Hallo zusammen
Ich habe ein Problem mit dem Windows Defender.
Etwa alle 20 Minuten kommt vom Windows Defender folgende Meldung:
windows defender has finished downloading the update.
please click OK to finish the updating process.
Danach meldet sich die Benutzerkontensteuerung mit folgenden worten:
Möchten sie zulassen, dass durch das folgende Programm Änderungen an diesem Computer vorgenommen werden.
Programmname: Windows Hostprozess (rundll32)
Herausgeber: Microsoft Windows
Wenn ich dann auf OK klicke passiert nichts. Zumindest nichts sichtbares.
Ich bin mir jetzt nicht sicher, ob ich irgendetwas falsch eingestellt habe oder ob ich mir was böses eingefangen habe.
Awira AntiVir Personal ist installiert (zeigte bei der letzten Prüfung nichts verdächtiges an)
Windows Firewall ist aktiviert
Windows Defender ist aktiviert (Die erwähnte Meldung erscheint auch wenn er deaktiviert ist)
Betriebssysthem: Windows 7 Home Premium 32-bit
1. CCleaner habe ich laut Anleitung des Forums ausgeführt.
2. Malwarebytes habe ich auch laut Anleitung ausgeführt.
Hier das Logfile
Zitat:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Datenbank Version: 4104
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
15.05.2010 22:12:14
mbam-log-2010-05-15 (22-12-14).txt
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 116583
Laufzeit: 6 Minute(n), 11 Sekunde(n)
Infizierte Speicherprozesse: 1
Infizierte Speichermodule: 2
Infizierte Registrierungsschlüssel: 3
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 2
Infizierte Verzeichnisse: 2
Infizierte Dateien: 62
Infizierte Speicherprozesse:
C:\Users\rocknblues\AppData\Roaming\SystemProc\lsass.exe (Trojan.Tracur) -> Unloaded process successfully.
Infizierte Speichermodule:
C:\Users\rocknblues\AppData\Roaming\1F50.tmp (Trojan.Tracur) -> Delete on reboot.
C:\ProgramData\diskcopy32.dll (Trojan.Tracur) -> Delete on reboot.
Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02c621e5-d073-4b1a-a490-fead88f4a026} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{02c621e5-d073-4b1a-a490-fead88f4a026} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{02c621e5-d073-4b1a-a490-fead88f4a026} (Trojan.Tracur) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\ctl3d3232.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\ctl3d3232.dll -> Delete on reboot.
Infizierte Verzeichnisse:
C:\ProgramData\1788690071 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Roaming\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully.
Infizierte Dateien:
C:\ProgramData\diskcopy32.dll (Trojan.BHO.H) -> Delete on reboot.
C:\Users\rocknblues\AppData\Roaming\1F50.tmp (Trojan.Tracur) -> Delete on reboot.
C:\Users\rocknblues\AppData\Roaming\SystemProc\lsass.exe (Trojan.Tracur) -> Delete on reboot.
C:\ProgramData\asycfilt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\AudioSes32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\C_ISCII32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\d3d10warp32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\d3d1132.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dbghelp32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dciman3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\defaultlocationcpl32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\DeviceDisplayStatusManager32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\DevicePairing32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\devobj32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dfdts32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\DfsShlEx32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dhcpcsvc632.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\difxapi32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\Display32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\AzSqlExt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\blb_ps32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\BOOTVID32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\bridgeres32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\BthpanContextHandler32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\BWContextHandler32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\cabview32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\cca32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\CertEnroll32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\cfgmgr3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\divx_xx0732.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dmdskmgr32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dmocx32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dmsynth32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\ds16gt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\ProgramData\dsdmo32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\cscapi32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\csrsrv32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\d3d1032.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\dot3api32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Windows\System32\dot3gpclnt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\1014.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\12F4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\1995.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\1E24.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\2297.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\27B2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\2E09.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\33A4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\362D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\36DC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\3AB3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\3EE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\4E71.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\5BB.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\5DF8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\6049.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\66DD.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\6C4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\F138.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\FB04.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Local\Temp\FEAC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Users\rocknblues\AppData\Roaming\SystemProc\upd.exe (Trojan.Agent) -> Delete on reboot. |
3. Random´s System Information, lässt sich nicht ausführen.
Wärend des Scan Vorgang´s, kommt folgende Meldung:
Line 2563 (File "C:\ro***es\Documents\ Downloads\RSIT.exe
Error: Variable used without being declared.