![]() |
Click Compare Trojaner in Firefox 27.0.1 ? Hallo zusammen, seit einer Woche erscheinen auf beliebigen Internet-Seiten kleine grüne Symbole, die das Lesen zunehmend behindern. Ausserdem taucht trtotz AdBlock vermehrt Werbung auf. Eigene Bereigungsversuche u.a. mit - Malwarebytes' Anti Malware - ESET Online Scan blieben bisher erfolglos. Ich hoffe, daß Ihr mir weiterhelfen könnt; vielen Dank dafür schon mal im Voraus! Das aktuellste Malwarebytes Logfile habe ich noch beigefügt. |
:hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Hallo Matthias, erstmal ein grosses Danke, dass Du so schnell reagiert hast. Beigefügt ist die [CODE] FRST.txt ################################# FRST Logfile: [CODE]Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-02-2014 02 Ran by fricke_h (administrator) on UESE001 on 01-03-2014 12:21:27 Running from C:\download Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\tools\MSI Afterburner\MSIAfterburner.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\tools\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\tools\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Malwarebytes Corporation) C:\tools\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe () C:\tools\Razer\DeathAdder\razerhid.exe (Razer USA Ltd.) C:\tools\Razer\Razer Lycosa\razerhid.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE () C:\tools\Razer\DeathAdder\razertra.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Razer Inc.) C:\tools\Razer\DeathAdder\razerofa.exe () C:\tools\Razer\DeathAdder\vdDaemon.exe () C:\tools\Razer\Razer Lycosa\razertra.exe (CANON INC.) C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE () C:\tools\MagicTune Premium\MagicTuneEngine.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Apple Inc.) C:\Program Files\QuickTime\QTTask.exe (SEC) C:\tools\MagicTune Premium\MagicTune.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\tools\MagicTune Premium\GammaTray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Crystal Dew World) C:\tools\CrystalDiskInfo\DiskInfo.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 2003\OFFICE11\OUTLOOK.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] () HKLM\...\Run: [DeathAdder] - C:\tools\Razer\DeathAdder\razerhid.exe [248832 2012-01-14] () HKLM\...\Run: [Lycosa] - C:\tools\Razer\Razer Lycosa\razerhid.exe [233984 2011-03-21] (Razer USA Ltd.) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.) HKLM\...\Run: [AMD AVT] - C:\Program Files\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2516296 2010-03-25] (CANON INC.) HKLM\...\Run: [CanonSolutionMenuEx] - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.) HKLM\...\Run: [MagicTuneEngine] - C:\tools\MagicTune Premium\MagicTuneEngine.exe [58368 2009-05-08] () HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM\...\Command Processor: <======= ATTENTION HKU\.DEFAULT\...\Run: [StartUp This] - C:\Program Files\Laplink\PCmover\LaunchSt.exe [251184 2009-09-17] (Laplink Software, Inc.) HKU\S-1-5-19\...\Run: [StartUp This] - C:\Program Files\Laplink\PCmover\LaunchSt.exe [251184 2009-09-17] (Laplink Software, Inc.) HKU\S-1-5-20\...\Run: [StartUp This] - C:\Program Files\Laplink\PCmover\LaunchSt.exe [251184 2009-09-17] (Laplink Software, Inc.) HKU\S-1-5-21-2916557675-37569280-243032172-1000\...\Run: [NCsoft Launcher] - C:\Program Files\NCsoft\Launcher\NCLauncher.exe [43304 2013-06-06] (NCSOFT) HKU\S-1-5-21-2916557675-37569280-243032172-1000\...\Run: [Spiele Post] - C:\Program Files\OXXOGames\GPlayer\GameCenterNotifier.exe HKU\S-1-5-21-2916557675-37569280-243032172-1000\...\Run: [Alamandi tray notifier] - c:\program files\deutschland spielt\alamandi\TaskBarNotifier.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKLM - RealoreStudios Toolbar - {03fee850-0101-4e9e-b6d4-6fc74d3db360} - C:\Program Files\RealoreStudios\tbReal.dll (Conduit Ltd.) URLSearchHook: HKCU - RealoreStudios Toolbar - {03fee850-0101-4e9e-b6d4-6fc74d3db360} - C:\Program Files\RealoreStudios\tbReal.dll (Conduit Ltd.) SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2412158 SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2412158 SearchScopes: HKCU - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2412158 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=110819&tt=060612_7_&babsrc=SP_ss&mntrId=38ee726e000000000000001d7d07e43d SearchScopes: HKCU - {6C595A61-FAAD-460E-A0A7-11AC0588F2DF} URL = hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000 SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2412158 SearchScopes: HKCU - {C7576B9D-B442-46bc-AF74-080A9E723E01} URL = hxxp://websearch.search-results.com/redirect?client=ie&tb=STC-SRS&o=41648033&src=crm&q={searchTerms}&locale=&apn_ptnrs=96&apn_dtid=YYYYYYYYDE&apn_uid=D9D51EAD-8EB7-40E8-BED0-E6FBE8F2AC2A&apn_sauid=97B9D0D2-5526-43C1-B051-2F118A3190F9& BHO: RealoreStudios Toolbar - {03fee850-0101-4e9e-b6d4-6fc74d3db360} - C:\Program Files\RealoreStudios\tbReal.dll (Conduit Ltd.) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files\Softonic\Softonic\1.8.21.14\bh\Softonic.dll (Softonic.com) Toolbar: HKLM - RealoreStudios Toolbar - {03fee850-0101-4e9e-b6d4-6fc74d3db360} - C:\Program Files\RealoreStudios\tbReal.dll (Conduit Ltd.) Toolbar: HKLM - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll (Softonic.com) Toolbar: HKCU - RealoreStudios Toolbar - {03FEE850-0101-4E9E-B6D4-6FC74D3DB360} - C:\Program Files\RealoreStudios\tbReal.dll (Conduit Ltd.) DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://go.microsoft.com/fwlink/?linkid=58813 DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233389859546 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - No File ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\..\Interfaces\{8DF88316-8B29-4D84-A1D6-182559EF8ED9}: [NameServer]192.168.100.99 Tcpip\..\Interfaces\{973585A1-BC56-4D55-80C6-F8A919BACDC9}: [NameServer]192.168.100.99 FireFox: ======== FF ProfilePath: C:\Users\fricke_h\AppData\Roaming\Mozilla\Firefox\C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-2916557675-37569280-243032172-1000\FireFox FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: Adobe Reader - C:\tools\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2013-02-08] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-12-06] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-12-06] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-12-06] FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-12-06] FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-12-06] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird ========================== Services (Whitelisted) ================= R2 avp; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 MBAMScheduler; C:\tools\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\tools\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R3 danewFltr; C:\Windows\System32\drivers\danew.sys [9856 2010-02-08] (Razer (Asia-Pacific) Pte Ltd) R0 jraid; C:\Windows\System32\DRIVERS\jraid.sys [83296 2008-11-04] (JMicron Technology Corp.) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-12-06] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-02-17] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576096 2014-02-17] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-02-17] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2013-12-18] (Kaspersky Lab ZAO) R3 LycoFltr; C:\Windows\System32\Drivers\Lycosa.sys [23680 2010-09-08] (Razer USA Ltd.) R1 MagicTune; C:\Windows\system32\drivers\MTiCtwl.sys [14848 2009-11-18] (Samsung Electronics, Inc. ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 RTCore32; C:\tools\MSI Afterburner\RTCore32.sys [5632 2011-09-06] () R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2011-06-15] (Realtek ) S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2011-06-15] (Realtek Corporation) S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan620.sys [27752 2011-09-16] (Realtek Corporation) S3 SIVDriver; C:\Windows\system32\Drivers\SIVX32.sys [99136 2012-07-14] (Ray Hinchliffe) S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2011-06-15] (Realtek Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-01 12:21 - 2014-03-01 12:21 - 00000000 ____D () C:\FRST 2014-02-26 07:54 - 2014-02-27 07:38 - 00000000 ____D () C:\Program Files\ESET 2014-02-25 21:01 - 2014-02-25 21:01 - 00000814 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-02-25 21:01 - 2014-02-25 21:01 - 00000000 ____D () C:\Users\fricke_h\AppData\Roaming\Malwarebytes 2014-02-25 21:01 - 2014-02-25 21:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-25 21:01 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-15 16:56 - 2014-02-15 16:56 - 00000000 ____D () C:\ProgramData\ATI 2014-02-15 09:20 - 2014-02-16 19:36 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-12 03:06 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 03:06 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 03:06 - 2014-02-06 11:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 03:06 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 03:06 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 03:06 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 03:06 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 03:06 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 03:06 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 03:06 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 03:06 - 2014-02-06 10:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 03:06 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 03:06 - 2014-02-06 10:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 03:06 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 03:06 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 03:06 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 03:06 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 03:06 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 03:06 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 03:06 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 03:06 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 03:02 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 02:02 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 02:02 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 02:02 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 02:02 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 02:02 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 02:02 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 02:02 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 02:02 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 02:02 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 02:02 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 02:02 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 02:02 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 02:02 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 02:02 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-10 19:09 - 2014-02-10 19:09 - 00000862 _____ () C:\Users\fricke_h\Desktop\Mozilla Firefox.lnk 2014-02-06 08:45 - 2014-02-06 10:01 - 00000000 ____D () C:\ProgramData\iolo 2014-02-06 08:45 - 2014-02-06 08:45 - 00074703 _____ () C:\Windows\system32\mfc45.dat 2014-02-06 08:45 - 2014-02-06 08:45 - 00000000 ____D () C:\Program Files\iolo ==================== One Month Modified Files and Folders ======= 2014-03-01 12:21 - 2014-03-01 12:21 - 00000000 ____D () C:\FRST 2014-03-01 12:21 - 2013-02-05 17:22 - 00000000 ____D () C:\download 2014-03-01 11:27 - 2012-09-01 14:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-01 10:46 - 2013-02-08 22:22 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-03-01 09:42 - 2009-07-14 05:34 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-01 09:42 - 2009-07-14 05:34 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-01 09:20 - 2013-02-05 16:22 - 01330719 _____ () C:\Windows\WindowsUpdate.log 2014-03-01 09:16 - 2013-02-13 17:05 - 00043770 _____ () C:\Windows\setupact.log 2014-03-01 09:16 - 2013-02-13 17:04 - 00175660 _____ () C:\Windows\PFRO.log 2014-03-01 09:16 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-27 07:38 - 2014-02-26 07:54 - 00000000 ____D () C:\Program Files\ESET 2014-02-26 03:13 - 2013-02-08 22:27 - 00000000 ___HD () C:\Windows\ie8 2014-02-26 03:09 - 2013-02-08 22:49 - 00000000 ____D () C:\Users\fricke_h\AppData\Roaming\Toolbar4 2014-02-26 03:09 - 2013-02-08 22:25 - 00000000 ____D () C:\Program Files\SweetIM 2014-02-26 03:01 - 2010-11-20 22:01 - 01729778 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-25 21:21 - 2013-02-05 16:18 - 00000000 ____D () C:\Windows\Panther 2014-02-25 21:01 - 2014-02-25 21:01 - 00000814 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-02-25 21:01 - 2014-02-25 21:01 - 00000000 ____D () C:\Users\fricke_h\AppData\Roaming\Malwarebytes 2014-02-25 21:01 - 2014-02-25 21:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-25 21:01 - 2013-02-05 17:48 - 00000000 ____D () C:\tools 2014-02-21 07:27 - 2013-02-18 16:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-21 07:27 - 2012-06-09 04:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-17 10:05 - 2013-10-17 15:47 - 00576096 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-02-17 10:05 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-02-17 10:05 - 2013-06-08 20:18 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-02-16 19:38 - 2013-02-05 17:14 - 00000000 ____D () C:\Users\fricke_h 2014-02-16 19:38 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\wfp 2014-02-16 19:37 - 2013-10-15 06:54 - 00000000 ____D () C:\Users\DefaultAppPool.IIS APPPOOL 2014-02-16 19:37 - 2013-02-08 22:21 - 00000000 ____D () C:\Users\Administrator 2014-02-16 19:36 - 2014-02-15 09:20 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-16 19:36 - 2013-04-21 10:19 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-16 19:36 - 2013-02-05 19:37 - 00000000 ____D () C:\Users\fricke_h\AppData\Roaming\Razer 2014-02-16 19:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-02-16 19:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-02-16 19:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-16 19:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\AppCompat 2014-02-16 19:35 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\registration 2014-02-16 19:32 - 2013-02-08 22:24 - 00000000 ____D () C:\Program Files\Java 2014-02-16 19:32 - 2013-02-07 21:43 - 00000000 ____D () C:\Program Files\AMD AVT 2014-02-16 19:32 - 2013-02-05 17:25 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-02-15 16:56 - 2014-02-15 16:56 - 00000000 ____D () C:\ProgramData\ATI 2014-02-15 16:56 - 2013-02-05 17:26 - 00000000 ____D () C:\ProgramData\AMD 2014-02-15 09:06 - 2013-02-09 10:15 - 00000000 ____D () C:\Users\fricke_h\Documents\Guild Wars 2 2014-02-15 09:05 - 2013-09-18 12:30 - 00000000 ____D () C:\Users\fricke_h\AppData\Roaming\Guild Wars 2 2014-02-12 03:06 - 2013-08-09 06:59 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-12 03:03 - 2009-01-22 19:34 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-10 19:09 - 2014-02-10 19:09 - 00000862 _____ () C:\Users\fricke_h\Desktop\Mozilla Firefox.lnk 2014-02-06 11:38 - 2014-02-12 03:06 - 17103872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 11:20 - 2014-02-12 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 11:19 - 2014-02-12 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 11:01 - 2014-02-12 03:06 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 11:00 - 2014-02-12 03:06 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-12 03:06 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 10:52 - 2014-02-12 03:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 10:52 - 2014-02-12 03:06 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 10:49 - 2014-02-12 03:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 10:47 - 2014-02-12 03:06 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 10:47 - 2014-02-12 03:06 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 10:46 - 2014-02-12 03:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 10:34 - 2014-02-12 03:06 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 10:25 - 2014-02-12 03:06 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 10:25 - 2014-02-12 03:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 10:13 - 2014-02-12 03:06 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:09 - 2014-02-12 03:06 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:03 - 2014-02-12 03:06 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:01 - 2014-02-06 08:45 - 00000000 ____D () C:\ProgramData\iolo 2014-02-06 09:41 - 2014-02-12 03:06 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 09:36 - 2014-02-12 03:06 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:34 - 2014-02-12 03:06 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 08:45 - 2014-02-06 08:45 - 00074703 _____ () C:\Windows\system32\mfc45.dat 2014-02-06 08:45 - 2014-02-06 08:45 - 00000000 ____D () C:\Program Files\iolo Files to move or delete: ==================== C:\Users\fricke_h\FilterData.dat Some content of TEMP: ==================== C:\Users\fricke_h\AppData\Local\Temp\autorun.dll C:\Users\fricke_h\AppData\Local\Temp\InstHelper.exe C:\Users\fricke_h\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\fricke_h\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\fricke_h\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\fricke_h\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\fricke_h\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\fricke_h\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\fricke_h\AppData\Local\Temp\LISTOOL.EXE C:\Users\fricke_h\AppData\Local\Temp\RealoreStudios.exe C:\Users\fricke_h\AppData\Local\Temp\SCC.dll C:\Users\fricke_h\AppData\Local\Temp\tbReal.dll C:\Users\fricke_h\AppData\Local\Temp\_inst1.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-28 00:16 ################# und die Addition.txt #################FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-02-2014 02 --- --- --- |
Servus, wir beginnen erst mal so: Scan mit Combofix
|
Hallo Matthias, dein Reaktionszeiten sind ja wirklich super. Beigefügt ist das COMBOFIX Log-File, wobei KIS2014 deaktiviert war. COMBOFIX hat auch nicht gemeckert. Combofix Logfile: Code: ComboFix 14-02-24.02 - fricke_h 01.03.2014 13:00:55.1.4 - x86 A36C5E4F47E84449FF07ED3517B43A31 [/CODE] |
Servus, Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Schritt 4 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Bitte poste mit deiner nächsten Antwort
|
Hallo Matthias, beigefügt sind: Logdatei von AdwCleaner Code: # AdwCleaner v3.020 - Bericht erstellt am 02/03/2014 um 16:09:05 Code: # AdwCleaner v3.020 - Bericht erstellt am 02/03/2014 um 16:10:08 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code: Malwarebytes Anti-Malware (Test) 1.75.0.1300 Code: Zoek.exe v5.0.0.0 Updated 19-February-2014 |
Servus, Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu einen Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
Hallo Matthias, zunächst das 1. LogFile von FRST: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-03-2014 2. LogFile FRST Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-03-2014 Code: SystemLook 30.07.11 by jpshortstuff Code: Protokollname: System |
Servus, Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss daran räumen wir auf und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: start Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
Guten Morgen Matthias, nachfolgend die Logdatei von FRST: Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-03-2014 HitmanPro: Bei HitmanPro kann man am Ende weder gefundene Schadsoftware entfernen noch eine Logdatei erzeugen, ohne dass man eine kostenlose 30-Tage-Lizenz erworben und diese aktiviert hat. Danach funktioniert aber alles problemlos. Ich habe allerdings 3 Versuche benötigt, um alles zu löschen. 1. Textfile HitmanPro: Code: HitmanPro 3.7.9.212 Code: HitmanPro 3.7.9.212 Code:
|
Servus, gut gemacht. :) Fehlen nur noch die Logdateien von ESET und SecurityCheck. |
Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:42 Uhr. |
Copyright ©2000-2025, Trojaner-Board