|
Plagegeister aller Art und deren Bekämpfung: Live Security Platinum VirusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.07.2012, 10:49 | #16 |
| Live Security Platinum Virus Hierdas ESET Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=18e0d5d5adf8a74ab14e730040fadffb # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-22 09:38:42 # local_time=2012-07-22 11:38:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 100054 94535140 0 0 # compatibility_mode=8192 67108863 100 0 160 160 0 0 # scanned=301220 # found=1 # cleaned=1 # scan_time=44632 D:\**-HP\Backup Set 2012-07-16 002330\Backup Files 2012-07-16 002330\Backup files 8.zip Java/Exploit.CVE-2012-1723.G trojan (deleted - quarantined) 00000000000000000000000000000000 C |
22.07.2012, 10:51 | #17 |
/// Helfer-Team | Live Security Platinum Virus Sehr gut!
__________________Combofix deinstallieren Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking (Norton) und Anti-Malware Programme deaktivieren. Start => Ausführen => dort reinschreiben ComboFix /Uninstall => Enter drücken Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch daraus die Schädlinge verschwinden. Es wird ein neuer Systemwiederherstellungspunkt erstellt. Gleichzeitig setzt Combofix die Zeiteinstellungen wieder auf die Ursprungseinstellungen, und setzt die Systemeinstellungen wieder so zurück, dass Dateierweiterungen und Systemdateien versteckt sind, was Du bei Bedarf im Explorer unter Extras => Ordneroptionen aber wieder ändern bzw. Deinen persönlichen Vorlieben entsprechend anpassen kannst. dann: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ |
22.07.2012, 11:28 | #18 |
| Live Security Platinum Virus Der sagt mir das McAfee aktiv ist:
__________________[IMG][/IMG] ist es aber nicht!!? [IMG][/IMG] Hallo, irgendwie hat es nicht funktioniert... ComboFix wurde nicht deinstalliert, sondern nochmal ausgeführt. Dabei gab es diese Fehlermeldung mit Mcafee. Hier das Logfile: Code:
ATTFilter ComboFix 12-07-19.02 - admin 22.07.2012 16:35:32.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8140.5943 [GMT 2:00] ausgeführt von:: c:\users\***\Desktop\ComboFix.exe Benutzte Befehlsschalter :: / uninstall AV: McAfee VirusScan Enterprise *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2012-06-22 bis 2012-07-22 )))))))))))))))))))))))))))))) . . 2012-07-22 14:41 . 2012-07-22 14:41 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-07-22 14:41 . 2012-07-22 14:41 -------- d-----w- c:\users\admin\AppData\Local\temp 2012-07-18 21:03 . 2012-07-18 21:03 -------- d-----w- C:\_OTL 2012-07-16 11:45 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys 2012-07-16 11:38 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll 2012-07-16 11:38 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll 2012-07-16 07:52 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll 2012-07-16 07:52 . 2012-06-06 06:06 1881600 ----a-w- c:\windows\system32\msxml3.dll 2012-07-16 07:52 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll 2012-07-16 07:52 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll 2012-07-16 07:52 . 2010-06-26 03:55 2048 ----a-w- c:\windows\system32\msxml3r.dll 2012-07-16 07:52 . 2010-06-26 03:24 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2012-07-16 07:52 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll 2012-07-15 22:34 . 2012-07-15 22:34 -------- d-----w- c:\users\***\AppData\Roaming\Malwarebytes 2012-07-15 22:31 . 2012-07-15 22:31 -------- d-----w- c:\users\admin\AppData\Roaming\Malwarebytes 2012-07-15 22:31 . 2012-07-15 22:31 -------- d-----w- c:\programdata\Malwarebytes 2012-07-15 22:31 . 2012-07-15 22:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-07-15 22:31 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-07-14 22:41 . 2012-07-15 14:45 -------- d-----w- c:\programdata\225932FD027865E6C6F46C5BF875F002 2012-07-06 14:29 . 2012-07-06 14:29 -------- d-----w- c:\users\***\AppData\Roaming\PACE Anti-Piracy 2012-07-06 14:29 . 2012-07-06 14:29 -------- d-----w- c:\users\***\AppData\Local\PACE Anti-Piracy 2012-07-06 14:29 . 2012-07-06 14:29 -------- d-----w- c:\programdata\PACE Anti-Piracy 2012-07-06 08:44 . 2012-07-06 08:44 -------- d-----w- c:\users\***\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 2012-07-05 21:13 . 2012-07-05 21:13 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2012-07-05 14:23 . 2012-07-05 14:23 -------- d-----w- c:\programdata\ALM 2012-07-05 14:17 . 2012-07-05 14:17 -------- d-----w- c:\users\admin\Adobe Flash Builder 4.6 2012-07-05 14:10 . 2011-11-03 01:01 56208 ------w- c:\windows\system32\drivers\PxHlpa64.sys 2012-07-05 14:10 . 2011-10-17 01:00 10224 ------w- c:\windows\system32\drivers\cdralw2k.sys 2012-07-05 14:10 . 2011-10-17 01:00 10224 ------w- c:\windows\system32\drivers\cdr4_xp.sys 2012-07-05 14:10 . 2012-07-05 14:10 -------- d-----w- c:\program files (x86)\Common Files\Sonic Shared 2012-07-05 14:10 . 2012-07-05 14:10 -------- d-----w- c:\program files (x86)\My Company Name 2012-07-05 12:49 . 2012-07-16 07:52 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-05 12:49 . 2012-07-16 07:52 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-05 12:49 . 2012-07-05 12:49 -------- d-----w- c:\windows\system32\Macromed 2012-07-04 19:44 . 2012-07-04 19:45 -------- d-----w- c:\program files (x86)\SpeedFan 2012-07-04 10:57 . 2012-07-04 10:57 -------- d-----w- c:\program files\WinRAR 2012-07-01 16:21 . 2012-07-05 18:14 -------- d-----w- c:\programdata\regid.1986-12.com.adobe 2012-07-01 16:20 . 2012-07-18 22:07 -------- d-----w- c:\program files\Adobe 2012-07-01 16:15 . 2012-07-18 22:14 -------- d-----w- c:\program files\Common Files\Adobe 2012-07-01 01:17 . 2012-07-01 01:17 -------- d-----w- c:\users\***\AppData\Local\DDMSettings 2012-07-01 01:16 . 2012-07-01 01:16 -------- d-----w- c:\users\admin\AppData\Roaming\DivX 2012-07-01 01:16 . 2012-07-05 14:10 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine 2012-07-01 01:16 . 2012-07-01 01:16 -------- d-----w- c:\program files\DivX 2012-07-01 01:15 . 2012-07-01 01:16 -------- d-----w- c:\program files (x86)\Common Files\DivX Shared 2012-07-01 01:13 . 2012-07-01 01:17 -------- d-----w- c:\program files (x86)\DivX 2012-07-01 01:12 . 2012-07-01 01:17 -------- d-----w- c:\programdata\DivX 2012-06-27 10:48 . 2012-06-27 10:48 -------- d-----w- c:\users\***\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2012-06-27 10:48 . 2012-06-27 10:48 -------- d-----w- c:\program files (x86)\Adobe Download Assistant 2012-06-27 10:48 . 2012-06-27 10:48 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR 2012-06-27 10:48 . 2012-07-05 14:29 -------- d-----w- c:\users\admin\AppData\Local\Adobe 2012-06-26 19:54 . 2012-07-21 12:03 -------- d-----w- c:\users\admin\AppData\Local\CrashDumps 2012-06-26 14:36 . 2012-07-22 05:48 -------- d-----w- c:\users\***\AppData\Local\Adobe 2012-06-26 08:12 . 2012-06-26 08:12 -------- d-----w- c:\users\***\AppData\Local\fontconfig 2012-06-26 08:12 . 2012-06-27 11:08 -------- d-----w- c:\users\***\.gimp-2.8 2012-06-26 08:12 . 2012-06-26 08:12 -------- d-----w- c:\users\***\AppData\Local\gegl-0.2 2012-06-26 08:11 . 2012-06-26 08:12 -------- d-----w- c:\program files\GIMP 2 2012-06-23 22:17 . 2012-06-23 22:17 -------- d-----w- c:\users\***\AppData\Local\Diagnostics . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-16 11:41 . 2012-06-12 19:55 59701280 ----a-w- c:\windows\system32\MRT.exe 2012-06-12 20:10 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll 2012-06-12 20:10 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2012-06-10 20:04 . 2012-06-10 20:04 476960 ----a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-06-10 20:04 . 2011-01-27 15:33 472864 ----a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-10 11:16 . 2012-06-10 11:16 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-06-10 11:16 . 2012-06-10 11:16 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-06-10 11:16 . 2012-06-10 11:16 89088 ----a-w- c:\windows\system32\ie4uinit.exe 2012-06-10 11:16 . 2012-06-10 11:16 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll 2012-06-10 11:16 . 2012-06-10 11:16 85504 ----a-w- c:\windows\system32\iesetup.dll 2012-06-10 11:16 . 2012-06-10 11:16 82432 ----a-w- c:\windows\system32\icardie.dll 2012-06-10 11:16 . 2012-06-10 11:16 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-06-10 11:16 . 2012-06-10 11:16 76800 ----a-w- c:\windows\system32\tdc.ocx 2012-06-10 11:16 . 2012-06-10 11:16 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-06-10 11:16 . 2012-06-10 11:16 74752 ----a-w- c:\windows\SysWow64\iesetup.dll 2012-06-10 11:16 . 2012-06-10 11:16 697344 ----a-w- c:\windows\system32\msfeeds.dll 2012-06-10 11:16 . 2012-06-10 11:16 65024 ----a-w- c:\windows\system32\pngfilt.dll 2012-06-10 11:16 . 2012-06-10 11:16 63488 ----a-w- c:\windows\SysWow64\tdc.ocx 2012-06-10 11:16 . 2012-06-10 11:16 603648 ----a-w- c:\windows\system32\vbscript.dll 2012-06-10 11:16 . 2012-06-10 11:16 55296 ----a-w- c:\windows\system32\msfeedsbs.dll 2012-06-10 11:16 . 2012-06-10 11:16 534528 ----a-w- c:\windows\system32\ieapfltr.dll 2012-06-10 11:16 . 2012-06-10 11:16 49664 ----a-w- c:\windows\system32\imgutil.dll 2012-06-10 11:16 . 2012-06-10 11:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2012-06-10 11:16 . 2012-06-10 11:16 48640 ----a-w- c:\windows\system32\mshtmler.dll 2012-06-10 11:16 . 2012-06-10 11:16 452608 ----a-w- c:\windows\system32\dxtmsft.dll 2012-06-10 11:16 . 2012-06-10 11:16 448512 ----a-w- c:\windows\system32\html.iec 2012-06-10 11:16 . 2012-06-10 11:16 420864 ----a-w- c:\windows\SysWow64\vbscript.dll 2012-06-10 11:16 . 2012-06-10 11:16 403248 ----a-w- c:\windows\system32\iedkcs32.dll 2012-06-10 11:16 . 2012-06-10 11:16 39936 ----a-w- c:\windows\system32\iernonce.dll 2012-06-10 11:16 . 2012-06-10 11:16 3695416 ----a-w- c:\windows\system32\ieapfltr.dat 2012-06-10 11:16 . 2012-06-10 11:16 367104 ----a-w- c:\windows\SysWow64\html.iec 2012-06-10 11:16 . 2012-06-10 11:16 35840 ----a-w- c:\windows\SysWow64\imgutil.dll 2012-06-10 11:16 . 2012-06-10 11:16 30720 ----a-w- c:\windows\system32\licmgr10.dll 2012-06-10 11:16 . 2012-06-10 11:16 282112 ----a-w- c:\windows\system32\dxtrans.dll 2012-06-10 11:16 . 2012-06-10 11:16 267776 ----a-w- c:\windows\system32\ieaksie.dll 2012-06-10 11:16 . 2012-06-10 11:16 249344 ----a-w- c:\windows\system32\webcheck.dll 2012-06-10 11:16 . 2012-06-10 11:16 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll 2012-06-10 11:16 . 2012-06-10 11:16 222208 ----a-w- c:\windows\system32\msls31.dll 2012-06-10 11:16 . 2012-06-10 11:16 197120 ----a-w- c:\windows\system32\msrating.dll 2012-06-10 11:16 . 2012-06-10 11:16 165888 ----a-w- c:\windows\system32\iexpress.exe 2012-06-10 11:16 . 2012-06-10 11:16 163840 ----a-w- c:\windows\system32\ieakui.dll 2012-06-10 11:16 . 2012-06-10 11:16 161792 ----a-w- c:\windows\SysWow64\msls31.dll 2012-06-10 11:16 . 2012-06-10 11:16 160256 ----a-w- c:\windows\system32\wextract.exe 2012-06-10 11:16 . 2012-06-10 11:16 160256 ----a-w- c:\windows\system32\ieakeng.dll 2012-06-10 11:16 . 2012-06-10 11:16 152064 ----a-w- c:\windows\SysWow64\wextract.exe 2012-06-10 11:16 . 2012-06-10 11:16 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2012-06-10 11:16 . 2012-06-10 11:16 149504 ----a-w- c:\windows\system32\occache.dll 2012-06-10 11:16 . 2012-06-10 11:16 145920 ----a-w- c:\windows\system32\iepeers.dll 2012-06-10 11:16 . 2012-06-10 11:16 135168 ----a-w- c:\windows\system32\IEAdvpack.dll 2012-06-10 11:16 . 2012-06-10 11:16 12288 ----a-w- c:\windows\system32\mshta.exe 2012-06-10 11:16 . 2012-06-10 11:16 11776 ----a-w- c:\windows\SysWow64\mshta.exe 2012-06-10 11:16 . 2012-06-10 11:16 114176 ----a-w- c:\windows\system32\admparse.dll 2012-06-10 11:16 . 2012-06-10 11:16 111616 ----a-w- c:\windows\system32\iesysprep.dll 2012-06-10 11:16 . 2012-06-10 11:16 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-06-10 11:16 . 2012-06-10 11:16 10752 ----a-w- c:\windows\system32\msfeedssync.exe 2012-06-10 11:16 . 2012-06-10 11:16 103936 ----a-w- c:\windows\system32\inseng.dll 2012-06-10 11:16 . 2012-06-10 11:16 101888 ----a-w- c:\windows\SysWow64\admparse.dll 2012-06-09 18:52 . 2012-06-09 18:52 163048 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10141.bin 2012-06-02 22:19 . 2012-06-21 18:27 38424 ----a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-21 18:28 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-21 18:28 57880 ----a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 18:28 44056 ----a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-21 18:27 701976 ----a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-21 18:28 2622464 ----a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-21 18:27 99840 ----a-w- c:\windows\system32\wudriver.dll 2012-06-02 13:19 . 2012-06-21 18:27 186752 ----a-w- c:\windows\system32\wuwebv.dll 2012-06-02 13:15 . 2012-06-21 18:27 36864 ----a-w- c:\windows\system32\wuapp.exe 2012-05-31 10:25 . 2012-06-11 19:29 279656 ------w- c:\windows\system32\MpSigStub.exe 2012-05-23 22:15 . 2010-06-24 10:33 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-05-09 15:00 . 2012-06-14 18:41 13184 ----a-w- c:\windows\system32\drivers\dvdfabio.sys 2012-05-09 15:00 . 2012-06-14 18:41 45952 ----a-w- c:\windows\system32\drivers\vdrive.sys 2012-05-04 11:06 . 2012-06-12 19:32 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-12 19:32 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-12 19:32 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40 . 2012-06-12 19:31 209920 ----a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-12 19:31 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-12 19:32 77312 ----a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-12 19:32 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-12 19:32 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-25 10:11 . 2012-04-25 10:11 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys 2012-04-25 10:11 . 2012-04-25 10:11 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll 2012-04-24 05:37 . 2012-06-12 19:32 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 05:37 . 2012-06-12 19:32 140288 ----a-w- c:\windows\system32\cryptnet.dll 2012-04-24 05:37 . 2012-06-12 19:32 1462272 ----a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-12 19:32 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll 2012-04-24 04:36 . 2012-06-12 19:32 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2012-04-24 04:36 . 2012-06-12 19:32 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll . . ((((((((((((((((((((((((((((( SnapShot@2012-07-19_20.42.18 ))))))))))))))))))))))))))))))))))))))))) . + 2011-01-27 15:16 . 2012-07-20 15:35 55636 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-07-21 20:44 33984 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2012-05-23 22:09 . 2012-07-19 19:54 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2012-05-23 22:09 . 2012-07-21 11:22 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-05-23 22:09 . 2012-07-19 19:54 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-05-23 22:09 . 2012-07-21 11:22 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-07-21 11:22 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-07-19 19:54 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-05-23 22:16 . 2012-07-21 20:44 7714 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-625476035-1192893045-2691204042-1001_UserData.bin + 2012-07-21 20:42 . 2012-07-21 20:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-07-19 19:46 . 2012-07-19 19:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-21 20:42 . 2012-07-21 20:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-07-19 19:46 . 2012-07-19 19:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-06-11 18:50 . 2012-07-22 14:19 285540 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2012-07-18 07:44 616008 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-07-21 21:11 616008 c:\windows\system32\perfh009.dat + 2011-01-27 23:28 . 2012-07-21 21:11 654166 c:\windows\system32\perfh007.dat - 2011-01-27 23:28 . 2012-07-18 07:44 654166 c:\windows\system32\perfh007.dat + 2009-07-14 02:36 . 2012-07-21 21:11 106388 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2012-07-18 07:44 106388 c:\windows\system32\perfc009.dat + 2011-01-27 23:28 . 2012-07-21 21:11 130006 c:\windows\system32\perfc007.dat - 2011-01-27 23:28 . 2012-07-18 07:44 130006 c:\windows\system32\perfc007.dat + 2009-07-14 05:01 . 2012-07-21 20:41 479208 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2012-07-19 19:46 479208 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2011-04-09 14:21 . 2012-07-19 19:46 1878552 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2011-04-09 14:21 . 2012-07-21 20:41 1878552 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2012-06-14 12:17 . 2012-07-21 20:41 25404684 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-625476035-1192893045-2691204042-1003-12288.dat - 2012-06-14 12:17 . 2012-07-18 21:04 25404684 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-625476035-1192893045-2691204042-1003-12288.dat . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-11-22 2736128] "DVDFab VDrive"="c:\program files\DVDFab Virtual Drive\vdrive.exe" [2012-05-09 412032] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-12-30 336384] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-11-25 75048] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-11-09 586296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2010-12-13 61112] "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2010-12-13 318520] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "McAfeeUpdaterUI"="c:\program files (x86)\McAfee\Common Framework\udaterui.exe" [2009-08-25 136512] "ShStatEXE"="c:\program files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-10-22 124240] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-04-04 36760] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-04-04 815512] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "!BingBar"="c:\program files (x86)\Microsoft\BingBar\7.1.361.0\MUExe\7.1.361.0\BingBarSetup-Partner.EXE" [2012-02-10 6191616] " Malwarebytes Anti-Malware "="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "OTL"="c:\users\***\Desktop\OTL.exe" [2012-07-17 596480] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-7-29 1132320] Snapfish PictureMover.lnk - c:\program files (x86)\PictureMover\Bin\PictureMover.exe [2010-11-18 1040952] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" . R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/04/09 16:09;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-11-24 241648] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-16 250056] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-06-22 113792] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2009-10-22 77104] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2012-03-26 22528] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208] S1 dvdfabio;dvdfabio;c:\windows\system32\drivers\dvdfabio.sys [2012-05-09 13184] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-12-31 203776] S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe [x] S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2010-12-07 249672] S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-07-21 103992] S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-05 291896] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-11-03 92216] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 30520] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-09 26680] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-13 13336] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 McAfeeEngineService;McAfee Engine Service;c:\program files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe [2009-10-22 19720] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2009-10-22 79504] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-11-23 2656280] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-12-31 8281600] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-12-31 292864] S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-07-14 344616] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-02 39464] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-12-10 31088] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2010-12-17 12256512] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-01-12 333928] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-10-19 406632] S3 vdrive;vdrive;c:\windows\system32\DRIVERS\vdrive.sys [2012-05-09 45952] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - CLKMDRV10_38F51D56 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2010-11-22 12:18 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Inhalt des "geplante Tasks" Ordners . 2012-07-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-625476035-1192893045-2691204042-1001Core.job - c:\users\***\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-10 11:09] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-625476035-1192893045-2691204042-1001UA.job - c:\users\***\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-10 11:09] . 2012-07-22 c:\windows\Tasks\HPCeeScheduleFor***.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 21:15] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00Zecter] @="{D25B32FE-CB96-491A-98FF-AD59DA382D69}" [HKEY_CLASSES_ROOT\CLSID\{D25B32FE-CB96-491A-98FF-AD59DA382D69}] 2010-12-11 02:32 2240000 ----a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01Zecter] @="{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}" [HKEY_CLASSES_ROOT\CLSID\{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}] 2010-12-11 02:32 2240000 ----a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02Zecter] @="{B3C78E40-6B64-47C3-AE34-60B770881EB8}" [HKEY_CLASSES_ROOT\CLSID\{B3C78E40-6B64-47C3-AE34-60B770881EB8}] 2010-12-11 02:32 2240000 ----a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03Zecter] @="{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}" [HKEY_CLASSES_ROOT\CLSID\{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}] 2010-12-11 02:32 2240000 ----a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\04Zecter] @="{855156F0-2A0F-11DE-8C30-0800200C9A66}" [HKEY_CLASSES_ROOT\CLSID\{855156F0-2A0F-11DE-8C30-0800200C9A66}] 2010-12-11 02:32 2240000 ----a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-12-17 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-12-17 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-12-17 418328] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-12-02 524800] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-07-21 8192] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "*Restore"="c:\windows\System32\rstrui.exe" [2010-11-20 296960] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.0.1 . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2012-07-22 16:42:54 ComboFix-quarantined-files.txt 2012-07-22 14:42 ComboFix2.txt 2012-07-19 20:44 . Vor Suchlauf: 17 Verzeichnis(se), 648.785.555.456 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 648.728.276.992 Bytes frei . - - End Of File - - 720BEF7F3923971BEBAAB28A711C1BB7 |
22.07.2012, 18:08 | #19 |
/// Helfer-Team | Live Security Platinum Virus Deinstalliere McAffee Mache mit Emsisoft weiter. |
23.07.2012, 12:19 | #20 |
| Live Security Platinum Virus Hallo, McAfee deinstalliert. Emsisoft wie beschrieben ausgeführt und fündig geworden: [IMG][/IMG] in Quarantäne verschoben. Dann auf "Bericht anzeigen" geklickt und: [IMG][/IMG] [IMG][/IMG] kein Pfad bzw. Ordner verschoben Geändert von TorPedetor (23.07.2012 um 12:25 Uhr) |
23.07.2012, 17:36 | #21 |
/// Helfer-Team | Live Security Platinum Virus Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html
__________________ --> Live Security Platinum Virus |
23.07.2012, 19:33 | #22 |
| Live Security Platinum Virus Java aktualisiert und richtig eingestellt. Ich glaube, ich weiß jetzt was ich die ganze Zeit falsch gemacht habe... Ich habe auf meinem Laptop 2 Benutzerkonten, ein admi und ein normaler Benutzer. Alle Anweisungen von Dir habe ich als normaler Benutzer ausgeführt und jedesmal, wenn er Administrator Rechte verlangt hat, habe ich das Password eingegeben und fertig. Aber eben als ich die Java Update Einstellungen vornehmen wollte, war diese Option grau hinterlegt und ließ sich auch nicht als Admi öffnen. Also habe ich (zum erstenmal!) den User gewechselt... und siehe da, OTL wurde automatisch ausgeführt und folgende OTL-LogDatei ausgespuckt: Code:
ATTFilter All processes killed ========== OTL ========== No active process named DivXUpdate.exe was found! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}\ not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully. C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-625476035-1192893045-2691204042-1001UA.job moved successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully. C:\Windows\Tasks\AutoKMS.job moved successfully. File C:\Windows\Tasks\AutoKMS.job not found. C:\Windows\Tasks\HPCeeScheduleForWIN-RS8RTOFVIIM$.job moved successfully. File C:\Windows\tasks\HPCeeScheduleFor***.job not found. C:\Windows\Tasks\AutoKMSDaily.job moved successfully. File C:\Windows\Tasks\AutoKMSDaily.job not found. C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-625476035-1192893045-2691204042-1001Core.job moved successfully. File C:\Windows\tasks\Adobe Flash Player Updater.job not found. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\***\Desktop\cmd.bat deleted successfully. C:\Users\***\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: admin ->Temp folder emptied: 7710653 bytes ->Temporary Internet Files folder emptied: 10576900 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 1012 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56478 bytes User: Default User User: *** ->Temp folder emptied: 41296258 bytes ->Temporary Internet Files folder emptied: 51134029 bytes ->Java cache emptied: 51256 bytes ->Google Chrome cache emptied: 64242416 bytes ->Flash cache emptied: 57497 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 8687762 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36028538 bytes RecycleBin emptied: 4259 bytes Total Files Cleaned = 210,00 mb [EMPTYFLASH] User: admin ->Flash cache emptied: 0 bytes User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User User: *** ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07192012_003030 Files\Folders moved on Reboot... File move failed. C:\Users\***\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot. PendingFileRenameOperations files... [2012.05.24 00:21:42 | 000,000,000 | ---- | M] () C:\Users\***\AppData\Local\Temp\FXSAPIDebugLogFile.txt : Unable to obtain MD5 Registry entries deleted on Reboot... |
24.07.2012, 00:43 | #23 |
/// Helfer-Team | Live Security Platinum Virus Sehr gut! damit bist Du sauber und entlassen! Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html |
Themen zu Live Security Platinum Virus |
adobe, autorun, bho, bingbar, bonjour, document, error, explorer, firefox, flash player, format, google, helper, home, igdpmd64.sys, launch, live security platinum entfernen, logfile, photoshop, plug-in, programme, pup.bundleinstaller.bi, realtek, recycle.bin, registry, searchscopes, security, services.exe, software, systemwiederherstellung, updates, usb, usb 3.0, virus, windows, windows 7 64 bit |