Adware + Umleitungen in Chrome / Wiederkehrende Blockade von Windows Defender Beim PC meines Vaters hat sich etwas eingenistet. Ich würde es gerne näher beschreiben / Titel geben, nur dies ist nicht möglich, daher Auflistung vom Verhalten
Verhalten:
- In Chrome gibt eine Erweiterung die nicht entfernbar ist im Menü, da angeblich über "Unternehmensrichtlinie" installiert. Ist allerdings ein Privat-PC, der nie mit einem Unternehmen verbunden oder eingesetzt ist.
- Beim Download von "Farbar's Recovery Scan Tool" wird Chrome umgeleitet zu "download-web-shield.com" ohne Download (über Firefox wenigstens möglich)
- Windows Defender ist auch via Unternehmensrichtlinie gesperrt. Entsperrrung über Regedit möglich, nach Neustart wieder gesperrt.
- Scans mit AdwCleaner und SpyBot Search und Destroy ausgeführt. AdwCleaner findet auch was, laut Log auch erfolgreich gelöscht, nach Neustart sind die Dateien wieder da und der nächste Scann gibt die gleichen Ergebnis aus.
- Rootkit-Scan von SpyBot hat keine Probleme ausgewiesen.
- Im Log von FRST sind einige Einträge drinnen, wo ich erkenne "es ist was krumm!",
- Aber ich habe den Eindruck, dass wenn nicht alles auf einmal entfernt wird (und zwar mehr als AdwCleaner, SpyBot, Windows Defender macht), dass es nichts bringt (siehe auch AdwCleaner Log). Löschung AdwCleaner Code:
# AdwCleaner 7.0.2.0 - Logfile created on Thu Aug 10 19:15:04 2017
# Updated on 2017/29/08 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support
***** [ Services ] *****
Deleted: OtherSearch
***** [ Folders ] *****
Deleted: C:\Program Files\c4301166122a25c34da96e1ec406d55c
***** [ Files ] *****
Deleted: C:\Windows\SysNative\drivers\LACE_WPF_X64.SYS
Deleted: C:\Windows\SysNative\drivers\Lace_wpf_x64.sys
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks deleted.
***** [ Registry ] *****
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Control\Class\{0C95ABFE-4FB6-49DB-B22F-0E1F5FC4BEEC}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Control\Class\{EEEFACB3-729F-4484-B66D-E7A7917BBFC1}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application
Deleted: [Key] - HKLM\SOFTWARE\OtherSearch
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries deleted.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries deleted.
*************************
::Tracing keys deleted
::Winsock settings cleared
::Prefetch files deleted
::Proxy settings cleared
::IE policies deleted
::Chrome policies deleted
::Additional Actions: 0
*************************
C:/AdwCleaner/AdwCleaner[C0].txt - [10302 B] - [2017/8/7 18:11:2]
C:/AdwCleaner/AdwCleaner[C1].txt - [2448 B] - [2017/8/7 18:29:41]
C:/AdwCleaner/AdwCleaner[C2].txt - [2207 B] - [2017/8/8 20:25:57]
C:/AdwCleaner/AdwCleaner[S0].txt - [12098 B] - [2017/8/7 18:6:15]
C:/AdwCleaner/AdwCleaner[S1].txt - [2495 B] - [2017/8/7 18:26:36]
C:/AdwCleaner/AdwCleaner[S2].txt - [1963 B] - [2017/8/8 20:24:7]
C:/AdwCleaner/AdwCleaner[S3].txt - [2067 B] - [2017/8/10 19:12:17]
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt ########## Nächster Scan nach Neustart Code:
# AdwCleaner 7.0.2.0 - Logfile created on Thu Aug 10 19:16:56 2017
# Updated on 2017/29/08 by Malwarebytes
# Database: 08-09-2017.2
# Running on Windows 10 Home (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
PUP.Adware.Heuristic, C:\Program Files\c4301166122a25c34da96e1ec406d55c
***** [ Files ] *****
PUP.Optional.Legacy, C:\END
PUP.Optional.Legacy, C:\Windows\SysNative\drivers\LACE_WPF_X64.SYS
PUP.Optional.Legacy, C:\Windows\SysNative\drivers\Lace_wpf_x64.sys
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.Legacy, [Key] - HKLM\SYSTEM\CurrentControlSet\Control\Class\{0C95ABFE-4FB6-49DB-B22F-0E1F5FC4BEEC}
PUP.Optional.Legacy, [Key] - HKLM\SYSTEM\CurrentControlSet\Control\Class\{EEEFACB3-729F-4484-B66D-E7A7917BBFC1}
Adware.Amonetize, [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application
Adware.Amonetize, [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application
PUP.Optional.OtherSearch, [Key] - HKLM\SOFTWARE\OtherSearch
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries.
*************************
C:/AdwCleaner/AdwCleaner[C0].txt - [10302 B] - [2017/8/7 18:11:2]
C:/AdwCleaner/AdwCleaner[C1].txt - [2448 B] - [2017/8/7 18:29:41]
C:/AdwCleaner/AdwCleaner[C2].txt - [2207 B] - [2017/8/8 20:25:57]
C:/AdwCleaner/AdwCleaner[C3].txt - [2228 B] - [2017/8/10 19:15:4]
C:/AdwCleaner/AdwCleaner[S0].txt - [12098 B] - [2017/8/7 18:6:15]
C:/AdwCleaner/AdwCleaner[S1].txt - [2495 B] - [2017/8/7 18:26:36]
C:/AdwCleaner/AdwCleaner[S2].txt - [1963 B] - [2017/8/8 20:24:7]
C:/AdwCleaner/AdwCleaner[S3].txt - [2067 B] - [2017/8/10 19:12:17]
########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt ########## Code:
// info: Rootkit removal help file
// copyright: (c) 2008-2017 Safer-Networking Ltd. All rights reserved.
:: RootAlyzer Results
File:"No admin in ACL","S:\Windows\System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask"
File:"No admin in ACL","S:\Windows\System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask"
File:"Unknown ADS","S:\Users\GG\OneDrive:ms-properties:$DATA"
File:"Unknown ADS","S:\Users\GG\OneDrive\Documents:ms-properties:$DATA"
File:"Unknown ADS","S:\Users\GG\OneDrive\Pictures:ms-properties:$DATA"
File:"Unknown ADS","S:\Users\GG\OneDrive\Pictures\Camera Roll:ms-properties:$DATA"
File:"Unknown ADS","S:\Users\GG\OneDrive\Documents\cc_20151025_135741.reg:ms-properties:$DATA"
File:"Unknown ADS","S:\Users\GG\OneDrive\Documents\duplicate.txt:ms-properties:$DATA"
File:"Unknown ADS","S:\Users\GG\OneDrive\Documents\notes LR.rtf:ms-properties:$DATA"
File:"No admin in ACL","S:\ProgramData\Protexis64\KGyGaAvL.sys"
File:"No admin in ACL","S:\ProgramData\Nero\Nero 10\OnlineServices"
File:"Unknown ADS","S:\ProgramData\CyberLink\PowerDVD14\CLDShowX.ini:Update.CL:$DATA"
File:"Unknown ADS","J:\Utilities\Bulk Rename Utility:Win32App_1:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170718_0471.tiff:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0471-2.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0471-3.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0471-5.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0471.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0472-3.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0472.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0473-3.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0473.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","H:\CameraScans\family\170719_0474.tif:3or4kl4x13tuuug3Byamue2s4b:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F:Win32App_1:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A:Win32App_1:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA71301B744CAF070E41400:Win32App_1:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\84b9c17023c712640acaf308593282f8:Win32App_1:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\91785D291CBB3CC40AB8659C8E48CCC2:Win32App_1:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0:Win32App_1:$DATA"
File:"Unknown ADS","C:\Windows\Installer\$PatchCache$\Managed\D20352A90C039D93DBF6126ECE614057:Win32App_1:$DATA"
File:"Unknown ADS","C:\Users\GG\AppData\Local\VirtualStore\Program Files (x86)\Belarc\BelarcAdvisor:Win32App_1:$DATA"
File:"Unknown ADS","C:\ProgramData\Adobe\Adobe PDF:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Adobe:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\LibreOffice 5:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Mozilla Firefox:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Mozilla Thunderbird:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\PDF24:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Photodex Presenter:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Spybot - Search & Destroy 2:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\TeamViewer:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\VideoLAN\VLC:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Photodex\ProShow Gold:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\NVIDIA Corporation\3D Vision:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\NVIDIA Corporation\Update Core:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\LibreOffice 5\help\de:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Google\Chrome\Application:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.5:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\EaseUS\Todo Backup:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Common Files\Adobe:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Common Files\Adobe AIR:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Common Files\Microsoft Shared\VC:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Common Files\Microsoft Shared\VC\amd64:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\WebKit:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Common Files\Adobe\ARM\1.0:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\Easy-WebPrint EX:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\IJ Scan Utility:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\My Image Garden:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\Quick Menu:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\Speed Dial Utility:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Canon\My Image Garden\AddOn:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Adobe\Acrobat Reader DC:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Adobe\Adobe Content Viewer:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Adobe\Adobe Help:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files (x86)\Adobe\Adobe Sync:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\7-Zip:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Adobe:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Affinity:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\LibreOffice 5:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\PTGui:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\TeraCopy:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\UNP:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Realtek\Audio\HDA:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Control Panel Client:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Display.NvContainer:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{77847ABF-6A26-4402-93AE-EB47DB9DDFAD}:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Installer2\Display.Update.{10769156-9E15-47FD-906E-CFBF70187C89}:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{A0DECFF8-DEC8-44AD-904F-B266CAC2260B}:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\NVIDIA Corporation\Installer2\NVDisplayContainerLS.{D21B21C1-3037-41D5-A0FB-419711922AB5}:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Malwarebytes\Anti-Malware:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Intel\BCA:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Common Files\microsoft shared\VC:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Common Files\Intel\RSSDK\v3:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Common Files\Intel\RSSDK\v3\bin\x64:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Canon\MyPrinter:Win32App_1:$DATA"
File:"Unknown ADS","C:\Program Files\Adobe\Adobe Photoshop CC 2017:Win32App_1:$DATA"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\WOW6432Node\Microsoft\Security Center\","Svc"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\WOW6432Node\Microsoft\Security Center\Svc\","Upgrade"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\WOW6432Node\Microsoft\InputMethod\Chs\","DuState"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Microsoft\Security Center\Svc\","Upgrade"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Microsoft\InputMethod\Chs\","DuState" Ich danke im Voraus.
Wenn es nichts zu retten gibt, und Neuinstallation das beste ist, bitte Bescheid geben. |