sanctuary.lnk
2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\unikgame
2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary
2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary
2014-05-14 23:24 - 2014-05-15 00:39 - 00000000 ____D () C:\Users\Martina\Documents\Big Bang West
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-13 00:36 - 2014-05-13 00:36 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\GameInvest
2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder
2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder
2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition
2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition
2014-05-07 13:01 - 2014-05-07 13:01 - 00017047 _____ () C:\Users\Martina\Documents\Mietvertrag Wohnungsbörse.odt
2014-05-04 16:54 - 2014-05-04 16:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-03 08:27 - 2014-05-03 08:30 - 00000000 ____D () C:\ProgramData\Emberwind
2014-05-03 08:25 - 2014-05-03 08:25 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-05-02 12:23 - 2014-05-02 12:23 - 00000000 ____D () C:\ProgramData\Magic-Heroes
2014-05-02 12:06 - 2014-05-02 12:06 - 00001923 _____ () C:\Users\Public\Desktop\Magic Heroes - Save Our Park.lnk
2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park
2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park
2014-05-01 13:19 - 2014-05-03 08:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom
2014-05-01 13:19 - 2014-05-03 08:34 - 00000000 ____D () C:\Program Files (x86)\RealArcade
2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\ProgramData\PlayFirst
2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\Program Files (x86)\Online Games Manager
2014-04-30 18:52 - 2014-04-30 18:52 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\WinRAR

==================== One Month Modified Files and Folders =======

2014-05-29 11:16 - 2014-05-29 11:16 - 00009341 _____ () C:\Users\Martina\Desktop\FRST.txt
2014-05-29 11:16 - 2014-05-20 10:23 - 00000000 ____D () C:\Users\Martina\Desktop\Neuer Ordner
2014-05-29 11:16 - 2014-05-20 09:52 - 00000000 ____D () C:\FRST
2014-05-29 11:15 - 2014-05-29 11:15 - 00000835 _____ () C:\Users\Martina\Desktop\checkup.txt
2014-05-29 11:04 - 2014-05-29 11:04 - 00854367 _____ () C:\Users\Martina\Desktop\SecurityCheck.exe
2014-05-29 09:20 - 2013-11-03 22:26 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-29 08:46 - 2013-11-03 20:32 - 01561723 _____ () C:\Windows\WindowsUpdate.log
2014-05-29 07:46 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-29 07:46 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-29 07:43 - 2011-04-12 09:43 - 00698688 _____ () C:\Windows\system32\perfh007.dat
2014-05-29 07:43 - 2011-04-12 09:43 - 00148828 _____ () C:\Windows\system32\perfc007.dat
2014-05-29 07:43 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-29 07:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-29 07:39 - 2009-07-14 06:51 - 00074431 _____ () C:\Windows\setupact.log
2014-05-26 12:12 - 2014-05-26 12:12 - 00000000 ____D () C:\BigFishCache
2014-05-26 10:46 - 2014-05-26 10:46 - 00000000 ____D () C:\Users\Martina\Desktop\FRST-OlderVersion
2014-05-26 10:46 - 2014-05-20 09:51 - 02066944 _____ (Farbar) C:\Users\Martina\Desktop\FRST64.exe
2014-05-26 10:32 - 2014-05-26 10:32 - 00001936 _____ () C:\Users\Martina\Malw. Suchlauf Protokoll.txt
2014-05-26 10:32 - 2013-11-03 20:34 - 00000000 ____D () C:\Users\Martina
2014-05-26 10:29 - 2014-05-26 10:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-26 10:28 - 2014-05-26 10:24 - 00000000 ____D () C:\AdwCleaner
2014-05-26 10:28 - 2010-11-21 05:47 - 00459318 _____ () C:\Windows\PFRO.log
2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-26 10:06 - 2014-05-26 10:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-26 10:06 - 2013-12-09 23:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-23 18:05 - 2013-11-17 18:20 - 00000000 ____D () C:\Users\Martina\AppData\Local\CrashDumps
2014-05-22 22:37 - 2013-11-04 07:43 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-05-22 22:23 - 2014-05-22 22:23 - 00001800 _____ () C:\Users\Public\Desktop\ANNO 1503.lnk
2014-05-22 22:23 - 2014-05-22 22:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ANNO 1503 GOLD
2014-05-22 22:20 - 2013-11-16 19:35 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-22 22:19 - 2013-12-11 01:00 - 00000000 ____D () C:\Spiele (Programme)
2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\cerasus.media
2014-05-21 23:43 - 2014-05-21 23:43 - 00000000 ____D () C:\ProgramData\cerasus.media
2014-05-21 23:42 - 2014-05-21 23:42 - 00000961 _____ () C:\Users\Public\Desktop\MahJongg - Ancient Mayas.lnk
2014-05-21 23:42 - 2014-05-21 23:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\freundin-Games
2014-05-21 22:33 - 2013-11-17 22:37 - 00000000 ___RD () C:\Users\Martina\Desktop\Games
2014-05-21 09:43 - 2014-05-21 09:32 - 00000000 ____D () C:\Qoobox
2014-05-21 09:42 - 2014-05-21 09:32 - 00000000 ____D () C:\Windows\erdnt
2014-05-21 09:41 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-20 08:28 - 2013-11-17 15:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-20 08:26 - 2014-04-04 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-20 07:38 - 2014-05-20 07:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-18 20:32 - 2013-11-13 15:35 - 00000000 ___RD () C:\Users\Martina\Desktop\Mieter & Verträge
2014-05-18 06:28 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-17 15:52 - 2014-05-17 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tradewinds Caravans
2014-05-17 15:52 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-05-16 20:04 - 2014-02-13 01:47 - 00001722 _____ () C:\Users\Public\Desktop\Farm Up.lnk
2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Farm Up
2014-05-16 20:03 - 2014-05-16 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Farm Up
2014-05-16 19:59 - 2013-11-18 16:15 - 00000000 ___RD () C:\MaBluEden
2014-05-16 19:59 - 2013-11-04 23:18 - 00000000 ___RD () C:\Users\Martina\AppData\Roaming\Realore
2014-05-16 19:48 - 2014-05-16 19:48 - 00001743 _____ () C:\Users\Public\Desktop\The Snow Fable.lnk
2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Snow Fable
2014-05-16 19:48 - 2014-05-16 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Snow Fable
2014-05-15 18:42 - 2014-05-15 18:42 - 00001888 _____ () C:\Users\Martina\Desktop\Mystika 2 - The Sanctuary.lnk
2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\unikgame
2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary
2014-05-15 18:42 - 2014-05-15 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mystika 2 - The Sanctuary
2014-05-15 00:39 - 2014-05-14 23:24 - 00000000 ____D () C:\Users\Martina\Documents\Big Bang West
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-13 00:36 - 2014-05-13 00:36 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\GameInvest
2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder
2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Zellians - Kingdom Builder
2014-05-12 07:26 - 2014-05-26 10:06 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-26 10:06 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-26 10:06 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 21:27 - 2013-11-06 08:46 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\AlawarEntertainment
2014-05-11 17:12 - 2013-12-24 23:15 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\ERS Game Studios
2014-05-11 17:00 - 2014-04-26 21:11 - 00000000 ____D () C:\Users\Martina\Documents\LDW
2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition
2014-05-11 09:46 - 2014-05-11 09:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forgotten Books - The Enchanted Crown Collectors Edition
2014-05-08 08:39 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-05-07 13:01 - 2014-05-07 13:01 - 00017047 _____ () C:\Users\Martina\Documents\Mietvertrag Wohnungsbörse.odt
2014-05-04 16:55 - 2014-05-04 16:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-03 08:34 - 2014-05-01 13:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom
2014-05-03 08:34 - 2014-05-01 13:19 - 00000000 ____D () C:\Program Files (x86)\RealArcade
2014-05-03 08:30 - 2014-05-03 08:27 - 00000000 ____D () C:\ProgramData\Emberwind
2014-05-03 08:25 - 2014-05-03 08:25 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-05-03 08:25 - 2014-05-03 08:25 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-05-02 12:23 - 2014-05-02 12:23 - 00000000 ____D () C:\ProgramData\Magic-Heroes
2014-05-02 12:06 - 2014-05-02 12:06 - 00001923 _____ () C:\Users\Public\Desktop\Magic Heroes - Save Our Park.lnk
2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park
2014-05-02 12:06 - 2014-05-02 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Heroes - Save Our Park
2014-05-01 13:46 - 2013-11-17 16:18 - 00000000 ____D () C:\Users\Martina\AppData\Local\VirtualStore
2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\ProgramData\PlayFirst
2014-04-30 18:55 - 2014-04-30 18:55 - 00000000 ____D () C:\Program Files (x86)\Online Games Manager
2014-04-30 18:55 - 2013-11-13 17:01 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\PlayFirst
2014-04-30 18:52 - 2014-04-30 18:52 - 00000000 ____D () C:\Users\Martina\AppData\Roaming\WinRAR

Some content of TEMP:
====================
C:\Users\Martina\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Martina\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-29 00:47

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Ich sage noch ein mal herzlichen Dank
und wünsche Dir einen schönen Tag

LG
Martina
__________________


Antwort

Themen zu nach firefox update / portaldosites in jedem neuen tap
erschein, erscheint, firefox, frage, heute, morgen, nationzoom, nationzoom entfernen, neue, neuen, portaldosites, pup.optional.feven.a, pup.optional.nationzoom.a, pup.optional.qone8, schnell, spyware, suche, update, win32/toolbar.conduit.ae




Ähnliche Themen: nach firefox update / portaldosites in jedem neuen tap


  1. Nach Firefox update 33.0 (x86de) ist nur noch ein schwarzes Fenster da!
    Mülltonne - 16.10.2014 (1)
  2. Firefox setzt Einstellung nach jedem Neustart zurück
    Alles rund um Windows - 16.10.2014 (3)
  3. Lästige Werbung im Browser nach Update von Firefox
    Plagegeister aller Art und deren Bekämpfung - 19.04.2014 (15)
  4. Firefox/Win7 – übermäßige Werbung (Pseudo-Links und WerbeFenster) nach Firefox-Update
    Log-Analyse und Auswertung - 12.12.2013 (9)
  5. "Portaldosites" in jedem Browser
    Log-Analyse und Auswertung - 04.10.2013 (7)
  6. portaldosites als Startseite im IE und FireFox lässt sich nicht löschen!
    Plagegeister aller Art und deren Bekämpfung - 29.08.2013 (20)
  7. web.de suche ungewollt in firefox nach update
    Plagegeister aller Art und deren Bekämpfung - 09.08.2013 (15)
  8. "Portaldosites" in jedem Browser
    Plagegeister aller Art und deren Bekämpfung - 03.06.2013 (3)
  9. Virus ahoi! "Portaldosites" in jedem Browser, MBAM-Fund, nicht löschbar?
    Plagegeister aller Art und deren Bekämpfung - 02.06.2013 (19)
  10. deltasearch automatisch bei jedem neuen leeren Tab
    Plagegeister aller Art und deren Bekämpfung - 12.05.2013 (3)
  11. www.searchnu.com/406 wird bei jedem neuen Tab geöffnet
    Plagegeister aller Art und deren Bekämpfung - 17.02.2013 (43)
  12. Nach WIN und Firefox Update ruckeln im Firefox und verschwundene Emails
    Log-Analyse und Auswertung - 08.01.2013 (28)
  13. MyStart Trojaner in jedem neuen Tab (Mozilla)
    Plagegeister aller Art und deren Bekämpfung - 02.10.2012 (49)
  14. Mystart incredibar in jedem neuen Tab
    Plagegeister aller Art und deren Bekämpfung - 22.09.2012 (3)
  15. Nach Firefox Update keine Rechte mehr
    Alles rund um Windows - 07.06.2012 (2)
  16. Fehlermeldung nach Firefox-Update
    Alles rund um Windows - 10.09.2008 (7)
  17. trojan-clicker.JS.agent.d nach Firefox-Update?
    Plagegeister aller Art und deren Bekämpfung - 04.02.2006 (3)

Zum Thema nach firefox update / portaldosites in jedem neuen tap - ESET Online Scanner Hier findest du eine bebilderte Anleitung zu ESET Online Scanner Lade und starte Eset Online Scanner Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden - nach firefox update / portaldosites in jedem neuen tap...
Archiv
Du betrachtest: nach firefox update / portaldosites in jedem neuen tap auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.