|
Plagegeister aller Art und deren Bekämpfung: Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.10.2011, 14:17 | #1 | ||
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Hallo, Ich versuche, alles genau nach der Anweisung zu machen, kenne mich mit dem ganzen Kram leider nicht gut aus – wenn etwas fehlt oder falsch ist, ist das keine Faulheit oder Frechheit, sondern schlicht Unfähigkeit, tut mir Leid! Das Problem: ich habe mir gestern anscheinend einen fakesysdef-Trojaner namens fakesysdef.506 eingefangen. Ich vermute, ihr wisst, was das Programm macht; gefakte Fehlermeldungen, ein angebliches Restore-Programm (bei mir hieß es „Data Restore“), versteckte Dateien, schwarzer Desktop. Ich muss gestehen, dass ich zuerst nicht realisiert habe, dass das ein Trojaner ist, sondern das Fake-Programm weitergeklickt habe. Ich habe Windows 7 (64bit) erst seit wenigen Wochen und bin mit der Benutzeroberfläche nicht so vertraut… erst bei der Aufforderung, die kostenpflichtige „Vollversion“ zu laden, hat’s irgendwann geklingelt, dass das eine malware sein könnte Was ich schon unternommen habe: Nach Internetrecherche habe ich einiges über das Problem gefunden, bin in den abgesicherten Modus gegangen und habe die aktiven Dateien dazu gelöscht, ebenso die Verknüpfung zu dem angeblichen Sicherungsprogramm und den beinhaltenden Ordner dazu (hieß "Data Restore" und hatte ein W7 - Logo). Dadurch war das laufende "sicherungs-"Programm weg und ich konnte den PC erstmal wieder normal nutzen. Ich habe verschiedentlich gelesen, dass man auch in der Registry etwas löschen muss, die Anleitung (hxxp://www.computerwissen.de/sicherheit/aktuelles/malware-und-spam/artikel/hinterlistiges-schadprogramm-microsoft-warnt-vor-system-defragmenter.html) war aber anscheinend für XP oder für eine ältere malware-Version, denn ich habe komplett andere Pfade. Ich habe nur in den ProgramData gelöscht, weil ich diesen als korrespondierenden Ordner zum XP-Ordner All Users/Application Data gefunden habe. Ich nutze Avira Antivir Personal und habe den daraufhin noch mal laufen lassen, welches fünf Dateien zu dem Trojaner in die Quarantäne geschoben hat (schon hatte?); TRFakeSysDef.506; vier davon in ProgramData/nxBPpaqQtFIXr.exe, eine in Users\***\AppData\Local\Microsoft\Windows\Temporary internet files\Content.IE5\D4K1N2PF\about[1].exe Dazu gleich eine Frage: Was mache ich damit? Hab es ans Virenlabor gesendet und nur die schon bekannte Info per Mail gekriegt, dass es sich um malware handelt. Kann/muss/soll ich das jetzt aus der Quarantäne löschen? Anschließend war das Fake-Programm gestoppt und nicht mehr auffindbar, das desktop konnte ich zurück ändern, und mit dem unhide-tool konnte ich die Dateien wieder normal sichtbar machen. Natürlich wüsste ich jetzt aber gern, ob es das war oder ob der PC immer noch verseucht ist und hoffe sehr, dass ihr mir helfen könnt! Ich habe mir anschließend noch Malwarebytes Antimaleware runtergeladen und dann manuell aktualisiert, laufen lassen und dieses Programm hat auch nichts mehr gefunden (war ein Vollscan). Der Log von Malwarebytes, falls das etwas nutzt (wenn unerwünscht, entschuldigung!): Zitat:
Nun zu den Log-Files: 1. defogger von jpshortstuff Habe ich runtergeladen, als Admin ausgeführt, „Disable“ geklickt und bekam eine Meldung, dass er jetzt was deaktivieren würde, habe das bestätigt, aber der Suchlauf war praktisch sofort beendet (Finished!) ohne Bericht oder Aufforderung zum Neustart, daher fürchte ich, dass das wohl nicht ganz geklappt hat. Daher hier der defogger_disable-Log. Zitat:
OTL Logfile: Code:
ATTFilter OTL logfile created on: 07.10.2011 14:26:20 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Lea\Desktop 64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,73 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 67,14% Memory free 7,45 Gb Paging File | 6,09 Gb Available in Paging File | 81,68% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 244,14 Gb Total Space | 197,29 Gb Free Space | 80,81% Space Free | Partition Type: NTFS Drive D: | 488,28 Gb Total Space | 464,79 Gb Free Space | 95,19% Space Free | Partition Type: NTFS Drive E: | 664,74 Gb Total Space | 664,64 Gb Free Space | 99,98% Space Free | Partition Type: NTFS Computer Name: LEASCOMPI | User Name: Lea | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.10.07 14:24:41 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL.exe PRC - [2011.10.07 13:53:22 | 000,059,964 | ---- | M] (Macrovision Europe Ltd.) -- C:\Users\Lea\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 PRC - [2011.09.15 18:36:59 | 000,079,360 | ---- | M] (Creative Labs) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe PRC - [2011.09.15 18:35:05 | 004,942,336 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFastUsb\XFastUsb.exe PRC - [2011.07.21 12:08:02 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2011.04.21 07:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2011.02.01 13:20:48 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011.02.01 13:20:46 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010.10.26 16:15:48 | 001,699,912 | ---- | M] (Elgato Systems) -- C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe PRC - [2010.05.14 07:02:56 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files (x86)\CyberLink\Shared files\brs.exe PRC - [2009.12.15 13:47:00 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe PRC - [2009.07.08 15:32:50 | 001,233,195 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe PRC - [2009.07.06 14:22:04 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe PRC - [2009.05.04 19:05:04 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe PRC - [2009.02.23 05:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe ========== Modules (No Company Name) ========== MOD - [2011.10.07 13:53:22 | 000,697,884 | ---- | M] () -- C:\Users\Lea\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0022\~df394b.tmp MOD - [2011.10.07 13:53:22 | 000,592,896 | ---- | M] () -- C:\Users\Lea\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0022\~de6248.tmp MOD - [2011.05.26 13:42:00 | 000,067,872 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2010.04.22 12:42:56 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll MOD - [2010.04.22 12:42:54 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll MOD - [2010.04.22 12:42:54 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll MOD - [2009.12.15 13:49:20 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll MOD - [2009.12.15 13:46:38 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll MOD - [2009.04.20 11:55:58 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL MOD - [2009.02.06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL ========== Win32 Services (SafeList) ========== SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2011.09.15 18:37:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service) SRV - [2011.09.15 18:37:27 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service) SRV - [2011.09.15 18:36:59 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service) SRV - [2011.07.21 12:08:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011.02.01 13:20:48 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R) SRV - [2011.02.01 13:20:46 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R) SRV - [2010.05.14 14:02:54 | 000,246,256 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe -- (CLKMSVC10_9EC60124) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.02.23 05:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011.09.15 18:40:20 | 000,031,808 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305) DRV:64bit: - [2011.09.15 18:35:06 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX) DRV:64bit: - [2011.08.31 19:53:22 | 012,306,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2011.07.21 12:11:10 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2011.07.21 12:11:09 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2011.02.08 07:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI) DRV:64bit: - [2011.02.08 07:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3) DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.10.19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R) DRV:64bit: - [2010.10.19 14:23:18 | 001,179,896 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\y_cx88x.sys -- (cxpl_mhd) DRV:64bit: - [2010.10.14 18:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R) DRV:64bit: - [2010.06.23 11:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2010.06.11 14:37:14 | 000,015,368 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C8 C4 20 F5 C7 73 CC 01 [binary data] IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.ecosia.org/" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.10.06 18:16:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.15 19:11:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2011.09.15 18:56:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lea\AppData\Roaming\mozilla\Extensions [2011.09.16 17:09:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lea\AppData\Roaming\mozilla\Firefox\Profiles\4tiqbgij.default\extensions [2011.09.15 18:55:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2011.10.03 22:09:41 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011.09.03 02:19:44 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.09.03 02:13:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2011.09.03 02:19:44 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011.09.03 02:19:44 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011.09.03 02:19:44 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011.09.03 02:19:44 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~2\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink) O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd) O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKLM..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe (FNet Co., Ltd.) O4 - HKCU..\Run: [ASRockXTU] File not found O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe (Elgato Systems) O4 - HKCU..\Run: [zASRockInstantBoot] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB5872B9-2107-4955-B1F7-2CFDFA09C0B2}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\cdo - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{68ca9c7c-dfb8-11e0-8ff1-002522c2fd68}\Shell - "" = AutoRun O33 - MountPoints2\{68ca9c7c-dfb8-11e0-8ff1-002522c2fd68}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker 2.6 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) MsConfig:64bit - StartUpReg: LGODDFU - hkey= - key= - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader) MsConfig:64bit - State: "startup" - Reg Error: Key error. MsConfig:64bit - State: "bootini" - Reg Error: Key error. CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.10.07 14:24:40 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL.exe [2011.10.06 23:21:37 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\ElevatedDiagnostics [2011.10.06 23:19:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Texmaker [2011.10.06 23:19:15 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Texmaker [2011.10.06 23:19:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Texmaker [2011.10.06 23:04:20 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\MiKTeX [2011.10.06 21:13:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Malwarebytes [2011.10.06 21:13:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.10.06 21:13:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.10.06 21:13:01 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011.10.06 21:13:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011.10.06 21:12:32 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Lea\mbam-setup-1.51.2.1300.exe [2011.10.06 18:30:12 | 000,000,000 | ---D | C] -- C:\Windows\pss [2011.10.06 17:29:59 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Avira [2011.10.03 16:50:50 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games [2011.09.29 16:54:02 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Splashtop [2011.09.26 19:00:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\Documents\My Albums [2011.09.26 19:00:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\ArcSoft [2011.09.26 08:59:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache [2011.09.25 11:50:17 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Brother [2011.09.22 20:26:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [2011.09.22 18:50:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra [2011.09.22 18:49:59 | 001,053,184 | ---- | C] (Cendant Software) -- C:\Windows\SysWow64\SierraNW.dll [2011.09.22 18:49:59 | 000,231,936 | ---- | C] (Cendant Software) -- C:\Windows\SysWow64\SNWValid.dll [2011.09.22 18:49:59 | 000,000,000 | ---D | C] -- C:\Windows\solcache [2011.09.22 18:48:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sierra On-Line [2011.09.22 18:48:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spiele [2011.09.22 18:40:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES [2011.09.22 18:39:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\Documents\EA Games [2011.09.22 18:34:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EA GAMES [2011.09.22 18:34:33 | 000,442,368 | R--- | C] (On2.com) -- C:\Windows\SysWow64\vp6vfw.dll [2011.09.20 20:26:54 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\.purple [2011.09.20 20:21:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pidgin [2011.09.20 20:16:31 | 000,000,000 | ---D | C] -- C:\ProgramData\MiKTeX [2011.09.20 20:15:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MiKTeX 2.8 [2011.09.20 20:08:47 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2011.09.19 19:09:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft PhotoStudio 5.5 [2011.09.19 19:09:27 | 000,212,480 | ---- | C] (Eastman Kodak) -- C:\Windows\pcdlib32.dll [2011.09.19 19:09:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ArcSoft [2011.09.19 19:07:29 | 000,000,000 | ---D | C] -- C:\CanoScan [2011.09.18 01:40:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\WMTools Downloaded Files [2011.09.18 01:36:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movie Maker 2.6 [2011.09.16 23:57:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0 [2011.09.16 17:24:06 | 000,000,000 | R--D | C] -- C:\Users\Lea\Videos [2011.09.16 17:24:06 | 000,000,000 | R--D | C] -- C:\Users\Lea\Pictures [2011.09.16 17:23:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\Application Data [2011.09.16 17:02:53 | 000,000,000 | R--D | C] -- C:\Users\Lea\Music [2011.09.16 16:58:13 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\vlc [2011.09.16 16:58:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2011.09.16 16:58:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VLC Player [2011.09.16 16:57:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Google [2011.09.16 16:57:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit [2011.09.16 16:57:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConduitEngine [2011.09.16 16:56:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winload [2011.09.16 16:56:59 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Conduit [2011.09.16 16:06:19 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Adobe [2011.09.16 16:01:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools [2011.09.16 16:01:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Designer [2011.09.16 16:00:46 | 000,000,000 | ---D | C] -- C:\Windows\Msagent [2011.09.16 16:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2011.09.16 15:25:22 | 000,000,000 | ---D | C] -- C:\Users\Lea\Documents\CyberLink [2011.09.16 15:13:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Power2Go [2011.09.15 22:04:33 | 000,000,000 | ---D | C] -- C:\Temp [2011.09.15 22:04:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG Tool Kit [2011.09.15 22:03:54 | 000,016,384 | ---- | C] (BitLeader) -- C:\Windows\SysWow64\lgfwunis.exe [2011.09.15 22:03:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\lg_fwupdate [2011.09.15 19:37:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\CyberLink [2011.09.15 19:35:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\CrashDumps [2011.09.15 19:35:12 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\CyberLink [2011.09.15 19:35:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Cyberlink [2011.09.15 19:32:38 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling [2011.09.15 19:32:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LightScribe [2011.09.15 19:32:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite [2011.09.15 19:31:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite [2011.09.15 19:31:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CyberLink [2011.09.15 19:29:54 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink [2011.09.15 19:29:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp [2011.09.15 19:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\TerraTec [2011.09.15 19:23:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TerraTec [2011.09.15 19:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TerraTec [2011.09.15 19:22:49 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\TerraTec [2011.09.15 19:20:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TerraTec [2011.09.15 19:12:50 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2011.09.15 19:12:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Apple Computer [2011.09.15 19:12:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Apple Computer [2011.09.15 19:12:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011.09.15 19:11:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2011.09.15 19:11:44 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2011.09.15 19:11:43 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2011.09.15 19:11:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2011.09.15 19:11:43 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2011.09.15 19:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2011.09.15 19:11:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2011.09.15 19:11:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2011.09.15 19:11:03 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Apple [2011.09.15 19:11:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2011.09.15 19:10:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2011.09.15 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2011.09.15 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour [2011.09.15 19:10:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2011.09.15 19:10:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple [2011.09.15 19:05:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011.09.15 19:05:23 | 000,123,784 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys [2011.09.15 19:05:23 | 000,088,288 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys [2011.09.15 19:05:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2011.09.15 19:05:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2011.09.15 19:03:51 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Thunderbird [2011.09.15 19:03:51 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Thunderbird [2011.09.15 19:03:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird [2011.09.15 18:58:35 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2011.09.15 18:55:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Mozilla [2011.09.15 18:55:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Mozilla [2011.09.15 18:55:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2011.09.15 18:51:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt [2011.09.15 18:43:42 | 000,000,000 | ---D | C] -- C:\ProgramData\DeviceVM [2011.09.15 18:42:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2011.09.15 18:40:49 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2011.09.15 18:40:41 | 000,000,000 | ---D | C] -- C:\ProgramData\{8533ADFA-85F0-4dc1-946A-2A0BA58E78E3} [2011.09.15 18:40:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\DeviceVm [2011.09.15 18:40:20 | 000,031,808 | ---- | C] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS [2011.09.15 18:38:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative [2011.09.15 18:38:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative Installation Information [2011.09.15 18:37:58 | 002,873,822 | ---- | C] (Creative) -- C:\Windows\SysWow64\Sens_oal.dll [2011.09.15 18:37:58 | 001,910,272 | ---- | C] (Creative) -- C:\Windows\SysNative\Sens_oal.dll [2011.09.15 18:37:58 | 000,466,456 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2011.09.15 18:37:58 | 000,444,952 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2011.09.15 18:37:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative [2011.09.15 18:37:22 | 000,000,000 | ---D | C] -- C:\Program Files\Creative [2011.09.15 18:36:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative Labs Shared [2011.09.15 18:36:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Creative [2011.09.15 18:36:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative [2011.09.15 18:36:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2011.09.15 18:36:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Macromedia [2011.09.15 18:36:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Adobe [2011.09.15 18:35:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2011.09.15 18:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2011.09.15 18:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2011.09.15 18:35:06 | 000,015,936 | ---- | C] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETURPX.SYS [2011.09.15 18:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\FNET [2011.09.15 18:35:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XFastUsb [2011.09.15 18:35:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB [2011.09.15 18:34:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASRock Utility [2011.09.15 18:34:46 | 000,015,368 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\AsrAppCharger.sys [2011.09.15 18:34:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility [2011.09.15 18:34:46 | 000,000,000 | ---D | C] -- C:\Program Files\ASRock Utility [2011.09.15 18:34:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Etron Technology [2011.09.15 18:34:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel [2011.09.15 18:34:05 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2011.09.15 18:32:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent [2011.09.15 18:32:25 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\InstallShield [2011.09.15 18:31:59 | 000,344,680 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys [2011.09.15 18:31:17 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM [2011.09.15 18:31:17 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2011.09.15 18:31:10 | 002,601,816 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll [2011.09.15 18:31:10 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll [2011.09.15 18:31:10 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll [2011.09.15 18:31:10 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll [2011.09.15 18:31:10 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll [2011.09.15 18:31:10 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll [2011.09.15 18:31:10 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll [2011.09.15 18:31:10 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll [2011.09.15 18:31:10 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll [2011.09.15 18:31:09 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll [2011.09.15 18:31:09 | 000,338,336 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll [2011.09.15 18:31:09 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll [2011.09.15 18:31:09 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll [2011.09.15 18:31:09 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll [2011.09.15 18:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Temp [2011.09.15 18:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek [2011.09.15 18:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information [2011.09.15 18:31:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield [2011.09.15 18:30:32 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel [2011.09.15 18:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel [2011.09.15 18:30:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel [2011.09.15 18:30:00 | 000,004,096 | ---- | C] ( ) -- C:\Windows\SysNative\IGFXDEVLib.dll [2011.09.15 18:28:00 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll [2011.09.15 18:28:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel [2011.09.15 18:27:58 | 000,000,000 | ---D | C] -- C:\Intel [2011.09.15 18:24:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Diagnostics [2011.09.15 18:20:59 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011.09.15 18:20:59 | 000,000,000 | R--D | C] -- C:\Users\Lea\Searches [2011.09.15 18:20:59 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011.09.15 18:20:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Identities [2011.09.15 18:20:46 | 000,000,000 | R--D | C] -- C:\Users\Lea\Contacts [2011.09.15 18:20:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\VirtualStore [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Vorlagen [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\AppData\Local\Verlauf [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\AppData\Local\Temporary Internet Files [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Startmenü [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\SendTo [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Recent [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Netzwerkumgebung [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Lokale Einstellungen [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Documents\Eigene Videos [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Documents\Eigene Musik [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Eigene Dateien [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Documents\Eigene Bilder [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Druckumgebung [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Cookies [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\AppData\Local\Anwendungsdaten [2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Anwendungsdaten [2011.09.15 18:20:34 | 000,000,000 | --SD | C] -- C:\Users\Lea\AppData\Roaming\Microsoft [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Links [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Favorites [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Downloads [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Documents [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Desktop [2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Temp [2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Microsoft [2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Media Center Programs [2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData [2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Recovery [2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Programme [2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien [2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2011.09.15 18:16:11 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2011.09.15 18:14:02 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2011.09.15 18:13:22 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.10.07 14:24:41 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL.exe [2011.10.07 14:05:26 | 000,000,000 | ---- | M] () -- C:\Users\Lea\defogger_reenable [2011.10.07 14:03:28 | 000,050,477 | ---- | M] () -- C:\Users\Lea\Desktop\Defogger.exe [2011.10.07 14:00:32 | 000,022,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.10.07 14:00:32 | 000,022,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.10.07 14:00:18 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011.10.07 14:00:18 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2011.10.07 14:00:18 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011.10.07 14:00:18 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2011.10.07 14:00:18 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011.10.07 13:53:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.10.07 13:53:07 | 3001,565,184 | -HS- | M] () -- C:\hiberfil.sys [2011.10.06 21:12:34 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Lea\mbam-setup-1.51.2.1300.exe [2011.10.06 20:49:59 | 000,001,921 | ---- | M] () -- C:\Users\Lea\Desktop\Sims2EP8 - Verknüpfung.lnk [2011.09.26 16:20:54 | 000,015,428 | ---- | M] () -- C:\Users\Lea\RefEdit.exd [2011.09.25 11:32:45 | 000,296,160 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2011.09.22 19:05:06 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf [2011.09.22 19:05:05 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf [2011.09.22 18:50:34 | 000,001,654 | ---- | M] () -- C:\Windows\wininit.ini [2011.09.22 18:50:34 | 000,000,151 | ---- | M] () -- C:\Windows\tmpcpyis.bat [2011.09.22 18:50:34 | 000,000,122 | ---- | M] () -- C:\Windows\tmpdelis.bat [2011.09.22 18:50:34 | 000,000,026 | ---- | M] () -- C:\Windows\winstart.bat [2011.09.22 18:50:17 | 000,001,369 | ---- | M] () -- C:\Users\Lea\Desktop\Caesar 3.lnk [2011.09.22 18:50:07 | 000,000,403 | ---- | M] () -- C:\Windows\SIERRA.INI [2011.09.22 14:06:12 | 000,000,343 | ---- | M] () -- C:\Windows\lgfwup.ini [2011.09.20 20:08:46 | 310,217,089 | ---- | M] () -- C:\Windows\MEMORY.DMP [2011.09.18 01:38:19 | 000,003,584 | ---- | M] () -- C:\Users\Lea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.09.16 17:14:41 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2011.09.16 16:01:40 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI [2011.09.15 22:05:17 | 000,016,384 | ---- | M] (BitLeader) -- C:\Windows\SysWow64\lgfwunis.exe [2011.09.15 19:14:16 | 000,000,425 | ---- | M] () -- C:\Windows\BRWMARK.INI [2011.09.15 19:14:16 | 000,000,027 | ---- | M] () -- C:\Windows\BRPP2KA.INI [2011.09.15 19:13:36 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2011.09.15 18:40:20 | 000,031,808 | ---- | M] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS [2011.09.15 18:38:03 | 000,000,159 | R--- | M] () -- C:\Windows\ctfile.rfc [2011.09.15 18:37:58 | 000,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2011.09.15 18:37:58 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2011.09.15 18:35:06 | 000,015,936 | ---- | M] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETURPX.SYS [2011.09.15 18:34:09 | 000,018,340 | ---- | M] () -- C:\Windows\SysNative\results.xml [2011.09.15 18:16:49 | 000,177,271 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2011.09.15 18:16:49 | 000,177,271 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.10.07 14:05:26 | 000,000,000 | ---- | C] () -- C:\Users\Lea\defogger_reenable [2011.10.07 14:02:42 | 000,050,477 | ---- | C] () -- C:\Users\Lea\Desktop\Defogger.exe [2011.10.06 20:49:59 | 000,001,921 | ---- | C] () -- C:\Users\Lea\Desktop\Sims2EP8 - Verknüpfung.lnk [2011.09.26 16:20:54 | 000,015,428 | ---- | C] () -- C:\Users\Lea\RefEdit.exd [2011.09.22 19:05:06 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf [2011.09.22 19:05:05 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf [2011.09.22 18:50:34 | 000,001,654 | ---- | C] () -- C:\Windows\wininit.ini [2011.09.22 18:50:34 | 000,000,151 | ---- | C] () -- C:\Windows\tmpcpyis.bat [2011.09.22 18:50:34 | 000,000,122 | ---- | C] () -- C:\Windows\tmpdelis.bat [2011.09.22 18:50:34 | 000,000,026 | ---- | C] () -- C:\Windows\winstart.bat [2011.09.22 18:50:17 | 000,001,369 | ---- | C] () -- C:\Users\Lea\Desktop\Caesar 3.lnk [2011.09.22 18:47:26 | 000,000,403 | ---- | C] () -- C:\Windows\SIERRA.INI [2011.09.20 20:08:46 | 310,217,089 | ---- | C] () -- C:\Windows\MEMORY.DMP [2011.09.19 19:09:27 | 000,000,021 | ---- | C] () -- C:\Windows\PS_setup.ini [2011.09.18 01:38:19 | 000,003,584 | ---- | C] () -- C:\Users\Lea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.09.16 17:14:41 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2011.09.16 16:01:40 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011.09.15 22:04:00 | 000,000,343 | ---- | C] () -- C:\Windows\lgfwup.ini [2011.09.15 19:14:16 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI [2011.09.15 19:14:16 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI [2011.09.15 19:13:36 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2011.09.15 18:38:15 | 000,005,037 | ---- | C] () -- C:\Windows\SysNative\cfgfx.ini [2011.09.15 18:38:15 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini [2011.09.15 18:38:15 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini [2011.09.15 18:38:15 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini [2011.09.15 18:38:03 | 000,191,488 | ---- | C] () -- C:\Windows\SysNative\APOMgr64.DLL [2011.09.15 18:38:03 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2011.09.15 18:38:03 | 000,089,088 | ---- | C] () -- C:\Windows\SysNative\CmdRtr64.DLL [2011.09.15 18:38:03 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2011.09.15 18:38:03 | 000,000,159 | R--- | C] () -- C:\Windows\ctfile.rfc [2011.09.15 18:34:09 | 000,018,340 | ---- | C] () -- C:\Windows\SysNative\results.xml [2011.09.15 18:32:37 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll [2011.09.15 18:31:59 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll [2011.09.15 18:30:00 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2011.09.15 18:30:00 | 000,145,804 | ---- | C] () -- C:\Windows\SysNative\igcompkrng600.bin [2011.09.15 18:30:00 | 000,094,208 | ---- | C] () -- C:\Windows\SysNative\IccLibDll_x64.dll [2011.09.15 18:30:00 | 000,000,151 | ---- | C] () -- C:\Windows\SysNative\GfxUI.exe.config [2011.09.15 18:22:09 | 000,001,409 | ---- | C] () -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2011.09.15 18:22:06 | 000,001,443 | ---- | C] () -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011.09.15 18:13:22 | 3001,565,184 | -HS- | C] () -- C:\hiberfil.sys [2011.08.31 19:51:16 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2011.08.31 19:51:16 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2011.08.31 19:46:00 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2011.08.31 19:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll [2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2011.09.27 22:04:34 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\.purple [2011.09.15 18:51:21 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\DeviceVm [2011.09.29 17:05:31 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\Splashtop [2011.10.06 18:16:06 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\TerraTec [2011.10.06 18:16:06 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\Thunderbird [2009.07.14 07:08:49 | 000,016,254 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.09.15 18:20:45 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2011.09.19 19:07:29 | 000,000,000 | ---D | M] -- C:\CanoScan [2009.07.14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2011.09.15 18:20:27 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2011.09.15 18:29:32 | 000,000,000 | ---D | M] -- C:\Intel [2009.07.14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs [2011.09.15 19:11:44 | 000,000,000 | R--D | M] -- C:\Program Files [2011.10.06 23:19:15 | 000,000,000 | R--D | M] -- C:\Program Files (x86) [2011.10.06 22:57:31 | 000,000,000 | ---D | M] -- C:\ProgramData [2011.09.15 18:20:28 | 000,000,000 | -HSD | M] -- C:\Programme [2011.09.15 18:20:28 | 000,000,000 | -HSD | M] -- C:\Recovery [2011.10.07 14:27:44 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2011.09.15 22:05:18 | 000,000,000 | ---D | M] -- C:\Temp [2011.09.15 18:20:34 | 000,000,000 | R--D | M] -- C:\Users [2011.10.06 18:31:04 | 000,000,000 | ---D | M] -- C:\Windows < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.manifest /3 > < MD5 for: EXPLORER.EXE > [2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe [2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe [2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe [2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe [2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe [2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe < MD5 for: REGEDIT.EXE > [2009.07.14 03:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=2E2C937846A0B8789E5E91739284D17A -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe [2009.07.14 03:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe [2009.07.14 03:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\SysWOW64\regedit.exe [2009.07.14 03:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5a78515e29ea6f39\regedit.exe < MD5 for: USERINIT.EXE > [2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe [2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe [2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > < End of report > Der andere Extra-Log befindet sich wie gewünscht im Anhang. Schritt 3 habe ich nicht durchgeführt, da ich ein 64 bit - System habe. Ich hoffe, dass mir jemand helfen kann und möchte, dafür schonmal herzlichen Dank!!! Liebe Grüße, Lea Geändert von Hicks-Boson (07.10.2011 um 14:18 Uhr) Grund: Tippfehlerkorrektur |
07.10.2011, 16:37 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Wie oft hast du mit Malwarebytes gescannt? Nur ein einziges Mal und es hat nichts gefunden?
__________________
__________________ |
07.10.2011, 17:18 | #3 | ||||
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Danke für deine Antwort!
__________________Dieser Scan hier ist von heute. ich hatte gestern schon mal mehrere Scans, bei denen aber ebenfalls nichts gefunden wurde. (Ich habe zweimal gescannt, weil ich das Programm da erst runtergeladen und aktualisiert habe, es aber dann nochmal manuell aktualisiert habe, weil ich nicht sicher war, ob es richtig geklappt hat. Malwarebytes hat bei der erneuten Aktualisierung, glaube ich, auch nochmal was runtergeladen) Hier die Logs von gestern: Zitat:
Zitat:
Zitat:
Hier noch der neueste Log von Avira: Zitat:
Würde Malwarebytes Reste des Trojaners finden oder tarnt der sich zu gut? Anmerkung: Das Laufwerk E ist ein leeres Laufwerk. Der PC hat eine sehr große Festplatte (1,5 TB), weshalb ich in drei Platten partitioniert habe, und E ist eben noch leer. Falls sich jemand wundert, dass da praktisch nichts durchsucht wurde Geändert von Hicks-Boson (07.10.2011 um 17:28 Uhr) Grund: Anmerkung ergänzt |
07.10.2011, 21:25 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Führ bitte auch ESET aus, danach sehen wir weiter: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
08.10.2011, 11:46 | #5 | |
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Hier der Log von ESET: Zitat:
zu der Festplatte H: Das ist eine externe, auf der ich eine Sicherung des alten PC hatte; darunter auch ein "Programme"-Ordner, da ich das komplette Laufwerk gesichert hatte inklusive einiger Programmdateien. Die letzten drei Funde sind daher möglicherweise einfach .exe - Dateien dieser Programme? |
08.10.2011, 17:13 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~2\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{68ca9c7c-dfb8-11e0-8ff1-002522c2fd68}\Shell - "" = AutoRun O33 - MountPoints2\{68ca9c7c-dfb8-11e0-8ff1-002522c2fd68}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true [2011.09.16 16:57:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit [2011.09.16 16:57:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConduitEngine [2011.09.16 16:56:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winload [2011.09.16 16:56:59 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Conduit :Files C:\Users\Lea\AppData\Local\Mozilla\Firefox\Profiles\4tiqbgij.default\Cache\1 :Commands [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ --> Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? |
08.10.2011, 17:21 | #7 | |
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Danke. Hier: Zitat:
Geändert von Hicks-Boson (08.10.2011 um 17:29 Uhr) |
08.10.2011, 17:49 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen!
__________________ Logfiles bitte immer in CODE-Tags posten |
08.10.2011, 18:37 | #9 | |
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Ist es normal, dass das so fix geht? Die anderen Scans haben immer ewig gedauert und dieser nur eine Minute oder so... Zitat:
|
09.10.2011, 16:37 | #10 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
09.10.2011, 17:00 | #11 |
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Hier der Log: Combofix Logfile: Code:
ATTFilter ComboFix 11-10-09.01 - Lea 09.10.2011 17:46:25.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3817.2564 [GMT 2:00] ausgeführt von:: c:\users\Lea\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\ntuser.dat c:\users\Lea\mbam-setup-1.51.2.1300.exe c:\windows\IsUn0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2011-09-09 bis 2011-10-09 )))))))))))))))))))))))))))))) . . 2011-10-09 15:49 . 2011-10-09 15:49 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-10-08 18:07 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll 2011-10-08 18:07 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll 2011-10-08 18:07 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll 2011-10-08 18:07 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll 2011-10-08 18:07 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll 2011-10-08 18:05 . 2011-10-08 18:05 -------- d-----w- c:\program files (x86)\SystemRequirementsLab 2011-10-08 18:04 . 2011-10-08 18:04 -------- d-----w- c:\program files (x86)\Common Files\Java 2011-10-08 18:04 . 2011-10-08 18:04 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2011-10-08 18:04 . 2011-10-08 18:04 -------- d-----w- c:\program files (x86)\Java 2011-10-08 16:17 . 2011-10-08 16:17 -------- d-----w- C:\_OTL 2011-10-08 08:15 . 2011-10-08 08:15 -------- d-----w- c:\program files (x86)\ESET 2011-10-07 11:57 . 2011-09-13 00:26 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FC0A4FEE-19FC-41A0-8592-FD3E33268DC6}\mpengine.dll 2011-10-06 21:19 . 2011-10-06 21:19 -------- d-----w- c:\program files (x86)\Texmaker 2011-10-06 19:13 . 2011-10-06 19:13 -------- d-----w- c:\programdata\Malwarebytes 2011-10-06 19:13 . 2011-10-06 19:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-10-06 19:13 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-09-26 06:59 . 2011-09-26 06:59 -------- d-----w- c:\program files (x86)\MSECache 2011-09-22 16:50 . 2011-09-22 16:50 26 ----a-w- c:\windows\winstart.bat 2011-09-22 16:50 . 2011-09-22 16:50 151 ----a-w- c:\windows\tmpcpyis.bat 2011-09-22 16:50 . 2011-09-22 16:50 122 ----a-w- c:\windows\tmpdelis.bat 2011-09-22 16:50 . 1997-09-17 22:00 490256 ----a-w- c:\windows\SysWow64\Oleaut32.1 2011-09-22 16:49 . 2011-09-22 16:49 -------- d-----w- c:\windows\solcache 2011-09-22 16:49 . 1998-06-10 11:07 1053184 ----a-w- c:\windows\SysWow64\SierraNW.dll 2011-09-22 16:49 . 1998-06-10 11:05 231936 ----a-w- c:\windows\SysWow64\SNWValid.dll 2011-09-22 16:48 . 2011-09-22 16:49 -------- d-----w- c:\program files (x86)\Sierra On-Line 2011-09-22 16:48 . 2011-09-22 16:48 -------- d-----w- c:\program files (x86)\Spiele 2011-09-22 16:34 . 2011-10-03 18:49 -------- d-----w- c:\program files (x86)\EA GAMES 2011-09-22 16:34 . 2005-02-26 05:34 442368 ----a-r- c:\windows\SysWow64\vp6vfw.dll 2011-09-20 18:21 . 2011-09-20 18:21 -------- d-----w- c:\program files (x86)\Pidgin 2011-09-20 18:16 . 2011-09-20 18:16 -------- d-----w- c:\programdata\MiKTeX 2011-09-20 18:15 . 2011-09-20 18:16 -------- d-----w- c:\program files (x86)\MiKTeX 2.8 2011-09-19 17:09 . 2011-09-19 17:09 -------- d-----w- c:\program files (x86)\ArcSoft 2011-09-19 17:09 . 1999-05-26 07:46 212480 ----a-w- c:\windows\pcdlib32.dll 2011-09-19 17:07 . 2011-09-19 17:07 -------- d-----w- C:\CanoScan 2011-09-17 23:36 . 2011-09-17 23:36 -------- d-----w- c:\program files (x86)\Movie Maker 2.6 2011-09-16 21:57 . 2011-09-16 21:57 -------- d-----w- c:\program files (x86)\MSXML 4.0 2011-09-16 14:58 . 2011-09-16 14:58 -------- d-----w- c:\program files (x86)\VLC Player 2011-09-16 14:00 . 2011-09-16 14:00 -------- d-----w- c:\windows\Msagent 2011-09-16 13:25 . 2011-10-06 16:16 -------- d-----w- c:\users\Public\CyberLink 2011-09-15 17:23 . 2011-09-15 17:23 -------- d-----w- c:\programdata\TerraTec 2011-09-15 17:20 . 2010-10-19 12:23 1179896 ----a-w- c:\windows\system32\drivers\y_cx88x.sys 2011-09-15 17:12 . 2011-09-15 16:20 -------- d-----w- c:\windows\Panther 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\program files\Common Files\Apple 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\program files\Bonjour 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\program files (x86)\Bonjour 2011-09-15 17:10 . 2011-09-15 17:11 -------- d-----w- c:\program files (x86)\Common Files\Apple 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\programdata\Apple 2011-09-15 17:05 . 2011-09-15 17:05 -------- d-----w- c:\programdata\Avira 2011-09-15 17:05 . 2011-09-15 17:05 -------- d-----w- c:\program files (x86)\Avira 2011-09-15 17:05 . 2011-07-21 10:11 123784 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-09-15 17:05 . 2011-07-21 10:11 88288 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2011-09-15 17:03 . 2011-10-06 16:16 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2011-09-15 16:57 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll 2011-09-15 16:53 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-09-15 16:53 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-09-15 16:53 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-09-15 16:51 . 2011-09-15 16:51 -------- d-----w- c:\windows\system32\appmgmt 2011-09-15 16:43 . 2011-09-15 16:45 -------- d-----w- c:\programdata\DeviceVM 2011-09-15 16:42 . 2011-10-06 16:16 -------- d-----w- c:\programdata\Norton 2011-09-15 16:40 . 2011-09-29 14:54 -------- d-----w- c:\programdata\{8533ADFA-85F0-4dc1-946A-2A0BA58E78E3} 2011-09-15 16:40 . 2011-09-15 16:40 31808 ----a-w- c:\windows\system32\drivers\FNETTBOH_305.SYS 2011-09-15 16:37 . 2011-09-15 16:37 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2011-09-15 16:37 . 2011-09-15 16:37 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2011-09-15 16:37 . 2011-09-15 16:37 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2011-09-15 16:37 . 2011-09-15 16:37 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2011-09-15 16:37 . 2009-06-10 11:48 1910272 ------w- c:\windows\system32\Sens_oal.dll 2011-09-15 16:37 . 2009-06-10 11:42 2873822 ------w- c:\windows\SysWow64\Sens_oal.dll 2011-09-15 16:37 . 2011-09-15 16:38 -------- d-----w- c:\program files\Creative 2011-09-15 16:37 . 2009-07-08 13:32 1233195 ------w- c:\windows\SysWow64\AMBSPISyncService.exe 2011-09-15 16:36 . 2011-09-15 16:36 -------- d-----w- c:\program files (x86)\Common Files\Creative Labs Shared 2011-09-15 16:36 . 2011-09-15 16:38 -------- d-----w- c:\programdata\Creative 2011-09-15 16:36 . 2011-09-15 16:37 -------- d-----w- c:\program files (x86)\Creative 2011-09-15 16:36 . 2011-09-15 16:36 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR 2011-09-15 16:35 . 2011-09-15 16:35 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2011-09-15 16:35 . 2011-09-15 16:35 15936 ----a-w- c:\windows\system32\drivers\FNETURPX.SYS 2011-09-15 16:35 . 2011-09-15 16:35 -------- d-----w- c:\programdata\FNET 2011-09-15 16:35 . 2011-09-15 16:35 -------- d-----w- c:\program files (x86)\XFastUsb 2011-09-15 16:34 . 2011-09-15 16:34 -------- d-----w- c:\program files (x86)\ASRock Utility 2011-09-15 16:34 . 2011-09-15 16:34 -------- d-----w- c:\program files\ASRock Utility 2011-09-15 16:34 . 2010-06-11 12:37 15368 ----a-w- c:\windows\system32\drivers\AsrAppCharger.sys 2011-09-15 16:34 . 2011-09-15 16:34 -------- d-----w- c:\program files (x86)\Etron Technology 2011-09-15 16:34 . 2011-10-06 16:16 -------- d-----w- c:\programdata\Intel 2011-09-15 16:34 . 2011-10-08 18:05 -------- d-sh--w- c:\windows\Installer 2011-09-15 16:32 . 2011-02-01 11:06 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll 2011-09-15 16:32 . 2011-09-15 16:32 -------- d-----w- c:\program files (x86)\Common Files\postureAgent 2011-09-15 16:32 . 2010-10-19 14:34 56344 ----a-w- c:\windows\system32\drivers\HECIx64.sys 2011-09-15 16:30 . 2011-09-15 16:30 -------- d-----w- c:\program files\Common Files\Intel 2011-09-15 16:28 . 2011-09-15 16:32 -------- d-----w- c:\program files (x86)\Intel 2011-09-15 16:28 . 2010-10-04 11:02 53248 ----a-w- c:\windows\SysWow64\CSVer.dll 2011-09-15 16:27 . 2011-09-15 16:29 -------- d-----w- C:\Intel . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-31 18:08 . 2011-08-31 18:08 167704 ----a-w- c:\windows\system32\igfxtray.exe 2011-08-31 18:08 . 2011-08-31 18:08 510232 ----a-w- c:\windows\system32\igfxsrvc.exe 2011-08-31 18:08 . 2011-08-31 18:08 416024 ----a-w- c:\windows\system32\igfxpers.exe 2011-08-31 18:08 . 2011-08-31 18:08 239896 ----a-w- c:\windows\system32\igfxext.exe 2011-08-31 18:08 . 2011-08-31 18:08 392472 ----a-w- c:\windows\system32\hkcmd.exe 2011-08-31 18:08 . 2011-08-31 18:08 4378392 ----a-w- c:\windows\system32\GfxUI.exe 2011-08-31 18:08 . 2011-08-31 18:08 179992 ----a-w- c:\windows\system32\difx64.exe 2011-08-31 17:58 . 2011-08-31 17:58 90112 ----a-w- c:\windows\system32\igfxCoIn_v2509.dll 2011-08-31 17:53 . 2011-08-31 17:53 12306848 ----a-w- c:\windows\system32\drivers\igdkmd64.sys 2011-08-31 17:51 . 2011-08-31 17:51 963116 ----a-w- c:\windows\system32\igkrng600.bin 2011-08-31 17:51 . 2011-08-31 17:51 216000 ----a-w- c:\windows\system32\igfcg600m.bin 2011-08-31 17:51 . 2011-08-31 17:51 75776 ----a-w- c:\windows\system32\igdde64.dll 2011-08-31 17:47 . 2011-08-31 17:47 6322688 ----a-w- c:\windows\SysWow64\igdumd32.dll 2011-08-31 17:46 . 2011-08-31 17:46 56832 ----a-w- c:\windows\SysWow64\igdde32.dll 2011-08-31 17:45 . 2011-08-31 17:45 581120 ----a-w- c:\windows\SysWow64\igdumdx32.dll 2011-08-31 17:31 . 2011-08-31 17:31 18641408 ----a-w- c:\windows\system32\ig4icd64.dll 2011-08-31 17:26 . 2011-08-31 17:26 13903872 ----a-w- c:\windows\SysWow64\ig4icd32.dll 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrrom.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrsky.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrhrv.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrtrk.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrslv.lrc 2011-08-31 17:22 . 2011-08-31 17:22 287232 ----a-w- c:\windows\system32\igfxresn.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrsve.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285696 ----a-w- c:\windows\system32\igfxrtha.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrrus.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrptg.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrplk.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrptb.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrnor.lrc 2011-08-31 17:22 . 2011-08-31 17:22 283136 ----a-w- c:\windows\system32\igfxrkor.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrita.lrc 2011-08-31 17:22 . 2011-08-31 17:22 283648 ----a-w- c:\windows\system32\igfxrjpn.lrc 2011-08-31 17:22 . 2011-08-31 17:22 287232 ----a-w- c:\windows\system32\igfxrell.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrdeu.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrhun.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285184 ----a-w- c:\windows\system32\igfxrheb.lrc 2011-08-31 17:22 . 2011-08-31 17:22 287232 ----a-w- c:\windows\system32\igfxrfra.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrnld.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrfin.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrcsy.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285696 ----a-w- c:\windows\system32\igfxrdan.lrc 2011-08-31 17:22 . 2011-08-31 17:22 282624 ----a-w- c:\windows\system32\igfxrcht.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285184 ----a-w- c:\windows\system32\igfxrara.lrc 2011-08-31 17:22 . 2011-08-31 17:22 282624 ----a-w- c:\windows\system32\igfxrchs.lrc 2011-08-31 17:22 . 2011-08-31 17:22 126976 ----a-w- c:\windows\system32\igfxcpl.cpl 2011-08-31 17:21 . 2011-08-31 17:21 378368 ----a-w- c:\windows\system32\igfxTMM.dll 2011-08-31 17:21 . 2011-08-31 17:21 28672 ----a-w- c:\windows\system32\igfxexps.dll 2011-08-31 17:20 . 2011-08-31 17:20 285696 ----a-w- c:\windows\system32\igfxrenu.lrc 2011-08-31 17:20 . 2011-08-31 17:20 142336 ----a-w- c:\windows\system32\igfxdo.dll 2011-08-31 17:16 . 2011-08-31 17:16 24576 ----a-w- c:\windows\SysWow64\igfxexps32.dll 2011-08-31 17:15 . 2011-08-31 17:15 294400 ----a-w- c:\windows\SysWow64\igfxdv32.dll 2011-08-31 17:13 . 2011-08-31 17:13 98304 ----a-w- c:\windows\SysWow64\iglhcp32.dll 2011-08-31 17:13 . 2011-08-31 17:13 98304 ----a-w- c:\windows\system32\iglhcp64.dll 2011-08-31 17:13 . 2011-08-31 17:13 376832 ----a-w- c:\windows\SysWow64\iglhsip32.dll 2011-08-31 17:13 . 2011-08-31 17:13 376832 ----a-w- c:\windows\system32\iglhsip64.dll 2011-08-31 17:13 . 2011-08-31 17:13 162816 ----a-w- c:\windows\SysWow64\igfxcmrt32.dll 2011-08-31 17:13 . 2011-08-31 17:13 140288 ----a-w- c:\windows\system32\igfxcmrt64.dll 2011-07-16 04:26 . 2011-09-15 16:58 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe 2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll 2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll 2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll 2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe 2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll 2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll 2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Remote Control Editor"="c:\program files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe" [2010-10-26 1699912] "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-04-22 2363392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2011-09-15 4942336] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195] "VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-18 421736] "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "MDS_Menu"="c:\program files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-12-15 103720] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-05-14 75048] "UpdatePPShortCut"="c:\program files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-02-17 218408] "UpdatePSTShortCut"="c:\program files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" [2010-06-02 222504] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/09/15 19:37;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-05-14 246256] R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-09-15 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-09-15 79360] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [x] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2011-09-15 79360] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [x] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360] S3 cxpl_mhd;Cinergy T PCIe Dual;c:\windows\system32\drivers\y_cx88x.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - CLKMDRV10_9EC60124 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2010-04-22 11:09 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-05 11474024] "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Lea\AppData\Roaming\Mozilla\Firefox\Profiles\4tiqbgij.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.ecosia.org/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{40c3cc16-7269-4b32-9531-17f2950fb06f} - (no file) Wow6432Node-HKCU-Run-ASRockXTU - (no file) Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file) AddRemove-Caesar 3 - c:\windows\IsUn0407.exe AddRemove-conduitEngine - c:\progra~2\CONDUI~1\ConduitEngineUninstall.exe AddRemove-Winload Toolbar - c:\progra~2\Winload\UNINST~1.EXE . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\CyberLink\Shared files\RichVideo.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\Avira\AntiVir Desktop\avwsc.exe . ************************************************************************** . Zeit der Fertigstellung: 2011-10-09 17:52:23 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2011-10-09 15:52 . Vor Suchlauf: 11 Verzeichnis(se), 211.705.397.248 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 211.542.470.656 Bytes frei . - - End Of File - - C7B99285A38F5FF7DC61E8EA0FFB5A91 |
10.10.2011, 11:56 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Combofix - Scripten 1. Starte das Notepad (Start / Ausführen / notepad[Enter]) 2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein. Code:
ATTFilter File:: c:\windows\system32\drivers\dmvsc.sys Driver:: dmvsc 4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall. (Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !) 5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet. 6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien: Combofix.txt Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten |
10.10.2011, 12:26 | #13 |
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? hier der neue log: Combofix Logfile: Code:
ATTFilter ComboFix 11-10-10.01 - Lea 10.10.2011 13:17:28.2.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3817.2690 [GMT 2:00] ausgeführt von:: c:\users\Lea\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\Lea\Desktop\CFScript.txt AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . FILE :: "c:\windows\system32\drivers\dmvsc.sys" . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\drivers\dmvsc.sys . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_dmvsc . . ((((((((((((((((((((((( Dateien erstellt von 2011-09-10 bis 2011-10-10 )))))))))))))))))))))))))))))) . . 2011-10-08 18:07 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll 2011-10-08 18:07 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll 2011-10-08 18:07 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll 2011-10-08 18:07 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll 2011-10-08 18:07 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll 2011-10-08 18:05 . 2011-10-08 18:05 -------- d-----w- c:\program files (x86)\SystemRequirementsLab 2011-10-08 18:04 . 2011-10-08 18:04 -------- d-----w- c:\program files (x86)\Common Files\Java 2011-10-08 18:04 . 2011-10-08 18:04 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2011-10-08 18:04 . 2011-10-08 18:04 -------- d-----w- c:\program files (x86)\Java 2011-10-08 16:17 . 2011-10-08 16:17 -------- d-----w- C:\_OTL 2011-10-08 08:15 . 2011-10-08 08:15 -------- d-----w- c:\program files (x86)\ESET 2011-10-07 11:57 . 2011-09-13 00:26 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FC0A4FEE-19FC-41A0-8592-FD3E33268DC6}\mpengine.dll 2011-10-06 21:19 . 2011-10-06 21:19 -------- d-----w- c:\program files (x86)\Texmaker 2011-10-06 19:13 . 2011-10-06 19:13 -------- d-----w- c:\programdata\Malwarebytes 2011-10-06 19:13 . 2011-10-06 19:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-10-06 19:13 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-09-26 06:59 . 2011-09-26 06:59 -------- d-----w- c:\program files (x86)\MSECache 2011-09-22 16:50 . 2011-09-22 16:50 26 ----a-w- c:\windows\winstart.bat 2011-09-22 16:50 . 2011-09-22 16:50 151 ----a-w- c:\windows\tmpcpyis.bat 2011-09-22 16:50 . 2011-09-22 16:50 122 ----a-w- c:\windows\tmpdelis.bat 2011-09-22 16:50 . 1997-09-17 22:00 490256 ----a-w- c:\windows\SysWow64\Oleaut32.1 2011-09-22 16:49 . 2011-09-22 16:49 -------- d-----w- c:\windows\solcache 2011-09-22 16:49 . 1998-06-10 11:07 1053184 ----a-w- c:\windows\SysWow64\SierraNW.dll 2011-09-22 16:49 . 1998-06-10 11:05 231936 ----a-w- c:\windows\SysWow64\SNWValid.dll 2011-09-22 16:48 . 2011-09-22 16:49 -------- d-----w- c:\program files (x86)\Sierra On-Line 2011-09-22 16:48 . 2011-09-22 16:48 -------- d-----w- c:\program files (x86)\Spiele 2011-09-22 16:34 . 2011-10-03 18:49 -------- d-----w- c:\program files (x86)\EA GAMES 2011-09-22 16:34 . 2005-02-26 05:34 442368 ----a-r- c:\windows\SysWow64\vp6vfw.dll 2011-09-20 18:21 . 2011-09-20 18:21 -------- d-----w- c:\program files (x86)\Pidgin 2011-09-20 18:16 . 2011-09-20 18:16 -------- d-----w- c:\programdata\MiKTeX 2011-09-20 18:15 . 2011-09-20 18:16 -------- d-----w- c:\program files (x86)\MiKTeX 2.8 2011-09-19 17:09 . 2011-09-19 17:09 -------- d-----w- c:\program files (x86)\ArcSoft 2011-09-19 17:09 . 1999-05-26 07:46 212480 ----a-w- c:\windows\pcdlib32.dll 2011-09-19 17:07 . 2011-09-19 17:07 -------- d-----w- C:\CanoScan 2011-09-17 23:36 . 2011-09-17 23:36 -------- d-----w- c:\program files (x86)\Movie Maker 2.6 2011-09-16 21:57 . 2011-09-16 21:57 -------- d-----w- c:\program files (x86)\MSXML 4.0 2011-09-16 14:58 . 2011-09-16 14:58 -------- d-----w- c:\program files (x86)\VLC Player 2011-09-16 14:00 . 2011-09-16 14:00 -------- d-----w- c:\windows\Msagent 2011-09-16 13:25 . 2011-10-06 16:16 -------- d-----w- c:\users\Public\CyberLink 2011-09-15 17:23 . 2011-09-15 17:23 -------- d-----w- c:\programdata\TerraTec 2011-09-15 17:20 . 2010-10-19 12:23 1179896 ----a-w- c:\windows\system32\drivers\y_cx88x.sys 2011-09-15 17:12 . 2011-09-15 16:20 -------- d-----w- c:\windows\Panther 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\program files\Common Files\Apple 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\program files\Bonjour 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\program files (x86)\Bonjour 2011-09-15 17:10 . 2011-09-15 17:11 -------- d-----w- c:\program files (x86)\Common Files\Apple 2011-09-15 17:10 . 2011-09-15 17:10 -------- d-----w- c:\programdata\Apple 2011-09-15 17:05 . 2011-09-15 17:05 -------- d-----w- c:\programdata\Avira 2011-09-15 17:05 . 2011-09-15 17:05 -------- d-----w- c:\program files (x86)\Avira 2011-09-15 17:05 . 2011-07-21 10:11 123784 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-09-15 17:05 . 2011-07-21 10:11 88288 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2011-09-15 17:03 . 2011-10-06 16:16 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2011-09-15 16:57 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll 2011-09-15 16:53 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-09-15 16:53 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-09-15 16:53 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-09-15 16:51 . 2011-09-15 16:51 -------- d-----w- c:\windows\system32\appmgmt 2011-09-15 16:43 . 2011-09-15 16:45 -------- d-----w- c:\programdata\DeviceVM 2011-09-15 16:42 . 2011-10-06 16:16 -------- d-----w- c:\programdata\Norton 2011-09-15 16:40 . 2011-09-29 14:54 -------- d-----w- c:\programdata\{8533ADFA-85F0-4dc1-946A-2A0BA58E78E3} 2011-09-15 16:40 . 2011-09-15 16:40 31808 ----a-w- c:\windows\system32\drivers\FNETTBOH_305.SYS 2011-09-15 16:37 . 2011-09-15 16:37 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2011-09-15 16:37 . 2011-09-15 16:37 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2011-09-15 16:37 . 2011-09-15 16:37 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2011-09-15 16:37 . 2011-09-15 16:37 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2011-09-15 16:37 . 2009-06-10 11:48 1910272 ------w- c:\windows\system32\Sens_oal.dll 2011-09-15 16:37 . 2009-06-10 11:42 2873822 ------w- c:\windows\SysWow64\Sens_oal.dll 2011-09-15 16:37 . 2011-09-15 16:38 -------- d-----w- c:\program files\Creative 2011-09-15 16:37 . 2009-07-08 13:32 1233195 ------w- c:\windows\SysWow64\AMBSPISyncService.exe 2011-09-15 16:36 . 2011-09-15 16:36 -------- d-----w- c:\program files (x86)\Common Files\Creative Labs Shared 2011-09-15 16:36 . 2011-09-15 16:38 -------- d-----w- c:\programdata\Creative 2011-09-15 16:36 . 2011-09-15 16:37 -------- d-----w- c:\program files (x86)\Creative 2011-09-15 16:36 . 2011-09-15 16:36 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR 2011-09-15 16:35 . 2011-09-15 16:35 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2011-09-15 16:35 . 2011-09-15 16:35 15936 ----a-w- c:\windows\system32\drivers\FNETURPX.SYS 2011-09-15 16:35 . 2011-09-15 16:35 -------- d-----w- c:\programdata\FNET 2011-09-15 16:35 . 2011-09-15 16:35 -------- d-----w- c:\program files (x86)\XFastUsb 2011-09-15 16:34 . 2011-09-15 16:34 -------- d-----w- c:\program files (x86)\ASRock Utility 2011-09-15 16:34 . 2011-09-15 16:34 -------- d-----w- c:\program files\ASRock Utility 2011-09-15 16:34 . 2010-06-11 12:37 15368 ----a-w- c:\windows\system32\drivers\AsrAppCharger.sys 2011-09-15 16:34 . 2011-09-15 16:34 -------- d-----w- c:\program files (x86)\Etron Technology 2011-09-15 16:34 . 2011-10-06 16:16 -------- d-----w- c:\programdata\Intel 2011-09-15 16:34 . 2011-10-08 18:05 -------- d-sh--w- c:\windows\Installer 2011-09-15 16:32 . 2011-02-01 11:06 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll 2011-09-15 16:32 . 2011-09-15 16:32 -------- d-----w- c:\program files (x86)\Common Files\postureAgent 2011-09-15 16:32 . 2010-10-19 14:34 56344 ----a-w- c:\windows\system32\drivers\HECIx64.sys 2011-09-15 16:30 . 2011-09-15 16:30 -------- d-----w- c:\program files\Common Files\Intel 2011-09-15 16:28 . 2011-09-15 16:32 -------- d-----w- c:\program files (x86)\Intel 2011-09-15 16:28 . 2010-10-04 11:02 53248 ----a-w- c:\windows\SysWow64\CSVer.dll 2011-09-15 16:27 . 2011-09-15 16:29 -------- d-----w- C:\Intel . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-31 18:08 . 2011-08-31 18:08 167704 ----a-w- c:\windows\system32\igfxtray.exe 2011-08-31 18:08 . 2011-08-31 18:08 510232 ----a-w- c:\windows\system32\igfxsrvc.exe 2011-08-31 18:08 . 2011-08-31 18:08 416024 ----a-w- c:\windows\system32\igfxpers.exe 2011-08-31 18:08 . 2011-08-31 18:08 239896 ----a-w- c:\windows\system32\igfxext.exe 2011-08-31 18:08 . 2011-08-31 18:08 392472 ----a-w- c:\windows\system32\hkcmd.exe 2011-08-31 18:08 . 2011-08-31 18:08 4378392 ----a-w- c:\windows\system32\GfxUI.exe 2011-08-31 18:08 . 2011-08-31 18:08 179992 ----a-w- c:\windows\system32\difx64.exe 2011-08-31 17:58 . 2011-08-31 17:58 90112 ----a-w- c:\windows\system32\igfxCoIn_v2509.dll 2011-08-31 17:53 . 2011-08-31 17:53 12306848 ----a-w- c:\windows\system32\drivers\igdkmd64.sys 2011-08-31 17:51 . 2011-08-31 17:51 963116 ----a-w- c:\windows\system32\igkrng600.bin 2011-08-31 17:51 . 2011-08-31 17:51 216000 ----a-w- c:\windows\system32\igfcg600m.bin 2011-08-31 17:51 . 2011-08-31 17:51 75776 ----a-w- c:\windows\system32\igdde64.dll 2011-08-31 17:47 . 2011-08-31 17:47 6322688 ----a-w- c:\windows\SysWow64\igdumd32.dll 2011-08-31 17:46 . 2011-08-31 17:46 56832 ----a-w- c:\windows\SysWow64\igdde32.dll 2011-08-31 17:45 . 2011-08-31 17:45 581120 ----a-w- c:\windows\SysWow64\igdumdx32.dll 2011-08-31 17:31 . 2011-08-31 17:31 18641408 ----a-w- c:\windows\system32\ig4icd64.dll 2011-08-31 17:26 . 2011-08-31 17:26 13903872 ----a-w- c:\windows\SysWow64\ig4icd32.dll 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrrom.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrsky.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrhrv.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrtrk.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrslv.lrc 2011-08-31 17:22 . 2011-08-31 17:22 287232 ----a-w- c:\windows\system32\igfxresn.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrsve.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285696 ----a-w- c:\windows\system32\igfxrtha.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrrus.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrptg.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrplk.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrptb.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrnor.lrc 2011-08-31 17:22 . 2011-08-31 17:22 283136 ----a-w- c:\windows\system32\igfxrkor.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrita.lrc 2011-08-31 17:22 . 2011-08-31 17:22 283648 ----a-w- c:\windows\system32\igfxrjpn.lrc 2011-08-31 17:22 . 2011-08-31 17:22 287232 ----a-w- c:\windows\system32\igfxrell.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrdeu.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrhun.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285184 ----a-w- c:\windows\system32\igfxrheb.lrc 2011-08-31 17:22 . 2011-08-31 17:22 287232 ----a-w- c:\windows\system32\igfxrfra.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrnld.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286208 ----a-w- c:\windows\system32\igfxrfin.lrc 2011-08-31 17:22 . 2011-08-31 17:22 286720 ----a-w- c:\windows\system32\igfxrcsy.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285696 ----a-w- c:\windows\system32\igfxrdan.lrc 2011-08-31 17:22 . 2011-08-31 17:22 282624 ----a-w- c:\windows\system32\igfxrcht.lrc 2011-08-31 17:22 . 2011-08-31 17:22 285184 ----a-w- c:\windows\system32\igfxrara.lrc 2011-08-31 17:22 . 2011-08-31 17:22 282624 ----a-w- c:\windows\system32\igfxrchs.lrc 2011-08-31 17:22 . 2011-08-31 17:22 126976 ----a-w- c:\windows\system32\igfxcpl.cpl 2011-08-31 17:21 . 2011-08-31 17:21 378368 ----a-w- c:\windows\system32\igfxTMM.dll 2011-08-31 17:21 . 2011-08-31 17:21 28672 ----a-w- c:\windows\system32\igfxexps.dll 2011-08-31 17:20 . 2011-08-31 17:20 285696 ----a-w- c:\windows\system32\igfxrenu.lrc 2011-08-31 17:20 . 2011-08-31 17:20 142336 ----a-w- c:\windows\system32\igfxdo.dll 2011-08-31 17:16 . 2011-08-31 17:16 24576 ----a-w- c:\windows\SysWow64\igfxexps32.dll 2011-08-31 17:15 . 2011-08-31 17:15 294400 ----a-w- c:\windows\SysWow64\igfxdv32.dll 2011-08-31 17:13 . 2011-08-31 17:13 98304 ----a-w- c:\windows\SysWow64\iglhcp32.dll 2011-08-31 17:13 . 2011-08-31 17:13 98304 ----a-w- c:\windows\system32\iglhcp64.dll 2011-08-31 17:13 . 2011-08-31 17:13 376832 ----a-w- c:\windows\SysWow64\iglhsip32.dll 2011-08-31 17:13 . 2011-08-31 17:13 376832 ----a-w- c:\windows\system32\iglhsip64.dll 2011-08-31 17:13 . 2011-08-31 17:13 162816 ----a-w- c:\windows\SysWow64\igfxcmrt32.dll 2011-08-31 17:13 . 2011-08-31 17:13 140288 ----a-w- c:\windows\system32\igfxcmrt64.dll 2011-07-16 04:26 . 2011-09-15 16:58 44032 ----a-w- c:\windows\apppatch\acwow64.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-10-09_15.50.22 ))))))))))))))))))))))))))))))))))))))))) . + 2010-11-21 03:09 . 2011-10-09 15:57 32754 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin - 2009-07-14 05:10 . 2011-10-09 15:38 33562 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-10-10 10:25 33562 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-09-15 16:17 . 2011-10-09 16:44 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-09-15 16:17 . 2011-10-06 19:54 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-10-09 16:44 . 2011-10-09 16:44 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-10-06 19:54 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-10-09 16:44 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-09-15 16:30 . 2011-10-10 10:25 7012 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2990705632-3891019107-3002588084-1000_UserData.bin - 2011-10-09 15:50 . 2011-10-09 15:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-10-10 11:20 . 2011-10-10 11:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-09-24 18:48 . 2011-10-09 17:10 223578 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin - 2009-07-14 02:36 . 2011-10-09 15:42 606992 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-10-10 10:30 606992 c:\windows\system32\perfh009.dat - 2011-04-12 07:43 . 2011-10-09 15:42 643628 c:\windows\system32\perfh007.dat + 2011-04-12 07:43 . 2011-10-10 10:30 643628 c:\windows\system32\perfh007.dat + 2009-07-14 02:36 . 2011-10-10 10:30 103370 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-10-09 15:42 103370 c:\windows\system32\perfc009.dat - 2011-04-12 07:43 . 2011-10-09 15:42 126188 c:\windows\system32\perfc007.dat + 2011-04-12 07:43 . 2011-10-10 10:30 126188 c:\windows\system32\perfc007.dat + 2009-07-14 05:01 . 2011-10-10 11:20 259684 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-10-09 15:49 259684 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-09-15 17:06 . 2011-10-10 11:20 20679732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2990705632-3891019107-3002588084-1000-8192.dat . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Remote Control Editor"="c:\program files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe" [2010-10-26 1699912] "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-04-22 2363392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2011-09-15 4942336] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195] "VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-18 421736] "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "MDS_Menu"="c:\program files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-12-15 103720] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-05-14 75048] "UpdatePPShortCut"="c:\program files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-02-17 218408] "UpdatePSTShortCut"="c:\program files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" [2010-06-02 222504] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/09/15 19:37;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-05-14 246256] R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-09-15 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-09-15 79360] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [x] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2011-09-15 79360] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [x] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360] S3 cxpl_mhd;Cinergy T PCIe Dual;c:\windows\system32\drivers\y_cx88x.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - CLKMDRV10_9EC60124 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2010-04-22 11:09 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-05 11474024] "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024] "combofix"="c:\combofix\CF4354.3XE" [2010-11-21 345088] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Lea\AppData\Roaming\Mozilla\Firefox\Profiles\4tiqbgij.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.ecosia.org/ . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\CyberLink\Shared files\RichVideo.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Zeit der Fertigstellung: 2011-10-10 13:23:08 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2011-10-10 11:23 ComboFix2.txt 2011-10-09 15:52 . Vor Suchlauf: 13 Verzeichnis(se), 212.471.508.992 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 211.883.552.768 Bytes frei . - - End Of File - - 78632CAB03F6F93EE6D3439FF0C7EED4 |
10.10.2011, 13:27 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
10.10.2011, 16:56 | #15 | |
| Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? hier bitte: Zitat:
|
Themen zu Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? |
0x00000001, 64-bit, antivir, autorun, avira, bho, bonjour, c:\windows\system32\rundll32.exe, conduit, error, excel, explorer, fakesysdef, firefox, format, frage, installation, langs, logfile, löschen?, malware, mozilla thunderbird, neustart, otl-log, problem, product key, programm, realtek, registry, remote control, software, trojaner, trojaner fakesysdef.506, usb, version=1.0, webcheck, windows, windows 7 64bit, windows xp, winload toolbar, winlogon.exe, ändern |