|
Plagegeister aller Art und deren Bekämpfung: google rocketnewsWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.05.2012, 20:45 | #16 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnews Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
20.05.2012, 21:35 | #17 |
| google rocketnews ich habe gerade das Problem dass ich mein AntiVir nicht vollständig abschalten kann. ich habe zwar den echtzeitscanner deaktiviert, aber das Programm an sich läuft noch. und da fängt das ComboFix dann an zu meckern. Wie kann ich denn das AnitVir komplett beenden? Im Programm selber finde ich nichts. Und wenn ich im Taskmanager den Prozess beenden will, kommt die Fehlermeldung, dass der Zugriff verweigert wird. Dabei habe ich eigentlich ein Admin-Benutzerkonto. Hättest du eine Idee wie ich das beheben kann? So will und soll ich das ComboFix ja nicht ausführen...
__________________ |
21.05.2012, 09:37 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnews Wenn der Regenschirm geschlossen ist (Echtzeitscanner deaktiviert) kannst du diese Meldung ignorieren
__________________
__________________ |
21.05.2012, 12:19 | #19 |
| google rocketnews so jetzt hat alles geklappt hier das log: Code:
ATTFilter ComboFix 12-05-20.10 - da_tschaemp2 21.05.2012 12:53:01.1.2 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.2047.1408 [GMT 2:00] ausgeführt von:: c:\users\da_tschaemp2\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2012-04-21 bis 2012-05-21 )))))))))))))))))))))))))))))) . . 2012-05-21 10:57 . 2012-05-21 10:57 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2012-05-21 10:57 . 2012-05-21 10:57 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-05-16 15:11 . 2012-05-17 10:05 -------- d-----w- C:\_OTL 2012-05-14 19:52 . 2012-05-14 19:52 -------- d-----w- c:\program files\ESET 2012-05-14 18:37 . 2012-05-14 18:37 -------- d-----w- c:\users\da_tschaemp2\AppData\Roaming\Malwarebytes 2012-05-14 18:37 . 2012-05-14 18:37 -------- d-----w- c:\programdata\Malwarebytes 2012-05-14 18:37 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-05-13 15:18 . 2012-03-30 10:23 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-05-13 15:18 . 2012-03-31 04:29 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2012-05-13 15:18 . 2012-03-31 04:30 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL 2012-05-13 15:18 . 2012-03-31 04:29 989184 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll 2012-05-13 15:18 . 2012-03-31 04:29 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll 2012-05-13 15:18 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-13 15:18 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-05-13 15:18 . 2012-03-31 02:36 2343424 ----a-w- c:\windows\system32\win32k.sys 2012-05-13 15:17 . 2012-03-17 07:27 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-13 15:17 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\system32\DWrite.dll 2012-05-13 15:17 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F3392A44-DFE9-4359-A1A3-1BFE5EBBE914}\mpengine.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-08 15:30 . 2012-02-29 18:13 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2012-05-08 15:30 . 2012-02-29 18:13 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys 2012-05-04 17:11 . 2012-03-29 05:18 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-04 17:11 . 2012-02-29 18:15 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-04 12:43 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2012-03-01 22:50 . 2012-03-01 22:45 2829 ----a-w- c:\windows\War3Unin.pif 2012-03-01 22:50 . 2012-03-01 22:45 139264 ----a-w- c:\windows\War3Unin.exe 2012-03-01 13:10 . 2012-03-01 13:10 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-03-01 05:46 . 2012-04-12 17:03 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2012-03-01 05:37 . 2012-04-12 17:03 172544 ----a-w- c:\windows\system32\wintrust.dll 2012-03-01 05:33 . 2012-04-12 17:03 159232 ----a-w- c:\windows\system32\imagehlp.dll 2012-03-01 05:29 . 2012-04-12 17:03 5120 ----a-w- c:\windows\system32\wmi.dll 2012-02-23 22:33 . 2012-02-29 18:10 27640 ----a-w- c:\windows\system32\nitrolocalmon2.dll 2012-02-23 22:33 . 2012-02-29 18:10 18936 ----a-w- c:\windows\system32\nitrolocalui2.dll 2012-02-23 08:18 . 2012-02-29 16:28 237072 ------w- c:\windows\system32\MpSigStub.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 ----a-w- c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 ----a-w- c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 ----a-w- c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 ----a-w- c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="e:\avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "3200 Scan2PC"="c:\windows\twain_32\Samsung\SCX3200\Scan2Pc.exe" [2010-05-18 1989120] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "iTunesHelper"="e:\itunes\iTunesHelper.exe" [2012-03-27 421736] "PDFPrint"="e:\pdf24\pdf24.exe" [2012-05-07 160840] "Malwarebytes' Anti-Malware"="e:\malwarebytes' anti-malware\mbamgui.exe" [2012-04-04 462408] . c:\users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2012-3-6 6144] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKLM\~\startupfolder\C:^Users^da_tschaemp2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Trillian.lnk] path=c:\users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk backup=c:\windows\pss\Trillian.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2012-02-15 12:35 17146504 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify] 2012-03-14 20:33 4011184 ----a-w- c:\users\da_tschaemp2\AppData\Roaming\Spotify\spotify.exe . R1 CXAVSAUD;Prolink 2388x Audio Capture;c:\windows\system32\DRIVERS\pvavsaud.sys [2005-10-25 11008] R1 SWIPsec;SonicWALL IPsec Driver;c:\windows\system32\Drivers\SWIPsec.sys [2009-03-05 87064] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-02-15 158856] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 257696] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [2006-05-27 147009] R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [2006-05-27 497216] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\HCW88BAR.sys [2006-05-27 23104] R3 SWVNIC;SonicWALL Virtual Miniport;c:\windows\system32\DRIVERS\swvnic.sys [2009-03-04 21016] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 13824] R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352] R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-16 36000] S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 17920] S2 AntiVirSchedulerService;Avira Planer;e:\avira\AntiVir Desktop\sched.exe [2012-05-08 86224] S2 dtpd;ShrewSoft DNS Proxy Daemon;e:\vpn\dtpd.exe [2010-10-08 54544] S2 iked;ShrewSoft IKE Daemon;e:\vpn\iked.exe [2010-10-08 726288] S2 ipsecd;ShrewSoft IPSEC Daemon;e:\vpn\ipsecd.exe [2010-10-08 541968] S2 MBAMService;MBAMService;e:\malwarebytes' anti-malware\mbamservice.exe [2012-04-04 654408] S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;e:\nitroreader\NitroPDFReaderDriverService2.exe [2012-02-23 198136] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-11-17 5120] S2 SWGVCSvc;SonicWALL Global VPN Client Service;e:\sonicwall\SWGVCSvc.exe [2009-03-05 227352] S2 TeamViewer7;TeamViewer 7;e:\teamviewer\TeamViewer_Service.exe [2012-02-23 2886528] S3 AtcL001;NDIS-Miniporttreiber für L1-Gigabit-Ethernet-Controller von Atheros;c:\windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344] S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-12-16 25088] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc . Inhalt des "geplante Tasks" Ordners . 2012-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 17:11] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\da_tschaemp2\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.178.1 TCP: Interfaces\{C17C8B53-9781-4D18-BEE2-DBFAD179FA5E}: NameServer = 193.174.193.80 FF - ProfilePath - c:\users\da_tschaemp2\AppData\Roaming\Mozilla\Firefox\Profiles\uhkxh89i.default\ . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'Explorer.exe'(1460) c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . Zeit der Fertigstellung: 2012-05-21 12:59:02 ComboFix-quarantined-files.txt 2012-05-21 10:59 . Vor Suchlauf: 9 Verzeichnis(se), 30.494.744.576 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 30.271.483.904 Bytes frei . - - End Of File - - F3FA58C043A921C1755899531E588FFA |
21.05.2012, 12:48 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnews Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM! Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes: Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.
__________________ Logfiles bitte immer in CODE-Tags posten |
21.05.2012, 20:08 | #21 |
| google rocketnews so, also das mit dem GMER hat nicht wirklich funktioniert, deswegen hier das OSAM log: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 21:06:46 on 21.05.2012 OS: Windows 7 Service Pack 1 (Build 7601), 32-bit Default Browser: Opera Software Opera Internet Browser 11.64 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [Control Panel Objects] -----( %SystemRoot%\system32 )----- "FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys "avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys "catchme" (catchme) - ? - C:\Users\DA_TSC~1\AppData\Local\Temp\catchme.sys (File not found) "Cisco Systems Inc. IPSec Driver" (CVPNDRVA) - "Cisco Systems, Inc." - C:\Windows\system32\Drivers\CVPNDRVA.sys "DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys (File not found) "fwtyqpog" (fwtyqpog) - ? - C:\Users\DA_TSC~1\AppData\Local\Temp\fwtyqpog.sys (Hidden registry entry, rootkit activity | File not found) "MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys "NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys "SonicWALL IPsec Driver" (SWIPsec) - "SonicWALL, Inc." - C:\Windows\system32\Drivers\SWIPsec.sys "ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys [Explorer] -----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Classes\Protocols\Filter )----- {807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL {88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\Display\nvui.dll {99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - E:\iTunes\iTunesMiniPlayer.dll {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\shlext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - E:\WinRAR\rarext.dll [Internet Explorer] -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL {48E73304-E1D6-4330-914C-F5F514E3486C} "Send to OneNote" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\jp2ssv.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\ssv.dll [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "Dropbox.lnk" - "Dropbox, Inc." - C:\Users\da_tschaemp2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Shortcut exists | File exists) -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "VPN Client.lnk" - "Cisco Systems, Inc." - E:\Cisco\vpngui.exe (Shortcut exists | File exists) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "3200 Scan2PC" - ? - "C:\Windows\twain_32\Samsung\SCX3200\Scan2Pc.exe" "APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "avgnt" - "Avira Operations GmbH & Co. KG" - "E:\Avira\AntiVir Desktop\avgnt.exe" /min "GrooveMonitor" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" "iTunesHelper" - "Apple Inc." - "E:\iTunes\iTunesHelper.exe" "Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "E:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray "PDFPrint" - "Geek Software GmbH" - E:\PDF24\pdf24.exe "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll "Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe "Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\avguard.exe "Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\sched.exe "Cisco Systems, Inc. VPN Service" (CVPND) - "Cisco Systems, Inc." - E:\Cisco\cvpnd.exe "Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe "MBAMService" (MBAMService) - "Malwarebytes Corporation" - E:\Malwarebytes' Anti-Malware\mbamservice.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE "Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe "NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - E:\NitroReader\NitroPDFReaderDriverService2.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files\WinPcap\rpcapd.exe "ShrewSoft DNS Proxy Daemon" (dtpd) - ? - E:\VPN\dtpd.exe (File found, but it contains no detailed information) "ShrewSoft IKE Daemon" (iked) - ? - E:\VPN\iked.exe (File found, but it contains no detailed information) "ShrewSoft IPSEC Daemon" (ipsecd) - ? - E:\VPN\ipsecd.exe (File found, but it contains no detailed information) "Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe "SonicWALL Global VPN Client Service" (SWGVCSvc) - "SonicWALL, Inc." - E:\SonicWall\SWGVCSvc.exe "TeamViewer 7" (TeamViewer7) - "TeamViewer GmbH" - E:\TeamViewer\TeamViewer_Service.exe [Winsock Providers] -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )----- "mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Code:
ATTFilter aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-05-21 21:09:11 ----------------------------- 21:09:11.130 OS Version: Windows 6.1.7601 Service Pack 1 21:09:11.130 Number of processors: 2 586 0x4303 21:09:11.131 ComputerName: DA_TSCHAEMP2-PC UserName: da_tschaemp2 21:09:12.380 Initialize success 21:12:37.333 AVAST engine defs: 12052100 21:12:55.736 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 21:12:55.738 Disk 0 Vendor: SAMSUNG_HD501LJ CR100-12 Size: 476940MB BusType: 3 21:12:56.050 Disk 0 MBR read successfully 21:12:56.057 Disk 0 MBR scan 21:12:56.082 Disk 0 Windows 7 default MBR code 21:12:56.089 Disk 0 Partition 1 00 42 SFS 100 MB offset 14 21:12:56.112 Disk 0 Partition 2 80 (A) 42 SFS NTFS 51200 MB offset 206848 21:12:56.133 Disk 0 Partition 3 00 42 SFS NTFS 425638 MB offset 105064448 21:12:56.264 Disk 0 scanning sectors +976771120 21:12:56.327 Disk 0 scanning C:\Windows\system32\drivers 21:12:56.331 Service scanning 21:13:12.501 Modules scanning 21:13:13.323 Disk 0 trace - called modules: 21:13:13.366 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 21:13:13.371 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85658a00] 21:13:13.376 3 CLASSPNP.SYS[88da559e] -> nt!IofCallDriver -> [0x851c6918] 21:13:13.381 5 ACPI.sys[887b53d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x848a9610] 21:13:13.602 AVAST engine scan C:\Windows 21:13:13.617 AVAST engine scan C:\Windows\system32 21:13:13.632 AVAST engine scan C:\Windows\system32\drivers 21:13:13.645 AVAST engine scan C:\Users\da_tschaemp2 21:13:13.651 AVAST engine scan C:\ProgramData 21:13:13.658 Scan finished successfully 21:13:39.848 Disk 0 MBR has been saved successfully to "C:\Users\da_tschaemp2\Desktop\MBR.dat" 21:13:39.856 The log file has been saved successfully to "C:\Users\da_tschaemp2\Desktop\aswMBR.txt" |
21.05.2012, 20:53 | #22 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnewsZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
21.05.2012, 21:10 | #23 |
| google rocketnews hier das neue OSAM log: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 22:09:10 on 21.05.2012 OS: Windows 7 Service Pack 1 (Build 7601), 32-bit Default Browser: Opera Software Opera Internet Browser 11.64 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [Control Panel Objects] -----( %SystemRoot%\system32 )----- "FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- "mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys "avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys "catchme" (catchme) - ? - C:\Users\DA_TSC~1\AppData\Local\Temp\catchme.sys (File not found) "Cisco Systems Inc. IPSec Driver" (CVPNDRVA) - "Cisco Systems, Inc." - C:\Windows\system32\Drivers\CVPNDRVA.sys "MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys "NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys "SonicWALL IPsec Driver" (SWIPsec) - "SonicWALL, Inc." - C:\Windows\system32\Drivers\SWIPsec.sys "ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys (Disabled) "DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys (File not found) [Explorer] -----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found) -----( HKLM\Software\Classes\Protocols\Filter )----- {807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL -----( HKLM\Software\Classes\Protocols\Handler )----- {314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL {88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\Display\nvui.dll {99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - E:\iTunes\iTunesMiniPlayer.dll {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll {0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\shlext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - E:\WinRAR\rarext.dll [Internet Explorer] -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL {48E73304-E1D6-4330-914C-F5F514E3486C} "Send to OneNote" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\jp2ssv.dll {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\ssv.dll [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "Dropbox.lnk" - "Dropbox, Inc." - C:\Users\da_tschaemp2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Shortcut exists | File exists) -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "VPN Client.lnk" - "Cisco Systems, Inc." - E:\Cisco\vpngui.exe (Shortcut exists | File exists) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "3200 Scan2PC" - ? - "C:\Windows\twain_32\Samsung\SCX3200\Scan2Pc.exe" "APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "avgnt" - "Avira Operations GmbH & Co. KG" - "E:\Avira\AntiVir Desktop\avgnt.exe" /min "GrooveMonitor" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" "iTunesHelper" - "Apple Inc." - "E:\iTunes\iTunesHelper.exe" "Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "E:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray "PDFPrint" - "Geek Software GmbH" - E:\PDF24\pdf24.exe "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll "Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe "Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\avguard.exe "Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\sched.exe "Cisco Systems, Inc. VPN Service" (CVPND) - "Cisco Systems, Inc." - E:\Cisco\cvpnd.exe "Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe "MBAMService" (MBAMService) - "Malwarebytes Corporation" - E:\Malwarebytes' Anti-Malware\mbamservice.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE "Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe "NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - E:\NitroReader\NitroPDFReaderDriverService2.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files\WinPcap\rpcapd.exe "ShrewSoft DNS Proxy Daemon" (dtpd) - ? - E:\VPN\dtpd.exe (File found, but it contains no detailed information) "ShrewSoft IKE Daemon" (iked) - ? - E:\VPN\iked.exe (File found, but it contains no detailed information) "ShrewSoft IPSEC Daemon" (ipsecd) - ? - E:\VPN\ipsecd.exe (File found, but it contains no detailed information) "Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe "SonicWALL Global VPN Client Service" (SWGVCSvc) - "SonicWALL, Inc." - E:\SonicWall\SWGVCSvc.exe "TeamViewer 7" (TeamViewer7) - "TeamViewer GmbH" - E:\TeamViewer\TeamViewer_Service.exe [Winsock Providers] -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )----- "mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll ===[ Logfile end ]=========================================[ Logfile end ]=== If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru |
22.05.2012, 12:18 | #25 |
| google rocketnews so ich denke diesmal hats geklappt... Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-05-22 13:15:33 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD501LJ rev.CR100-12 Running: 2po7kjfe.exe; Driver: C:\Users\DA_TSC~1\AppData\Local\Temp\fwtyqpog.sys ---- System - GMER 1.0.15 ---- SSDT 8E1D3CBE ZwCreateSection SSDT 8E1D3CC8 ZwRequestWaitReplyPort SSDT 8E1D3CC3 ZwSetContextThread SSDT 8E1D3CCD ZwSetSecurityObject SSDT 8E1D3CD2 ZwSystemDebugControl SSDT 8E1D3C5F ZwTerminateProcess ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82A873C9 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AC0D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 82AC7EAC 4 Bytes [BE, 3C, 1D, 8E] .text ntkrnlpa.exe!KeRemoveQueueEx + 1553 82AC8208 4 Bytes [C8, 3C, 1D, 8E] {ENTER 0x1d3c, 0x8e} .text ntkrnlpa.exe!KeRemoveQueueEx + 1597 82AC824C 4 Bytes [C3, 3C, 1D, 8E] .text ntkrnlpa.exe!KeRemoveQueueEx + 1613 82AC82C8 4 Bytes [CD, 3C, 1D, 8E] .text ntkrnlpa.exe!KeRemoveQueueEx + 1667 82AC831C 4 Bytes [D2, 3C, 1D, 8E] .text ... ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \Driver\ACPI_HAL \Device\00000057 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation) ---- EOF - GMER 1.0.15 ---- |
22.05.2012, 13:19 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnews Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!!
__________________ Logfiles bitte immer in CODE-Tags posten |
22.05.2012, 19:42 | #27 |
| google rocketnewsCode:
ATTFilter Malwarebytes Anti-Malware (Test) 1.61.0.1400 www.malwarebytes.org Datenbank Version: v2012.05.22.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 da_tschaemp2 :: DA_TSCHAEMP2-PC [Administrator] Schutz: Deaktiviert 22.05.2012 19:42:27 mbam-log-2012-05-22 (19-42-27).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 325592 Laufzeit: 51 Minute(n), 36 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
22.05.2012, 19:46 | #28 |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnews Das ist schon mal ok
__________________ Logfiles bitte immer in CODE-Tags posten |
22.05.2012, 20:05 | #29 |
| google rocketnewsCode:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 05/22/2012 at 08:53 PM Application Version : 5.0.1150 Core Rules Database Version : 8632 Trace Rules Database Version: 6444 Scan type : Quick Scan Total Scan Time : 00:03:49 Operating System Information Windows 7 Professional 32-bit, Service Pack 1 (Build 6.01.7601) UAC On - Administrator Memory items scanned : 699 Memory threats detected : 0 Registry items scanned : 27453 Registry threats detected : 1 File items scanned : 7661 File threats detected : 75 Adware.Tracking Cookie C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\XBXRKGU4.txt [ /mediaplex.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\E3EV5O16.txt [ /ad.yieldmanager.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\U60X147P.txt [ /track.adform.net ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\FN70AM1W.txt [ /invitemedia.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\YFZS01LZ.txt [ /smartadserver.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\VDP4E7SM.txt [ /c.atdmt.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\R1QZ7PF2.txt [ /dyntracker.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\L8A0YQGT.txt [ /atdmt.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\HDGR0L02.txt [ /apmebf.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\MQ3WI5W4.txt [ /adform.net ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\MNCADX1N.txt [ /fastclick.net ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\4ZZHMMP9.txt [ /imrworldwide.com ] .doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] track.adform.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] track.adform.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .adform.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .ad-emea.doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .ad-emea.doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .ad-emea.doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\RPPGIHD0.txt [ /serving-sys.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\EILJ14BJ.txt [ /bs.serving-sys.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\M3FZM7YP.txt [ /eas.apm.emediate.eu ] .a.revenuemax.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\13DG6UXZ.txt [ /tracking.quisma.com ] C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\UX97VHG2.txt [ /zanox.com ] .atdmt.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] ad2.adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] xml.trafficno.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] xml.trafficno.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] ox-d.enveromedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .zanox.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\XBXRKGU4.txt [ Cookie:da_tschaemp2@mediaplex.com/ ] .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\E3EV5O16.txt [ Cookie:da_tschaemp2@ad.yieldmanager.com/ ] .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\U60X147P.txt [ Cookie:da_tschaemp2@track.adform.net/ ] C:\USERS\DA_TSCHAEMP2\Cookies\FN70AM1W.txt [ Cookie:da_tschaemp2@invitemedia.com/ ] .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] ad3.adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\YFZS01LZ.txt [ Cookie:da_tschaemp2@smartadserver.com/ ] C:\USERS\DA_TSCHAEMP2\Cookies\VDP4E7SM.txt [ Cookie:da_tschaemp2@c.atdmt.com/ ] .tracking.quisma.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\L8A0YQGT.txt [ Cookie:da_tschaemp2@atdmt.com/ ] .invitemedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\HDGR0L02.txt [ Cookie:da_tschaemp2@apmebf.com/ ] ad.yieldmanager.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] adx.chip.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ] C:\USERS\DA_TSCHAEMP2\Cookies\EILJ14BJ.txt [ Cookie:da_tschaemp2@bs.serving-sys.com/ ] C:\USERS\DA_TSCHAEMP2\Cookies\M3FZM7YP.txt [ Cookie:da_tschaemp2@eas.apm.emediate.eu/ ] C:\USERS\DA_TSCHAEMP2\Cookies\13DG6UXZ.txt [ Cookie:da_tschaemp2@tracking.quisma.com/ ] C:\USERS\DA_TSCHAEMP2\Cookies\UX97VHG2.txt [ Cookie:da_tschaemp2@zanox.com/ ] System.BrokenFileAssociation HKCR\.exe |
22.05.2012, 20:24 | #30 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | google rocketnewsZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu google rocketnews |
aktiviere, andere, anderen, anleitungen, antworten, board, eigenes, einfach, erstell, falsche, geleitet, google, links, nicht mehr, nicht sicher, problem, radio, rocketnews, thema, windows-sicherheitscenter, worte |