![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Windows 7 64 / Google Chrome macht immer neue Werbeseiten auf / will Chrom oder Java UdatenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #9 |
![]() | Windows 7 64 / Google Chrome macht immer neue Werbeseiten auf / will Chrom oder Java Udaten Soweit scheint alles OK zu sein. Nur Outlook geht weder mit Explorer noch mit Chrom auf ?? Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2014
Ran by FlyingSascha at 2015-01-01 09:06:03 Run:1
Running from C:\Users\FlyingSascha\Desktop
Loaded Profile: FlyingSascha (Available profiles: FlyingSascha & FlyingFabian)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
C:\Users\FlyingSascha\Downloads\mgxapkg11-di.rar
C:\Users\FlyingSascha\Downloads\mgxapkg-di\MAGIX All Products 2013 Keygen\keygen.exe
C:\Users\FlyingSascha\Downloads\mgxapkg-di\MAGIX All Products 2013 Keygen\magic.dll
C:\Users\FlyingSascha\Downloads\mgxapkg11-di\Magix Products Multikeygen 1.1-DI\Keygen.exe
C:\Users\FlyingSascha\Downloads\mgxapkg11-di\Magix Products Multikeygen 1.1-DI\Magic.dll
C:\Windows\Installer\MSIBA3B.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll
C:\Windows\Installer\MSIBA3B.tmp-\Smartbar.Resources.LanguageSettings.resources.dll
C:\Windows\Installer\MSIBA3B.tmp-\spbe.dll
C:\Windows\Installer\MSIBA3B.tmp-\spbl.dll
C:\Windows\Installer\MSIBA3B.tmp-\sppsm.dll
C:\Windows\Installer\MSIBA3B.tmp-\spusm.dll
C:\Windows\Installer\MSIBA3B.tmp-\srbs.dll
C:\Windows\Installer\MSIBA3B.tmp-\srptc.dll
C:\Windows\Installer\MSIBA3B.tmp-\srpu.dll
E:\Note 2 Datensicherung\TitaniumBackup\com.easy.paint-ddab254fcb030a60d5e8b7ef5196a8af.apk.gz
E:\SD N2\TitaniumBackup\com.easy.paint-ddab254fcb030a60d5e8b7ef5196a8af.apk.gz
E:\Sicherung N2\TitaniumBackup\com.easy.paint-ddab254fcb030a60d5e8b7ef5196a8af.apk.gz
F:\Downloads\Babylon9_setup
F:\Downloads\Babylon9_setup.exe
F:\Downloads\vlc-2.0.2-win32.exe
F:\Festplatte C\SuperOneClickv2.2-ShortFuse\Exploits\zergRush
F:\Festplatte C\ZC.DVCrea.668\ZC DVD Creator Platinum 6.6.8\zcdvdcreator.exe
F:\HTC Desire\appmonster2\backup\com.outfit7.talkingtom2free\rev\9.apk
F:\MediaPad\unlockroot21.exe
F:\Note 2 Speicherkarte 32 GB\TitaniumBackup (1)\com.LemengGame.guonen.LostTempleII-20130401-102927.tar.gz
F:\Note 2 Speicherkarte 32 GB\TitaniumBackup (1)\eu.chainfire.exynosabuse-20130401-103507.tar.gz
F:\Programme\Copernic-Desktop-Search-Setup.exe
F:\Programme\cover-druckstudio-20-setup-Downloader.exe
F:\Programme\DTLite4481-0347.exe
F:\Programme\FileConverter_1_3.exe
F:\Programme\FreeYouTubeToMP3Converter34.exe
F:\Programme\lauge-2-25.exe
F:\Programme\NetworkMeterVersion96 (1).exe
F:\Programme\NetworkMeterVersion96.exe
F:\Programme\ZipOpenerSetup.exe
F:\Programme\ZipSetup.exe
F:\Stick Schwarz-Rot\Laptop\DownloadSetup (47).exe
F:\Stick Schwarz-Rot\Laptop\iLividSetupV1 (1).exe
F:\Stick Schwarz-Rot\Laptop\iLividSetupV1.exe
G:\Users\All Users\gfhlpbbmhkonieglgegpgmgmgakhfcmi
G:\Users\Fabian\AppData\Roaming\OpenCandy\OpenCandy_00F218D21CF74437A271719206186F4B\registrybooster21.exe
G:\Users\Fabian\AppData\Roaming\OpenCandy\OpenCandy_00F218D21CF74437A271719206186F4B\registrybooster21Wrapped.exe
G:\Users\Fabian\Downloads\sirius.20.12.installer_new.exe
G:\Users\Flyingflorian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWZ36KLH\SoftonicDownloader_fuer_little-fighter-ii[1].exe
G:\Users\Flyingflorian\Downloads\SoftonicDownloader_fuer_t-dsl-speed-manager.exe
G:\Users\FlyingSascha\AppData\Local\Babylon\Setup\Setup.exe
G:\Users\FlyingSascha\Downloads\Babylon9_setup.exe
G:\Users\FlyingSascha\Downloads\iLividSetupV1 (1).exe
G:\Users\FlyingSascha\Downloads\iLividSetupV1 (2).exe
G:\Users\FlyingSascha\Downloads\iLividSetupV1 (3).exe
G:\Users\FlyingSascha\Downloads\Setup (1).exe
G:\Users\FlyingSascha\Downloads\SweetImSetup.exe
G:\Users\FlyingSascha\Downloads\Programme\Elf_1.exe
G:\Windows\Installer\a8a3b20.msi
H:\MW2\Sirius MT2\neuer_patcher
H:\Note2 Datensicherung\Ordner Card\TitaniumBackup (1)\com.LemengGame.guonen.LostTempleII-20130401-102927.tar.gz
H:\Note2 Datensicherung\Ordner Card\TitaniumBackup (1)\eu.chainfire.exynosabuse-20130401-103507.tar.gz
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-71949653-2680169956-912045377-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-71949653-2680169956-912045377-1001] => http=127.0.0.1:8555;https=127.0.0.1:8555
CHR HKLM-x32\...\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] - No Path
CHR HKLM-x32\...\Chrome\Extension: [heoldelcflnigdllmlopiefhkkobendj] - No Path
S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [X]
Emptytemp:
*****************
C:\Users\FlyingSascha\Downloads\mgxapkg11-di.rar => Moved successfully.
C:\Users\FlyingSascha\Downloads\mgxapkg-di\MAGIX All Products 2013 Keygen\keygen.exe => Moved successfully.
C:\Users\FlyingSascha\Downloads\mgxapkg-di\MAGIX All Products 2013 Keygen\magic.dll => Moved successfully.
C:\Users\FlyingSascha\Downloads\mgxapkg11-di\Magix Products Multikeygen 1.1-DI\Keygen.exe => Moved successfully.
C:\Users\FlyingSascha\Downloads\mgxapkg11-di\Magix Products Multikeygen 1.1-DI\Magic.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\Smartbar.Resources.HistoryAndStatsWrapper.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\Smartbar.Resources.LanguageSettings.resources.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\spbe.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\spbl.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\sppsm.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\spusm.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\srbs.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\srptc.dll => Moved successfully.
C:\Windows\Installer\MSIBA3B.tmp-\srpu.dll => Moved successfully.
E:\Note 2 Datensicherung\TitaniumBackup\com.easy.paint-ddab254fcb030a60d5e8b7ef5196a8af.apk.gz => Moved successfully.
E:\SD N2\TitaniumBackup\com.easy.paint-ddab254fcb030a60d5e8b7ef5196a8af.apk.gz => Moved successfully.
E:\Sicherung N2\TitaniumBackup\com.easy.paint-ddab254fcb030a60d5e8b7ef5196a8af.apk.gz => Moved successfully.
"F:\Downloads\Babylon9_setup" => File/Directory not found.
F:\Downloads\Babylon9_setup.exe => Moved successfully.
F:\Downloads\vlc-2.0.2-win32.exe => Moved successfully.
F:\Festplatte C\SuperOneClickv2.2-ShortFuse\Exploits\zergRush => Moved successfully.
F:\Festplatte C\ZC.DVCrea.668\ZC DVD Creator Platinum 6.6.8\zcdvdcreator.exe => Moved successfully.
F:\HTC Desire\appmonster2\backup\com.outfit7.talkingtom2free\rev\9.apk => Moved successfully.
F:\MediaPad\unlockroot21.exe => Moved successfully.
F:\Note 2 Speicherkarte 32 GB\TitaniumBackup (1)\com.LemengGame.guonen.LostTempleII-20130401-102927.tar.gz => Moved successfully.
F:\Note 2 Speicherkarte 32 GB\TitaniumBackup (1)\eu.chainfire.exynosabuse-20130401-103507.tar.gz => Moved successfully.
F:\Programme\Copernic-Desktop-Search-Setup.exe => Moved successfully.
F:\Programme\cover-druckstudio-20-setup-Downloader.exe => Moved successfully.
F:\Programme\DTLite4481-0347.exe => Moved successfully.
F:\Programme\FileConverter_1_3.exe => Moved successfully.
F:\Programme\FreeYouTubeToMP3Converter34.exe => Moved successfully.
F:\Programme\lauge-2-25.exe => Moved successfully.
F:\Programme\NetworkMeterVersion96 (1).exe => Moved successfully.
F:\Programme\NetworkMeterVersion96.exe => Moved successfully.
F:\Programme\ZipOpenerSetup.exe => Moved successfully.
F:\Programme\ZipSetup.exe => Moved successfully.
F:\Stick Schwarz-Rot\Laptop\DownloadSetup (47).exe => Moved successfully.
F:\Stick Schwarz-Rot\Laptop\iLividSetupV1 (1).exe => Moved successfully.
F:\Stick Schwarz-Rot\Laptop\iLividSetupV1.exe => Moved successfully.
G:\Users\All Users\gfhlpbbmhkonieglgegpgmgmgakhfcmi => Moved successfully.
G:\Users\Fabian\AppData\Roaming\OpenCandy\OpenCandy_00F218D21CF74437A271719206186F4B\registrybooster21.exe => Moved successfully.
G:\Users\Fabian\AppData\Roaming\OpenCandy\OpenCandy_00F218D21CF74437A271719206186F4B\registrybooster21Wrapped.exe => Moved successfully.
G:\Users\Fabian\Downloads\sirius.20.12.installer_new.exe => Moved successfully.
G:\Users\Flyingflorian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWZ36KLH\SoftonicDownloader_fuer_little-fighter-ii[1].exe => Moved successfully.
G:\Users\Flyingflorian\Downloads\SoftonicDownloader_fuer_t-dsl-speed-manager.exe => Moved successfully.
G:\Users\FlyingSascha\AppData\Local\Babylon\Setup\Setup.exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\Babylon9_setup.exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\iLividSetupV1 (1).exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\iLividSetupV1 (2).exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\iLividSetupV1 (3).exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\Setup (1).exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\SweetImSetup.exe => Moved successfully.
G:\Users\FlyingSascha\Downloads\Programme\Elf_1.exe => Moved successfully.
G:\Windows\Installer\a8a3b20.msi => Moved successfully.
H:\MW2\Sirius MT2\neuer_patcher => Moved successfully.
H:\Note2 Datensicherung\Ordner Card\TitaniumBackup (1)\com.LemengGame.guonen.LostTempleII-20130401-102927.tar.gz => Moved successfully.
H:\Note2 Datensicherung\Ordner Card\TitaniumBackup (1)\eu.chainfire.exynosabuse-20130401-103507.tar.gz => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKU\S-1-5-21-71949653-2680169956-912045377-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\S-1-5-21-71949653-2680169956-912045377-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dflinnddekagfkncpgojoppgnppfkbkj" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\heoldelcflnigdllmlopiefhkkobendj" => Key deleted successfully.
esgiguard => Service deleted successfully.
EmptyTemp: => Removed 834.4 MB temporary data.
The system needed a reboot.
==== End of Fixlog 09:07:08 ====
Geändert von FlyingSascha (01.01.2015 um 09:23 Uhr) |
| Themen zu Windows 7 64 / Google Chrome macht immer neue Werbeseiten auf / will Chrom oder Java Udaten |
| antivirus, browser, canon, ccsetup, computer, converter, driver booster, dvdvideosoft ltd., excel, failed, fehler, flash player, google, helper, iexplore.exe, internet, kaspersky, lightning, mozilla, problem, registry, rundll, scan, security, software, super, svchost.exe, system, teamspeak, teredo, uplay, usb, windows |