![]() |
| |||||||
Log-Analyse und Auswertung: POPUP Fenster gehen auf!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | POPUP Fenster gehen auf! Java und Adobe updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\ProgramData\{55ad6f76-482a-c5b2-55ad-d6f76482bdd9}
C:\Users\andrea.hafner\Desktop\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001c7a
C:\Users\andrea.hafner\Desktop\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P5FJ8OAA\pack[1].7z
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\BabMaint.exe
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\BExternal.dll
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\BUSolution.dll
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\CrxInstaller.dll
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\delta.crx
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\IEHelper.dll
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\MyBabylonTB.exe
C:\Users\andrea.hafner\Desktop\AppData\Local\Temp\EEE47331-BAB0-7891-AE75-8531FCB0104C\Latest\Setup.exe
C:\Users\andrea.hafner\Desktop\AppData\Roaming\BabSolution\CR\Delta.crx
C:\Users\andrea.hafner\Desktop\AppData\Roaming\BabSolution\Shared\BabMaint.exe
C:\Users\andrea.hafner\Desktop\AppData\Roaming\BabSolution\Shared\BUSolution.dll
C:\Users\andrea.hafner\Desktop\AppData\Roaming\OpenCandy\6DCCF8E2E0764F6F9C355F37FC9D78FE\DeltaTB.exe
C:\Users\andreas.chudalla\AppData\Local\Temp\DMR\dmr_72.exe
E:\PC-0406\Backup Set 2013-10-01 150158\Backup Files 2013-10-01 150158\Backup files 1.zip
E:\PC-0406\Backup Set 2013-10-01 150158\Backup Files 2013-10-01 150158\Backup files 21.zip
E:\PC-0406\Backup Set 2013-10-01 150158\Backup Files 2013-10-01 150158\Backup files 5.zip
E:\PC-0406\Backup Set 2013-10-01 150158\Backup Files 2013-10-01 150158\Backup files 7.zip
E:\PC-0406\Backup Set 2013-10-01 150158\Backup Files 2013-10-01 150158\Backup files 8.zip
E:\PC-0406\Backup Set 2013-10-01 150158\Backup Files 2014-03-04 073341\Backup files 1.zip
E:\PC-0406\Backup Set 2014-04-14 073903\Backup Files 2014-04-14 073903\Backup files 1.zip
E:\PC-0406\Backup Set 2014-04-14 073903\Backup Files 2014-04-14 073903\Backup files 2.zip
E:\PC-0406\Backup Set 2014-04-14 073903\Backup Files 2014-04-14 073903\Backup files 31.zip
E:\PC-0406\Backup Set 2014-04-14 073903\Backup Files 2014-04-14 073903\Backup files 6.zip
E:\PC-0406\Backup Set 2014-04-14 073903\Backup Files 2014-04-14 073903\Backup files 8.zip
E:\PC-0406\Backup Set 2014-04-14 073903\Backup Files 2014-04-14 073903\Backup files 9.zip
E:\PC-0406\Backup Set 2014-06-02 073326\Backup Files 2014-06-02 073326\Backup files 32.zip
E:\PC-0406\Backup Set 2014-06-02 073326\Backup Files 2014-06-02 073326\Backup files 6.zip
E:\PC-0406\Backup Set 2014-06-02 073326\Backup Files 2014-06-02 073326\Backup files 7.zip
E:\PC-0406\Backup Set 2014-06-02 073326\Backup Files 2014-06-02 073326\Backup files 9.zip
E:\PC-0406\Backup Set 2014-07-21 073442\Backup Files 2014-07-21 073442\Backup files 33.zip
E:\PC-0406\Backup Set 2014-07-21 073442\Backup Files 2014-07-21 073442\Backup files 6.zip
E:\PC-0406\Backup Set 2014-07-21 073442\Backup Files 2014-07-21 073442\Backup files 7.zip
E:\PC-0406\Backup Set 2014-07-21 073442\Backup Files 2014-07-21 073442\Backup files 9.zip
E:\PC-0406\Backup Set 2014-09-22 073726\Backup Files 2014-09-22 073726\Backup files 35.zip
E:\PC-0406\Backup Set 2014-09-22 073726\Backup Files 2014-09-22 073726\Backup files 7.zip
E:\PC-0406\Backup Set 2014-09-22 073726\Backup Files 2014-09-22 073726\Backup files 8.zip
E:\PC-0406\Backup Set 2014-09-22 073726\Backup Files 2014-09-22 073726\Backup files 9.zip
E:\PC-0406\Backup Set 2014-11-17 073148\Backup Files 2014-11-17 073148\Backup files 35.zip
E:\PC-0406\Backup Set 2014-11-17 073148\Backup Files 2014-11-17 073148\Backup files 7.zip
E:\PC-0406\Backup Set 2014-11-17 073148\Backup Files 2014-11-17 073148\Backup files 8.zip
E:\PC-0406\Backup Set 2014-11-17 073148\Backup Files 2014-11-17 073148\Backup files 9.zip
E:\PC-0406\Backup Set 2015-01-12 073627\Backup Files 2015-01-12 073627\Backup files 25.zip
E:\PC-0406\Backup Set 2015-01-12 073627\Backup Files 2015-01-12 073627\Backup files 7.zip
E:\PC-0406\Backup Set 2015-01-12 073627\Backup Files 2015-01-12 073627\Backup files 8.zip
E:\PC-0406\Backup Set 2015-01-12 073627\Backup Files 2015-01-12 073627\Backup files 9.zip
E:\PC-0406\Backup Set 2015-01-12 073627\Backup Files 2015-02-09 074010\Backup files 1.zip
HKU\S-1-5-21-3409918318-3268832435-3554840575-1245\...\Run: [winengine] => C:\Users\andreas.chudalla\AppData\Local\winengine\rkr0.exe [511416 2014-12-12] ()
HKU\S-1-5-21-3409918318-3268832435-3554840575-1245\...\Run: [winengine2] => C:\Users\andreas.chudalla\AppData\Local\winengine\rkr1.exe [511416 2014-12-12] ()
C:\Users\andreas.chudalla\AppData\Local\winengine
Startup: C:\Users\andreas.chudalla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OptimizerProInstaller.lnk
ShortcutTarget: OptimizerProInstaller.lnk -> C:\ProgramData\{55ad6f76-482a-c5b2-55ad-d6f76482bdd9}\OptimizerProInstaller.exe (PC Utilities Software Limited)
Emptytemp:
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
| Themen zu POPUP Fenster gehen auf! |
| adobe, adobe flash player, bho, desktop, explorer, file, flash player, helper, hijack, internet, internet explorer, monitor, nvidia, pdf, popup, problem, proxy, security, seiten, senden, software, suche, system, windows, wmp |