Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 07.08.2012, 23:14   #1
Dharkkum
 
win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast! - Standard

win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!



Hallo Zusammen,
ich bin neu hier, also erstmal einen Gruß in die Runde.
Und schon muss ich Euch mit einem Problem belästigen. Bin nicht der Held in diesen Dingen, also entschuldigt meine "blöden" Fragen.
Versuche mich jetzt mal verständlich auszudrücken.

Also avast "schreit" mich heute mit drei Meldungen an.

Win32:Sirefef-AO[Rtk] in C:Windows/Installer/.../800000cb.@
Win64:Sirefef-A.[Trj] in C:Windows/Installer/.../80000000.@
Win32:Maleware.gen in C:Windows/Installer/.../00000001.@

hab versucht diese in den Container zu verschieben, was nicht viel brachte. Daher habe ich gegooglet und bei Euch im Forum gelesen. Nur habe ich mich ehrlich gesagt nicht getraut allein Hand anzulegen.
Deshalb habe ich versucht Euren Hinweisen nachzugehen und hab Logfiles erstellt.
Hoffe das es so richtig war. Ansonsten bitte nicht schlagen, sondern bescheid sagen. Danke schön .
Wenn ich das richtig verstanden habe wollt Ihr den OTL.txt im Thread haben.
Und die anderen als Anhang.
Würde mich sehr über Hilfe freuen.
Danke schön
Gruß
Lio


Zitat:
OTL logfile created on: 07.08.2012 20:25:25 - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\melfluga\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,25 Gb Total Physical Memory | 1,84 Gb Available Physical Memory | 56,52% Memory free
6,70 Gb Paging File | 5,47 Gb Available in Paging File | 81,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 153,63 Gb Total Space | 83,70 Gb Free Space | 54,48% Space Free | Partition Type: NTFS
Drive D: | 303,34 Gb Total Space | 284,54 Gb Free Space | 93,80% Space Free | Partition Type: NTFS

Computer Name: MELFLUGA-PC | User Name: melfluga | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.08.07 20:24:49 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\melfluga\Downloads\OTL.exe
PRC - [2012.07.03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.06.27 13:01:14 | 000,096,768 | ---- | M] (Freemake) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
PRC - [2011.08.01 10:28:16 | 000,124,480 | ---- | M] (ICQ, LLC.) -- C:\Programme\ICQ7.5\ICQ.exe
PRC - [2010.12.14 16:49:23 | 001,169,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
PRC - [2010.09.21 14:03:14 | 001,710,464 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2010.09.21 14:03:14 | 000,193,408 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009.02.26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009.01.09 19:46:32 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.bin
PRC - [2009.01.09 19:45:26 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 3\program\soffice.exe
PRC - [2008.06.02 09:47:34 | 000,277,616 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\Zlh.exe
PRC - [2008.05.30 18:12:24 | 001,502,208 | ---- | M] (Koninklijke Philips Electronics N.V.) -- C:\Programme\Philips\SA19xx\Philips Device Manager\bin\DeviceManager.exe
PRC - [2008.05.28 16:06:02 | 006,144,000 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.05.28 13:40:28 | 000,020,480 | ---- | M] ( ) -- C:\Programme\Google\Google EULA\GoogleEULALauncher.exe
PRC - [2008.05.13 10:49:00 | 000,203,896 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\Njeeves.exe
PRC - [2008.04.25 14:23:36 | 000,303,104 | ---- | M] (Fujitsu Siemens Computers) -- C:\Programme\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
PRC - [2008.04.24 12:04:34 | 000,429,176 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\Zanda.exe
PRC - [2008.02.26 03:23:34 | 000,443,968 | ---- | M] (Google Inc.) -- C:\Programme\Picasa2\PicasaMediaDetector.exe
PRC - [2008.02.07 11:07:04 | 000,121,912 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\nvoy.exe
PRC - [2007.12.06 16:15:44 | 000,609,384 | ---- | M] (National Instruments Corporation) -- C:\Programme\National Instruments\Shared\Tagger\tagsrv.exe
PRC - [2007.11.27 16:38:04 | 000,695,136 | ---- | M] (National Instruments, Inc.) -- C:\Windows\System32\lkcitdl.exe
PRC - [2007.11.27 14:57:52 | 000,213,552 | ---- | M] (National Instruments Corporation) -- C:\Programme\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2007.11.27 14:57:20 | 000,050,736 | ---- | M] (National Instruments Corporation) -- C:\Windows\System32\lktsrv.exe
PRC - [2007.11.27 14:56:48 | 000,040,488 | ---- | M] (National Instruments Corporation) -- C:\Windows\System32\lkads.exe
PRC - [2007.11.21 09:59:54 | 000,150,584 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\elogsvc.exe
PRC - [2007.10.28 16:38:32 | 000,221,184 | ---- | M] (Aladdin Knowledge Systems, Ltd.) -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\PKIMonitor.exe
PRC - [2007.10.26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2007.09.18 11:41:18 | 000,154,680 | ---- | M] (Norman ASA) -- C:\Programme\Norman\Npm\Bin\nvcsched.exe
PRC - [2007.08.03 14:59:24 | 000,012,696 | ---- | M] (National Instruments Corporation) -- C:\Programme\National Instruments\MAX\nimxs.exe
PRC - [2007.07.19 17:38:16 | 000,048,704 | ---- | M] (National Instruments Corp.) -- C:\Windows\System32\nisvcloc.exe


========== Modules (No Company Name) ==========

MOD - [2012.06.14 16:59:15 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_5e32eb55\system.drawing.dll
MOD - [2012.06.14 16:59:10 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_af72375d\system.windows.forms.dll
MOD - [2012.06.14 16:58:53 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2012.01.14 12:12:00 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_94ee0c3a\mscorlib.dll
MOD - [2012.01.14 12:11:47 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_89d7c255\system.dll
MOD - [2012.01.14 12:11:32 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012.01.14 12:11:31 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2008.10.04 13:39:19 | 000,299,008 | ---- | M] () -- c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
MOD - [2008.09.16 21:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2008.07.29 13:55:14 | 000,969,728 | ---- | M] () -- C:\Programme\OpenOffice.org 3\program\libxml2.dll
MOD - [2007.03.29 15:11:10 | 000,217,088 | ---- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\QtXml4.dll
MOD - [2007.03.27 20:06:46 | 000,131,072 | R--- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\plugins\imageformats\qjpeg1.dll
MOD - [2007.03.27 20:04:00 | 005,529,600 | R--- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\QtGui4.dll
MOD - [2007.03.27 20:04:00 | 001,466,368 | R--- | M] () -- C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\QtCore4.dll


========== Win32 Services (SafeList) ==========

SRV - [2012.07.14 02:13:54 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.06.27 13:01:14 | 000,096,768 | ---- | M] (Freemake) [Auto | Running] -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2010.09.23 00:21:24 | 001,493,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2010.09.22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 14:03:14 | 001,710,464 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2008.05.13 10:49:00 | 000,203,896 | ---- | M] (Norman ASA) [On_Demand | Running] -- C:\Programme\Norman\Npm\Bin\Njeeves.exe -- (Norman NJeeves)
SRV - [2008.04.25 14:23:36 | 000,303,104 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\Programme\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
SRV - [2008.04.24 12:04:34 | 000,429,176 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Programme\Norman\Npm\Bin\Zanda.exe -- (Norman ZANDA)
SRV - [2008.02.07 11:07:04 | 000,121,912 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Programme\Norman\Npm\Bin\nvoy.exe -- (NVOY)
SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2007.12.06 16:15:44 | 000,609,384 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Programme\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService)
SRV - [2007.11.27 16:38:04 | 000,695,136 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- C:\Windows\System32\lkcitdl.exe -- (LkCitadelServer)
SRV - [2007.11.27 14:57:52 | 000,213,552 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Programme\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2007.11.27 14:57:20 | 000,050,736 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Windows\System32\lktsrv.exe -- (lkTimeSync)
SRV - [2007.11.27 14:56:48 | 000,040,488 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Windows\System32\lkads.exe -- (lkClassAds)
SRV - [2007.11.21 09:59:54 | 000,150,584 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Programme\Norman\Npm\Bin\elogsvc.exe -- (eLoggerSvc6)
SRV - [2007.10.31 09:20:36 | 001,007,616 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- C:\Programme\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager)
SRV - [2007.10.26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2007.09.18 11:41:18 | 000,154,680 | ---- | M] (Norman ASA) [On_Demand | Running] -- C:\Programme\Norman\Npm\Bin\nvcsched.exe -- (NVCScheduler)
SRV - [2007.08.03 14:59:24 | 000,012,696 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Programme\National Instruments\MAX\nimxs.exe -- (mxssvr)
SRV - [2007.07.19 17:38:16 | 000,048,704 | ---- | M] (National Instruments Corp.) [Auto | Running] -- C:\Windows\System32\nisvcloc.exe -- (niSvcLoc)
SRV - [2007.05.09 16:34:34 | 000,098,304 | ---- | M] (OPC Foundation) [On_Demand | Stopped] -- C:\Windows\System32\Opcenum.exe -- (OpcEnum)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\4F76.tmp -- (MEMSWEEP2)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012.07.03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.07.03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.07.03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.07.03 18:21:53 | 000,057,656 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012.07.03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.07.03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009.06.18 12:55:41 | 000,018,816 | ---- | M] (Sophos Plc) [Kernel | System | Running] -- C:\Windows\System32\SAVRKBootTasks.sys -- (SAVRKBootTasks)
DRV - [2008.05.27 13:55:54 | 000,173,576 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ahcix86s.sys -- (ahcix86s)
DRV - [2008.05.02 13:59:40 | 000,122,368 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008.04.03 14:58:46 | 000,076,688 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID)
DRV - [2008.03.19 19:30:00 | 007,438,432 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007.10.26 14:27:00 | 000,306,300 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2007.10.23 11:00:00 | 000,004,096 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [2007.09.11 16:43:16 | 000,048,296 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\aksifdh.sys -- (AKSIFDH)
DRV - [2007.09.11 16:43:16 | 000,034,472 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\aksup.sys -- (AKSUP)
DRV - [2007.09.11 16:43:16 | 000,012,456 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\eTSCFLT.sys -- (eTSCFLT)
DRV - [2007.07.19 12:56:44 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NiViPxiKl.sys -- (NiViPxiK)
DRV - [2007.07.19 12:56:44 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NiViPciKl.sys -- (NiViPciK)
DRV - [2007.07.19 12:48:36 | 000,011,384 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NiViFWKl.sys -- (NiViFWK)
DRV - [2007.07.18 22:12:02 | 000,011,896 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nipalusbedl.sys -- (nipalusbedl)
DRV - [2007.07.18 22:11:38 | 000,580,184 | ---- | M] (National Instruments Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nipalk.sys -- (NIPALK)
DRV - [2007.07.18 22:11:02 | 000,011,904 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nipalfwedl.sys -- (nipalfwedl)
DRV - [2007.07.12 19:18:14 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nidimkl.sys -- (nidimk)
DRV - [2007.07.12 18:31:08 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\niorbkl.sys -- (niorbk)
DRV - [2007.07.10 21:08:14 | 000,015,448 | ---- | M] (National Instruments Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nipbcfk.sys -- (nipbcfk)
DRV - [2007.01.31 13:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2007.01.18 16:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FUJC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.gmx.net/br/ie9_startpage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.gmx.net/br/ie9_startpage
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81fae9c9-cfbd-4cb3-8322-412e72f55f65} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{09038620-190C-402B-A92F-18864E6AB22F}: "URL" = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
IE - HKCU\..\SearchScopes\{40064957-18EB-412d-9146-3F57E8D92EEC}: "URL" = hxxp://go.gmx.net/br/ie9_search_pic/?su={searchTerms}
IE - HKCU\..\SearchScopes\{5A817CF6-92D5-4DE5-AC38-82DF8A73EF28}: "URL" = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FUJC
IE - HKCU\..\SearchScopes\{6A3BAADF-623E-4EBF-AFED-45178AA1808B}: "URL" = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
IE - HKCU\..\SearchScopes\{6B1D1FB7-7233-4F7C-802C-21A1DDB12754}: "URL" = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
IE - HKCU\..\SearchScopes\{8D27B32E-89EE-460e-82D2-5FC354078EAD}: "URL" = hxxp://go.gmx.net/br/ie9_search_produkte/?su={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQFPC8pHI&i=26
IE - HKCU\..\SearchScopes\{DCE59F23-A446-45a5-9459-E68FDC0DE38D}: "URL" = hxxp://go.gmx.net/br/ie9_search_maps/?su={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..CT3228856.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "FreemakeVideoConverterTB Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT3228856&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3228856&SearchSource=2&q="


FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\melfluga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012.07.28 19:12:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.08.05 17:40:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.08.07 19:25:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010.08.06 16:25:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Extensions
[2012.08.07 14:34:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions
[2011.05.14 11:50:17 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.07.06 11:59:21 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.08.07 14:34:07 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\5cgy6pvp.FHB2FHBRech\extensions\ffxtlbr@incredibar.com
[2012.08.07 19:23:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions
[2010.09.22 12:26:30 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.05.19 16:05:05 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.07.25 16:33:54 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.07.28 19:12:06 | 000,000,000 | ---D | M] (FreemakeVideoConverterTB) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\{81fae9c9-cfbd-4cb3-8322-412e72f55f65}
[2012.08.07 14:34:06 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\ffxtlbr@incredibar.com
[2011.05.29 20:04:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\melfluga\AppData\Roaming\mozilla\Firefox\Profiles\i0z660ph.default\extensions\nostmp
[2012.08.07 19:26:22 | 000,000,853 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\11-suche.xml
[2012.08.07 15:11:47 | 000,000,941 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\conduit.xml
[2012.08.07 19:26:23 | 000,002,209 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\englische-ergebnisse.xml
[2012.08.07 19:26:22 | 000,010,506 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\gmx-suche.xml
[2012.08.03 13:43:38 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-1.xml
[2011.08.27 14:49:23 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-10.xml
[2011.10.03 16:22:22 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-11.xml
[2011.11.27 16:02:00 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-12.xml
[2011.12.06 14:27:00 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-13.xml
[2012.01.08 15:16:47 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-14.xml
[2012.01.15 20:15:03 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-15.xml
[2012.07.29 12:19:26 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-16.xml
[2010.10.25 13:18:17 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-2.xml
[2010.10.30 16:59:02 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-3.xml
[2010.12.26 15:53:00 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-4.xml
[2010.12.29 21:21:33 | 000,000,656 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-5.xml
[2011.05.10 12:57:30 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-6.xml
[2011.05.29 20:04:49 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-7.xml
[2011.07.06 11:59:25 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-8.xml
[2011.08.21 11:30:33 | 000,000,950 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin-9.xml
[2012.07.24 14:48:30 | 000,000,168 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin.gif
[2012.07.24 14:48:30 | 000,000,618 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin.src
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\icqplugin.xml
[2012.08.07 19:26:22 | 000,002,368 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\lastminute.xml
[2012.08.07 14:33:44 | 000,002,203 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\MyStart Search.xml
[2012.08.07 19:26:22 | 000,005,489 | ---- | M] () -- C:\Users\melfluga\AppData\Roaming\Mozilla\Firefox\Profiles\i0z660ph.default\searchplugins\webde-suche.xml
[2012.08.07 19:25:45 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.08.05 17:40:44 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012.07.28 19:12:19 | 000,000,000 | ---D | M] (Freemake Video Converter Plugin) -- C:\PROGRAM FILES\FREEMAKE\FREEMAKE VIDEO CONVERTER\BROWSERPLUGIN\FIREFOX
[2012.08.07 15:10:31 | 000,503,717 | ---- | M] () (No name found) -- C:\USERS\MELFLUGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I0Z660PH.DEFAULT\EXTENSIONS\TOOLBAR@GMX.NET.XPI
[2012.07.14 02:15:45 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.14 02:45:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

========== Chrome ==========

CHR - homepage: hxxp://www.google.com
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: hxxp://www.google.com
CHR - Extension: No name found = C:\Users\melfluga\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: No name found = C:\Users\melfluga\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\

O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {81FAE9C9-CFBD-4CB3-8322-412E72F55F65} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [eTMonitor] C:\Programme\Common Files\Aladdin Shared\eToken\PKIClient\x32\PKIMonitor.exe (Aladdin Knowledge Systems, Ltd.)
O4 - HKLM..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe ( )
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" File not found
O4 - HKLM..\Run: [Norman ZANDA] C:\Program Files\Norman\Npm\Bin\ZLH.EXE (Norman ASA)
O4 - HKLM..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe /LOAD File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PhilipsDM\SA1916] C:\Program Files\Philips\SA19XX\Philips Device Manager\Bin\LaunchDM.exe (Koninklijke Philips Electronics N.V.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [fsc-reg] C:\fsc-reg\fscreg.exe (Fujitsu Siemens)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [laxzyldodalp] C:\Users\melfluga\laxzyldodalp.exe File not found
O4 - HKCU..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - Startup: C:\Users\melfluga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\melfluga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} hxxp://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9BFF10D2-C0C5-46F9-B7AE-A76B17ED3CE4}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper2_white.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper2_white.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012.08.07 19:25:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.08.07 19:25:46 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.08.07 19:23:45 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\Talkback
[2012.08.07 19:22:41 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.08.07 19:06:40 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{C3FD24A1-70CA-43A4-B931-24BAA9D74587}
[2012.08.07 19:06:18 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{0219835C-8191-4F1C-B576-AC28498C549B}
[2012.08.07 18:54:19 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{D4D91617-CC77-48E7-BDE9-55BD21E2B671}
[2012.08.07 18:45:13 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{470EA7CE-CE90-40FA-9AC7-4381CE90692A}
[2012.08.07 18:38:57 | 000,018,816 | ---- | C] (Sophos Plc) -- C:\Windows\System32\SAVRKBootTasks.sys
[2012.08.07 17:38:09 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{A84E662F-0A30-4F2F-83DB-B8542B056F0C}
[2012.08.07 17:37:49 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{BA49D768-26AF-475A-B96A-B5E095820786}
[2012.08.07 15:22:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2012.08.07 15:22:54 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2012.08.07 14:35:37 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\vlc
[2012.08.07 14:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.08.07 14:35:01 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012.08.07 14:20:33 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\Malwarebytes
[2012.08.07 14:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.08.07 14:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.08.07 14:20:20 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.08.07 14:20:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.08.07 13:54:07 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{CD215D49-3F62-4D9F-9627-FDF2E16EF6A9}
[2012.08.05 18:07:56 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2012.08.05 17:41:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.08.05 17:41:41 | 000,353,688 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.08.05 17:41:41 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.08.05 17:41:37 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012.08.05 17:41:36 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.08.05 17:41:34 | 000,721,000 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.08.05 17:41:32 | 000,057,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.08.05 17:40:34 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.08.05 17:40:33 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012.08.05 17:40:08 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.08.05 17:40:08 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.08.03 19:22:48 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012.07.29 19:57:07 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder634791886270979735
[2012.07.29 19:49:54 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder634791881947009735
[2012.07.29 19:36:12 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder634791873723459735
[2012.07.28 23:11:43 | 000,000,000 | -H-D | C] -- C:\Users\melfluga\Documents\Freemake_do_not_remove_this_folder
[2012.07.28 19:12:37 | 000,000,000 | ---D | C] -- C:\Users\melfluga\Documents\Freemake
[2012.07.28 19:12:20 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2012.07.28 19:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
[2012.07.28 19:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2012.07.28 19:12:06 | 000,000,000 | ---D | C] -- C:\Program Files\Freemake
[2012.07.28 19:11:51 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2012.07.28 19:11:47 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\Conduit
[2012.07.15 14:12:42 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{8EBB47B6-7D46-488A-85AF-D4CCC1B94684}
[2012.07.09 21:13:40 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{F8668D41-5714-42E7-B781-AE2B3760ABCC}
[2012.07.09 21:12:58 | 000,000,000 | ---D | C] -- C:\Users\melfluga\AppData\Local\{FCFC65F7-4953-4E8A-B0CD-3698DF1290D6}
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012.08.07 20:20:57 | 000,000,000 | ---- | M] () -- C:\Users\melfluga\defogger_reenable
[2012.08.07 19:25:48 | 000,000,852 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.08.07 18:48:42 | 000,634,440 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.08.07 18:48:41 | 000,674,582 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.08.07 18:48:41 | 000,146,266 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.08.07 18:48:41 | 000,120,004 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.08.07 18:43:24 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.07 18:43:24 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.07 18:43:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.07 18:42:07 | 3488,866,304 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.07 14:35:27 | 000,000,865 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.08.07 14:34:07 | 000,000,454 | ---- | M] () -- C:\user.js
[2012.08.07 14:20:22 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.08.05 17:41:42 | 000,001,835 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.08.05 17:41:32 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012.07.28 19:23:23 | 000,005,632 | ---- | M] () -- C:\Users\melfluga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.28 19:12:19 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012.07.28 19:12:09 | 000,000,009 | ---- | M] () -- C:\END
[2012.07.28 18:15:48 | 000,000,085 | -HS- | M] () -- C:\ProgramData\.zreglib
[2012.07.25 10:21:09 | 000,316,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.08.07 20:20:57 | 000,000,000 | ---- | C] () -- C:\Users\melfluga\defogger_reenable
[2012.08.07 19:25:48 | 000,000,864 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.08.07 19:22:43 | 000,000,852 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.08.07 14:35:27 | 000,000,865 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.08.07 14:34:06 | 000,000,454 | ---- | C] () -- C:\user.js
[2012.08.07 14:20:22 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.08.05 17:41:42 | 000,001,835 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.07.28 19:12:19 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012.07.28 19:12:08 | 000,000,009 | ---- | C] () -- C:\END
[2012.06.24 13:26:33 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2012.01.14 12:00:37 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{7cdd0fcc-31ef-f3c4-073f-a1dbf674cc1d}\@
[2012.01.14 12:00:37 | 000,002,048 | -HS- | C] () -- C:\Users\melfluga\AppData\Local\{7cdd0fcc-31ef-f3c4-073f-a1dbf674cc1d}\@
[2010.12.21 13:03:16 | 000,000,680 | ---- | C] () -- C:\Users\melfluga\AppData\Local\d3d9caps.dat
[2008.10.20 12:04:18 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008.10.04 13:39:27 | 000,000,096 | ---- | C] () -- C:\Users\melfluga\AppData\Local\fusioncache.dat
[2008.09.28 13:19:59 | 000,005,632 | ---- | C] () -- C:\Users\melfluga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2012.02.27 15:50:17 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\1&1 Mail & Media GmbH
[2012.05.29 13:10:38 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\elsterformular
[2009.05.24 13:07:45 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\EPSON
[2010.12.31 15:42:41 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\FileZilla
[2012.08.07 18:45:26 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\ICQ
[2009.04.13 12:56:05 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\OpenOffice.org
[2008.10.04 13:35:43 | 000,000,000 | ---D | M] -- C:\Users\melfluga\AppData\Roaming\T-Online
[2012.08.07 18:39:24 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Alt 11.08.2012, 22:23   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast! - Standard

win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!



Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.
__________________

__________________

Antwort

Themen zu win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!
adobe, antivirus, avast, bho, desktop, error, explorer, firefox, format, frage, home, mozilla, national, norman, nvidia, origin, pdf, picasa, plug-in, problem, programme, realtek, registry, scan, security, senden, software, vista, win64




Ähnliche Themen: win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!


  1. Windows 7: Befall von mehreren Trojanern/Viren -Win64/Conedex.B + C + I, Win64/Sirefef.AZ+BJ
    Log-Analyse und Auswertung - 15.02.2014 (86)
  2. Trojan:Win32/Sirefef.AB und Trojan:Win64/Sirefef.P entfernen!
    Log-Analyse und Auswertung - 10.12.2013 (22)
  3. Trojan:Win32/Sirefef.AB und Trojan:Win64/Sirefef.P entfernen!
    Log-Analyse und Auswertung - 02.08.2013 (14)
  4. Win64/Sirefef.AB, W, !cfg, AE
    Plagegeister aller Art und deren Bekämpfung - 23.02.2013 (1)
  5. Win64/Patched.A und Luhe.Sirefef.A gefunden
    Log-Analyse und Auswertung - 21.01.2013 (5)
  6. Win64:Sirefef-A [Trj]
    Plagegeister aller Art und deren Bekämpfung - 20.01.2013 (38)
  7. Trojaner eingefangen - Sirefef-A/Sirefef-AHF/BitCoinMiner-U/Malware-gen
    Log-Analyse und Auswertung - 31.08.2012 (27)
  8. Win64/Sirefef.w - Sirefef.ab und Sirefef.M eingefangen
    Plagegeister aller Art und deren Bekämpfung - 14.08.2012 (29)
  9. Virus/Trojaner: Win64/sirefef.A ; Win64/sirefef.AB ; Win64/sirefef.W ; Auto-Neustart nach 1 Minute
    Plagegeister aller Art und deren Bekämpfung - 13.08.2012 (18)
  10. sirefef.ah und sirefef.r auf Win7 (32bit) gefunden. Rechner fährt automatisch runter.
    Plagegeister aller Art und deren Bekämpfung - 06.08.2012 (37)
  11. Win64/Sirefef.AE Trojaner Win64/Agent.BA TrojanerC:\Windows\Installer\{f041020c-58e9-a705-4143-4ddcc
    Plagegeister aller Art und deren Bekämpfung - 25.07.2012 (7)
  12. Virusbefall (Trojan.Generic, Trojan.Sirefef, Win64.Sirefef, Win32.Atraps) bei windows installer & Co
    Plagegeister aller Art und deren Bekämpfung - 23.07.2012 (19)
  13. Win64:Sirefef-A (Trj) und Win32:Sirefef-AO (Rtk) eingefangen
    Log-Analyse und Auswertung - 10.06.2012 (14)
  14. Trojan:Win64/Sirefef.K + .../Sirefef.D + .../Sirefef.E
    Log-Analyse und Auswertung - 13.01.2012 (15)
  15. Trojan:Win64/Sirefef.K, Sirefef.E und Sirefef.D kommen immer wieder
    Plagegeister aller Art und deren Bekämpfung - 04.01.2012 (1)
  16. Win64/Sirefef.D / E / K
    Plagegeister aller Art und deren Bekämpfung - 03.01.2012 (2)
  17. Trojan:Win64/Sirefef.K & Sirefef.D & Sirefef.E
    Log-Analyse und Auswertung - 02.01.2012 (6)

Zum Thema win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast! - Hallo Zusammen, ich bin neu hier, also erstmal einen Gruß in die Runde. Und schon muss ich Euch mit einem Problem belästigen. Bin nicht der Held in diesen Dingen, also - win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast!...
Archiv
Du betrachtest: win 32:Sirefef-AO und Malware.gen, win64:Sirefef-A gefunden von avast! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.