24.08.2012, 22:21
|
#7 |
| | Win32: Sirefef-AHF [Trj] und Win32: Malware-gen in C:\Windows\System32\services.exe Windows 7 64bit Mhhh, alles getan
Log von AdwCleaner: Zitat:
# AdwCleaner v1.801 - Logfile created 08/24/2012 at 20:40:49
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (64 bits)
# User : Stephie - STEIN
# Boot Mode : Normal
# Running from : C:\Users\Stephie\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Users\Stephie\AppData\Local\OpenCandy
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Stephie\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\Profiles\mtcnqs2u.default\Conduit
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\Program Files (x86)\DAEMON Tools Toolbar
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\afurladvisor@anchorfree.com
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\quickstores@quickstores.de
Folder Deleted : C:\Windows\assembly\GAC_MSIL\QuickStoresToolbar
File Deleted : C:\Users\Stephie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QuickStores.url
File Deleted : C:\Users\Stephie\AppData\Roaming\Microsoft\Windows\Start Menu\QuickStores.url
File Deleted : C:\Users\Public\Desktop\Get The Best Facebook Chat Messenger.lnk
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\Softonic
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.7601.17514
[OK] Registry is clean.
-\\ Mozilla Firefox v5.0 (de)
Profile name : default
File : C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\Profiles\mtcnqs2u.default\prefs.js
C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\Profiles\mtcnqs2u.default\user.js ... Deleted !
Deleted : user_pref("aol_toolbar.surf.date", "41");
Deleted : user_pref("aol_toolbar.surf.lastDate", "31");
Deleted : user_pref("aol_toolbar.surf.lastMonth", "9");
Deleted : user_pref("aol_toolbar.surf.lastYear", "2011");
Deleted : user_pref("aol_toolbar.surf.month", "196");
Deleted : user_pref("aol_toolbar.surf.prevMonth", "32");
Deleted : user_pref("aol_toolbar.surf.total", "18155");
Deleted : user_pref("aol_toolbar.surf.week", "41");
Deleted : user_pref("aol_toolbar.surf.year", "18073");
-\\ Opera v11.64.1403.0
File : C:\Users\Stephie\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [4329 octets] - [24/08/2012 19:36:25]
AdwCleaner[S1].txt - [3634 octets] - [24/08/2012 20:40:49]
########## EOF - C:\AdwCleaner[S1].txt - [3762 octets] ##########
| Und noch von Emsisoft Anti-Malware Zitat:
Emsisoft Anti-Malware - Version 6.6
Letztes Update: 24.08.2012 20:47:49
Scan Einstellungen:
Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\
Archiv Scan: An
ADS Scan: An
Scan Beginn: 24.08.2012 20:48:01
Key: hkey_local_machine\software\trymedia systems gefunden: Trace.Registry.trymedia!E1
Key: hkey_local_machine\software\trymedia systems\activemark software gefunden: Trace.Registry.trymedia!E1
C:\_OTL\MovedFiles\08242012_100029\C_Windows\Installer\{3c89fd90-a438-6635-af2f-36e132e1456f}\U\80000064.@ gefunden: Trojan.Win64!E2
C:\Windows\Installer\{3c89fd90-a438-6635-af2f-36e132e1456f}\U\80000064.@ gefunden: Trojan.Win64!E2
C:\Windows\Installer\{3c89fd90-a438-6635-af2f-36e132e1456f}\U\80000000.@ gefunden: Backdoor.Win64.AMN!E1
C:\Windows\Installer\{3c89fd90-a438-6635-af2f-36e132e1456f}\U\trzF761.tmp gefunden: Trojan.Win64.Sirefef.AMN!E1
C:\Windows\Installer\{3c89fd90-a438-6635-af2f-36e132e1456f}\U\00000004.@ gefunden: Trojan.Win64.Sirefef.AMN!E1
C:\Windows\assembly\GAC_64\Desktop.ini gefunden: Trojan.Win64!E2
C:\Windows\assembly\GAC_32\Desktop.ini gefunden: Trojan.Win32.Sirefef!E2
D:\Games\LA Noire\SKIDROW\LANoire.exe gefunden: Trojan.Crypt!E2
Gescannt 774093
Gefunden 10
Scan Ende: 24.08.2012 23:18:22
Scan Zeit: 2:30:21
[/B]
| |