|
Plagegeister aller Art und deren Bekämpfung: Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/NeopWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.08.2013, 11:28 | #1 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo ihr Lieben, ich habe gestern eine Zip-Datei einer Phishing-Mail geöffnet, es passierte nichts und erst im Nachhinein wurde mir klar, dass es eine Phishing-Mail war. Antivir habe ich mir gestern Abend dann sofort nach Öffnen der Mail runtergeladen - keine Funde. Dieses Programm ist momentan aktiviert für PC und Internet. Als ich die Zip-Datei öffnete kam eine Meldung von den Microsoft Security Essentials, die ich aber nur am Rande mitbekommen hatte gestern. Das Programm war bisher meine Antivir-Software und ist es auch jetzt noch. (Das heißt, Antivir und die Essentials sind beide aktiv) Heut habe ich gesehen, dass die Microsoft Essentials den Trojaner Trojan:Win32/Neop gestern gefunden hat, Warnstufe "schwerwiegend" und den Trojaner habe ich dann wie empfohlen entfernen lassen und die sind jetzt in Quarantäne. Die Datei, von der der Trojaner kommt, wird hier auch angezeigt und ist die Datei, die ich in der Phishing Mail als Anhang hatte: file:C:\Users\Mira\AppData\Local\Temp\Temp1_20.08.2013 abgewiesene Lastschrift.zip\Abgewiesene Lastschrift vom 20.08.2013.com Ich finde sie aber an dem angegeben Ort nicht. Ich finde bei den Microsoft Essentials keinen Log, den ich kopieren kann und auch hier im Forum keine Beschreibung, wie man bei den Microsoft Security Essentials an den Log kommt. Ich habe jetzt bei dem Programm mal eingestellt, dass automatisch Trojaner der Stufe "Schwerwiegend" entfernt werden sollen. Ich habe mir eure Schritte etc. durchgelesen, weiß aber nicht genau, welcher jetzt in meinem Fall zu tun ist. Es wäre für mich hilfreich zu wissen, welche Programme ich mir herunterladen sollte oder laufen lassen soll, oder was ich jetzt als nächstes tun soll. Weiterhin würde ich gerne wissen, ob ich momentan besser kein Online-Banking mehr machen soll, etc. da ich nicht weiß, inwiefern so ein Trojaner fähig ist Passwörter zu scannen oder sonstige Aktionen an meinem PC auszuführen. Wie bekomme ich meinen PC sicher frei? Ist er nun schon frei, weil der Trojaner in Quarantäne ist? Vielen Dank schon einmal für eure Antworten. Liebe Grüße Mira Geändert von TheMissMico (25.08.2013 um 11:44 Uhr) |
25.08.2013, 11:56 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
25.08.2013, 15:14 | #3 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo, vielen Dank für die schnelle Rückmeldung. Hier die zwei Logs:
__________________FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-08-2013 Ran by Mira (administrator) on 25-08-2013 16:05:22 Running from C:\Users\Mira\Downloads Microsoft Windows 7 Professional N Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation) HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-18] (Avira Operations GmbH & Co. KG) Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X] HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18706176 2013-01-08] (Skype Technologies S.A.) HKCU\...\Run: [DAEMON Tools Pro Agent] - C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) HKCU\...\Run: [Google Update] - C:\Users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-17] (Google Inc.) MountPoints2: {569515fb-fcc5-11e2-9425-001e376878f4} - F:\Startme.exe BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Mira\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Mira\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-18] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-18] (Avira Operations GmbH & Co. KG) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation) R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-02-01] (DT Soft Ltd) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-25 15:58 - 2013-08-25 15:58 - 01070459 _____ (Farbar) C:\Users\Mira\Downloads\FRST.exe 2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Avira 2013-08-25 11:23 - 2013-08-25 11:23 - 00095056 _____ C:\Windows\PFRO.log 2013-08-25 01:19 - 2013-08-25 01:15 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-25 01:01 - 2013-08-25 01:01 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-25 00:56 - 2013-07-18 08:02 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-25 00:56 - 2013-07-18 08:02 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-25 00:56 - 2013-03-06 16:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-08-25 00:56 - 2012-08-27 15:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-08-25 00:51 - 2013-08-25 00:59 - 00000000 ____D C:\ProgramData\Avira 2013-08-25 00:51 - 2013-08-25 00:51 - 00000000 ____D C:\Program Files\Avira 2013-08-25 00:22 - 2013-08-25 00:29 - 110344048 _____ C:\Users\Mira\Downloads\avira_free4045_antivirus_de.exe 2013-08-24 23:51 - 2013-08-24 23:56 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-24 23:51 - 2013-08-24 23:51 - 00002119 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-08-24 23:50 - 2013-08-24 23:51 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-08-24 23:50 - 2009-01-25 13:14 - 00015224 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe 2013-08-24 23:43 - 2013-08-24 23:46 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(5).exe 2013-08-24 23:42 - 2013-08-24 23:44 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(4).exe 2013-08-24 23:39 - 2013-08-24 23:41 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(3).exe 2013-08-24 23:38 - 2013-08-24 23:40 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(2).exe 2013-08-24 23:38 - 2013-08-24 23:40 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(1).exe 2013-08-24 23:34 - 2013-08-24 23:35 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2.exe 2013-08-24 22:44 - 2013-08-24 22:44 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-21 09:11 - 2013-08-21 09:12 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-21 09:03 - 2013-08-21 09:03 - 00000000 ____D C:\Users\Mira\Documents\Canon Utilities 2013-08-20 23:21 - 2013-08-20 23:21 - 00000000 ____D C:\Users\Mira\AppData\Roaming\CANON INC 2013-08-20 23:11 - 2013-08-20 23:11 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles 2013-08-20 23:09 - 2013-08-20 23:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\Common Files\Canon_Inc_IC 2013-08-20 23:02 - 2013-08-20 23:02 - 00000000 ____D C:\Users\Mira\AppData\Roaming\canon 2013-08-20 23:01 - 2013-08-20 23:02 - 00000000 ____D C:\ProgramData\Canon_Inc_IC 2013-08-15 08:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 08:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 08:40 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 08:40 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 08:40 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 08:40 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 08:40 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 08:40 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 08:40 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 08:37 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-15 08:37 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 08:37 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 08:37 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 08:37 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 08:37 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-15 08:36 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 08:36 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-08 16:54 - 2013-08-08 16:55 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3(1).zip 2013-08-08 16:42 - 2013-08-08 16:43 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3.zip 2013-08-07 09:30 - 2013-08-07 09:30 - 00009439 _____ C:\Users\Mira\Desktop\CHORDS AIR.odt 2013-08-05 13:06 - 2013-08-25 11:23 - 00003080 _____ C:\Windows\setupact.log 2013-08-05 13:06 - 2013-08-05 13:06 - 00000000 _____ C:\Windows\setuperr.log 2013-08-04 08:15 - 2013-08-04 08:17 - 19159080 _____ (Sony Ericsson ) C:\Users\Mira\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe ==================== One Month Modified Files and Folders ======= 2013-08-25 16:05 - 2013-08-25 16:05 - 00000000 ____D C:\FRST 2013-08-25 16:04 - 2013-02-17 22:39 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job 2013-08-25 16:04 - 2013-01-21 21:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-25 15:58 - 2013-08-25 15:58 - 01070459 _____ (Farbar) C:\Users\Mira\Downloads\FRST.exe 2013-08-25 15:54 - 2013-01-26 17:49 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Skype 2013-08-25 15:36 - 2009-07-14 06:02 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-25 15:36 - 2009-07-14 06:02 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-25 13:07 - 2013-01-17 00:08 - 01741591 _____ C:\Windows\WindowsUpdate.log 2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Avira 2013-08-25 11:23 - 2013-08-25 11:23 - 00095056 _____ C:\Windows\PFRO.log 2013-08-25 11:23 - 2013-08-05 13:06 - 00003080 _____ C:\Windows\setupact.log 2013-08-25 11:23 - 2009-07-14 06:17 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-25 01:15 - 2013-08-25 01:19 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-25 01:01 - 2013-08-25 01:01 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-25 00:59 - 2013-08-25 00:51 - 00000000 ____D C:\ProgramData\Avira 2013-08-25 00:51 - 2013-08-25 00:51 - 00000000 ____D C:\Program Files\Avira 2013-08-25 00:29 - 2013-08-25 00:22 - 110344048 _____ C:\Users\Mira\Downloads\avira_free4045_antivirus_de.exe 2013-08-25 00:04 - 2013-02-17 22:39 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job 2013-08-24 23:56 - 2013-08-24 23:51 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-24 23:51 - 2013-08-24 23:51 - 00002119 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-08-24 23:51 - 2013-08-24 23:50 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-08-24 23:46 - 2013-08-24 23:43 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(5).exe 2013-08-24 23:44 - 2013-08-24 23:42 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(4).exe 2013-08-24 23:41 - 2013-08-24 23:39 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(3).exe 2013-08-24 23:40 - 2013-08-24 23:38 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(2).exe 2013-08-24 23:40 - 2013-08-24 23:38 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(1).exe 2013-08-24 23:36 - 2013-01-17 00:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-24 23:35 - 2013-08-24 23:34 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2.exe 2013-08-24 23:05 - 2013-01-17 00:26 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Mozilla 2013-08-24 23:04 - 2013-01-21 21:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-08-24 23:04 - 2013-01-21 21:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-08-24 22:44 - 2013-08-24 22:44 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-22 14:17 - 2013-01-26 13:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\vlc 2013-08-22 14:14 - 2010-11-20 23:03 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 09:12 - 2013-08-21 09:11 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-21 09:03 - 2013-08-21 09:03 - 00000000 ____D C:\Users\Mira\Documents\Canon Utilities 2013-08-20 23:21 - 2013-08-20 23:21 - 00000000 ____D C:\Users\Mira\AppData\Roaming\CANON INC 2013-08-20 23:11 - 2013-08-20 23:11 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles 2013-08-20 23:09 - 2013-08-20 23:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\Common Files\Canon_Inc_IC 2013-08-20 23:02 - 2013-08-20 23:02 - 00000000 ____D C:\Users\Mira\AppData\Roaming\canon 2013-08-20 23:02 - 2013-08-20 23:01 - 00000000 ____D C:\ProgramData\Canon_Inc_IC 2013-08-16 07:44 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-08-15 18:21 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 10:37 - 2013-01-17 00:04 - 00000000 ____D C:\Windows\Panther 2013-08-15 10:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-15 08:48 - 2013-07-25 00:02 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 08:46 - 2013-02-18 17:04 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-08 16:55 - 2013-08-08 16:54 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3(1).zip 2013-08-08 16:43 - 2013-08-08 16:42 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3.zip 2013-08-07 21:36 - 2013-01-26 13:14 - 00000000 ____D C:\Users\Mira\AppData\Roaming\dvdcss 2013-08-07 09:30 - 2013-08-07 09:30 - 00009439 _____ C:\Users\Mira\Desktop\CHORDS AIR.odt 2013-08-06 02:28 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-08-05 13:06 - 2013-08-05 13:06 - 00000000 _____ C:\Windows\setuperr.log 2013-08-04 08:19 - 2013-06-09 08:35 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-08-04 08:19 - 2013-01-17 00:28 - 00001912 _____ C:\Windows\epplauncher.mif 2013-08-04 08:17 - 2013-08-04 08:15 - 19159080 _____ (Sony Ericsson ) C:\Users\Mira\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe 2013-07-26 05:13 - 2013-08-15 08:40 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 05:13 - 2013-08-15 08:40 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 05:13 - 2013-08-15 08:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 05:12 - 2013-08-15 08:41 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 05:12 - 2013-08-15 08:40 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 05:11 - 2013-08-15 08:40 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 05:11 - 2013-08-15 08:40 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 04:49 - 2013-08-15 08:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 03:59 - 2013-08-15 08:40 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 15:21 ==================== End Of Log ============================ Und hier noch das Additional nach dem ersten Scan: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-08-2013 Ran by Mira at 2013-08-25 16:06:25 Running from C:\Users\Mira\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader XI (11.0.03) - Deutsch (Version: 11.0.03) Apple Application Support (Version: 2.3.3) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (Version: 2.1.3.127) Audacity 2.0.3 (Version: 2.0.3) Avidemux 2.6 (32-bit) (Version: 2.6.4.8696) Avira Free Antivirus (Version: 13.0.0.3885) Bonjour (Version: 3.0.0.10) CCleaner (Version: 4.02) Citavi (Version: 3.4.0.2) DAEMON Tools Pro (Version: 5.2.0.0348) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Free Audio Converter version 5.0.23.320 (Version: 5.0.23.320) Google Talk Plugin (Version: 4.5.2.14837) HP Quick Launch Buttons (Version: 6.50.14.1) Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.1930) Intel(R) TV Wizard iTunes (Version: 11.0.2.26) Jewel Legends Atlantis 1.00 (Version: 1.00) Logic Fun 4.8 Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Language Pack 2010 - German/Deutsch (Version: 14.0.7015.1000) Microsoft Office O MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook Connector (Version: 14.0.5118.5000) Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office SharePoint Designer MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office X MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (Version: 14.0.5120.5000) Microsoft Security Client (Version: 4.3.0215.0) Microsoft Security Essentials (Version: 4.3.215.0) Microsoft SharePoint Designer 2010 Service Pack 1 (SP1) Microsoft SkyDrive (HKCU Version: 17.0.2010.0530) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) OpenOffice.org 3.4.1 (Version: 3.41.9593) QLBCASL (Version: 6.40.17.2) QuickTime (Version: 7.73.80.64) Rolling Idols Lost City 1.00 (Version: 1.00) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition Skype™ 6.1 (Version: 6.1.129) Spybot - Search & Destroy (Version: 2.1.21) TheTreasuresOfMontezuma2 (Version: 1.0) Tiny Toon Adventures - Buster's Hidden Treasure Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Designer 2010 (KB2553459) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition VLC media player 2.0.5 (Version: 2.0.5) YTD Video Downloader 3.9.6 (Version: 3.9.6) Zuma's Revenge! (Version: 1.0) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {066F98B3-F5B4-430C-9722-3AC358AB43B0} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe No File Task: {081E91AD-DEFF-4A72-8FC2-22F208B75395} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe No File Task: {1FAFD4E5-7B7E-4C49-B476-5D284CC1A9EE} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {2012DECA-ED88-4D09-987E-962775291A71} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA => C:\Users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.) Task: {212D94FB-28D8-4B8E-B0C0-A9380AC109D3} - System32\Tasks\Google Updater and Installer => C:\Users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.) Task: {27AE2671-CB34-4F45-BAE9-2279F1653042} - System32\Tasks\{B55723B1-A482-4ECB-960B-BEB009111A98} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {2B44E3FE-8B19-4375-9518-E72C73026AB7} - System32\Tasks\{97F47321-1F9E-42E6-8454-D1260A35F730} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {44D14AB5-6FFC-48B6-912C-5B25790FC28C} - System32\Tasks\{D4FAA3DA-B324-4A5C-87AA-2C42B774E6E7} => C:\Program Files\Canon\CameraWindowLauncher\CameraLauncher.exe No File Task: {5753AAA5-0C87-4BF9-8DD3-C3D1DE296F81} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe No File Task: {57B14918-0388-4DE4-B336-FE1991D1A1BA} - System32\Tasks\{D848EFD7-643E-499E-9C54-1C358A2139A8} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {58D14D21-FE00-4035-AC78-BBB4809943E9} - System32\Tasks\{6294D1BF-1F07-4F7E-8AE1-BF86F8429BC9} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {6814A9E5-1512-4EB5-9B69-7B37498FD488} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation) Task: {859C1BA8-D6C8-44D4-96FC-C5C614B1ED0F} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {88B565E1-7390-43C3-828D-86D37E81F47D} - System32\Tasks\{A8A4493D-7415-4C7A-B11F-5B85E11EDC9B} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {9A4BF635-187B-4639-A5E4-EDC32CF87948} - System32\Tasks\{DE1E38C0-9B52-4B30-BB3A-F4E719763403} => C:\Program Files\Canon\CameraWindowLauncher\CameraLauncher.exe No File Task: {B5E93AAC-8EF7-48CD-A365-69AF2EA53CE1} - System32\Tasks\{F88EBC64-5844-455D-B0DF-0831EABFE54F} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {C26C78E6-F95E-4BDA-9BD6-071D819D6C20} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd) Task: {C60D5456-3CBA-4382-A8D0-C634C59DE5DC} - System32\Tasks\{E5165796-1B04-46DF-A511-085FDAAD5D40} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: {D81A3C4E-3398-44AA-9928-D696275060C0} - \AutoKMS No Task File Task: {E2537122-52C5-4C27-9DDA-1C8DAEA72606} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core => C:\Users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17] (Google Inc.) Task: {E2B8FD92-CC4F-4891-8828-9F3AF1D1F6DE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-24] (Adobe Systems Incorporated) Task: {ED6E728E-DB63-41B6-9D33-5CA6685703FF} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-06-20] (Microsoft Corporation) Task: {FDECB34A-2AED-47A4-90A1-9A9EE0F416CD} - System32\Tasks\{4343E85B-78DB-4583-BC79-1769251844FF} => C:\Users\Mira\Desktop\Games\Shit\luxor_2_x86.exe No File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job => C:\Users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job => C:\Users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/25/2013 01:23:41 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 47393 Error: (08/25/2013 01:23:41 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 47393 Error: (08/25/2013 01:23:41 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/25/2013 01:23:26 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 31808 Error: (08/25/2013 01:23:26 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 31808 Error: (08/25/2013 01:23:26 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/25/2013 01:23:10 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15709 Error: (08/25/2013 01:23:10 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15709 Error: (08/25/2013 01:23:10 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/25/2013 00:53:05 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 23.0.1.4974, Zeitstempel: 0x520bc252 Name des fehlerhaften Moduls: xul.dll, Version: 23.0.1.4974, Zeitstempel: 0x520bc166 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0017af08 ID des fehlerhaften Prozesses: 0x128 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 System errors: ============= Error: (08/25/2013 11:24:40 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (08/25/2013 11:24:40 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht. Error: (08/25/2013 01:19:08 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/25/2013 01:19:03 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (08/25/2013 01:18:54 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (08/25/2013 01:10:21 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Adobe Flash Player Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (08/25/2013 01:10:20 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Adobe Flash Player Update Service erreicht. Error: (08/24/2013 11:36:23 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 24.08.2013 um 23:34:47 unerwartet heruntergefahren. Error: (08/24/2013 10:16:44 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (08/24/2013 09:34:31 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 106.0.0.0 Aktualisierungsquelle: %NT-AUTORITÄT51 Aktualisierungsphase: 4.3.0215.00 Quellpfad: 4.3.0215.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\NETZWERKDIENST Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Microsoft Office Sessions: ========================= Error: (08/25/2013 01:23:41 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 47393 Error: (08/25/2013 01:23:41 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 47393 Error: (08/25/2013 01:23:41 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/25/2013 01:23:26 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 31808 Error: (08/25/2013 01:23:26 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 31808 Error: (08/25/2013 01:23:26 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/25/2013 01:23:10 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15709 Error: (08/25/2013 01:23:10 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15709 Error: (08/25/2013 01:23:10 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/25/2013 00:53:05 PM) (Source: Application Error)(User: ) Description: firefox.exe23.0.1.4974520bc252xul.dll23.0.1.4974520bc166c00000050017af0812801cea17775b80e31C:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Mozilla Firefox\xul.dll84e71e62-0d74-11e3-9a42-001e376878f4 ==================== Memory info =========================== Percentage of memory in use: 78% Total physical RAM: 1015.3 MB Available physical RAM: 221.03 MB Total Pagefile: 2039.3 MB Available Pagefile: 696.05 MB Total Virtual: 2047.88 MB Available Virtual: 1897.64 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:29.66 GB) (Free:8.56 GB) NTFS Drive d: () (Fixed) (Total:82.03 GB) (Free:21.57 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 95AA95AA) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=30 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=82 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Vielen Dank schon einmal, habe beide Dateien auch noch sicherheitshalber angehängt. Viele liebe Grüße Mira |
25.08.2013, 19:42 | #4 | |
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/NeopCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.08.2013, 21:49 | #5 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo, vielen Dank für die Nachricht. Habe alles gemacht. Leider habe ich beim ersten Mal vergessen ComboFix auf dem Desktop zu speichern, deshalb hab ich nun alles zweimal gemacht. Beim zweiten Mal war Combofix auf dem Desktop gespeichert, beim ersten Mal nicht. Ich poste nun mal alles. Hier der Combofix-Log 1 ohne Desktop-Speicherung: Code:
ATTFilter ComboFix 13-08-25.01 - Mira 25.08.2013 22:31:21.1.2 - x86 Microsoft Windows 7 Professional N 6.1.7601.1.1252.49.1031.18.1015.173 [GMT 2:00] ausgeführt von:: c:\users\Mira\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\security\Database\tmp.edb . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-25 bis 2013-08-25 )))))))))))))))))))))))))))))) . . 2013-08-25 20:38 . 2013-08-25 20:39 -------- d-----w- c:\users\Mira\AppData\Local\temp 2013-08-25 20:38 . 2013-08-25 20:38 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-25 20:22 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1999145B-6BE5-4357-9C19-89419BC35233}\mpengine.dll 2013-08-25 14:05 . 2013-08-25 14:05 -------- d-----w- C:\FRST 2013-08-25 10:04 . 2013-08-25 10:04 -------- d-----w- c:\users\Mira\AppData\Roaming\Avira 2013-08-24 23:19 . 2013-08-24 23:15 67168 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-08-24 22:56 . 2013-07-18 06:02 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-08-24 22:56 . 2013-03-06 14:13 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-08-24 22:56 . 2013-07-18 06:02 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-08-24 22:51 . 2013-08-24 22:59 -------- d-----w- c:\programdata\Avira 2013-08-24 22:51 . 2013-08-24 22:51 -------- d-----w- c:\program files\Avira 2013-08-24 21:51 . 2013-08-25 20:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2013-08-24 21:50 . 2009-01-25 11:14 15224 ----a-w- c:\windows\system32\sdnclean.exe 2013-08-24 21:50 . 2013-08-24 21:51 -------- d-----w- c:\program files\Spybot - Search & Destroy 2 2013-08-24 19:47 . 2013-08-24 19:45 697992 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5346A05D-3D98-4BC7-8D24-C440DB68108F}\gapaengine.dll 2013-08-24 19:46 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-08-20 21:21 . 2013-08-20 21:21 -------- d-----w- c:\users\Mira\AppData\Roaming\CANON INC 2013-08-20 21:09 . 2013-08-20 21:09 -------- d-----w- c:\users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 21:05 . 2013-08-20 21:05 -------- d-----w- c:\program files\Common Files\Canon_Inc_IC 2013-08-20 21:02 . 2013-08-20 21:02 -------- d-----w- c:\users\Mira\AppData\Roaming\canon 2013-08-20 21:01 . 2013-08-20 21:02 -------- d-----w- c:\programdata\Canon_Inc_IC 2013-08-15 06:41 . 2013-07-26 02:49 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-08-15 06:37 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-15 06:37 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-15 06:37 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll 2013-08-15 06:37 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll 2013-08-15 06:37 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-15 06:37 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-15 06:37 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-15 06:37 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-15 06:37 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll 2013-08-15 06:36 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys 2013-08-15 06:36 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-24 21:04 . 2013-01-21 19:33 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-08-24 21:04 . 2013-01-21 19:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-07-18 06:32 . 2013-06-14 11:03 698504 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2013-07-17 00:14 . 2013-07-17 00:14 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-07-17 00:14 . 2013-07-17 00:14 185344 ----a-w- c:\windows\system32\elshyph.dll 2013-07-17 00:14 . 2013-07-17 00:14 158720 ----a-w- c:\windows\system32\msls31.dll 2013-07-17 00:14 . 2013-07-17 00:14 523264 ----a-w- c:\windows\system32\vbscript.dll 2013-07-17 00:14 . 2013-07-17 00:14 150528 ----a-w- c:\windows\system32\iexpress.exe 2013-07-17 00:14 . 2013-07-17 00:14 138752 ----a-w- c:\windows\system32\wextract.exe 2013-07-17 00:14 . 2013-07-17 00:14 137216 ----a-w- c:\windows\system32\ieUnatt.exe 2013-07-17 00:14 . 2013-07-17 00:14 12800 ----a-w- c:\windows\system32\mshta.exe 2013-07-17 00:14 . 2013-07-17 00:14 38400 ----a-w- c:\windows\system32\imgutil.dll 2013-07-17 00:14 . 2013-07-17 00:14 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-07-17 00:14 . 2013-07-17 00:14 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-07-17 00:14 . 2013-07-17 00:14 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-07-17 00:14 . 2013-07-17 00:14 61952 ----a-w- c:\windows\system32\tdc.ocx 2013-07-17 00:14 . 2013-07-17 00:14 361984 ----a-w- c:\windows\system32\html.iec 2013-07-17 00:14 . 2013-07-17 00:14 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-07-17 00:14 . 2013-07-17 00:14 23040 ----a-w- c:\windows\system32\licmgr10.dll 2013-07-17 00:14 . 2013-07-17 00:14 1441280 ----a-w- c:\windows\system32\inetcpl.cpl 2013-06-18 19:50 . 2013-06-18 19:50 211560 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-06-18 19:50 . 2012-08-30 20:03 107392 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-06-05 03:05 . 2013-07-11 06:20 2347520 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 04:53 . 2013-07-11 06:20 509440 ----a-w- c:\windows\system32\qedit.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18706176] "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 995176] "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-07-18 345144] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Google Update"="c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe" /c . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime . R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688] R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-06-20 295376] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-07-18 589368] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-06 37352] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-01 242240] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-07-18 84024] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168] S3 ATSwpWDF;AuthenTec TruePrint WBF Driver;c:\windows\system32\DRIVERS\ATSwpWDF.sys [2012-10-18 971752] S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896] S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - SSMDRV . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc . Inhalt des "geplante Tasks" Ordners . 2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-21 21:04] . 2013-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job - c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38] . 2013-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job - c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Notify-SDWinLogon - SDWinLogon.dll SafeBoot-Wdf01000.sys AddRemove-Free Audio Converter_is1 - c:\program files\Common Files\DVDVideoSoft\lib\Uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-25 22:42:05 ComboFix-quarantined-files.txt 2013-08-25 20:42 . Vor Suchlauf: 8.352.518.144 Bytes frei Nach Suchlauf: 8.477.544.448 Bytes frei . - - End Of File - - 967C16BAEC0421E5E57622D261AD4555 A36C5E4F47E84449FF07ED3517B43A31 Und hier der 2. Log mit Speicherung auf dem Desktop: Code:
ATTFilter ComboFix 13-08-25.01 - Mira 25.08.2013 23:16:44.2.2 - x86 Microsoft Windows 7 Professional N 6.1.7601.1.1252.49.1031.18.1015.220 [GMT 2:00] ausgeführt von:: c:\users\Mira\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-25 bis 2013-08-25 )))))))))))))))))))))))))))))) . . 2013-08-25 21:24 . 2013-08-25 21:24 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-25 20:51 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9AD9D156-7551-4EE6-9970-93F16286FB3C}\mpengine.dll 2013-08-25 20:42 . 2013-08-25 21:24 -------- d-----w- c:\users\Mira\AppData\Local\temp 2013-08-25 14:05 . 2013-08-25 14:05 -------- d-----w- C:\FRST 2013-08-25 10:04 . 2013-08-25 10:04 -------- d-----w- c:\users\Mira\AppData\Roaming\Avira 2013-08-24 23:19 . 2013-08-24 23:15 67168 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-08-24 22:56 . 2013-07-18 06:02 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-08-24 22:56 . 2013-03-06 14:13 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-08-24 22:56 . 2013-07-18 06:02 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-08-24 22:51 . 2013-08-24 22:59 -------- d-----w- c:\programdata\Avira 2013-08-24 22:51 . 2013-08-24 22:51 -------- d-----w- c:\program files\Avira 2013-08-24 21:51 . 2013-08-25 20:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2013-08-24 21:50 . 2009-01-25 11:14 15224 ----a-w- c:\windows\system32\sdnclean.exe 2013-08-24 21:50 . 2013-08-24 21:51 -------- d-----w- c:\program files\Spybot - Search & Destroy 2 2013-08-24 19:47 . 2013-08-24 19:45 697992 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5346A05D-3D98-4BC7-8D24-C440DB68108F}\gapaengine.dll 2013-08-24 19:46 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-08-20 21:21 . 2013-08-20 21:21 -------- d-----w- c:\users\Mira\AppData\Roaming\CANON INC 2013-08-20 21:09 . 2013-08-20 21:09 -------- d-----w- c:\users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 21:05 . 2013-08-20 21:05 -------- d-----w- c:\program files\Common Files\Canon_Inc_IC 2013-08-20 21:02 . 2013-08-20 21:02 -------- d-----w- c:\users\Mira\AppData\Roaming\canon 2013-08-20 21:01 . 2013-08-20 21:02 -------- d-----w- c:\programdata\Canon_Inc_IC 2013-08-15 06:41 . 2013-07-26 02:49 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-08-15 06:37 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-15 06:37 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-15 06:37 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll 2013-08-15 06:37 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll 2013-08-15 06:37 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-15 06:37 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-15 06:37 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-15 06:37 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-15 06:37 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll 2013-08-15 06:36 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys 2013-08-15 06:36 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-24 21:04 . 2013-01-21 19:33 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-08-24 21:04 . 2013-01-21 19:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-07-18 06:32 . 2013-06-14 11:03 698504 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2013-07-17 00:14 . 2013-07-17 00:14 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-07-17 00:14 . 2013-07-17 00:14 185344 ----a-w- c:\windows\system32\elshyph.dll 2013-07-17 00:14 . 2013-07-17 00:14 158720 ----a-w- c:\windows\system32\msls31.dll 2013-07-17 00:14 . 2013-07-17 00:14 523264 ----a-w- c:\windows\system32\vbscript.dll 2013-07-17 00:14 . 2013-07-17 00:14 150528 ----a-w- c:\windows\system32\iexpress.exe 2013-07-17 00:14 . 2013-07-17 00:14 138752 ----a-w- c:\windows\system32\wextract.exe 2013-07-17 00:14 . 2013-07-17 00:14 137216 ----a-w- c:\windows\system32\ieUnatt.exe 2013-07-17 00:14 . 2013-07-17 00:14 12800 ----a-w- c:\windows\system32\mshta.exe 2013-07-17 00:14 . 2013-07-17 00:14 38400 ----a-w- c:\windows\system32\imgutil.dll 2013-07-17 00:14 . 2013-07-17 00:14 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-07-17 00:14 . 2013-07-17 00:14 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-07-17 00:14 . 2013-07-17 00:14 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-07-17 00:14 . 2013-07-17 00:14 61952 ----a-w- c:\windows\system32\tdc.ocx 2013-07-17 00:14 . 2013-07-17 00:14 361984 ----a-w- c:\windows\system32\html.iec 2013-07-17 00:14 . 2013-07-17 00:14 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-07-17 00:14 . 2013-07-17 00:14 23040 ----a-w- c:\windows\system32\licmgr10.dll 2013-07-17 00:14 . 2013-07-17 00:14 1441280 ----a-w- c:\windows\system32\inetcpl.cpl 2013-06-18 19:50 . 2013-06-18 19:50 211560 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-06-18 19:50 . 2012-08-30 20:03 107392 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-06-05 03:05 . 2013-07-11 06:20 2347520 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 04:53 . 2013-07-11 06:20 509440 ----a-w- c:\windows\system32\qedit.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18706176] "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 995176] "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-07-18 345144] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Google Update"="c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe" /c . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime . R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688] R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-06-20 295376] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-07-18 589368] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-06 37352] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-01 242240] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-07-18 84024] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168] S3 ATSwpWDF;AuthenTec TruePrint WBF Driver;c:\windows\system32\DRIVERS\ATSwpWDF.sys [2012-10-18 971752] S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896] S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc . Inhalt des "geplante Tasks" Ordners . 2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-21 21:04] . 2013-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job - c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38] . 2013-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job - c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default\ . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a "{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0, b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:00,32,9b,af,92,08,ce,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b1,06,18,dc,58,54,00,4b,bb,28,d1,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b1,06,18,dc,58,54,00,4b,bb,28,d1,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-25 23:27:49 ComboFix-quarantined-files.txt 2013-08-25 21:27 ComboFix2.txt 2013-08-25 20:42 . Vor Suchlauf: 8.638.435.328 Bytes frei Nach Suchlauf: 9.067.077.632 Bytes frei . - - End Of File - - 59E179108273EC769A566F0508FFCE64 A36C5E4F47E84449FF07ED3517B43A31 Nochmals meine Frage: Sollte ich meine Passwörter ändern (von anderem PC vielleicht?), meine Daten sichern oder ist dann auch der jeweilige Stick infiziert? Online Banking sperren oder so etwas zur Sicherheit oder besteht dafür kein Anlass? Liebe Grüße Mira Geändert von TheMissMico (25.08.2013 um 22:34 Uhr) |
26.08.2013, 08:57 | #6 | |
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/NeopZitat:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop |
26.08.2013, 13:24 | #7 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo, vielen Dank für die Nachricht. Habe alles gemacht. Hier die Logs (und auch nochmal alles im Anhang): Malwarebytes-Antimalware: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.26.01 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16660 Mira :: MIRA-PC [Administrator] Schutz: Aktiviert 26.08.2013 13:01:38 mbam-log-2013-08-26 (13-01-38).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214761 Laufzeit: 12 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 3 C:\Users\Mira\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mira\AppData\Roaming\OpenCandy\12A7E9CC48D64222A930523D1C6430A4 (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mira\AppData\Roaming\OpenCandy\BBEE9DFE9511418BBD36A6BD517D15CB (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 2 C:\Users\Mira\AppData\Roaming\OpenCandy\12A7E9CC48D64222A930523D1C6430A4\TuneUpUtilities2013-2200217_de-DE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Mira\AppData\Roaming\OpenCandy\BBEE9DFE9511418BBD36A6BD517D15CB\speedupmypcDE.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleanerR0: Code:
ATTFilter # AdwCleaner v3.001 - Report created 26/08/2013 at 13:37:23 # Updated 24/08/2013 by Xplode # Operating System : Windows 7 Professional N Service Pack 1 (32 bits) # Username : Mira - MIRA-PC # Running from : C:\Users\Mira\Downloads\adwcleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\Users\Mira\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk File Found : C:\Users\Mira\Desktop\Startfenster.lnk Folder Found C:\ProgramData\Alawar Stargaze ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\APN PIP Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Found : HKLM\SOFTWARE\Classes\speedupmypc Key Found : HKLM\Software\PIP Key Found : HKLM\Software\Uniblue\DriverScanner ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1301 octets] - [26/08/2013 13:37:23] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1361 octets] ########## AdwCleanerS0: Code:
ATTFilter # AdwCleaner v3.001 - Report created 26/08/2013 at 13:38:45 # Updated 24/08/2013 by Xplode # Operating System : Windows 7 Professional N Service Pack 1 (32 bits) # Username : Mira - MIRA-PC # Running from : C:\Users\Mira\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Alawar Stargaze File Deleted : C:\Users\Mira\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk File Deleted : C:\Users\Mira\Desktop\Startfenster.lnk ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKCU\Software\APN PIP Key Deleted : HKLM\Software\PIP Key Deleted : HKLM\Software\Uniblue\DriverScanner ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1441 octets] - [26/08/2013 13:37:23] AdwCleaner[S0].txt - [1384 octets] - [26/08/2013 13:38:45] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1444 octets] ########## Junkware Removal Tool: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.4 (08.22.2013:1) OS: Windows 7 Professional N x86 Ran by Mira on 26.08.2013 at 13:55:00,43 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\uniblue ~~~ Files Successfully deleted: [File] "C:\Users\Mira\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader" ~~~ FireFox Emptied folder: C:\Users\Mira\AppData\Roaming\mozilla\firefox\profiles\z00lni02.default\minidumps [239 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 26.08.2013 at 13:57:44,80 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frisches FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-08-2013 Ran by Mira (administrator) on 26-08-2013 14:16:10 Running from C:\Users\Mira\Downloads Microsoft Windows 7 Professional N Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation) HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-18] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18706176 2013-01-08] (Skype Technologies S.A.) HKCU\...\Run: [DAEMON Tools Pro Agent] - C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Mira\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Mira\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-18] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-18] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation) S2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-02-01] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 catchme; \??\C:\Users\Mira\AppData\Local\Temp\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-26 14:15 - 2013-08-26 14:16 - 01070979 _____ (Farbar) C:\Users\Mira\Downloads\FRST.exe 2013-08-26 13:57 - 2013-08-26 13:57 - 00001156 _____ C:\Users\Mira\Desktop\JRT.txt 2013-08-26 13:54 - 2013-08-26 13:54 - 00000000 ____D C:\Windows\ERUNT 2013-08-26 13:49 - 2013-08-26 13:50 - 01021434 _____ (Thisisu) C:\Users\Mira\Downloads\JRT.exe 2013-08-26 13:36 - 2013-08-26 13:38 - 00000000 ____D C:\AdwCleaner 2013-08-26 13:33 - 2013-08-26 13:35 - 00994642 _____ C:\Users\Mira\Downloads\adwcleaner.exe 2013-08-26 12:55 - 2013-08-26 12:55 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-26 12:55 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-26 12:53 - 2013-08-26 12:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mira\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-25 23:32 - 2013-08-25 23:32 - 00014856 _____ C:\ComboFix2.txt 2013-08-25 23:27 - 2013-08-25 23:27 - 00014856 _____ C:\ComboFix.txt 2013-08-25 23:01 - 2013-08-25 23:02 - 05113393 ____R (Swearware) C:\Users\Mira\Desktop\ComboFix.exe 2013-08-25 22:26 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-25 22:26 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-25 22:26 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-25 22:17 - 2013-08-25 23:27 - 00000000 ____D C:\Qoobox 2013-08-25 22:16 - 2013-08-25 22:40 - 00000000 ____D C:\Windows\erdnt 2013-08-25 22:12 - 2013-08-25 22:13 - 05113393 ____R (Swearware) C:\Users\Mira\Downloads\ComboFix.exe 2013-08-25 16:06 - 2013-08-25 16:06 - 00018279 _____ C:\Users\Mira\Downloads\Addition.txt 2013-08-25 16:05 - 2013-08-25 16:05 - 00000000 ____D C:\FRST 2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Avira 2013-08-25 11:23 - 2013-08-26 13:21 - 00097724 _____ C:\Windows\PFRO.log 2013-08-25 01:19 - 2013-08-25 01:15 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-25 01:01 - 2013-08-25 01:01 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-25 00:56 - 2013-07-18 08:02 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-25 00:56 - 2013-07-18 08:02 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-25 00:56 - 2013-03-06 16:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-08-25 00:56 - 2012-08-27 15:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-08-25 00:51 - 2013-08-25 00:59 - 00000000 ____D C:\ProgramData\Avira 2013-08-25 00:51 - 2013-08-25 00:51 - 00000000 ____D C:\Program Files\Avira 2013-08-25 00:22 - 2013-08-25 00:29 - 110344048 _____ C:\Users\Mira\Downloads\avira_free4045_antivirus_de.exe 2013-08-24 23:51 - 2013-08-25 22:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-24 23:51 - 2013-08-24 23:51 - 00002119 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-08-24 23:50 - 2013-08-24 23:51 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-08-24 23:50 - 2009-01-25 13:14 - 00015224 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe 2013-08-24 23:43 - 2013-08-24 23:46 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(5).exe 2013-08-24 23:42 - 2013-08-24 23:44 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(4).exe 2013-08-24 23:39 - 2013-08-24 23:41 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(3).exe 2013-08-24 23:38 - 2013-08-24 23:40 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(2).exe 2013-08-24 23:38 - 2013-08-24 23:40 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(1).exe 2013-08-24 23:34 - 2013-08-24 23:35 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2.exe 2013-08-24 22:44 - 2013-08-24 22:44 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-21 09:11 - 2013-08-21 09:12 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-21 09:03 - 2013-08-21 09:03 - 00000000 ____D C:\Users\Mira\Documents\Canon Utilities 2013-08-20 23:21 - 2013-08-20 23:21 - 00000000 ____D C:\Users\Mira\AppData\Roaming\CANON INC 2013-08-20 23:11 - 2013-08-20 23:11 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles 2013-08-20 23:09 - 2013-08-20 23:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\Common Files\Canon_Inc_IC 2013-08-20 23:02 - 2013-08-20 23:02 - 00000000 ____D C:\Users\Mira\AppData\Roaming\canon 2013-08-20 23:01 - 2013-08-20 23:02 - 00000000 ____D C:\ProgramData\Canon_Inc_IC 2013-08-15 08:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 08:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 08:40 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 08:40 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 08:40 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 08:40 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 08:40 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 08:40 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 08:40 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 08:37 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-15 08:37 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 08:37 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 08:37 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 08:37 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 08:37 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-15 08:36 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 08:36 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-08 16:54 - 2013-08-08 16:55 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3(1).zip 2013-08-08 16:42 - 2013-08-08 16:43 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3.zip 2013-08-07 09:30 - 2013-08-07 09:30 - 00009439 _____ C:\Users\Mira\Desktop\CHORDS AIR.odt 2013-08-05 13:06 - 2013-08-26 13:41 - 00003304 _____ C:\Windows\setupact.log 2013-08-05 13:06 - 2013-08-05 13:06 - 00000000 _____ C:\Windows\setuperr.log 2013-08-04 08:15 - 2013-08-04 08:17 - 19159080 _____ (Sony Ericsson ) C:\Users\Mira\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe ==================== One Month Modified Files and Folders ======= 2013-08-26 14:16 - 2013-08-26 14:15 - 01070979 _____ (Farbar) C:\Users\Mira\Downloads\FRST.exe 2013-08-26 14:16 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default 2013-08-26 14:04 - 2013-02-17 22:39 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job 2013-08-26 14:04 - 2013-01-21 21:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-26 13:57 - 2013-08-26 13:57 - 00001156 _____ C:\Users\Mira\Desktop\JRT.txt 2013-08-26 13:54 - 2013-08-26 13:54 - 00000000 ____D C:\Windows\ERUNT 2013-08-26 13:51 - 2009-07-14 06:02 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-26 13:51 - 2009-07-14 06:02 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-26 13:50 - 2013-08-26 13:49 - 01021434 _____ (Thisisu) C:\Users\Mira\Downloads\JRT.exe 2013-08-26 13:50 - 2013-01-17 00:08 - 02047539 _____ C:\Windows\WindowsUpdate.log 2013-08-26 13:41 - 2013-08-05 13:06 - 00003304 _____ C:\Windows\setupact.log 2013-08-26 13:41 - 2013-01-26 17:49 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Skype 2013-08-26 13:41 - 2009-07-14 06:17 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-26 13:38 - 2013-08-26 13:36 - 00000000 ____D C:\AdwCleaner 2013-08-26 13:35 - 2013-08-26 13:33 - 00994642 _____ C:\Users\Mira\Downloads\adwcleaner.exe 2013-08-26 13:21 - 2013-08-25 11:23 - 00097724 _____ C:\Windows\PFRO.log 2013-08-26 12:55 - 2013-08-26 12:55 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-26 12:53 - 2013-08-26 12:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mira\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-25 23:32 - 2013-08-25 23:32 - 00014856 _____ C:\ComboFix2.txt 2013-08-25 23:27 - 2013-08-25 23:27 - 00014856 _____ C:\ComboFix.txt 2013-08-25 23:27 - 2013-08-25 22:17 - 00000000 ____D C:\Qoobox 2013-08-25 23:25 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2013-08-25 23:02 - 2013-08-25 23:01 - 05113393 ____R (Swearware) C:\Users\Mira\Desktop\ComboFix.exe 2013-08-25 22:42 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-08-25 22:40 - 2013-08-25 22:16 - 00000000 ____D C:\Windows\erdnt 2013-08-25 22:24 - 2013-08-24 23:51 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-25 22:13 - 2013-08-25 22:12 - 05113393 ____R (Swearware) C:\Users\Mira\Downloads\ComboFix.exe 2013-08-25 16:06 - 2013-08-25 16:06 - 00018279 _____ C:\Users\Mira\Downloads\Addition.txt 2013-08-25 16:05 - 2013-08-25 16:05 - 00000000 ____D C:\FRST 2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Avira 2013-08-25 01:15 - 2013-08-25 01:19 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-25 01:01 - 2013-08-25 01:01 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-25 00:59 - 2013-08-25 00:51 - 00000000 ____D C:\ProgramData\Avira 2013-08-25 00:51 - 2013-08-25 00:51 - 00000000 ____D C:\Program Files\Avira 2013-08-25 00:29 - 2013-08-25 00:22 - 110344048 _____ C:\Users\Mira\Downloads\avira_free4045_antivirus_de.exe 2013-08-25 00:04 - 2013-02-17 22:39 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job 2013-08-24 23:51 - 2013-08-24 23:51 - 00002119 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-08-24 23:51 - 2013-08-24 23:50 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-08-24 23:46 - 2013-08-24 23:43 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(5).exe 2013-08-24 23:44 - 2013-08-24 23:42 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(4).exe 2013-08-24 23:41 - 2013-08-24 23:39 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(3).exe 2013-08-24 23:40 - 2013-08-24 23:38 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(2).exe 2013-08-24 23:40 - 2013-08-24 23:38 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(1).exe 2013-08-24 23:36 - 2013-01-17 00:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-24 23:35 - 2013-08-24 23:34 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2.exe 2013-08-24 23:05 - 2013-01-17 00:26 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Mozilla 2013-08-24 23:04 - 2013-01-21 21:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-08-24 23:04 - 2013-01-21 21:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-08-24 22:44 - 2013-08-24 22:44 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-22 14:17 - 2013-01-26 13:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\vlc 2013-08-22 14:14 - 2010-11-20 23:03 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 09:12 - 2013-08-21 09:11 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-21 09:03 - 2013-08-21 09:03 - 00000000 ____D C:\Users\Mira\Documents\Canon Utilities 2013-08-20 23:21 - 2013-08-20 23:21 - 00000000 ____D C:\Users\Mira\AppData\Roaming\CANON INC 2013-08-20 23:11 - 2013-08-20 23:11 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles 2013-08-20 23:09 - 2013-08-20 23:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\Common Files\Canon_Inc_IC 2013-08-20 23:02 - 2013-08-20 23:02 - 00000000 ____D C:\Users\Mira\AppData\Roaming\canon 2013-08-20 23:02 - 2013-08-20 23:01 - 00000000 ____D C:\ProgramData\Canon_Inc_IC 2013-08-16 07:44 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-08-15 18:21 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 10:37 - 2013-01-17 00:04 - 00000000 ____D C:\Windows\Panther 2013-08-15 10:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-15 08:48 - 2013-07-25 00:02 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 08:46 - 2013-02-18 17:04 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-08 16:55 - 2013-08-08 16:54 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3(1).zip 2013-08-08 16:43 - 2013-08-08 16:42 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3.zip 2013-08-07 21:36 - 2013-01-26 13:14 - 00000000 ____D C:\Users\Mira\AppData\Roaming\dvdcss 2013-08-07 09:30 - 2013-08-07 09:30 - 00009439 _____ C:\Users\Mira\Desktop\CHORDS AIR.odt 2013-08-06 02:28 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-08-05 13:06 - 2013-08-05 13:06 - 00000000 _____ C:\Windows\setuperr.log 2013-08-04 08:19 - 2013-06-09 08:35 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-08-04 08:19 - 2013-01-17 00:28 - 00001912 _____ C:\Windows\epplauncher.mif 2013-08-04 08:17 - 2013-08-04 08:15 - 19159080 _____ (Sony Ericsson ) C:\Users\Mira\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe Files to move or delete: ==================== C:\Users\Mira\AppData\Local\Temp\Quarantine.exe C:\Users\Mira\AppData\Local\Temp\jrt\erunt\ERUNT.EXE ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 15:21 ==================== End Of Log ============================ Vielen Dank! Liebe Grüße Mira |
26.08.2013, 17:56 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/NeopESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.08.2013, 18:19 | #9 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo Schrauber, habe alle meine Medien (externe Festplatte und USB-Sticks) gerade nicht vor Ort um sie anzuschließen. Dennoch den Scan und Weiteres durchführen? Liebe Grüße Mira Geändert von TheMissMico (26.08.2013 um 18:26 Uhr) |
26.08.2013, 18:26 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Nein das ist ein Onlinescan zum Finden von Resten, und da würde es sich anbieten gleich alles zu scannen. Wenn Du die Medien nicht da hast dann eben nur den Rechner
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.08.2013, 21:10 | #11 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo, ok danke. Habe den Scan schon gemacht. Mache nun noch den Security Check. Sorry für die Frage, aber beim Online Scan wurden 4 Threads gefunden, wieso sollte ich die denn nicht entfernen lassen, also das Häkchen hab ich ja weggemacht am Anfang?! Denn dann sind die Threads ja noch drauf? Hier mal alle Logs: OnlineScanner: Code:
ATTFilter # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0bbc841cff32e44096b4bbf97db4fd2d # engine=14908 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-26 07:32:57 # local_time=2013-08-26 09:32:57 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 95 96895 242968867 37203 0 # compatibility_mode=5893 16776574 100 94 3978832 129176768 0 0 # scanned=92785 # found=4 # cleaned=0 # scan_time=7536 sh=3DD1C3C620107C9C64CF62BF4274D6FFDE0D543B ft=1 fh=565c04b4ce849f23 vn="Win32/StartPage.OPH trojan" ac=I fn="C:\Users\Mira\Downloads\vlc-2.0.5-win32.exe" sh=80E3061B67C65B5D85F70AD6C8D79B8F7F96A1E7 ft=0 fh=0000000000000000 vn="Win32/StartPage.OPH trojan" ac=I fn="D:\MIRA-PC\Backup Set 2013-06-09 081724\Backup Files 2013-06-09 081724\Backup files 4.zip" sh=DD1A17FE270D9477F05A732D2F187DD788E48AC2 ft=0 fh=0000000000000000 vn="Win32/StartPage.OPH trojan" ac=I fn="D:\MIRA-PC\Backup Set 2013-06-25 152720\Backup Files 2013-06-25 152720\Backup files 5.zip" sh=294837753C497B1A95BB65E254F62F2C892BD5E7 ft=0 fh=0000000000000000 vn="Win32/StartPage.OPH trojan" ac=I fn="D:\MIRA-PC\Backup Set 2013-08-11 190010\Backup Files 2013-08-11 190010\Backup files 4.zip" Security Check: Code:
ATTFilter Results of screen317's Security Check version 0.99.72 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Adobe Flash Player 11.8.800.94 Adobe Reader XI Mozilla Firefox (23.0.1) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Spybot Teatimer.exe is disabled! Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-08-2013 Ran by Mira (administrator) on 26-08-2013 22:06:43 Running from C:\Users\Mira\Downloads Microsoft Windows 7 Professional N Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Google) C:\Users\Mira\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\prevhost.exe () C:\Users\Mira\Downloads\SecurityCheck.exe (Microsoft Corporation) C:\Windows\system32\cmd.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation) HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-18] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18706176 2013-01-08] (Skype Technologies S.A.) HKCU\...\Run: [DAEMON Tools Pro Agent] - C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== ProxyServer: localhost:21320 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Mira\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Mira\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Mira\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-18] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-18] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-06-20] (Microsoft Corporation) S2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-02-01] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 catchme; \??\C:\Users\Mira\AppData\Local\Temp\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-26 19:25 - 2013-08-26 19:25 - 00000000 ____D C:\Program Files\ESET 2013-08-26 19:20 - 2013-08-26 19:20 - 02347384 _____ (ESET) C:\Users\Mira\Downloads\esetsmartinstaller_enu.exe 2013-08-26 14:17 - 2013-08-26 14:17 - 00027667 _____ C:\Users\Mira\Desktop\FRST.txt 2013-08-26 14:17 - 2013-08-26 13:38 - 00001524 _____ C:\Users\Mira\Desktop\AdwCleaner[S0].txt 2013-08-26 14:17 - 2013-08-26 13:37 - 00001441 _____ C:\Users\Mira\Desktop\AdwCleaner[R0].txt 2013-08-26 14:15 - 2013-08-26 14:16 - 01070979 _____ (Farbar) C:\Users\Mira\Downloads\FRST.exe 2013-08-26 13:57 - 2013-08-26 13:57 - 00001156 _____ C:\Users\Mira\Desktop\JRT.txt 2013-08-26 13:54 - 2013-08-26 13:54 - 00000000 ____D C:\Windows\ERUNT 2013-08-26 13:49 - 2013-08-26 13:50 - 01021434 _____ (Thisisu) C:\Users\Mira\Downloads\JRT.exe 2013-08-26 13:36 - 2013-08-26 13:38 - 00000000 ____D C:\AdwCleaner 2013-08-26 13:33 - 2013-08-26 13:35 - 00994642 _____ C:\Users\Mira\Downloads\adwcleaner.exe 2013-08-26 12:55 - 2013-08-26 12:55 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-26 12:55 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-26 12:53 - 2013-08-26 12:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mira\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-25 23:32 - 2013-08-25 23:32 - 00014856 _____ C:\ComboFix2.txt 2013-08-25 23:27 - 2013-08-25 23:27 - 00014856 _____ C:\ComboFix.txt 2013-08-25 23:01 - 2013-08-25 23:02 - 05113393 ____R (Swearware) C:\Users\Mira\Desktop\ComboFix.exe 2013-08-25 22:26 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-25 22:26 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-25 22:26 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-25 22:26 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-25 22:17 - 2013-08-25 23:27 - 00000000 ____D C:\Qoobox 2013-08-25 22:16 - 2013-08-25 22:40 - 00000000 ____D C:\Windows\erdnt 2013-08-25 22:12 - 2013-08-25 22:13 - 05113393 ____R (Swearware) C:\Users\Mira\Downloads\ComboFix.exe 2013-08-25 16:06 - 2013-08-25 16:06 - 00018279 _____ C:\Users\Mira\Downloads\Addition.txt 2013-08-25 16:05 - 2013-08-25 16:05 - 00000000 ____D C:\FRST 2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Avira 2013-08-25 11:23 - 2013-08-26 13:21 - 00097724 _____ C:\Windows\PFRO.log 2013-08-25 01:19 - 2013-08-25 01:15 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-25 01:01 - 2013-08-25 01:01 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-25 00:56 - 2013-07-18 08:02 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-25 00:56 - 2013-07-18 08:02 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-25 00:56 - 2013-03-06 16:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-08-25 00:56 - 2012-08-27 15:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-08-25 00:51 - 2013-08-25 00:59 - 00000000 ____D C:\ProgramData\Avira 2013-08-25 00:51 - 2013-08-25 00:51 - 00000000 ____D C:\Program Files\Avira 2013-08-25 00:22 - 2013-08-25 00:29 - 110344048 _____ C:\Users\Mira\Downloads\avira_free4045_antivirus_de.exe 2013-08-24 23:51 - 2013-08-25 22:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-24 23:51 - 2013-08-24 23:51 - 00002119 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-08-24 23:50 - 2013-08-24 23:51 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-08-24 23:50 - 2009-01-25 13:14 - 00015224 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe 2013-08-24 23:43 - 2013-08-24 23:46 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(5).exe 2013-08-24 23:42 - 2013-08-24 23:44 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(4).exe 2013-08-24 23:39 - 2013-08-24 23:41 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(3).exe 2013-08-24 23:38 - 2013-08-24 23:40 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(2).exe 2013-08-24 23:38 - 2013-08-24 23:40 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(1).exe 2013-08-24 23:34 - 2013-08-24 23:35 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2.exe 2013-08-24 22:44 - 2013-08-24 22:44 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-21 09:11 - 2013-08-21 09:12 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-21 09:03 - 2013-08-21 09:03 - 00000000 ____D C:\Users\Mira\Documents\Canon Utilities 2013-08-20 23:21 - 2013-08-20 23:21 - 00000000 ____D C:\Users\Mira\AppData\Roaming\CANON INC 2013-08-20 23:11 - 2013-08-20 23:11 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles 2013-08-20 23:09 - 2013-08-20 23:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\Common Files\Canon_Inc_IC 2013-08-20 23:02 - 2013-08-20 23:02 - 00000000 ____D C:\Users\Mira\AppData\Roaming\canon 2013-08-20 23:01 - 2013-08-20 23:02 - 00000000 ____D C:\ProgramData\Canon_Inc_IC 2013-08-15 08:41 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 08:41 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 08:40 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 08:40 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 08:40 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 08:40 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 08:40 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 08:40 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 08:40 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 08:40 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 08:37 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-15 08:37 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 08:37 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 08:37 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 08:37 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 08:37 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 08:37 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-15 08:36 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 08:36 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-08 16:54 - 2013-08-08 16:55 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3(1).zip 2013-08-08 16:42 - 2013-08-08 16:43 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3.zip 2013-08-07 09:30 - 2013-08-07 09:30 - 00009439 _____ C:\Users\Mira\Desktop\CHORDS AIR.odt 2013-08-05 13:06 - 2013-08-26 19:11 - 00003360 _____ C:\Windows\setupact.log 2013-08-05 13:06 - 2013-08-05 13:06 - 00000000 _____ C:\Windows\setuperr.log 2013-08-04 08:15 - 2013-08-04 08:17 - 19159080 _____ (Sony Ericsson ) C:\Users\Mira\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe ==================== One Month Modified Files and Folders ======= 2013-08-26 22:04 - 2013-02-17 22:39 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job 2013-08-26 22:04 - 2013-01-21 21:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-26 21:58 - 2013-08-26 21:58 - 00891115 _____ C:\Users\Mira\Downloads\SecurityCheck.exe 2013-08-26 21:34 - 2013-01-17 00:08 - 01060297 _____ C:\Windows\WindowsUpdate.log 2013-08-26 20:39 - 2013-01-26 17:49 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Skype 2013-08-26 19:25 - 2013-08-26 19:25 - 00000000 ____D C:\Program Files\ESET 2013-08-26 19:22 - 2009-07-14 06:02 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-26 19:22 - 2009-07-14 06:02 - 00019920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-26 19:20 - 2013-08-26 19:20 - 02347384 _____ (ESET) C:\Users\Mira\Downloads\esetsmartinstaller_enu.exe 2013-08-26 19:11 - 2013-08-05 13:06 - 00003360 _____ C:\Windows\setupact.log 2013-08-26 19:11 - 2009-07-14 06:17 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-26 14:17 - 2013-08-26 14:17 - 00027667 _____ C:\Users\Mira\Desktop\FRST.txt 2013-08-26 14:16 - 2013-08-26 14:15 - 01070979 _____ (Farbar) C:\Users\Mira\Downloads\FRST.exe 2013-08-26 14:16 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default 2013-08-26 13:57 - 2013-08-26 13:57 - 00001156 _____ C:\Users\Mira\Desktop\JRT.txt 2013-08-26 13:54 - 2013-08-26 13:54 - 00000000 ____D C:\Windows\ERUNT 2013-08-26 13:50 - 2013-08-26 13:49 - 01021434 _____ (Thisisu) C:\Users\Mira\Downloads\JRT.exe 2013-08-26 13:38 - 2013-08-26 14:17 - 00001524 _____ C:\Users\Mira\Desktop\AdwCleaner[S0].txt 2013-08-26 13:38 - 2013-08-26 13:36 - 00000000 ____D C:\AdwCleaner 2013-08-26 13:37 - 2013-08-26 14:17 - 00001441 _____ C:\Users\Mira\Desktop\AdwCleaner[R0].txt 2013-08-26 13:35 - 2013-08-26 13:33 - 00994642 _____ C:\Users\Mira\Downloads\adwcleaner.exe 2013-08-26 13:21 - 2013-08-25 11:23 - 00097724 _____ C:\Windows\PFRO.log 2013-08-26 12:55 - 2013-08-26 12:55 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-26 12:55 - 2013-08-26 12:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-08-26 12:53 - 2013-08-26 12:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mira\Downloads\mbam-setup-1.75.0.1300.exe 2013-08-25 23:32 - 2013-08-25 23:32 - 00014856 _____ C:\ComboFix2.txt 2013-08-25 23:27 - 2013-08-25 23:27 - 00014856 _____ C:\ComboFix.txt 2013-08-25 23:27 - 2013-08-25 22:17 - 00000000 ____D C:\Qoobox 2013-08-25 23:25 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2013-08-25 23:02 - 2013-08-25 23:01 - 05113393 ____R (Swearware) C:\Users\Mira\Desktop\ComboFix.exe 2013-08-25 22:42 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-08-25 22:40 - 2013-08-25 22:16 - 00000000 ____D C:\Windows\erdnt 2013-08-25 22:24 - 2013-08-24 23:51 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-25 22:13 - 2013-08-25 22:12 - 05113393 ____R (Swearware) C:\Users\Mira\Downloads\ComboFix.exe 2013-08-25 16:06 - 2013-08-25 16:06 - 00018279 _____ C:\Users\Mira\Downloads\Addition.txt 2013-08-25 16:05 - 2013-08-25 16:05 - 00000000 ____D C:\FRST 2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Avira 2013-08-25 01:15 - 2013-08-25 01:19 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-25 01:01 - 2013-08-25 01:01 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-25 00:59 - 2013-08-25 00:51 - 00000000 ____D C:\ProgramData\Avira 2013-08-25 00:51 - 2013-08-25 00:51 - 00000000 ____D C:\Program Files\Avira 2013-08-25 00:29 - 2013-08-25 00:22 - 110344048 _____ C:\Users\Mira\Downloads\avira_free4045_antivirus_de.exe 2013-08-25 00:04 - 2013-02-17 22:39 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job 2013-08-24 23:51 - 2013-08-24 23:51 - 00002119 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-08-24 23:51 - 2013-08-24 23:50 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2013-08-24 23:46 - 2013-08-24 23:43 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(5).exe 2013-08-24 23:44 - 2013-08-24 23:42 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(4).exe 2013-08-24 23:41 - 2013-08-24 23:39 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(3).exe 2013-08-24 23:40 - 2013-08-24 23:38 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(2).exe 2013-08-24 23:40 - 2013-08-24 23:38 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2(1).exe 2013-08-24 23:36 - 2013-01-17 00:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-24 23:35 - 2013-08-24 23:34 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Mira\Downloads\spybotsd-2.1.21-SR2.exe 2013-08-24 23:05 - 2013-01-17 00:26 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Mozilla 2013-08-24 23:04 - 2013-01-21 21:33 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-08-24 23:04 - 2013-01-21 21:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-08-24 22:44 - 2013-08-24 22:44 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-22 14:17 - 2013-01-26 13:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\vlc 2013-08-22 14:14 - 2010-11-20 23:03 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 09:12 - 2013-08-21 09:11 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-21 09:03 - 2013-08-21 09:03 - 00000000 ____D C:\Users\Mira\Documents\Canon Utilities 2013-08-20 23:21 - 2013-08-20 23:21 - 00000000 ____D C:\Users\Mira\AppData\Roaming\CANON INC 2013-08-20 23:11 - 2013-08-20 23:11 - 00000000 ____D C:\Users\Public\Documents\Canon MyCameraFiles 2013-08-20 23:09 - 2013-08-20 23:09 - 00000000 ____D C:\Users\Mira\AppData\Roaming\Canon_Inc_IC 2013-08-20 23:05 - 2013-08-20 23:05 - 00000000 ____D C:\Program Files\Common Files\Canon_Inc_IC 2013-08-20 23:02 - 2013-08-20 23:02 - 00000000 ____D C:\Users\Mira\AppData\Roaming\canon 2013-08-20 23:02 - 2013-08-20 23:01 - 00000000 ____D C:\ProgramData\Canon_Inc_IC 2013-08-16 07:44 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-08-15 18:21 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 10:37 - 2013-01-17 00:04 - 00000000 ____D C:\Windows\Panther 2013-08-15 10:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-15 08:48 - 2013-07-25 00:02 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 08:46 - 2013-02-18 17:04 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-08 16:55 - 2013-08-08 16:54 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3(1).zip 2013-08-08 16:43 - 2013-08-08 16:42 - 00157234 _____ C:\Users\Mira\Downloads\RouterReconnect_1.3.zip 2013-08-07 21:36 - 2013-01-26 13:14 - 00000000 ____D C:\Users\Mira\AppData\Roaming\dvdcss 2013-08-07 09:30 - 2013-08-07 09:30 - 00009439 _____ C:\Users\Mira\Desktop\CHORDS AIR.odt 2013-08-06 02:28 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-08-05 13:06 - 2013-08-05 13:06 - 00000000 _____ C:\Windows\setuperr.log 2013-08-04 08:19 - 2013-06-09 08:35 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-08-04 08:19 - 2013-01-17 00:28 - 00001912 _____ C:\Windows\epplauncher.mif 2013-08-04 08:17 - 2013-08-04 08:15 - 19159080 _____ (Sony Ericsson ) C:\Users\Mira\Downloads\Sony_Ericsson_PC_Suite_6.011.00_Web_DEU.exe Files to move or delete: ==================== C:\Users\Mira\AppData\Local\Temp\Quarantine.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\Objlist.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\runprocesses.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\uninstalllist.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\cmdinfo.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\nircmdc.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\sed.exe C:\Users\Mira\AppData\Local\Temp\RarSFX0\SecurityCheck\Other\swreg.exe C:\Users\Mira\AppData\Local\Temp\jrt\erunt\ERUNT.EXE ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 15:21 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Deinstallieren tu ich den Online Scanner erst jetzt. Sollte das falsch sein und ich soll den Security Check und FRST nochmal nach der Deinstallation von Edet machen, bitte bescheid geben. Sry, war zu schnell und dann weiß ich immer nicht ob ich das hätte davor oder danach machen sollen, oder ob das überhaupt wichtig ist, usw Und noch eine letzte Sache. Ich hatte noch keine Möglichkeit meine Passwörter etc. von einem anderen Laptop aus zu ändern, abgesehen davon ist die Änderung meiner Online-Banking Passwörter glaube ich garnicht so einfach!? Ich hoffe, dass es genügt, wenn ich das morgen mache? :/ Und würde mich natürlich interessieren, um was für einen Virus, Trojaner oder was auch immer es sich bei mir handelt (sind es mehrere?) und was diese anrichten? Vielen Dank, liebe Grüße Mira Geändert von TheMissMico (26.08.2013 um 21:29 Uhr) |
27.08.2013, 09:58 | #12 | ||
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/NeopZitat:
Wenn bei dem Funden was dabei ist was weg muss wird das nach dem Scan von hand entfernt. In diesem Fall kannste den Installer für VLC Player sowie das angemeckerte Backup einfach von Hand löschen. Zitat:
Wo die Infektion herkommt ist nicht nachvollziehbar. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.08.2013, 10:11 | #13 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo Schrauber, vielen Dank für deine Nachricht. Wo finde ich den Installer für VLC und den "angemeckerten Backup"? Und was ist nun mit den 4 Threads, wie lösche ich diese manuell? Sry. Ich kenn mich nicht aus |
27.08.2013, 11:09 | #14 | |
/// the machine /// TB-Ausbilder | Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop die 4 Threads sind doch die von mir genannten Backups Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.08.2013, 11:19 | #15 |
| Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop Hallo Schrauber, danke VLC konnte ich manuell löschen. (also nicht deinstallieren?) In diesem Mira-PC Ordner habe ich nun alle Sicherungen gelöscht. Jetzt habe ich keine Sicherung mehr. Schlimm? Und ist der Trojaner ist vollständig verschwunden, kann ich also wie gewohnt Online-Banking etc. machen? Liebe Grüße Mira |
Themen zu Windows 7: Zip-Datei aus Phishing-Mail runtergeladen und geöffnet,Trojaner: Trojan:Win32/Neop |
antivir, automatisch, besser, computer, e-banking, entfernen, entfernt, forum, hilfreich, kopieren, log, microsoft essentials, namen, nicht mehr, nichts, online-banking, passwörter, phishing-mail, programm, programme, scan, scannen, security, tan, trojaner, win, windows, windows 7, worte |