|
Log-Analyse und Auswertung: GVU TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
26.08.2013, 17:15 | #1 |
| GVU Trojaner Hallo, ich habe mir den GVU Trojaner am Wochenende eingefangen. Ihr seid meine letzte Hilfe. Habe mir die FRST.exe schon geladen und folgende Log-Datei erzeugt. Was muss ich jetzt machen? Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-08-2013 Ran by SYSTEM on 26-08-2013 18:04:52 Running from F:\ Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet003 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation) HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13548064 2008-07-26] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - C:\Windows\system32\NvMcTray.dll [92704 2008-07-26] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-16] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-25] (Synaptics, Inc.) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [71216 2007-03-14] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [NeroFilterCheck] - C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2010-12-06] (Nullsoft, Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1644680 2013-03-10] (Ask) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) HKU\peter\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [ 2008-03-17] (Hewlett-Packard Company) HKU\peter\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2010-10-11] (Google Inc.) HKU\peter\...\Run: [AnyDVD] - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe [ 2011-10-11] (SlySoft, Inc.) HKU\peter\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-20] (Microsoft Corporation) HKU\peter\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2013-06-20] (Skype Technologies S.A.) HKU\peter\...\Run: [GoogleChromeAutoLaunch_C33915310E970B1AAC9D49F3C6144E57] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-08-15] (Google Inc.) HKU\peter\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe [ 2013-08-23] (Valve Corporation) <===== ATTENTION HKU\peter\...\Command Processor: "C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe" <===== ATTENTION! ========================== Services (Whitelisted) ================= S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-01] (Avira Operations GmbH & Co. KG) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2006-12-19] () ==================== Drivers (Whitelisted) ==================== S3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus.sys [14336 2012-03-02] (LG Electronics Inc.) S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag.sys [20736 2012-03-02] (LG Electronics Inc.) S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps.sys [20096 2012-03-02] (LG Electronics Inc.) S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem.sys [25088 2012-03-02] (LG Electronics Inc.) S3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [121464 2011-08-19] (SlySoft, Inc.) S3 APL531; C:\Windows\System32\Drivers\ov550i.sys [580992 2006-07-30] (Omnivision Technologies, Inc.) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-25] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-25] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-25] (Avira Operations GmbH & Co. KG) S0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-10] (Microsoft Corporation) S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG) S2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-05-23] (SAMSUNG ELECTRONICS CO., LTD.) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-22] (Avira GmbH) S3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [242048 2008-06-04] (Vimicro Corporation) S3 VMC326; C:\Windows\System32\Drivers\VMC326.sys [238464 2008-09-03] (Vimicro Corporation) S0 iaStor; system32\DRIVERS\iaStor.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-23 11:03 - 2013-08-23 11:03 - 01084834 _____ C:\ProgramData\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084805 _____ C:\Users\peter\AppData\Roaming\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084771 _____ C:\Users\peter\AppData\Local\2433f433 2013-08-15 03:31 - 2013-07-24 18:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-08-15 03:31 - 2013-07-24 18:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-08-15 03:31 - 2013-07-24 18:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-08-15 03:31 - 2013-07-24 18:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-08-15 03:31 - 2013-07-24 18:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-08-15 03:31 - 2013-07-24 18:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-08-15 03:31 - 2013-07-24 18:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\System32\url.dll 2013-08-15 03:31 - 2013-07-24 18:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-08-15 03:31 - 2013-07-24 18:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-08-15 03:31 - 2013-07-24 18:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-08-15 03:31 - 2013-07-24 18:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-08-15 03:31 - 2013-07-24 18:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-08-15 03:31 - 2013-07-24 18:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-08-15 03:31 - 2013-07-24 18:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-08-15 03:31 - 2013-07-24 18:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-08-15 03:31 - 2013-07-24 18:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-08-14 11:47 - 2013-07-17 11:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2013-08-14 11:47 - 2013-07-10 01:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2013-08-14 11:47 - 2013-07-09 04:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2013-08-14 11:47 - 2013-07-07 20:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-08-14 11:47 - 2013-07-07 20:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-08-14 11:47 - 2013-07-07 20:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2013-08-14 11:47 - 2013-07-07 20:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-08-14 11:47 - 2013-07-07 20:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-08-14 11:47 - 2013-07-07 20:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-08-14 11:47 - 2013-07-04 20:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-08-14 11:47 - 2013-06-15 05:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\icaapi.dll 2013-08-14 11:47 - 2013-06-15 03:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys 2013-08-02 09:05 - 2013-08-02 09:05 - 00977765 _____ C:\Users\peter\Desktop\Lazy Sun.m4r 2013-08-02 02:49 - 2013-08-02 02:53 - 00000000 ____D C:\Users\peter\AppData\Roaming\Apple Computer 2013-08-02 02:49 - 2013-08-02 02:49 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-02 02:49 - 2013-08-02 02:49 - 00000000 ____D C:\Users\peter\AppData\Local\Apple Computer 2013-08-02 02:49 - 2012-08-21 03:01 - 00026840 _____ (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys 2013-08-02 02:47 - 2013-08-02 02:48 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-08-02 02:47 - 2013-08-02 02:48 - 00000000 ____D C:\Program Files\iTunes 2013-08-02 02:47 - 2013-08-02 02:47 - 00000000 ____D C:\ProgramData\Apple Computer 2013-08-02 02:47 - 2013-08-02 02:47 - 00000000 ____D C:\Program Files\iPod 2013-08-02 02:46 - 2013-08-02 02:46 - 00000000 ____D C:\Users\peter\AppData\Local\Apple 2013-08-02 02:46 - 2013-08-02 02:46 - 00000000 ____D C:\Program Files\Apple Software Update 2013-08-02 02:43 - 2013-08-02 02:47 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-08-02 02:43 - 2013-08-02 02:44 - 00000000 ____D C:\Program Files\Bonjour 2013-08-01 23:39 - 2013-08-01 23:39 - 00000000 ____H C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2013-07-28 02:14 - 2013-08-02 09:29 - 00000000 ____D C:\Users\peter\Desktop\Bilder LG Handy 2013-07-27 22:25 - 2013-08-15 03:41 - 00000000 ____D C:\Windows\System32\MRT ==================== One Month Modified Files and Folders ======= 2013-08-26 06:22 - 2008-10-09 18:51 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-08-26 06:21 - 2012-04-09 06:39 - 00027839 _____ C:\ProgramData\nvModes.001 2013-08-26 06:21 - 2006-11-02 04:47 - 00004784 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-26 06:21 - 2006-11-02 04:47 - 00004784 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-26 06:07 - 2009-03-17 13:08 - 01595969 _____ C:\Windows\WindowsUpdate.log 2013-08-26 06:06 - 2012-04-09 06:20 - 00027839 _____ C:\ProgramData\nvModes.dat 2013-08-23 22:19 - 2011-10-16 12:16 - 00000024 _____ C:\Windows\27A79DE698F3EF4D.log 2013-08-23 22:19 - 2011-10-16 11:36 - 00000040 ___SH C:\ProgramData\.zreglib 2013-08-23 11:03 - 2013-08-23 11:03 - 01084834 _____ C:\ProgramData\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084805 _____ C:\Users\peter\AppData\Roaming\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084771 _____ C:\Users\peter\AppData\Local\2433f433 2013-08-23 10:54 - 2011-07-13 07:23 - 00000000 ____D C:\Users\peter\AppData\Roaming\Skype 2013-08-20 11:19 - 2012-12-07 07:14 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-19 08:25 - 2006-11-02 02:33 - 01445546 _____ C:\Windows\System32\PerfStringBackup.INI 2013-08-19 08:21 - 2006-11-02 04:52 - 00109675 _____ C:\Windows\setupact.log 2013-08-15 07:59 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 07:50 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache 2013-08-15 07:33 - 2008-01-20 18:47 - 00076692 _____ C:\Windows\PFRO.log 2013-08-15 03:41 - 2013-07-27 22:25 - 00000000 ____D C:\Windows\System32\MRT 2013-08-15 03:41 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\de-DE 2013-08-15 03:39 - 2006-11-02 02:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-08-15 03:30 - 2006-11-02 02:23 - 00000546 _____ C:\Windows\win.ini 2013-08-12 07:23 - 2010-09-09 08:07 - 00000000 ____D C:\Users\peter\AppData\Local\Adobe 2013-08-02 09:29 - 2013-07-28 02:14 - 00000000 ____D C:\Users\peter\Desktop\Bilder LG Handy 2013-08-02 09:29 - 2011-03-05 03:26 - 00000000 ____D C:\Users\peter\AppData\Roaming\Winamp 2013-08-02 09:05 - 2013-08-02 09:05 - 00977765 _____ C:\Users\peter\Desktop\Lazy Sun.m4r 2013-08-02 07:30 - 2011-01-02 07:38 - 00000000 ____D C:\Users\peter\AppData\Local\Microsoft Games 2013-08-02 02:53 - 2013-08-02 02:49 - 00000000 ____D C:\Users\peter\AppData\Roaming\Apple Computer 2013-08-02 02:49 - 2013-08-02 02:49 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-02 02:49 - 2013-08-02 02:49 - 00000000 ____D C:\Users\peter\AppData\Local\Apple Computer 2013-08-02 02:48 - 2013-08-02 02:47 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-08-02 02:48 - 2013-08-02 02:47 - 00000000 ____D C:\Program Files\iTunes 2013-08-02 02:47 - 2013-08-02 02:47 - 00000000 ____D C:\ProgramData\Apple Computer 2013-08-02 02:47 - 2013-08-02 02:47 - 00000000 ____D C:\Program Files\iPod 2013-08-02 02:47 - 2013-08-02 02:43 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-08-02 02:46 - 2013-08-02 02:46 - 00000000 ____D C:\Users\peter\AppData\Local\Apple 2013-08-02 02:46 - 2013-08-02 02:46 - 00000000 ____D C:\Program Files\Apple Software Update 2013-08-02 02:45 - 2012-04-09 06:19 - 00000000 ____D C:\ProgramData\Apple 2013-08-02 02:45 - 2010-08-28 02:55 - 00000000 ____D C:\users\peter 2013-08-02 02:44 - 2013-08-02 02:43 - 00000000 ____D C:\Program Files\Bonjour 2013-08-01 23:39 - 2013-08-01 23:39 - 00000000 ____H C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2013-07-29 12:27 - 2010-10-11 22:48 - 00000000 ____D C:\Program Files\Google 2013-07-28 04:16 - 2011-02-05 02:54 - 00000000 ____D C:\Users\peter\Desktop\YouTube 2013-07-28 02:14 - 2012-09-22 03:09 - 00000000 ____D C:\ProgramData\LGMOBILEAX 2013-07-28 02:12 - 2012-09-22 03:10 - 00000779 _____ C:\Users\peter\Desktop\LGMobile Support Tool.lnk 2013-07-28 02:12 - 2012-09-22 03:09 - 00002411 _____ C:\Windows\System32\lgAxconfig.ini Files to move or delete: ==================== C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe C:\ProgramData\nvModes.dat C:\Users\peter\AppData\Local\Temp\isxaqmwsqxhwtradj.exe C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.dll C:\Users\peter\AppData\Local\Temp\SkypeSetup.exe C:\Users\peter\AppData\Local\Temp\{F6FE42B2-0210-475C-A676-55B8DB67AE8B}\InstallFlashPlayer.exe C:\Users\peter\AppData\Local\Temp\{9BB3C59E-A88B-426E-AEE6-0231FAD1E82D}\InstallFlashPlayer.exe C:\Users\peter\AppData\Local\Temp\{575D6417-5EA9-4AEC-B736-E760FA35B75C}\InstallFlashPlayer.exe C:\Users\peter\AppData\Local\Temp\UpdateWizard_72269\SilentUpdater.exe C:\Users\peter\AppData\Local\Temp\RarSFX0\avmres.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\avwebloader.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\avwebloader.exe C:\Users\peter\AppData\Local\Temp\RarSFX0\avwebloadergui.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\msvcp100.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\msvcr100.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcimage.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_ar.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_de.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_en.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_es.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_fr.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_it.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_jp.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_ko.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_nl.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_pt.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_ru.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_tr.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_zhcn.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_zhtw.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\scewxmlw.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\update.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\64bitProxy.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aebb.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aecore.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeemu.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeexp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aegen.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aehelp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeheur.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeoffice.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aepack.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aerdl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aesbx.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aescn.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aescript.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aevdf.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\apcfile.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ApnIC.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ApnStub.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ApnToolbarInstaller.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_64.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_API.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_CLI.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avacl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avadmin.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avarkt.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avbb.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avcenter.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avconfig.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avconfig.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avesvc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avevtlog.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avgio.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avgnt.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avguard.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avinet.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avipc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avlode.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avmres.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avnotify.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avpref.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avreg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avrep.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avrestart.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avscan.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avscplr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avsda.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avsda64.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avsmtp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avupgsvc.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebgrd.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebloader.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebloader.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebloadergui.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwinll.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwmi.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwsc.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccavscanex.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccev.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccevw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccgen.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccgenw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccgrdw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccguard.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cchips.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cclic.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cclicw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccmsg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccprofil.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccquamgr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccquaw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccreport.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccrepow.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccscanw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccsched.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccschedw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccupdate.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccupdw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwebtabs.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwgrd.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwgrdw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwkrlib.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cfglib.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\extdlgfw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\fact.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpavgio.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpevtlog.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgavid.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgen.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgenrep.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgrd.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgui.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpipc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gplegacy.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpschd.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\grdcore.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\guardgui.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\imp64b.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\inssda64.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\insthlp.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ipmgui.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libapr-1.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libapriconv-1.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libaprutil-1.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libcurl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libdb44.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libeay32.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\licmgr.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\luke.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\mgrs.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\msgclient.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\msvcp80.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\msvcr80.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\netnt.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\onlcfg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\presetup.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ar.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_de.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_en.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_es.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_fr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_it.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_jp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ko.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_nl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_pt.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ru.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_tr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_zhcn.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_zhtw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\scewxmlw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\sched.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\setup.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\setuppending.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\shlext.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\shlext64.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\sqlite3.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ssleay32.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\thorwac.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\toastNotifier.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\unacev2.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\update.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\update.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\updext.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\updgui.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\updrgui.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\vcredist_x86.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\wksstats.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\wsctool.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\xp\avshadow.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\vista64\avipc64.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\vista64\avshadow.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avconfigrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avesvcr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avevtrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avnotify.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avscanrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avwebgrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccavscanexrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccevrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccgenrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccgrdrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\cchipsrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\cclicrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccmainrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccmsgrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccquarc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccreporc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccscanrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccscherc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccupdrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccwebtabsrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccwgrdrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\factrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\guardmsg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\licmgr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\lukeres.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\rchelp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\rcimage.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\rctext.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\restartrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\schedr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\setup.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\updaterc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\updguirc.dll ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-08-09 07:21:25 Restore point made on: 2013-08-10 01:39:24 Restore point made on: 2013-08-11 02:32:39 Restore point made on: 2013-08-12 07:18:02 Restore point made on: 2013-08-13 09:56:13 Restore point made on: 2013-08-14 07:02:59 Restore point made on: 2013-08-15 03:27:59 Restore point made on: 2013-08-17 08:17:57 Restore point made on: 2013-08-18 02:32:15 Restore point made on: 2013-08-21 02:08:13 Restore point made on: 2013-08-23 04:38:38 ==================== Memory info =========================== Percentage of memory in use: 15% Total physical RAM: 3065.88 MB Available physical RAM: 2589.72 MB Total Pagefile: 2796.48 MB Available Pagefile: 2644.25 MB Total Virtual: 2047.88 MB Available Virtual: 1963.11 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:100.25 GB) (Free:48.66 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:187.83 GB) (Free:187.74 GB) NTFS Drive f: () (Removable) (Total:0.95 GB) (Free:0.94 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive z: (RECOVERY) (Fixed) (Total:10 GB) (Free:1.05 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: ECE69603) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=188 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 968 MB) (Disk ID: 00292BAC) Partition 1: (Active) - (Size=968 MB) - (Type=06) LastRegBack: 2013-08-26 05:59 ==================== End Of Log ============================ |
26.08.2013, 17:18 | #2 |
/// TB-Ausbilder | GVU Trojaner Hallo,
__________________startet der Rechner nach diesem Fix wieder normal? Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\peter\...\Run: [GoogleChromeAutoLaunch_C33915310E970B1AAC9D49F3C6144E57] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-08-15] (Google Inc.) HKU\peter\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe [ 2013-08-23] (Valve Corporation) <===== ATTENTION HKU\peter\...\Command Processor: "C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe" <===== ATTENTION! 2013-08-23 11:03 - 2013-08-23 11:03 - 01084834 _____ C:\ProgramData\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084805 _____ C:\Users\peter\AppData\Roaming\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084771 _____ C:\Users\peter\AppData\Local\2433f433 C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe C:\Users\peter\AppData\Local\Temp\isxaqmwsqxhwtradj.exe C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.dll
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ |
26.08.2013, 17:27 | #3 |
| GVU Trojaner Hammer. Der Rechner startet weider. Super!!!! Danke!!!!!
__________________Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-08-2013 Ran by SYSTEM at 2013-08-26 18:25:01 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** HKU\peter\...\Run: [GoogleChromeAutoLaunch_C33915310E970B1AAC9D49F3C6144E57] - C:\Program Files\Google\Chrome\Application\chrome.exe [ 2013-08-15] (Google Inc.) HKU\peter\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe [ 2013-08-23] (Valve Corporation) <===== ATTENTION HKU\peter\...\Command Processor: "C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe" <===== ATTENTION! 2013-08-23 11:03 - 2013-08-23 11:03 - 01084834 _____ C:\ProgramData\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084805 _____ C:\Users\peter\AppData\Roaming\2433f433 2013-08-23 11:03 - 2013-08-23 11:03 - 01084771 _____ C:\Users\peter\AppData\Local\2433f433 C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe C:\Users\peter\AppData\Local\Temp\isxaqmwsqxhwtradj.exe C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.dll ***************** HKU\peter\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_C33915310E970B1AAC9D49F3C6144E57 => Value deleted successfully. HKU\peter\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value deleted successfully. HKU\peter\Software\Microsoft\Command Processor\\AutoRun => Value deleted successfully. C:\ProgramData\2433f433 => Moved successfully. C:\Users\peter\AppData\Roaming\2433f433 => Moved successfully. C:\Users\peter\AppData\Local\2433f433 => Moved successfully. C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.exe => Moved successfully. C:\Users\peter\AppData\Local\Temp\isxaqmwsqxhwtradj.exe => Moved successfully. C:\Users\peter\AppData\Local\Temp\ongafbviktirfawet.dll => Moved successfully. ==== End of Fixlog ==== |
26.08.2013, 17:29 | #4 |
/// TB-Ausbilder | GVU Trojaner Gut, dann verschiebe die frst.exe vom USB-Stick auf den Desktop.
__________________ cheers, Leo |
26.08.2013, 17:38 | #5 |
| GVU Trojaner FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-08-2013 Ran by peter (administrator) on 26-08-2013 18:33:34 Running from C:\Users\peter\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.0.318\McUicnt.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13548064 2008-07-26] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] - C:\Windows\system32\NvMcTray.dll [92704 2008-07-26] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-26] (Synaptics, Inc.) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [71216 2007-03-14] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [NeroFilterCheck] - C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2010-12-07] (Nullsoft, Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1644680 2013-03-11] (Ask) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2289664 2008-03-17] (Hewlett-Packard Company) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-10-12] (Google Inc.) HKCU\...\Run: [AnyDVD] - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe [5389944 2011-10-11] (SlySoft, Inc.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) MountPoints2: {35f491c4-2e18-11e0-8421-001377f7b986} - H:\LaunchU3.exe -a HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=2eaf3132-8f36-45ed-b518-1d7224d3eebc&searchtype=ds&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bild.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=2eaf3132-8f36-45ed-b518-1d7224d3eebc&searchtype=ds&q={searchTerms} URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 SearchScopes: HKCU - DefaultScope {8F7D68B7-351B-495E-9EED-CF45B5B1B84B} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_de SearchScopes: HKCU - 3E7F8CA7D905448192B576FB831052B9 URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_de SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=2eaf3132-8f36-45ed-b518-1d7224d3eebc&searchtype=ds&q={searchTerms} SearchScopes: HKCU - {043C5167-00BB-4324-AF7E-62013FAEDACF} URL = hxxp://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {5CCBE8F9-FD45-40A1-8819-A94926D628F7} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=fb5d8310-74dc-4c2f-b0cc-742694b7e80d&apn_sauid=5E11F363-583B-4C58-950F-D833BD557520 SearchScopes: HKCU - {8F7D68B7-351B-495E-9EED-CF45B5B1B84B} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_de SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 BHO: vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll () BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll () Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) Toolbar: HKLM - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll () Toolbar: HKCU -DVDVideoSoftTB Toolbar - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) Toolbar: HKCU -Winamp Toolbar - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: msdaipp - No CLSID Value - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll () Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 36 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 212.38.2.130 212.38.26.132 Chrome: ======= CHR HomePage: hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP&dt=072613 CHR RestoreOnStartup: "hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP&dt=072613", "hxxp://www.google.com/" CHR DefaultSearchURL: (Bing) - hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=072613&q={searchTerms}&src=IE-SearchBox CHR DefaultSuggestURL: (Bing) - hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language}&form=UP97DF&PC=UP97&dt=072613 CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\pdf.dll () CHR Plugin: (Free Studio) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\np_dvs_plugin.dll (DVDVideoSoft Ltd.) CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U30) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (YouTube) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1 CHR Extension: (Google Search) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0 CHR Extension: (Gmail) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-01] (Avira Operations GmbH & Co. KG) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2006-12-19] () ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus.sys [14336 2012-03-02] (LG Electronics Inc.) S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag.sys [20736 2012-03-02] (LG Electronics Inc.) S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps.sys [20096 2012-03-02] (LG Electronics Inc.) S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem.sys [25088 2012-03-02] (LG Electronics Inc.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [121464 2011-08-19] (SlySoft, Inc.) S3 APL531; C:\Windows\System32\Drivers\ov550i.sys [580992 2006-07-31] (Omnivision Technologies, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-25] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-17] (Elaborate Bytes AG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2007-05-23] (SAMSUNG ELECTRONICS CO., LTD.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-23] (Avira GmbH) S3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [242048 2008-06-05] (Vimicro Corporation) R3 VMC326; C:\Windows\System32\Drivers\VMC326.sys [238464 2008-09-03] (Vimicro Corporation) S0 iaStor; system32\DRIVERS\iaStor.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-26 18:33 - 2013-08-26 17:59 - 01070979 _____ (Farbar) C:\Users\peter\Desktop\FRST.exe 2013-08-15 13:31 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 13:31 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 13:31 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 13:31 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 13:31 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 13:31 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-08-15 13:31 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-08-15 13:31 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 13:31 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 13:31 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 13:31 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 13:31 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-08-15 13:31 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-08-15 13:31 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 13:31 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 13:31 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-08-14 21:47 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 21:47 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 21:47 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 21:47 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-14 21:47 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 21:47 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 21:47 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 21:47 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 21:47 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 21:47 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 21:47 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-08-14 21:47 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-02 19:05 - 2013-08-02 19:05 - 00977765 _____ C:\Users\peter\Desktop\Lazy Sun.m4r 2013-08-02 12:49 - 2013-08-02 12:53 - 00000000 ____D C:\Users\peter\AppData\Roaming\Apple Computer 2013-08-02 12:49 - 2013-08-02 12:49 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-02 12:49 - 2013-08-02 12:49 - 00000000 ____D C:\Users\peter\AppData\Local\Apple Computer 2013-08-02 12:49 - 2012-08-21 13:01 - 00026840 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2013-08-02 12:47 - 2013-08-02 12:48 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-08-02 12:47 - 2013-08-02 12:48 - 00000000 ____D C:\Program Files\iTunes 2013-08-02 12:47 - 2013-08-02 12:47 - 00000000 ____D C:\ProgramData\Apple Computer 2013-08-02 12:47 - 2013-08-02 12:47 - 00000000 ____D C:\Program Files\iPod 2013-08-02 12:46 - 2013-08-02 12:46 - 00000000 ____D C:\Users\peter\AppData\Local\Apple 2013-08-02 12:46 - 2013-08-02 12:46 - 00000000 ____D C:\Program Files\Apple Software Update 2013-08-02 12:43 - 2013-08-02 12:47 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-08-02 12:43 - 2013-08-02 12:44 - 00000000 ____D C:\Program Files\Bonjour 2013-08-02 09:39 - 2013-08-02 09:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2013-07-28 12:14 - 2013-08-02 19:29 - 00000000 ____D C:\Users\peter\Desktop\Bilder LG Handy 2013-07-28 08:25 - 2013-08-15 13:41 - 00000000 ____D C:\Windows\system32\MRT ==================== One Month Modified Files and Folders ======= 2013-08-27 04:04 - 2013-08-27 04:04 - 00000000 ____D C:\FRST 2013-08-26 18:33 - 2006-11-02 14:52 - 00110471 _____ C:\Windows\setupact.log 2013-08-26 18:29 - 2009-03-17 23:08 - 01598949 _____ C:\Windows\WindowsUpdate.log 2013-08-26 18:27 - 2011-10-16 21:36 - 00000040 ___SH C:\ProgramData\.zreglib 2013-08-26 18:26 - 2012-04-09 16:39 - 00027839 _____ C:\ProgramData\nvModes.001 2013-08-26 18:26 - 2010-10-12 08:49 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-26 18:26 - 2010-08-28 12:55 - 00000000 ____D C:\Users\peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2013-08-26 18:26 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-26 18:26 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-26 18:26 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-26 17:59 - 2013-08-26 18:33 - 01070979 _____ (Farbar) C:\Users\peter\Desktop\FRST.exe 2013-08-26 16:22 - 2008-10-10 04:51 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-08-26 16:22 - 2006-11-02 15:01 - 00032586 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-26 16:10 - 2010-10-12 08:49 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-26 16:06 - 2012-04-09 16:20 - 00027839 _____ C:\ProgramData\nvModes.dat 2013-08-24 08:19 - 2011-10-16 22:16 - 00000024 _____ C:\Windows\27A79DE698F3EF4D.log 2013-08-23 20:54 - 2011-07-13 17:23 - 00000000 ____D C:\Users\peter\AppData\Roaming\Skype 2013-08-23 20:52 - 2012-04-02 16:21 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-20 21:19 - 2012-12-07 17:14 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-19 18:25 - 2006-11-02 12:33 - 01445546 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-15 17:59 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 17:50 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-08-15 17:33 - 2008-01-21 04:47 - 00076692 _____ C:\Windows\PFRO.log 2013-08-15 13:41 - 2013-07-28 08:25 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 13:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-15 13:39 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-08-15 13:30 - 2006-11-02 12:23 - 00000546 _____ C:\Windows\win.ini 2013-08-12 17:23 - 2010-09-09 18:07 - 00000000 ____D C:\Users\peter\AppData\Local\Adobe 2013-08-02 19:29 - 2013-07-28 12:14 - 00000000 ____D C:\Users\peter\Desktop\Bilder LG Handy 2013-08-02 19:29 - 2011-03-05 13:26 - 00000000 ____D C:\Users\peter\AppData\Roaming\Winamp 2013-08-02 19:05 - 2013-08-02 19:05 - 00977765 _____ C:\Users\peter\Desktop\Lazy Sun.m4r 2013-08-02 17:30 - 2011-01-02 17:38 - 00000000 ____D C:\Users\peter\AppData\Local\Microsoft Games 2013-08-02 12:53 - 2013-08-02 12:49 - 00000000 ____D C:\Users\peter\AppData\Roaming\Apple Computer 2013-08-02 12:49 - 2013-08-02 12:49 - 00001664 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-02 12:49 - 2013-08-02 12:49 - 00000000 ____D C:\Users\peter\AppData\Local\Apple Computer 2013-08-02 12:48 - 2013-08-02 12:47 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-08-02 12:48 - 2013-08-02 12:47 - 00000000 ____D C:\Program Files\iTunes 2013-08-02 12:47 - 2013-08-02 12:47 - 00000000 ____D C:\ProgramData\Apple Computer 2013-08-02 12:47 - 2013-08-02 12:47 - 00000000 ____D C:\Program Files\iPod 2013-08-02 12:47 - 2013-08-02 12:43 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-08-02 12:46 - 2013-08-02 12:46 - 00000000 ____D C:\Users\peter\AppData\Local\Apple 2013-08-02 12:46 - 2013-08-02 12:46 - 00000000 ____D C:\Program Files\Apple Software Update 2013-08-02 12:45 - 2012-04-09 16:19 - 00000000 ____D C:\ProgramData\Apple 2013-08-02 12:45 - 2010-08-28 12:55 - 00000000 ____D C:\Users\peter 2013-08-02 12:44 - 2013-08-02 12:43 - 00000000 ____D C:\Program Files\Bonjour 2013-08-02 09:39 - 2013-08-02 09:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2013-07-29 22:27 - 2010-10-12 08:48 - 00000000 ____D C:\Program Files\Google 2013-07-28 14:16 - 2011-02-05 12:54 - 00000000 ____D C:\Users\peter\Desktop\YouTube 2013-07-28 12:14 - 2012-09-22 13:09 - 00000000 ____D C:\ProgramData\LGMOBILEAX 2013-07-28 12:12 - 2012-09-22 13:10 - 00000779 _____ C:\Users\peter\Desktop\LGMobile Support Tool.lnk 2013-07-28 12:12 - 2012-09-22 13:09 - 00002411 _____ C:\Windows\system32\lgAxconfig.ini Files to move or delete: ==================== C:\ProgramData\nvModes.dat C:\Users\peter\AppData\Local\Temp\SkypeSetup.exe C:\Users\peter\AppData\Local\Temp\{F6FE42B2-0210-475C-A676-55B8DB67AE8B}\InstallFlashPlayer.exe C:\Users\peter\AppData\Local\Temp\{9BB3C59E-A88B-426E-AEE6-0231FAD1E82D}\InstallFlashPlayer.exe C:\Users\peter\AppData\Local\Temp\{575D6417-5EA9-4AEC-B736-E760FA35B75C}\InstallFlashPlayer.exe C:\Users\peter\AppData\Local\Temp\UpdateWizard_72269\SilentUpdater.exe C:\Users\peter\AppData\Local\Temp\RarSFX0\avmres.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\avwebloader.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\avwebloader.exe C:\Users\peter\AppData\Local\Temp\RarSFX0\avwebloadergui.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\msvcp100.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\msvcr100.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcimage.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_ar.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_de.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_en.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_es.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_fr.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_it.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_jp.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_ko.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_nl.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_pt.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_ru.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcnwload_tr.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_zhcn.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\rcNwLoad_zhtw.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\scewxmlw.dll C:\Users\peter\AppData\Local\Temp\RarSFX0\update.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\64bitProxy.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aebb.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aecore.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeemu.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeexp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aegen.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aehelp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeheur.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aeoffice.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aepack.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aerdl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aesbx.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aescn.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aescript.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\aevdf.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\apcfile.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ApnIC.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ApnStub.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ApnToolbarInstaller.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_64.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_API.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\AppRemover_CLI.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avacl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avadmin.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avarkt.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avbb.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avcenter.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avconfig.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avconfig.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avesvc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avevtlog.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avgio.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avgnt.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avguard.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avinet.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avipc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avlode.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avmres.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avnotify.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avpref.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avreg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avrep.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avrestart.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avscan.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avscplr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avsda.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avsda64.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avsmtp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avupgsvc.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebgrd.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebloader.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebloader.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwebloadergui.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwinll.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwmi.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\avwsc.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccavscanex.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccev.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccevw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccgen.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccgenw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccgrdw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccguard.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cchips.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cclic.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cclicw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccmsg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccprofil.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccquamgr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccquaw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccreport.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccrepow.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccscanw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccsched.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccschedw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccupdate.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccupdw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwebtabs.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwgrd.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwgrdw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ccwkrlib.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\cfglib.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\extdlgfw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\fact.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpavgio.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpevtlog.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgavid.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgen.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgenrep.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgrd.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpgui.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpipc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gplegacy.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\gpschd.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\grdcore.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\guardgui.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\imp64b.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\inssda64.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\insthlp.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ipmgui.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libapr-1.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libapriconv-1.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libaprutil-1.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libcurl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libdb44.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\libeay32.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\licmgr.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\luke.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\mgrs.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\msgclient.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\msvcp80.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\msvcr80.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\netnt.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\onlcfg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\presetup.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ar.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_de.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_en.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_es.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_fr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_it.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_jp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ko.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_nl.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_pt.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_ru.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_tr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_zhcn.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\rcnwload_zhtw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\scewxmlw.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\sched.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\setup.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\setuppending.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\shlext.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\shlext64.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\sqlite3.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\ssleay32.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\thorwac.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\toastNotifier.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\unacev2.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\update.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\update.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\updext.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\updgui.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\updrgui.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\vcredist_x86.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\wksstats.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\wsctool.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\xp\avshadow.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\vista64\avipc64.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\vista64\avshadow.exe C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avconfigrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avesvcr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avevtrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avnotify.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avscanrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\avwebgrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccavscanexrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccevrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccgenrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccgrdrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\cchipsrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\cclicrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccmainrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccmsgrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccquarc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccreporc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccscanrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccscherc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccupdrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccwebtabsrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\ccwgrdrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\factrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\guardmsg.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\licmgr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\lukeres.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\rchelp.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\rcimage.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\rctext.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\restartrc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\schedr.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\setup.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\updaterc.dll C:\Users\peter\AppData\Local\Temp\avnwldrtemp\setup\de-de\updguirc.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-26 18:32 ==================== End Of Log ============================ --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 26-08-2013 Ran by peter at 2013-08-26 18:34:52 Running from C:\Users\peter\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 50 FREE MP3s +1 Free Audiobook! (Version: 1.0.0.1) Adobe Flash Player 11 ActiveX (Version: 11.8.800.94) Adobe Reader 8.3.0 - Deutsch (Version: 8.3.0) Agere Systems HDA Modem AnyDVD (Version: 6.8.8.0) Apple Application Support (Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (Version: 2.1.3.127) ArcSoft PhotoImpression 6 (Version: 6.1.8.146) Ask Toolbar (Version: 1.15.20.0) Atheros WLAN Client (Version: 1.00.000) Avira Free Antivirus (Version: 13.0.0.3885) Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.2.4.37949) Bonjour (Version: 3.0.0.10) CloneDVD2 DVDVideoSoftTB Toolbar (Version: ) Easy Battery Manager (Version: 3.2.1.7) Free YouTube to MP3 Converter version 3.11.37.1212 (Version: 3.11.37.1212) Google Chrome (Version: 29.0.1547.57) Google Earth Plug-in (Version: 7.1.1.1888) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4413.1752) Google Update Helper (Version: 1.3.21.153) imagine digital freedom - Samsung (Version: 1.0.2.2) Intel PROSet Wireless Intel(R) PROSet/Wireless WiFi-Software (Version: 12.00.4000) iTunes (Version: 11.0.4.4) Java Auto Updater (Version: 2.0.6.1) Java(TM) 6 Update 30 (Version: 6.0.300) LabelPrint (Version: .2406) LG United Mobile Driver (Version: 3.7.2.0) LightScribe System Software 1.12.37.1 (Version: 1.12.37.1) McAfee Security Scan Plus (Version: 3.0.318.3) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1) Microsoft SQL Server Native Client (Version: 9.00.2047.00) Microsoft SQL Server VSS Writer (Version: 9.00.2047.00) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Namuga 1.3M Webcam (Version: 1.00.0000) Nero 6 NVIDIA Drivers OVT Scanner X86 (Version: 1.00.0000) PowerDVD (Version: 7.0.3118.0) Realtek High Definition Audio Driver (Version: 6.0.1.5605) Skat 8.4 (Version: 8.4.0.39) Skat24sv Skat-Online V9 Skype Toolbars (Version: 5.5.7896) Skype™ 6.6 (Version: 6.6.106) Synaptics Pointing Device Driver (Version: 10.1.2.0) Uninstall OVT Scanner Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.2047.00) Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) User Guide (Version: 1.0) Vimicro UVC Camera (Version: 1.00.0000) vShare Plugin WIDCOMM Bluetooth Software 6.0.1.6300 (Version: 6.0.1.6300) Winamp (Version: 5.601 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) Winamp Toolbar ==================== Restore Points ========================= 09-08-2013 15:19:35 Geplanter Prüfpunkt 10-08-2013 09:39:07 Geplanter Prüfpunkt 11-08-2013 10:32:28 Geplanter Prüfpunkt 12-08-2013 15:17:42 Geplanter Prüfpunkt 13-08-2013 17:55:55 Geplanter Prüfpunkt 14-08-2013 15:02:54 Geplanter Prüfpunkt 15-08-2013 11:27:25 Windows Update 17-08-2013 16:17:51 Geplanter Prüfpunkt 18-08-2013 10:31:59 Geplanter Prüfpunkt 21-08-2013 10:08:01 Geplanter Prüfpunkt 23-08-2013 12:38:25 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0261853F-ED34-422B-A482-36972D30F43A} - System32\Tasks\{4E31B958-5921-4FA9-9A8B-470917EC094D} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {04569AA2-EDD0-4FD1-9F4A-D01D0FD7A25F} - System32\Tasks\{35841863-EECB-4230-9B06-4C9E211A21AC} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {056B8496-11B4-4C4E-9111-87952579E6E2} - System32\Tasks\{DFEBC95A-BAC6-49A1-A5F5-556EC6B6160F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {0C508323-1D22-40B2-9CEA-33F41D00766D} - System32\Tasks\{FF6B1CE2-F38E-48AC-A4AC-14AA01406553} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {0F0606D6-8758-4076-97AE-0D7C227F5DF1} - System32\Tasks\{E63E9B10-E59B-46BC-925D-2265304BD115} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {10D8088E-C1D8-4F43-8726-CAD96BA0462B} - System32\Tasks\{A7E4ADFF-CE3C-4BDC-AAAB-AA801647FE42} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {16CA4294-4B8B-4461-AD41-EC4EEF31F459} - System32\Tasks\{1F461078-21AB-418E-B669-A3BE806434C1} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {19E6414D-ECC6-4F72-9091-E87A38D4D4FD} - System32\Tasks\{396FB8A3-E4B4-4A05-B143-E36BE5C074FD} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {1A64663D-5DFF-45B0-9278-85D2C8E6328C} - System32\Tasks\{84275FF1-5A5F-481B-B3EF-7CBA01F8622A} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {1C9A4230-020E-443D-BD67-8B878CBA7D21} - System32\Tasks\{0D26CBC7-D05E-4714-AD8F-26DCD34ED18C} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {1E44BD4D-5A9F-4022-BA87-33869234F453} - System32\Tasks\{21D52B12-4559-4357-9392-86AD9E2817F8} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {21984BBA-2481-4542-8AB8-1C28537C52E2} - System32\Tasks\{C44FB6A6-C4DE-4C53-BF68-8879023C3581} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {21E70F0A-19C2-4ECE-B06A-4C501FA788A6} - System32\Tasks\{B9387479-E56F-4D27-BD7C-6E074F806BCE} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {21F582B4-7E50-4393-927A-431F77DA85A7} - System32\Tasks\{3310201F-D9DB-44FB-9BD2-3EF455D8B140} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {29BC025C-2334-4622-B928-5012EB72C5FC} - System32\Tasks\{B91DF84B-F137-4349-B7F6-E543E38770F9} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {2AB83FC1-5DA9-457A-ADE8-BD382CFD92C3} - System32\Tasks\{04E27F83-E48E-46ED-AA79-371B936D989F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {35FF4A3F-EBFD-4B78-94DE-25F59CEE0EEB} - System32\Tasks\{4B0A7CEA-E2A8-43D6-B2E6-8AF3F81D2F32} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {3651833E-250B-4135-B759-950883CDD13F} - System32\Tasks\{46DBD40A-B1E5-4843-870E-258711B1522F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {39DEA4F1-4642-4208-8C10-3CDE24355734} - System32\Tasks\{114B6E23-E000-43E4-B3DC-FA0F3798E8B7} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3C829AEF-9486-4B68-A789-2A2A65055DA4} - System32\Tasks\{AC07C8F8-07B6-402E-8F4A-259E7051A1A8} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {3E29C35D-6CA7-4A53-BBA0-6BD309E3712F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-21] (Microsoft Corporation) Task: {417DC53B-0A60-4DF7-96B6-E0506C282F51} - System32\Tasks\{EA4840FF-B157-467D-8BCA-FB1572911987} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {425E967B-240D-41FB-B224-CACAD2D6F4F7} - System32\Tasks\{5E6B9B75-2F6E-4A8F-A81E-726705A3DA87} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {43A30557-566C-4BB7-BD1E-7016F1543971} - System32\Tasks\{5403D0A9-3BED-44A5-9D90-5D551F13E1EB} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {463682C6-9501-40B4-AAE7-D9D43FB4C4B1} - System32\Tasks\{64C6D176-3A73-47D8-97FA-E2EC70E6CF6C} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {48CB255F-611B-423A-B220-59E44763BD3E} - System32\Tasks\{F5F3E164-0686-4BE6-BEEC-C8BD93D7C954} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {48E3EFB6-77DD-496A-ADD8-7471C69C5854} - System32\Tasks\{C9FC7742-3457-44A5-AFD6-E8138F2F3DF2} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {49D432D3-E9C9-4880-A73E-1307851467ED} - System32\Tasks\{0C269852-6797-48BE-97AA-D7BB4A5AA6D0} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {4AF11A15-0A9F-4EB7-BCF3-E945284611D8} - System32\Tasks\{B5F8BC67-D127-4DFE-A494-E936C92ECD26} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {4CE32777-3092-462C-ABD7-A59CD095C0D0} - System32\Tasks\{22F33C26-A3DA-4882-A739-908B700EABF7} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {5155CDB8-59FE-4265-8356-C86E0A04265B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {5F2677C2-3398-44A1-A00A-A417E7DB0B31} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe [2013-03-11] () Task: {5F3CF44D-028B-404F-B2D2-84BD8A27531A} - System32\Tasks\{D2F59B4C-E42C-45D4-A1F5-1909A9F8576A} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {617E5EDE-0B13-442D-A87B-BE3F69857FFA} - System32\Tasks\{6F789592-F530-40CF-A5EF-BC787A2A3F98} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {62AEF66D-05E3-4CC0-BB27-38A1FBA85024} - System32\Tasks\WPD\SqmUpload_S-1-5-21-586206976-2465041360-4002502863-1003 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {62B1A842-5DD3-4BBB-AF09-26645959A73A} - System32\Tasks\{F15C2A16-F47F-48F5-A566-FC5EB8C5076A} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {685307C5-E8FE-4B03-BC9F-0B7EAB894832} - System32\Tasks\{C2BE2507-D2BE-404D-808F-66BF84C1F7AB} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {685D3CAF-8A57-44C8-BC88-D36BB58F7B31} - System32\Tasks\{9D1B7888-D614-4831-99DE-DBC71A854A1F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {6A9A99A9-2B21-4C40-99AC-5A4218F3FFAC} - System32\Tasks\{18DA9169-9538-4BE0-9BB5-B153DA7FA74E} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {6AC53978-32D9-4890-B91B-6EC0D0CFC50D} - System32\Tasks\{B0B6DA46-2D70-42CF-B476-7CC1EF30B23C} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {6BC7C1A9-349B-47A0-847C-45CE5CFC460D} - System32\Tasks\{3C1A2C93-04A2-44ED-BEAC-B25EA917917B} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {6FBD39DB-CB7B-4736-9E23-E372A8B9FC4C} - System32\Tasks\{DDD80422-9383-4000-8EB8-24AFB459625A} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {6FFE2A6A-41BB-4504-AE02-CE8B5F49ACC2} - System32\Tasks\{BF81DCFC-9C13-45DB-80C0-054C6751D561} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {7432E22C-B04D-4536-9527-F731BAF06F9A} - System32\Tasks\B2CNotiAgent => C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [2013-06-27] (LG Electronics) Task: {7AED5902-351E-48A5-9239-BA5232CE6CA4} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation) Task: {7C7E444B-4809-49A7-A263-F5A549398C51} - System32\Tasks\{3F5064DF-7329-461B-8A0D-95EC9078B866} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {7F9EC796-7E7F-44CA-82B6-380175EDB384} - System32\Tasks\{D54435C3-4721-43C0-9BBF-C8ED4C38FB35} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {7FE38288-20D8-4D91-A19F-1FB2CF6D0DC9} - System32\Tasks\{147E484E-FF51-473D-BCAB-BEF3B01E3520} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {802049F0-5435-4139-B5C3-897D4A4ADCA9} - System32\Tasks\{8F5FB7CB-EC1C-4F4C-844E-5BE8B385C83F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {8034440F-A375-47A2-A5AF-2D0AD61B3B15} - System32\Tasks\{850D5D4A-5CE7-4702-9243-64F3679F42D8} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {8912CF25-A40D-4177-907C-F8132C028F9C} - System32\Tasks\{315267FF-8EBC-4AAF-9557-7A22C02FCCC6} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {8C3CF2CC-7712-44B0-A1E5-1A6B62B41125} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-29] (Adobe Systems Incorporated) Task: {8EE0E8BE-35A1-46B4-BF47-2E2B973D2EB0} - System32\Tasks\{77955CCC-A298-4BB2-8B6D-05BD880C9600} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {8F57FEDC-5D21-43B5-A901-4E2C0A1D7216} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {92BC9B3F-35DF-43FB-928D-80F91FDCC8B2} - System32\Tasks\{FEB78E60-7472-4FAC-A24B-D8FF7BC94D25} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {93C01CF8-D35D-40D2-8095-714D6FF5FABA} - System32\Tasks\{EEF82CA2-9890-45FA-976C-F7D671238A1B} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {95AA632B-DCA0-413A-B459-6198ABB41B28} - System32\Tasks\{097CFC04-8779-47A2-83ED-2EDE28C483C0} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {995C721B-579C-42A7-A151-F5E607A108D2} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09] (Sun Microsystems, Inc.) Task: {9D2D1182-3FEF-469F-BED7-AFF1C5A60A64} - System32\Tasks\{14FB00D1-DA77-4922-8156-FF3C169150C3} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {A363C24E-3853-4758-BF34-4D1D6CBDB01C} - System32\Tasks\{8DF23DAB-228C-41EC-8ED2-6825FBB7D183} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {A4701146-4870-4E17-BC78-AC4D7E45C042} - System32\Tasks\{9E7D8499-81EF-4318-901E-19F99A920B0F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-21] (Microsoft Corporation) Task: {A6C1A9E2-A4A0-4DF4-9E1A-4710F1FF94FC} - System32\Tasks\{59DDA356-E6B0-4460-BCB3-E01497A3D093} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {ADBB2BF7-FDFA-4EA4-BF53-6128B77537DC} - System32\Tasks\{16482F09-FBB1-4FAC-9872-426EEAED89DC} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {AE24AEF2-37AE-428F-AD92-ADA28370D57C} - System32\Tasks\{9C906740-2C85-4AFC-8EE1-88D877E9134A} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {B21563E7-8EA3-47F4-9734-FCEFD88300D5} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2008-08-07] (SAMSUNG Electronics co., LTD.) Task: {B268EFEC-DF99-46DC-873B-91CA9088CE50} - System32\Tasks\{D0820779-54F9-4060-980F-A8E30B028D06} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {B50DE26D-F85F-4869-898D-047BFEC31FC1} - System32\Tasks\{847E396E-EFC2-407A-9886-4AA2DDCDA2E4} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {B69E3F43-6B54-4AEF-BD50-A2F45C84839B} - System32\Tasks\{796DBE6C-FFCF-407B-9C94-4FAA4AEF1B4E} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {B96B6FD4-25A5-4FC9-AE37-336EF428ECFB} - System32\Tasks\{D7532369-B725-4A97-9C40-FDA23A7C6DA9} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {BAFF64DD-46E4-46AA-8BF1-A7EC01C9F41B} - System32\Tasks\{EF0BEDD2-5195-4A9B-8A10-F75BCF5DE322} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {BBD60C3C-93DA-4F63-BB2B-57733B544D75} - System32\Tasks\{CF03B01B-9B29-4BC8-83D5-45D8E830154C} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {BC1B15AD-F2E4-43B1-B7F0-B84E43C0678B} - System32\Tasks\{07EB3F50-FF1A-4C2A-B667-ED87AE83519E} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {C136CFF2-E4FF-4380-9285-736D3F5220A0} - System32\Tasks\{623391DD-1D2D-4B85-BD86-A243D6BCC031} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {D0B29A6B-8828-404B-B9EB-8DEAA6358158} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D2CD8ED3-DC98-44A7-98E3-41C361B1D57B} - System32\Tasks\{C27A2D3A-B732-4B12-8EFB-F3CDF5ED919F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {D5871D96-995E-4FF4-92CA-E4E140FE2809} - System32\Tasks\{A6325BFB-A60E-4B63-A469-96E65C79E3F8} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {D5FF7535-B15A-4AA7-B0F6-FC7B34F3567D} - System32\Tasks\{EA27871F-9C70-49A0-9B64-4459070B4C4D} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {D9739852-96A5-40AC-B4E0-5EB6181B50A1} - System32\Tasks\{21D5A164-5BBF-4538-873D-149E4CD27EA2} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {DE5C8208-CBF9-4787-9F11-BC101A6DE616} - System32\Tasks\{0BBF99E0-5A1A-485A-97EE-545334945CFF} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {E10E29AA-7DF7-4C1B-B6E8-8FABA465FC58} - System32\Tasks\{56E26283-AB4A-470D-8EF1-3191963D6B21} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {E4A2A330-87ED-4F5E-9F8A-5BBEDD732B9E} - System32\Tasks\{2984F95C-7FC3-4DA8-A63D-EA4508B3C91F} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {E51889C1-465E-46EA-9B5F-4C6B95014E45} - System32\Tasks\{2DB86F37-EC08-4E43-B104-BB183E55541D} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {EA648595-5E68-4DF8-96B2-FA4ACED68F7A} - System32\Tasks\{B355AEC5-B969-4BEE-B47E-72B9F44EBCCA} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {EAE4DB22-0717-4427-B46A-984F17B734C2} - System32\Tasks\{596FBBDE-5572-428E-8947-80B065C5A372} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {ECAB8C41-E95A-472A-B735-8B4FD6F9206C} - System32\Tasks\{2732E24C-DA48-492C-85BC-7D765AE11AC2} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {F39ABBDE-0CFC-4C89-8CBA-F474C2FFC997} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-16] (Adobe Systems Incorporated) Task: {F9C78719-0C29-4ED4-9383-CB471B0D1C30} - System32\Tasks\{946DB541-3313-4AD0-B9CE-0C6BE514A7CC} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {FDD3FB64-5A5F-41B1-9666-20EDA6C5619B} - System32\Tasks\{F8F9651B-7707-4AEC-8204-6D339D158ED4} => C:\Program Files\Internet Explorer\iexplore.exe [2013-07-25] (Microsoft Corporation) Task: {FF54EC00-0D04-4456-8047-38FF54A1281C} - System32\Tasks\{2C42A756-FCBA-4351-927D-3E245D04923B} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/26/2013 06:28:07 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 04:22:33 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 04:10:00 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 03:54:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 03:52:15 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Details: Could not query the status of the EventSystem service. System Error: Der Computer wird heruntergefahren. Error: (08/26/2013 03:36:17 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 03:32:31 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 06:07:20 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 06:01:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 05:41:10 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/26/2013 06:28:08 PM) (Source: Service Control Manager) (User: ) Description: iaStor Error: (08/26/2013 06:28:08 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (08/26/2013 04:22:33 PM) (Source: Service Control Manager) (User: ) Description: iaStor Error: (08/26/2013 04:22:33 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (08/26/2013 04:10:01 PM) (Source: Service Control Manager) (User: ) Description: iaStor Error: (08/26/2013 04:10:01 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (08/26/2013 03:54:35 PM) (Source: Service Control Manager) (User: ) Description: iaStor Error: (08/26/2013 03:54:35 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (08/26/2013 03:48:20 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: C:\Windows\system32\athihvs.dll21 Error: (08/26/2013 03:47:55 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 26.08.2013 um 15:46:12 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= Error: (08/26/2013 06:28:07 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 04:22:33 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 04:10:00 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 03:54:35 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 03:52:15 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: Could not query the status of the EventSystem service. System Error: Der Computer wird heruntergefahren. Error: (08/26/2013 03:36:17 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/26/2013 03:32:31 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 06:07:20 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 06:01:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/25/2013 05:41:10 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2008-10-09 13:54:29.117 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2008-10-09 13:54:29.086 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2008-10-09 13:54:29.070 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2008-10-09 13:54:29.024 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 34% Total physical RAM: 3065.88 MB Available physical RAM: 2020.49 MB Total Pagefile: 6368.16 MB Available Pagefile: 5307.52 MB Total Virtual: 2047.88 MB Available Virtual: 1916.21 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:100.25 GB) (Free:48.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:187.83 GB) (Free:187.74 GB) NTFS Drive f: () (Removable) (Total:0.95 GB) (Free:0.94 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: ECE69603) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=188 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 968 MB) (Disk ID: 00292BAC) Partition 1: (Active) - (Size=968 MB) - (Type=06) ==================== End Of Log ============================ |
26.08.2013, 17:43 | #6 |
/// TB-Ausbilder | GVU Trojaner Wie läuft der Rechner? Alles normal? Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 ESET Online Scanner
Bitte poste in deiner nächsten Antwort:
__________________ --> GVU Trojaner |
26.08.2013, 19:16 | #7 |
| GVU TrojanerCode:
ATTFilter # AdwCleaner v3.001 - Report created 26/08/2013 at 18:48:14 # Updated 24/08/2013 by Xplode # Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Username : peter - PETER-PC # Running from : C:\Users\peter\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\apn Folder Deleted : C:\ProgramData\Winamp Toolbar Folder Deleted : C:\Program Files\Ask.com Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\DVDVideoSoftTB Folder Deleted : C:\Program Files\vShare Folder Deleted : C:\Program Files\Winamp Toolbar Folder Deleted : C:\Program Files\Common Files\DVDVideoSoft\TB Folder Deleted : C:\Program Files\Common Files\Plasmoo Folder Deleted : C:\Users\peter\AppData\Local\apn Folder Deleted : C:\Users\peter\AppData\Local\AskToolbar Folder Deleted : C:\Users\peter\AppData\Local\Winamp Toolbar Folder Deleted : C:\Users\peter\AppData\Local\Temp\AskSearch Folder Deleted : C:\Users\peter\AppData\Local\Temp\Smartbar Folder Deleted : C:\Users\peter\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\peter\AppData\LocalLow\Conduit Folder Deleted : C:\Users\peter\AppData\LocalLow\DVDVideoSoftTB Folder Deleted : C:\Users\peter\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\peter\AppData\LocalLow\vShare Folder Deleted : C:\Users\peter\AppData\Roaming\dvdvideosoftiehelpers Folder Deleted : C:\Users\peter\AppData\Roaming\OpenCandy File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Shortcuts ] ***** ***** [ Registry ] ***** [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F2677C2-3398-44A1-A00A-A417E7DB0B31} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F2677C2-3398-44A1-A00A-A417E7DB0B31} Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\vsharechrome Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1 Key Deleted : HKLM\SOFTWARE\Classes\vShare.IMedixProtocol Key Deleted : HKLM\SOFTWARE\Classes\vShare.IMedixProtocol.1 Key Deleted : HKLM\SOFTWARE\Classes\vShare.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\vShare.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\vShare.ScriptHelpers Key Deleted : HKLM\SOFTWARE\Classes\vShare.ScriptHelpers.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1 Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Key Deleted : HKLM\SOFTWARE\Classes\AppID\ Key Deleted : HKLM\SOFTWARE\Classes\AppID\ Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\ Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF9A17DA-4818-4C8D-BDB4-B8BBCD0F2F8E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{06098AF3-9406-4171-9486-3ECB08D5D295} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\ Key Deleted : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{20ED5AF7-D9C4-409E-9EB3-D2A44A77FB6D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057} Key Deleted : HKLM\SOFTWARE\Classes\Interface\ Key Deleted : HKLM\SOFTWARE\Classes\Interface\ Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{0C58B7D1-D415-492B-A149-E976156BD3B8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3E315C81-442B-431C-AEC8-ED189699EC24} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\ Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\ Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\ Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\ Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\ Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{06098AF3-9406-4171-9486-3ECB08D5D295} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\ Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\ Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\ Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{043C5167-00BB-4324-AF7E-62013FAEDACF}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{043C5167-00BB-4324-AF7E-62013FAEDACF}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\vShare Key Deleted : HKCU\Software\Winamp Toolbar Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKLM\Software\APN Key Deleted : HKLM\Software\AskToolbar Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DVDVideoSoftTB Key Deleted : HKLM\Software\InstallIQ Key Deleted : HKLM\Software\Winamp Toolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vShare Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\vShare Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar Product Deleted : Ask Toolbar ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16502 Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar] Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL] Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] -\\ Google Chrome v29.0.1547.57 [ File : C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [19786 octets] - [26/08/2013 18:47:22] AdwCleaner[S0].txt - [17831 octets] - [26/08/2013 18:48:14] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17892 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.26.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 peter :: PETER-PC [Administrator] 26.08.2013 19:02:52 mbam-log-2013-08-26 (19-02-52).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 208883 Laufzeit: 7 Minute(n), 15 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=6e091c1c311d0d439f23036256b6541c # engine=14908 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-26 06:10:04 # local_time=2013-08-26 08:10:04 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 97 15065 148211909 7811 0 # compatibility_mode=5892 16776574 66 100 35365975 215073332 0 0 # scanned=137925 # found=3 # cleaned=0 # scan_time=3044 sh=6E130EF22197401BB4451DF5EBF3D7182AE86DA3 ft=0 fh=0000000000000000 vn="Win32/Spy.SpyEye.CFG.A trojan" ac=I fn="C:\Recicle\DC9E1109FD19AF2" sh=D10A393D81C7F92F04CD1F4E36C818F83DD57B10 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.PJI trojan" ac=I fn="C:\Users\peter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\6d191a80-7a291426" sh=3B0992B284AA48D854E86AD5D517B45DC8BEBB7D ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.PJI trojan" ac=I fn="C:\Users\peter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\8faa7e-7cf76e8f" |
26.08.2013, 19:23 | #8 |
/// TB-Ausbilder | GVU Trojaner ok. Scan mit Combofix
__________________ cheers, Leo |
26.08.2013, 19:47 | #9 |
| GVU TrojanerCode:
ATTFilter ComboFix 13-08-25.01 - peter 26.08.2013 20:37:50.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3066.1862 [GMT 2:00] ausgeführt von:: c:\users\peter\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini c:\windows\27A79DE698F3EF4D.log . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-26 bis 2013-08-26 )))))))))))))))))))))))))))))) . . 2013-08-27 02:04 . 2013-08-27 02:04 -------- d-----w- C:\FRST 2013-08-26 18:43 . 2013-08-26 18:43 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-26 16:52 . 2013-08-26 16:52 -------- d-----w- c:\users\peter\AppData\Roaming\Malwarebytes 2013-08-26 16:52 . 2013-08-26 16:52 -------- d-----w- c:\programdata\Malwarebytes 2013-08-26 16:52 . 2013-08-26 16:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-08-26 16:52 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-08-26 16:47 . 2013-08-26 16:48 -------- d-----w- C:\AdwCleaner 2013-08-14 19:47 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll 2013-08-14 19:47 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys 2013-08-14 19:47 . 2013-07-05 04:53 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-14 19:47 . 2013-07-17 19:41 2048 ----a-w- c:\windows\system32\tzres.dll 2013-08-14 19:47 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-14 19:47 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll 2013-08-14 19:47 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-14 19:47 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-14 19:47 . 2013-07-08 04:20 172544 ----a-w- c:\windows\system32\wintrust.dll 2013-08-14 19:47 . 2013-07-08 04:16 98304 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-14 19:47 . 2013-07-08 04:16 133120 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-14 19:47 . 2013-07-08 04:16 992768 ----a-w- c:\windows\system32\crypt32.dll 2013-08-02 10:49 . 2013-08-02 10:49 -------- d-----w- c:\users\peter\AppData\Local\Apple Computer 2013-08-02 10:49 . 2013-08-02 10:53 -------- d-----w- c:\users\peter\AppData\Roaming\Apple Computer 2013-08-02 10:49 . 2013-08-02 10:49 -------- dc----w- c:\windows\system32\DRVSTORE 2013-08-02 10:49 . 2012-08-21 11:01 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2013-08-02 10:47 . 2013-08-02 10:47 -------- d-----w- c:\program files\iPod 2013-08-02 10:47 . 2013-08-02 10:48 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-08-02 10:47 . 2013-08-02 10:48 -------- d-----w- c:\program files\iTunes 2013-08-02 10:47 . 2013-08-02 10:47 -------- d-----w- c:\programdata\Apple Computer 2013-08-02 10:46 . 2013-08-02 10:46 -------- d-----w- c:\users\peter\AppData\Local\Apple 2013-08-02 10:46 . 2013-08-02 10:46 -------- d-----w- c:\program files\Apple Software Update 2013-08-02 10:43 . 2013-08-02 10:44 -------- d-----w- c:\program files\Bonjour 2013-08-02 10:43 . 2013-08-02 10:47 -------- d-----w- c:\program files\Common Files\Apple 2013-07-28 06:25 . 2013-08-15 11:41 -------- d-----w- c:\windows\system32\MRT . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-16 15:39 . 2012-04-02 14:21 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-16 15:39 . 2011-05-15 06:00 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-06-04 01:50 . 2013-07-10 14:50 2049024 ----a-w- c:\windows\system32\win32k.sys 2013-06-01 04:06 . 2013-07-10 14:49 505344 ----a-w- c:\windows\system32\qedit.dll 2013-02-06 12:01 . 2013-02-06 12:01 4126720 ----a-w- c:\program files\GUT89F7.tmp . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-17 2289664] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-12 39408] "AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2011-10-11 5389944] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-21 19875432] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-26 13548064] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-26 92704] "RtHDVCpl"="RtHDVCpl.exe" [2008-04-17 6111232] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-06 74752] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-05-31 152392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] " Malwarebytes Anti-Malware "="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "B2C_AGENT"=c:\programdata\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - MBAMSWISSARMY *Deregistered* - avipbb *Deregistered* - MBAMSwissArmy *Deregistered* - ssmdrv . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-03-17 08:56 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-08-20 19:10 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-08-26 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 15:39] . 2013-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 06:49] . 2013-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-12 06:49] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.bild.de/ uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: Free YouTube to MP3 Converter - c:\users\peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.188.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . SafeBoot-WudfPf SafeBoot-WudfRd AddRemove-OVT Scanner - c:\windows\omniuns.exe USB\Vid_05a9&PID_1550 OVT Scanner . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-08-26 20:43 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'Explorer.exe'(3164) c:\windows\system32\btmmhook.dll . Zeit der Fertigstellung: 2013-08-26 20:46:16 ComboFix-quarantined-files.txt 2013-08-26 18:45 . Vor Suchlauf: 10 Verzeichnis(se), 55.603.810.304 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 55.773.851.648 Bytes frei . - - End Of File - - AD296F3D18D15AF4E4D6FBDCEF1C6409 61A349592C4728853F4A90FF78F7628E |
26.08.2013, 19:56 | #10 |
/// TB-Ausbilder | GVU Trojaner ok. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter CMD: dir /a/b "C:\" Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ cheers, Leo |
26.08.2013, 20:03 | #11 |
| GVU TrojanerCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-08-2013 Ran by peter at 2013-08-26 21:02:32 Run:2 Running from C:\Users\peter\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** CMD: dir /a/b "C:\" ***************** ========= dir /a/b "C:\" ========= $RECYCLE.BIN AdwCleaner autoexec.bat Boot bootmgr BOOTSECT.BAK ComboFix ComboFix.txt config.sys Documents and Settings Dokumente und Einstellungen FRST hiberfil.sys IO.SYS LGP500 MSDOS.SYS MyWorks pagefile.sys PerfLogs Program Files ProgramData Programme Qoobox Recicle RHDSetup.log setup.log System Volume Information Users windiag Windows _wdsuef.dmp ========= End of CMD: ========= ==== End of Fixlog ==== |
26.08.2013, 20:17 | #12 |
/// TB-Ausbilder | GVU Trojaner Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Recicle Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ cheers, Leo |
26.08.2013, 20:20 | #13 |
| GVU TrojanerCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-08-2013 Ran by peter at 2013-08-26 21:20:04 Run:3 Running from C:\Users\peter\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Recicle ***************** C:\Recicle => Moved successfully. ==== End of Fixlog ==== |
26.08.2013, 20:26 | #14 |
/// TB-Ausbilder | GVU Trojaner So, dann wärs das jetzt. Wir räumen auf. Schritt 1 Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Schritt 2 Dein Java ist nicht mehr aktuell. Ältere Versionen enthalten Sicherheitslücken, die von Malware zur Infizierung per Drive-by Download missbraucht werden können. Die aktuelle Version ist Java 7 Update 25.
Überleg dir also, ob du eine Java-Installation wirklich brauchst. Falls du Java weiterhin verwenden möchtest, dann:
Schritt 3 Die Version deines Adobe PDF Readers ist veraltet, wir müssen ihn updaten:
Überprüfe dann mit diesem Plugin-Check (mit dem Firefox hier), ob nun alle deine verwendeten Versionen aktuell sind und update sie anderenfalls. Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
26.08.2013, 20:28 | #15 |
| GVU Trojaner Ok. Das mache ich jetzt noch alles. Vielen vielen Dank. Hätte das alleine nie hinbekommen. Klasse das ihrso etwas macht. Vielen Dank nochmal. gruss, Peter |
Themen zu GVU Trojaner |
antivir, association, avg, avira, crypt, defender, desktop, explorer, explorer.exe, farbar, farbar recovery scan tool, google, home, log-datei, microsoft, nvidia, opera, realtek, registry, scan, security, services.exe, software, svchost.exe, system, temp, trojaner, vcredist, vista, winlogon.exe |