|
Plagegeister aller Art und deren Bekämpfung: Ist Mein Rechner Infiziert?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.09.2013, 13:24 | #16 |
| Ist Mein Rechner Infiziert?Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-09-2013 01 Ran by Muri at 2013-09-07 14:16:14 Running from C:\Users\Muri\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.7) Battlefield 3™ (x32 Version: 1.6.0.0) Battlelog Web Plugins (x32 Version: 2.1.7) ESN Sonar (x32 Version: 0.70.4) Fraps (remove only) (x32) Intel(R) Management Engine Components (x32 Version: 7.0.0.1118) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MozBackup 1.5.1 (x32) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) Norton Internet Security (x32 Version: 20.4.0.40) Notepad++ (x32 Version: 6.4.5) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) ON_OFF Charge B11.1102.1 (x32 Version: 1.00.0001) Origin (x32 Version: 9.3.2.2730) PunkBuster Services (x32 Version: 0.991) Realtek Ethernet Controller Driver (x32 Version: 7.49.927.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6662) ROCCAT Kone[+] Mouse Driver (x32) rosoft .NET Framework 4 Client Profile (Version: 4.0.30319) Skype™ 6.7 (x32 Version: 6.7.102) Steam (x32 Version: 1.0.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) WinRAR 5.00 (64-Bit) (Version: 5.00.0) ==================== Restore Points ========================= 30-08-2013 13:42:24 Windows Update 30-08-2013 16:11:10 Windows Update 31-08-2013 11:42:21 Windows Update 01-09-2013 10:07:52 Windows Update 03-09-2013 17:08:39 Konfiguriert Atheros Communications Inc.(R) AR81Family Gigabit/FDvä$ 04-09-2013 20:40:46 Norton_Power_Eraser_20130904224044077 ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-09-05 21:20 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {0FD903B3-DA1D-45BE-B1AE-87A44898C8BF} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {9C66B505-FEAE-4D46-9169-955E4ECF3030} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {A8120F0D-C57A-4B1B-8C3D-B170C4AC9E25} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-29] (Adobe Systems Incorporated) Task: {BBFE1225-BE5A-409B-A7B5-B9CBA2805C50} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {C394F3E4-15FC-4587-A4F3-452F0EAF73DE} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-28 21:12 - 2013-06-21 14:06 - 15920536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-08-29 12:53 - 2013-08-22 19:01 - 00214104 _____ (Alexander Roshal) C:\Program Files\WinRAR\rarext.dll 2013-08-31 14:30 - 2013-06-04 06:45 - 00243536 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\20.4.0.40\NavShExt.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 01060232 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\20.4.0.40\ccL120U.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00119176 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\20.4.0.40\ccVrTrst.dll 2013-08-31 14:30 - 2013-05-23 07:25 - 00114056 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\20.4.0.40\EFACli64.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00475528 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\20.4.0.40\ccSet.dll 2013-08-31 14:30 - 2013-05-30 03:23 - 00553264 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\20.4.0.40\diStRptr.dll 2013-08-29 08:32 - 2011-11-17 07:38 - 01292080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-29 08:33 - 2012-11-30 06:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\syswow64\kernel32.dll 2013-08-29 08:33 - 2012-11-30 06:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\syswow64\KERNELBASE.dll 2013-07-15 22:58 - 2013-07-15 22:58 - 00290232 _____ (Symantec Corporation) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\BASHDefs\20130715.001\UMEngx86.dll 2013-08-29 08:32 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\syswow64\msvcrt.dll 2013-08-29 17:44 - 2010-11-20 14:21 - 01667584 _____ (Microsoft Corporation) C:\Windows\syswow64\SETUPAPI.dll 2013-08-29 08:32 - 2011-05-24 12:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\syswow64\CFGMGR32.dll 2013-08-30 14:17 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\syswow64\RPCRT4.dll 2013-08-29 08:28 - 2012-06-02 06:34 - 00096768 _____ (Microsoft Corporation) C:\Windows\syswow64\SspiCli.dll 2009-07-14 01:12 - 2009-07-14 03:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\syswow64\CRYPTBASE.dll 2009-07-14 01:11 - 2009-07-14 03:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2013-08-29 17:44 - 2010-11-20 14:18 - 00640512 _____ (Microsoft Corporation) C:\Windows\syswow64\ADVAPI32.dll 2013-08-29 17:44 - 2010-11-20 14:08 - 00311296 _____ (Microsoft Corporation) C:\Windows\syswow64\GDI32.dll 2013-08-29 17:44 - 2010-11-20 14:08 - 00833024 _____ (Microsoft Corporation) C:\Windows\syswow64\USER32.dll 2009-07-14 01:25 - 2009-07-14 03:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\syswow64\LPK.dll 2013-08-29 08:33 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\syswow64\USP10.dll 2013-08-29 08:32 - 2011-08-27 06:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\syswow64\OLEAUT32.dll 2013-08-29 17:44 - 2010-11-20 14:20 - 01414144 _____ (Microsoft Corporation) C:\Windows\syswow64\ole32.dll 2013-08-29 08:32 - 2011-05-24 12:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\syswow64\DEVOBJ.dll 2009-07-14 01:28 - 2009-07-14 03:15 - 00828928 _____ (Microsoft Corporation) C:\Windows\syswow64\MSCTF.dll 2013-08-30 14:17 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\syswow64\WINTRUST.dll 2013-08-30 14:17 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\syswow64\CRYPT32.dll 2013-08-29 17:44 - 2010-11-20 14:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\syswow64\MSASN1.dll 2013-08-29 17:44 - 2010-11-20 14:21 - 00269824 _____ (Microsoft Corporation) C:\Windows\syswow64\WLDAP32.dll 2013-08-29 17:44 - 2010-11-20 14:21 - 00350208 _____ (Microsoft Corporation) C:\Windows\syswow64\SHLWAPI.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00705928 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccL120U.dll 2009-07-14 01:12 - 2009-07-14 03:16 - 00008704 _____ (Microsoft Corporation) C:\Windows\syswow64\NSI.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00089480 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccVrTrst.dll 2013-08-31 14:30 - 2013-05-23 07:25 - 00086408 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\EFACli.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00157576 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvc.dll 2013-08-31 14:30 - 2013-05-21 06:40 - 00410576 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\srtsp32.dll 2013-08-30 14:17 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\syswow64\SHELL32.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00159624 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccIPC.dll 2013-08-31 14:30 - 2013-05-30 03:22 - 00556336 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\DIMASTER.DLL 2013-08-31 14:30 - 2013-05-21 06:44 - 00345480 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSet.dll 2009-07-14 01:44 - 2009-07-14 03:15 - 00522240 _____ (Microsoft Corporation) C:\Windows\syswow64\CLBCatQ.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 00205136 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\FWSETUP.DLL 2013-08-31 14:30 - 2013-04-25 02:43 - 00240560 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymNeti.dll 2009-07-14 01:53 - 2009-07-14 03:15 - 00462848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00289160 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccGEvt.dll 2013-08-31 14:35 - 2013-07-22 09:17 - 00813904 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\COSVCPLG.DLL 2013-08-31 14:30 - 2013-05-21 06:44 - 00207240 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccGLog.dll 2013-08-31 14:30 - 2013-05-21 06:44 - 00401288 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\CCJOBMGR.DLL 2013-08-31 14:30 - 2013-05-21 06:44 - 00324488 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\CCSUBENG.DLL 2013-08-31 14:30 - 2013-05-21 06:44 - 00207752 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\CCEMLPXY.DLL 2013-08-29 17:44 - 2010-11-20 14:18 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2013-08-31 14:30 - 2013-05-08 02:53 - 00620920 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\IRON.DLL 2013-08-31 14:30 - 2013-04-25 02:43 - 00074672 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymRedir.dll 2013-08-31 14:30 - 2013-04-25 02:43 - 00251824 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\SNDSVC.DLL 2013-08-31 14:30 - 2013-04-25 02:43 - 00040880 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\SYMRDRSV.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 00474960 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\HNCORE.DLL 2013-08-31 14:30 - 2013-05-24 04:09 - 00284552 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\APPMGR32.DLL 2013-08-31 14:35 - 2013-06-28 07:17 - 01849168 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\ISDATAPR.DLL 2013-08-30 15:55 - 2013-08-30 15:55 - 01767936 _____ (Microsoft Corporation) C:\Windows\syswow64\WININET.dll 2009-07-14 01:15 - 2009-07-14 03:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\syswow64\normaliz.DLL 2013-08-30 15:55 - 2013-08-30 15:55 - 02048512 _____ (Microsoft Corporation) C:\Windows\syswow64\iertutil.dll 2013-08-31 14:30 - 2013-05-24 04:09 - 01771400 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\avModule.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 03857232 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\NCW.DLL 2013-08-29 13:29 - 2012-03-01 07:33 - 00159232 _____ (Microsoft Corporation) C:\Windows\syswow64\imagehlp.dll 2013-08-31 14:30 - 2013-05-21 00:50 - 00932176 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\cltPE.dll 2013-08-31 14:30 - 2013-05-24 04:09 - 00502664 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\AVIfc.dll 2013-08-31 14:30 - 2013-05-30 04:13 - 01078576 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\DataStor.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00719184 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\AVPSVC32.DLL 2013-08-31 14:30 - 2013-06-04 03:23 - 01550672 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\SQSVC.DLL 2013-08-31 14:30 - 2013-06-04 06:43 - 00243024 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\QSPLUGIN.DLL 2013-09-06 14:14 - 2013-08-30 17:29 - 00799136 _____ (Symantec Corporation) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\IPSDefs\20130905.001\IDSxpx86.dll 2013-08-31 14:30 - 2013-05-31 03:46 - 00999760 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coDataPr.dll 2013-08-31 14:30 - 2013-05-31 03:48 - 00551760 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coShdObj.dll 2013-08-31 14:30 - 2013-05-21 00:50 - 01035088 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\CLTLMS.DLL 2013-08-31 14:30 - 2012-06-11 19:58 - 00147448 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\BHSVCPLG.DLL 2013-08-31 14:30 - 2013-05-30 04:13 - 00633648 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\SPOCCLNT.DLL 2013-08-31 14:30 - 2013-05-21 07:02 - 00655240 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\DSCli.dll 2013-08-31 14:30 - 2013-05-30 04:13 - 00348464 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SQLite.dll 2013-08-31 14:30 - 2013-05-30 04:13 - 00965936 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\COMM.DLL 2013-08-31 14:30 - 2013-05-30 04:13 - 00693040 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\EVENTSVC.DLL 2013-08-31 14:30 - 2013-05-21 00:50 - 00985424 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\CLTLMJ.DLL 2013-08-31 14:30 - 2013-05-30 04:13 - 00103216 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ProxyClt.dll 2013-08-31 14:30 - 2013-05-30 04:13 - 01337136 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\MCLNTASK.DLL 2013-08-31 14:32 - 2013-07-03 23:42 - 00821552 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\NAHELPER.DLL 2009-07-14 01:33 - 2009-07-14 03:17 - 00249680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2013-08-31 14:30 - 2013-04-09 03:27 - 00124896 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\IPSPLUG.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 01185104 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\ISDATASV.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 00475472 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\FWCORE.DLL 2013-07-15 22:58 - 2013-07-15 22:58 - 01893816 _____ (Symantec Corporation) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\BASHDefs\20130715.001\BHEngine.dll 2013-08-31 14:30 - 2013-05-30 03:22 - 00320816 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\diStRptr.dll 2013-08-31 14:30 - 2012-06-11 19:58 - 00198648 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\BHClient.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00175440 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\FWGenPlg.dll 2013-08-31 14:30 - 2013-05-24 04:09 - 00098696 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\AVMail.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 04060496 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\asEngine.dll 2013-08-31 14:30 - 2013-05-31 03:48 - 00148816 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\coParse.dll 2013-08-29 17:44 - 2010-11-20 14:21 - 00505856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll 2013-08-31 14:30 - 2013-05-24 04:09 - 00113544 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\QBackup.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00075088 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IMCfg.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00537424 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\AVPAPP32.dll 2013-08-29 08:28 - 2012-06-02 06:40 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00548176 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\asHelper.dll 2013-08-31 14:30 - 2013-05-30 03:22 - 00517424 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\diArkive.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00183120 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\FWHelper.dll 2009-07-14 01:55 - 2009-07-14 03:16 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSOCK32.dll 2013-08-29 17:44 - 2010-11-20 14:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\syswow64\WS2_32.dll 2009-07-14 01:15 - 2009-07-14 03:16 - 00006144 _____ (Microsoft Corporation) C:\Windows\syswow64\PSAPI.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 00548688 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\NPCTRAY.DLL 2013-08-31 14:30 - 2013-06-04 06:43 - 00962384 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\uiMain.dll 2013-08-31 14:30 - 2013-05-28 09:42 - 02430800 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SYMHTMDX.DLL 2013-08-30 15:55 - 2013-08-30 15:55 - 01141248 _____ (Microsoft Corporation) C:\Windows\syswow64\urlmon.dll 2013-08-29 17:44 - 2010-11-20 14:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\syswow64\COMDLG32.dll 2013-08-31 14:30 - 2013-05-30 04:13 - 01337136 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\MClnTask.dll 2013-08-31 14:35 - 2013-06-28 07:17 - 01849168 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\isDataPr.dll 2013-08-31 14:30 - 2013-05-31 03:48 - 01397584 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\COACTMGR.DLL 2013-08-31 14:30 - 2012-05-30 08:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\wincfi39.dll 2013-08-31 14:30 - 2013-05-30 04:13 - 00965936 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Comm.dll 2013-08-31 14:32 - 2013-07-03 23:42 - 00821552 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\naHelper.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00548176 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\ASHELPER.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 00579408 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\ASOEHOOK.DLL 2013-08-31 14:30 - 2013-06-04 06:42 - 00537424 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\AVPAPP32.DLL 2013-08-31 14:30 - 2013-05-21 00:50 - 02651472 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\CLTALDIS.DLL 2013-08-31 14:30 - 2013-05-21 00:50 - 01035088 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\cltLMS.dll 2013-08-31 14:30 - 2013-06-04 06:42 - 00528208 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\FWSESAL.DLL 2013-08-31 14:30 - 2013-06-10 19:10 - 00629072 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\MUI\20.4.0.40\07\01\cltRes.loc 2013-08-31 14:30 - 2013-06-04 06:42 - 00502608 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\NUEX.DLL 2013-08-31 14:30 - 2012-05-15 03:27 - 00588216 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\SDKCMN.DLL 2013-08-31 14:30 - 2013-06-04 06:43 - 00916304 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\UIALERT.DLL 2013-08-31 14:30 - 2013-05-30 04:13 - 00028464 ____R (Symantec Corporation) C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\USERCTXT.DLL 2013-08-31 14:30 - 2013-06-04 06:43 - 01065808 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Settings.dll 2013-08-29 17:44 - 2010-11-20 14:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\syswow64\comdlg32.dll 2013-08-29 13:05 - 2010-06-22 13:50 - 00061440 _____ () C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\hiddriver.dll 2013-08-28 20:38 - 2010-10-05 20:43 - 01892352 _____ (Apache Software Foundation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\xerces-c_2_7.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Users\Muri\Desktop\Thumbs.db:encryptable ==================== Faulty Device Manager Devices ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (09/07/2013 02:02:56 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/07/2013 01:28:23 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/07/2013 01:28:21 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/07/2013 01:28:21 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/07/2013 01:23:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (09/06/2013 06:49:59 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= Error: (09/07/2013 02:02:56 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (09/07/2013 01:28:23 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Muri\Desktop\esetsmartinstaller_enu.exe Error: (09/07/2013 01:28:21 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Muri\Desktop\esetsmartinstaller_enu.exe Error: (09/07/2013 01:28:21 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Muri\Desktop\esetsmartinstaller_enu.exe Error: (09/07/2013 01:23:30 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Muri\Desktop\esetsmartinstaller_enu.exe CodeIntegrity Errors: =================================== Date: 2013-09-05 21:19:55.520 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume5\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-09-05 21:19:55.489 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume5\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 22% Total physical RAM: 8156.17 MB Available physical RAM: 6280.39 MB Total Pagefile: 16310.52 MB Available Pagefile: 14487.05 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:849.71 GB) NTFS Drive d: (Fraps) (Fixed) (Total:465.54 GB) (Free:327.83 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3C7CE2D5) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 466 GB) (Disk ID: 4F7D8676) Partition: GPT Partition Type ==================== End Of Log ============================ |
07.09.2013, 21:09 | #17 |
/// the machine /// TB-Ausbilder | Ist Mein Rechner Infiziert? Fertig
__________________Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
08.09.2013, 12:10 | #18 |
| Ist Mein Rechner Infiziert? Hi schrauber,alles erledigt.vielen vielen dank für deine hilfe
__________________gruß MuRi82 |
09.09.2013, 05:52 | #19 |
/// the machine /// TB-Ausbilder | Ist Mein Rechner Infiziert? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Ist Mein Rechner Infiziert? |
bösartig, clients, command, eraser, firefox.exe, folge, folgendes, gefunde, infiziert, infiziert?, machine, norton, norton power eraser, power, rechner, registry, shell, software, was tun, was tun? |