|
Log-Analyse und Auswertung: Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
21.02.2015, 14:44 | #16 |
| Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden.Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01 Ran by Bina at 2015-02-21 14:33:42 Run:1 Running from C:\Users\Bina\Desktop Loaded Profiles: Bina (Available profiles: Bina & krizz) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction CHR HKU\S-1-5-21-2174489219-974603214-2956640213-1000\SOFTWARE\Policies\Google: Policy restriction HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction HKU\S-1-5-21-2174489219-974603214-2956640213-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKU\S-1-5-21-2174489219-974603214-2956640213-1000 -> No Name - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No File CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPDB258463-4080-48BE-B4A6-DA827DF08E43&SSPV=" cmd: type "C:\ProgramData\UnhJWFY.bat" cmd: type "C:\ProgramData\UnhJWFY.reg" C:\ProgramData\UnhJWFY.bat C:\ProgramData\UnhJWFY.reg Task: {1C33CFBF-704D-464C-892A-EA47C5168CB2} - System32\Tasks\{544F2744-B9FD-4DE5-8B2D-E34D76DE8258} => pcalua.exe -a C:\Users\Bina\Desktop\fs\Uninstal.exe Task: {40B84B81-9DAD-448C-8D18-B6071BC31A37} - System32\Tasks\{13D677FE-DEA3-4099-B53A-041F6397C5C3} => pcalua.exe -a C:\Users\Bina\Desktop\Progs\Take_On_Helicopters_Demo.exe -d C:\Users\Bina\Desktop\Progs AlternateDataStreams: C:\ProgramData\Temp:7BFFC6A9 AlternateDataStreams: C:\ProgramData\Temp:80253E8D EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKU\S-1-5-21-2174489219-974603214-2956640213-1000\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-2174489219-974603214-2956640213-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKU\S-1-5-21-2174489219-974603214-2956640213-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} => value deleted successfully. HKCR\CLSID\{C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} => Key not found. Chrome StartupUrls deleted successfully. ========= type "C:\ProgramData\UnhJWFY.bat" ========= START "ok" rundll32.exe C:\Users\Chris\AppData\Local\Temp\YFWJhnU.exe,M1N1 /B ========= End of CMD: ========= ========= type "C:\ProgramData\UnhJWFY.reg" ========= Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="C:\\PROGRA~3\\UnhJWFY.bat" ========= End of CMD: ========= C:\ProgramData\UnhJWFY.bat => Moved successfully. C:\ProgramData\UnhJWFY.reg => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1C33CFBF-704D-464C-892A-EA47C5168CB2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1C33CFBF-704D-464C-892A-EA47C5168CB2}" => Key deleted successfully. C:\Windows\System32\Tasks\{544F2744-B9FD-4DE5-8B2D-E34D76DE8258} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{544F2744-B9FD-4DE5-8B2D-E34D76DE8258}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40B84B81-9DAD-448C-8D18-B6071BC31A37}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40B84B81-9DAD-448C-8D18-B6071BC31A37}" => Key deleted successfully. C:\Windows\System32\Tasks\{13D677FE-DEA3-4099-B53A-041F6397C5C3} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{13D677FE-DEA3-4099-B53A-041F6397C5C3}" => Key deleted successfully. C:\ProgramData\Temp => ":7BFFC6A9" ADS removed successfully. C:\ProgramData\Temp => ":80253E8D" ADS removed successfully. EmptyTemp: => Removed 583.5 MB temporary data. The system needed a reboot. ==== End of Fixlog 14:34:33 ==== LG Bina |
21.02.2015, 16:30 | #17 | |
/// TB-Ausbilder /// Anleitungs-Guru | Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden. So war es damals...
__________________Zitat:
ESET Online Scanner
Schritt 2 Downloade Dir HitmanProauf Deinen Desktop: HitmanPro-32 Bit Version HitmanPro-64 Bit Version
__________________ |
21.02.2015, 23:25 | #18 |
| Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden.Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=d61975459f74b7429fc2c028ad676718 # engine=13249 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-02-26 10:25:51 # local_time=2013-02-26 11:25:51 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 100 88 13184 138627423 0 0 # compatibility_mode=5893 16776574 100 94 25065 113547401 0 0 # scanned=229482 # found=4 # cleaned=0 # scan_time=8242 sh=46C1319EE38510C365A4226621DE30BDF7E462FF ft=1 fh=662930a683ab766b vn="Win64/Conedex.C trojan" ac=I fn="C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2174489219-974603214-2956640213-1004\$623235fd9acb63d37cd05f847f298693\U\00000004.@.vir" sh=810E28D4E7B28D658DC48A82F0C65B46149AAE89 ft=1 fh=120d32a29875bbd8 vn="Win64/Conedex.B trojan" ac=I fn="C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2174489219-974603214-2956640213-1004\$623235fd9acb63d37cd05f847f298693\U\000000cb.@.vir" sh=061A3739739904F13A5B9ADCBF4AC2E8A3157B18 ft=1 fh=3f70b78fb0084ee4 vn="Win64/Sirefef.AW trojan" ac=I fn="C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2174489219-974603214-2956640213-1004\$623235fd9acb63d37cd05f847f298693\U\80000000.@.vir" sh=75BB04900AC0028C289D41EC423A1C898DB67CE2 ft=1 fh=2b46c437d4ba4830 vn="a variant of Win64/Sirefef.AN trojan" ac=I fn="C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2174489219-974603214-2956640213-1004\$623235fd9acb63d37cd05f847f298693\U\80000064.@.vir" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=d61975459f74b7429fc2c028ad676718 # engine=13399 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-03-16 10:37:25 # local_time=2013-03-16 11:37:25 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=772 16777213 83 91 349283 140140117 0 0 # compatibility_mode=5893 16776574 100 94 1541359 115060095 0 0 # scanned=183248 # found=0 # cleaned=0 # scan_time=58802 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=d61975459f74b7429fc2c028ad676718 # engine=22587 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-21 09:42:38 # local_time=2015-02-21 10:42:38 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 92 6260848 188975448 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 51020789 176184808 0 0 # scanned=113699 # found=2 # cleaned=0 # scan_time=5537 sh=16068B8977B4DC562AE782D91BC009472667E331 ft=1 fh=c3b5a87b7d152749 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Bina\AppData\Local\Temp\OCS\ocs_v71a.exe.vir" sh=C058C543D91955AA533C6C6840DCB1DC67E746B6 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.AL evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Bina\AppData\Local\CRE\leocdeigfnkaojcapikdjcdbedcjmffc.crx" Code:
ATTFilter
|
22.02.2015, 10:59 | #19 |
/// TB-Ausbilder /// Anleitungs-Guru | Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden. Hi, Du hast den ESET Scan abgebrochen. Unabhängig davon glaube ich aber nicht, dass Dein Problem von aktiver Malware verursacht wird. Das war vor zwei Jahren ja auch nicht der Fall.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
22.02.2015, 21:57 | #20 |
| Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden.Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=d61975459f74b7429fc2c028ad676718 # engine=22593 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-22 08:52:04 # local_time=2015-02-22 09:52:04 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 92 6344214 189058814 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 51104155 176268174 0 0 # scanned=232280 # found=3 # cleaned=3 # scan_time=8076 sh=16068B8977B4DC562AE782D91BC009472667E331 ft=1 fh=c3b5a87b7d152749 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Bina\AppData\Local\Temp\OCS\ocs_v71a.exe.vir" sh=43A2C751E8596F50DAFC0D360FC594F77018049D ft=1 fh=de54c1316c0a6707 vn="Variante von Win32/InstallCore.UF evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Bina\Downloads\ML_TrialLogoSmartz_CB-DL-Manager.exe" sh=CE4437D9AEF8DA1F3193FAD5CF38ABB8925699C4 ft=1 fh=3ed5c1fb2c9e35ce vn="Variante von Win32/InstallCore.BY evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\krizz\Downloads\bass-sport-fishing.exe" |
22.02.2015, 22:16 | #21 |
/// TB-Ausbilder /// Anleitungs-Guru | Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden. Ok. Aber wie gesagt, es scheint nicht an Malware etc. zu liegen. Der PC ist ja sauber...
__________________ --> Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden. |
Themen zu Pop Up System32 beim starten des PC verschwindet sofort wieder PC ist sehr langsam geworden. |
antivirus, branding, browser, combofix, desktop, device driver, error, failed, flash player, google, home, homepage, langsam, launch, mozilla, netzwerk, packard bell, problem, realtek, registry, scan, security, software, starten, svchost.exe, system, vista, warnung, windows |