Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten.

Trojaner FakeAlert

Trojaner FakeAlert


heute hat sich ein "Antiviren-Programm" bei mir gemütlich gemacht. Bin derzeit im abgesicherten Modus und habe Malwarebytes drüber scannen lassen.

Hier die Log-Datei:

Malwarebytes' Anti-Malware

Datenbank Version: 8159

Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 9.0.8112.16421

14.11.2011 11:41:42
mbam-log-2011-11-14 (11-41-42).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 190621
Laufzeit: 3 Minute(n), 40 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 2
Infizierte Verzeichnisse: 0
Infizierte Dateien: 10

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sIyTmnsPQfX.exe (Trojan.FakeAlert) -> Value: sIyTmnsPQfX.exe -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\programdata\siytmnspqfx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\orf1rbdmofdjpb.exe (Rogue.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\18paam6x8uy32g.exe.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\3093.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\98D7.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\guqsxfgvoxlht0.exe.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\wusa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\~!#BF9A.tmp (Trojan.Inject) -> Quarantined and deleted successfully.
c:\Users\*\AppData\Local\Temp\0.4948223278427448.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.

Hier noch Log-Datein von alten Scans:

Malwarebytes' Anti-Malware

Datenbank Version: 7883

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

06.10.2011 13:24:23
mbam-log-2011-10-06 (13-24-23).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 201419
Laufzeit: 7 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
Malwarebytes' Anti-Malware

Datenbank Version: 6624

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.19048

20.05.2011 11:33:35
mbam-log-2011-05-20 (11-33-35).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 370370
Laufzeit: 1 Stunde(n), 1 Minute(n), 50 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B922D405-6D13-4A2B-AE89-08A030DA4402}\COMPONENTS\PDFFORGETOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: PDFFORGETOOLBARFF.DLL -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\mozilla firefox\extensions\{b922d405-6d13-4a2b-ae89-08a030da4402}\components\pdfforgetoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware

Datenbank Version: 6624

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.19048

20.05.2011 10:21:06
mbam-log-2011-05-20 (10-21-06).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 175581
Laufzeit: 3 Minute(n), 54 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

OTL Extras logfile created on: 14.11.2011 11:51:47 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\*\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,37 Gb Available Physical Memory | 78,97% Memory free
6,20 Gb Paging File | 5,79 Gb Available in Paging File | 93,35% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 576,61 Gb Total Space | 406,05 Gb Free Space | 70,42% Space Free | Partition Type: NTFS
Drive D: | 19,55 Gb Total Space | 13,33 Gb Free Space | 68,19% Space Free | Partition Type: FAT32
Computer Name: *-PC | User Name: * | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
========== Firewall Settings ==========
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
"{182E67FC-4F59-474F-B9C1-9A929ACA6FF3}" = rport=139 | protocol=6 | dir=out | app=system | 
"{1F0F7712-BF80-4AEB-8F9C-928CD50811F7}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{28947FAA-1985-41AD-9BA6-B944B53BF501}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{355FB103-FD41-4A10-A6C1-7FB164F54612}" = rport=137 | protocol=17 | dir=out | app=system | 
"{5C921513-FA38-41B5-AFBB-D8FAF561C2AE}" = rport=445 | protocol=6 | dir=out | app=system | 
"{69D85F44-B385-4149-BA59-F8A92EA80B44}" = lport=139 | protocol=6 | dir=in | app=system | 
"{6AD37F0C-EC13-4241-B8A3-2073CFE75587}" = lport=1542 | protocol=6 | dir=in | name=realtek wps tcp prot | 
"{78DD2770-F3A5-4436-B2BC-BA0CBD94A8F7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{7A0926A4-F5FB-4A62-8EFD-9D7B1B2D73D4}" = lport=445 | protocol=6 | dir=in | app=system | 
"{7BEBADC2-E40A-4B76-9A85-85AB26E20F59}" = lport=53 | protocol=17 | dir=in | name=realtek ap udp prot | 
"{8BB5D3A3-F541-4D00-854C-BDD13980D283}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{90720311-134C-4EF5-9D5D-814DB9EC2496}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{917C7491-0480-45B8-9036-79444CD6CB23}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{971DBBAD-A81D-42BA-A64C-A5DC571A343E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{A8B1D00B-5B0D-4DB5-AC29-0408592D2B91}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{AA4DABD8-A2AC-4E94-9C76-D46AF7BF9E6D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{B7F48FCF-F3CA-480A-AAD4-B7EFB0731D93}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{C1270D8B-5EC4-4710-95A6-03E70C263BD4}" = lport=1542 | protocol=17 | dir=in | name=realtek wps udp prot | 
"{C58EABCF-525A-448C-8EC3-88E1AE270152}" = lport=138 | protocol=17 | dir=in | app=system | 
"{E3CA773C-C55B-41D4-8F8F-342D63CC18BA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{E8934A54-F31B-4807-B5AF-AEA04B10B508}" = rport=138 | protocol=17 | dir=out | app=system | 
"{EE73CAD9-BCC6-486E-B444-7A003C1F99AE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{F1B022FB-A0B8-46ED-99E4-93AA579609A8}" = lport=137 | protocol=17 | dir=in | app=system | 
========== Vista Active Application Exception List ==========
"{02ED4ACB-F7C6-42FE-A167-4B83FB00F793}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{1BFFC4AF-9B13-4A66-84DD-B71A10C2F1F1}" = protocol=6 | dir=in | app=c:\users\*\appdata\local\temp\ins4308\setup\bin\maininst.exe | 
"{1F0B1D74-9CB2-4A10-95D5-31EA94FAEFAD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{1F360168-4EEB-4A22-920A-BF70179401CB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | 
"{25F9F6B1-C512-4A18-8C8A-48CEE00BF5DC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{38010F0C-9E0C-434E-AA6E-BB0B2648817F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{77619B93-13FC-4027-9635-FC47ED167F1E}" = protocol=6 | dir=in | app=c:\program files\realtek\11n usb wireless lan utility\rtwlan.exe | 
"{78E7469C-DD8A-4B64-ADFB-3F7C7EA46041}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{8151AF7F-6145-4804-AA7E-5F09C93C02A1}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | 
"{8A5B0940-5EDA-4CA7-95C9-439067DEDA82}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{943721B8-3FED-4623-93C5-20AED5B22CF0}" = protocol=17 | dir=in | app=c:\users\*\appdata\local\temp\ins4308\setup\bin\maininst.exe | 
"{9F734A5C-EC0A-4782-8B20-1A3D993D6AA6}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{AD1979FD-2837-4573-8F0A-1F874A96BCA1}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{B8176040-B066-42FF-84EF-71174CD5CEE9}" = protocol=17 | dir=in | app=c:\program files\realtek\11n usb wireless lan utility\rtwlan.exe | 
"{BEA0A3B3-DBE4-44E8-A4AB-20C18015BE1F}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{DB436949-CC95-4F1C-9471-0ECA2D776867}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{DC7B8546-71F4-492F-A101-7C107DDA9B35}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{FD08C18A-C13B-4844-85AA-6D109830918D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | 
"TCP Query User{16AA6523-F560-4DAC-B64D-8E7237B6F345}C:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"TCP Query User{1DCD0280-613B-4811-9E74-DD36F3ACCE32}C:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"TCP Query User{316FB121-4081-441A-B18C-86019EF9E70E}C:\users\*\appdata\local\data becker\web to date 7.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\*\appdata\local\data becker\web to date 7.0\apache\apache.exe | 
"TCP Query User{67764990-4DB3-4CAB-A98E-4E9F34D497A1}C:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"TCP Query User{7312BBD5-C7C3-49C3-B913-DA29869DAAE8}C:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"TCP Query User{831B596B-B10B-4F2B-916C-BB72AC8F160F}C:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"TCP Query User{975233EA-C0DD-4D25-8BCD-47278132FB03}C:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=6 | dir=in | app=c:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"TCP Query User{E853903F-41E6-45D3-A136-7FE411A53898}E:\setup.exe" = protocol=6 | dir=in | app=e:\setup.exe | 
"UDP Query User{1A048BCE-1EC8-4265-8441-86B03DB182BE}C:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"UDP Query User{24BA53AC-A94A-46FB-9EEB-008CEB2EC677}C:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"UDP Query User{649AEF97-1F1C-4538-9296-4531599888A9}C:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"UDP Query User{7AE73B26-2A3E-4C06-96DC-CFF942496D43}C:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\gast shop2date\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"UDP Query User{AE1DCDAD-67A1-46E6-BA41-CB402500C593}C:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\*\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"UDP Query User{CD70A618-C923-4ADB-953F-A55BB91A90DB}C:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\gast\appdata\local\data becker\web to date 6.0\apache\apache.exe | 
"UDP Query User{E7E5D31B-6D42-41AD-A16D-D6C31DE1C235}E:\setup.exe" = protocol=17 | dir=in | app=e:\setup.exe | 
"UDP Query User{FECA17D4-82E4-41A0-ADB6-FE99D21A6BF7}C:\users\*\appdata\local\data becker\web to date 7.0\apache\apache.exe" = protocol=17 | dir=in | app=c:\users\*\appdata\local\data becker\web to date 7.0\apache\apache.exe | 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0ED47137-C071-46CC-A243-E5E33271E10E}" = Windows Live Sign-in Assistant
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}" = Corel Graphics Suite 11
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DDB7A5-00A9-96D3-AF53-AF143CE29CD1}" = Catalyst Control Center InstallProxy
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 25
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{432DEFB9-9C74-A859-1B66-F67530CF1D33}" = Catalyst Control Center Localization German
"{47948554-90C6-4AAC-8CFA-D23CE11C1031}" = Nero 8 Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EF8BE6A-899C-4196-94E7-297C5F7A203E}" = pdfforge Toolbar v1.1
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73EBF259-D41F-3517-78C6-29F335BD252B}" = Skins
"{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}" = Windows Live installer
"{7AEBD87F-7818-2C67-F0F5-822E0260D002}" = Catalyst Control Center Graphics Full New
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{98129815-2DEB-7E30-8105-65CC9D0E3F0D}" = ccc-utility
"{9992BAC0-E57C-1BBB-8391-3DEC5BFC025B}" = ATI Catalyst Install Manager
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C049499-055C-4a0c-A916-1D8CA1FF45EB}" = REALTEK Wireless LAN Driver and Utility
"{9E752ADC-4903-E12F-8843-743A78CD3CBB}" = ccc-core-static
"{9F9D923C-8BF4-859A-853A-7C4299FD98DD}" = Catalyst Control Center Core Implementation
"{A1D08B90-AE1A-4885-AC29-731496FD397E}" = Windows Live Fotogalerie
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A90000000001}" = Adobe Reader 9 - Deutsch
"{AC76BA86-7AD7-1031-7B44-A91000000001}" = Adobe Reader 9.1 - Deutsch
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}" = Windows Live Writer
"{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}" = Microsoft SQL Server 2005 Compact Edition [DEU]
"{BF8DC7F0-DB69-5F15-4871-5B38C95410EA}" = Catalyst Control Center Graphics Light
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1D1D5FE-AF9E-9150-1493-C76A81A69FEE}" = Catalyst Control Center Graphics Full Existing
"{D66BDB75-FBB8-4B4E-5379-B17E7EBD7B1A}" = CCC Help English
"{DC344C96-0A5D-65C7-F0D3-CCBA48DDA190}" = CCC Help German
"{E37C6398-2D75-6EF3-FA55-CF4B92371940}" = Catalyst Control Center Graphics Previews Vista
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"HFRS_is1" = Trend Micro SafeSync
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP-Color LaserJet 2600n" = Color LaserJet 2600n
"InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}" = CorelDRAW Graphics Suite 11
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox 7.0.1 (x86 de)" = Mozilla Firefox 7.0.1 (x86 de)
"Mozilla Thunderbird (6.0.1)" = Mozilla Thunderbird (6.0.1)
"NVIDIA Drivers" = NVIDIA Drivers
"Plugin Marketing Booster_is1" = DATA BECKER Plugin Marketing Booster
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"Recuva" = Recuva
"Samsung CLP-320 Series" = Wartung Samsung CLP-320 Series
"SEO Traffic-Booster_is1" = DATA BECKER SEO Traffic-Booster
"shop to date 6.0 pro MultiUser_is1" = DATA BECKER shop to date 6.0 pro MultiUser
"shop to date 7 pro MultiUser_is1" = DATA BECKER shop to date 7 pro MultiUser
"uninstall.exe" = iLinc Client
"VLC media player" = VLC media player 1.0.5
"web2date" = DATA BECKER shop to date 5
"WinRAR archiver" = WinRAR
========== HKEY_CURRENT_USER Uninstall List ==========
"Google Chrome" = Google Chrome
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 14.11.2011 06:22:29 | Computer Name = *-PC | Source = WinMgmt | ID = 10
Description = 
Error - 14.11.2011 06:24:21 | Computer Name = *-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
Error - 14.11.2011 06:24:21 | Computer Name = *-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
Error - 14.11.2011 06:24:25 | Computer Name = *-PC | Source = WinMgmt | ID = 10
Description = 
Error - 14.11.2011 06:24:37 | Computer Name = *-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version, Zeitstempel
 0x47c6bd1b, fehlerhaftes Modul unknown, Version, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x17271727,  Prozess-ID 0x5a8, Anwendungsstartzeit
Error - 14.11.2011 06:31:01 | Computer Name = *-PC | Source = WinMgmt | ID = 10
Description = 
Error - 14.11.2011 06:31:08 | Computer Name = *-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
Error - 14.11.2011 06:31:08 | Computer Name = *-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
Error - 14.11.2011 06:34:07 | Computer Name = *-PC | Source = EventSystem | ID = 4609
Description = 
Error - 14.11.2011 06:34:13 | Computer Name = *-PC | Source = WinMgmt | ID = 10
Description = 
[ OSession Events ]
Error - 01.07.2010 05:27:00 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2779
 seconds with 360 seconds of active time.  This session ended with a crash.
Error - 30.07.2010 07:30:14 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9923
 seconds with 780 seconds of active time.  This session ended with a crash.
Error - 01.09.2010 06:49:56 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3039
 seconds with 360 seconds of active time.  This session ended with a crash.
Error - 22.09.2010 04:56:25 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1326
 seconds with 1200 seconds of active time.  This session ended with a crash.
Error - 22.09.2010 08:43:22 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 13569
 seconds with 240 seconds of active time.  This session ended with a crash.
Error - 30.09.2010 08:46:30 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6923
 seconds with 600 seconds of active time.  This session ended with a crash.
Error - 04.10.2010 04:56:01 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3401
 seconds with 300 seconds of active time.  This session ended with a crash.
Error - 12.10.2010 02:38:50 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 820
 seconds with 540 seconds of active time.  This session ended with a crash.
Error - 26.10.2010 08:51:00 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6441
 seconds with 240 seconds of active time.  This session ended with a crash.
Error - 28.10.2010 04:55:04 | Computer Name = *-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6405
 seconds with 420 seconds of active time.  This session ended with a crash.
[ System Events ]
Error - 14.11.2011 06:33:38 | Computer Name = *-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am 14.11.2011 um 11:32:02 unerwartet heruntergefahren.
Error - 14.11.2011 06:34:00 | Computer Name = *-PC | Source = DCOM | ID = 10005
Description = 
Error - 14.11.2011 06:33:59 | Computer Name = *-PC | Source = netbt | ID = 4321
Description = Der Name "*-PC       :0" konnte nicht auf der Schnittstelle mit
 IP-Adresse  registriert werden. Der Computer mit IP-Adresse
 hat nicht  zugelassen, dass dieser Computer diesen Namen verwendet.
Error - 14.11.2011 06:33:59 | Computer Name = *-PC | Source = netbt | ID = 4321
Description = Der Name "*-PC       :0" konnte nicht auf der Schnittstelle mit
 IP-Adresse  registriert werden. Der Computer mit IP-Adresse
 hat nicht  zugelassen, dass dieser Computer diesen Namen verwendet.
Error - 14.11.2011 06:34:07 | Computer Name = *-PC | Source = DCOM | ID = 10005
Description = 
Error - 14.11.2011 06:34:08 | Computer Name = *-PC | Source = DCOM | ID = 10005
Description = 
Error - 14.11.2011 06:34:09 | Computer Name = *-PC | Source = DCOM | ID = 10005
Description = 
Error - 14.11.2011 06:34:10 | Computer Name = *-PC | Source = DCOM | ID = 10005
Description = 
Error - 14.11.2011 06:34:14 | Computer Name = *-PC | Source = Service Control Manager | ID = 7001
Description = 
Error - 14.11.2011 06:34:14 | Computer Name = *-PC | Source = Service Control Manager | ID = 7026
Description = 
[ TuneUp Events ]
Error - 10.10.2011 07:49:55 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-10 13:49:55', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','5388',0)
Error - 12.10.2011 04:11:56 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-12 10:11:56', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','3732',0)
Error - 12.10.2011 04:43:09 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-12 10:43:09', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','5016',0)
Error - 12.10.2011 05:07:16 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-12 11:07:16', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','5580',0)
Error - 12.10.2011 07:35:27 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-12 13:35:27', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','3844',0)
Error - 14.10.2011 04:19:58 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-14 10:19:58', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','4260',0)
Error - 14.10.2011 04:20:13 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-14 10:20:13', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','2988',0)
Error - 18.10.2011 08:41:59 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-18 14:41:59', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','3736',0)
Error - 19.10.2011 02:31:04 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-19 08:31:04', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','3060',0)
Error - 26.10.2011 08:29:43 | Computer Name = *-PC | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
 ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2011-10-26 14:29:43', '\device\harddiskvolume1\program
 files\malwarebytes' anti-malware\mbam.exe','3172',0)
< End of report >
< End of report >

defogger_disable by jpshortstuff (
Log created at 12:00 on 14/11/2011 (Reblu)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...



GMER - hxxp://www.gmer.net
Rootkit scan 2011-11-14 12:42:18
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000056 WDC_WD64 rev.05.0
Running: knnmbkcs.exe; Driver: C:\Users\*\AppData\Local\Temp\pwlorpod.sys

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                                                                                                                                                                      fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- Files - GMER 1.0.15 ----

File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay coffret PERSONA découvrez vos jours de fertilité (Artikel 160000674781 endet 29_06_06 181745 MESZ)-Dateien\CADERLXU-Dateien        0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay coffret PERSONA découvrez vos jours de fertilité (Artikel 160000674781 endet 29_06_06 181745 MESZ)-Dateien\eBayISAPI-Dateien       0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay Monitor Persona come nuovo Mai Usato Test Ovulazione (Artikel 7775845278 endet 27_06_06 163044 MESZ)-Dateien\CAFNDE8X-Dateien      0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay Monitor Persona come nuovo Mai Usato Test Ovulazione (Artikel 7775845278 endet 27_06_06 163044 MESZ)-Dateien\eBayISAPI-Dateien     0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay persona - contraccettivo naturale - controllo fertilità (Artikel 9531881472 endet 26_06_06 134950 MESZ)-Dateien\CAQZZZNW-Dateien   0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay persona - contraccettivo naturale - controllo fertilità (Artikel 9531881472 endet 26_06_06 134950 MESZ)-Dateien\eBayISAPI-Dateien  0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay PERSONA - Sistema di contaccezione naturale (Artikel 130012277600 endet 09_08_06 235240 MESZ)-Dateien\CAMGUBYD-Dateien             0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay PERSONA - Sistema di contaccezione naturale (Artikel 130012277600 endet 09_08_06 235240 MESZ)-Dateien\eBayISAPI-Dateien            0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay PERSONA CONTRACCETTIVO NATURALE - CONTROLLO FERTILITÀ (Artikel 180001841273 endet 06_07_06 132912 MESZ)-Dateien\CA3ZTSAX-Dateien   0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\Ebay\gespeicherte Ebay-Angebote\Persona\eBay PERSONA CONTRACCETTIVO NATURALE - CONTROLLO FERTILITÀ (Artikel 180001841273 endet 06_07_06 132912 MESZ)-Dateien\eBayISAPI-Dateien  0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay coffret PERSONA découvrez vos jours de fertilité (Artikel 160000674781 endet 29_06_06 181745 MESZ)-Dateien\CADERLXU-Dateien             0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay coffret PERSONA découvrez vos jours de fertilité (Artikel 160000674781 endet 29_06_06 181745 MESZ)-Dateien\eBayISAPI-Dateien            0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay Monitor Persona come nuovo Mai Usato Test Ovulazione (Artikel 7775845278 endet 27_06_06 163044 MESZ)-Dateien\CAFNDE8X-Dateien           0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay Monitor Persona come nuovo Mai Usato Test Ovulazione (Artikel 7775845278 endet 27_06_06 163044 MESZ)-Dateien\eBayISAPI-Dateien          0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay persona - contraccettivo naturale - controllo fertilità (Artikel 9531881472 endet 26_06_06 134950 MESZ)-Dateien\CAQZZZNW-Dateien        0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay persona - contraccettivo naturale - controllo fertilità (Artikel 9531881472 endet 26_06_06 134950 MESZ)-Dateien\eBayISAPI-Dateien       0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay PERSONA CONTRACCETTIVO NATURALE - CONTROLLO FERTILITÀ (Artikel 180001841273 endet 06_07_06 132912 MESZ)-Dateien\CA3ZTSAX-Dateien        0 bytes
File            C:\Users\*\AppData\Local\Trend Micro\OSDP\*@*.de\root\Festplatte\Externe Festplatte H\Ebay\gespeicherte Ebay-Angebote\Persona\eBay PERSONA CONTRACCETTIVO NATURALE - CONTROLLO FERTILITÀ (Artikel 180001841273 endet 06_07_06 132912 MESZ)-Dateien\eBayISAPI-Dateien       0 bytes

---- EOF - GMER 1.0.15 ----

Trojaner FakeAlert

Trojaner FakeAlert

Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset



Trojaner FakeAlert

Trojaner FakeAlert


Malwarebytes' Anti-Malware

Datenbank Version: 8160

Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 9.0.8112.16421

14.11.2011 16:46:44
mbam-log-2011-11-14 (16-46-44).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 399134
Laufzeit: 1 Stunde(n), 19 Minute(n), 41 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=7ca3c9cca1a31c46885d44ee0ad86604
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-11-14 04:32:54
# local_time=2011-11-14 05:32:54 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1797 16775166 100 100 18653 96177592 19186 0
# compatibility_mode=5892 16776573 100 100 13431 158813756 0 0
# compatibility_mode=8192 67108863 100 0 3700 3700 0 0
# scanned=220420
# found=3
# cleaned=0
# scan_time=7346
C:\Program Files\pdfforge Toolbar\SearchSettings.exe	Win32/Adware.Toolbar.Dealio application (unable to clean)	00000000000000000000000000000000	I
C:\Users\*\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\57c430d-34fda5a5	Win32/TrojanDownloader.Small.PHM trojan (unable to clean)	00000000000000000000000000000000	I
C:\Users\*\Downloads\SoftonicDownloader_fuer_recuva.exe	a variant of Win32/SoftonicDownloader.A application (unable to clean)	00000000000000000000000000000000	I

Trojaner FakeAlert

Trojaner FakeAlert

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.exe /s
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
Logfiles bitte immer in CODE-Tags posten

Alt 15.11.2011, 10:17   #5
Trojaner FakeAlert

Trojaner FakeAlert

OTL Logfile:
OTL logfile created on: 15.11.2011 09:54:28 - Run 2
OTL by OldTimer - Version     Folder = C:\Users\*\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,45 Gb Available Physical Memory | 81,87% Memory free
6,19 Gb Paging File | 5,85 Gb Available in Paging File | 94,47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 576,61 Gb Total Space | 405,56 Gb Free Space | 70,34% Space Free | Partition Type: NTFS
Drive D: | 19,55 Gb Total Space | 13,33 Gb Free Space | 68,19% Space Free | Partition Type: FAT32
Computer Name: *-PC | User Name: * | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.11.14 11:49:47 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\*\Desktop\OTL.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2010.03.15 10:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - [2011.08.01 18:12:42 | 003,730,192 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro SafeSync\hrfscore.exe -- (OnlineStorageService)
SRV - [2011.07.04 19:11:47 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.29 08:06:19 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.03.01 14:12:56 | 000,604,488 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2011.03.01 14:12:56 | 000,361,288 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009.11.16 12:25:48 | 000,029,000 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2009.10.13 21:03:54 | 000,187,456 | -H-- | M] (DATA BECKER GmbH & Co KG) [Auto | Stopped] -- C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2009.07.10 11:23:54 | 000,036,864 | ---- | M] (Realtek) [Auto | Stopped] -- C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
SRV - [2008.01.21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011.08.01 18:20:10 | 000,143,120 | ---- | M] (Trend Micro Inc.) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hrfsmrx.sys -- (hrfsmrx)
DRV - [2011.07.04 19:11:48 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.04 19:11:48 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.03.10 09:33:48 | 000,526,848 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192su.sys -- (RTL8192su)
DRV - [2010.06.17 14:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.02.24 11:22:10 | 000,185,472 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2009.09.10 08:50:11 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT)
DRV - [2009.06.09 12:04:48 | 000,110,304 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\ACEDRV09.sys -- (ACEDRV09)
DRV - [2009.02.13 11:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.11.13 05:41:54 | 004,179,456 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008.09.05 01:01:00 | 000,419,328 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fwlanusbn.sys -- (fwlanusbn)
DRV - [2008.09.05 01:01:00 | 000,265,088 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB)
DRV - [2008.09.05 01:01:00 | 000,004,352 | R--- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avmeject.sys -- (avmeject)
DRV - [2007.12.08 07:28:08 | 000,140,320 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2007.11.17 19:39:50 | 001,040,544 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2007.10.12 15:53:10 | 000,013,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.medion.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.medion.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = fritz.box;;*.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: foxyseotool@foxyseotool.com:0.8.4
FF - prefs.js..extensions.enabledItems: {d57c9ff1-6389-48fc-b770-f78bd89b6e8a}:1.33
FF - prefs.js..extensions.enabledItems: senseo@nicosteiner.de:1.4.3
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.6.6
FF - prefs.js..extensions.enabledItems: seoquake-plugin-seolinx@seoquake.com:1.0.2
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Users\*\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\*\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\*\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.10.06 11:35:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.06 10:46:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.09.04 18:33:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2008.02.22 16:24:06 | 000,095,832 | ---- | M] ()
[2010.11.18 11:08:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*\AppData\Roaming\mozilla\Extensions
[2010.11.18 11:08:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.05.05 10:20:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2011.11.11 09:34:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*\AppData\Roaming\mozilla\Firefox\Profiles\v1uhkq63.default\extensions
[2010.10.29 09:09:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\*\AppData\Roaming\mozilla\Firefox\Profiles\v1uhkq63.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.10.25 09:21:25 | 000,000,000 | ---D | M] (SeoQuake) -- C:\Users\*\AppData\Roaming\mozilla\Firefox\Profiles\v1uhkq63.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2009.10.08 11:02:24 | 000,000,000 | ---D | M] (RankQuest SEO Toolbar) -- C:\Users\*\AppData\Roaming\mozilla\Firefox\Profiles\v1uhkq63.default\extensions\{556d6eb2-aed0-4a4c-98a0-6f1dd597b98b}
[2011.10.06 11:35:55 | 000,000,000 | ---D | M] (Page Speed) -- C:\Users\*\AppData\Roaming\mozilla\Firefox\Profiles\v1uhkq63.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2009.10.08 11:05:05 | 000,000,000 | ---D | M] (SeoQuake Plugin - Seolinx) -- C:\Users\*\AppData\Roaming\mozilla\Firefox\Profiles\v1uhkq63.default\extensions\seoquake-plugin-seolinx@seoquake.com
[2011.05.20 10:42:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.01.20 10:18:18 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009.07.03 13:29:44 | 000,000,000 | ---D | M] (pdfforge Toolbar Plugin) -- C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}
[2011.05.20 10:37:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.05.20 10:42:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2009.07.03 13:29:44 | 000,000,000 | ---D | M] (Search Settings Plugin) -- C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
[2011.10.06 11:35:50 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009.05.30 00:20:07 | 000,535,840 | ---- | M] (iLinc Communications, Inc.) -- C:\Program Files\mozilla firefox\plugins\NPCltInstall.dll
[2011.04.14 04:08:00 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.06 11:35:48 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.06 11:35:48 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.06 11:35:48 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.06 11:35:48 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.06 11:35:48 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.06 11:35:48 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome  ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\*\AppData\Local\Google\Chrome\Application\13.0.782.220\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java(TM) Platform SE 6 U13 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U13 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\*\AppData\Local\Google\Chrome\Application\13.0.782.220\pdf.dll
CHR - plugin: Google Gears (Enabled) = C:\Users\*\AppData\Local\Google\Chrome\Application\13.0.782.220\gears.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: iLinc Communications Netscape/Mozilla Install Plugin v 10.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPCltInstall.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleOneClick8.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Users\*\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts:       localhost
O1 - Hosts: ::1             localhost
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll (Spigot, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 11\Register\registration.exe (Corel Corporation)
O4 - HKLM..\Run: [Google EULA Launcher] C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe (Google)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - Startup: C:\Users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Inhaltsverzeichnis.onetoc2 ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: samsungsetup.com ([www] http in Vertrauenswürdige Sites)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://ips.poi.de/ips-opdata/operator/69189345/objects/jordan.cab (JordanUploader Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{389EAD2B-CB3B-4DBE-AF76-B4DDA96042D2}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{676F61E6-2878-4DB0-9FC3-602069A8F55B}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{754E2F00-44F8-4003-A773-0E2976769286}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8FAD0C66-3017-4A6F-B0FC-39D80FB40CD4}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9067AE95-3FC3-4C5A-A0DB-3AB697C7FD83}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{914E0EA0-B606-40E8-BACC-BAC20B424978}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC299F6F-9EAA-4D25-9CE3-E963A17F1F3B}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C47FD66D-8815-4180-BD75-9F637405777B}: DhcpNameServer =
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: 
O24 - Desktop BackupWallPaper: 
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{00f6fecb-1ca6-11df-adc2-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{00f6fecb-1ca6-11df-adc2-806e6f6e6963}\Shell\AutoRun\command - "" = I:\pushinst.exe
O33 - MountPoints2\{088d9884-a746-11de-a692-002185c49f05}\Shell - "" = AutoRun
O33 - MountPoints2\{088d9884-a746-11de-a692-002185c49f05}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{0db6c9d7-51c9-11de-8a4d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0db6c9d7-51c9-11de-8a4d-806e6f6e6963}\Shell\AutoRun\command - "" = I:\pushinst.exe
O33 - MountPoints2\{80d15e22-71d9-11de-b623-002185c49f05}\Shell - "" = AutoRun
O33 - MountPoints2\{80d15e22-71d9-11de-b623-002185c49f05}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{97f527cc-ecd4-11df-b06b-002185c49f05}\Shell - "" = AutoRun
O33 - MountPoints2\{97f527cc-ecd4-11df-b06b-002185c49f05}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{d4011230-4d15-11df-ac73-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d4011230-4d15-11df-ac73-806e6f6e6963}\Shell\AutoRun\command - "" = G:\pushinst.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >
--- --- ---

Alt 15.11.2011, 11:41   #6
Trojaner FakeAlert

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

[2009.07.03 13:29:44 | 000,000,000 | ---D | M] (pdfforge Toolbar Plugin) -- C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}
[2009.07.03 13:29:44 | 000,000,000 | ---D | M] (Search Settings Plugin) -- C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll (Spigot, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{00f6fecb-1ca6-11df-adc2-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{00f6fecb-1ca6-11df-adc2-806e6f6e6963}\Shell\AutoRun\command - "" = I:\pushinst.exe
O33 - MountPoints2\{088d9884-a746-11de-a692-002185c49f05}\Shell - "" = AutoRun
O33 - MountPoints2\{088d9884-a746-11de-a692-002185c49f05}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{0db6c9d7-51c9-11de-8a4d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0db6c9d7-51c9-11de-8a4d-806e6f6e6963}\Shell\AutoRun\command - "" = I:\pushinst.exe
O33 - MountPoints2\{80d15e22-71d9-11de-b623-002185c49f05}\Shell - "" = AutoRun
O33 - MountPoints2\{80d15e22-71d9-11de-b623-002185c49f05}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{97f527cc-ecd4-11df-b06b-002185c49f05}\Shell - "" = AutoRun
O33 - MountPoints2\{97f527cc-ecd4-11df-b06b-002185c49f05}\Shell\AutoRun\command - "" = F:\pushinst.exe
O33 - MountPoints2\{d4011230-4d15-11df-ac73-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d4011230-4d15-11df-ac73-806e6f6e6963}\Shell\AutoRun\command - "" = G:\pushinst.exe
[2011.11.14 11:25:11 | 000,000,288 | -H-- | C] () -- C:\ProgramData\~oRf1rBdMoFDJPb
[2011.11.14 11:25:11 | 000,000,208 | -H-- | C] () -- C:\ProgramData\~oRf1rBdMoFDJPbr
[2011.11.14 11:24:57 | 000,000,440 | -H-- | C] () -- C:\ProgramData\oRf1rBdMoFDJPb
Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
--> Trojaner FakeAlert

Alt 15.11.2011, 13:10   #7
Hallo cosinus,

nach dem Fix hat sich keine Log-Datei geöffnet und ich hatte nur noch die Möglichkeit für einen Neustart und die OTL.txt auf dem Desktop ist die, die ich vormals gepostet hatte.

Ist die irgendwo archiviert oder können wir auch so weiter machen?

Alt 15.11.2011, 13:31   #8
Trojaner FakeAlert - Standard

Trojaner FakeAlert

Schau in den Ordner C:\_OTL nach
Logfiles bitte immer in CODE-Tags posten

Alt 15.11.2011, 13:40   #9
All processes killed
========== OTL ==========
C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\chrome\skin folder moved successfully.
========== COMMANDS ==========
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 83 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Gast
->Temp folder emptied: 748874162 bytes
->Temporary Internet Files folder emptied: 7211374 bytes
->FireFox cache emptied: 46797725 bytes
->Flash cache emptied: 1855 bytes
User: Gast Shop2Date
->Temp folder emptied: 763393363 bytes
->Temporary Internet Files folder emptied: 24412210 bytes
->FireFox cache emptied: 173867923 bytes
->Flash cache emptied: 6761 bytes
User: Public
User: *
->Temp folder emptied: 4387377 bytes
->Temporary Internet Files folder emptied: 984307209 bytes
->Java cache emptied: 20581789 bytes
->FireFox cache emptied: 231710870 bytes
->Google Chrome cache emptied: 143776119 bytes
->Flash cache emptied: 63624 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6238058 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 3.009,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version log created on 11152011_115238

Alt 15.11.2011, 13:59   #10
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojaner FakeAlert - Standard

Trojaner FakeAlert

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen!
Logfiles bitte immer in CODE-Tags posten

Alt 15.11.2011, 14:24   #11
Trojaner FakeAlert - Standard

Trojaner FakeAlert

14:22:49.0207 1556	avmeject ( UnsignedFile.Multi.Generic ) - skipped by user
14:22:49.0207 1556	avmeject ( UnsignedFile.Multi.Generic ) - User select action: Skip 
14:22:49.0208 1556	SSPORT ( UnsignedFile.Multi.Generic ) - skipped by user
14:22:49.0208 1556	SSPORT ( UnsignedFile.Multi.Generic ) - User select action: Skip

Alt 15.11.2011, 14:40   #12
Trojaner FakeAlert - Standard

Trojaner FakeAlert

Dann bitte jetzt CF ausführen:


Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.
Logfiles bitte immer in CODE-Tags posten

Alt 15.11.2011, 15:03   #13
anCombofix Logfile:
ComboFix 11-11-15.01 - * 15.11.2011  14:57:02.1.4 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.49.1031.18.3070.2309 [GMT 1:00]
ausgeführt von:: c:\users\*\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
c:\users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore
c:\users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\System Restore.lnk
c:\users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\Uninstall System Restore.lnk
(((((((((((((((((((((((   Dateien erstellt von 2011-10-15 bis 2011-11-15  ))))))))))))))))))))))))))))))
2011-11-15 14:00 . 2011-11-15 14:00	--------	d-----w-	c:\users\*\AppData\Local\temp
2011-11-15 11:00 . 2011-11-15 11:00	56200	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8B898B3-213A-4605-8EC4-4C6E523A6F8F}\offreg.dll
2011-11-15 10:52 . 2011-11-15 10:52	--------	d-----w-	C:\_OTL
2011-11-14 16:22 . 2011-11-14 16:22	--------	d-----w-	c:\windows\Sun
2011-11-14 14:28 . 2011-11-14 14:28	--------	d-----w-	c:\program files\ESET
2011-11-11 07:58 . 2011-10-07 03:48	6668624	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8B898B3-213A-4605-8EC4-4C6E523A6F8F}\mpengine.dll
2011-11-09 08:06 . 2011-10-17 11:41	2409784	----a-w-	c:\program files\Windows Mail\OESpamFilter.dat
2011-11-09 08:06 . 2011-09-20 21:02	905088	----a-w-	c:\windows\system32\drivers\tcpip.sys
2011-11-09 08:06 . 2011-09-30 15:57	707584	----a-w-	c:\program files\Common Files\System\wab32.dll
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-09-28 11:42 . 2011-09-28 11:42	0	----a-w-	c:\users\*\AppData\Local\BITE860.tmp
2011-09-27 05:56 . 2011-05-17 13:06	404640	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 13:30 . 2011-10-14 07:04	2043392	----a-w-	c:\windows\system32\win32k.sys
2011-09-05 06:37 . 2011-09-05 06:37	76800	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2011-09-05 06:37 . 2011-09-05 06:37	74752	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2011-09-05 06:37 . 2011-09-05 06:37	161792	----a-w-	c:\windows\system32\msls31.dll
2011-09-05 06:37 . 2011-09-05 06:37	86528	----a-w-	c:\windows\system32\iesysprep.dll
2011-09-05 06:37 . 2011-09-05 06:37	63488	----a-w-	c:\windows\system32\tdc.ocx
2011-09-05 06:37 . 2011-09-05 06:37	48640	----a-w-	c:\windows\system32\mshtmler.dll
2011-09-05 06:37 . 2011-09-05 06:37	367104	----a-w-	c:\windows\system32\html.iec
2011-09-05 06:37 . 2011-09-05 06:37	74752	----a-w-	c:\windows\system32\iesetup.dll
2011-09-05 06:37 . 2011-09-05 06:37	420864	----a-w-	c:\windows\system32\vbscript.dll
2011-09-05 06:37 . 2011-09-05 06:37	23552	----a-w-	c:\windows\system32\licmgr10.dll
2011-09-05 06:37 . 2011-09-05 06:37	152064	----a-w-	c:\windows\system32\wextract.exe
2011-09-05 06:37 . 2011-09-05 06:37	150528	----a-w-	c:\windows\system32\iexpress.exe
2011-09-05 06:37 . 2011-09-05 06:37	1427456	----a-w-	c:\windows\system32\inetcpl.cpl
2011-09-05 06:37 . 2011-09-05 06:37	35840	----a-w-	c:\windows\system32\imgutil.dll
2011-09-05 06:37 . 2011-09-05 06:37	142848	----a-w-	c:\windows\system32\ieUnatt.exe
2011-09-05 06:37 . 2011-09-05 06:37	11776	----a-w-	c:\windows\system32\mshta.exe
2011-09-05 06:37 . 2011-09-05 06:37	110592	----a-w-	c:\windows\system32\IEAdvpack.dll
2011-09-05 06:37 . 2011-09-05 06:37	101888	----a-w-	c:\windows\system32\admparse.dll
2011-08-31 15:00 . 2011-05-20 08:16	22216	----a-w-	c:\windows\system32\drivers\mbam.sys
2011-08-25 16:15 . 2011-10-14 07:03	555520	----a-w-	c:\windows\system32\UIAutomationCore.dll
2011-08-25 16:14 . 2011-10-14 07:03	563712	----a-w-	c:\windows\system32\oleaut32.dll
2011-08-25 16:14 . 2011-10-14 07:03	238080	----a-w-	c:\windows\system32\oleacc.dll
2011-08-25 13:31 . 2011-10-14 07:03	4096	----a-w-	c:\windows\system32\oleaccrc.dll
2011-10-06 10:35 . 2011-05-23 07:07	134104	----a-w-	c:\program files\mozilla firefox\components\browsercomps.dll
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
2011-08-01 17:19	1104656	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
2011-08-01 17:19	1104656	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
2011-08-01 17:19	1104656	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
2011-08-01 17:19	1104656	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-05 39408]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2008-09-09 6281760]
"Skytel"="Skytel.exe" [2008-09-09 1833504]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-10-14 20480]
"CorelDRAW Graphics Suite 11b"="c:\program files\Corel\Corel Graphics 11\Register\registration.exe" [2005-02-17 315392]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2009-06-12 998400]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2010-06-07 618496]
"OTL"="c:\users\*\Desktop\OTL.exe" [2011-11-14 584192]
c:\users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
OneNote Inhaltsverzeichnis.onetoc2 [2010-1-7 3656]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Trend Micro SafeSync.lnk - c:\program files\Trend Micro SafeSync\HrfsClient.exe [2011-9-4 2210576]
"EnableUIADesktopToggle"= 0 (0x0)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter
"Google Update"="c:\users\*\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
R2 ACEDRV09;ACEDRV09;c:\windows\system32\drivers\ACEDRV09.sys [2009-06-09 110304]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472]
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-29 136360]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DBService;DATA BECKER Update Service;c:\program files\Common Files\DATA BECKER Shared\DBService.exe [2009-10-13 187456]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R2 Realtek11nSU;Realtek11nSU;c:\program files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [2009-07-10 36864]
R2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-09-10 5120]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2008-09-05 4352]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2008-09-05 265088]
R3 fwlanusbn;FRITZ!WLAN N;c:\windows\system32\DRIVERS\fwlanusbn.sys [2008-09-05 419328]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R3 hrfsmrx;hrfsmrx;c:\windows\System32\Drivers\hrfsmrx.sys [2011-08-01 143120]
R3 OnlineStorageService;OnlineStorageService;c:\program files\Trend Micro SafeSync\hrfscore.exe [2011-08-01 3730192]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2011-03-10 526848]
--- Andere Dienste/Treiber im Speicher ---
*NewlyCreated* - 10621496
*Deregistered* - 10621496
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Inhalt des "geplante Tasks" Ordners
2011-11-14 c:\windows\Tasks\1-Klick-Wartung.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 12:00]
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 09:57]
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 09:57]
2011-11-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1121016878-2803726019-2787449478-1000Core.job
- c:\users\*\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 07:17]
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1121016878-2803726019-2787449478-1000UA.job
- c:\users\*\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 07:17]
2010-12-17 c:\windows\Tasks\User_Feed_Synchronization-{E06AF3D3-5AFE-464C-84A3-8485B5260C55}.job
- c:\windows\system32\msfeedssync.exe [2011-09-05 06:37]
------- Zusätzlicher Suchlauf -------
uStart Page = hxxp://www.google.de/
uInternet Settings,ProxyOverride = fritz.box;;*.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4
Trusted Zone: samsungsetup.com\www
TCP: DhcpNameServer =
DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://ips.poi.de/ips-opdata/operator/69189345/objects/jordan.cab
FF - ProfilePath - c:\users\*\AppData\Roaming\Mozilla\Firefox\Profiles\v1uhkq63.default\
FF - prefs.js: browser.startup.homepage - www.google.de
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
AddRemove-web2date - c:\windows\IsUn0407.exe
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-11-15 15:00
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse... 
Scanne versteckte Autostarteinträge... 
Scanne versteckte Dateien... 
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'Explorer.exe'(1816)
c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
Zeit der Fertigstellung: 2011-11-15  15:01:31
ComboFix-quarantined-files.txt  2011-11-15 14:01
Vor Suchlauf: 9 Verzeichnis(se), 438.373.535.744 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 437.246.844.928 Bytes frei
- - End Of File - - D26410FD281C8B168AB013981498C966
--- --- ---

Alt 15.11.2011, 15:38   #14
/// Winkelfunktion
/// TB-Süch-Tiger™
Trojaner FakeAlert - Standard

Trojaner FakeAlert

Boot type: Safe boot with network
Warum machst du eigentlich ALLES im angesicherten Modus mit Netzwerktreibern?
Soweit nicht anders erwähnt, solltest du möglichst alles im normalen Modus machen.
Logfiles bitte immer in CODE-Tags posten

Alt 16.11.2011, 08:33   #15
Trojaner FakeAlert - Standard

Trojaner FakeAlert


im normalen Modus haute mir der Trojaner das System zusammen bis zu einem Bluescreen. Ich konnte ja nicht mal Malwarebytes ausführen zu Anfang. Daher schien mir das als sichere Variante, um zu scannen und zu posten.

Was soll ich nun machen? Wie gehts weiter? Bin nun im normalen Modus.

Was soll ich nun machen? Wie gehts weiter? Bin nun im normalen Modus.


