![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: updownlinkg.comWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 | |
![]() ![]() | updownlinkg.com Hallo Jungs und Mädels ich habe seit tagen dieses kleine Problem. Es geht immer wieder eine seite auf und fordert mich auf java zu installieren Zitat:
Geändert von tce (19.04.2014 um 09:24 Uhr) |
| | #2 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | updownlinkg.com hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
| | #3 |
![]() ![]() | updownlinkg.com Habe ich versucht mit FRST 64-Bit, da ich einen 64 bit habe. Aber der läuft nicht durch macht einen error.
__________________Siehe bild ![]() Ich spamme ungerne jetzz, aber hat einer eine lösung für mein problem oder muss ich meinen PC neu Konfigurieren. Also Plat machen. |
| | #4 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | updownlinkg.com Ich sehe keinen Error, nur dass er gerade dabei ist die Eventviewer Einträge zu lesen. Mach mal den Haken raus bei Addition.txt und scanne nochmal.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #5 | |
![]() ![]() | updownlinkg.com So jetzt habe ich es noch mal gemacht Zitat:
|
| | #6 | |
![]() ![]() | updownlinkg.com zweite hälfte Zitat:
|
| | #7 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | updownlinkg.com So funktioniert es:Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #8 |
![]() ![]() | updownlinkg.comCode:
ATTFilter ComboFix 14-04-20.01 - Tce 21.04.2014 22:08:42.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6135.3061 [GMT 2:00]
ausgeführt von:: c:\users\Tce\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tce\AppData\Local\nsnB740.tmp
c:\users\Tce\AppData\Local\Temp\nsv8629.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-03-21 bis 2014-04-21 ))))))))))))))))))))))))))))))
.
.
2014-04-21 20:14 . 2014-04-21 20:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-19 15:01 . 2014-04-19 15:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B165C49-67B7-4551-9425-CF8CBEF363FF}\offreg.dll
2014-04-19 08:53 . 2014-04-20 18:38 -------- d-----w- C:\FRST
2014-04-18 12:41 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B165C49-67B7-4551-9425-CF8CBEF363FF}\mpengine.dll
2014-04-14 12:06 . 2014-04-14 12:06 -------- d-----w- c:\program files (x86)\Common Files\logishrd
2014-04-14 12:06 . 2014-04-14 12:06 -------- d-----w- c:\program files\Common Files\logishrd
2014-04-12 22:41 . 2014-04-12 22:41 -------- d-----w- c:\users\Tce\oxwell
2014-04-09 15:25 . 2005-08-30 10:02 24576 ------w- c:\windows\SysWow64\Ulead Photo Explorer 86.scr
2014-04-09 15:23 . 2006-07-22 17:37 49152 ------w- c:\windows\SysWow64\INETWH32.dll
2014-04-09 15:23 . 1999-10-15 10:50 1056768 ------w- c:\windows\SysWow64\ROBOEX32.DLL
2014-04-09 15:23 . 2014-04-09 15:25 -------- d-----w- c:\program files (x86)\Common Files\Ulead Systems
2014-04-09 15:22 . 2002-12-02 13:22 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2014-04-08 23:49 . 2014-04-09 00:01 -------- d-----w- c:\users\Tce\ersatz
2014-04-08 23:19 . 2014-04-12 23:42 -------- d-----w- c:\users\Tce\templat_top
2014-04-06 11:03 . 2014-04-06 11:03 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-04-06 08:35 . 2014-04-06 08:35 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2014-04-06 01:46 . 2014-04-14 16:35 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-06 01:45 . 2014-04-06 01:45 -------- d-----w- c:\programdata\Malwarebytes
2014-04-06 01:33 . 2014-04-06 01:33 -------- d-----w- c:\windows\ERUNT
2014-04-06 01:28 . 2014-04-16 08:55 -------- d-----w- C:\AdwCleaner
2014-04-06 00:39 . 2014-04-06 00:58 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-04-05 23:29 . 2014-04-06 00:27 -------- d-----w- c:\program files (x86)\Uninstaller
2014-04-05 23:29 . 2008-04-07 03:38 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll
2014-04-05 22:36 . 2014-04-05 22:36 -------- d-----w- c:\users\Tce\AppData\Roaming\Avira
2014-04-05 22:35 . 2014-02-25 09:41 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2014-04-05 22:35 . 2014-02-25 09:41 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-04-05 22:35 . 2014-02-25 09:41 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-04-05 22:35 . 2014-04-05 22:35 -------- d-----w- c:\programdata\Avira
2014-04-05 21:37 . 2014-04-05 21:37 -------- d-----w- c:\programdata\FLEXnet
2014-04-05 08:48 . 2014-04-12 14:19 -------- d-----w- c:\program files (x86)\WinSCP
2014-04-05 08:47 . 2014-04-05 08:47 -------- d-----w- c:\users\Tce\AppData\Local\Programs
2014-04-05 07:25 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-04-05 07:25 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-04-05 07:10 . 2014-04-05 07:10 -------- d-----w- c:\users\Tce\AppData\Local\NVIDIA
2014-04-05 07:01 . 2014-04-11 01:04 -------- d-----w- c:\windows\system32\MRT
2014-04-05 07:00 . 2014-03-04 11:32 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-04-05 07:00 . 2014-03-04 13:05 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-04-05 06:58 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-04-05 06:58 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-04-05 06:58 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-04-05 06:58 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-04-04 12:29 . 2014-04-04 12:29 -------- d-----w- c:\program files (x86)\Hewlett-Packard
2014-04-04 12:29 . 2014-04-11 13:47 -------- d-----w- c:\users\Tce\AppData\Roaming\HpUpdate
2014-04-04 12:29 . 2012-10-17 02:31 741480 ------w- c:\windows\system32\HPDiscoPM5912.dll
2014-04-04 12:28 . 2014-04-04 12:29 -------- d-----w- c:\program files (x86)\HP
2014-04-04 12:28 . 2014-04-04 12:28 -------- d-----w- c:\programdata\HP
2014-04-04 12:28 . 2014-04-04 12:28 -------- d-----w- c:\program files\HP
2014-04-04 12:28 . 2014-04-04 12:32 -------- d-----w- c:\users\Tce\AppData\Local\HP
2014-04-04 12:24 . 2014-04-04 12:24 -------- d-----w- c:\users\Tce\AppData\Local\ElevatedDiagnostics
2014-04-03 19:32 . 2014-04-03 19:32 -------- d-----w- c:\users\Tce\AppData\Roaming\vlc
2014-04-03 19:31 . 2014-04-03 19:31 -------- d-----w- c:\program files (x86)\VideoLAN
2014-04-03 10:04 . 2014-04-03 10:04 -------- d-----w- c:\users\Tce\AppData\Local\AviraSpeedup
2014-04-03 09:51 . 2014-04-05 22:36 -------- d-----w- c:\program files (x86)\Avira
2014-03-27 15:24 . 2014-03-27 15:24 -------- d-----w- c:\users\Tce\config
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-21 08:24 . 2014-03-14 07:45 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-21 08:24 . 2014-03-14 07:45 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-31 07:35 . 2014-03-14 20:40 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-21 02:04 . 2014-03-21 02:04 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-03-21 02:04 . 2014-03-21 02:04 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-03-21 02:04 . 2014-03-21 02:04 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-03-21 02:04 . 2014-03-21 02:04 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-03-21 02:04 . 2014-03-21 02:04 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-03-21 02:04 . 2014-03-21 02:04 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-03-21 02:04 . 2014-03-21 02:04 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-03-21 02:04 . 2014-03-21 02:04 81408 ----a-w- c:\windows\system32\icardie.dll
2014-03-21 02:04 . 2014-03-21 02:04 774144 ----a-w- c:\windows\system32\jscript.dll
2014-03-21 02:04 . 2014-03-21 02:04 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-03-21 02:04 . 2014-03-21 02:04 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-03-21 02:04 . 2014-03-21 02:04 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-03-21 02:04 . 2014-03-21 02:04 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-03-21 02:04 . 2014-03-21 02:04 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-03-21 02:04 . 2014-03-21 02:04 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-03-21 02:04 . 2014-03-21 02:04 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-03-21 02:04 . 2014-03-21 02:04 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-03-21 02:04 . 2014-03-21 02:04 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-03-21 02:04 . 2014-03-21 02:04 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-03-21 02:04 . 2014-03-21 02:04 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-03-21 02:04 . 2014-03-21 02:04 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-03-21 02:04 . 2014-03-21 02:04 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2014-03-21 02:04 . 2014-03-21 02:04 413696 ----a-w- c:\windows\system32\html.iec
2014-03-21 02:04 . 2014-03-21 02:04 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-21 02:04 . 2014-03-21 02:04 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-03-21 02:04 . 2014-03-21 02:04 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-21 02:04 . 2014-03-21 02:04 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-03-21 02:04 . 2014-03-21 02:04 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-03-21 02:04 . 2014-03-21 02:04 296960 ----a-w- c:\windows\system32\dxtrans.dll
2014-03-21 02:04 . 2014-03-21 02:04 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-03-21 02:04 . 2014-03-21 02:04 247808 ----a-w- c:\windows\system32\msls31.dll
2014-03-21 02:04 . 2014-03-21 02:04 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-03-21 02:04 . 2014-03-21 02:04 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-03-21 02:04 . 2014-03-21 02:04 235520 ----a-w- c:\windows\system32\url.dll
2014-03-21 02:04 . 2014-03-21 02:04 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-03-21 02:04 . 2014-03-21 02:04 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-03-21 02:04 . 2014-03-21 02:04 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-03-21 02:04 . 2014-03-21 02:04 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-03-21 02:04 . 2014-03-21 02:04 147968 ----a-w- c:\windows\system32\occache.dll
2014-03-21 02:04 . 2014-03-21 02:04 143872 ----a-w- c:\windows\system32\wextract.exe
2014-03-21 02:04 . 2014-03-21 02:04 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-03-21 02:04 . 2014-03-21 02:04 13824 ----a-w- c:\windows\system32\mshta.exe
2014-03-21 02:04 . 2014-03-21 02:04 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-03-21 02:04 . 2014-03-21 02:04 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-03-21 02:04 . 2014-03-21 02:04 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-03-21 02:04 . 2014-03-21 02:04 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-03-21 02:04 . 2014-03-21 02:04 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-03-21 02:04 . 2014-03-21 02:04 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-03-21 02:04 . 2014-03-21 02:04 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-03-21 02:04 . 2014-03-21 02:04 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-03-21 02:04 . 2014-03-21 02:04 101376 ----a-w- c:\windows\system32\inseng.dll
2014-03-20 21:03 . 2010-08-26 09:11 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-03-20 21:03 . 2010-08-26 09:11 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-20 21:03 . 2014-03-20 21:03 947808 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-03-20 21:03 . 2014-03-20 21:03 832936 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-03-20 21:03 . 2014-03-20 21:03 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll
2014-03-20 21:03 . 2014-03-20 21:03 11589272 ----a-w- c:\windows\system32\nvopencl.dll
2014-03-20 21:02 . 2014-03-20 21:02 31474976 ----a-w- c:\windows\system32\nvoglv64.dll
2014-03-20 21:02 . 2014-03-20 21:02 353504 ----a-w- c:\windows\system32\nvoglshim64.dll
2014-03-20 21:02 . 2014-03-20 21:02 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2014-03-20 21:02 . 2014-03-20 21:02 23716640 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2014-03-20 21:02 . 2014-03-20 21:02 12708128 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-03-20 21:02 . 2014-03-20 21:02 892704 ----a-w- c:\windows\system32\NvIFR64.dll
2014-03-20 21:02 . 2014-03-20 21:02 863064 ----a-w- c:\windows\SysWow64\NvIFR.dll
2014-03-20 21:02 . 2014-03-20 21:02 174296 ----a-w- c:\windows\system32\nvinitx.dll
2014-03-20 21:02 . 2014-03-20 21:02 148016 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-03-20 21:02 . 2014-03-20 21:02 877856 ----a-w- c:\windows\system32\NvFBC64.dll
2014-03-20 21:02 . 2014-03-20 21:02 846168 ----a-w- c:\windows\SysWow64\NvFBC.dll
2014-03-20 21:02 . 2014-03-20 21:02 1885472 ----a-w- c:\windows\system32\nvdispco6433523.dll
2014-03-20 21:02 . 2014-03-20 21:02 1516488 ----a-w- c:\windows\system32\nvdispgenco6433523.dll
2014-03-20 21:02 . 2014-03-20 21:02 3143456 ----a-w- c:\windows\system32\nvcuvid.dll
2014-03-20 21:02 . 2014-03-20 21:02 17755424 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-03-20 21:02 . 2010-08-26 09:10 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-20 21:02 . 2014-03-20 21:02 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll
2014-03-20 21:02 . 2014-03-20 21:02 2958792 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2014-03-20 21:02 . 2014-03-20 21:02 2783008 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-03-20 21:02 . 2014-03-20 21:02 2411976 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2014-03-20 21:02 . 2014-03-20 21:02 11636176 ----a-w- c:\windows\system32\nvcuda.dll
2014-03-20 21:02 . 2014-03-20 21:02 17561544 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2014-03-20 21:02 . 2014-03-20 21:02 25255256 ----a-w- c:\windows\system32\nvcompiler.dll
2014-03-20 21:02 . 2010-08-26 09:10 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-20 21:02 . 2014-03-20 21:02 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-20 02:11 . 2014-03-20 02:11 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-03-20 02:11 . 2014-03-20 02:11 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-03-20 02:11 . 2014-03-20 02:11 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-03-20 02:11 . 2014-03-20 02:11 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-03-20 02:11 . 2014-03-20 02:11 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-20 02:11 . 2014-03-20 02:11 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A18A516C-AA41-46A9-92DB-60208917E442}]
2013-12-11 14:49 184400 ----a-w- c:\program files (x86)\Avira\Internet Explorer\avira32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-11 39408]
"HP Officejet Pro 8600 (NET)"="c:\program files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe" [2012-10-17 2573416]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Hotkey Utility"="c:\program files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe" [2010-08-04 611872]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-25 689744]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"Ulead AutoDetector v2"="c:\program files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AviraSpeedup"="c:\program files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" [2014-04-03 5085416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Photo Frame.lnk - c:\program files (x86)\Northstar\Photo Frame\Photo Frame.exe [2010-5-11 93568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 vosr;Service Component of VO;c:\users\Tce\AppData\Roaming\VOPackage\VOsrv.exe;c:\users\Tce\AppData\Roaming\VOPackage\VOsrv.exe [x]
R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 EraserUtilDrv11312;EraserUtilDrv11312;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11312.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11312.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UPnPService;UPnPService;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [x]
S2 USBS3S4Detection;USBS3S4Detection;c:\oem\USBDECTION\USBS3S4Detection.exe;c:\oem\USBDECTION\USBS3S4Detection.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-10 18:04 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-14 08:24]
.
2014-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-13 18:47]
.
2014-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-13 18:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-09 10060320]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-03-20 1797064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\acaptuser64.dll
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://google.de/
uLocal Page = c:\windows\system32\blank.htm
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Tce\AppData\Roaming\Mozilla\Firefox\Profiles\qeubepd2.default\
FF - prefs.js: browser.search.selectedEngine - Web Search (powered by Google)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://search.toolbars.alexa.com/?ver=alxf-2.19&src=ab&aid=viw8j1sZQw00qN&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1934781817-2233350501-3576918985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1934781817-2233350501-3576918985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-04-21 22:17:13
ComboFix-quarantined-files.txt 2014-04-21 20:17
.
Vor Suchlauf: 10 Verzeichnis(se), 393.403.760.640 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 394.279.129.088 Bytes frei
.
- - End Of File - - B83F049F1CA3B5BDC523C8C5FD388E33
A36C5E4F47E84449FF07ED3517B43A31
|
| | #9 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | updownlinkg.com Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
| Themen zu updownlinkg.com |
| immer wieder, installiere, java, jungs, kleine, runter, seite, tagen |