|
Log-Analyse und Auswertung: Windows 7: angeklickt flash player nicht aktuellWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.06.2014, 12:23 | #16 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuellESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.06.2014, 00:46 | #17 |
| Windows 7: angeklickt flash player nicht aktuell eset
__________________Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=31866a36f010b544a00473f54dea9c55 # engine=18711 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=truae # utc_time=2014-06-13 11:28:30 # local_time=2014-06-14 01:28:30 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7600 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 66 85 12893348 154333301 0 0 # scanned=93089 # found=6 # cleaned=0 # scan_time=1033 sh=1F9E04ABC6E7B940139988D421CDFCB8DC0B2C0E ft=1 fh=393f367b591a7585 vn="Variante von Win32/InstallCore.JW evtl. unerwünschte Anwendung" ac=I fn="C:\Users\eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QYTKW2M\downloadablecdn_com[1].exe" sh=1B0CD89EED75E6CD67143E9EF11DAD324491D242 ft=1 fh=ab6962ff595a4f76 vn="Win32/BrowseFox.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\eva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LTA9MF8W\Setup[1].exe" sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="Win32/InstallCore.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\eva\AppData\Local\Temp\379628.Uninstall\uninstaller.exe" sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="Win32/InstallCore.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\eva\AppData\Local\Temp\525536.Uninstall\uninstaller.exe" sh=A836A8346F791EC8A83B51BC78E84B2F6659E6DA ft=1 fh=0a2e45c370149901 vn="Win32/Wajam.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\eva\AppData\Local\Temp\is1242154493\1184098_stp\wajam_validate.exe" sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="Win32/InstallCore.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\eva\AppData\Local\Temp\is1242154493\1184409_stp\uninstaller.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 x86 (UAC is enabled) Out of date service pack!! ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` McAfee Virus and Spyware Protection Service Adobe Flash Player 10 Flash Player out of Date! Mozilla Firefox (30.0) ````````Process Check: objlist.exe by Laurent```````` McAfee Managed VirusScan DesktopUI XTray.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014 Ran by eva (administrator) on EVA-HP on 14-06-2014 01:42:35 Running from C:\Users\eva\Desktop Platform: Microsoft Windows 7 Home Premium (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\stacsv.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\AEstSrv.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) C:\Program Files\McAfee\MPF\MpfSrv.exe (PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company) HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard) HKLM\...\Run: [Microsoft Default Manager] => C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM\...\Run: [McAfee Managed Services Tray] => C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.Exe [476480 2010-02-17] (McAfee, Inc.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-05] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-17] (IDT, Inc.) HKLM\...\Run: [NortonOnlineBackupReminder] => C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKU\S-1-5-21-2839968430-3032943032-2816752695-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company) HKU\S-1-5-21-2839968430-3032943032-2816752695-1001\...\MountPoints2: {1c3f02cb-556b-11e3-a9c1-806e6f6e6963} - F:\Setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/10 SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100909125144.dll (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - @C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\eva\AppData\Roaming\Mozilla\Firefox\Profiles\vu7osdcp.default FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @Microsoft.com/NpWinExt,version=5.0 - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\Firefox FF Extension: Bing Bar - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-09-09] FF HKLM\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ FF Extension: Search Helper Extension - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [] FF HKLM\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ FF Extension: Default Manager - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-01] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-01] ========================== Services (Whitelisted) ================= R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [121344 2010-07-01] (Hewlett-Packard Company) [File not signed] R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard) R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed] R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [170144 2010-02-04] (McAfee, Inc.) R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [141792 2010-02-08] (McAfee, Inc.) R2 MpfService; C:\Program Files\McAfee\MPF\MPFSrv.exe [893112 2009-05-09] (McAfee, Inc.) R2 Net Driver HPZ12; C:\windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc) R2 Pml Driver HPZ12; C:\windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\STacSV.exe [229458 2010-03-17] (IDT, Inc.) S2 myAgtSvc; "C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe" /ServiceStart [X] ==================== Drivers (Whitelisted) ==================== R3 mfeapfk; C:\windows\System32\drivers\mfeapfk.sys [95728 2010-02-08] (McAfee, Inc.) R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [152736 2010-02-08] (McAfee, Inc.) R3 mfebopk; C:\windows\System32\drivers\mfebopk.sys [51720 2010-02-08] (McAfee, Inc.) R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [385184 2010-02-08] (McAfee, Inc.) S3 mferkdet; C:\windows\System32\drivers\mferkdet.sys [83912 2010-02-08] (McAfee, Inc.) R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [160912 2010-02-08] (McAfee, Inc.) R1 MPFP; C:\windows\System32\Drivers\Mpfp.sys [130424 2009-04-09] (McAfee, Inc.) R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-04-27] () R1 {42e50651-9669-456e-9081-d5a836274274}w; C:\windows\System32\drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys [52920 2014-05-30] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-14 01:42 - 2014-06-14 01:42 - 00012542 _____ () C:\Users\eva\Desktop\FRST.txt 2014-06-14 01:08 - 2014-06-14 01:08 - 02347384 _____ (ESET) C:\Users\eva\Desktop\esetsmartinstaller_deu.exe 2014-06-14 01:08 - 2014-06-14 01:08 - 00854367 _____ () C:\Users\eva\Desktop\SecurityCheck.exe 2014-06-12 17:59 - 2014-06-12 17:59 - 00000000 ____D () C:\windows\ERUNT 2014-06-12 17:58 - 2014-06-12 17:58 - 01016261 _____ (Thisisu) C:\Users\eva\Desktop\JRT.exe 2014-06-12 17:46 - 2014-06-12 17:48 - 00000000 ____D () C:\AdwCleaner 2014-06-12 17:26 - 2014-06-12 17:26 - 01333465 _____ () C:\Users\eva\Desktop\adwcleaner_3.212.exe 2014-06-12 17:25 - 2014-06-12 17:44 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-12 17:25 - 2014-06-12 17:25 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-12 17:25 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-06-12 17:25 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-06-12 17:25 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-06-12 17:08 - 2014-06-12 17:08 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-06-12 17:06 - 2014-06-12 17:06 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Roaming\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Local\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-12 11:57 - 2014-06-14 01:42 - 00000000 ____D () C:\FRST 2014-06-12 11:56 - 2014-06-12 11:56 - 01073152 _____ (Farbar) C:\Users\eva\Desktop\FRST.exe 2014-06-02 09:25 - 2014-05-30 14:25 - 00052920 _____ (StdLib) C:\windows\system32\Drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys ==================== One Month Modified Files and Folders ======= 2014-06-14 01:42 - 2014-06-14 01:42 - 00012542 _____ () C:\Users\eva\Desktop\FRST.txt 2014-06-14 01:42 - 2014-06-12 11:57 - 00000000 ____D () C:\FRST 2014-06-14 01:42 - 2013-11-24 18:05 - 00000000 ____D () C:\Users\eva\AppData\Local\Temp 2014-06-14 01:12 - 2009-07-14 06:34 - 00019536 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-14 01:12 - 2009-07-14 06:34 - 00019536 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-14 01:10 - 2010-09-09 20:53 - 01472002 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-14 01:08 - 2014-06-14 01:08 - 02347384 _____ (ESET) C:\Users\eva\Desktop\esetsmartinstaller_deu.exe 2014-06-14 01:08 - 2014-06-14 01:08 - 00854367 _____ () C:\Users\eva\Desktop\SecurityCheck.exe 2014-06-14 01:08 - 2013-11-24 18:05 - 00185925 _____ () C:\windows\WindowsUpdate.log 2014-06-14 01:04 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-14 01:04 - 2009-07-14 06:39 - 00102210 _____ () C:\windows\setupact.log 2014-06-12 18:19 - 2010-09-09 21:52 - 00006923 _____ () C:\windows\system32\Config.MPF 2014-06-12 17:59 - 2014-06-12 17:59 - 00000000 ____D () C:\windows\ERUNT 2014-06-12 17:58 - 2014-06-12 17:58 - 01016261 _____ (Thisisu) C:\Users\eva\Desktop\JRT.exe 2014-06-12 17:56 - 2010-09-09 21:57 - 00014288 _____ () C:\windows\PFRO.log 2014-06-12 17:48 - 2014-06-12 17:46 - 00000000 ____D () C:\AdwCleaner 2014-06-12 17:44 - 2014-06-12 17:25 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-12 17:26 - 2014-06-12 17:26 - 01333465 _____ () C:\Users\eva\Desktop\adwcleaner_3.212.exe 2014-06-12 17:25 - 2014-06-12 17:25 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-12 17:20 - 2010-09-09 21:50 - 00000000 ____D () C:\ProgramData\McAfee 2014-06-12 17:20 - 2010-09-09 21:50 - 00000000 ____D () C:\Program Files\McAfee 2014-06-12 17:08 - 2014-06-12 17:08 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-06-12 17:06 - 2014-06-12 17:06 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Roaming\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Local\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-12 17:06 - 2009-07-14 04:04 - 00000540 _____ () C:\windows\win.ini 2014-06-12 11:56 - 2014-06-12 11:56 - 01073152 _____ (Farbar) C:\Users\eva\Desktop\FRST.exe 2014-06-11 21:08 - 2010-09-09 21:09 - 00000000 ____D () C:\ProgramData\PDFC 2014-05-30 14:25 - 2014-06-02 09:25 - 00052920 _____ (StdLib) C:\windows\system32\Drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys Some content of TEMP: ==================== C:\Users\eva\AppData\Local\Temp\CpqMC.dll C:\Users\eva\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\eva\AppData\Local\Temp\HPQSi.exe C:\Users\eva\AppData\Local\Temp\lowproc.exe C:\Users\eva\AppData\Local\Temp\Quarantine.exe C:\Users\eva\AppData\Local\Temp\stubhelper.dll ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-03-13 22:23 ==================== End Of Log ============================ |
14.06.2014, 18:16 | #18 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell Flash Player updaten. WIndows updaten, da fehlt ein Servicepack.
__________________Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
14.06.2014, 22:20 | #19 |
| Windows 7: angeklickt flash player nicht aktuell alles klar nochmal vielen dank für die hilfe war jetzt eigentlich was drauf was die Account daten abgreifen konnte? |
15.06.2014, 06:31 | #20 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell Nö, aber Passwörter ändern ist bei Befall Standard
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: angeklickt flash player nicht aktuell |
4d36e972-e325-11ce-bfc1-08002be10318, antivirus, association, branding, homepage, msil/domaiq.a, pup.optional.bundleinstaller.a, pup.optional.findright.a, pup.optional.installcore.a, realtek, software, super, svchost.exe, teredo, tr/trash.gen, vcredist, werbung, win32/anyprotect.d, win32/browsefox.e, win32/domaiq.bb, win32/domaiq.bh, win32/installcore.az, win32/installcore.jw, win32/softpulse.b, win32/tivmonk.b, win32/vopackage.h, win32/wajam.f, windowsprotectmanger |