![]() |
|
Plagegeister aller Art und deren Bekämpfung: GVU Fragezeichen?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() GVU Fragezeichen? Guten Abend. Ich habe folgendes Problem. Seit heute öffnet sich ein Fenster nach dem Booten dass ich auf herkömmlicherweise nicht schließen kann. Ähnlich wie beim GVU. Man kann allerdings über den Taskmanager die betroffene exe beenden (cvaetzwc.exe) und somit das Fenster schließen. Zu Beginn war auch noch die vom GVU bekannte wpbt0.dll im Manager, aber die ist irgendwie verschwunden. Ich seh auch im Process Explorer welcher Prozess dieses Fenster startet. Ich hab nun Malwarebytes durchlaufenlassen und die cvaetzwc.exe gefunden sowie eine Abwandlung von ihr in der Reg, als auch die wpbt0.dll Ich hab nur keinen Plan was ich machen soll... Malwarebytes Anti-Malware 1.70.0.1100 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.03.09.07 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 09.03.2013 16:06:11 mbam-log-2013-03-09 (16-06-11).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 445557 Laufzeit: 44 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|cvaetzwcgsogagn (Trojan.EOFail) -> Daten: C:\ProgramData\cvaetzwc.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 5 C:\ProgramData\cvaetzwc.exe (Trojan.EOFail) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\geraldo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HG1417VS\Prv[1].bin (Trojan.EOFail) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\geraldo\AppData\Local\Temp\wpbt0.dll (Trojan.EOFail) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
![]() | #2 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen?![]() Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
So geht es weiter: Schritt 1 Downloade dir bitte DDS ( von sUBs ) von einem der folgenden Downloadspiegel und speichere die Datei auf deinem Desktop. dds.com dds.exe
Schritt 2 Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Schritt 3 Bitte lade dir ![]()
![]()
Bitte poste mit deiner nächsten Antwort
|
![]() | #3 |
![]() ![]() | ![]() GVU Fragezeichen? OK, hab jetzt alles gemacht. Nur ein Problem: Ich konnte die Logdatei von GMER nicht so speichern wie beschrieben. Also auf Save klicken hat nichts bewirkt obwohl ich alles befolgt habe, habs auch im Abgesicherten Modus versucht, schlussendlich habe ich Copy und dann in ein Wordpad gespeichert, hoffentlich kommt das aufs selbe...
__________________DDS DDS Logfile: Code:
ATTFilter DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.10.2 Run at 14:06:06 on 2013-03-10 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8105.6819 [GMT 1:00] . AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF} AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe C:\Program Files\Common Files\WireHelpSvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxpers.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\rundll32.exe C:\Program Files (x86)\XFastUsb\XFastUsb.exe C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe C:\Program Files (x86)\A1\A1 Diagnose\A1Diagnose.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/?affID=113480&babsrc=HP_ss&mntrId=fe956921000000000000002522c22eef uURLSearchHooks: SearchHook Class: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll mWinlogon: Userinit = userinit.exe BHO: SmartView VisualBookmark: {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\DeviceVM\SmartView\SmartView.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ips\ipsbho.dll BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll uRun: [ASRockXTU] <no file> mRun: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe /StartRunKey mRun: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r mRun: [UpdReg] C:\Windows\UpdReg.EXE mRun: [SmartViewAgent] "C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml mRun: [A1Diagnose] C:\Program Files (x86)\A1\A1 Diagnose\A1Diagnose.exe /auto mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" StartupFolder: C:\Users\geraldo\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: NameServer = 10.0.0.138 TCP: Interfaces\{22BED806-6C8D-45B6-97C9-D8B6C312695D} : DHCPNameServer = 10.0.0.138 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SSODL: WebCheck - <orphaned> IFEO: taskmgr.exe - "C:\USERS\GERALDO\APPDATA\LOCAL\TEMP\RAR$EXA0.997\PROCEXP.EXE" x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - <orphaned> x64-IFEO: taskmgr.exe - "C:\USERS\GERALDO\APPDATA\LOCAL\TEMP\RAR$EXA0.997\PROCEXP.EXE" . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\ FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-02-24 11:38; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF - ExtSQL: 2013-02-24 11:38; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn FF - ExtSQL: 2013-02-24 13:25; exif_viewer@mozilla.doslash.org; C:\Users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1207020.003\symds64.sys [2012-7-9 450680] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1207020.003\symefa64.sys [2012-7-9 912504] R1 AsrAppCharger;AsrAppCharger;C:\Windows\System32\drivers\AsrAppCharger.sys [2012-7-6 15368] R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2012-10-11 27800] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120823.007\BHDrvx64.sys [2012-9-1 1161376] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-12-2 283200] R1 FNETURPX;FNETURPX;C:\Windows\System32\drivers\FNETURPX.SYS [2012-7-6 15936] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120831.001\IDSviA64.sys [2012-9-1 512672] R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1207020.003\ironx64.sys [2012-7-9 171128] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1207020.003\symnets.sys [2012-7-9 386168] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-6-11 239616] R2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-10-11 86752] R2 AntiVirService;Avira Echtzeit-Scanner;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-10-11 110816] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2012-10-11 99912] R2 ESLWireAC;ESLWireAC;C:\Windows\System32\drivers\ESLWireACD.sys [2012-7-6 147472] R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2012-9-5 6364024] R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe [2012-7-9 130008] R2 SmartViewService;SmartView service;C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [2010-9-2 125216] R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-6 2656280] R2 WCUService;SmartView Software Updater Service;C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [2010-9-2 456976] R2 WireHelpSvc;WireHelpSvc;C:\Program Files\Common Files\WireHelpSvc.exe [2012-7-6 168864] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-2-23 95760] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-17 138912] R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2011-2-8 39936] R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2011-2-8 64512] R3 gbxavs;Maschine Midi;C:\Windows\System32\drivers\gbxavs.sys [2011-7-7 357968] R3 gbxusb_svc;Maschine Controller;C:\Windows\System32\drivers\gbxusb.sys [2011-7-7 68688] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-7-6 428136] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2012-7-6 79360] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-7-6 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-7-6 79360] S3 FNETTBOH_305;FNETTBOH_305;C:\Windows\System32\drivers\FNETTBOH_305.SYS [2012-7-21 31808] S3 gbxavs_x64;gbxavs_x64;C:\Windows\System32\drivers\gbxavs_x64.sys [2009-10-8 45136] S3 gbxusb_x64;gbxusb_x64;C:\Windows\System32\drivers\gbxusb_x64.sys [2009-10-8 300624] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] . =============== Created Last 30 ================ . 2013-03-09 15:04:23 344576 ----a-w- C:\Windows\System32\utilman.exe 2013-03-09 13:29:21 -------- d-----w- C:\ProgramData\Astroburn Lite 2013-03-09 13:29:21 -------- d-----w- C:\Program Files (x86)\Astroburn Lite 2013-03-09 11:08:51 -------- d-----w- C:\Users\geraldo\AppData\Roaming\Malwarebytes 2013-03-09 11:08:43 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys 2013-03-09 11:08:43 -------- d-----w- C:\ProgramData\Malwarebytes 2013-03-09 11:08:42 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-03-09 11:08:34 -------- d-----w- C:\Users\geraldo\AppData\Local\Programs 2013-03-08 23:06:50 -------- d-----w- C:\ProgramData\hikwhymogrxznoo 2013-02-24 12:51:54 -------- d-----w- C:\Users\geraldo\AppData\Local\Macromedia 2013-02-24 12:24:57 -------- d-----w- C:\Users\geraldo\AppData\Local\Mozilla 2013-02-24 12:23:03 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service 2013-02-17 12:52:30 -------- d-----w- C:\Users\geraldo\AppData\Local\Apple Computer 2013-02-17 12:52:00 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2013-02-17 12:51:32 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-17 12:51:32 -------- d-----w- C:\Program Files\iTunes 2013-02-17 12:51:32 -------- d-----w- C:\Program Files\iPod 2013-02-17 12:51:32 -------- d-----w- C:\Program Files (x86)\iTunes 2013-02-17 12:46:41 -------- d-----w- C:\Users\geraldo\AppData\Local\Apple 2013-02-17 12:46:19 -------- d-----w- C:\Program Files\Bonjour 2013-02-17 12:46:19 -------- d-----w- C:\Program Files (x86)\Bonjour . ==================== Find3M ==================== . 2013-01-03 13:59:24 95184 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-03 13:59:24 859072 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-01-03 13:59:24 779704 ----a-w- C:\Windows\SysWow64\deployJava1.dll 2013-01-03 13:56:50 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll 2013-01-03 13:56:49 959976 ----a-w- C:\Windows\System32\deployJava1.dll 2013-01-03 13:56:49 1081320 ----a-w- C:\Windows\System32\npDeployJava1.dll 2012-12-11 18:27:30 99912 ----a-w- C:\Windows\System32\drivers\avgntflt.sys 2012-07-03 14:41:12 168864 ----a-w- C:\Program Files\Common Files\WireHelpSvc.exe . ============= FINISH: 14:06:19,52 =============== defogger_disable.log Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 14:15 on 10/03/2013 (geraldo) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- GMER Logfile: Code:
ATTFilter GMER 2.1.19155 - hxxp://www.gmer.net Rootkit scan 2013-03-10 14:52:04 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 WDC_WD5000AAKX-001CA0 rev.15.01H15 465,76GB Running: b6j43ent.exe; Driver: C:\Users\geraldo\AppData\Local\Temp\pwtirfow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82 00000000737b17fa 2 bytes CALL 773a1199 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88 00000000737b1860 2 bytes CALL 773a1199 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98 00000000737b1942 2 bytes JMP 7720c29f C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109 00000000737b194d 2 bytes JMP 7720418d C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077cd1401 2 bytes JMP 773beb26 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077cd1419 2 bytes JMP 773cb513 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077cd1431 2 bytes JMP 77448609 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000077cd144a 2 bytes CALL 773a1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000077cd14dd 2 bytes JMP 77447efe C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000077cd14f5 2 bytes JMP 774480d8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000077cd150d 2 bytes JMP 77447df4 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077cd1525 2 bytes JMP 774481c2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000077cd153d 2 bytes JMP 773bf088 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077cd1555 2 bytes JMP 773cb885 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000077cd156d 2 bytes JMP 774486c1 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077cd1585 2 bytes JMP 77448222 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000077cd159d 2 bytes JMP 77447db8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000077cd15b5 2 bytes JMP 773bf121 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000077cd15cd 2 bytes JMP 773cb29f C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000077cd16b2 2 bytes JMP 77448584 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000077cd16bd 2 bytes JMP 77447d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?CreateDifferenceFile@CC2CDifferenceFile@@UAEGPAD00@Z 00000000667236bd 5 bytes JMP 0000000101c900b0 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?RestoreOriginalFile@CC2CDifferenceFile@@UAEGPAD00@Z 0000000066723e40 5 bytes JMP 0000000101c90150 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?MakeAsciiDifferenceFile@CC2CDifferenceFile@@UAEGPAD0@Z 00000000667243c1 5 bytes JMP 0000000101c90100 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?LoadJumpDbFromBuffer@CJumpRun@@UAEGKPAE@Z 000000006672a952 5 bytes JMP 0000000101c903c0 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?LoadJumpDbFromBuffer@CJumpRun@@UAEGKPAE@Z + 126 000000006672a9d0 13 bytes [2A, 9D, FF, 95, 2E, C4, 1E, ...] .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?GetKeyData@CKeyBasic@@UAEGPAE@Z 000000006672e35f 5 bytes JMP 0000000101c90630 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformXor@@UAEGVCDataArea@@0@Z 000000006672ea2f 5 bytes JMP 0000000101c8f970 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformXor@@UAEGVCDataArea@@0@Z + 768 000000006672ed2f 15 bytes [90, 6A, 23, E7, 76, 50, 88, ...] .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformRandomAccumulate@@UAEGVCDataArea@@0@Z 000000006672ee42 5 bytes JMP 0000000101c8f700 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformRandomAccumulate@@UAEGVCDataArea@@0@Z + 850 000000006672f194 5 bytes JMP 0000000101c8a050 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?LoadModuleDetails@CModuleMonitor@@QAEGPAD@Z 0000000066733ce7 5 bytes JMP 0000000101c8f220 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?ScanModule@CModuleMonitor@@QAEGKG@Z 00000000667342f0 5 bytes JMP 0000000101c8f490 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?IsModuleChecksumOkay@CModuleMonitor@@QAEGXZ 0000000066734a23 5 bytes JMP 0000000101c90b10 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?IsModuleWithinLimits@CModuleMonitor@@QAEGKKK@Z 0000000066734a59 5 bytes JMP 0000000101c90da0 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?SetupInterruptHandler@CAltAsc@@QAEGPAX00PAK1@Z 00000000667590d5 5 bytes JMP 0000000101c90010 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?RestoreInterruptHandler@CAltAsc@@QAEGXZ 0000000066759569 5 bytes JMP 0000000101c91300 .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077cd1401 2 bytes JMP 773beb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077cd1419 2 bytes JMP 773cb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077cd1431 2 bytes JMP 77448609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000077cd144a 2 bytes CALL 773a1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000077cd14dd 2 bytes JMP 77447efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000077cd14f5 2 bytes JMP 774480d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000077cd150d 2 bytes JMP 77447df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077cd1525 2 bytes JMP 774481c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000077cd153d 2 bytes JMP 773bf088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077cd1555 2 bytes JMP 773cb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000077cd156d 2 bytes JMP 774486c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077cd1585 2 bytes JMP 77448222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000077cd159d 2 bytes JMP 77447db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000077cd15b5 2 bytes JMP 773bf121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000077cd15cd 2 bytes JMP 773cb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000077cd16b2 2 bytes JMP 77448584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000077cd16bd 2 bytes JMP 77447d4d C:\Windows\syswow64\kernel32.dll ? C:\Windows\system32\mssprxy.dll [2608] entry point in ".rdata" section 0000000071cc71e6 ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2288:4828] 000007fefc322a74 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2288:4836] 000007feeeee7cc0 ---- EOF - GMER 2.1 ----v Geändert von HeAdAche (10.03.2013 um 15:31 Uhr) |
![]() | #4 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen? Servus, Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Scan mit Combofix
Bitte poste mit deiner nächsten Antwort
|
![]() | #5 |
![]() ![]() | ![]() GVU Fragezeichen? Hey Matthias! Also, hab jetzt alles durchführen können. Ging auch recht zügig. Zwei Dinge die aufgefallen sind. Bei dem Combofix hat er zwei mal angeschlagen dass Avira läuft, wobei ich es eigentlich geschlossen hatte. Und es gab keinen automatischen Reboot. Edit: Hab mich vertan, dachte bei Combo gibt es auch nen Reboot. ![]() AdwCleaner[1] AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.114 - Datei am 11/03/2013 um 17:33:32 erstellt # Aktualisiert am 05/03/2013 von Xplode # Betriebssystem : Windows 7 Ultimate (64 bits) # Benutzer : geraldo - GERALDO-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\geraldo\Desktop\trojan\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\user.js Gelöscht mit Neustart : C:\ProgramData\Babylon Gelöscht mit Neustart : C:\Users\geraldo\AppData\Local\Babylon Gelöscht mit Neustart : C:\Users\geraldo\AppData\Local\Temp\BabylonToolbar Gelöscht mit Neustart : C:\Users\geraldo\AppData\LocalLow\BabylonToolbar Gelöscht mit Neustart : C:\Users\geraldo\AppData\Roaming\Babylon Gelöscht mit Neustart : C:\Users\geraldo\AppData\Roaming\dvdvideosoftiehelpers ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7600.16385 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=113480&babsrc=HP_ss&mntrId=fe956921000000000000002522c22eef --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=113480&babsrc=NT_ss&mntrId=fe956921000000000000002522c22eef --> hxxp://www.google.com -\\ Mozilla Firefox v19.0.2 (de) Datei : C:\Users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\prefs.js [OK] Die Datei ist sauber. -\\ Opera v12.0.1467.0 Datei : C:\Users\geraldo\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [3589 octets] - [11/03/2013 17:33:32] ########## EOF - C:\AdwCleaner[S1].txt - [3649 octets] ########## [/CODE] JRT JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.6.9 (03.06.2013:1) OS: Windows 7 Ultimate x64 Ran by geraldo on 11.03.2013 at 17:39:22,87 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\babylon" ~~~ FireFox Emptied folder: C:\Users\geraldo\AppData\Roaming\mozilla\firefox\profiles\2igtq7nb.default\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.03.2013 at 17:43:58,46 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Combofix [CODE] Combofix Logfile: Code:
ATTFilter ComboFix 13-03-11.01 - geraldo 11.03.2013 17:49:29.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8105.6447 [GMT 1:00] ausgeführt von:: c:\users\geraldo\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\A1 c:\program files (x86)\A1\A1 Bandbreiten-Optimierer\A1_Bandbreiten_Optimierer.exe c:\program files (x86)\A1\A1 Breitband\A1Breitband.chm c:\program files (x86)\A1\A1 Breitband\A1Breitband.exe c:\program files (x86)\A1\A1 Breitband\Browser\FF_Setup.exe c:\program files (x86)\A1\A1 Breitband\inifiles.dat c:\program files (x86)\A1\A1 Breitband\ipworks6.dll c:\program files (x86)\A1\A1 Diagnose\A1CMDTool.exe c:\program files (x86)\A1\A1 Diagnose\A1Diagnose.exe c:\program files (x86)\A1\A1 Diagnose\A1Mailboxen.exe c:\program files (x86)\A1\A1 Diagnose\A1Modemkonfigurator.exe c:\program files (x86)\A1\A1 Diagnose\A1WLANAssistent.exe c:\program files (x86)\A1\A1 Diagnose\inifiles.dat c:\program files (x86)\A1\A1 Diagnose\ipworks6.dll c:\program files (x86)\A1\A1 Diagnose\KCO.exe c:\program files (x86)\A1\A1 Modemwechsel\A1Modemwechsel.chm c:\program files (x86)\A1\A1 Modemwechsel\A1Modemwechsel.exe c:\program files (x86)\A1\A1 Modemwechsel\inifiles.dat c:\program files (x86)\A1\A1 Modemwechsel\ipworks6.dll c:\program files (x86)\A1\A1 Servicecenter\A1Servicecenter.chm c:\program files (x86)\A1\A1 Servicecenter\A1Servicecenter.exe c:\program files (x86)\A1\A1 Servicecenter\Content\broadband.html c:\program files (x86)\A1\A1 Servicecenter\Content\cd_index.html c:\program files (x86)\A1\A1 Servicecenter\Content\fonts\a1ta_medium_web01-webfont.ttf c:\program files (x86)\A1\A1 Servicecenter\Content\fonts\a1ta_regular_web01-webfont.ttf c:\program files (x86)\A1\A1 Servicecenter\Content\img\01a_a1_breitband_200x300.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\01a_weitere_services.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\01a_wlan_einrichten.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02a_a1_breitband_installieren_200x366.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02a_modemkonfigurationssoftware.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02a_modemwechselsoftware.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_breitband_unterwegs.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_breitband_zuhause.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_hinzufuegen.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_installation.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_wiederherstellen.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\03_zusaetzliche_wlan_geraete.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\03_zusaetzliche_wlan_sicherheitseinstellungen.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\1x1_white_15.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\AdobeX_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\arrow_down_black.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\arrow_down_green.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\arrow_up_green.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\back.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_box_big.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_box_small.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_faq.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_faq_open.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_overlay.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_sliderButtonLeft.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_sliderButtonRight.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\btn_close.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\cd_intro.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\FF_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\footer_trenner.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\icon_info.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\IE_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_bl.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_br.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_tl.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_tr.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\intro.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_active_center.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_active_left.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_active_right.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow_back.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow_back_black.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow_black.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\loader.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo.jpg c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_chrome_150.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_chrome_48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_glas_48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_kabel_48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\mm_icon_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\productslider_next.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\productslider_prev.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_diagnose.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_diagnose_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_internet.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_internet_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_mail.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_mail_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_manuals.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_manuals_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_wlan.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_wlan_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_zusatzsoftware.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_zusatzsoftware_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\includes\main.css c:\program files (x86)\A1\A1 Servicecenter\Content\includes\main.js c:\program files (x86)\A1\A1 Servicecenter\Content\index.html c:\program files (x86)\A1\A1 Servicecenter\Content\manuals.html c:\program files (x86)\A1\A1 Servicecenter\Content\software.html c:\program files (x86)\A1\A1 Servicecenter\Content\wlan.html c:\program files (x86)\A1\A1 Servicecenter\icudt42.dll c:\program files (x86)\A1\A1 Servicecenter\libcef.dll c:\program files (x86)\A1\A1 Servicecenter\reqdata.cfg c:\program files (x86)\A1\A1 Servicecenter\Start.exe c:\program files (x86)\A1\A1 Servicecenter\Start.ini c:\program files (x86)\A1\A1 Update\M2Updater.exe c:\windows\SysWow64\tmp37C2.tmp c:\windows\SysWow64\tmp37D2.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-11 bis 2013-03-11 )))))))))))))))))))))))))))))) . . 2013-03-11 16:53 . 2013-03-11 16:53 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-11 16:39 . 2013-03-11 16:39 -------- d-----w- c:\windows\ERUNT 2013-03-11 16:39 . 2013-03-11 16:39 -------- d-----w- C:\JRT 2013-03-11 16:33 . 2013-03-11 16:33 400 ----a-w- c:\windows\DeleteOnReboot.bat 2013-03-09 15:04 . 2009-07-14 01:39 344576 ----a-w- c:\windows\system32\utilman.exe 2013-03-09 14:38 . 2013-03-09 14:39 -------- d-----w- c:\users\Administrator 2013-03-09 13:29 . 2013-03-09 13:29 -------- d-----w- c:\program files (x86)\Astroburn Lite 2013-03-09 13:29 . 2013-03-09 13:29 -------- d-----w- c:\programdata\Astroburn Lite 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\users\geraldo\AppData\Roaming\Malwarebytes 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\programdata\Malwarebytes 2013-03-09 11:08 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\users\geraldo\AppData\Local\Programs 2013-03-08 23:06 . 2013-03-08 23:07 -------- d-----w- c:\programdata\hikwhymogrxznoo 2013-02-24 12:51 . 2013-02-24 12:51 -------- d-----w- c:\users\geraldo\AppData\Local\Macromedia 2013-02-24 12:24 . 2013-02-24 12:24 -------- d-----w- c:\users\geraldo\AppData\Local\Mozilla 2013-02-24 12:23 . 2013-03-09 12:48 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2013-02-17 12:52 . 2013-02-17 12:58 -------- d-----w- c:\users\geraldo\AppData\Roaming\Apple Computer 2013-02-17 12:52 . 2013-02-17 12:52 -------- d-----w- c:\users\geraldo\AppData\Local\Apple Computer 2013-02-17 12:52 . 2013-02-17 12:52 -------- dc----w- c:\windows\system32\DRVSTORE 2013-02-17 12:52 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files\iTunes 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files (x86)\iTunes 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\programdata\Apple Computer 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files\iPod 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\users\geraldo\AppData\Local\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files (x86)\Apple Software Update 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files\Common Files\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files\Bonjour 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files (x86)\Bonjour 2013-02-17 12:46 . 2013-02-17 12:51 -------- d-----w- c:\program files (x86)\Common Files\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\programdata\Apple . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-03 13:59 . 2013-01-03 13:59 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-01-03 13:59 . 2013-01-03 13:59 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-03 13:59 . 2013-01-03 13:59 95184 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-03 13:56 . 2013-01-03 13:56 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-01-03 13:56 . 2013-01-03 13:56 308200 ----a-w- c:\windows\system32\javaws.exe 2013-01-03 13:56 . 2013-01-03 13:56 188392 ----a-w- c:\windows\system32\javaw.exe 2013-01-03 13:56 . 2013-01-03 13:56 188392 ----a-w- c:\windows\system32\java.exe 2013-01-03 13:56 . 2012-07-11 14:41 959976 ----a-w- c:\windows\system32\deployJava1.dll 2013-01-03 13:56 . 2012-07-11 14:41 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-12-11 18:27 . 2012-10-11 15:17 99912 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2012-12-11 18:27 . 2012-10-11 15:17 129216 ----a-w- c:\windows\system32\drivers\avipbb.sys 2012-07-03 14:41 . 2012-07-06 18:31 168864 ----a-w- c:\program files\Common Files\WireHelpSvc.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"= "c:\program files (x86)\DeviceVM\SmartView\AddressBarSearch.dll" [2010-09-02 162080] . [HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1] [HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-02-25 1602984] "ESL Wire"="c:\program files\EslWire\wire.exe" [2012-07-03 3890176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2012-07-06 4942336] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195] "VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "SmartViewAgent"="c:\program files (x86)\DeviceVM\SmartView\SmartViewAgent.exe" [2010-09-02 948504] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-02-07 385248] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [x] R3 gbxavs_x64;gbxavs_x64;c:\windows\system32\Drivers\gbxavs_x64.sys [x] R3 gbxusb_x64;gbxusb_x64;c:\windows\system32\Drivers\gbxusb_x64.sys [x] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1207020.003\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1207020.003\SYMEFA64.SYS [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120823.007\BHDrvx64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120831.001\IDSvia64.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [x] S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [x] S2 SmartViewService;SmartView service;c:\program files (x86)\DeviceVM\SmartView\SmartViewService.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 WCUService;SmartView Software Updater Service;c:\program files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [x] S2 WireHelpSvc;WireHelpSvc;c:\program files\Common Files\WireHelpSvc.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x] S3 gbxavs;Maschine Midi;c:\windows\system32\Drivers\gbxavs.sys [x] S3 gbxusb_svc;Maschine Controller;c:\windows\system32\Drivers\gbxusb.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-30 11660904] "RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube to MP3 Converter - c:\users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 10.0.0.138 FF - ProfilePath - c:\users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\ FF - ExtSQL: 2013-02-24 11:38; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF - ExtSQL: 2013-02-24 11:38; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn FF - ExtSQL: 2013-02-24 13:25; exif_viewer@mozilla.doslash.org; c:\users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-ASRockXTU - (no file) Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file) Wow6432Node-HKLM-Run-A1Diagnose - c:\program files (x86)\A1\A1 Diagnose\A1Diagnose.exe AddRemove-Native Instruments Maschine Controller Driver - c:\programdata\{3C6B30C3-46C9-4FD1-AAC3-6011E43BF0D1}\Maschine Controller Driver Setup.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe AddRemove-Sylenth1_is1 - c:\program files (x86)\Steinberg\VSTPlugins\Sylenth1\unins000.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\diMaster.dll\" /prefetch:1" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-11 17:54:53 ComboFix-quarantined-files.txt 2013-03-11 16:54 . Vor Suchlauf: 10 Verzeichnis(se), 255.358.676.992 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 255.365.537.792 Bytes frei . - - End Of File - - EB95E95C3049B6EA88DD660B26256348 Geändert von HeAdAche (11.03.2013 um 18:09 Uhr) |
![]() | #6 | |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen? Servus, Schritt 1 Mir ist aufgefallen, dass Du mehr als ein Anti-Virus-Programm mit Hintergrundwächter laufen hast: Code:
ATTFilter Norton Internet Security Avira Berichte, für welches Anti-Virus-Programm Du Dich entschieden hast. Zitat:
Schritt 2 Combofix-Skript
Schritt 3 Starte bitte OTL.exe und drücke den Quick Scan Button. Poste die OTL.txt hier in deinen Thread. Bitte poste mit deiner nächsten Antwort
|
![]() | #7 |
![]() ![]() | ![]() GVU Fragezeichen? OTL Logfile: Code:
ATTFilter OTL logfile created on: 18.03.2013 11:10:42 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\geraldo\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 6,26 Gb Available Physical Memory | 79,09% Memory free 15,83 Gb Paging File | 13,91 Gb Available in Paging File | 87,87% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 238,17 Gb Free Space | 51,15% Space Free | Partition Type: NTFS Computer Name: GERALDO-PC | User Name: geraldo | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.03.18 11:05:26 | 000,059,964 | ---- | M] (Macrovision Europe Ltd.) -- C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 PRC - [2013.03.11 20:42:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe PRC - [2013.03.08 13:27:44 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2013.02.07 15:13:59 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2013.02.07 15:13:33 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.02.07 15:13:33 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2012.11.17 13:22:51 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2012.07.06 17:34:31 | 000,079,360 | ---- | M] (Creative Labs) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe PRC - [2012.07.06 17:33:13 | 004,942,336 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFastUsb\XFastUsb.exe PRC - [2011.02.22 11:14:40 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011.02.22 11:14:34 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010.09.02 16:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe PRC - [2010.09.02 16:01:22 | 000,948,504 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe PRC - [2010.09.02 13:26:08 | 000,456,976 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe PRC - [2009.07.14 02:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe PRC - [2009.07.08 14:32:50 | 001,233,195 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe PRC - [2009.05.04 18:05:04 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe PRC - [2009.02.23 04:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe ========== Modules (No Company Name) ========== MOD - [2013.03.18 11:05:29 | 000,592,896 | ---- | M] () -- C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~de6248.tmp MOD - [2013.03.18 11:05:28 | 000,697,884 | ---- | M] () -- C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~df394b.tmp MOD - [2013.03.08 13:27:44 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012.11.28 14:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.11.28 14:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2010.09.02 16:01:22 | 000,948,504 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe MOD - [2010.09.02 15:54:26 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\sqlite3.dll MOD - [2009.04.20 10:55:58 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL MOD - [2009.02.06 17:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL ========== Services (SafeList) ========== SRV:64bit: - [2012.06.11 18:19:14 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2013.03.08 13:27:44 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.02.25 07:39:32 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013.02.07 15:13:59 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.02.07 15:13:33 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.11.17 13:22:51 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2012.11.09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.09.05 19:38:06 | 006,364,024 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService) SRV - [2012.07.06 17:35:21 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service) SRV - [2012.07.06 17:34:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service) SRV - [2012.07.06 17:34:31 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service) SRV - [2012.07.03 15:41:12 | 000,168,864 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\WireHelpSvc.exe -- (WireHelpSvc) SRV - [2011.02.22 11:14:40 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011.02.22 11:14:34 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010.09.02 16:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe -- (SmartViewService) SRV - [2010.09.02 13:26:08 | 000,456,976 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe -- (WCUService) SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.02.23 04:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.12.11 19:27:30 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2012.12.11 19:27:30 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2012.12.02 22:06:13 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012.09.24 08:58:11 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr) DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2012.07.21 21:22:59 | 000,031,808 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305) DRV:64bit: - [2012.07.06 17:33:14 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX) DRV:64bit: - [2012.07.03 15:41:04 | 000,147,472 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC) DRV:64bit: - [2012.06.11 19:59:38 | 010,248,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012.06.11 17:26:14 | 000,367,616 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012.02.23 13:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2011.07.07 11:54:28 | 000,357,968 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\gbxavs.sys -- (gbxavs) DRV:64bit: - [2011.07.07 11:54:28 | 000,068,688 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\gbxusb.sys -- (gbxusb_svc) DRV:64bit: - [2011.04.10 04:51:06 | 012,223,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2011.02.16 10:11:08 | 000,428,136 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011.02.08 06:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI) DRV:64bit: - [2011.02.08 06:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3) DRV:64bit: - [2010.10.19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010.06.11 13:37:14 | 000,015,368 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger) DRV:64bit: - [2009.11.04 19:54:48 | 000,359,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm) DRV:64bit: - [2009.11.04 19:54:47 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus) DRV:64bit: - [2009.11.04 19:54:47 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb) DRV:64bit: - [2009.11.04 19:54:47 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr) DRV:64bit: - [2009.10.08 13:09:02 | 000,045,136 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gbxavs_x64.sys -- (gbxavs_x64) DRV:64bit: - [2009.10.08 13:08:59 | 000,300,624 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gbxusb_x64.sys -- (gbxusb_x64) DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7A 79 A6 79 96 5B CD 01 [binary data] IE - HKCU\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK IE - HKCU\..\SearchScopes\{D9F17454-3E51-41e2-8C1E-B51C57C1956F}: "URL" = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: exif_viewer%40mozilla.doslash.org:2.00 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 13:27:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 13:27:44 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.02.24 13:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\Extensions [2013.02.24 13:25:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\Firefox\Profiles\2igtq7nb.default\extensions [2013.02.24 13:25:41 | 000,230,013 | ---- | M] () (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\firefox\profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi [2013.03.08 13:27:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013.03.08 13:27:44 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2013.02.16 05:15:47 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.02.16 05:15:47 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2013.02.16 05:15:47 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2013.02.16 05:15:47 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2013.02.16 05:15:47 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2013.02.16 05:15:47 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013.03.11 20:36:30 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.) O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd) O4 - HKLM..\Run: [SmartViewAgent] C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe () O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKLM..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe (FNet Co., Ltd.) O4 - HKCU..\Run: [ESL Wire] C:\Program Files\EslWire\wire.exe (Turtle Entertainment GmbH) O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation) O4 - Startup: C:\Users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: blank ([]about in Local intranet) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22BED806-6C8D-45B6-97C9-D8B6C312695D}: DhcpNameServer = 10.0.0.138 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.03.18 11:05:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013.03.11 20:42:53 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe [2013.03.11 20:37:32 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.03.11 17:48:11 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.03.11 17:48:11 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.03.11 17:48:11 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.03.11 17:46:46 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.03.11 17:46:35 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.03.11 17:45:55 | 005,037,889 | R--- | C] (Swearware) -- C:\Users\geraldo\Desktop\ComboFix.exe [2013.03.11 17:39:20 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2013.03.11 17:39:08 | 000,000,000 | ---D | C] -- C:\JRT [2013.03.10 14:05:14 | 000,000,000 | ---D | C] -- C:\Users\geraldo\Desktop\trojan [2013.03.09 14:29:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite [2013.03.09 14:29:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Astroburn Lite [2013.03.09 14:29:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Astroburn Lite [2013.03.09 12:49:12 | 234,009,856 | ---- | C] (Emsisoft GmbH ) -- C:\Users\geraldo\Desktop\EmsisoftAntiMalwareSetup_7.0.0.18.exe [2013.03.09 12:08:51 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Malwarebytes [2013.03.09 12:08:43 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.03.09 12:08:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.03.09 12:08:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.03.09 12:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.03.09 12:08:34 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Programs [2013.03.08 13:27:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.02.27 22:11:03 | 000,000,000 | ---D | C] -- C:\Users\geraldo\Documents\Geraldo [2013.02.24 13:51:54 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Macromedia [2013.02.24 13:24:57 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Mozilla [2013.02.24 13:24:57 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Mozilla [2013.02.24 13:23:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2013.02.24 13:23:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2013.02.17 13:52:30 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Apple Computer [2013.02.17 13:52:30 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Apple Computer [2013.02.17 13:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2013.02.17 13:52:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2013.02.17 13:46:41 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Apple [2013.02.17 13:46:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2013.02.17 13:46:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2013.02.17 13:46:19 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2013.02.17 13:46:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour [2013.02.17 13:46:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2013.02.17 13:46:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple ========== Files - Modified Within 30 Days ========== [2013.03.18 11:13:36 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.18 11:13:36 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.18 11:12:49 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.03.18 11:12:49 | 000,645,502 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.03.18 11:12:49 | 000,607,530 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.03.18 11:12:49 | 000,126,822 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.03.18 11:12:49 | 000,103,908 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.03.18 11:05:38 | 000,001,404 | ---- | M] () -- C:\Users\geraldo\Desktop\Games.lnk [2013.03.18 11:05:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.03.18 11:05:03 | 2078,806,015 | -HS- | M] () -- C:\hiberfil.sys [2013.03.11 20:42:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe [2013.03.11 20:36:30 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013.03.11 20:27:50 | 005,037,889 | R--- | M] (Swearware) -- C:\Users\geraldo\Desktop\ComboFix.exe [2013.03.11 17:33:57 | 000,000,400 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2013.03.10 14:39:48 | 000,377,856 | ---- | M] () -- C:\Users\geraldo\Desktop\hskobdf1.exe [2013.03.10 14:14:45 | 000,000,168 | ---- | M] () -- C:\Users\geraldo\defogger_reenable [2013.03.10 14:03:22 | 000,377,856 | ---- | M] () -- C:\Users\geraldo\Desktop\b6j43ent.exe [2013.03.09 14:29:23 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk [2013.03.09 13:43:56 | 322,961,408 | ---- | M] () -- C:\Users\geraldo\Desktop\pmagic_2013_02_28.iso [2013.03.09 13:29:55 | 001,160,893 | ---- | M] () -- C:\Users\geraldo\Desktop\ProcessExplorer.zip [2013.03.09 12:56:03 | 234,009,856 | ---- | M] (Emsisoft GmbH ) -- C:\Users\geraldo\Desktop\EmsisoftAntiMalwareSetup_7.0.0.18.exe [2013.03.09 00:06:50 | 000,074,126 | ---- | M] () -- C:\ProgramData\gqcbupulgcceydk [2013.02.26 18:33:22 | 014,018,244 | ---- | M] () -- C:\Users\geraldo\Desktop\hurensohn.wav [2013.02.24 13:23:06 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.02.19 20:15:41 | 000,193,401 | ---- | M] () -- C:\Users\geraldo\Documents\Das Erleben u. bew. einer Koronarintervention.pdf ========== Files Created - No Company Name ========== [2013.03.11 17:48:11 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.03.11 17:48:11 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.03.11 17:48:11 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.03.11 17:48:11 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.03.11 17:48:11 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.03.11 17:33:52 | 000,000,400 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat [2013.03.10 14:39:47 | 000,377,856 | ---- | C] () -- C:\Users\geraldo\Desktop\hskobdf1.exe [2013.03.10 14:14:45 | 000,000,168 | ---- | C] () -- C:\Users\geraldo\defogger_reenable [2013.03.10 14:05:25 | 000,377,856 | ---- | C] () -- C:\Users\geraldo\Desktop\b6j43ent.exe [2013.03.09 14:29:22 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk [2013.03.09 13:33:12 | 322,961,408 | ---- | C] () -- C:\Users\geraldo\Desktop\pmagic_2013_02_28.iso [2013.03.09 13:29:54 | 001,160,893 | ---- | C] () -- C:\Users\geraldo\Desktop\ProcessExplorer.zip [2013.03.09 00:06:34 | 000,074,126 | ---- | C] () -- C:\ProgramData\gqcbupulgcceydk [2013.03.06 22:22:33 | 000,001,404 | ---- | C] () -- C:\Users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk [2013.03.06 22:22:33 | 000,001,404 | ---- | C] () -- C:\Users\geraldo\Desktop\Games.lnk [2013.02.26 18:33:22 | 014,018,244 | ---- | C] () -- C:\Users\geraldo\Desktop\hurensohn.wav [2013.02.24 13:23:06 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.02.24 13:23:05 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.02.19 20:15:20 | 000,193,401 | ---- | C] () -- C:\Users\geraldo\Documents\Das Erleben u. bew. einer Koronarintervention.pdf [2013.02.17 13:46:40 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2012.11.17 13:20:03 | 000,282,296 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2012.11.17 13:20:02 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2012.11.17 13:20:02 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2012.07.06 20:10:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2012.07.06 19:31:05 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe [2012.07.06 17:35:37 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini [2012.07.06 17:35:37 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini [2012.07.06 17:35:37 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini [2012.07.06 17:35:26 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2012.07.06 17:35:26 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2012.07.06 17:29:03 | 013,356,032 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll [2012.07.06 17:29:03 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2012.07.06 17:29:03 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2012.07.06 17:29:03 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2012.07.06 17:29:03 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2012.06.11 17:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012.06.11 17:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012.05.10 15:35:16 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2011.09.12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.09.04 15:53:15 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\A1 Servicecenter [2012.10.26 14:41:34 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Antares [2012.12.02 22:07:59 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DAEMON Tools Lite [2012.07.06 17:39:06 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DeviceVm [2012.10.23 21:36:32 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DVDVideoSoft [2012.11.02 13:04:46 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\EurekaLog [2012.07.14 15:33:24 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\F4 [2012.10.10 09:54:37 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Image-Line [2012.07.19 14:18:06 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\LolClient [2012.09.04 15:46:56 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\mquadr.at [2012.10.23 18:24:28 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\OpenOffice.org [2012.07.06 17:45:58 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Opera [2012.10.18 15:45:00 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Publish Providers [2012.10.18 15:44:50 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Sony [2013.03.09 13:17:12 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\TS3Client ========== Purity Check ========== < End of report > |
![]() | #8 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen? Servus, bitte beantworte mir die folgenden Fragen, bevor wir weitermachen: Wie läuft dein Rechner derzeit? Gibt es noch Probleme mit Malware? Wenn ja, welche? |
![]() | #9 |
![]() ![]() | ![]() GVU Fragezeichen? Also mein Rechner läuft normal. So wie davor, es gibt kein Fenster(Welches beim GVU auftritt) mehr nach dem Startup, die Leistung sollte die selbe sein. Mit Maleware gibts eigentlich keine ersichtlichen Probleme. PS: Sry dass ich so spät geantwortet habe, aber ging leider nicht früher. |
![]() | #10 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen? Servus, wir entfernen noch ein paar Reste und kontrollieren alles: Schritt 1 Fixen mit OTL
Code:
ATTFilter :OTL O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found [2013.03.11 17:33:57 | 000,000,400 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2013.03.09 00:06:50 | 000,074,126 | ---- | M] () -- C:\ProgramData\gqcbupulgcceydk :commands [Emptytemp]
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
![]() | #11 |
![]() ![]() | ![]() GVU Fragezeichen? hey, kann ich später darauf antworten? aufgrund von komplikationen musste ich nochmal operiert werden, wahrscheinlich komm ich erst am WE raus, und meine freundin ist damit völlig überfordert. |
![]() | #12 | |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen? Servus, Zitat:
Meld dich einfach wieder, wenn du Zeit hast. Alles Gute für die OP! |
![]() | #13 |
![]() ![]() | ![]() GVU Fragezeichen? Hey, mir gehts wieder gut. Danke. Kleine Auffälligkeit, beim StartUp ist mein Desktop für mehrere Sekunden schwarz und dann erst zeigt sich alles. Ach und bei Malewarebytes hab ich n paar Dateien die in Quarantäne sind, was mach ich mit denen am besten? Code:
ATTFilter All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube to MP3 Converter\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube to MP3 Converter\ not found. C:\Windows\DeleteOnReboot.bat moved successfully. C:\ProgramData\gqcbupulgcceydk moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33237 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 56502 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56502 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: geraldo ->Temp folder emptied: 75011 bytes ->Temporary Internet Files folder emptied: 24601439 bytes ->Java cache emptied: 2208456 bytes ->FireFox cache emptied: 10561940 bytes ->Opera cache emptied: 19455189 bytes ->Flash cache emptied: 88347 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 608 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50501 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 55,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 03232013_164556 Files\Folders moved on Reboot... C:\Users\geraldo\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.03.23.07 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 geraldo :: GERALDO-PC [Administrator] 23.03.2013 16:53:13 mbam-log-2013-03-23 (16-53-13).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 234513 Laufzeit: 2 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Geändert von HeAdAche (23.03.2013 um 17:02 Uhr) |
![]() | #14 | ||
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Fragezeichen? Servus, Zitat:
Zitat:
![]() Fehlen noch die Logdatei von ESET und SecurityCheck. |
![]() | #15 |
![]() ![]() | ![]() GVU Fragezeichen? Eset und Security Check: ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=988549b4f9eb494fbe2cbb7256373f7c # engine=13457 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-03-23 06:01:24 # local_time=2013-03-23 07:01:24 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1799 16775165 100 96 12023 229484974 4807 0 # compatibility_mode=5893 16776573 100 94 17154213 116467355 0 0 # scanned=222708 # found=0 # cleaned=0 # scan_time=6782 Security Check: Results of screen317's Security Check version 0.99.59 Windows 7 x64 (UAC is enabled) Out of date service pack!! Internet Explorer 8 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 Java 7 Update 10 Java version out of Date! Adobe Flash Player 11.3.300.262 Flash Player out of Date! Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (19.0.2) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
![]() |
Themen zu GVU Fragezeichen? |
.dll, beenden, bekannte, booten, exe, explorer, fenster, folge, folgendes, fragezeichen, gefunde, guten, heute, malwarebytes, nicht schließen, process, prozess, schließe, schließen, starte, taskma, taskmanager, trojan.eofail, wpbt0.dll, öffnet |