|
Plagegeister aller Art und deren Bekämpfung: Hive Cluster\49600\Megalomon_swarmWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.06.2011, 01:17 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Hive Cluster\49600\Megalomon_swarm Dann beende das mal. Starte Windows danach neu, lösch die alte cofi.exe, lade CF neu als cofi.exe runter und probier es bitte nochmal.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.06.2011, 02:15 | #17 |
| Hive Cluster\49600\Megalomon_swarm Und hier Combofix log:
__________________Combofix Logfile: Code:
ATTFilter ComboFix 11-06-10.09 - Megalomon 11.06.2011 2:40.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4063.2487 [GMT 2:00] ausgeführt von:: c:\users\Megalomon\Desktop\Cofi.exe AV: Norton 360 Online *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton 360 Online *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton 360 Online *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Images c:\users\Megalomon\Documents\mspaint.exe . . ((((((((((((((((((((((( Dateien erstellt von 2011-05-11 bis 2011-06-11 )))))))))))))))))))))))))))))) . . 2011-06-11 00:48 . 2011-06-11 00:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2011-06-11 00:48 . 2011-06-11 00:48 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-06-10 22:29 . 2011-06-10 22:29 -------- d-----w- C:\Cofi 2011-06-10 16:19 . 2011-06-10 16:19 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2011-06-09 20:35 . 2011-06-09 20:35 -------- d-----w- C:\_OTL 2011-06-09 10:46 . 2011-06-09 10:46 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Malwarebytes 2011-06-09 10:46 . 2011-05-29 07:11 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-06-09 10:46 . 2011-06-09 10:46 -------- d-----w- c:\programdata\Malwarebytes 2011-06-09 10:46 . 2011-06-09 20:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-06-09 10:46 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-06-07 17:37 . 2011-06-07 17:37 -------- d-----w- c:\program files (x86)\Microsoft XNA 2011-06-07 17:14 . 2011-06-07 22:35 -------- d-----w- c:\program files (x86)\Terraria 2011-06-06 14:44 . 2011-06-06 14:44 -------- d-----w- c:\program files (x86)\Common Files\EZB Systems 2011-06-06 12:00 . 2011-06-06 14:44 -------- d-----w- c:\program files (x86)\UltraISO 2011-06-06 11:36 . 2011-06-06 11:36 -------- d-----w- c:\program files (x86)\Smart Projects 2011-06-06 11:24 . 2011-06-11 00:26 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Bitcoin 2011-06-06 11:24 . 2011-06-06 11:24 -------- d-----w- c:\program files (x86)\Bitcoin 2011-06-06 08:45 . 2011-05-20 11:49 34624 ----a-w- c:\windows\system32\TURegOpt.exe 2011-06-06 08:45 . 2011-05-20 11:43 36160 ----a-w- c:\windows\system32\uxtuneup.dll 2011-06-06 08:45 . 2011-05-20 11:43 25920 ----a-w- c:\windows\system32\authuitu.dll 2011-06-06 08:45 . 2011-05-20 11:43 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll 2011-06-06 08:45 . 2011-05-20 11:43 21312 ----a-w- c:\windows\SysWow64\authuitu.dll 2011-06-06 08:44 . 2011-06-06 08:44 -------- d-----w- c:\users\Megalomon\AppData\Roaming\TuneUp Software 2011-06-06 08:44 . 2011-06-06 08:45 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011 2011-06-06 08:43 . 2011-06-06 08:45 -------- d-----w- c:\programdata\TuneUp Software 2011-06-06 08:43 . 2011-06-06 08:43 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} 2011-06-05 22:30 . 2011-06-10 22:33 -------- d-----w- c:\programdata\SecTaskMan 2011-06-05 22:30 . 2011-06-05 22:30 -------- d-----w- c:\program files (x86)\Security Task Manager 2011-06-05 12:24 . 2011-06-05 12:25 -------- d-----w- c:\program files (x86)\TweakMe! 2011-06-04 13:14 . 2011-06-04 13:14 -------- d-sh--w- c:\programdata\DSS 2011-06-04 13:12 . 2011-05-19 20:30 446976 ----a-w- c:\program files (x86)\Microsoft Games\Fable III\paul.dll 2011-06-04 13:11 . 2011-06-04 13:11 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Lionhead Studios 2011-06-04 13:08 . 2011-05-17 19:42 79648 ----a-r- c:\program files (x86)\Microsoft Games\Fable III\UPDATE\setup.exe 2011-06-03 15:24 . 2011-06-03 15:24 -------- d-----w- c:\program files (x86)\Lionhead Studios Ltd 2011-06-03 15:11 . 2011-06-03 15:18 -------- d-----w- c:\program files\CCleaner 2011-06-03 12:33 . 2011-06-03 12:33 -------- d-----w- c:\program files (x86)\Visual Basic 6.0 Runtime&Steuerelemente 2011-06-03 12:32 . 2011-06-03 12:32 290816 ------w- c:\windows\Setup1.exe 2011-06-03 12:32 . 2011-06-03 12:32 74752 ----a-w- c:\windows\ST6UNST.EXE 2011-06-02 17:32 . 2011-06-02 17:32 53248 ----a-r- c:\users\Megalomon\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2011-06-02 17:32 . 2011-06-02 17:32 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Leadertech 2011-06-02 17:32 . 2011-06-02 17:32 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd 2011-06-02 17:32 . 2011-06-02 17:32 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2011-06-02 17:31 . 2011-06-02 17:44 -------- d-----w- c:\programdata\Logishrd 2011-06-02 17:31 . 2011-06-02 17:31 -------- d-----w- c:\program files\Logitech 2011-06-02 17:31 . 2011-06-02 17:32 -------- d-----w- c:\program files\Common Files\Logishrd 2011-06-02 17:21 . 2011-06-02 17:44 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Logitech 2011-06-02 17:21 . 2011-06-02 17:21 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Logishrd 2011-06-02 16:44 . 2011-06-02 16:49 -------- d-----w- c:\users\Megalomon\ThingZ 2011-06-02 14:15 . 2011-06-02 14:15 -------- d-----w- c:\program files (x86)\XMedia Recode 2011-06-01 23:52 . 2002-07-19 18:27 122350 ----a-w- c:\windows\system32\xbadpcm.acm 2011-06-01 23:37 . 2011-06-01 23:37 -------- d-----w- c:\program files (x86)\Software4u 2011-05-31 03:36 . 2011-05-31 03:36 -------- d-----w- c:\program files (x86)\MAGIX 2011-05-31 03:36 . 2011-05-31 03:36 -------- d-----w- c:\programdata\MAGIX 2011-05-31 03:36 . 2011-05-31 03:36 -------- d-----w- c:\program files (x86)\Common Files\MAGIX Services 2011-05-30 13:15 . 2009-03-18 15:35 33856 ---ha-w- c:\windows\system32\hamachi.sys 2011-05-30 13:15 . 2011-05-30 13:15 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi 2011-05-29 19:16 . 2011-05-31 03:37 -------- d-----w- c:\users\Megalomon\AppData\Roaming\MAGIX 2011-05-29 18:17 . 2001-04-12 16:00 182272 ----a-w- c:\windows\patchw32.dll 2011-05-26 10:49 . 2009-07-14 01:41 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\LXKPTPRC.DLL 2011-05-26 09:43 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-26 05:18 . 2011-05-26 05:18 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2011-05-26 05:18 . 2011-05-26 05:18 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2011-05-26 05:18 . 2011-05-26 05:18 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2011-05-26 05:18 . 2011-05-26 05:18 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2011-05-26 05:18 . 2011-05-26 05:18 -------- d-----w- c:\program files (x86)\OpenAL 2011-05-26 05:16 . 2011-05-26 05:18 -------- d-----w- c:\program files (x86)\Penumbra Overture 2011-05-25 15:22 . 2011-05-25 20:19 -------- d-----w- c:\users\Megalomon\.revenge_of_the_titans_1.80 2011-05-25 15:22 . 2011-05-25 15:22 -------- d-----w- c:\program files (x86)\Revenge Of The Titans HIB 2011-05-25 14:34 . 2009-10-27 17:31 3982240 ----a-w- c:\windows\SysWow64\Flash10d.ocx 2011-05-25 14:34 . 2011-05-25 14:34 -------- d-----w- c:\program files (x86)\StreamTransport 2011-05-25 10:22 . 2011-05-25 10:22 -------- d-----w- c:\program files (x86)\Data Realms 2011-05-25 07:47 . 2011-05-25 07:47 -------- d-----w- c:\users\Public\CyberLink 2011-05-25 07:47 . 2011-05-25 07:47 -------- d-----w- c:\users\Megalomon\AppData\Roaming\CyberLink 2011-05-25 06:34 . 2011-05-25 06:35 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Teeworlds 2011-05-24 10:23 . 2011-05-24 10:23 -------- d-----w- c:\program files (x86)\TeamViewer 2011-05-24 10:18 . 2011-05-24 10:18 -------- d-----w- c:\users\Megalomon\AppData\Roaming\TeamViewer 2011-05-24 09:36 . 2011-05-24 10:52 -------- d-----w- c:\users\Megalomon\AppData\Local\Temporary Projects 2011-05-23 13:56 . 2011-05-23 13:56 -------- d-----w- c:\program files (x86)\EA 2011-05-23 13:54 . 2011-05-23 13:54 -------- d-----w- c:\windows\8A809006C25A4A3A9DAB94659BCDB107.TMP 2011-05-22 16:40 . 2011-05-22 16:40 -------- d-----w- C:\Sierra 2011-05-19 17:39 . 2011-05-19 17:39 -------- d-----w- c:\programdata\NexonEU 2011-05-19 06:28 . 2011-06-10 13:31 -------- d-----w- C:\Downloads 2011-05-18 14:05 . 2011-05-18 14:06 -------- d-----w- c:\windows\msdownld.tmp 2011-05-18 14:05 . 2011-05-18 14:34 -------- d-----w- c:\program files (x86)\N8 2011-05-16 12:59 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2011-05-16 12:59 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe 2011-05-15 20:41 . 2011-05-15 20:41 -------- d-----w- c:\programdata\CanonBJ 2011-05-15 20:41 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL 2011-05-15 02:18 . 2011-05-15 02:18 -------- d-----w- c:\program files (x86)\Croteam 2011-05-13 06:09 . 2011-05-15 21:02 -------- d-----w- c:\users\Megalomon\AppData\Local\ElevatedDiagnostics 2011-05-12 10:24 . 2011-04-09 07:02 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-05-12 10:24 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-12 10:24 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-12 10:24 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-12 10:24 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-12 10:24 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2011-05-12 10:24 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-12 10:24 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-12 10:24 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys 2011-05-12 08:49 . 2011-06-07 17:30 -------- d-----w- c:\users\Megalomon\AppData\Local\CrashDumps . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-19 13:17 . 2011-05-01 07:24 235 ----a-w- c:\windows\SysWow64\nxEuUninstall.bat 2011-05-19 13:17 . 2011-05-01 07:24 446464 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe 2011-05-12 07:15 . 2011-04-30 09:45 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2011-05-06 19:50 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll 2011-05-06 19:50 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-04-30 10:00 . 2011-04-30 10:01 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2011-04-30 03:39 . 2011-04-30 03:39 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-04-30 03:39 . 2011-04-30 03:39 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-04-30 03:39 . 2011-04-30 03:39 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll 2011-04-30 03:39 . 2011-04-30 03:39 85504 ----a-w- c:\windows\system32\iesetup.dll 2011-04-30 03:39 . 2011-04-30 03:39 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-04-30 03:39 . 2011-04-30 03:39 76800 ----a-w- c:\windows\system32\tdc.ocx 2011-04-30 03:39 . 2011-04-30 03:39 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-04-30 03:39 . 2011-04-30 03:39 74752 ----a-w- c:\windows\SysWow64\iesetup.dll 2011-04-30 03:39 . 2011-04-30 03:39 63488 ----a-w- c:\windows\SysWow64\tdc.ocx 2011-04-30 03:39 . 2011-04-30 03:39 603648 ----a-w- c:\windows\system32\vbscript.dll 2011-04-30 03:39 . 2011-04-30 03:39 49664 ----a-w- c:\windows\system32\imgutil.dll 2011-04-30 03:39 . 2011-04-30 03:39 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2011-04-30 03:39 . 2011-04-30 03:39 48640 ----a-w- c:\windows\system32\mshtmler.dll 2011-04-30 03:39 . 2011-04-30 03:39 448512 ----a-w- c:\windows\system32\html.iec 2011-04-30 03:39 . 2011-04-30 03:39 420864 ----a-w- c:\windows\SysWow64\vbscript.dll 2011-04-30 03:39 . 2011-04-30 03:39 367104 ----a-w- c:\windows\SysWow64\html.iec 2011-04-30 03:39 . 2011-04-30 03:39 35840 ----a-w- c:\windows\SysWow64\imgutil.dll 2011-04-30 03:39 . 2011-04-30 03:39 30720 ----a-w- c:\windows\system32\licmgr10.dll 2011-04-30 03:39 . 2011-04-30 03:39 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2011-04-30 03:39 . 2011-04-30 03:39 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-04-30 03:39 . 2011-04-30 03:39 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll 2011-04-30 03:39 . 2011-04-30 03:39 2303488 ----a-w- c:\windows\system32\jscript9.dll 2011-04-30 03:39 . 2011-04-30 03:39 222208 ----a-w- c:\windows\system32\msls31.dll 2011-04-30 03:39 . 2011-04-30 03:39 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll 2011-04-30 03:39 . 2011-04-30 03:39 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2011-04-30 03:39 . 2011-04-30 03:39 165888 ----a-w- c:\windows\system32\iexpress.exe 2011-04-30 03:39 . 2011-04-30 03:39 161792 ----a-w- c:\windows\SysWow64\msls31.dll 2011-04-30 03:39 . 2011-04-30 03:39 160256 ----a-w- c:\windows\system32\wextract.exe 2011-04-30 03:39 . 2011-04-30 03:39 152064 ----a-w- c:\windows\SysWow64\wextract.exe 2011-04-30 03:39 . 2011-04-30 03:39 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2011-04-30 03:39 . 2011-04-30 03:39 1492992 ----a-w- c:\windows\system32\inetcpl.cpl 2011-04-30 03:39 . 2011-04-30 03:39 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2011-04-30 03:39 . 2011-04-30 03:39 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2011-04-30 03:39 . 2011-04-30 03:39 1389056 ----a-w- c:\windows\system32\wininet.dll 2011-04-30 03:39 . 2011-04-30 03:39 135168 ----a-w- c:\windows\system32\IEAdvpack.dll 2011-04-30 03:39 . 2011-04-30 03:39 12288 ----a-w- c:\windows\system32\mshta.exe 2011-04-30 03:39 . 2011-04-30 03:39 11776 ----a-w- c:\windows\SysWow64\mshta.exe 2011-04-30 03:39 . 2011-04-30 03:39 114176 ----a-w- c:\windows\system32\admparse.dll 2011-04-30 03:39 . 2011-04-30 03:39 1126912 ----a-w- c:\windows\SysWow64\wininet.dll 2011-04-30 03:39 . 2011-04-30 03:39 111616 ----a-w- c:\windows\system32\iesysprep.dll 2011-04-30 03:39 . 2011-04-30 03:39 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-04-30 03:39 . 2011-04-30 03:39 101888 ----a-w- c:\windows\SysWow64\admparse.dll 2011-04-30 03:07 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll 2011-04-30 03:07 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2011-04-30 01:37 . 2009-11-07 20:54 588472 ----a-w- c:\windows\SysWow64\ezsvc7x.dll 2011-04-18 07:15 . 2011-04-30 02:00 8802128 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B0804166-B8DE-46CB-A80C-C36F9FC4C858}\mpengine.dll 2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll 2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll 2011-04-08 05:14 . 2011-04-30 09:31 8411752 ----a-w- c:\windows\system32\nvwgf2umx.dll 2011-04-08 05:14 . 2011-04-30 09:31 6974056 ----a-w- c:\windows\system32\nvcuda.dll 2011-04-08 05:14 . 2011-04-30 09:31 67176 ----a-w- c:\windows\system32\OpenCL.dll 2011-04-08 05:14 . 2011-04-30 09:31 6299752 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2011-04-08 05:14 . 2011-04-30 09:31 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll 2011-04-08 05:14 . 2011-04-30 09:31 5183080 ----a-w- c:\windows\SysWow64\nvcuda.dll 2011-04-08 05:14 . 2011-04-30 09:31 2893416 ----a-w- c:\windows\system32\nvcuvid.dll 2011-04-08 05:14 . 2011-04-30 09:31 2765928 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2011-04-08 05:14 . 2011-04-30 09:31 2273896 ----a-w- c:\windows\system32\nvapi64.dll 2011-04-08 05:14 . 2011-04-30 09:31 2204264 ----a-w- c:\windows\system32\nvcuvenc.dll 2011-04-08 05:14 . 2011-04-30 09:31 2074216 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2011-04-08 05:14 . 2011-04-30 09:31 20700264 ----a-w- c:\windows\system32\nvoglv64.dll 2011-04-08 05:14 . 2011-04-30 09:31 2034280 ----a-w- c:\windows\SysWow64\nvapi.dll 2011-04-08 05:14 . 2011-04-30 09:31 18578536 ----a-w- c:\windows\system32\nvcompiler.dll 2011-04-08 05:14 . 2011-04-30 09:31 1619048 ----a-w- c:\windows\system32\nvdispco6420140.dll 2011-04-08 05:14 . 2011-04-30 09:31 15227496 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2011-04-08 05:14 . 2011-04-30 09:31 1404008 ----a-w- c:\windows\system32\nvgenco642060.dll 2011-04-08 05:14 . 2011-04-30 09:31 13262184 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2011-04-08 05:14 . 2011-04-30 09:31 13007464 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2011-04-08 05:14 . 2011-04-30 09:31 12934248 ----a-w- c:\windows\system32\nvd3dumx.dll 2011-04-08 05:14 . 2011-04-30 09:31 10071656 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2011-04-07 21:19 . 2011-04-07 21:19 61032 ----a-w- c:\windows\system32\nvshext.dll 2011-04-07 21:19 . 2011-04-07 21:19 318056 ----a-w- c:\windows\system32\nvhotkey.dll 2011-04-07 21:19 . 2011-04-07 21:19 2582120 ----a-w- c:\windows\system32\nvsvcr.dll 2011-04-07 21:19 . 2011-04-07 21:19 117864 ----a-w- c:\windows\system32\nvmctray.dll 2011-04-07 21:19 . 2011-04-07 21:19 1012328 ----a-w- c:\windows\system32\nvvsvc.exe 2011-04-07 21:19 . 2011-04-07 21:19 797288 ----a-w- c:\windows\system32\easyUpdatusAPIU64.dll 2011-04-07 21:19 . 2011-04-07 21:19 6338152 ----a-w- c:\windows\system32\nvcpl.dll 2011-04-07 21:18 . 2011-04-07 21:18 3041384 ----a-w- c:\windows\system32\nvsvc64.dll 2011-04-06 14:26 . 2011-04-06 14:26 96544 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 14:26 . 2011-04-06 14:26 69408 ----a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 14:26 . 2011-04-06 14:26 237856 ----a-w- c:\windows\system32\dnssdX.dll 2011-04-06 14:26 . 2011-04-06 14:26 119584 ----a-w- c:\windows\system32\dns-sd.exe 2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\SysWow64\jdns_sd.dll 2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\SysWow64\dnssdX.dll 2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\SysWow64\dns-sd.exe 2011-03-31 03:00 . 2011-05-10 06:36 744568 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\srtsp64.sys 2011-03-31 03:00 . 2011-05-10 06:36 40568 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\srtspx64.sys 2011-03-22 00:39 . 2011-05-10 06:36 382584 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\symnets.sys 2011-03-15 02:31 . 2011-05-10 06:36 912504 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\symefa64.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-28 843072] "iTeleportConnect"="c:\program files (x86)\iTeleport\iTeleport Connect\iTeleportConnect.exe" [2011-04-11 1989120] "ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 89600] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "iTeleportService"="c:\program files (x86)\iTeleport\iTeleport Connect\iTeleportService.exe" [2011-04-11 20480] . c:\users\Megalomon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ BatteryBar.lnk - c:\program files\BatteryBar\BatteryBar.exe [N/A] Bitcoin.lnk - c:\program files (x86)\Bitcoin\bitcoin.exe [2011-4-27 7490048] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "LogMeIn Hamachi Ui"=-"c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408] R3 DAUpdaterSvc;Dragon Age: Origins - Inhaltsupdater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888] R3 NETw1v64;Intel(R) Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw1v64.sys [x] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110519.002\BHDrvx64.sys [2011-05-19 1143416] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110604.001\IDSvia64.sys [2011-06-03 488056] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\0501000.01D\SYMNETS.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] S2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-10-18 20549] S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376] S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720] S2 iTeleportService;iTeleportService;c:\program files (x86)\iTeleport\iTeleport Connect\iTeleportService.exe [2011-04-11 20480] S2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008] S2 NetBalancer Windows Service;NetBalancer Windows Service;c:\program files\NetBalancer\SeriousBit.NetBalancer.Service.exe [2010-11-22 10240] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-05-20 2026304] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-10 136824] S3 Nbdrv;NetBalancer Service;c:\windows\system32\DRIVERS\nbdrv.sys [x] S3 NETw5s64;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-04-26 11856] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Inhalt des "geplante Tasks" Ordners . 2011-06-09 c:\windows\Tasks\HPCeeScheduleForMegalomon.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 03:22] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-05-13 487424] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Megalomon\AppData\Roaming\Mozilla\Firefox\Profiles\vem6yn1k.default\ FF - prefs.js: browser.startup.homepage - about:home FF - user.js: network.http.max-connections-per-server - 6 FF - user.js: network.http.max-persistent-connections-per-server - 3 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-QlbCtrl.exe - -c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\xampp\mysql\bin\mysqld.exe c:\program files (x86)\CyberLink\Shared files\RichVideo.exe c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe c:\program files\NORTON 360\ENGINE\5.1.0.29\cltLMH.exe . ************************************************************************** . Zeit der Fertigstellung: 2011-06-11 03:06:25 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2011-06-11 01:06 . Vor Suchlauf: 27 Verzeichnis(se), 108.097.830.912 Bytes frei Nach Suchlauf: 33 Verzeichnis(se), 107.947.724.800 Bytes frei . - - End Of File - - 009DB80BEF683B6FF28E1A447236829A Ich bin grad etwas verwirrt, wieso wurde mspaint und der images ordner gelöscht? |
11.06.2011, 16:45 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Hive Cluster\49600\Megalomon_swarm Downloade Dir bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________
__________________ |
11.06.2011, 18:47 | #19 | |
| Hive Cluster\49600\Megalomon_swarm Scan lief ohne Probleme. Zitat:
|
11.06.2011, 19:25 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Hive Cluster\49600\Megalomon_swarm Wir sollten den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten. Hast Du noch andere Betriebssysteme außer Win7 (64-Bit) installiert? Wenn nicht: Schau mal hier => RescueDisc-Win7-64-Bit Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten) Falls Du eine normale Win7-Installations-DVD (64-Bit) hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten. Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.06.2011, 20:24 | #21 |
| Hive Cluster\49600\Megalomon_swarm Ich hätte sone DVD-Sammlung von HP zu der ich aufgefordert wurde diese zu brennen nachdem ich das Laptop das erste mal in betrieb genommen habe. Es sind 4 DVD's. Sind wohl dafür da, falls die recovery-partition nen schaden hat. Könnte einen von denen auch gehen? |
11.06.2011, 20:52 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Hive Cluster\49600\Megalomon_swarm Nein, nimm lieber die ISO und brenn es.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.06.2011, 23:30 | #23 | |
| Hive Cluster\49600\Megalomon_swarm Beides Problemlos verlaufen: MBRCheck: Zitat:
GMER Logfile: Code:
ATTFilter GMER 1.0.15.15640 - hxxp://www.gmer.net Rootkit scan 2011-06-12 00:30:15 Windows 6.1.7601 Service Pack 1 Running: 1208ky31.exe ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4D 0x54 0x5E 0x06 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0xC2 0x0F 0x9E ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x61 0x65 0x23 0xC5 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDA 0x0A 0x48 0xAC ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x79 0x7D 0x0A 0x41 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0x57 0x56 0x05 0x6A ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4D 0x54 0x5E 0x06 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0xC2 0x0F 0x9E ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x61 0x65 0x23 0xC5 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDA 0x0A 0x48 0xAC ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x79 0x7D 0x0A 0x41 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0x57 0x56 0x05 0x6A ... ---- EOF - GMER 1.0.15 ---- |
13.06.2011, 18:35 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Hive Cluster\49600\Megalomon_swarm Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
14.06.2011, 14:43 | #25 |
| Hive Cluster\49600\Megalomon_swarm Die Explorer.exe stürzt leider immernoch von Zeit zu Zeit ab. |
Themen zu Hive Cluster\49600\Megalomon_swarm |
aller dateien, allgemeine, allgemeinen, andere, anderen, appdata, befinden, besondere, bewusst, cluster, dateien, frage, inhalt, installier, installierte, ordner, programm, punkt, roaming, servus, suche, unterverzeichnis, users, warscheinlich, winrar, zuordnen |