Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Avast springt auf einmal auf "läuft..." keine Internetverbindung (https://www.trojaner-board.de/171906-avast-springt-einmal-laeuft-keine-internetverbindung.html)

lorey 23.10.2015 19:03

Bei dem ersten Schritt habe ich leider schon Probleme. Beim ersten Versuch stad auf dem Programm selbst (keine Rückmeldung), Strg, Alt und Entf funktionierte nicht, herunterfahren ging auch nicht. Habe den Stecker gezogen.

Neustart und neuer Versuch, aber das Fenster des Programms ist nicht zu bewegen. Er erstellt ganz schön lange einen Wiederherstellungspunkt.:confused:

M-K-D-B 24.10.2015 10:38

Zitat:

Zitat von lorey (Beitrag 1528378)
Beim ersten Versuch stad auf dem Programm selbst (keine Rückmeldung)

Und da hättest du einfach warten und nichts tun sollen.... es kann schon einige Minuten dauern, bis FRST fertig ist... das ist nichts Ungewöhnliches.

Gib mir Bescheid, wenn die Systemwiederherstellung abgeschlossen ist.

lorey 27.10.2015 20:05

Wie lange soll ich denn warten? Das Programm läuft seit 5 Stunden, seit 4,5 Stunden steht da "entfernen wird durchgeführt". Ich finde das etwas zu lang

M-K-D-B 28.10.2015 16:19

Von Stunden hat niemand was gesagt, wenn nach 10 Minuten nichts geht, dann lass es gut sein. ;)

Wurde eine fixlog.txt von FRST erstellt? (C:\FRST\Logs\fixlog.txt) Wenn ja, poste mir deren Inhalt bitte.

Bitte weiter mit den anderen Schritten.

lorey 29.10.2015 15:41

Hallo,

dann haben wir uns missverstanden, ich habe schon beim ersten Mal natürlich länger gewartet.

Leider wurde kein fixlog erstellt.

Ich habe Hitman aus Versehen nicht aufs Desktop geladen, ist das schlimm?
Code:


       
Code:

       
HitmanPro 3.7.10.250
www.hitmanpro.com

   Computer name . . . . : MEINPC-PC
   Windows . . . . . . . : 6.1.1.7601.X64/2
   User name . . . . . . : Meinpc-PC\Meinpc
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2015-10-29 14:58:53
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 6m 25s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 5

   Objects scanned . . . : 1.502.023
   Files scanned . . . . : 44.454
   Remnants scanned  . . : 338.776 files / 1.118.793 keys

Suspicious files ____________________________________________________________

   C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WSQR4JC\FRST64[1].exe
      Size . . . . . . . : 2.197.504 bytes
      Age  . . . . . . . : 2.1 days (2015-10-27 13:33:18)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : C4A53C155BD170DB89D19ABCA61CB00E9DBEB7EACD2F98C184B62213618784CB
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
         -0.3s C:\Users\Meinpc\AppData\Roaming\Microsoft\Windows\Cookies\57JKIRJR.txt
         -0.3s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41NUBSCX\82[1].htm
          0.0s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WSQR4JC\FRST64[1].exe
          0.0s C:\Users\Meinpc\Desktop\FRST64.exe
         12.4s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WSQR4JC\up64[2]

   C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FKM2IY8G\FRST64[1].exe
      Size . . . . . . . : 2.196.992 bytes
      Age  . . . . . . . : 8.9 days (2015-10-20 17:58:44)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 5A08C26FE732502F3812AE5F297D676EED72307534EEB08544C5A5D825616080
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 23.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
         -0.3s C:\Users\Meinpc\AppData\Roaming\Microsoft\Windows\Cookies\46WTXYC0.txt
          0.0s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FKM2IY8G\FRST64[1].exe
          2.7s C:\Users\Meinpc\Desktop\FRST-OlderVersion\

   C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HOZGX5DH\FRST64[1].exe
      Size . . . . . . . : 2.196.480 bytes
      Age  . . . . . . . : 5.9 days (2015-10-23 17:34:00)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A6CE58B50CA37F34060EF79D4A9D62EBDDBF53CDE7F047E58279B8A755CC81AE
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.

   C:\Users\Meinpc\Desktop\FRST-OlderVersion\FRST64.exe
      Size . . . . . . . : 2.196.480 bytes
      Age  . . . . . . . : 20.0 days (2015-10-09 14:12:21)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A6CE58B50CA37F34060EF79D4A9D62EBDDBF53CDE7F047E58279B8A755CC81AE
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 23.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.

   C:\Users\Meinpc\Desktop\FRST64.exe
      Size . . . . . . . : 2.197.504 bytes
      Age  . . . . . . . : 2.1 days (2015-10-27 13:33:18)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : C4A53C155BD170DB89D19ABCA61CB00E9DBEB7EACD2F98C184B62213618784CB
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
         -0.3s C:\Users\Meinpc\AppData\Roaming\Microsoft\Windows\Cookies\57JKIRJR.txt
         -0.3s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\41NUBSCX\82[1].htm
         -0.0s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WSQR4JC\FRST64[1].exe
          0.0s C:\Users\Meinpc\Desktop\FRST64.exe
         12.4s C:\Users\Meinpc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WSQR4JC\up64[2]



Code:

Farbar Service Scanner Version: 26-07-2015
Ran by Meinpc (administrator) on 29-10-2015 at 15:31:29
Running from "C:\Users\Meinpc\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****


M-K-D-B 30.10.2015 21:59

Servus,


wie läuft der Rechner aktuell?

Gibt es noch Probleme? Wenn ja, welche?

M-K-D-B 03.11.2015 09:20

Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:34 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131