|
Log-Analyse und Auswertung: Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete TapsWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.10.2014, 10:04 | #16 |
/// the machine /// TB-Ausbilder | Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete Taps Verknüpfung löschen, frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.10.2014, 09:52 | #17 |
| Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete Taps Moin,
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-10-2014 02 Ran by Arne (administrator) on ARNE-PC on 13-10-2014 10:50:55 Running from C:\Users\Arne\Desktop Loaded Profiles: Arne & UpdatusUser (Available profiles: Arne & UpdatusUser) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-06] (AVAST Software) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-856369245-1405169768-1277596959-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2A55E714350ACF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://de.yahoo.com?fr=hp-avast&type=avastbcl SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.0.43.193 217.0.43.1 FireFox: ======== FF ProfilePath: C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\df3df6ur.default-1412603674226 FF NewTab: hxxp://www.google.com FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-09-24] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-06] Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M8D78C416-8019-401D-A1B0-3CC4DAE287A7&SearchSource=55&CUI=&UM=6&UP=SP180D9BB4-14B5-495E-ABE7-82C44A8FF09D&SSPV= CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M8D78C416-8019-401D-A1B0-3CC4DAE287A7&SearchSource=55&CUI=&UM=6&UP=SP180D9BB4-14B5-495E-ABE7-82C44A8FF09D&SSPV=" CHR DefaultSearchKeyword: Default -> trovi.search CHR DefaultSearchProvider: Default -> Trovi search CHR DefaultNewTabURL: Default -> https://www.trovi.com/?gd=&ctid=CT3321486&octid=EB_ORIGINAL_CTID&ISID=M078E6E70-A7BB-4DEE-BCBE-95DF6726CCF2&SearchSource=69&CUI=&SSPV=&lay=5&p=cnts&UM=6&UP=SP4546EDA4-BEC5-429B-A964-4D9EB978AC16&SAT=CNTS CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-04] CHR Extension: (Google Drive) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-04] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-16] CHR Extension: (YouTube) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-04] CHR Extension: (Google-Suche) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-04] CHR Extension: (avast! Online Security) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-06-05] CHR Extension: (Skype Click to Call) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-16] CHR Extension: (Google Wallet) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-04] CHR Extension: (Google Mail) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-04] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-06] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-06] (AVAST Software) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2014-09-30] (Elex do Brasil Participações Ltda) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-06] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-06] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-06] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-06] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-06] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-06] () R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [248488 2014-09-30] (Elex do Brasil Participações Ltda) R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [99496 2014-09-30] (Elex do Brasil Participações Ltda) R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [65704 2014-09-30] (Elex do Brasil Participações Ltda) R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [49320 2014-09-22] (Elex do Brasil Participações Ltda) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 10:50 - 2014-10-13 10:50 - 00000000 ____D () C:\Users\Arne\Desktop\FRST-OlderVersion 2014-10-10 13:21 - 2014-10-10 13:21 - 00854417 _____ () C:\Users\Arne\Desktop\SecurityCheck.exe 2014-10-10 13:15 - 2014-10-10 13:15 - 00003725 _____ () C:\Users\Arne\Desktop\eset.txt 2014-10-10 11:16 - 2014-10-10 11:17 - 02347384 _____ (ESET) C:\Users\Arne\Desktop\esetsmartinstaller_deu.exe 2014-10-09 16:15 - 2014-10-09 16:15 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\eCyber 2014-10-09 12:11 - 2014-10-09 12:11 - 00027871 _____ () C:\Users\Arne\Desktop\FRST2.txt 2014-10-09 12:08 - 2014-10-09 12:08 - 00000846 _____ () C:\Users\Arne\Desktop\JRT.txt 2014-10-09 12:00 - 2014-10-09 12:00 - 00000000 ____D () C:\Windows\ERUNT 2014-10-09 11:58 - 2014-10-09 11:58 - 01705755 _____ (Thisisu) C:\Users\Arne\Downloads\JRT.exe 2014-10-09 11:56 - 2014-10-09 11:56 - 00016631 _____ () C:\Users\Arne\Desktop\AdwCleaner[S0].txt 2014-10-09 11:52 - 2014-10-09 11:52 - 01375089 _____ () C:\Users\Arne\Downloads\AdwCleaner_3.311.exe 2014-10-09 11:51 - 2014-10-09 11:51 - 00007930 _____ () C:\Users\Arne\Desktop\mbam.txt 2014-10-09 11:44 - 2014-10-09 11:45 - 00000298 _____ () C:\Windows\Tasks\Tempo Runner zoomifyL32.job 2014-10-09 11:44 - 2014-10-09 11:44 - 00002736 _____ () C:\Windows\System32\Tasks\Tempo Runner zoomifyL32 2014-10-09 11:44 - 2014-10-09 11:44 - 00000298 _____ () C:\Windows\Tasks\Tempo Runner zoomifyL64.job 2014-10-09 11:44 - 2014-10-09 11:44 - 00000298 _____ () C:\Windows\Tasks\Tempo Runner zoomifyD32.job 2014-10-09 11:28 - 2014-10-09 11:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-09 11:28 - 2014-10-09 11:28 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-09 11:28 - 2014-10-09 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-09 11:28 - 2014-10-09 11:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-09 11:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-09 11:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-09 11:28 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-09 11:25 - 2014-10-09 11:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Arne\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-10-08 13:40 - 2014-10-08 13:40 - 00018664 _____ () C:\Users\Arne\Desktop\ComboFix.txt 2014-10-08 13:38 - 2014-10-08 13:38 - 00018664 _____ () C:\ComboFix.txt 2014-10-08 13:22 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-08 13:22 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-08 13:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-08 13:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-08 13:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-08 13:22 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-08 13:22 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-08 13:22 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-08 13:18 - 2014-10-08 13:39 - 00000000 ____D () C:\Qoobox 2014-10-08 13:18 - 2014-10-08 13:34 - 00000000 ____D () C:\Windows\erdnt 2014-10-08 13:13 - 2014-10-08 13:14 - 05582481 ____R (Swearware) C:\Users\Arne\Desktop\ComboFix.exe 2014-10-08 12:27 - 2014-10-08 12:27 - 00002268 _____ () C:\Windows\System32\Tasks\Tempo Runner wzoomifyd 2014-10-08 12:27 - 2014-10-08 12:27 - 00000196 _____ () C:\Windows\Tasks\Tempo Runner wzoomifyd.job 2014-10-07 12:12 - 2014-10-07 12:12 - 00314227 _____ () C:\Users\Arne\Desktop\Gmer.txt 2014-10-07 12:03 - 2014-10-07 12:03 - 00380416 _____ () C:\Users\Arne\Desktop\Gmer-19357.exe 2014-10-07 12:01 - 2014-10-07 12:01 - 00000470 _____ () C:\Users\Arne\Desktop\defogger_disable.log 2014-10-07 11:54 - 2014-10-07 11:56 - 00021543 _____ () C:\Users\Arne\Desktop\Addition.txt 2014-10-07 11:53 - 2014-10-13 10:50 - 00014522 _____ () C:\Users\Arne\Desktop\FRST.txt 2014-10-07 11:53 - 2014-10-13 10:50 - 00000000 ____D () C:\FRST 2014-10-07 11:51 - 2014-10-13 10:50 - 02110464 _____ (Farbar) C:\Users\Arne\Desktop\FRST64.exe 2014-10-07 11:49 - 2014-10-07 11:49 - 00000470 _____ () C:\Windows\SysWOW64\defogger_disable.log 2014-10-07 11:49 - 2014-10-07 11:49 - 00000000 _____ () C:\Users\Arne\defogger_reenable 2014-10-07 11:46 - 2014-10-07 11:46 - 00050477 _____ () C:\Users\Arne\Desktop\Defogger.exe 2014-10-07 02:03 - 2014-10-07 02:03 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-10-07 02:03 - 2014-10-07 02:03 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-10-07 02:03 - 2014-10-07 02:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-07 02:00 - 2014-10-07 02:00 - 00244408 _____ () C:\Users\Arne\Downloads\Firefox Setup Stub 32.0.3 (1).exe 2014-10-06 23:09 - 2014-10-09 11:55 - 00000000 ____D () C:\AdwCleaner 2014-10-06 22:14 - 2014-10-06 22:17 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft 2014-10-06 22:14 - 2014-10-06 22:14 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Abelssoft 2014-10-06 22:14 - 2014-10-06 22:14 - 00000000 ____D () C:\Users\Arne\AppData\Local\Abelssoft 2014-10-06 22:14 - 2014-10-06 22:14 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-10-06 22:12 - 2014-10-06 22:13 - 01589182 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-10-06 22:04 - 2014-10-06 22:04 - 00001452 _____ () C:\Users\Arne\Desktop\Goodgame Empire.lnk 2014-10-06 22:04 - 2014-10-06 22:04 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\DesktopIconGoodgame 2014-10-06 22:04 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll 2014-10-06 22:04 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll 2014-10-06 22:03 - 2014-10-06 22:03 - 01101648 _____ () C:\Users\Arne\Downloads\HijackThis - CHIP-Installer.exe 2014-10-06 21:01 - 2014-10-13 10:34 - 00003080 _____ () C:\Windows\setupact.log 2014-10-06 21:01 - 2014-10-06 21:01 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-06 21:00 - 2014-10-11 12:56 - 00018178 _____ () C:\Windows\PFRO.log 2014-10-06 19:41 - 2014-10-07 01:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC 2014-10-06 19:41 - 2014-10-06 19:41 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Elex-tech 2014-10-06 19:41 - 2014-10-06 19:41 - 00000000 ____D () C:\Program Files (x86)\Elex-tech 2014-10-06 19:41 - 2014-09-22 14:13 - 00049320 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys 2014-10-06 16:09 - 2014-10-06 16:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-06 16:07 - 2014-10-06 16:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Arne\Downloads\mbam-setup-2.0.2.1012.exe 2014-10-06 15:49 - 2014-10-09 11:55 - 00000000 ____D () C:\Windows\system32\log 2014-10-06 15:18 - 2014-10-06 15:18 - 00000000 _____ () C:\autoexec.bat 2014-10-06 15:16 - 2014-10-06 15:16 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-10-06 15:15 - 2014-10-06 15:58 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-10-06 15:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-10-06 14:43 - 2014-10-06 15:54 - 00000000 ____D () C:\Users\Arne\Desktop\Alte Firefox-Daten 2014-10-06 11:55 - 2014-10-06 11:55 - 00000099 _____ () C:\Windows\Reimage.ini 2014-10-06 11:42 - 2014-10-06 11:42 - 00244408 _____ () C:\Users\Arne\Downloads\Firefox Setup Stub 32.0.3.exe 2014-10-06 00:46 - 2014-10-13 10:34 - 00001334 _____ () C:\Windows\Tasks\NMBDOU.job 2014-10-06 00:46 - 2014-10-13 10:34 - 00001332 _____ () C:\Windows\Tasks\KZXMT.job 2014-10-06 00:46 - 2014-10-06 00:46 - 00004356 _____ () C:\Windows\System32\Tasks\NMBDOU 2014-10-06 00:46 - 2014-10-06 00:46 - 00004354 _____ () C:\Windows\System32\Tasks\KZXMT 2014-10-06 00:40 - 2014-10-06 00:40 - 00256848 _____ () C:\Users\Arne\Downloads\TinyPlayerInstaller.exe 2014-09-27 21:39 - 2014-09-27 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-09-27 21:39 - 2014-09-27 21:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-09-24 22:33 - 2014-10-07 02:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-16 11:23 - 2014-09-16 11:24 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-09-16 11:23 - 2014-09-16 11:23 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-09-16 11:23 - 2014-09-16 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-09-16 11:20 - 2014-09-16 11:20 - 01678440 _____ (Skype Technologies S.A.) C:\Users\Arne\Downloads\SkypeSetup(2).exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 10:49 - 2014-06-05 00:31 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-13 10:42 - 2009-07-14 06:45 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-13 10:42 - 2009-07-14 06:45 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-13 10:40 - 2014-01-06 17:27 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-10-13 10:34 - 2014-06-05 00:31 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-13 10:34 - 2014-01-05 19:54 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-10-13 10:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-13 01:59 - 2014-01-05 01:14 - 01633407 _____ () C:\Windows\WindowsUpdate.log 2014-10-13 01:26 - 2014-01-07 20:39 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-10 11:28 - 2009-07-14 19:58 - 00696370 _____ () C:\Windows\system32\perfh007.dat 2014-10-10 11:28 - 2009-07-14 19:58 - 00147634 _____ () C:\Windows\system32\perfc007.dat 2014-10-10 11:28 - 2009-07-14 07:13 - 01611160 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-09 11:16 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-08 13:33 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-10-07 11:49 - 2014-01-05 01:18 - 00000000 ____D () C:\Users\Arne 2014-10-07 01:24 - 2014-01-06 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-10-07 01:24 - 2014-01-06 19:38 - 00000000 ____D () C:\Program Files\CCleaner 2014-10-07 01:24 - 2014-01-06 17:58 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\FreeCommander 2014-10-07 01:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-10-06 22:42 - 2009-07-14 06:45 - 00417872 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-06 22:17 - 2014-01-05 18:38 - 00111336 _____ () C:\Users\Arne\AppData\Local\GDIPFONTCACHEV1.DAT 2014-10-06 21:00 - 2014-06-05 00:32 - 00000000 ____D () C:\Program Files\Google 2014-10-06 21:00 - 2014-02-04 20:01 - 00000000 ____D () C:\Program Files (x86)\Google 2014-10-06 20:57 - 2014-01-05 01:10 - 00000000 ____D () C:\Windows\Panther 2014-10-06 19:45 - 2014-02-04 20:01 - 00000000 ____D () C:\Users\Arne\AppData\Local\Google 2014-10-06 16:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-10-06 15:49 - 2014-06-05 00:33 - 00002233 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-10-06 14:05 - 2014-01-06 18:42 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-10-06 11:30 - 2014-01-05 18:28 - 00000000 ____D () C:\Windows\Minidump 2014-09-28 19:50 - 2014-04-14 10:29 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Skype 2014-09-27 22:10 - 2014-04-14 10:58 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-09-24 15:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-09-24 11:26 - 2014-01-07 20:39 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-24 11:26 - 2014-01-07 20:39 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-24 11:26 - 2014-01-07 20:39 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-19 17:20 - 2014-01-06 19:16 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-09-16 11:23 - 2014-04-14 10:29 - 00000000 ____D () C:\ProgramData\Skype 2014-09-15 09:06 - 2014-01-05 18:56 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-27 13:03 ==================== End Of Log ============================ |
13.10.2014, 16:43 | #18 |
/// the machine /// TB-Ausbilder | Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete Taps Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
13.10.2014, 18:45 | #19 |
| Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete Taps Was hat das nun zu bedeuten? Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-10-2014 02 Ran by Arne at 2014-10-13 19:44:45 Run:2 Running from C:\Users\Arne\Desktop Loaded Profiles: Arne & UpdatusUser (Available profiles: Arne & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] ***************** esgiguard => Service deleted successfully. iSafeKrnlBoot => Error deleting Service ==== End of Fixlog ==== |
14.10.2014, 12:43 | #20 |
/// the machine /// TB-Ausbilder | Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete Taps Poste mal ein frisches FRST log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |