Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Firefox langsam, friert ein, Umleitung zu unerwünschten Seiten (https://www.trojaner-board.de/96361-firefox-langsam-friert-umleitung-unerwuenschten-seiten.html)

bartolo 11.03.2011 14:22

Keine Veränderung... da hilft wohl langsam nur noch Windows neu installieren...

cosinus 11.03.2011 14:32

Irgendwas muss ich übersehen haben. Ich will den Router ausschließen, obwohl du sagtest, dass es an ihm nicht liegt.

Klick mal bitte in der Systemsteuerung dahin, um die Adaptereinstellungen deines WLAN-Adapters zu ändern. Rechtsklick auf den WLAN-Adapter => Eigenschaften. Doppelklick auf TCP/IP Version 4. Lass die Adresse auf automatisch beziehen (DHCP) aber die beiden unteren trägst du manuell IP-Adressen ein, nämlich die von OpenDNS:

1. DNS-Server: 208.67.222.222
2. DNS-Server: 208.67.220.220

bartolo 11.03.2011 21:03

Leider keine Besserung...

cosinus 12.03.2011 12:21

Hm, das gibts doch nicht :balla:
Führe bitte nochmal CF mit einer neue cofi aus. Siehe obige Anleitung.

bartolo 12.03.2011 13:48

Ok, cf ist nochmal durchgelaufen. Hier der log.

(By the way: bis hierher schon mal vielen, vielen Dank, dass Du Dir so viele Gedanken machst. Tut mir leid, dass das so viel Zeit in Anspruch nimmt!)




Combofix Logfile:
Code:

ComboFix 11-03-11.02 - Max 12.03.2011  13:39:04.2.2 - x64
Microsoft Windows 7 Home Premium  6.1.7600.0.1252.49.1031.18.4061.2721 [GMT 1:00]
ausgeführt von:: c:\users\Max\Desktop\cofi.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-02-12 bis 2011-03-12  ))))))))))))))))))))))))))))))
.
.
2011-03-12 12:43 . 2011-03-12 12:43        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-03-11 10:44 . 2011-03-11 10:44        --------        d-----w-        c:\users\Test
2011-03-11 08:03 . 2011-02-11 07:30        7947600        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{50F5EB9F-E0F8-421E-ABEB-05B6AE071F47}\mpengine.dll
2011-03-10 13:55 . 2011-03-10 13:55        --------        d-----w-        c:\users\Max\AppData\Roaming\SUPERAntiSpyware.com
2011-03-10 13:55 . 2011-03-10 13:55        --------        d-----w-        c:\programdata\SUPERAntiSpyware.com
2011-03-10 13:54 . 2011-03-10 13:54        --------        d-----w-        c:\programdata\!SASCORE
2011-03-10 13:54 . 2011-03-10 13:55        --------        d-----w-        c:\program files\SUPERAntiSpyware
2011-03-08 19:21 . 2011-03-08 19:21        --------        d-----w-        c:\program files\CCleaner
2011-03-08 11:27 . 2011-03-08 11:27        --------        d-----w-        c:\users\Max\AppData\Roaming\Malwarebytes
2011-03-08 11:27 . 2010-12-20 17:09        38224        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-08 11:27 . 2011-03-08 11:27        --------        d-----w-        c:\programdata\Malwarebytes
2011-03-08 11:27 . 2011-03-08 11:27        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-08 11:27 . 2010-12-20 17:08        24152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-03-05 17:02 . 2011-03-05 17:02        --------        d-----w-        c:\users\Max\AppData\Roaming\Buhl Data Service
2011-03-05 17:01 . 2011-03-05 17:02        --------        d-----w-        c:\users\Max\AppData\Local\Buhl
2011-03-05 17:00 . 2011-03-05 17:00        --------        d-----w-        c:\program files (x86)\WISO
2011-03-05 16:59 . 2011-03-05 17:02        --------        d-----w-        c:\programdata\Buhl Data Service GmbH
2011-03-05 16:59 . 2011-03-05 16:59        --------        d-----w-        c:\users\Max\AppData\Local\Buhl Data Service
2011-02-23 08:52 . 2010-09-14 06:45        367104        ----a-w-        c:\windows\system32\wcncsvc.dll
2011-02-23 08:52 . 2010-09-14 06:07        276992        ----a-w-        c:\windows\SysWow64\wcncsvc.dll
2011-02-23 07:28 . 2011-01-07 08:07        662528        ----a-w-        c:\windows\system32\XpsPrint.dll
2011-02-23 07:28 . 2011-01-07 07:31        442880        ----a-w-        c:\windows\SysWow64\XpsPrint.dll
2011-02-23 07:28 . 2011-01-07 08:07        475648        ----a-w-        c:\windows\system32\XpsGdiConverter.dll
2011-02-23 07:28 . 2011-01-07 07:31        288256        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-22 21:17 . 2011-03-12 12:33        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2011-02-22 21:17 . 2011-02-23 08:27        --------        d-----w-        c:\program files (x86)\Spybot - Search & Destroy
2011-02-18 22:11 . 2011-02-18 22:11        --------        d-----w-        c:\programdata\DivX
2011-02-18 22:09 . 2011-02-18 22:09        51200        ----a-w-        c:\windows\system32\pdh32.dll
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-11 07:30 . 2011-01-19 19:10        7947600        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-01-26 06:53 . 2011-02-10 06:44        982912        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:53 . 2011-02-10 06:44        265088        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:31 . 2011-02-10 06:44        144384        ----a-w-        c:\windows\system32\cdd.dll
2011-01-18 16:45 . 2011-01-18 16:45        601424        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{ABC97789-A918-4940-BE7E-D0970AD63890}\gapaengine.dll
2011-01-07 08:06 . 2011-02-10 06:44        46080        ----a-w-        c:\windows\system32\atmlib.dll
2011-01-07 07:27 . 2011-02-10 06:44        34304        ----a-w-        c:\windows\SysWow64\atmlib.dll
2011-01-07 05:49 . 2011-02-10 06:44        366080        ----a-w-        c:\windows\system32\atmfd.dll
2011-01-07 05:33 . 2011-02-10 06:44        294400        ----a-w-        c:\windows\SysWow64\atmfd.dll
2011-01-05 06:20 . 2011-02-10 06:44        612352        ----a-w-        c:\windows\system32\vbscript.dll
2011-01-05 05:37 . 2011-02-10 06:44        428032        ----a-w-        c:\windows\SysWow64\vbscript.dll
2011-01-05 04:00 . 2011-02-10 06:44        3127808        ----a-w-        c:\windows\system32\win32k.sys
2010-12-21 06:16 . 2011-02-10 06:44        62976        ----a-w-        c:\windows\system32\wscapi.dll
2010-12-21 06:16 . 2011-02-10 06:44        97280        ----a-w-        c:\windows\system32\wscsvc.dll
2010-12-21 06:16 . 2011-02-10 06:44        214016        ----a-w-        c:\windows\system32\winsrv.dll
2010-12-21 06:16 . 2011-02-10 06:44        442880        ----a-w-        c:\windows\system32\winhttp.dll
2010-12-21 06:16 . 2011-02-10 06:44        1197056        ----a-w-        c:\windows\system32\wininet.dll
2010-12-21 06:16 . 2011-02-10 06:44        258048        ----a-w-        c:\windows\system32\WebClnt.dll
2010-12-21 06:15 . 2011-02-10 06:44        264192        ----a-w-        c:\windows\system32\upnp.dll
2010-12-21 06:15 . 2011-02-10 06:44        15360        ----a-w-        c:\windows\system32\slwga.dll
2010-12-21 06:13 . 2011-02-10 06:44        2003968        ----a-w-        c:\windows\system32\msxml6.dll
2010-12-21 06:13 . 2011-02-10 06:44        1880576        ----a-w-        c:\windows\system32\msxml3.dll
2010-12-21 06:10 . 2011-02-10 06:44        100864        ----a-w-        c:\windows\system32\davclnt.dll
2010-12-21 05:38 . 2011-02-10 06:44        51200        ----a-w-        c:\windows\SysWow64\wscapi.dll
2010-12-21 05:38 . 2011-02-10 06:44        981504        ----a-w-        c:\windows\SysWow64\wininet.dll
2010-12-21 05:38 . 2011-02-10 06:44        350720        ----a-w-        c:\windows\SysWow64\winhttp.dll
2010-12-21 05:38 . 2011-02-10 06:44        204800        ----a-w-        c:\windows\SysWow64\WebClnt.dll
2010-12-21 05:38 . 2011-02-10 06:44        204288        ----a-w-        c:\windows\SysWow64\upnp.dll
2010-12-21 05:38 . 2011-02-10 06:44        14336        ----a-w-        c:\windows\SysWow64\slwga.dll
2010-12-21 05:36 . 2011-02-10 06:44        1389568        ----a-w-        c:\windows\SysWow64\msxml6.dll
2010-12-21 05:36 . 2011-02-10 06:44        1236992        ----a-w-        c:\windows\SysWow64\msxml3.dll
2010-12-21 05:34 . 2011-02-10 06:44        80384        ----a-w-        c:\windows\SysWow64\davclnt.dll
2010-12-18 06:11 . 2011-02-10 06:44        57856        ----a-w-        c:\windows\system32\licmgr10.dll
2010-12-18 06:11 . 2011-02-10 06:44        714752        ----a-w-        c:\windows\system32\kerberos.dll
2010-12-18 05:29 . 2011-02-10 06:44        44544        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2010-12-18 05:29 . 2011-02-10 06:44        541184        ----a-w-        c:\windows\SysWow64\kerberos.dll
2010-12-18 04:55 . 2011-02-10 06:44        482816        ----a-w-        c:\windows\system32\html.iec
2010-12-18 04:20 . 2011-02-10 06:44        386048        ----a-w-        c:\windows\SysWow64\html.iec
2010-12-18 04:13 . 2011-02-10 06:44        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2010-12-18 03:47 . 2011-02-10 06:44        1638912        ----a-w-        c:\windows\SysWow64\mshtml.tlb
.
.
(((((((((((((((((((((((((((((  SnapShot@2011-03-08_19.37.45  )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-11 20:54 . 2011-03-11 20:54        13294              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-03-08 11:35 . 2011-03-08 11:35        13294              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 04:54 . 2011-03-12 07:27        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-03-08 11:36        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-03-08 11:36        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-12 07:27        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-12 07:27        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-08 11:36        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-13 02:11 . 2011-03-11 13:18        35554              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-03-12 07:29        37966              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-11-15 11:02 . 2011-03-12 07:29        10044              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3918243433-2482154821-786915770-1001_UserData.bin
+ 2010-11-08 13:12 . 2011-03-11 10:53        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-08 13:12 . 2011-03-08 19:21        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-11-08 13:12 . 2011-03-11 10:53        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-11-08 13:12 . 2011-03-08 19:21        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-08 19:21        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-11 10:53        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-11-15 11:09 . 2011-03-08 11:36        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-11-15 11:09 . 2011-03-12 07:27        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:46 . 2011-03-11 07:59        80352              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-02-22 07:17 . 2011-03-08 11:37        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2011-02-22 07:17 . 2011-03-12 07:28        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2011-02-22 07:17 . 2011-03-08 11:37        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2011-02-22 07:17 . 2011-03-12 07:28        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2011-02-22 07:17 . 2011-03-12 07:28        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2011-02-22 07:17 . 2011-03-08 11:37        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2010-11-15 11:09 . 2011-03-08 11:37        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-11-15 11:09 . 2011-03-12 07:28        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-11-15 11:09 . 2011-03-08 11:36        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-15 11:09 . 2011-03-12 07:27        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-15 11:05 . 2011-03-12 12:27        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-15 11:05 . 2011-03-08 19:13        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-15 11:05 . 2011-03-08 19:13        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-15 11:05 . 2011-03-12 12:27        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-11-15 23:02 . 2011-03-06 20:35        3716              c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2010-11-15 23:02 . 2011-03-11 20:54        3716              c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2010-11-16 10:08 . 2011-03-11 10:50        8192              c:\windows\system32\Microsoft\Protect\Recovery\Recovery.dat
- 2010-11-16 10:08 . 2010-11-16 10:09        8192              c:\windows\system32\Microsoft\Protect\Recovery\Recovery.dat
+ 2011-03-12 07:27 . 2011-03-12 07:27        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-03-08 11:36 . 2011-03-08 11:36        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-03-12 07:27 . 2011-03-12 07:27        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-03-08 11:36 . 2011-03-08 11:36        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-09 16:59 . 2010-12-23 05:28        850432              c:\windows\SysWOW64\sbe.dll
- 2009-07-14 00:06 . 2009-07-14 01:16        850432              c:\windows\SysWOW64\sbe.dll
+ 2011-03-11 07:53 . 2011-03-11 07:53        234656              c:\windows\SysWOW64\Macromed\Flash\FlashUtil10n_ActiveX.exe
+ 2011-03-11 07:53 . 2011-03-11 07:53        311456              c:\windows\SysWOW64\Macromed\Flash\FlashUtil10n_ActiveX.dll
+ 2011-03-09 16:59 . 2010-12-23 05:28        534528              c:\windows\SysWOW64\EncDec.dll
- 2009-07-14 00:41 . 2009-07-14 01:16        534528              c:\windows\SysWOW64\EncDec.dll
+ 2011-03-09 16:59 . 2011-02-19 05:32        739840              c:\windows\SysWOW64\d2d1.dll
- 2011-01-12 19:28 . 2010-11-02 04:35        739840              c:\windows\SysWOW64\d2d1.dll
+ 2011-03-09 16:59 . 2010-12-23 05:28        642048              c:\windows\SysWOW64\CPFilters.dll
+ 2010-11-15 17:16 . 2011-03-12 12:24        236690              c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2010-11-16 09:55 . 2011-03-12 08:28        251310              c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:36 . 2011-03-06 17:12        618552              c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-03-10 16:16        618552              c:\windows\system32\perfh009.dat
- 2009-08-04 09:51 . 2011-03-06 17:12        656710              c:\windows\system32\perfh007.dat
+ 2009-08-04 09:51 . 2011-03-10 16:16        656710              c:\windows\system32\perfh007.dat
- 2009-07-14 02:36 . 2011-03-06 17:12        107574              c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-03-10 16:16        107574              c:\windows\system32\perfc009.dat
- 2009-08-04 09:51 . 2011-03-06 17:12        131192              c:\windows\system32\perfc007.dat
+ 2009-08-04 09:51 . 2011-03-10 16:16        131192              c:\windows\system32\perfc007.dat
+ 2011-03-09 16:59 . 2010-12-23 06:07        723968              c:\windows\system32\EncDec.dll
+ 2011-03-09 16:59 . 2011-02-19 06:36        902656              c:\windows\system32\d2d1.dll
- 2011-01-12 19:28 . 2010-11-02 05:12        902656              c:\windows\system32\d2d1.dll
- 2010-11-16 08:02 . 2010-08-04 07:07        961024              c:\windows\system32\CPFilters.dll
+ 2011-03-09 16:59 . 2010-12-23 06:07        961024              c:\windows\system32\CPFilters.dll
- 2009-07-14 05:01 . 2011-03-08 11:35        226136              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-03-11 20:54        226136              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-03-09 16:59 . 2010-12-18 05:30        2690560              c:\windows\SysWOW64\mstscax.dll
+ 2011-03-09 16:59 . 2010-12-18 05:26        1034240              c:\windows\SysWOW64\mstsc.exe
- 2011-01-12 19:28 . 2010-11-02 04:35        1074176              c:\windows\SysWOW64\DWrite.dll
+ 2011-03-09 16:59 . 2011-02-19 05:32        1074176              c:\windows\SysWOW64\DWrite.dll
- 2009-07-14 00:21 . 2009-07-14 01:41        1118720              c:\windows\system32\sbe.dll
+ 2011-03-09 16:59 . 2010-12-23 06:07        1118720              c:\windows\system32\sbe.dll
+ 2011-03-09 16:59 . 2010-12-18 06:12        3138048              c:\windows\system32\mstscax.dll
+ 2011-03-09 16:59 . 2010-12-18 06:08        1097216              c:\windows\system32\mstsc.exe
+ 2011-03-09 16:59 . 2011-02-19 06:37        1135104              c:\windows\system32\FntCache.dll
+ 2011-03-09 16:59 . 2011-02-19 06:37        1540608              c:\windows\system32\DWrite.dll
- 2011-01-12 19:28 . 2010-11-02 05:12        1540608              c:\windows\system32\DWrite.dll
- 2009-07-14 04:45 . 2011-03-06 13:32        3798234              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2011-03-10 13:18        3798234              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 02:34 . 2011-03-12 07:40        10223616              c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2011-03-08 11:46        10223616              c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2010-11-23 15:16 . 2011-03-09 22:18        39946696              c:\windows\system32\MRT.exe
.
-- Snapshot auf jetziges Datum zurückgesetzt --
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08        143360        ----a-w-        c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Syncables"="c:\program files (x86)\syncables\syncables desktop\Syncables.exe" [2010-04-05 370480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-02-18 2987976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-08-13 2429]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 170624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2010-06-17 370176]
"BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-11-24 110592]
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-8-13 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-8-13 156880]
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2011\mshaktuell.exe [2011-3-5 1199400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-13 135664]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-13 02:00]
.
2011-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-13 02:00]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52        159744        ----a-w-        c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49        70656        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-08-05 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-08-05 387608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-08-05 365592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-28 16336488]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 617856]
"Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: {2D055E3D-5B6B-4021-977C-65D774522DCC} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\2pkm6r93.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-03-12  13:45:30
ComboFix-quarantined-files.txt  2011-03-12 12:45
ComboFix2.txt  2011-03-08 19:39
.
Vor Suchlauf: 13 Verzeichnis(se), 24.307.535.872 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 24.252.813.312 Bytes frei
.
- - End Of File - - 99DD5141732109AA45E126EC6B9C7465

--- --- ---

bartolo 12.03.2011 17:13

Aha. Nun hat firefox kurz funktioniert; er war normal schnell und ohne Weiterleitungen. Dann habe ich für comunio.de, wo die Weiterleitung immer passierte, ein Lesezeichen gesetzt und den Computer neu gestartet. Danach war die Weiterleitung wieder da und firefox wieder lahm... Kannst Du damit etwas anfangen?

cosinus 13.03.2011 13:29

Mir gehen die Ideen aus. :stirn:

Scann mal den Rechner hiermir => http://www.trojaner-board.de/83997-k...scue-disk.html

Wenn der auch nichts findet würde ich dann nochmal sichergehen, ob das nur unter Windows so ist, oder auch mit anderen Betriebssystemen.
Lad dir mal sowas wie Knoppix oder Ubuntu herunter (Kaspersky Rescue Disk müsste auch gehen), brenn die iso Datei per Imagebrennfunktion auf eine CD und boote den Rechner davon.
Teste dann mal ausgiebig die Internetverbindung unter Linux....

bartolo 13.03.2011 21:15

Bestehen irgendwelche Bedenken gegen Neuinstallation von Windows? Sonst mache ich das einfach. Die Daten sind sowieso auch auf ner externen Festplatte und ist jetzt wahrscheinlich einfacherer als der ganze Rest...

cosinus 14.03.2011 09:49

Klar geht auch. Aber dadurch wissen wir nicht, was letztenendes bei dir das Problem verursacht hat.

bartolo 17.03.2011 11:32

So, jetzt habe ich wieder ein bisschen mehr Zeit für meinen Computer. Installation und booten von Kaspersky hat geklappt, allerdings funktioniert das Update nicht. Anscheinend hat er keine Internetverbindung. Automatische Konfiguration des Netzwerkadapters funktioniert irgendwie nicht und auf der Kasperky-Homepage komme ich nicht weiter, sodass ich PC-Amateur wohl auf Deine Hilfe angewiesen bin...

cosinus 17.03.2011 11:41

Teste bitte erstmal die Internetverbindung über Ubuntu oder Knoppix und berichte ob die Umleitung da auch ist.

bartolo 17.03.2011 23:53

Also, die Probleme treten nur bei Windows auf. Bei Ubuntu läuft firefox einwandfrei. Auch hat mein Asus ein Express Gate, das eine eigene vereinfachte Benutzerfläche mit Grundfunktionen wie Internet ist und per Knopfdruck in 2 sek zu erreichen ist. Mit dem dortigen Browser gibt es auch keine Probleme...

cosinus 18.03.2011 12:02

Ok, dann liegt es an Windows. Wärst du bereit, mal den MBR neu zu schreiben? Dazu brauchst du eine Win7-DVD 64-Bit.

bartolo 18.03.2011 15:00

Ok, die habe ich. Wie mache ich denn das und muss ich davor meine Daten sichern?

cosinus 18.03.2011 15:05

Daten sichern wäre nicht schlecht...

Danach einfach von der Win7-DVD 64-Bit booten.
Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen.

Prüf, ob die Weiterleitungen dann immer noch bestehen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 11:23 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131