Hallo,
ich bin auf das Forum gestoßen, da es mich leider auch erwischt hat. Nach dem Wechsel der Computerbild Antivirensoftware (Kaspersky hat jahrelang problemlos gearbeitet) hat mich nun der im Titel erwähnte Trojaner heimgesucht.
Ich habe anhand anderer Beiträge mit Farbars Recovery Scan Tool folgendes Logfile erstellt (hat aber einige Zeit gedauert, ich bin kein Experte, daher bitte nicht zu viel Wissen vorasussetzen):
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-07-2013
Ran by SYSTEM on 20-07-2013 09:53:18
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Runonce: [awde7zip23012] - [x]
HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2011-10-13] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKU\H1\...\Run: [Copernic Desktop Search - Home] - "C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchService.exe" /tray [1651200 2012-07-23] (Copernic Inc.)
HKU\H1\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\H1\AppData\Local\Temp\cabskmnvdjkotusiq.exe [57856 2013-07-19] (Cisco Systems, Inc.) <===== ATTENTION
HKU\H1\...\Winlogon: [Shell] cmd.exe [345088 2010-11-20] (Microsoft Corporation) <==== ATTENTION
HKU\H1\...\Command Processor: "C:\Users\H1\AppData\Local\Temp\cabskmnvdjkotusiq.exe" <===== ATTENTION!
==================== Services (Whitelisted) =================
S2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-10-13] (Advanced Micro Devices, Inc.)
S2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
S2 NIS; C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation)
==================== Drivers (Whitelisted) ====================
S1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\BASHDefs\20120815.002\BHDrvx64.sys [1385120 2012-08-10] (Symantec Corporation)
S1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\BASHDefs\20120815.002\BHDrvx64.sys [1385120 2012-08-10] (Symantec Corporation)
S1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation)
S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-10-12] (Samsung Electronics Co., Ltd.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-10-12] (Samsung Electronics Co., Ltd.)
S1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\IPSDefs\20120811.001\IDSVia64.sys [512672 2012-08-10] (Symantec Corporation)
S1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\IPSDefs\20120811.001\IDSVia64.sys [512672 2012-08-10] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20120818.001\ENG64.SYS [125600 2012-08-17] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20120818.001\ENG64.SYS [125600 2012-08-17] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20120818.001\EX64.SYS [2084000 2012-08-17] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20120818.001\EX64.SYS [2084000 2012-08-17] (Symantec Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation)
S1 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation)
S0 SymDS; C:\Windows\System32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation)
S0 SymEFA; C:\Windows\System32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation)
S1 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation)
S1 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-20 09:53 - 2013-07-20 09:53 - 00000000 ____D C:\FRST
2013-07-19 09:08 - 2013-07-19 09:08 - 00163073 _____ C:\ProgramData\2433f433
2013-07-19 09:08 - 2013-07-19 09:08 - 00163039 _____ C:\Users\H1\AppData\Local\2433f433
2013-07-19 09:08 - 2013-07-19 09:08 - 00162991 _____ C:\Users\H1\AppData\Roaming\2433f433
2013-07-11 10:31 - 2013-07-11 10:31 - 01069032 _____ (Solid State Networks) C:\Users\H1\Downloads\install_flashplayer11x32_mssd_aaa_aih.exe
2013-07-10 20:44 - 2013-06-11 15:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-10 20:44 - 2013-06-11 15:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-10 20:44 - 2013-06-11 15:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-10 20:44 - 2013-06-11 15:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-10 20:44 - 2013-06-11 15:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-10 20:44 - 2013-06-11 15:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-10 20:44 - 2013-06-11 15:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-10 20:44 - 2013-06-11 15:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-10 20:44 - 2013-06-11 15:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-10 20:44 - 2013-06-11 15:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-10 20:44 - 2013-06-11 15:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-10 20:44 - 2013-06-11 15:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-10 20:44 - 2013-06-11 15:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-10 20:44 - 2013-06-11 15:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-07-10 20:44 - 2013-06-11 15:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-07-10 20:44 - 2013-06-11 15:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-07-10 20:44 - 2013-06-11 15:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-07-10 20:44 - 2013-06-11 15:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-07-10 20:44 - 2013-06-11 14:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-10 20:44 - 2013-06-11 14:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-10 20:44 - 2013-06-06 19:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-07-10 20:44 - 2013-06-06 18:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-10 12:53 - 2013-07-10 12:53 - 00000000 ____D C:\c0cf1613d0ad7a1b7b
2013-07-10 09:40 - 2013-06-03 22:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\System32\qedit.dll
2013-07-10 09:40 - 2013-06-03 20:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-10 09:40 - 2013-05-05 22:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-07-10 09:40 - 2013-05-05 20:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-10 09:33 - 2013-06-04 19:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-07-10 09:28 - 2013-04-09 15:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-10 09:28 - 2013-04-02 14:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2013-07-08 09:32 - 2013-07-08 09:32 - 00000000 ____D C:\Users\H1\AppData\Local\CrashDumps
2013-07-03 09:25 - 2013-07-03 09:33 - 122019512 _____ C:\Users\H1\Downloads\Mediencenter.zip
2013-07-03 08:38 - 2013-07-03 08:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-24 12:03 - 2013-06-26 08:51 - 00000000 ____D C:\Users\H1\dwhelper
2013-06-21 21:02 - 2013-06-21 21:07 - 29084672 _____ C:\Users\H1\Downloads\070---Das-gestohlene-Hexenkraut.rar.part
2013-06-21 20:21 - 2013-06-21 20:49 - 121672834 _____ C:\Users\H1\Downloads\Kids-F32_D2013[][]]][.rar
2013-06-20 08:54 - 2013-06-20 08:54 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security CBE
==================== One Month Modified Files and Folders =======
2013-07-20 09:53 - 2013-07-20 09:53 - 00000000 ____D C:\FRST
2013-07-19 23:49 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-19 23:49 - 2009-07-13 20:51 - 00077621 _____ C:\Windows\setupact.log
2013-07-19 23:44 - 2012-06-14 12:11 - 01691907 _____ C:\Windows\WindowsUpdate.log
2013-07-19 23:44 - 2009-07-13 20:45 - 00016752 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-19 23:44 - 2009-07-13 20:45 - 00016752 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-19 23:24 - 2012-06-15 21:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-19 09:13 - 2013-05-02 12:13 - 00000274 _____ C:\Windows\Tasks\DSite.job
2013-07-19 09:08 - 2013-07-19 09:08 - 00163073 _____ C:\ProgramData\2433f433
2013-07-19 09:08 - 2013-07-19 09:08 - 00163039 _____ C:\Users\H1\AppData\Local\2433f433
2013-07-19 09:08 - 2013-07-19 09:08 - 00162991 _____ C:\Users\H1\AppData\Roaming\2433f433
2013-07-18 10:15 - 2012-06-15 21:14 - 00000000 ____D C:\Users\H1\AppData\Roaming\vlc
2013-07-17 10:15 - 2013-06-17 08:13 - 00000005 _____ C:\Users\H1\AppData\Roaming\WBPU-TTL.DAT
2013-07-15 09:38 - 2012-08-02 00:27 - 00000000 ____D C:\Program Files (x86)\Lidl_Fotos
2013-07-11 10:31 - 2013-07-11 10:31 - 01069032 _____ (Solid State Networks) C:\Users\H1\Downloads\install_flashplayer11x32_mssd_aaa_aih.exe
2013-07-10 21:04 - 2010-11-20 19:47 - 00015322 _____ C:\Windows\PFRO.log
2013-07-10 20:52 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-10 20:52 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-10 20:48 - 2011-05-16 06:04 - 00653928 _____ C:\Windows\System32\perfh007.dat
2013-07-10 20:48 - 2011-05-16 06:04 - 00129800 _____ C:\Windows\System32\perfc007.dat
2013-07-10 20:48 - 2009-07-13 21:13 - 01518986 _____ C:\Windows\System32\PerfStringBackup.INI
2013-07-10 20:45 - 2012-06-19 21:18 - 78185248 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-07-10 20:39 - 2013-03-13 13:39 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-10 20:39 - 2013-03-13 13:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-10 20:39 - 2011-04-12 00:28 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-10 20:39 - 2009-07-13 20:45 - 00304952 _____ C:\Windows\System32\FNTCACHE.DAT
2013-07-10 12:53 - 2013-07-10 12:53 - 00000000 ____D C:\c0cf1613d0ad7a1b7b
2013-07-10 11:07 - 2012-06-15 22:14 - 00000000 ____D C:\Users\H1\01_Büro
2013-07-10 11:05 - 2013-05-10 03:46 - 00000000 ____D C:\Users\H1\Desktop\EasyCash&Tax -06.2013
2013-07-09 09:20 - 2013-05-05 01:23 - 00000000 ____D C:\Users\H1\AppData\Roaming\Dropbox
2013-07-09 09:19 - 2013-05-05 02:00 - 00000000 ___RD C:\Users\H1\Dropbox
2013-07-08 09:32 - 2013-07-08 09:32 - 00000000 ____D C:\Users\H1\AppData\Local\CrashDumps
2013-07-04 08:50 - 2012-06-14 21:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-03 09:33 - 2013-07-03 09:25 - 122019512 _____ C:\Users\H1\Downloads\Mediencenter.zip
2013-07-03 08:38 - 2013-07-03 08:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-26 08:52 - 2012-06-15 21:55 - 00000000 ____D C:\Users\H1\02_Fotos
2013-06-26 08:51 - 2013-06-24 12:03 - 00000000 ____D C:\Users\H1\dwhelper
2013-06-24 12:03 - 2012-06-14 12:52 - 00000000 ____D C:\users\H1
2013-06-21 21:07 - 2013-06-21 21:02 - 29084672 _____ C:\Users\H1\Downloads\070---Das-gestohlene-Hexenkraut.rar.part
2013-06-21 20:49 - 2013-06-21 20:21 - 121672834 _____ C:\Users\H1\Downloads\Kids-F32_D2013[][]]][.rar
2013-06-20 10:20 - 2012-08-11 03:37 - 00000000 ____D C:\Users\H1\AppData\Roaming\Applian FLV and Media Player
2013-06-20 08:54 - 2013-06-20 08:54 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security CBE
2013-06-20 08:54 - 2013-05-31 09:24 - 00003242 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-06-20 08:54 - 2013-05-31 09:24 - 00000000 ____D C:\Windows\System32\Drivers\NISx64
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-07-05 09:23:57
Restore point made on: 2013-07-07 09:00:35
Restore point made on: 2013-07-09 04:56:03
Restore point made on: 2013-07-10 12:51:15
Restore point made on: 2013-07-10 20:43:32
Restore point made on: 2013-07-14 09:29:29
Restore point made on: 2013-07-16 07:55:53
Restore point made on: 2013-07-19 08:46:44
==================== Memory info ===========================
Percentage of memory in use: 11%
Total physical RAM: 5624.15 MB
Available physical RAM: 4975.1 MB
Total Pagefile: 5622.35 MB
Available Pagefile: 4953.9 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: (C) (Fixed) (Total:997.75 GB) (Free:912.6 GB) NTFS (Disk=0 Partition=3)
Drive d: (D) (Fixed) (Total:865.04 GB) (Free:784.45 GB) NTFS (Disk=0 Partition=4)
Drive g: () (Removable) (Total:1.88 GB) (Free:0.82 GB) FAT32 (Disk=2 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: 8A8F4F8D)
Partition: GPT Partition Type
========================================================
Disk: 2 (Size: 2 GB) (Disk ID: 91F72D24)
Partition 1: (Active) - (Size=2 GB) - (Type=0B)
LastRegBack: 2013-07-12 21:53
==================== End Of Log ============================
Ich hoffe, das ist soweit richtig und ihr könnt mir helfen. Danke.