|
Plagegeister aller Art und deren Bekämpfung: Delta-homes hijackWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.12.2014, 12:00 | #1 |
| Delta-homes hijack Guten morgen, ich habe gestern meinen Flash player aktualisiert... heute morgen beim Starten des PC wurde ich auf die domain delta-homes.com umgeleitet, die auch als Startseite ebi jedem neuen Tab aufploppt... kann mir da bitte jemand helfen? Vielen Dank im voraus und anbei der FRST Scan und add. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-12-2014 03 Ran by Marc (administrator) on MARC-PC on 12-12-2014 11:53:50 Running from C:\Users\Marc\Downloads Loaded Profile: Marc (Available profiles: Marc) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaRegistry64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\WinZipper\winzipersvc.exe () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.) HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\...\Run: [AdobeBridge] => [X] AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hama Wireless LAN Utility.lnk ShortcutTarget: Hama Wireless LAN Utility.lnk -> C:\Program Files (x86)\Hama\Common\RaUI.exe (Ralink Technology, Corp.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?type=sc&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 SearchScopes: HKU\S-1-5-21-3978302629-4045270245-2468114167-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} SearchScopes: HKU\S-1-5-21-3978302629-4045270245-2468114167-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-3978302629-4045270245-2468114167-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default FF NewTab: hxxp://www.delta-homes.com/newtab/?type=nt&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 FF SelectedSearchEngine: delta-homes FF Homepage: hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\delta-homes.xml FF Extension: Security Protection - C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\Extensions\detgdp@gmail.com [2014-12-12] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\extensions\detgdp@gmail.com FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.delta-homes.com/?type=sc&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [Not Found] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.) [File not signed] R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2013-09-17] () S2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2013-09-17] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [1632256 2013-08-05] (ASUSTeK Computer Inc.) [File not signed] S3 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 RalinkRegistryWriter; C:\Program Files (x86)\Hama\Common\RaRegistry.exe [193888 2010-06-01] (Ralink Technology, Corp.) R2 RalinkRegistryWriter64; C:\Program Files (x86)\Hama\Common\RaRegistry64.exe [211296 2010-06-01] (Ralink Technology, Corp.) R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [485888 2014-12-10] (Fuyu LIMITED) [File not signed] R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [425136 2014-11-26] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] () S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-09] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-09] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-09] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-09] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-09] (Kaspersky Lab ZAO) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-12 11:53 - 2014-12-12 11:54 - 00017692 _____ () C:\Users\Marc\Downloads\FRST.txt 2014-12-12 11:53 - 2014-12-12 11:53 - 02119680 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe 2014-12-12 11:53 - 2014-12-12 11:53 - 00000000 ____D () C:\FRST 2014-12-12 10:34 - 2014-12-12 10:34 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\WinZipper 2014-12-12 10:34 - 2014-12-12 10:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper 2014-12-12 10:34 - 2014-12-12 10:34 - 00000000 ____D () C:\Program Files (x86)\WinZipper 2014-12-10 16:24 - 2014-12-10 16:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-12-10 16:14 - 2014-12-10 16:14 - 03981488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-12-05 13:40 - 2014-12-05 13:40 - 06126536 _____ (Tim Kosse) C:\Users\Marc\Downloads\FileZilla_3.9.0.6_win32-setup.exe 2014-12-01 16:32 - 2014-12-01 16:32 - 14532901 _____ () C:\Users\Marc\Downloads\A&D Weihnachtshäuschen.zip 2014-11-20 12:50 - 2014-11-20 12:50 - 00000022 _____ () C:\Users\Marc\Downloads\Presse.zip 2014-11-14 16:57 - 2014-11-14 16:57 - 00002105 _____ () C:\Users\Public\Desktop\Perfect Effects Free 9.lnk 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\onOne Software 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\ProgramData\Nalpeiron 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onOne Software 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\Program Files\onOne Software 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\Program Files (x86)\onOne Software 2014-11-14 16:56 - 2014-11-14 16:57 - 00000000 ____D () C:\ProgramData\onOne Software 2014-11-14 16:48 - 2014-11-14 16:48 - 01125200 _____ () C:\Users\Marc\Downloads\Perfect Effects Free - CHIP-Installer.exe 2014-11-13 13:54 - 2014-11-13 13:54 - 00001124 _____ () C:\Users\Marc\Documents\WIRTSCHAFTSDATEN - Verknüpfung.lnk 2014-11-12 18:12 - 2014-11-12 20:05 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\dvdcss ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-12 11:49 - 2014-06-08 15:19 - 01930390 _____ () C:\Windows\WindowsUpdate.log 2014-12-12 11:14 - 2014-07-14 16:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-12 10:39 - 2009-07-14 05:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-12 10:39 - 2009-07-14 05:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-12 10:38 - 2011-04-12 08:43 - 00713634 _____ () C:\Windows\system32\perfh007.dat 2014-12-12 10:38 - 2011-04-12 08:43 - 00153750 _____ () C:\Windows\system32\perfc007.dat 2014-12-12 10:38 - 2009-07-14 06:13 - 01647328 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-12 10:34 - 2014-07-03 15:29 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect 2014-12-12 10:34 - 2014-06-09 12:24 - 00001383 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-12 10:34 - 2014-06-09 12:24 - 00001371 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-12 10:34 - 2014-06-09 02:04 - 00003748 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-12-12 10:34 - 2014-06-08 15:17 - 00001657 _____ () C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-12 10:33 - 2009-07-14 05:45 - 04677672 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-12 10:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-12 10:32 - 2009-07-14 05:51 - 00042805 _____ () C:\Windows\setupact.log 2014-12-11 10:54 - 2014-08-23 09:01 - 00000000 ____D () C:\Users\Marc\AppData\Local\Adobe 2014-12-11 10:53 - 2014-07-14 16:22 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-11 10:53 - 2014-07-14 16:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-11 10:53 - 2014-07-14 16:22 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-12-11 10:49 - 2014-06-09 12:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-12-10 16:00 - 2014-07-03 10:06 - 00000000 ____D () C:\KEYSALE 2014-12-08 15:33 - 2014-07-03 15:08 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\FileZilla 2014-12-08 09:15 - 2014-08-04 15:04 - 00000000 ____D () C:\Users\Marc\Desktop\KORREKTUREN 2014-12-05 16:41 - 2014-06-09 01:28 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\Adobe 2014-11-27 09:39 - 2014-06-08 15:17 - 00000000 ____D () C:\Users\Marc 2014-11-26 04:42 - 2011-02-20 05:03 - 00421040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll 2014-11-26 04:42 - 2011-02-19 06:40 - 00773808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll 2014-11-15 13:04 - 2014-07-03 15:53 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\vlc 2014-11-14 16:57 - 2014-06-09 01:08 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-11-12 18:11 - 2014-07-03 15:50 - 00000871 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-11-12 11:54 - 2014-07-03 15:05 - 00000000 ____D () C:\Users\Marc\Documents\Smart Investor ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-05 18:20 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-12-2014 03 Ran by Marc at 2014-12-12 11:54:16 Running from C:\Users\Marc\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.) Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe Creative Suite 4 Master Collection (HKLM-x32\...\Adobe_460067e24608d484cb4a1c5166f545a) (Version: 4.0 - Adobe Systems Incorporated) Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated) Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden Adobe InDesign CS4 Icon Handler x64 (Version: 6.0 - Adobe Systems Incorporated) Hidden Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden FileZilla Client 3.9.0.5 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse) Free WMA to MP3 Converter 1.16 (HKLM-x32\...\Free WMA to MP3 Converter_is1) (Version: - Jodix Technologies Ltd.) Free YouTube Download version 3.2.46.923 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.46.923 - DVDVideoSoft Ltd.) Hama Wireless LAN Adapter (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 10.6.0 - Hama) Hsp-Verwaltung 2.0 (HKLM-x32\...\{D0CF92F2-5F1A-4D60-BF58-16F515C57CEE}) (Version: 1.0.0.0 - ) Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 34.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla) Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) MySQL Connector/ODBC 3.51 (HKLM-x32\...\{C0D3D93F-C200-4F45-A7B0-4B7753E18590}) (Version: 3.51.28 - Oracle Corporation) PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden Perfect Effects Free 9 (HKLM-x32\...\Perfect Effects Free 9) (Version: 9.0.0 - onOne Software) Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden TP-LINK Wireless Client Utility (HKLM-x32\...\{7A2A107B-9695-423F-9462-8F17C178BD35}) (Version: 7.0 - TP-LINK) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) WindowsMangerProtect20.0.0.502 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.502 - WindowsProtect LIMITED) <==== ATTENTION WinZipper (HKLM-x32\...\WinZipper) (Version: 1.5.66 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 14-11-2014 15:56:52 Installiert Perfect Effects Free 9 26-11-2014 22:43:21 Geplanter Prüfpunkt 04-12-2014 12:12:11 Geplanter Prüfpunkt 11-12-2014 12:18:32 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-09-26 15:50 - 00002177 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 hxxp://www.adobeereg.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 192.150.18.108 127.0.0.1 activate.adobe.com:443 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 www.adobeereg.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 192.150.18.108 127.0.0.1 adobeereg.com 127.0.0.1 www.adobeereg.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 192.150.18.108 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com There are 7 more lines. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {990F458F-A495-46C2-996D-37A461B85CB1} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {AB6BB5EB-75C3-456B-9BD7-A181FC2228B7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-11] (Adobe Systems Incorporated) Task: {BB6F1ED9-3AD1-4108-B24E-570FB2708FC7} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-06-09] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-05-01 20:29 - 2014-05-01 20:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2014-04-17 21:29 - 2014-04-17 21:29 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2014-02-11 06:08 - 2014-02-11 06:08 - 00817152 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2014-02-11 06:08 - 2014-02-11 06:08 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2014-04-17 21:29 - 2014-04-17 21:29 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2014-04-17 21:29 - 2014-04-17 21:29 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-06-09 01:11 - 2013-09-17 17:58 - 00920736 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe 2014-12-12 10:34 - 2014-11-26 04:42 - 00612528 _____ () C:\Program Files (x86)\WinZipper\sqlite3.dll 2014-06-09 01:11 - 2014-12-12 10:34 - 00033792 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.19\PEbiosinterface32.dll 2014-06-09 01:11 - 2010-06-29 09:58 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.19\ATKEX.dll 2014-12-10 16:24 - 2014-12-10 16:24 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-3978302629-4045270245-2468114167-500 - Administrator - Disabled) Gast (S-1-5-21-3978302629-4045270245-2468114167-501 - Limited - Disabled) Marc (S-1-5-21-3978302629-4045270245-2468114167-1000 - Administrator - Enabled) => C:\Users\Marc ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/12/2014 10:55:18 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (12/12/2014 10:34:26 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/12/2014 10:34:09 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 34.0.5.5443, Zeitstempel: 0x5475dd5d Name des fehlerhaften Moduls: mozalloc.dll, Version: 34.0.5.5443, Zeitstempel: 0x5475d664 Ausnahmecode: 0x80000003 Fehleroffset: 0x00001425 ID des fehlerhaften Prozesses: 0xd50 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (12/11/2014 00:27:48 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (12/11/2014 10:51:31 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/10/2014 04:52:28 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (12/10/2014 03:08:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/10/2014 01:53:01 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/08/2014 09:05:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/08/2014 10:25:05 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. System errors: ============= Error: (12/12/2014 11:51:05 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "ASUS HM Com Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (12/12/2014 10:32:48 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Error: (12/11/2014 11:22:41 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (12/11/2014 11:22:41 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (12/11/2014 11:22:40 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (12/11/2014 11:22:40 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (12/11/2014 10:49:54 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Error: (12/10/2014 03:10:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Error: (12/10/2014 01:51:24 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Error: (12/08/2014 09:03:43 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\athExt.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (12/12/2014 10:55:18 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (12/12/2014 10:34:26 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/12/2014 10:34:09 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.5.54435475dd5dmozalloc.dll34.0.5.54435475d6648000000300001425d5001d015eec3688539C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll058bd36a-81e2-11e4-9e9e-40167e25abfa Error: (12/11/2014 00:27:48 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (12/11/2014 10:51:31 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/10/2014 04:52:28 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (12/10/2014 03:08:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/10/2014 01:53:01 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/08/2014 09:05:18 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/08/2014 10:25:05 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 CodeIntegrity Errors: =================================== Date: 2014-12-12 10:55:25.307 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-12 10:55:25.305 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-12 10:55:25.302 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-12 10:55:25.292 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-12 10:55:25.290 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-12 10:55:25.287 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-11 12:27:54.690 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-11 12:27:54.690 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-11 12:27:54.690 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-12-11 12:27:54.680 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: AMD FX(tm)-6300 Six-Core Processor Percentage of memory in use: 28% Total physical RAM: 3996.06 MB Available physical RAM: 2850.64 MB Total Pagefile: 7990.3 MB Available Pagefile: 6429.37 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:866.62 GB) NTFS Drive e: () (Fixed) (Total:143.56 GB) (Free:114.4 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B9CADC24) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 149.1 GB) (Disk ID: B8FDB8FD) Partition 1: (Active) - (Size=143.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=5.5 GB) - (Type=1C) ==================== End Of Log ============================ whismerhill |
12.12.2014, 12:05 | #2 |
/// the machine /// TB-Ausbilder | Delta-homes hijack hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ |
12.12.2014, 13:10 | #3 |
| Delta-homes hijack Hi Schrauber,
__________________vielen Dank, dass Du mir hilfst. COMBO Code:
ATTFilter ComboFix 14-12-10.03 - Marc 12.12.2014 12:47:21.1.6 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3996.2735 [GMT 1:00] ausgeführt von:: c:\users\Marc\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Marc\AppData\Local\Temp\_@B4FF.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-11-12 bis 2014-12-12 )))))))))))))))))))))))))))))) . . 2014-12-12 11:50 . 2014-12-12 11:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-12-12 11:40 . 2014-12-12 11:40 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-12-12 10:53 . 2014-12-12 10:54 -------- d-----w- C:\FRST 2014-12-12 09:34 . 2014-12-12 09:34 -------- d-----w- c:\users\Marc\AppData\Roaming\WinZipper 2014-12-10 15:14 . 2014-12-10 15:14 3981488 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2014-11-18 16:38 . 2014-12-05 11:07 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2014-11-18 16:38 . 2014-12-05 11:07 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2014-11-14 15:57 . 2014-11-14 15:57 -------- d-----w- c:\programdata\Nalpeiron 2014-11-14 15:57 . 2014-11-14 15:57 -------- d-----w- c:\users\Marc\AppData\Roaming\onOne Software 2014-11-14 15:57 . 2014-11-14 15:57 -------- d-----w- c:\program files\onOne Software 2014-11-14 15:57 . 2014-11-14 15:57 -------- d-----w- c:\program files (x86)\onOne Software 2014-11-14 15:56 . 2014-11-14 15:57 -------- d-----w- c:\programdata\onOne Software 2014-11-12 17:12 . 2014-11-12 19:05 -------- d-----w- c:\users\Marc\AppData\Roaming\dvdcss . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-12-11 09:53 . 2014-07-14 15:22 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-12-11 09:53 . 2014-07-14 15:22 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-12-04 10:54 . 2014-11-03 13:52 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2014-12-04 10:54 . 2014-11-03 13:51 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2014-11-26 03:42 . 2011-02-19 05:40 773808 ----a-w- c:\windows\SysWow64\msvcr100.dll 2014-11-26 03:42 . 2011-02-20 04:03 421040 ----a-w- c:\windows\SysWow64\msvcp100.dll 2014-11-18 16:38 . 2014-11-03 13:51 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2014-11-05 09:22 . 2014-11-05 09:22 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2014-11-04 13:30 . 2010-11-21 03:27 275080 ------w- c:\windows\system32\MpSigStub.exe 2014-10-20 01:37 . 2014-11-10 12:39 11627712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F4245B6A-E489-4C13-8BF4-E7DBAFA556AC}\mpengine.dll 2014-10-07 02:54 . 2014-11-10 12:30 378552 ----a-w- c:\windows\system32\iedkcs32.dll 2014-10-03 09:02 . 2014-11-10 12:32 103265616 ----a-w- c:\windows\system32\MRT.exe 2014-09-29 12:20 . 2014-10-02 15:41 81792 ----a-w- c:\windows\SysWow64\mslvddsfilter2.ax 2014-09-29 00:58 . 2014-11-10 12:28 3198976 ----a-w- c:\windows\system32\win32k.sys 2014-09-25 22:50 . 2014-11-10 12:30 13619200 ----a-w- c:\windows\system32\ieframe.dll 2014-09-25 22:32 . 2014-11-10 12:30 2017280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-09-25 22:31 . 2014-11-10 12:30 2108416 ----a-w- c:\windows\system32\inetcpl.cpl 2014-09-19 02:25 . 2014-11-10 12:30 23631360 ----a-w- c:\windows\system32\mshtml.dll 2014-09-19 01:56 . 2014-11-10 12:30 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-09-19 01:55 . 2014-11-10 12:30 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-09-19 01:41 . 2014-11-10 12:30 2796032 ----a-w- c:\windows\system32\iertutil.dll 2014-09-19 01:40 . 2014-11-10 12:30 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-09-19 01:40 . 2014-11-10 12:30 547328 ----a-w- c:\windows\system32\vbscript.dll 2014-09-19 01:39 . 2014-11-10 12:30 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-09-19 01:38 . 2014-11-10 12:30 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-09-19 01:36 . 2014-11-10 12:30 5829632 ----a-w- c:\windows\system32\jscript9.dll 2014-09-19 01:31 . 2014-11-10 12:30 51200 ----a-w- c:\windows\system32\jsproxy.dll 2014-09-19 01:30 . 2014-11-10 12:30 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-09-19 01:27 . 2014-11-10 12:30 595968 ----a-w- c:\windows\system32\ieui.dll 2014-09-19 01:26 . 2014-11-10 12:30 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-09-19 01:25 . 2014-11-10 12:30 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-09-19 01:25 . 2014-11-10 12:30 4201472 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-09-19 01:25 . 2014-11-10 12:30 758272 ----a-w- c:\windows\system32\jscript9diag.dll 2014-09-19 01:18 . 2014-11-10 12:30 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-09-19 01:14 . 2014-11-10 12:30 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-09-19 01:14 . 2014-11-10 12:30 446464 ----a-w- c:\windows\system32\dxtmsft.dll 2014-09-19 01:06 . 2014-11-10 12:30 72704 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-09-19 01:02 . 2014-11-10 12:30 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-09-19 01:01 . 2014-11-10 12:30 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-09-19 01:01 . 2014-11-10 12:30 195584 ----a-w- c:\windows\system32\msrating.dll 2014-09-19 01:01 . 2014-11-10 12:30 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-09-19 01:00 . 2014-11-10 12:30 85504 ----a-w- c:\windows\system32\mshtmled.dll 2014-09-19 00:59 . 2014-11-10 12:30 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-09-19 00:58 . 2014-11-10 12:30 289280 ----a-w- c:\windows\system32\dxtrans.dll 2014-09-19 00:50 . 2014-11-10 12:30 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-09-19 00:49 . 2014-11-10 12:30 597504 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-09-19 00:42 . 2014-11-10 12:30 731136 ----a-w- c:\windows\system32\msfeeds.dll 2014-09-19 00:42 . 2014-11-10 12:30 710656 ----a-w- c:\windows\system32\ie4uinit.exe 2014-09-19 00:40 . 2014-11-10 12:30 1249280 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-09-19 00:36 . 2014-11-10 12:30 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-09-19 00:33 . 2014-11-10 12:30 2309632 ----a-w- c:\windows\system32\wininet.dll 2014-09-19 00:18 . 2014-11-10 12:30 1068032 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-09-19 00:14 . 2014-11-10 12:30 1447936 ----a-w- c:\windows\system32\urlmon.dll 2014-09-18 23:59 . 2014-11-10 12:30 775168 ----a-w- c:\windows\system32\ieapfltr.dll 2014-09-18 23:59 . 2014-11-10 12:30 1810944 ----a-w- c:\windows\SysWow64\wininet.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-04-17 767200] "AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Hama Wireless LAN Utility.lnk - c:\program files (x86)\Hama\Common\RaUI.exe -s [2014-7-2 6479712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AiChargerPlus;AiChargerPlus;SysWow64\drivers\AiChargerPlus.sys;SysWow64\drivers\AiChargerPlus.sys [x] R3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AODDriver4.3;AODDriver4.3;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [x] S2 AsusFanControlService;AsusFanControlService;c:\program files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe;c:\program files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [x] S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\Hama\Common\RaRegistry64.exe;c:\program files (x86)\Hama\Common\RaRegistry64.exe [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-12-12 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-14 09:53] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-08-19 7202520] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 uDefault_Search_URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} mDefault_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} mDefault_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 mStart Page = hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms} IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Zu Anti-Banner hinzufügen - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\ FF - prefs.js: browser.search.selectedEngine - delta-homes FF - prefs.js: browser.startup.homepage - hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) AddRemove-Perfect Effects Free 9 - c:\windows\sysnative\wscript.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.15" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-12-12 12:52:29 ComboFix-quarantined-files.txt 2014-12-12 11:52 . Vor Suchlauf: 11 Verzeichnis(se), 929.996.791.808 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 929.461.735.424 Bytes frei . - - End Of File - - 6F4510FCBDF397FF6C02799CE5AEDF8B A36C5E4F47E84449FF07ED3517B43A31 whismerhill |
13.12.2014, 08:15 | #4 |
/// the machine /// TB-Ausbilder | Delta-homes hijack Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.12.2014, 13:55 | #5 |
| Delta-homes hijack Hi Schrauber, vielen Dank schon einmal zwischendurch..hier die logs MBAM Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 13.12.2014 Suchlauf-Zeit: 11:54:58 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2014.12.13.03 Rootkit Datenbank: v2014.12.08.03 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Marc Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 336180 Verstrichene Zeit: 5 Min, 11 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 12 PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\delta-homesSoftware, In Quarantäne, [d285164cc6b6072f0835cc9a649f9c64], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [65f2d88a007cd2646ded8c3a2cd8956b], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [3027f66cbbc1ba7cb65c4f129d66e41c], PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [500777eb37458babc21b3189b0545ea2], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [6cebcb97572566d03ba59fc15ca7ac54], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [74e34e14403c41f5e0314a17d033cf31], PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [4d0a42202f4db482151bfb5bd72cd32d], PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [9fb8570b17656cca87aa4c0a46bd1be5], PUP.Optional.Softonic.A, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [b89fe979d4a8999dddc9afa000034fb1], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [1641b9a9acd01d19ec66464ab251a858], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [1146362cd5a7b87eda98b9ed83817888], PUP.Optional.Qone8, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [8fc86002b6c649ed8779f2c042c21ce4], Registrierungswerte: 3 PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [6cebcb97572566d03ba59fc15ca7ac54] PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [74e34e14403c41f5e0314a17d033cf31] PUP.Optional.InstallCore.A, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [1146362cd5a7b87eda98b9ed83817888] Registrierungsdaten: 9 PUP.Optional.Delta.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998),Ersetzt,[f76040220b71d75fd906105d63a2b947] PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998),Ersetzt,[9fb8de8484f80036defbfb722bdaf10f] PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998),Ersetzt,[db7c97cb5a2289add50af9748c7902fe] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms}),Ersetzt,[d5823a2834482f077ebd1b52927331cf] PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998),Ersetzt,[c295a3bf81fbc86e9f36eb8226df49b7] PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998),Ersetzt,[66f17de5ccb058de419886e7679ecc34] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404397725&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms}),Ersetzt,[d08766fc1c609c9aaf8c1e44da2b06fa] PUP.Optional.Delta.A, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998),Ersetzt,[b1a6283a19634aecd6046ffef411966a] PUP.Optional.Delta.A, HKU\S-1-5-21-3978302629-4045270245-2468114167-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://search.delta-homes.com/web/?type=ds&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998&q={searchTerms}),Ersetzt,[eb6c82e0f18b191d13c5df8ec73e9868] Ordner: 3 PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [abac7ae83d3fd75f9f3dbb75ff0439c7], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [abac7ae83d3fd75f9f3dbb75ff0439c7], PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [0d4ad68c1e5e171f5bea80b94db6d729], Dateien: 5 PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [fa5db9a9f488c37305ac7cb9827e20e0], PUP.Optional.Softonic.A, C:\Users\Marc\Downloads\SoftonicDownloader_fuer_jodix-free-wma-to-mp3-converter.exe, In Quarantäne, [d7802042bdbf79bdee55c27b03fee51b], PUP.Optional.Delta.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml, In Quarantäne, [a5b295cd7c001125a431b2bd9d6643bd], PUP.Optional.Delta.A, C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998");), Ersetzt,[89cea9b9780463d315bce8bcf70e8779] PUP.Optional.Delta.A, C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998");), Ersetzt,[91c6cf9317651a1c9141297b8283f30d] Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v4.105 - Bericht erstellt am 13/12/2014 um 12:12:03 # Aktualisiert 08/12/2014 von Xplode # Database : 2014-12-13.2 [Live] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Marc - MARC-PC # Gestartet von : C:\Users\Marc\Downloads\AdwCleaner_4.105.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Marc\AppData\Roaming\WinZipper ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Verknüpfung Desinfiziert : C:\Users\Marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\SOFTWARE\hdcode Schlüssel Gelöscht : HKLM\SOFTWARE\V9 Schlüssel Gelöscht : HKLM\SOFTWARE\winzipersvc ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17344 -\\ Mozilla Firefox v34.0.5 (x86 de) [i469nsp3.default\prefs.js] - Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.delta-homes.com/newtab/?type=nt&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998"); [i469nsp3.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "delta-homes"); [i469nsp3.default\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.delta-homes.com/?type=hp&ts=1418376849&from=wpm12123&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F221899818998"); [i469nsp3.default\prefs.js] - Zeile gelöscht : user_pref("extensions.quick_start.enable_search1", false); [i469nsp3.default\prefs.js] - Zeile gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", true); ************************* AdwCleaner[R0].txt - [1805 octets] - [13/12/2014 12:05:48] AdwCleaner[S0].txt - [2588 octets] - [13/12/2014 12:12:03] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2648 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows 7 Home Premium x64 Ran by Marc on 13.12.2014 at 12:15:16,93 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Marc\AppData\Roaming\mozilla\firefox\profiles\i469nsp3.default\minidumps [56 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.12.2014 at 12:17:41,76 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2014 Ran by Marc (administrator) on MARC-PC on 13-12-2014 12:19:07 Running from C:\Users\Marc\Downloads Loaded Profile: Marc (Available profiles: Marc) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaRegistry64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaUI.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hama Wireless LAN Utility.lnk ShortcutTarget: Hama Wireless LAN Utility.lnk -> C:\Program Files (x86)\Hama\Common\RaUI.exe (Ralink Technology, Corp.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-3978302629-4045270245-2468114167-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Extension: Security Protection - C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\Extensions\detgdp@gmail.com [2014-12-12] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\extensions\detgdp@gmail.com FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [Not Found] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.) [File not signed] R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2013-09-17] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2013-09-17] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [1632256 2013-08-05] (ASUSTeK Computer Inc.) [File not signed] S3 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 RalinkRegistryWriter; C:\Program Files (x86)\Hama\Common\RaRegistry.exe [193888 2010-06-01] (Ralink Technology, Corp.) R2 RalinkRegistryWriter64; C:\Program Files (x86)\Hama\Common\RaRegistry64.exe [211296 2010-06-01] (Ralink Technology, Corp.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] () S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-09] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-09] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-09] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-09] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-09] (Kaspersky Lab ZAO) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-13 12:19 - 2014-12-13 12:19 - 00000000 ____D () C:\Users\Marc\Downloads\FRST-OlderVersion 2014-12-13 12:17 - 2014-12-13 12:17 - 00000755 _____ () C:\Users\Marc\Desktop\JRT.txt 2014-12-13 12:15 - 2014-12-13 12:15 - 00000000 ____D () C:\Windows\ERUNT 2014-12-13 12:14 - 2014-12-13 12:15 - 01707646 _____ (Thisisu) C:\Users\Marc\Downloads\JRT.exe 2014-12-13 12:13 - 2014-12-13 12:13 - 00002728 _____ () C:\Users\Marc\Desktop\AdwCleaner[S0].txt 2014-12-13 12:05 - 2014-12-13 12:12 - 00000000 ____D () C:\AdwCleaner 2014-12-13 12:05 - 2014-12-13 12:05 - 02166272 _____ () C:\Users\Marc\Downloads\AdwCleaner_4.105.exe 2014-12-13 12:04 - 2014-12-13 12:04 - 00008827 _____ () C:\Users\Marc\Desktop\mbam.txt 2014-12-13 11:54 - 2014-12-13 12:03 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-13 11:54 - 2014-12-13 11:54 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-12-13 11:54 - 2014-12-13 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-13 11:54 - 2014-12-13 11:54 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-13 11:54 - 2014-12-13 11:54 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-12-13 11:54 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-13 11:54 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-13 11:54 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-13 11:53 - 2014-12-13 11:53 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Marc\Downloads\mbam-setup-2.0.4.1028.exe 2014-12-12 14:20 - 2014-12-12 14:20 - 00021137 _____ () C:\Users\Marc\Desktop\COMBO.txt 2014-12-12 12:52 - 2014-12-12 12:52 - 00021137 _____ () C:\ComboFix.txt 2014-12-12 12:46 - 2014-12-12 12:52 - 00000000 ____D () C:\Qoobox 2014-12-12 12:46 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-12-12 12:46 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-12-12 12:46 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-12 12:45 - 2014-12-12 12:51 - 00000000 ____D () C:\Windows\erdnt 2014-12-12 12:45 - 2014-12-12 12:45 - 05600944 ____R (Swearware) C:\Users\Marc\Desktop\ComboFix.exe 2014-12-12 12:40 - 2014-12-12 12:40 - 00001268 _____ () C:\Users\Marc\Desktop\Revo Uninstaller.lnk 2014-12-12 12:40 - 2014-12-12 12:40 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-12-12 12:39 - 2014-12-12 12:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Marc\Downloads\revosetup95.exe 2014-12-12 11:54 - 2014-12-12 11:54 - 00024293 _____ () C:\Users\Marc\Downloads\Addition.txt 2014-12-12 11:53 - 2014-12-13 12:19 - 02119168 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe 2014-12-12 11:53 - 2014-12-13 12:19 - 00014830 _____ () C:\Users\Marc\Downloads\FRST.txt 2014-12-12 11:53 - 2014-12-13 12:19 - 00000000 ____D () C:\FRST 2014-12-10 16:24 - 2014-12-10 16:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-12-10 16:14 - 2014-12-10 16:14 - 03981488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-12-05 13:40 - 2014-12-05 13:40 - 06126536 _____ (Tim Kosse) C:\Users\Marc\Downloads\FileZilla_3.9.0.6_win32-setup.exe 2014-12-01 16:32 - 2014-12-01 16:32 - 14532901 _____ () C:\Users\Marc\Downloads\A&D Weihnachtshäuschen.zip 2014-11-20 12:50 - 2014-11-20 12:50 - 00000022 _____ () C:\Users\Marc\Downloads\Presse.zip 2014-11-14 16:57 - 2014-11-14 16:57 - 00002105 _____ () C:\Users\Public\Desktop\Perfect Effects Free 9.lnk 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\onOne Software 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\ProgramData\Nalpeiron 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onOne Software 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\Program Files\onOne Software 2014-11-14 16:57 - 2014-11-14 16:57 - 00000000 ____D () C:\Program Files (x86)\onOne Software 2014-11-14 16:56 - 2014-11-14 16:57 - 00000000 ____D () C:\ProgramData\onOne Software 2014-11-14 16:48 - 2014-11-14 16:48 - 01125200 _____ () C:\Users\Marc\Downloads\Perfect Effects Free - CHIP-Installer.exe 2014-11-13 13:54 - 2014-11-13 13:54 - 00001124 _____ () C:\Users\Marc\Documents\WIRTSCHAFTSDATEN - Verknüpfung.lnk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-13 12:19 - 2009-07-14 05:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-13 12:19 - 2009-07-14 05:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-13 12:17 - 2011-04-12 08:43 - 00713634 _____ () C:\Windows\system32\perfh007.dat 2014-12-13 12:17 - 2011-04-12 08:43 - 00153750 _____ () C:\Windows\system32\perfc007.dat 2014-12-13 12:17 - 2009-07-14 06:13 - 01647328 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-13 12:14 - 2014-07-14 16:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-13 12:14 - 2014-06-09 02:04 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-12-13 12:14 - 2009-07-14 05:45 - 04677672 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-13 12:13 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-13 12:13 - 2009-07-14 05:51 - 00042973 _____ () C:\Windows\setupact.log 2014-12-13 12:12 - 2014-06-09 12:24 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-13 12:12 - 2014-06-09 12:24 - 00001053 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-13 12:12 - 2014-06-08 15:19 - 01941651 _____ () C:\Windows\WindowsUpdate.log 2014-12-13 12:12 - 2014-06-08 15:17 - 00000993 _____ () C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-13 12:12 - 2010-11-21 04:47 - 00031548 _____ () C:\Windows\PFRO.log 2014-12-13 12:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\security 2014-12-12 12:52 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-12-12 12:50 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-12-11 10:54 - 2014-08-23 09:01 - 00000000 ____D () C:\Users\Marc\AppData\Local\Adobe 2014-12-11 10:53 - 2014-07-14 16:22 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-11 10:53 - 2014-07-14 16:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-11 10:53 - 2014-07-14 16:22 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-12-11 10:49 - 2014-06-09 12:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-12-10 16:00 - 2014-07-03 10:06 - 00000000 ____D () C:\KEYSALE 2014-12-08 15:33 - 2014-07-03 15:08 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\FileZilla 2014-12-08 09:15 - 2014-08-04 15:04 - 00000000 ____D () C:\Users\Marc\Desktop\KORREKTUREN 2014-12-05 16:41 - 2014-06-09 01:28 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\Adobe 2014-11-27 09:39 - 2014-06-08 15:17 - 00000000 ____D () C:\Users\Marc 2014-11-26 04:42 - 2011-02-20 05:03 - 00421040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll 2014-11-26 04:42 - 2011-02-19 06:40 - 00773808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll 2014-11-15 13:04 - 2014-07-03 15:53 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\vlc 2014-11-14 16:57 - 2014-06-09 01:08 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information Some content of TEMP: ==================== C:\Users\Marc\AppData\Local\Temp\Quarantine.exe C:\Users\Marc\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-05 18:20 ==================== End Of Log ============================ --- --- --- delta-homes tritt nicht mehr auf beim Hochfahren bzw. wenn ein neuer Tab geladen wird Liebe Grüße whismerhill |
14.12.2014, 11:24 | #6 |
/// the machine /// TB-Ausbilder | Delta-homes hijackESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Delta-homes hijack |
16.12.2014, 13:22 | #7 |
| Delta-homes hijack Hi Schrauber, war zwei Tage beruflich unterwegs, darum erst jetzt die logs...DANKE! ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=2bb9a071d9907042b652231f33b0d377 # engine=21575 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-12-16 12:12:48 # local_time=2014-12-16 01:12:48 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1292 16777214 100 100 13228944 50209990 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 3112369 170361818 0 0 # scanned=152484 # found=4 # cleaned=0 # scan_time=2957 sh=C6CE374713ABB2DDC4FC132C8C4515FB5D99577F ft=0 fh=0000000000000000 vn="JS/Trackware.Agent.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Marc\AppData\Local\Mozilla\Firefox\Profiles\i469nsp3.default\cache2\entries\E36A497F7D6382B6299E95FE29E4FE27AD29B188" sh=1E380A2D4B4138B280EE3063C0F9B0558C131271 ft=0 fh=0000000000000000 vn="JS/Trackware.Agent.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\extensions\detgdp@gmail.com\chrome\content\js\epurls.js" sh=8B414057414E369B9B99B5DE95F198A1DA5E182C ft=0 fh=0000000000000000 vn="JS/Trackware.Agent.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\extensions\detgdp@gmail.com\chrome\content\js\inject.js" sh=CC8D150C9714F31878D99909655BFF89BEDF6D46 ft=1 fh=c71c00117ff9061f vn="Variante von Win32/InstallCore.LA evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Marc\Downloads\FileZilla_3.8.1_win32-setup.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.91 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 16.0.0.235 Mozilla Firefox (34.0.5) Mozilla Thunderbird (24.6.0) ````````Process Check: objlist.exe by Laurent```````` Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2014 Ran by Marc (administrator) on MARC-PC on 16-12-2014 13:19:05 Running from C:\Users\Marc\Downloads Loaded Profile: Marc (Available profiles: Marc) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaRegistry64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RaUI.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Kaspersky Lab ZAO) C:\ProgramData\Kaspersky Lab\AVP14.0.0\Temp\temporaryFolder\updates\bin\kav14\14.0.0.4651_i\avpui.exe.6988_2553_4126.removeOnNextReboot (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hama Wireless LAN Utility.lnk ShortcutTarget: Hama Wireless LAN Utility.lnk -> C:\Program Files (x86)\Hama\Common\RaUI.exe (Ralink Technology, Corp.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3978302629-4045270245-2468114167-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-3978302629-4045270245-2468114167-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Extension: Security Protection - C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\Extensions\detgdp@gmail.com [2014-12-12] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Модуль перевірки посилань - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Віртуальна клавіатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Модуль блокування небезпечних веб-сайтів - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Безпечні платежі - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-09] FF HKLM-x32\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\i469nsp3.default\extensions\detgdp@gmail.com FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [Not Found] CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [Not Found] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.) [File not signed] R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2013-09-17] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2013-09-17] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [1632256 2013-08-05] (ASUSTeK Computer Inc.) [File not signed] R3 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 RalinkRegistryWriter; C:\Program Files (x86)\Hama\Common\RaRegistry.exe [193888 2010-06-01] (Ralink Technology, Corp.) R2 RalinkRegistryWriter64; C:\Program Files (x86)\Hama\Common\RaRegistry64.exe [211296 2010-06-01] (Ralink Technology, Corp.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] () S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-09] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-09] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-09] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-09] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-09] (Kaspersky Lab ZAO) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-16 13:18 - 2014-12-16 13:18 - 00000833 _____ () C:\Users\Marc\Desktop\checkup.txt 2014-12-16 13:16 - 2014-12-16 13:16 - 00852490 _____ () C:\Users\Marc\Desktop\SecurityCheck.exe 2014-12-16 13:16 - 2014-12-16 13:16 - 00001800 _____ () C:\Users\Marc\Desktop\ESET.txt 2014-12-16 12:16 - 2014-12-16 12:16 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-12-16 12:15 - 2014-12-16 12:15 - 02347384 _____ (ESET) C:\Users\Marc\Desktop\esetsmartinstaller_deu.exe 2014-12-13 12:19 - 2014-12-13 12:19 - 00000000 ____D () C:\Users\Marc\Downloads\FRST-OlderVersion 2014-12-13 12:17 - 2014-12-13 12:17 - 00000755 _____ () C:\Users\Marc\Desktop\JRT.txt 2014-12-13 12:15 - 2014-12-13 12:15 - 00000000 ____D () C:\Windows\ERUNT 2014-12-13 12:14 - 2014-12-13 12:15 - 01707646 _____ (Thisisu) C:\Users\Marc\Downloads\JRT.exe 2014-12-13 12:13 - 2014-12-13 12:13 - 00002728 _____ () C:\Users\Marc\Desktop\AdwCleaner[S0].txt 2014-12-13 12:05 - 2014-12-13 12:12 - 00000000 ____D () C:\AdwCleaner 2014-12-13 12:05 - 2014-12-13 12:05 - 02166272 _____ () C:\Users\Marc\Downloads\AdwCleaner_4.105.exe 2014-12-13 12:04 - 2014-12-13 12:04 - 00008827 _____ () C:\Users\Marc\Desktop\mbam.txt 2014-12-13 11:54 - 2014-12-13 12:03 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-13 11:54 - 2014-12-13 11:54 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-12-13 11:54 - 2014-12-13 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-13 11:54 - 2014-12-13 11:54 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-13 11:54 - 2014-12-13 11:54 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-12-13 11:54 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-13 11:54 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-13 11:54 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-13 11:53 - 2014-12-13 11:53 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Marc\Downloads\mbam-setup-2.0.4.1028.exe 2014-12-12 14:20 - 2014-12-12 14:20 - 00021137 _____ () C:\Users\Marc\Desktop\COMBO.txt 2014-12-12 12:52 - 2014-12-12 12:52 - 00021137 _____ () C:\ComboFix.txt 2014-12-12 12:46 - 2014-12-12 12:52 - 00000000 ____D () C:\Qoobox 2014-12-12 12:46 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-12-12 12:46 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-12-12 12:46 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-12-12 12:46 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-12 12:45 - 2014-12-12 12:51 - 00000000 ____D () C:\Windows\erdnt 2014-12-12 12:45 - 2014-12-12 12:45 - 05600944 ____R (Swearware) C:\Users\Marc\Desktop\ComboFix.exe 2014-12-12 12:40 - 2014-12-12 12:40 - 00001268 _____ () C:\Users\Marc\Desktop\Revo Uninstaller.lnk 2014-12-12 12:40 - 2014-12-12 12:40 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-12-12 12:39 - 2014-12-12 12:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Marc\Downloads\revosetup95.exe 2014-12-12 11:54 - 2014-12-12 11:54 - 00024293 _____ () C:\Users\Marc\Downloads\Addition.txt 2014-12-12 11:53 - 2014-12-16 13:19 - 00015316 _____ () C:\Users\Marc\Downloads\FRST.txt 2014-12-12 11:53 - 2014-12-16 13:19 - 00000000 ____D () C:\FRST 2014-12-12 11:53 - 2014-12-13 12:19 - 02119168 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe 2014-12-10 16:24 - 2014-12-10 16:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-12-10 16:14 - 2014-12-10 16:14 - 03981488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-12-05 13:40 - 2014-12-05 13:40 - 06126536 _____ (Tim Kosse) C:\Users\Marc\Downloads\FileZilla_3.9.0.6_win32-setup.exe 2014-12-01 16:32 - 2014-12-01 16:32 - 14532901 _____ () C:\Users\Marc\Downloads\A&D Weihnachtshäuschen.zip 2014-11-20 12:50 - 2014-11-20 12:50 - 00000022 _____ () C:\Users\Marc\Downloads\Presse.zip ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-16 13:14 - 2014-07-14 16:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-16 12:34 - 2014-06-09 12:29 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-12-16 12:07 - 2014-06-08 15:19 - 01945684 _____ () C:\Windows\WindowsUpdate.log 2014-12-16 11:31 - 2009-07-14 05:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-16 11:31 - 2009-07-14 05:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-16 11:29 - 2011-04-12 08:43 - 00713634 _____ () C:\Windows\system32\perfh007.dat 2014-12-16 11:29 - 2011-04-12 08:43 - 00153750 _____ () C:\Windows\system32\perfc007.dat 2014-12-16 11:29 - 2009-07-14 06:13 - 01647328 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-16 11:26 - 2014-06-09 02:04 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-12-16 11:25 - 2009-07-14 05:45 - 04677672 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-16 11:24 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-16 11:24 - 2009-07-14 05:51 - 00043029 _____ () C:\Windows\setupact.log 2014-12-13 14:10 - 2014-07-03 15:53 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\vlc 2014-12-13 12:12 - 2014-06-09 12:24 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-13 12:12 - 2014-06-09 12:24 - 00001053 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-13 12:12 - 2014-06-08 15:17 - 00000993 _____ () C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-13 12:12 - 2010-11-21 04:47 - 00031548 _____ () C:\Windows\PFRO.log 2014-12-13 12:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\security 2014-12-12 12:52 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-12-12 12:50 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-12-11 10:54 - 2014-08-23 09:01 - 00000000 ____D () C:\Users\Marc\AppData\Local\Adobe 2014-12-11 10:53 - 2014-07-14 16:22 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-11 10:53 - 2014-07-14 16:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-11 10:53 - 2014-07-14 16:22 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-12-11 10:49 - 2014-06-09 12:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-12-10 16:00 - 2014-07-03 10:06 - 00000000 ____D () C:\KEYSALE 2014-12-08 15:33 - 2014-07-03 15:08 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\FileZilla 2014-12-08 09:15 - 2014-08-04 15:04 - 00000000 ____D () C:\Users\Marc\Desktop\KORREKTUREN 2014-12-05 16:41 - 2014-06-09 01:28 - 00000000 ____D () C:\Users\Marc\AppData\Roaming\Adobe 2014-11-27 09:39 - 2014-06-08 15:17 - 00000000 ____D () C:\Users\Marc 2014-11-26 04:42 - 2011-02-20 05:03 - 00421040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll 2014-11-26 04:42 - 2011-02-19 06:40 - 00773808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll Some content of TEMP: ==================== C:\Users\Marc\AppData\Local\Temp\Quarantine.exe C:\Users\Marc\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-16 11:54 ==================== End Of Log ============================ PC läuft, soweit ich das sehe in bester Ordnung..delta homes poppt nicht mehr auf Liebe Grüße whismerhill |
16.12.2014, 21:41 | #8 |
/// the machine /// TB-Ausbilder | Delta-homes hijack Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.12.2014, 12:09 | #9 |
| Delta-homes hijack firefox hat alles geklappt...beim uninstallen von Combofix hab ich beide Möglichkleiten versucht (Windowtaste / und Umbenennen)..in beiden Fällen startete Combofix nen Scan..beim ersten Mal hab ich abgebrochen, beim 2 Versuch hab ich durchlaufen lassen..dachte, dass sich Programm evtl. am Ende des Scans dann löscht..war aber nicht der Fall (hab zwar das Icon von Combofix auf dem Desktop aber find das Programm auf C nicht) ... da immer vor Benutzung von Combofix ohne ausdrückliche Ansage gewarnt wird, hoffe ich mal, dass nichts kaputt ist..hier der unfreiwillige log Code:
ATTFilter ComboFix 14-12-10.03 - Marc 17.12.2014 11:11:32.2.6 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3996.2758 [GMT 1:00] ausgeführt von:: c:\users\Marc\Desktop\uninstall.exe.exe AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2014-11-17 bis 2014-12-17 )))))))))))))))))))))))))))))) . . 2014-12-17 10:14 . 2014-12-17 10:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-12-13 11:15 . 2014-12-13 11:15 -------- d-----w- c:\windows\ERUNT 2014-12-13 11:05 . 2014-12-13 11:12 -------- d-----w- C:\AdwCleaner 2014-12-13 10:54 . 2014-12-13 11:03 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-12-13 10:54 . 2014-12-13 10:54 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-12-13 10:54 . 2014-12-13 10:54 -------- d-----w- c:\programdata\Malwarebytes 2014-12-13 10:54 . 2014-11-21 05:14 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-12-13 10:54 . 2014-11-21 05:14 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-12-13 10:54 . 2014-11-21 05:14 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-12-12 11:40 . 2014-12-17 09:53 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-12-12 10:53 . 2014-12-16 12:19 -------- d-----w- C:\FRST 2014-12-10 15:14 . 2014-12-10 15:14 3981488 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2014-11-18 16:38 . 2014-12-05 11:07 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2014-11-18 16:38 . 2014-12-05 11:07 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-12-17 09:48 . 2014-11-03 13:52 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2014-12-17 09:48 . 2014-11-03 13:51 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2014-12-11 09:53 . 2014-07-14 15:22 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-12-11 09:53 . 2014-07-14 15:22 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-11-26 03:42 . 2011-02-19 05:40 773808 ----a-w- c:\windows\SysWow64\msvcr100.dll 2014-11-26 03:42 . 2011-02-20 04:03 421040 ----a-w- c:\windows\SysWow64\msvcp100.dll 2014-11-18 16:38 . 2014-11-03 13:51 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2014-11-05 09:22 . 2014-11-05 09:22 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2014-11-04 13:30 . 2010-11-21 03:27 275080 ------w- c:\windows\system32\MpSigStub.exe 2014-10-20 01:37 . 2014-11-10 12:39 11627712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F4245B6A-E489-4C13-8BF4-E7DBAFA556AC}\mpengine.dll 2014-10-07 02:54 . 2014-11-10 12:30 378552 ----a-w- c:\windows\system32\iedkcs32.dll 2014-10-03 09:02 . 2014-11-10 12:32 103265616 ----a-w- c:\windows\system32\MRT.exe 2014-09-29 12:20 . 2014-10-02 15:41 81792 ----a-w- c:\windows\SysWow64\mslvddsfilter2.ax 2014-09-29 00:58 . 2014-11-10 12:28 3198976 ----a-w- c:\windows\system32\win32k.sys 2014-09-25 22:50 . 2014-11-10 12:30 13619200 ----a-w- c:\windows\system32\ieframe.dll 2014-09-25 22:32 . 2014-11-10 12:30 2017280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-09-25 22:31 . 2014-11-10 12:30 2108416 ----a-w- c:\windows\system32\inetcpl.cpl 2014-09-19 02:25 . 2014-11-10 12:30 23631360 ----a-w- c:\windows\system32\mshtml.dll 2014-09-19 01:56 . 2014-11-10 12:30 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-09-19 01:55 . 2014-11-10 12:30 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-09-19 01:41 . 2014-11-10 12:30 2796032 ----a-w- c:\windows\system32\iertutil.dll 2014-09-19 01:40 . 2014-11-10 12:30 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-09-19 01:40 . 2014-11-10 12:30 547328 ----a-w- c:\windows\system32\vbscript.dll 2014-09-19 01:39 . 2014-11-10 12:30 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-09-19 01:38 . 2014-11-10 12:30 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-09-19 01:36 . 2014-11-10 12:30 5829632 ----a-w- c:\windows\system32\jscript9.dll 2014-09-19 01:31 . 2014-11-10 12:30 51200 ----a-w- c:\windows\system32\jsproxy.dll 2014-09-19 01:30 . 2014-11-10 12:30 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-09-19 01:27 . 2014-11-10 12:30 595968 ----a-w- c:\windows\system32\ieui.dll 2014-09-19 01:26 . 2014-11-10 12:30 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-09-19 01:25 . 2014-11-10 12:30 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-09-19 01:25 . 2014-11-10 12:30 4201472 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-09-19 01:25 . 2014-11-10 12:30 758272 ----a-w- c:\windows\system32\jscript9diag.dll 2014-09-19 01:18 . 2014-11-10 12:30 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-09-19 01:14 . 2014-11-10 12:30 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-09-19 01:14 . 2014-11-10 12:30 446464 ----a-w- c:\windows\system32\dxtmsft.dll 2014-09-19 01:06 . 2014-11-10 12:30 72704 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-09-19 01:02 . 2014-11-10 12:30 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-09-19 01:01 . 2014-11-10 12:30 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-09-19 01:01 . 2014-11-10 12:30 195584 ----a-w- c:\windows\system32\msrating.dll 2014-09-19 01:01 . 2014-11-10 12:30 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-09-19 01:00 . 2014-11-10 12:30 85504 ----a-w- c:\windows\system32\mshtmled.dll 2014-09-19 00:59 . 2014-11-10 12:30 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-09-19 00:58 . 2014-11-10 12:30 289280 ----a-w- c:\windows\system32\dxtrans.dll 2014-09-19 00:50 . 2014-11-10 12:30 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-09-19 00:49 . 2014-11-10 12:30 597504 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-09-19 00:42 . 2014-11-10 12:30 731136 ----a-w- c:\windows\system32\msfeeds.dll 2014-09-19 00:42 . 2014-11-10 12:30 710656 ----a-w- c:\windows\system32\ie4uinit.exe 2014-09-19 00:40 . 2014-11-10 12:30 1249280 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-09-19 00:36 . 2014-11-10 12:30 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-09-19 00:33 . 2014-11-10 12:30 2309632 ----a-w- c:\windows\system32\wininet.dll 2014-09-19 00:18 . 2014-11-10 12:30 1068032 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-09-19 00:14 . 2014-11-10 12:30 1447936 ----a-w- c:\windows\system32\urlmon.dll 2014-09-18 23:59 . 2014-11-10 12:30 775168 ----a-w- c:\windows\system32\ieapfltr.dll 2014-09-18 23:59 . 2014-11-10 12:30 1810944 ----a-w- c:\windows\SysWow64\wininet.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-04-17 767200] "AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Hama Wireless LAN Utility.lnk - c:\program files (x86)\Hama\Common\RaUI.exe -s [2014-7-2 6479712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AiChargerPlus;AiChargerPlus;SysWow64\drivers\AiChargerPlus.sys;SysWow64\drivers\AiChargerPlus.sys [x] R3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AODDriver4.3;AODDriver4.3;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [x] S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [x] S2 AsusFanControlService;AsusFanControlService;c:\program files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe;c:\program files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [x] S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\Hama\Common\RaRegistry64.exe;c:\program files (x86)\Hama\Common\RaRegistry64.exe [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-12-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-14 09:53] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-08-19 7202520] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = www.google.com uDefault_Search_URL = www.google.com mDefault_Search_URL = www.google.com mDefault_Page_URL = www.google.com mStart Page = www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = www.google.com IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Zu Anti-Banner hinzufügen - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Marc\AppData\Roaming\Mozilla\Firefox\Profiles\tb46wi0d.default-1418810736960\ FF - prefs.js: browser.startup.homepage - hxxp://www.ixquick.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) AddRemove-Perfect Effects Free 9 - c:\windows\sysnative\wscript.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.15" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-12-17 11:15:59 ComboFix-quarantined-files.txt 2014-12-17 10:15 ComboFix2.txt 2014-12-12 11:52 . Vor Suchlauf: 16 Verzeichnis(se), 928.003.604.480 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 927.568.207.872 Bytes frei . - - End Of File - - 9FCA0D849F0F9300A9F2B45FB0919F56 A36C5E4F47E84449FF07ED3517B43A31 Lg whismerhill NACHTRAG: Combofix Uninstall hat funktioniert..das Problem bestand darin, dass ich Combofix in Uninstall.exe umbenannt habe...dadurch entstand in Wirklichkeit Uninstall.exe.exe und darum wurde gescannt..wieder was gelernt..falls ich jetzt nicht irgendwas durch den zusätzlichen Combo-Scan vermurkst habe sind wir durch.. TAUSEND DANK Schrauber und kannst den Beitrag aus der Liste nehmen Herzliche Grüße whismerhill |
17.12.2014, 20:57 | #10 |
/// the machine /// TB-Ausbilder | Delta-homes hijack Passt schon Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |