![]() |
|
Plagegeister aller Art und deren Bekämpfung: Adware: Win32/PriceGongWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #3 |
![]() | ![]() Adware: Win32/PriceGong Hallo Matthias,
__________________es gab im Ablauf keinerlei Probleme. Alle Programme sind reibungslos gelaufen. Anbei die Log-Dateien. Window Defender hat nichts mehr von sich gegeben. Vielleicht kannst du mir sagen, ob jetzt alles in Ordnung ist. Kann ich die Log-Dateien und Programme wieder vom Computer löschen??? Combofix: Code:
ATTFilter ComboFix 13-05-04.01 - ***1252.49.1031.18.3767.1819 [GMT 2:00] ausgeführt von:: c:\users\***\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF} SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\VideoWebCamera.exe.lnk c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe c:\windows\wininit.ini . Infizierte Kopie von c:\windows\SysWow64\userinit.exe wurde gefunden und desinfiziert Kopie von - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe wurde wiederhergestellt . . ((((((((((((((((((((((( Dateien erstellt von 2013-04-04 bis 2013-05-04 )))))))))))))))))))))))))))))) . . 2013-05-04 17:41 . 2013-05-04 17:41 -------- d-----w- c:\users\UpdatusUser.***\AppData\Local\temp 2013-05-04 17:41 . 2013-05-04 17:41 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-05-04 13:50 . 2013-05-04 14:32 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C6D57609-269C-4769-8934-55F6311E6746}\offreg.dll 2013-05-04 13:24 . 2013-04-10 03:46 9317456 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C6D57609-269C-4769-8934-55F6311E6746}\mpengine.dll 2013-04-24 11:14 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-11 10:39 . 2013-02-15 06:06 3717632 ----a-w- c:\windows\system32\mstscax.dll 2013-04-11 10:39 . 2013-02-15 04:37 3217408 ----a-w- c:\windows\SysWow64\mstscax.dll 2013-04-11 10:39 . 2013-02-15 06:02 158720 ----a-w- c:\windows\system32\aaclient.dll 2013-04-11 10:39 . 2013-02-15 04:34 131584 ----a-w- c:\windows\SysWow64\aaclient.dll 2013-04-11 10:39 . 2013-02-15 06:08 44032 ----a-w- c:\windows\system32\tsgqec.dll 2013-04-11 10:39 . 2013-02-15 03:25 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll 2013-04-11 10:39 . 2013-03-01 03:36 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-04-11 10:39 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys 2013-04-11 10:38 . 2013-03-19 06:04 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-04-11 10:38 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-04-11 10:38 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-04-11 10:38 . 2013-03-19 05:46 43520 ----a-w- c:\windows\system32\csrsrv.dll 2013-04-11 10:38 . 2013-03-19 04:47 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll 2013-04-11 10:38 . 2013-03-19 03:06 112640 ----a-w- c:\windows\system32\smss.exe . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-02 00:06 . 2011-05-21 16:20 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-04-11 11:48 . 2011-06-17 07:03 72702784 ----a-w- c:\windows\system32\MRT.exe 2013-04-03 16:41 . 2013-04-03 16:41 0 ----a-w- c:\windows\SysWow64\sho5918.tmp 2013-04-03 08:58 . 2013-04-03 08:58 0 ----a-w- c:\windows\SysWow64\sho8372.tmp 2013-03-25 08:10 . 2013-03-25 08:10 0 ----a-w- c:\windows\SysWow64\sho783C.tmp 2013-03-15 05:53 . 2013-03-27 10:08 61216 ----a-w- c:\windows\system32\OpenCL.dll 2013-03-15 05:53 . 2013-03-27 10:08 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll 2013-03-15 05:53 . 2013-03-27 10:01 9414456 ----a-w- c:\windows\system32\nvcuda.dll 2013-03-15 05:53 . 2013-03-27 10:01 7959000 ----a-w- c:\windows\SysWow64\nvcuda.dll 2013-03-15 05:53 . 2013-03-27 10:01 2913056 ----a-w- c:\windows\system32\nvcuvid.dll 2013-03-15 05:53 . 2013-03-27 10:01 2864144 ----a-w- c:\windows\system32\nvapi64.dll 2013-03-15 05:53 . 2013-03-27 10:01 2728736 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2013-03-15 05:53 . 2013-03-27 10:01 2539128 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-03-15 05:53 . 2013-03-27 10:01 25256736 ----a-w- c:\windows\system32\nvcompiler.dll 2013-03-15 05:53 . 2013-03-27 10:01 250504 ----a-w- c:\windows\system32\nvinitx.dll 2013-03-15 05:53 . 2013-03-27 10:01 2355488 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-03-15 05:53 . 2013-03-27 10:01 205184 ----a-w- c:\windows\SysWow64\nvinit.dll 2013-03-15 05:53 . 2013-03-27 10:01 1995552 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-03-15 05:53 . 2013-03-27 10:01 1807136 ----a-w- c:\windows\system32\nvdispco6431422.dll 2013-03-15 05:53 . 2013-03-27 10:01 17990800 ----a-w- c:\windows\system32\nvd3dumx.dll 2013-03-15 05:53 . 2013-03-27 10:01 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2013-03-15 05:53 . 2013-03-27 10:01 1510176 ----a-w- c:\windows\system32\nvdispgenco6431422.dll 2013-03-15 05:53 . 2013-03-27 10:01 15042928 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-03-15 05:53 . 2013-03-27 10:01 968408 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2013-03-15 05:53 . 2013-03-27 10:01 7573816 ----a-w- c:\windows\system32\nvopencl.dll 2013-03-15 05:53 . 2013-03-27 10:01 6271872 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-03-15 05:53 . 2013-03-27 10:01 30496 ----a-w- c:\windows\system32\drivers\nvpciflt.sys 2013-03-15 05:53 . 2013-03-27 10:01 26956576 ----a-w- c:\windows\system32\nvoglv64.dll 2013-03-15 05:53 . 2013-03-27 10:01 20542752 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2013-03-15 05:53 . 2013-03-27 10:01 15508512 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-03-15 05:53 . 2013-03-27 10:01 13088000 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-03-15 05:53 . 2013-03-27 10:01 1118776 ----a-w- c:\windows\system32\nvumdshimx.dll 2013-03-15 05:53 . 2013-03-27 10:01 11048736 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-03-15 04:16 . 2013-03-27 10:09 3477280 ----a-w- c:\windows\system32\nvsvc64.dll 2013-03-15 04:16 . 2013-03-27 10:09 6398240 ----a-w- c:\windows\system32\nvcpl.dll 2013-03-15 04:16 . 2013-03-27 10:09 877856 ----a-w- c:\windows\system32\nvvsvc.exe 2013-03-15 04:16 . 2013-03-27 10:09 76064 ----a-w- c:\windows\system32\nv3dappshextr.dll 2013-03-15 04:16 . 2013-03-27 10:09 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-03-15 04:16 . 2013-03-27 10:09 2555680 ----a-w- c:\windows\system32\nvsvcr.dll 2013-03-15 04:16 . 2013-03-27 10:09 237856 ----a-w- c:\windows\system32\nvmctray.dll 2013-03-15 04:16 . 2013-03-27 10:09 1016096 ----a-w- c:\windows\system32\nv3dappshext.dll 2013-03-13 16:24 . 2013-03-27 10:09 3065455 ----a-w- c:\windows\system32\nvcoproc.bin 2013-03-13 07:23 . 2012-05-04 15:03 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-13 07:23 . 2011-07-12 07:26 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-01 07:29 . 2013-03-01 07:29 0 ----a-w- c:\windows\SysWow64\shoD24C.tmp 2013-02-13 18:53 . 2013-02-13 18:53 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-02-13 18:53 . 2013-02-13 18:53 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-02-13 18:53 . 2013-02-13 18:53 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-02-13 18:53 . 2013-02-13 18:53 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-02-13 18:53 . 2013-02-13 18:53 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-02-13 18:53 . 2013-02-13 18:53 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-02-13 18:53 . 2013-02-13 18:53 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-02-13 18:53 . 2013-02-13 18:53 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-02-13 18:53 . 2013-02-13 18:53 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-02-13 18:53 . 2013-02-13 18:53 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-02-13 18:53 . 2013-02-13 18:53 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-02-13 18:53 . 2013-02-13 18:53 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2013-02-13 18:53 . 2013-02-13 18:53 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-02-13 18:53 . 2013-02-13 18:53 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-02-13 18:53 . 2013-02-13 18:53 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-02-13 18:53 . 2013-02-13 18:53 2434560 ----a-w- c:\windows\system32\d3d10warp.dll 2013-02-13 18:53 . 2013-02-13 18:53 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-02-13 18:53 . 2013-02-13 18:53 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-02-13 18:53 . 2013-02-13 18:53 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-02-13 18:53 . 2013-02-13 18:53 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-02-13 18:53 . 2013-02-13 18:53 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2013-02-13 18:53 . 2013-02-13 18:53 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-02-13 18:53 . 2013-02-13 18:53 1885696 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2013-02-13 18:53 . 2013-02-13 18:53 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2013-02-13 18:53 . 2013-02-13 18:53 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2013-02-13 18:53 . 2013-02-13 18:53 1643008 ----a-w- c:\windows\system32\DWrite.dll 2013-02-13 18:53 . 2013-02-13 18:53 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2013-02-13 18:53 . 2013-02-13 18:53 1504768 ----a-w- c:\windows\SysWow64\d3d11.dll 2013-02-13 18:53 . 2013-02-13 18:53 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-02-13 18:53 . 2013-02-13 18:53 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2013-02-13 18:53 . 2013-02-13 18:53 1238528 ----a-w- c:\windows\system32\d3d10.dll 2013-02-13 18:53 . 2013-02-13 18:53 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2013-02-13 18:53 . 2013-02-13 18:53 1175552 ----a-w- c:\windows\system32\FntCache.dll 2013-02-13 18:53 . 2013-02-13 18:53 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2013-02-13 18:53 . 2013-02-13 18:53 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll 2013-02-13 18:53 . 2013-02-13 18:53 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-02-13 18:53 . 2013-02-13 18:53 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-02-12 05:45 . 2013-03-13 09:25 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-13 09:25 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" [2010-06-28 263936] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2012-11-02 206448] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-06-17 246376] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2013-03-15 30496] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-16 55024] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-10 29488] S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104] S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2010-06-11 868896] S2 GREGService;GREGService;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2010-06-28 255744] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920] S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2010-01-28 243232] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 158976] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-06-21 287232] S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-05-15 384040] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 22544] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2013-05-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 07:23] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552] "Acer ePower Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2010-06-11 861216] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 392984] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 417560] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://packardbell.msn.com mStart Page = hxxp://packardbell.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 10.0.0.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-05-04 19:51:22 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-05-04 17:51 . Vor Suchlauf: 10 Verzeichnis(se), 403.021.357.056 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 405.684.744.192 Bytes frei . - - End Of File - - B28026D8A0AD18811AED9B7468EF9F13 Junkware: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.3 (04.29.2013:2) OS: Windows 7 Home Premium x64 Ran by ***on 04.05.2013 at 20:03:57,24 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8EE77658-AA7F-4A76-BAD3-A8F61A745F84} ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\sho1C04.tmp Successfully deleted: [File] C:\Windows\syswow64\sho1C1B.tmp Successfully deleted: [File] C:\Windows\syswow64\sho1F29.tmp Successfully deleted: [File] C:\Windows\syswow64\sho22CF.tmp Successfully deleted: [File] C:\Windows\syswow64\sho2E9F.tmp Successfully deleted: [File] C:\Windows\syswow64\sho47F9.tmp Successfully deleted: [File] C:\Windows\syswow64\sho4C1C.tmp Successfully deleted: [File] C:\Windows\syswow64\sho53D1.tmp Successfully deleted: [File] C:\Windows\syswow64\sho5918.tmp Successfully deleted: [File] C:\Windows\syswow64\sho5A6F.tmp Successfully deleted: [File] C:\Windows\syswow64\sho5F9.tmp Successfully deleted: [File] C:\Windows\syswow64\sho6153.tmp Successfully deleted: [File] C:\Windows\syswow64\sho70DB.tmp Successfully deleted: [File] C:\Windows\syswow64\sho72C0.tmp Successfully deleted: [File] C:\Windows\syswow64\sho783C.tmp Successfully deleted: [File] C:\Windows\syswow64\sho7A14.tmp Successfully deleted: [File] C:\Windows\syswow64\sho7ED0.tmp Successfully deleted: [File] C:\Windows\syswow64\sho8288.tmp Successfully deleted: [File] C:\Windows\syswow64\sho8372.tmp Successfully deleted: [File] C:\Windows\syswow64\sho83E5.tmp Successfully deleted: [File] C:\Windows\syswow64\sho9CB8.tmp Successfully deleted: [File] C:\Windows\syswow64\shoB579.tmp Successfully deleted: [File] C:\Windows\syswow64\shoCC09.tmp Successfully deleted: [File] C:\Windows\syswow64\shoD24C.tmp Successfully deleted: [File] C:\Windows\syswow64\shoD59B.tmp Successfully deleted: [File] C:\Windows\syswow64\shoE0BC.tmp ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\big fish games" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.05.2013 at 20:08:19,50 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner v2.300 - Datei am 04/05/2013 um 19:57:36 erstellt # Aktualisiert am 28/04/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : *** # Bootmodus : Normal # Ausgeführt unter : C:\Users\***\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Users\***\AppData\Local\Conduit Ordner Gelöscht : C:\Users\***\AppData\LocalLow\Conduit ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT1703539 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DVDVideoSoftTBToolbarHelper_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DVDVideoSoftTBToolbarHelper_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16476 [OK] Die Registrierungsdatenbank ist sauber. ************************* AdwCleaner[S1].txt - [2599 octets] - [04/05/2013 19:57:36] ########## EOF - C:\AdwCleaner[S1].txt - [2659 octets] ########## gerade ist mir etwas aufgefallen. Unsere PS3 hat jetzt einen Windows Media Player drauf. Daneben steht der Laptop-Name und die User. Wie kommt das jetzt??? |
Themen zu Adware: Win32/PriceGong |
avg secure search, avg security toolbar, bho, cid, computer, converter, desktop, diner dash, ebay, error, failed, firefox, flash player, home, iexplore.exe, install.exe, internet, kaspersky, launch, logfile, microsoft office starter 2010, mp3, nvpciflt.sys, packard bell, problem, realtek, registry, richtlinie, scan, secure search, security, software, super, svchost.exe, tastatur, vtoolbarupdater, wildtangent games, windows |