|
Log-Analyse und Auswertung: Gesperrter Computer Vista 32 BusinessWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.07.2013, 06:42 | #16 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business Kannst ja mal im Forum rumschauen. Normalerweise entsperre ich so ein Ding mit einem Post, restlos. Aber nur, wenn man den entsprechenden Startpunkt im Log sieht. Sehr selten ist das nicht der Fall, er zeigt sich nur nach x Scans, so wie bei Dir. Er ist immer noch nicht zu sehen. Also wenn Du Zeit/Bock hast probieren wir noch, ansonsten mach Platt und beginn neu
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 06:54 | #17 |
| Gesperrter Computer Vista 32 Business Guten Morgen Schrauber,
__________________wenn die Chancen so stehen, sollten wir das weiter versuchen. Kann nur sein, dass ich ab 09:30 für ca 3 Stunden weg bin und nicht antworte. Der Aufwand das Ding platt zu machen ist auch mindestens 1 Tag. Sag an, welcher Scan? Gruß und Dank für deine gigantische Unterstützung Michael sag mir mal, woran ich den Startpunkt erkennen kann und welchen Scan ich hierfür laufen lassen muss, dann lass ich das Ding solange scannen, bis ich etwas sehe |
04.07.2013, 07:42 | #18 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business Naja, es muss ein HKLM oder HK(C)U Startpunkt sein mit der random-Datei drin.
__________________Falls Du kein Brennprogramm installiert hast, lade dir bitte ISOBurner herunter. Das Programm wird Dir erlauben, OTLPE auf eine CD zu brennen und sie bootfähig zu machen. Du brauchst das Tool nur zu installieren, der Rest läuft automatisch => Wie brenne ich eine ISO Datei auf CD/DVD.
Hinweis: Wie boote ich von CD
__________________ |
04.07.2013, 08:02 | #19 |
| Gesperrter Computer Vista 32 Business ok, noch eine Frage, da ich mich in den Katakomben der PC nun absolut nicht auskenne, wie kopiere ich eine Datei in der Eingabeaufforderung von C: auf den Stick? Sorry ok, meine Frage nach dem Kopieren ist beantwortet, der hat ein Xp installiert. Allerdings kam die Frage "Do you wish to load the remote registry" nicht?? wohl aber alle anderen Eine C:Extras.txt hat er nicht generiert, aber die OTL.Txt, hier ist der inhalt #OTL Logfile: Code:
ATTFilter OTL logfile created on: 7/4/2013 10:21:35 AM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows Vista (TM) Business Service Pack 2 (Version = 6.0.6002) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 216.00 Gb Total Space | 142.47 Gb Free Space | 65.96% Space Free | Partition Type: NTFS Drive D: | 72.03 Gb Total Space | 43.51 Gb Free Space | 60.40% Space Free | Partition Type: NTFS Drive E: | 10.00 Gb Total Space | 1.79 Gb Free Space | 17.86% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - [2013/06/12 11:24:02 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/05/21 00:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe -- (NIS) SRV - [2012/11/16 16:44:46 | 000,217,088 | ---- | M] (AMD) [Auto] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/09/02 10:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto] -- C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service) SRV - [2009/02/23 06:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc) SRV - [2007/05/31 05:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007/05/31 05:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) SRV - [2007/03/21 09:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R) SRV - [2007/02/13 14:57:06 | 002,655,848 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe -- (Norton Save and Restore) SRV - [2006/11/08 08:42:27 | 002,541,248 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate) SRV - [2006/11/08 08:42:27 | 000,194,240 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatisches LiveUpdate - Scheduler) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand] -- -- (IpInIp) DRV - [2013/06/19 00:36:07 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent) DRV - [2013/05/31 12:58:19 | 001,002,072 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys -- (BHDrvx86) DRV - [2013/05/23 01:25:28 | 000,934,488 | ---- | M] (Symantec Corporation) [File_System | Boot] -- C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys -- (SymEFA) DRV - [2013/05/22 00:59:33 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130702.021\NAVEX15.SYS -- (NAVEX15) DRV - [2013/05/22 00:59:33 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130702.021\NAVENG.SYS -- (NAVENG) DRV - [2013/05/21 01:02:00 | 000,367,704 | ---- | M] (Symantec Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\NIS\1404000.028\symds.sys -- (SymDS) DRV - [2013/05/16 01:02:14 | 000,603,224 | ---- | M] (Symantec Corporation) [File_System | On_Demand] -- C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS -- (SRTSP) DRV - [2013/04/25 09:32:44 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130702.001\IDSvix86.sys -- (IDSVix86) DRV - [2013/04/24 20:43:56 | 000,352,344 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS -- (SYMTDIv) DRV - [2013/04/15 22:41:14 | 000,134,744 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys -- (ccSet_NIS) DRV - [2013/03/04 21:39:19 | 000,175,264 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS -- (SymIRON) DRV - [2013/03/04 21:21:35 | 000,032,344 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL) DRV - [2012/12/31 08:40:50 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2012/11/16 17:07:06 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300) DRV - [2012/11/16 17:07:06 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2012/11/16 17:07:06 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag) DRV - [2012/11/16 15:38:48 | 000,290,304 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap) DRV - [2012/08/17 21:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) DRV - [2008/05/16 07:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) DRV - [2008/05/16 07:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) DRV - [2008/05/16 07:33:14 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016mdfl.sys -- (s0016mdfl) DRV - [2008/05/16 07:33:12 | 000,120,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016mdm.sys -- (s0016mdm) DRV - [2008/05/16 07:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) DRV - [2008/05/16 07:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016obex.sys -- (s0016obex) DRV - [2008/05/16 07:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM) DRV - [2008/01/09 07:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri) DRV - [2007/05/21 07:35:14 | 000,228,224 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R) DRV - [2007/05/09 16:51:34 | 000,041,888 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta) DRV - [2007/05/09 16:47:00 | 001,276,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI) DRV - [2007/05/09 16:46:48 | 000,014,112 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\lv302af.sys -- (pepifilter) DRV - [2007/02/13 15:06:36 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2007/02/13 14:33:06 | 000,131,944 | ---- | M] (StorageCraft) [File_System | Boot] -- C:\Windows\System32\drivers\symsnap.sys -- (symsnap) DRV - [2007/02/13 14:33:04 | 000,037,864 | ---- | M] (Symantec Corporation) [Kernel | Auto] -- C:\Windows\System32\drivers\v2imount.sys -- (v2imount) DRV - [2007/02/13 14:30:28 | 000,014,072 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vproeventmonitor.sys -- (VProEventMonitor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\EUPROCON_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\EUPROCON_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\EUPROCON_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\System32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/07/03 07:51:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/04/26 04:32:46 | 000,000,000 | ---D | M] [2013/01/29 02:40:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation) O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation) O3 - HKU\EUPROCON_ON_C\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( ) O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [Norton Save and Restore 2.0] C:\Program Files\Norton Save and Restore\Agent\VProTray.exe (Symantec Corporation) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe () O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\LocalService_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\NetworkService_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - Startup: C:\Users\EUPROCON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) O8 - Extra context menu item: Neue Notiz - C:\Program Files\Evernote\Evernote\\EvernoteIERes\NewNote.html () O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\\EvernoteIERes\AddNote.html () O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\\EvernoteIERes\AddNote.html () O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39) O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0) O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2013/07/03 07:46:43 | 000,000,000 | ---D | C] -- C:\FRST [2013/07/03 04:08:27 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro [2013/07/01 02:57:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2013/07/01 02:57:00 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2013/07/01 02:27:27 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt [2013/06/20 01:45:39 | 000,000,000 | ---D | C] -- C:\Users\EUPROCON\AppData\Local\Apps [2013/06/20 01:45:38 | 000,000,000 | ---D | C] -- C:\Users\EUPROCON\AppData\Local\Deployment [2013/06/13 14:50:46 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2013/06/13 14:50:46 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2013/06/13 14:50:45 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2013/06/13 14:50:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2013/06/13 14:50:45 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2013/06/13 14:50:45 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2013/06/13 14:50:44 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2013/06/13 14:50:44 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2013/06/13 14:50:44 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2013/06/13 14:50:43 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2013/06/13 00:50:16 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32spl.dll [2013/06/13 00:50:16 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printcom.dll [2013/06/13 00:50:13 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe [2013/06/13 00:50:13 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll [2013/06/13 00:50:05 | 003,603,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2013/06/13 00:50:04 | 003,551,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2013/06/13 00:50:02 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptdlg.dll [1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/07/04 03:13:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/07/04 03:13:35 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013/07/04 03:13:34 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013/07/04 03:13:34 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013/07/04 03:13:22 | 2143,461,376 | -HS- | M] () -- C:\hiberfil.sys [2013/07/03 08:32:19 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013/07/03 07:51:11 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013/07/03 06:34:19 | 000,688,236 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013/07/03 06:34:19 | 000,644,998 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013/07/03 06:34:19 | 000,150,212 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013/07/03 06:34:19 | 000,121,826 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013/07/03 05:22:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/07/03 04:58:32 | 000,001,036 | ---- | M] () -- C:\Windows\System32\.crusader [2013/07/03 01:30:36 | 000,002,759 | ---- | M] () -- C:\Users\EUPROCON\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook 2007.lnk [2013/07/01 02:57:19 | 000,001,894 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013/07/01 02:57:18 | 000,001,804 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013/06/24 02:36:05 | 000,002,657 | ---- | M] () -- C:\Users\EUPROCON\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk [2013/06/19 00:49:40 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security [2013/06/19 00:49:20 | 002,098,046 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1404000.028\Cat.DB [2013/06/19 00:36:07 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS [2013/06/19 00:36:07 | 000,007,611 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT [2013/06/19 00:36:07 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF [2013/06/12 11:23:58 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2013/06/12 11:23:57 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/07/04 03:13:22 | 2143,461,376 | -HS- | C] () -- C:\hiberfil.sys [2013/07/03 04:58:32 | 000,001,036 | ---- | C] () -- C:\Windows\System32\.crusader [2013/07/01 02:57:18 | 000,001,894 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2013/07/01 02:57:18 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2013/06/20 01:46:10 | 000,001,102 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013/06/20 01:46:08 | 000,001,098 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013/01/01 08:43:58 | 000,000,124 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc [2012/12/31 07:04:17 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2012/12/31 07:04:06 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2012/12/31 07:03:22 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2012/12/31 07:03:22 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2012/12/30 17:11:14 | 000,013,312 | ---- | C] () -- C:\Users\EUPROCON\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/12/30 17:04:38 | 000,007,268 | ---- | C] () -- C:\Users\EUPROCON\AppData\Local\d3d9caps.dat [2012/11/16 15:37:32 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll [2012/11/16 11:01:04 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe [2012/03/06 13:59:32 | 000,618,823 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2011/09/12 18:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat [2008/01/26 15:33:15 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat [2008/01/26 07:45:11 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2008/01/26 07:37:33 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2007/05/09 15:35:54 | 000,057,126 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [2006/11/07 15:25:58 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini [2006/11/02 11:42:41 | 000,688,236 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2006/11/02 11:42:41 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2006/11/02 11:42:41 | 000,150,212 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2006/11/02 11:42:41 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2006/11/02 08:56:48 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 08:47:43 | 000,414,712 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 06:33:01 | 000,644,998 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 06:33:01 | 000,121,826 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006/09/16 19:36:50 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll [2006/09/16 19:36:50 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll ========== LOP Check ========== [2013/04/17 07:02:22 | 000,000,000 | ---D | M] -- C:\Users\EUPROCON\AppData\Roaming\Motorola [2013/04/17 07:09:39 | 000,000,000 | ---D | M] -- C:\Users\EUPROCON\AppData\Roaming\Motorola Mobility [2012/12/30 16:59:10 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2013/01/24 03:32:01 | 000,000,000 | ---D | M] -- C:\ProgramData\BVRP Software [2012/12/30 16:59:10 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2012/12/30 16:59:10 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2012/12/30 16:59:10 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2013/07/03 04:58:52 | 000,000,000 | ---D | M] -- C:\ProgramData\HitmanPro [2012/12/30 16:59:10 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2008/01/26 08:04:42 | 000,000,000 | ---D | M] -- C:\ProgramData\SupportSoft [2012/12/30 16:59:10 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2013/01/01 08:56:55 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch [2013/07/04 03:13:36 | 000,032,510 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 76 bytes -> C:\Users\EUPROCON\Documents\Symantec:Roxio EMC Stream @Alternate Data Stream - 76 bytes -> C:\Users\EUPROCON\Documents\Sony Ericsson:Roxio EMC Stream < End of report > |
04.07.2013, 12:48 | #20 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 BusinessFixen mit OTL
Code:
ATTFilter :files C:\Users\EUPROCON\AppData\Local\Temp\*.dll C:\Users\EUPROCON\AppData\Local\Temp\*.exe
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 12:57 | #21 |
| Gesperrter Computer Vista 32 Business Die generierte Datei heißt: 07042013_145818.log und der Inhalt: # ========== FILES ========== C:\Users\EUPROCON\AppData\Local\Temp\amwubelyahjmiytos.dll moved successfully. C:\Users\EUPROCON\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe moved successfully. C:\Users\EUPROCON\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe moved successfully. C:\Users\EUPROCON\AppData\Local\Temp\Softonic_chr_1-8-8-11.exe moved successfully. OTLPE by OldTimer - Version 3.1.48.0 log created on 07042013_145418 ======= Neustart war nicht erforderlich Gruß Michael |
04.07.2013, 13:45 | #22 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business Dann bitte neustarten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 14:14 | #23 |
| Gesperrter Computer Vista 32 Business Hallo Schrauber, bingo!! das Baby tut es wieder, dafür dickes Lob und besten Dank. Allerdings erhalte ich die Meldung, dass das Sicherheitcenter ausgeschaltet ist und wenn ich versuche, es einzuschalten kommt eine Fehlermeldung. Ich weiß allerdings nicht, ob ich es brauche, da auf dem Rechner Norton Internet Security installiert ist und somit eigentlich die windowsseitigen Sierheitsvorrichtungen außer Betrieb sind.?? Wenn du jetzt dazu noch einen Kommentar hast Gruß Michael |
04.07.2013, 14:19 | #24 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business Ja wir sind auch noch nit durch. Ab jetzt alles im normalen WIndows Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade dir bitte Farbar Service Scanner
Poste bitte den Inhalt hier. Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 14:35 | #25 |
| Gesperrter Computer Vista 32 Business Hier kommt schon einmal das Ergenbis von AdwCleaner: #AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.304 - Datei am 04/07/2013 um 16:29:50 erstellt # Aktualisiert am 03/07/2013 von Xplode # Betriebssystem : Windows Vista (TM) Business Service Pack 2 (32 bits) # Benutzer : EUPROCON - EPCDESK05 # Bootmodus : Normal # Ausgeführt unter : C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Users\EUPROCON\AppData\LocalLow\Softonic ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\Software\Description ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16490 [OK] Die Registrierungsdatenbank ist sauber. ************************* AdwCleaner[S1].txt - [923 octets] - [04/07/2013 16:29:50] ########## EOF - C:\AdwCleaner[S1].txt - [982 octets] ########## und hier das Ergenis vom JRT: # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows Vista (TM) Business x86 Ran by EUPROCON on 04.07.2013 at 16:37:23,90 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CD7ECDF3-9763-4584-B167-C4A61247BCF5} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.07.2013 at 16:39:06,89 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und hier das Ergebnis vom FSS: # Farbar Service Scanner Version: 27-06-2013 Ran by EUPROCON (administrator) on 04-07-2013 at 16:42:19 Running from "C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue" Microsoft® Windows Vista™ Business Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ wscsvc Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist. Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys [2013-06-13 06:50] - [2013-05-08 06:37] - 0905576 ____A (Microsoft Corporation) 548E198BAE21EFC21F8B5F0C1728AD27 C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll [2013-06-13 06:50] - [2013-04-24 06:00] - 0133120 ____A (Microsoft Corporation) 3EDE4C1F9672C972479201544969ADCB C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\ipnathlp.dll => MD5 is legit C:\Windows\system32\iphlpsvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** und hier das Ergebnis vom FRST, für die Addition.txt muss ich aber den entsprechenden Haken setzen! # FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013 Ran by EUPROCON (administrator) on 04-07-2013 16:45:33 Running from C:\Users\EUPROCON\Desktop Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation) C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe (Motorola) C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Farbar) C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue\FSS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x] HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [174872 2007-03-21] (Intel Corporation) HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [90112 2006-11-10] () HKLM\...\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2006-10-03] (Macrovision Corporation) HKLM\...\Run: [] [x] HKLM\...\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [221184 2006-11-05] (Sonic Solutions) HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [118784 2006-10-20] (CyberLink Corp.) HKLM\...\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe" [2020968 2007-02-13] (Symantec Corporation) HKLM\...\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [16384 2007-11-15] ( ) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKCU\...\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun [1233920 2009-04-11] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2013-06-20] (Google Inc.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 Startup: C:\Users\EUPROCON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab Tcpip\..\Interfaces\{312A21D2-F4E4-4219-A452-933C43BD8FA7}: [NameServer]192.168.100.7,192.168.100.17 ========================== Services (Whitelisted) ================= R2 Automatisches LiveUpdate - Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [194240 2006-11-08] (Symantec Corporation) S3 LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2541248 2006-11-08] (Symantec Corporation) S3 MSSQL$MSSMLBIZ; c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation) R2 Norton Save and Restore; C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe [2655848 2007-02-13] (Symantec Corporation) R2 PST Service; C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-08-18] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-12-31] (Symantec Corporation) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130702.001\IDSvix86.sys [386720 2013-04-25] (Symantec Corporation) R3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41888 2007-05-09] (Logitech Inc.) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130702.021\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130702.021\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation) R3 pepifilter; C:\Windows\System32\DRIVERS\lv302af.sys [14112 2007-05-09] (Logitech Inc.) R3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [1276832 2007-05-09] (Logitech Inc.) S3 R300; C:\Windows\System32\DRIVERS\atikmdag.sys [10070016 2012-11-16] (Advanced Micro Devices, Inc.) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation) R2 v2imount; C:\Windows\System32\DRIVERS\v2imount.sys [37864 2007-02-13] (Symantec Corporation) S3 VProEventMonitor; C:\Windows\System32\DRIVERS\vproeventmonitor.sys [14072 2007-02-13] (Symantec Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-04 20:54 - 2013-07-04 20:54 - 00000000 ____D C:\_OTL 2013-07-04 16:45 - 2013-07-04 16:45 - 01373373 ____A (Farbar) C:\Users\EUPROCON\Desktop\FRST.exe 2013-07-04 16:42 - 2013-07-04 16:42 - 00003512 ____A C:\Users\EUPROCON\Desktop\FSS.txt 2013-07-04 16:39 - 2013-07-04 16:39 - 00000780 ____A C:\Users\EUPROCON\Desktop\JRT.txt 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\Windows\ERUNT 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\JRT 2013-07-04 16:29 - 2013-07-04 16:30 - 00001050 ____A C:\AdwCleaner[S1].txt 2013-07-04 16:23 - 2013-07-04 16:23 - 00054310 ____A C:\OTL.Txt 2013-07-03 13:46 - 2013-07-03 13:46 - 00000000 ____D C:\FRST 2013-07-03 10:58 - 2013-07-03 10:58 - 00001036 ____A C:\Windows\System32\.crusader 2013-07-03 10:08 - 2013-07-03 10:58 - 00000000 ____D C:\ProgramData\HitmanPro 2013-07-01 08:57 - 2013-07-01 08:57 - 00001894 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Adobe 2013-07-01 08:27 - 2013-07-01 08:27 - 00000000 ____D C:\Windows\System32\appmgmt 2013-06-20 07:47 - 2013-06-20 07:47 - 00000000 ____D C:\Program Files\GUM16FB.tmp 2013-06-20 07:46 - 2013-07-04 16:32 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-20 07:46 - 2013-07-03 13:51 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-20 07:45 - 2013-06-20 07:46 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Deployment 2013-06-20 07:45 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Apps\2.0 2013-06-13 20:50 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-13 20:50 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-13 20:50 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-13 20:50 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-13 20:50 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-13 20:50 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-13 20:50 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-13 20:50 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-13 20:50 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-13 20:50 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-13 20:50 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-13 20:50 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-13 20:50 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-13 20:50 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-13 20:50 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-13 20:50 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-13 06:50 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-13 06:50 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-06-13 06:50 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-06-13 06:50 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-13 06:50 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-13 06:50 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-13 06:50 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll ==================== One Month Modified Files and Folders ======== 2013-07-04 20:54 - 2013-07-04 20:54 - 00000000 ____D C:\_OTL 2013-07-04 16:45 - 2013-07-04 16:45 - 01373373 ____A (Farbar) C:\Users\EUPROCON\Desktop\FRST.exe 2013-07-04 16:42 - 2013-07-04 16:42 - 00003512 ____A C:\Users\EUPROCON\Desktop\FSS.txt 2013-07-04 16:39 - 2013-07-04 16:39 - 00000780 ____A C:\Users\EUPROCON\Desktop\JRT.txt 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\Windows\ERUNT 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\JRT 2013-07-04 16:37 - 2006-11-02 12:33 - 01601156 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-04 16:35 - 2008-01-26 13:38 - 01913092 ____A C:\Windows\WindowsUpdate.log 2013-07-04 16:32 - 2013-06-20 07:46 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-04 16:31 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-04 16:31 - 2006-11-02 14:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-04 16:31 - 2006-11-02 14:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-04 16:30 - 2013-07-04 16:29 - 00001050 ____A C:\AdwCleaner[S1].txt 2013-07-04 16:30 - 2008-01-26 13:45 - 00000012 ____A C:\Windows\bthservsdp.dat 2013-07-04 16:30 - 2006-11-02 15:01 - 00032510 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-04 16:23 - 2013-07-04 16:23 - 00054310 ____A C:\OTL.Txt 2013-07-04 16:22 - 2013-01-08 09:32 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-04 16:21 - 2013-01-01 14:41 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\SimpleSYN 2013-07-04 16:21 - 2012-12-30 23:02 - 00000000 ____D C:\users\EUPROCON 2013-07-03 13:51 - 2013-06-20 07:46 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-03 13:46 - 2013-07-03 13:46 - 00000000 ____D C:\FRST 2013-07-03 10:58 - 2013-07-03 10:58 - 00001036 ____A C:\Windows\System32\.crusader 2013-07-03 10:58 - 2013-07-03 10:08 - 00000000 ____D C:\ProgramData\HitmanPro 2013-07-03 09:01 - 2006-11-02 14:52 - 00026169 ____A C:\Windows\setupact.log 2013-07-01 18:40 - 2006-11-02 15:00 - 00035488 ____A C:\Windows\PFRO.log 2013-07-01 09:02 - 2012-12-30 23:47 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Adobe 2013-07-01 08:57 - 2013-07-01 08:57 - 00001894 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Adobe 2013-07-01 08:57 - 2008-01-26 14:02 - 00000000 ____D C:\ProgramData\Adobe 2013-07-01 08:27 - 2013-07-01 08:27 - 00000000 ____D C:\Windows\System32\appmgmt 2013-06-20 07:49 - 2012-12-30 23:05 - 00000000 ____D C:\Users\EUPROCON\AppData\Roaming\Google 2013-06-20 07:47 - 2013-06-20 07:47 - 00000000 ____D C:\Program Files\GUM16FB.tmp 2013-06-20 07:47 - 2012-12-30 23:04 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Google 2013-06-20 07:46 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Deployment 2013-06-20 07:46 - 2008-01-26 14:01 - 00000000 ____D C:\ProgramData\Google 2013-06-20 07:46 - 2008-01-26 14:01 - 00000000 ____D C:\Program Files\Google 2013-06-20 07:45 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Apps\2.0 2013-06-19 06:49 - 2012-12-31 14:00 - 00000000 ____D C:\Windows\System32\Drivers\NIS 2013-06-19 06:36 - 2012-12-31 14:01 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2013-06-19 06:36 - 2012-12-31 14:01 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2013-06-14 09:57 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-06-14 09:40 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE 2013-06-13 20:51 - 2008-01-26 13:54 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-06-13 20:49 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-06-12 17:23 - 2013-01-08 09:32 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-06-12 17:23 - 2013-01-08 09:32 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-04 16:37 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- und hier das Ergebnis des 2. Scan mit der Addition.txt #FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-07-2013 Ran by EUPROCON at 2013-07-04 17:05:20 Running from C:\Users\EUPROCON\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 2007 Microsoft Office Suite Service Pack 3 (SP3) 2007 Microsoft Office system (Version: 12.0.6612.1000) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) AMD APP SDK Runtime (Version: 10.0.937.2) AMD Catalyst Install Manager (Version: 8.0.877.0) ATI Catalyst Control Center (Version: 2.007.0914.2138) Avanquest update (Version: 1.12) Benutzerhandbuch Browser Address Error Redirector (Version: 1.00.0000) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1) Catalyst Control Center - Branding (Version: 1.00.0000) Catalyst Control Center Core Implementation (Version: 2007.0914.2139.36828) Catalyst Control Center Graphics Full Existing (Version: 2007.0914.2139.36828) Catalyst Control Center Graphics Full New (Version: 2007.0914.2139.36828) Catalyst Control Center Graphics Light (Version: 2007.0914.2139.36828) Catalyst Control Center Graphics Previews Common (Version: 2007.0914.2139.36828) Catalyst Control Center Graphics Previews Common (Version: 2012.1116.1515.27190) Catalyst Control Center Graphics Previews Vista (Version: 2007.0914.2139.36828) Catalyst Control Center InstallProxy (Version: 2012.1116.1515.27190) Catalyst Control Center Localization All (Version: 2012.1116.1515.27190) Catalyst Control Center Localization Chinese Standard (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Chinese Traditional (Version: 2007.0914.2139.36828) Catalyst Control Center Localization French (Version: 2007.0914.2139.36828) Catalyst Control Center Localization German (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Hungarian (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Italian (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Japanese (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Korean (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Polish (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Portuguese (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Spanish (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Thai (Version: 2007.0914.2139.36828) Catalyst Control Center Localization Turkish (Version: 2007.0914.2139.36828) CCC Help Chinese Standard (Version: 2007.0914.2138.36828) CCC Help Chinese Standard (Version: 2012.1116.1514.27190) CCC Help Chinese Traditional (Version: 2007.0914.2138.36828) CCC Help Chinese Traditional (Version: 2012.1116.1514.27190) CCC Help Czech (Version: 2012.1116.1514.27190) CCC Help Danish (Version: 2012.1116.1514.27190) CCC Help Dutch (Version: 2012.1116.1514.27190) CCC Help English (Version: 2007.0914.2138.36828) CCC Help English (Version: 2012.1116.1514.27190) CCC Help Finnish (Version: 2012.1116.1514.27190) CCC Help French (Version: 2007.0914.2138.36828) CCC Help French (Version: 2012.1116.1514.27190) CCC Help German (Version: 2007.0914.2138.36828) CCC Help German (Version: 2012.1116.1514.27190) CCC Help Greek (Version: 2012.1116.1514.27190) CCC Help Hungarian (Version: 2007.0914.2138.36828) CCC Help Hungarian (Version: 2012.1116.1514.27190) CCC Help Italian (Version: 2007.0914.2138.36828) CCC Help Italian (Version: 2012.1116.1514.27190) CCC Help Japanese (Version: 2007.0914.2138.36828) CCC Help Japanese (Version: 2012.1116.1514.27190) CCC Help Korean (Version: 2007.0914.2138.36828) CCC Help Korean (Version: 2012.1116.1514.27190) CCC Help Norwegian (Version: 2012.1116.1514.27190) CCC Help Polish (Version: 2007.0914.2138.36828) CCC Help Polish (Version: 2012.1116.1514.27190) CCC Help Portuguese (Version: 2007.0914.2138.36828) CCC Help Portuguese (Version: 2012.1116.1514.27190) CCC Help Russian (Version: 2012.1116.1514.27190) CCC Help Spanish (Version: 2007.0914.2138.36828) CCC Help Spanish (Version: 2012.1116.1514.27190) CCC Help Swedish (Version: 2012.1116.1514.27190) CCC Help Thai (Version: 2007.0914.2138.36828) CCC Help Thai (Version: 2012.1116.1514.27190) CCC Help Turkish (Version: 2007.0914.2138.36828) CCC Help Turkish (Version: 2012.1116.1514.27190) ccc-core-static (Version: 2007.0914.2139.36828) ccc-utility (Version: 2007.0914.2139.36828) ccc-utility (Version: 2012.1116.1515.27190) D3DX10 (Version: 15.4.2368.0902) Dell DataSafe (Version: 2.00.0000) Dell Handbuch zum Einstieg (Version: 1.00.0000) Dell Support Center (Version: 2.0.07311) Evernote v. 4.6.4 (Version: 4.6.4.8136) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4209.2358) Google Update Helper (Version: 1.3.21.145) Intel(R) Matrix Storage Manager Intel(R) PRO Network Connections 12.1.11.0 (Version: ) Java(TM) 6 Update 39 (Version: 6.0.390) Java(TM) SE Runtime Environment 6 (Version: 1.6.0.0) Junk Mail filter update (Version: 15.4.3502.0922) LiveUpdate 3.2 (Symantec Corporation) (Version: 3.2.0.26) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office 2003 Web Components (Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Outlook Connector (Version: 14.0.5118.5000) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319) Motorola Device Manager (Version: 2.3.9) Motorola Device Software Update (Version: 13.02.1402) Motorola Mobile Drivers Installation 6.0.0 (Version: 6.0.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) Norton Internet Security (Version: 20.4.0.40) Norton Save and Restore (Version: 2.0.0.19488) PowerDVD (Version: 7.0) Realtek High Definition Audio Driver Roxio Creator Audio (Version: 3.3.0) Roxio Creator BDAV Plugin (Version: 3.3.0) Roxio Creator Copy (Version: 3.3.0) Roxio Creator Data (Version: 3.3.0) Roxio Creator DE (Version: 3.3.0) Roxio Creator Tools (Version: 3.3.0) Roxio Express Labeler (Version: 2.1.0) Roxio MyDVD DE (Version: 9.0.116) Roxio Update Manager (Version: 3.0.0) Segoe UI (Version: 15.4.2271.0615) SimpleSYN 2.1 (Version: 2.1.4189) Skins (Version: 2007.0914.2139.36828) Sonic Activation Module (Version: 1.0) Sony Ericsson PC Suite 4.006.00 (Version: 4.006.00) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817327) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live Messenger (Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0) ==================== Restore Points ========================= 12-06-2013 09:26:19 Geplanter Prüfpunkt 13-06-2013 05:06:24 Geplanter Prüfpunkt 13-06-2013 18:47:52 Windows Update 14-06-2013 10:35:31 Geplanter Prüfpunkt 17-06-2013 06:57:07 Geplanter Prüfpunkt 19-06-2013 07:50:51 Geplanter Prüfpunkt 20-06-2013 05:25:49 Geplanter Prüfpunkt 20-06-2013 19:18:54 Geplanter Prüfpunkt 21-06-2013 08:37:36 Geplanter Prüfpunkt 24-06-2013 06:19:00 Geplanter Prüfpunkt 25-06-2013 09:31:19 Geplanter Prüfpunkt 26-06-2013 07:04:17 Geplanter Prüfpunkt 27-06-2013 08:04:37 Geplanter Prüfpunkt 28-06-2013 05:12:20 Geplanter Prüfpunkt 01-07-2013 05:26:55 Geplanter Prüfpunkt 01-07-2013 06:26:32 Removed Adobe Reader X (10.1.7) - Deutsch. 02-07-2013 08:40:07 Geplanter Prüfpunkt 03-07-2013 05:22:38 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {00B99C81-FEA0-4EA8-A2DD-8497265D8DBD} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {0CAB7B68-718C-40E0-B83B-89DDF7007DC8} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {150171E4-43E8-4CAE-9215-09B289C0B60B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-20] (Google Inc.) Task: {155723BA-60E2-4354-93AF-84EAC8D3C2D8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2012-12-31] () Task: {238816F3-39F2-4B65-90F6-A098D9F50160} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {252FCF61-1430-4291-A46E-883AD1A7DB80} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-20] (Google Inc.) Task: {286240E7-7A81-41B2-A5A9-3BE9A8C9AD78} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2012-12-31] (Microsoft Corporation) Task: {2DE18FE4-6467-484F-8431-206702EC5546} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {2E5B7D97-F14C-4CFF-864E-620AABA892D1} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {31D0C8A4-B75D-4D62-A659-434925C2BAAA} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {4B1C44C0-0C36-46E2-A44D-00330FC1779C} - System32\Tasks\Motorola Device Manager Update => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] () Task: {4D72741E-769C-45DB-8604-CB8EBDADAA29} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {65F13DF8-CD1A-4844-8722-FA6950B590A4} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: {68BD8876-790B-41BE-8CA7-9DD9C5A902DF} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {9939460C-8C1C-458D-961D-47E52C71DEDF} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] () Task: {9A6891EF-765E-4FA7-BD40-E14660D05EDC} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {CA78D833-DD8F-4AF2-83B4-D702882ECF8A} - System32\Tasks\WPD\SqmUpload_S-1-5-21-488772620-2242768751-4285676057-1003 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {CFECDF04-592C-434A-9A23-BA5E3EE2C6A5} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-03-25] () Task: {D138F985-86A8-41BB-A566-156B9D649048} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\VistaSP1CEIP => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {F7841EB9-9AD6-4997-B8E8-02200781B08F} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {FF98BB55-CC50-434A-BEE0-946A0C290230} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-07-04 16:56:45.312 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:45.205 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:45.099 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:44.993 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:37.755 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:37.649 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:37.542 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:37.436 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:36.307 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-04 16:56:36.178 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 52% Total physical RAM: 2045.45 MB Available physical RAM: 971.61 MB Total Pagefile: 4327.95 MB Available Pagefile: 3062.41 MB Total Virtual: 2047.88 MB Available Virtual: 1894.69 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:216 GB) (Free:143.49 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DELL BACKUP) (Fixed) (Total:72.03 GB) (Free:43.5 GB) NTFS Drive e: (RECOVERY) (Fixed) (Total:10 GB) (Free:1.78 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 50000000) Partition 1: (Not Active) - (Size=55 MB) - (Type=DE) Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS) Partition 3: (Active) - (Size=216 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=72 GB) - (Type=OF Extended) ==================== End Of Log ============================ Hallo Schrauber, ich habe den Rechner zwischenzeitlich neu gestartet. Eigentlich macht er (fast) alles, was er soll, allerdinge besteht nach wie vor das Thema, dass der Sicherheitscenterdienst ausgeschaltet ist und sich nicht einschalten lässt. Ein zweites Thema versuche ich auf einem anderen Wege zu lösen. Gruß Michael By the way, ich sehe zwischenzeitlich fast 400 Hits auf dem Thema, heißt das, dass es soviele weiter Problemfälle gibt? Hallo Schrauber, mein Virenscanner hat eben einen Vollscann durchgeführt und drei signifikante Bedrohungen erkannt und behoben. Hier die Screenshots: 1. ==================== Dateiname: igjc.class Bedrohungsname: Trojan.Maljava Vollständiger Pfad: c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\44\1000236c-31e6bd23 ____________________________ Details Unbekannte Community-Verbreitung,* Unbekanntes Alter,* Risiko Hoch Ursprung Heruntergeladen von*Unbekannt Aktivität Ausgeführte Aktionen: Ausgeführte Aktionen: 1 ____________________________ Auf Computern ab*04.07.2013 um 20:29:00 Zuletzt verwendet*04.07.2013 um 19:57:29 Start-Element*Nein Gestarted*Nein ____________________________ Unbekannt Es ist nicht bekannt, wie viele Benutzer in der Norton Community diese Datei verwendet haben. Unbekannt Diese Dateiversion ist nicht bekannt. Hoch Das Risiko dieser Datei ist hoch. Art der Bedrohung: Virus. Programme, die andere Programme, Dateien oder Computerbereiche infizieren, indem sie sich einfügen oder anhängen. ____________________________ Quelle: externe Medien ___________________________ Dateiaktionen igjc.class[Enthalten in] c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\44\1000236c-31e6bd23Gelöscht ____________________________ Dateiabdruck - SHA: 21aed8cbc5fbc1231deb17f8dc8638308af6f0f27fe0ba7a59a246304eba4f1b Dateiabdruck - MD5: Nicht verfügbar ===================== 2. ===================== Dateiname: igjc.class Bedrohungsname: Trojan.Maljava Vollständiger Pfad: c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\58\79632ba-57ac9334 ____________________________ Details Unbekannte Community-Verbreitung,* Unbekanntes Alter,* Risiko Hoch Ursprung Heruntergeladen von*Unbekannt Aktivität Ausgeführte Aktionen: Ausgeführte Aktionen: 1 ____________________________ Auf Computern ab*04.07.2013 um 20:31:49 Zuletzt verwendet*04.07.2013 um 19:57:35 Start-Element*Nein Gestarted*Nein ____________________________ Unbekannt Es ist nicht bekannt, wie viele Benutzer in der Norton Community diese Datei verwendet haben. Unbekannt Diese Dateiversion ist nicht bekannt. Hoch Das Risiko dieser Datei ist hoch. Art der Bedrohung: Virus. Programme, die andere Programme, Dateien oder Computerbereiche infizieren, indem sie sich einfügen oder anhängen. ____________________________ Quelle: externe Medien ____________________________ Dateiaktionen igjc.class[Enthalten in] c:\users\euprocon\appdata\locallow\sun\java\deployment\cache\6.0\58\79632ba-57ac9334Gelöscht ____________________________ Dateiabdruck - SHA: 21aed8cbc5fbc1231deb17f8dc8638308af6f0f27fe0ba7a59a246304eba4f1b Dateiabdruck - MD5: Nicht verfügbar ====================== und 3. (den Anhang habe ich sicherlich nicht geöffnet, wahrscheinlich war der schon rausgeflogen) ====================== Dateiname: pixmania gift voucher.scr Bedrohungsname: Trojan Horse Vollständiger Pfad: pixmania gift voucher.zip ____________________________ Details Unbekannte Community-Verbreitung,* Unbekanntes Alter,* Risiko Hoch Ursprung Gesendet von"pixmania.com service" <e-gift@pixmania.com> Aktivität Ausgeführte Aktionen: Ausgeführte Aktionen: 1 ____________________________ Auf Computern ab*Nicht verfügbar Zuletzt verwendet*07.06.2013 um 11:13:12 Start-Element*Nein Gestarted*Nein ____________________________ Unbekannt Es ist nicht bekannt, wie viele Benutzer in der Norton Community diese Datei verwendet haben. Unbekannt Diese Dateiversion ist nicht bekannt. Hoch Das Risiko dieser Datei ist hoch. Art der Bedrohung: Virus. Programme, die andere Programme, Dateien oder Computerbereiche infizieren, indem sie sich einfügen oder anhängen. ____________________________ Quelle: externe Medien Betreff: Pixmania Gift Voucher (50 EUR) Absender: "pixmania.com service" <e-gift@pixmania.com> Empfänger: "esfb" <diam.Duis@quis.org> ____________________________ Dateiaktionen pixmania gift voucher.scr[Enthalten in] pixmania gift voucher.zip [in einem E-Mail-Anhang] ____________________________ Dateiabdruck - SHA: 4a6837755926dc26b45677347df673edd0c7168e05995d4a321afc26336e80a5 Dateiabdruck - MD5: Nicht verfügbar =========================== |
04.07.2013, 19:34 | #26 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business http://download.bleepingcomputer.com...sta/wscsvc.reg auf dem Desktop speichern, ausführen, erlauben. Reboot. Sicherheitscenter? Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST Log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 20:02 | #27 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business und noch was bitte Scan mit SystemLook Lade SystemLook von jpshortstuff vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 20:07 | #28 |
| Gesperrter Computer Vista 32 Business Zwischenmeldung: Das Thema Sicherheitscenter ist wohl gegessen und der TFC rödelt. Melde mich wenn ESET gelaufen ist. ok, den SystemLook nach dem frischen FRST oder davor? |
04.07.2013, 20:11 | #29 |
/// the machine /// TB-Ausbilder | Gesperrter Computer Vista 32 Business Egal, wie Du zeit hast
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 21:04 | #30 |
| Gesperrter Computer Vista 32 Business ich habe einiges gelernt die Tage, 1. ein reiner Kommunikations/Internet-PC ist enorm wichtig, nicht auszudenken, wie lange die Scans dauern würden, wenn mein Arbeitstier betroffen wäre 2. runter von dem Rechner, was heruntergeladen, installiert und als sicher empfunden wurde. Der Scant sich einen Wolf mit den gigantischen Programm-Installationsdateien im download-Ordner 3. keinerlei wichtige Daten auf dem Kommunikations-PC, wenn was passiert, dann ist auch das Platt-Machen eine reelle Option. 4. ein noch deutlich besseres Konfigurations- und Dateimanagement. Programmdateien können spätestens nach dem übernächsten Release gelöscht werden und hier das Ergebnis der ESET Nachtschicht: # ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=914e0d3f2f3f034fb7aa52848c28b0ef # engine=14274 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-04 09:51:45 # local_time=2013-07-04 11:51:45 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=3591 16777213 100 93 196157 135571290 0 0 # compatibility_mode=5892 16776574 66 100 16025787 210507407 0 0 # scanned=139396 # found=1 # cleaned=0 # scan_time=4853 sh=4007ADB00DF116FD14156DAEFC82CC515B666D45 ft=1 fh=5bc1c012c75fd4a0 vn="Win32/Medfos.RS trojan" ac=I fn="C:\_OTL\MovedFiles\07042013_145418\C_Users\EUPROCON\AppData\Local\Temp\amwubelyahjmiytos.dll" ich werde jetzt ESET aufräumen und dann mit SecurityCheck fortfahren ..und hier das Ergebnis vom SecurityCheck: # Results of screen317's Security Check version 0.99.68 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Norton Internet Security WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java(TM) 6 Update 39 Java(TM) SE Runtime Environment 6 Java version out of Date! Adobe Reader 10.1.7 Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Hier das frische FRST log: # FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013 Ran by EUPROCON (administrator) on 05-07-2013 05:27:48 Running from C:\Users\EUPROCON\Downloads\Downloads\Programme\Rescue Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation) C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe (Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Motorola) C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x] HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [174872 2007-03-21] (Intel Corporation) HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [90112 2006-11-10] () HKLM\...\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2006-10-03] (Macrovision Corporation) HKLM\...\Run: [] [x] HKLM\...\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [221184 2006-11-05] (Sonic Solutions) HKLM\...\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [118784 2006-10-20] (CyberLink Corp.) HKLM\...\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe" [2020968 2007-02-13] (Symantec Corporation) HKLM\...\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [16384 2007-11-15] ( ) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKCU\...\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun [1233920 2009-04-11] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2013-06-20] (Google Inc.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 Startup: C:\Users\EUPROCON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab Tcpip\..\Interfaces\{312A21D2-F4E4-4219-A452-933C43BD8FA7}: [NameServer]192.168.100.7,192.168.100.17 ========================== Services (Whitelisted) ================= R2 Automatisches LiveUpdate - Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [194240 2006-11-08] (Symantec Corporation) S3 LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2541248 2006-11-08] (Symantec Corporation) S3 MSSQL$MSSMLBIZ; c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\diMaster.dll [556336 2013-05-30] (Symantec Corporation) R2 Norton Save and Restore; C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe [2655848 2007-02-13] (Symantec Corporation) R2 PST Service; C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130702.001\BHDrvx86.sys [1002072 2013-05-31] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-08-18] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-12-31] (Symantec Corporation) R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130704.001\IDSvix86.sys [386720 2013-04-25] (Symantec Corporation) R3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41888 2007-05-09] (Logitech Inc.) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130704.009\NAVENG.SYS [93272 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130704.009\NAVEX15.SYS [1611992 2013-05-22] (Symantec Corporation) R3 pepifilter; C:\Windows\System32\DRIVERS\lv302af.sys [14112 2007-05-09] (Logitech Inc.) R3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [1276832 2007-05-09] (Logitech Inc.) S3 R300; C:\Windows\System32\DRIVERS\atikmdag.sys [10070016 2012-11-16] (Advanced Micro Devices, Inc.) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation) R2 v2imount; C:\Windows\System32\DRIVERS\v2imount.sys [37864 2007-02-13] (Symantec Corporation) S3 VProEventMonitor; C:\Windows\System32\DRIVERS\vproeventmonitor.sys [14072 2007-02-13] (Symantec Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-04 21:39 - 2013-07-04 21:39 - 00005256 ____A C:\Users\EUPROCON\Downloads\wscsvc.reg 2013-07-04 20:54 - 2013-07-04 20:54 - 00000000 ____D C:\_OTL 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\Windows\ERUNT 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\JRT 2013-07-04 16:29 - 2013-07-04 16:30 - 00001050 ____A C:\AdwCleaner[S1].txt 2013-07-04 16:23 - 2013-07-04 16:23 - 00054310 ____A C:\OTL.Txt 2013-07-03 13:46 - 2013-07-03 13:46 - 00000000 ____D C:\FRST 2013-07-03 10:58 - 2013-07-03 10:58 - 00001036 ____A C:\Windows\System32\.crusader 2013-07-03 10:08 - 2013-07-03 10:58 - 00000000 ____D C:\ProgramData\HitmanPro 2013-07-01 08:57 - 2013-07-01 08:57 - 00001894 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Adobe 2013-07-01 08:27 - 2013-07-01 08:27 - 00000000 ____D C:\Windows\System32\appmgmt 2013-06-20 07:47 - 2013-06-20 07:47 - 00000000 ____D C:\Program Files\GUM16FB.tmp 2013-06-20 07:46 - 2013-07-05 01:51 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-20 07:46 - 2013-07-04 21:52 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-20 07:45 - 2013-06-20 07:46 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Deployment 2013-06-20 07:45 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Apps\2.0 2013-06-13 20:50 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-13 20:50 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-13 20:50 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-13 20:50 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-13 20:50 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-13 20:50 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-13 20:50 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-13 20:50 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-13 20:50 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-13 20:50 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-13 20:50 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-13 20:50 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-13 20:50 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-13 20:50 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-13 20:50 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-13 20:50 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-13 06:50 - 2013-05-08 06:37 - 00905576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-13 06:50 - 2013-05-03 00:03 - 03603832 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-06-13 06:50 - 2013-05-03 00:03 - 03551096 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-06-13 06:50 - 2013-05-02 06:04 - 00443904 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-13 06:50 - 2013-05-02 06:03 - 00037376 ____A (Microsoft Corporation) C:\Windows\System32\printcom.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00985600 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-13 06:50 - 2013-04-24 06:00 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-13 06:50 - 2013-04-24 03:46 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-13 06:50 - 2013-04-17 14:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll ==================== One Month Modified Files and Folders ======== 2013-07-05 04:14 - 2008-01-26 13:38 - 01967143 ____A C:\Windows\WindowsUpdate.log 2013-07-05 03:52 - 2006-11-02 14:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-05 03:52 - 2006-11-02 14:47 - 00003552 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-05 01:51 - 2013-06-20 07:46 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-05 01:22 - 2013-01-08 09:32 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-04 22:21 - 2006-11-02 12:33 - 01601156 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-04 22:19 - 2006-11-02 14:52 - 00026965 ____A C:\Windows\setupact.log 2013-07-04 21:52 - 2013-06-20 07:46 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-04 21:51 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-04 21:50 - 2008-01-26 13:45 - 00000012 ____A C:\Windows\bthservsdp.dat 2013-07-04 21:50 - 2006-11-02 15:01 - 00032510 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-04 21:39 - 2013-07-04 21:39 - 00005256 ____A C:\Users\EUPROCON\Downloads\wscsvc.reg 2013-07-04 20:54 - 2013-07-04 20:54 - 00000000 ____D C:\_OTL 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\Windows\ERUNT 2013-07-04 16:37 - 2013-07-04 16:37 - 00000000 ____D C:\JRT 2013-07-04 16:30 - 2013-07-04 16:29 - 00001050 ____A C:\AdwCleaner[S1].txt 2013-07-04 16:23 - 2013-07-04 16:23 - 00054310 ____A C:\OTL.Txt 2013-07-04 16:21 - 2013-01-01 14:41 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\SimpleSYN 2013-07-04 16:21 - 2012-12-30 23:02 - 00000000 ____D C:\users\EUPROCON 2013-07-03 13:46 - 2013-07-03 13:46 - 00000000 ____D C:\FRST 2013-07-03 10:58 - 2013-07-03 10:58 - 00001036 ____A C:\Windows\System32\.crusader 2013-07-03 10:58 - 2013-07-03 10:08 - 00000000 ____D C:\ProgramData\HitmanPro 2013-07-01 18:40 - 2006-11-02 15:00 - 00035488 ____A C:\Windows\PFRO.log 2013-07-01 09:02 - 2012-12-30 23:47 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Adobe 2013-07-01 08:57 - 2013-07-01 08:57 - 00001894 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-01 08:57 - 2013-07-01 08:57 - 00000000 ____D C:\Program Files\Adobe 2013-07-01 08:57 - 2008-01-26 14:02 - 00000000 ____D C:\ProgramData\Adobe 2013-07-01 08:27 - 2013-07-01 08:27 - 00000000 ____D C:\Windows\System32\appmgmt 2013-06-20 07:49 - 2012-12-30 23:05 - 00000000 ____D C:\Users\EUPROCON\AppData\Roaming\Google 2013-06-20 07:47 - 2013-06-20 07:47 - 00000000 ____D C:\Program Files\GUM16FB.tmp 2013-06-20 07:47 - 2012-12-30 23:04 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Google 2013-06-20 07:46 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Deployment 2013-06-20 07:46 - 2008-01-26 14:01 - 00000000 ____D C:\ProgramData\Google 2013-06-20 07:46 - 2008-01-26 14:01 - 00000000 ____D C:\Program Files\Google 2013-06-20 07:45 - 2013-06-20 07:45 - 00000000 ____D C:\Users\EUPROCON\AppData\Local\Apps\2.0 2013-06-19 06:49 - 2012-12-31 14:00 - 00000000 ____D C:\Windows\System32\Drivers\NIS 2013-06-19 06:36 - 2012-12-31 14:01 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2013-06-19 06:36 - 2012-12-31 14:01 - 00007611 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2013-06-14 09:57 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-06-14 09:40 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\System32\de-DE 2013-06-13 20:51 - 2008-01-26 13:54 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-06-13 20:49 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-06-12 17:23 - 2013-01-08 09:32 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-06-12 17:23 - 2013-01-08 09:32 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-04 21:57 ==================== End Of Log ============================ --- --- --- --- --- --- nanu, das mit dem SystemLook ging aber fix: Ergebnis SystemLook: # SystemLook 30.07.11 by jpshortstuff Log created at 05:33 on 05/07/2013 by EUPROCON Administrator - Elevation successful ========== reg ========== [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers] (No values found) [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\BriefcaseMenu] @="{85BBD920-42A0-1069-A2E4-08002B30309D}" [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\Open With] @="{09799AFB-AD67-11d1-ABCD-00C04FC30936}" [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\Open With EncryptionMenu] @="{A470F8CF-A1E8-4f65-8335-227475AA5C46}" [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\Sharing] @="{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu] @="{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}" [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\{0BCE32B2-DA1B-41D7-A71F-C02A7D633CE5}] (No values found) [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}] @="Start Menu Pin" [HKEY_CURRENT_USER\Software\Classes\*\shellex\ContextMenuHandlers] (No values found) [HKEY_CURRENT_USER\Software\Classes\*\shellex\ContextMenuHandlers\{66691188-2112-6990-9021-518636446111}] (No values found) ========== regfind ========== Searching for "amwubelyahjmiytos" |
Themen zu Gesperrter Computer Vista 32 Business |
adobe, adobe flash player, association, computer, defender, desktop, explorer.exe, farbar, farbar recovery scan tool, flash player, frst.txt, google, microsoft, monitor, norton internet security, problem, security, server, services.exe, svchost.exe, symantec, system, trojan.maljava, win32/medfos.rs, winlogon, winlogon.exe, wmp |