Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: GVU Trojaner | WinVista32bit

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 03.09.2013, 13:42   #1
pascal1994
 
GVU Trojaner | WinVista32bit - Unglücklich

GVU Trojaner | WinVista32bit



Hallo Forum ,
Ich bin leider wieder an den GVU Trojaner geraten...
Ich habe mit FRST schonmal den Computer durchscannen lassen und poste den Text hier rein.
Ich hoffe um schnelle Hilfe

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-07-2013 (ATTENTION: FRST version is 46 days old)
Ran by SYSTEM on 03-09-2013 14:30:18
Running from G:\
Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Policies\Explorer\Run: [blank] C:\Users\noli\AppData\Roaming\update.exe [x]
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll [X]
HKU\Default\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\Default\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\Default User\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\Default User\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\noli\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-20] (Microsoft Corporation)
HKU\noli\...\Run: [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\noli\...\Run: [blank] - C:\Users\noli\AppData\Roaming\update.exe [ 2009-03-29] (Microsoft Corporation)
HKU\noli\...\Run: [Spotify Web Helper] - "C:\Users\noli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [x]
HKU\noli\...\Run: [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKU\noli\...\Run: [icq] - C:\Users\noli\AppData\Roaming\ICQM\icq.exe -CU [ 2013-01-10] (ICQ)
HKU\noli\...\Run: [Pando Media Booster] - C:\Program Files\Pando Networks\Media Booster\PMB.exe [ 2013-02-04] ()
HKU\noli\...\Run: [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKU\noli\...\Run: [Spotify] - "C:\Users\noli\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [x]
HKU\noli\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin [ 2013-06-11] (Adobe Systems Incorporated)
HKU\noli\...\Policies\system: [LogonHoursAction] 2
HKU\noli\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\TEMP\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\TEMP\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\UpdatusUser\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\UpdatusUser\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-20] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [RGSC] - C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent [x]
HKU\UpdatusUser\...\Run: [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\UpdatusUser\...\Run: [csrss] - C:\Users\UpdatusUser\AppData\Roaming\csrss .exe [x]
HKU\UpdatusUser\...\Run: [blank] - C:\Users\UpdatusUser\AppData\Roaming\update.exe [x]
HKU\UpdatusUser\...\Run: [msvcnp] - C:\Users\UpdatusUser\AppData\Roaming\msvcnp .exe [x]
HKU\UpdatusUser\...\Run: [spotimote] - "C:\Program Files\spotimote\spotimote.exe" C:\Program Files\spotimote\ [x]
HKU\UpdatusUser\...\Run: [Spotify] - "C:\Users\noli\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart [x]
HKU\UpdatusUser\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\UpdatusUser\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil11f_Plugin.exe -update plugin [x]
HKU\UpdatusUser\...\Policies\system: [LogonHoursAction] 2
HKU\UpdatusUser\...\Policies\system: [DontDisplayLogonHoursWarnings] 1

========================== Services (Whitelisted) =================

S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [136360 2011-04-27] (Avira GmbH)
S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [269480 2011-06-28] (Avira GmbH)
S2 Browser Manager; C:\ProgramData\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2847696 2013-07-26] ()
S2 DefaultTabSearch; C:\Program Files\DefaultTab\DefaultTabSearch.exe [572928 2013-02-10] ()
S2 DefaultTabUpdate; C:\Users\noli\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [107520 2013-02-11] ()
S2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-11-28] ()
S2 hasplms; C:\Windows\system32\hasplms.exe [2869760 2009-04-21] (Aladdin Knowledge Systems Ltd.)
S2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1016112 2013-05-16] ()
S2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
S2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2253120 2011-10-15] (NVIDIA Corporation)
S2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2012-05-15] ()
S2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1723744 2012-11-29] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

S2 aksfridge; C:\Windows\system32\drivers\aksfridge.sys [352256 2009-01-16] (Aladdin Knowledge Systems Ltd.)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-06-28] (Avira GmbH)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-06-28] (Avira GmbH)
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-11-23] (DT Soft Ltd)
S3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-15] (SlySoft, Inc.)
S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [24232 2009-02-17] (Elaborate Bytes AG)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S2 hardlock; C:\Windows\system32\drivers\hardlock.sys [587776 2009-07-09] (Aladdin Knowledge Systems Ltd.)
S3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [5632 2008-10-08] (Windows (R) Codename Longhorn DDK provider)
S2 int15; C:\Windows\system32\drivers\int15.sys [69632 2008-03-12] ()
S3 LADF_CaptureOnly; C:\Windows\System32\DRIVERS\ladfGSCi386.sys [378568 2011-04-11] (Logitech)
S3 LADF_DHP2; C:\Windows\System32\DRIVERS\ladfDHP2i386.sys [53976 2010-09-29] (Logitech)
S3 LADF_RenderOnly; C:\Windows\System32\DRIVERS\ladfGSRi386.sys [317384 2011-04-11] (Logitech)
S3 LADF_SBVM; C:\Windows\System32\DRIVERS\ladfSBVMi386.sys [335064 2010-09-29] (Logitech)
S3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-23] (Logitech Inc.)
S3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-23] (Logitech Inc.)
S3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [37392 2009-06-17] (Logitech, Inc.)
S3 nuvotonhidgeneric; C:\Windows\System32\DRIVERS\nuvotonhidgeneric.sys [22528 2008-10-08] (Nuvoton Technology Corporation)
S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2012-11-23] (Duplex Secure Ltd.)
S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
S3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-11-16] (TuneUp Software)
S3 USB_RNDIS; C:\Windows\System32\DRIVERS\usb8023.sys [15872 2013-02-11] (Microsoft Corporation)
S3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex)
S3 WSVD; C:\Windows\system32\drivers\WSVD.sys [81704 2008-05-26] (CyberLink)
S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [521216 2008-01-20] (Microsoft Corporation)
S3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [56448 2009-04-08] (Microsoft Corporation)
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 nmwcd; system32\drivers\ccdcmb.sys [x]
S3 nmwcdc; system32\drivers\ccdcmbo.sys [x]
S3 nmwcdnsu; system32\drivers\nmwcdnsu.sys [x]
S3 nmwcdnsuc; system32\drivers\nmwcdnsuc.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x]
S3 UsbserFilt; system32\DRIVERS\usbser_lowerfltj.sys [x]
S3 WDC_SAM; system32\DRIVERS\wdcsam.sys [x]
S3 WisINT15; \??\C:\Elements\1stboot\WisINT15.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-28 10:17 - 2013-08-01 20:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-08-17 17:37 - 2013-08-17 17:40 - 00000000 ____D C:\Windows\System32\MRT
2013-08-17 17:05 - 2013-07-24 18:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-08-17 17:05 - 2013-07-24 18:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-08-17 17:05 - 2013-07-24 18:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-08-17 17:05 - 2013-07-24 18:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-08-17 17:05 - 2013-07-24 18:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-08-17 17:05 - 2013-07-24 18:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-08-17 17:05 - 2013-07-24 18:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-08-17 17:05 - 2013-07-24 18:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-08-17 17:05 - 2013-07-24 18:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-08-17 17:05 - 2013-07-24 18:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-08-17 17:05 - 2013-07-24 18:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-08-17 17:05 - 2013-07-24 18:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-08-17 17:05 - 2013-07-24 18:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-08-17 17:05 - 2013-07-24 18:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-08-17 17:05 - 2013-07-24 18:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-08-17 17:05 - 2013-07-24 18:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-08-17 09:20 - 2013-07-17 11:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-08-17 09:20 - 2013-07-04 20:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-08-17 09:20 - 2013-06-15 05:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\icaapi.dll
2013-08-17 09:20 - 2013-06-15 03:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys
2013-08-17 09:19 - 2013-07-10 01:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2013-08-17 09:19 - 2013-07-09 04:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-08-17 09:19 - 2013-07-07 20:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2013-08-17 09:19 - 2013-07-07 20:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-08-17 09:19 - 2013-07-07 20:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2013-08-17 09:19 - 2013-07-07 20:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-08-17 09:19 - 2013-07-07 20:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-08-17 09:19 - 2013-07-07 20:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll

==================== One Month Modified Files and Folders =======

2013-09-03 04:27 - 2009-01-16 08:08 - 00000000 _____ C:\Windows\System32\LogConfigTemp.xml
2013-09-03 04:26 - 2006-11-02 04:47 - 00003216 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-03 04:26 - 2006-11-02 04:47 - 00003216 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-03 04:25 - 2012-03-14 18:23 - 01558924 _____ C:\Windows\PFRO.log
2013-09-02 05:31 - 2009-01-16 07:51 - 01552938 _____ C:\Windows\WindowsUpdate.log
2013-09-01 03:13 - 2012-03-25 13:14 - 00000000 ____D C:\Users\noli\AppData\Roaming\Spotify
2013-08-28 17:00 - 2012-03-25 13:14 - 00000000 ____D C:\Users\noli\AppData\Local\Spotify
2013-08-25 09:32 - 2010-06-06 02:19 - 00000000 ____D C:\Users\noli\AppData\Roaming\Skype
2013-08-18 05:35 - 2009-03-17 09:10 - 00000000 ___RD C:\Users\noli\Desktop
2013-08-18 05:35 - 2006-11-02 02:33 - 00005780 _____ C:\Windows\System32\PerfStringBackup.INI
2013-08-18 03:04 - 2012-05-22 08:17 - 00000000 ____D C:\Users\noli\AppData\Local\PMB Files
2013-08-17 18:16 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache
2013-08-17 18:15 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-17 17:56 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\de-DE
2013-08-17 17:40 - 2013-08-17 17:37 - 00000000 ____D C:\Windows\System32\MRT
2013-08-17 17:37 - 2006-11-02 02:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\System32\mrt.exe
2013-08-17 17:34 - 2008-11-19 19:57 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-17 09:00 - 2010-10-03 09:15 - 00000680 __RSH C:\Users\noli\ntuser.pol
2013-08-17 09:00 - 2009-03-17 09:10 - 00000000 ____D C:\users\noli
2013-08-17 08:59 - 2012-09-12 12:29 - 00000000 ____D C:\ProgramData\Browser Manager

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-07-31 05:47:58
Restore point made on: 2013-08-17 09:18:07
Restore point made on: 2013-08-17 17:01:50
Restore point made on: 2013-08-19 03:15:10
Restore point made on: 2013-08-22 11:40:44
Restore point made on: 2013-08-23 05:13:06
Restore point made on: 2013-08-27 05:44:00
Restore point made on: 2013-08-28 17:00:52
Restore point made on: 2013-08-29 09:24:36

==================== Memory info =========================== 

Percentage of memory in use: 15%
Total physical RAM: 4089.93 MB
Available physical RAM: 3468.12 MB
Total Pagefile: 3780.2 MB
Available Pagefile: 3615.49 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.64 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:142.65 GB) (Free:1.09 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:142.67 GB) (Free:22.56 GB) NTFS
Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:0.61 GB) FAT32
Drive g: (LEXAR) (Removable) (Total:3.73 GB) (Free:2.08 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 18C07842)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=143 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=143 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=3 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=4 GB) - (Type=0B)


LastRegBack: 2013-08-18 18:13

==================== End Of Log ============================
         

 

Themen zu GVU Trojaner | WinVista32bit
.dll, adobe, association, avira, browser, computer, desktop, explorer, farbar, farbar recovery scan tool, google, helper, home, log, microsoft, nvidia, popup, registry, services.exe, software, spotify web helper, svchost.exe, system, temp, trojaner, usb, vista, windows xp, winlogon.exe





Zum Thema GVU Trojaner | WinVista32bit - Hallo Forum , Ich bin leider wieder an den GVU Trojaner geraten... Ich habe mit FRST schonmal den Computer durchscannen lassen und poste den Text hier rein. Ich hoffe um - GVU Trojaner | WinVista32bit...
Archiv
Du betrachtest: GVU Trojaner | WinVista32bit auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.