|
Plagegeister aller Art und deren Bekämpfung: Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98%Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.09.2013, 12:25 | #1 |
| Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98%. Unter Scanner 'Fund' steht: Adware/bProtect.D Rechner fährt hoch aber sobald eine Anwendung gestartet wird läuft diese nicht! Wer kann mir da weiterhilfen. Bin neu und keine PC 'Leuchte'.Gruss |
06.09.2013, 12:29 | #2 |
/// the machine /// TB-Ausbilder | Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
06.09.2013, 15:19 | #3 |
| Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% Hallo, danke für die Mail. Habe es versucht und dabei 2 Probleme:
__________________1. finde auch mit rechtem Mausklick nicht heraus welche (32 oder 64) bit Version ich habe. 2. Internet zugang ist (vermutlich durch den Angriff) nicht stabil -kann die Anwendung nicht runterladen. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-09-2013 Ran by shikha (administrator) on SHIKHA-PC on 06-09-2013 16:17:02 Running from C:\Users\shikha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7ACAJOXF Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (CyberLink) C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe () C:\Acer\Empowering Technology\ePerformance\MemCheck.exe (Realtek Semiconductor) C:\Windows\RAVCpl64.exe () C:\Acer\Empowering Technology\SysMonitor.exe (Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe (NVIDIA Corporation) C:\Windows\System32\nvraidservice.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Sabre Inc.) C:\SABRE\Apps\OADP\Oadp.exe () C:\Windows\sabserv.exe (Bewotec GmbH) C:\jack\CRSTrans.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe () C:\Windows\SysWOW64\CfgSrvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe () C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Windows\SysWOW64\CfgSrvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe () C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe () C:\Windows\SDMan.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe () C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (Acer Inc.) C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (Acer Inc.) C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Egis inc.) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RAVCpl64.exe [6150656 2008-03-26] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [Acer Empowering Technology Monitor] - C:\Acer\Empowering Technology\SysMonitor.exe [326176 2008-01-09] () HKLM\...\Run: [eDataSecurity Loader] - C:\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe [560688 2008-03-04] (Egis Incorporated) HKLM\...\Run: [NVRaidService] - C:\Windows\system32\nvraidservice.exe [333344 2008-06-06] (NVIDIA Corporation) Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\822\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.) Winlogon\Notify\GoToAssist Express Customer: C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\498\g2ax_winlogonx64.dll (Citrix Online, a division of Citrix Systems, Inc.) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [Ihadivoz] - C:\Users\shikha\AppData\Roaming\Alluoz\ecus.exe [354304 2010-09-02] (SoftVector Solutions ) HKCU\...\Policies\Explorer: [NoDrives] 0 HKLM-x32\...\Run: [PCMMediaSharing] - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [204908 2008-01-25] () HKLM-x32\...\Run: [WarReg_PopUp] - C:\Acer\WR_PopUp\WarReg_PopUp.exe [57344 2006-11-05] (Acer Inc.) HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation) HKU\Default\...\RunOnce: [RUN] - C:\Windows\Acer_Normal\run_DT.exe [31528 2007-04-19] () HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation) HKU\Default User\...\RunOnce: [RUN] - C:\Windows\Acer_Normal\run_DT.exe [31528 2007-04-19] () HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation) HKU\UpdatusUser\...\RunOnce: [RUN] - C:\Windows\Acer_Normal\run_DT.exe [31528 2007-04-19] () AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll [2691536 2013-07-26] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ASETRES.EXE () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk ShortcutTarget: Empowering Technology Launcher.lnk -> C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Oadp - Verknüpfung.lnk ShortcutTarget: Oadp - Verknüpfung.lnk -> C:\SABRE\Apps\OADP\Oadp.exe (Sabre Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Sabre Server.lnk ShortcutTarget: Sabre Server.lnk -> C:\Windows\sabserv.exe () Startup: C:\Users\shikha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CRSTrans.exe - Verknüpfung.lnk ShortcutTarget: CRSTrans.exe - Verknüpfung.lnk -> C:\jack\CRSTrans.exe (Bewotec GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = WEB.DE - E-Mail-Adresse kostenlos, FreeMail, Nachrichten & Services HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Acer | explore beyond limits HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = Babylon Search HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = iGoogle Redirect HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = iGoogle Redirect HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - {84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZO^xdm071^YY^de&si=PI_UT_FIG_GER_196&ptb=FC7AFD6D-4B85-4AFE-9525-01297D13AFA9&ind=2013052505&n=77fcbe59&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=119816&babsrc=SP_ss_din2g&mntrId=88D5002421803A95 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=119816&babsrc=SP_ss_din2g&mntrId=88D5002421803A95 SearchScopes: HKCU - {84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZO^xdm071^YY^de&si=PI_UT_FIG_GER_196&ptb=FC7AFD6D-4B85-4AFE-9525-01297D13AFA9&ind=2013052505&n=77fcbe59&psa=&st=sb&searchfor={searchTerms} BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO-x32: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) BHO-x32: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation) BHO-x32: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.) Toolbar: HKLM-x32 - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: HKLM-x32 {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [304128] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (DealPly Shopping ) - C:\Users\shikha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma\3.5.0.0 CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\shikha\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM-x32\...\Chrome\Extension: [fmfnfnpmhcllokmkepffndflpnadjmma] - C:\Program Files (x86)\DealPly\DealPly.crx ==================== Services (Whitelisted) ================= R2 Acer HomeMedia Connect Service; C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [269448 2008-01-25] (CyberLink) R2 AcerMemUsageCheckService; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [28672 2007-10-17] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG) R2 BrowserDefendert; C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2847696 2013-07-26] () R2 CfgSrvc; C:\Windows\SysWOW64\CfgSrvc.exe [55296 2001-11-09] () R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [500784 2008-03-04] (Egis Incorporated) R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.) R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] () S3 GoToAssist Remote Support Customer; C:\Program Files (x86)\Citrix\GoToAssist Remote Support Customer\498\g2ax_service.exe [611400 2013-05-31] (Citrix Online, a division of Citrix Systems, Inc.) R2 HsspConfig; C:\Windows\SysWow64\CfgSrvc.exe [55296 2001-11-09] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [241734 2008-06-13] () S4 SabrePrint; C:\SABRE\Apps\OADP\Oadp.exe [516096 2008-01-21] (Sabre Inc.) R2 SDMan; C:\Windows\SDMan.EXE [106496 2001-05-29] () S3 gusvc; "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG) R2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [15656 2006-10-04] () R2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [15656 2006-10-04] () R0 nvrd64; C:\Windows\System32\drivers\nvrd64.sys [166944 2008-06-07] (NVIDIA Corporation) R0 PSDFilter; C:\Windows\System32\DRIVERS\psdfilter.sys [22064 2008-03-04] (Egis Incorporated) R2 PSDNServ; C:\Windows\System32\DRIVERS\PSDNServ.sys [21040 2008-03-04] (Egis Incorporated) R2 psdvdisk; C:\Windows\System32\DRIVERS\PSDVdisk.sys [60976 2008-03-04] (Egis Incorporated) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation) S3 AtiDCM; \??\C:\Windows\Temp\atidcmxx.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== NETSVCx32: mfnqlu -> No ServiceDLL Path. ==================== One Month Created Files and Folders ======== 2013-09-06 16:12 - 2013-09-06 16:12 - 00000000 _____ C:\Users\shikha\Desktop\FRST_exe.0gae7yl.partial 2013-09-06 11:28 - 2013-09-06 11:28 - 96324866 _____ C:\Windows\SysWOW64\劉傁ᴼĻ 2013-09-06 10:14 - 2013-09-06 10:14 - 96304236 _____ C:\Windows\SysWOW64\눞詫ᴼĿ 2013-08-30 10:47 - 2013-08-30 17:13 - 00000000 ____D C:\Users\shikha\AppData\Roaming\Acco 2013-08-30 10:47 - 2013-08-30 10:47 - 00000000 ____D C:\Users\shikha\AppData\Roaming\Omehuc 2013-08-30 10:47 - 2013-08-30 10:47 - 00000000 ____D C:\Users\shikha\AppData\Roaming\Alluoz 2013-08-28 10:07 - 2013-08-02 16:06 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-28 10:07 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-23 10:56 - 2013-08-23 10:56 - 00014000 _____ C:\Users\shikha\Desktop\hs_err_pid1116.log 2013-08-20 12:06 - 2013-08-20 12:06 - 00014086 _____ C:\Users\shikha\Desktop\hs_err_pid512.log 2013-08-15 10:40 - 2013-08-15 10:44 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 10:36 - 2013-07-25 05:54 - 17830400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 10:36 - 2013-07-25 05:37 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 10:36 - 2013-07-25 05:35 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 10:36 - 2013-07-25 05:31 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 10:36 - 2013-07-25 05:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 10:36 - 2013-07-25 05:29 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-08-15 10:36 - 2013-07-25 05:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-08-15 10:36 - 2013-07-25 05:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 10:36 - 2013-07-25 05:28 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 10:36 - 2013-07-25 05:28 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 10:36 - 2013-07-25 05:28 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 10:36 - 2013-07-25 05:28 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-08-15 10:36 - 2013-07-25 05:28 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-08-15 10:36 - 2013-07-25 05:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 10:36 - 2013-07-25 05:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-08-15 10:36 - 2013-07-25 05:26 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 10:36 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 10:36 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 10:36 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 10:36 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 10:36 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 10:36 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-08-15 10:36 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-08-15 10:36 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 10:36 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 10:36 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 10:36 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 10:36 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-08-15 10:36 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-08-15 10:36 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 10:36 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 10:36 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-08-14 10:45 - 2013-07-17 22:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 10:45 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 10:45 - 2013-07-10 11:47 - 00677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 10:45 - 2013-07-10 11:42 - 01303552 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 10:45 - 2013-07-09 14:04 - 01585256 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 10:45 - 2013-07-09 14:04 - 01168088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 10:45 - 2013-07-08 06:51 - 04691904 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 10:45 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 10:45 - 2013-07-08 06:20 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 10:45 - 2013-07-08 06:18 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 10:45 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 10:45 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 10:45 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 10:45 - 2013-07-08 06:15 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 10:45 - 2013-07-08 06:15 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 10:45 - 2013-07-08 06:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-08-14 10:45 - 2013-07-08 06:12 - 01276416 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 10:45 - 2013-07-08 06:12 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 10:45 - 2013-07-08 06:12 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 10:45 - 2013-07-08 03:39 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 10:45 - 2013-07-08 03:39 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 10:45 - 2013-07-08 03:39 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 10:45 - 2013-07-05 06:45 - 01423808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 10:45 - 2013-06-15 15:27 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-08-14 10:45 - 2013-06-15 13:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys ==================== One Month Modified Files and Folders ======= 2013-09-06 16:17 - 2009-09-30 13:47 - 00000148 _____ C:\Windows\session.txt 2013-09-06 16:15 - 2013-09-06 16:15 - 96334488 _____ C:\Windows\SysWOW64\ᴼľ 2013-09-06 16:12 - 2013-09-06 16:12 - 00000000 _____ C:\Users\shikha\Desktop\FRST_exe.0gae7yl.partial 2013-09-06 15:57 - 2013-05-22 18:24 - 01922163 _____ C:\Windows\WindowsUpdate.log 2013-09-06 15:54 - 2008-08-13 00:14 - 00410256 _____ C:\Users\Public\eDSMSNLoader32.log 2013-09-06 15:53 - 2008-08-12 23:28 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-06 15:53 - 2006-11-02 17:22 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-06 15:53 - 2006-11-02 17:22 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-06 15:53 - 2006-11-02 17:21 - 00300568 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-06 15:49 - 2013-05-21 09:56 - 00481312 _____ C:\Windows\PFRO.log 2013-09-06 14:50 - 2009-09-29 14:15 - 00000000 ___RD C:\Users\shikha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-06 12:56 - 2013-04-11 18:39 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.bak 2013-09-06 12:56 - 2013-04-11 18:39 - 00000000 _____ C:\Windows\system32\Drivers\etc\lmhosts.bak 2013-09-06 12:56 - 2009-09-29 16:15 - 00000204 _____ C:\Users\shikha\sslvpn-config.properties 2013-09-06 12:56 - 2009-09-29 15:42 - 00014873 _____ C:\Users\shikha\sslvpn-client.log 2013-09-06 12:56 - 2009-09-29 15:42 - 00001740 _____ C:\Users\shikha\sslvpn-client-out-err.log 2013-09-06 12:56 - 2009-09-29 14:32 - 00001290 _____ C:\Windows\Sabre.Ini 2013-09-06 11:30 - 2009-09-29 15:37 - 01445372 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-06 11:30 - 2008-01-21 13:09 - 00628742 _____ C:\Windows\system32\perfh007.dat 2013-09-06 11:30 - 2008-01-21 13:09 - 00126486 _____ C:\Windows\system32\perfc007.dat 2013-09-06 11:28 - 2013-09-06 11:28 - 96324866 _____ C:\Windows\SysWOW64\劉傁ᴼĻ 2013-09-06 11:25 - 2009-09-29 14:13 - 00000000 ____D C:\Users\shikha 2013-09-06 10:28 - 2013-04-03 14:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-06 10:14 - 2013-09-06 10:14 - 96304236 _____ C:\Windows\SysWOW64\눞詫ᴼĿ 2013-09-06 10:11 - 2006-11-02 17:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-05 18:31 - 2006-11-02 17:42 - 00032510 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-05 18:23 - 2009-10-02 11:57 - 00000000 ____D C:\MerlinX 2013-09-05 16:01 - 2009-09-30 13:26 - 00000000 ____D C:\SPL 2013-09-04 10:13 - 2013-04-11 18:36 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-04 10:13 - 2013-04-11 18:36 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-30 17:13 - 2013-08-30 10:47 - 00000000 ____D C:\Users\shikha\AppData\Roaming\Acco 2013-08-30 10:47 - 2013-08-30 10:47 - 00000000 ____D C:\Users\shikha\AppData\Roaming\Omehuc 2013-08-30 10:47 - 2013-08-30 10:47 - 00000000 ____D C:\Users\shikha\AppData\Roaming\Alluoz 2013-08-23 10:56 - 2013-08-23 10:56 - 00014000 _____ C:\Users\shikha\Desktop\hs_err_pid1116.log 2013-08-20 12:06 - 2013-08-20 12:06 - 00014086 _____ C:\Users\shikha\Desktop\hs_err_pid512.log 2013-08-15 11:25 - 2006-11-02 15:33 - 00000000 ____D C:\Windows\rescache 2013-08-15 10:44 - 2013-08-15 10:40 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 10:40 - 2006-11-02 14:35 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe Files to move or delete: ==================== C:\ProgramData\nvModes.dat C:\Users\shikha\GoToAssistDownloadHelper.exe C:\Users\shikha\AppData\Local\Temp\bitool.dll C:\Users\shikha\AppData\Local\Temp\DeltaTB.exe C:\Users\shikha\AppData\Local\Temp\FileSystemView.dll C:\Users\shikha\AppData\Local\Temp\JNISupport56116.dll C:\Users\shikha\AppData\Local\Temp\{AC76BA86-7AD7-1031-7B44-A82000000003}\FixTransforms.exe C:\Users\shikha\AppData\Local\Temp\{AC76BA86-7AD7-1031-7B44-A82000000003}\FixTransforms64bit.exe C:\Users\shikha\AppData\Local\Temp\upd9B95\BabScheduler2000201.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Desktop.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_ar.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_bg.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_cs.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_da.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_de.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_el.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_en.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_es.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_fi.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_fr.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_he.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_hr.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_hu.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_id.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_it.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_ja.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_ko.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_lt.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_nl.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_no.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_pl.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_pt.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_ro.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_ru.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_sk.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_sr.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_sv.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_th.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_tr.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_uk.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_vi.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_zhCN.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Resource_zhTW.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_Service.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\TeamViewer_StaticRes.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\tv_w32.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\tv_w32.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\tv_x64.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\tv_x64.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\uninstall.exe C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\x64\Teamviewer_PrintProcessor.dll C:\Users\shikha\AppData\Local\Temp\TeamViewer\Version8\outlook\TeamViewerMeetingAddIn.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\BabMaint.exe C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\BExternal.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\BUSolForMontiera.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\BUSolution.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\ccp.exe C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\ChromeToolbarSetup.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\CrxInstaller.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\GUninstaller.exe C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\IEHelper.dll C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\MyBabylonTB.exe C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\Setup.exe C:\Users\shikha\AppData\Local\Temp\C8F1860E-BAB0-7891-AB12-508F099865BC\Latest\sqlite3.dll C:\Users\shikha\AppData\Local\Temp\bus94A1\BUSolution.dll C:\Users\shikha\AppData\Local\Temp\bus927E\BUSolution.dll C:\Users\shikha\AppData\Local\Temp\bus8FEF\CrxUpdater_d.exe C:\Users\shikha\AppData\Local\Temp\bus8C86\CrxUpdater_d.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-06 16:00 ==================== End Of Log ============================ --- --- --- |
07.09.2013, 07:15 | #4 | |
/// the machine /// TB-Ausbilder | Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98%Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.09.2013, 09:07 | #5 |
| Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% Habe einen neuen Scan durchgeführt, da der letzte nicht vollständig zu sein schien. Hier folgt der Inhalt: Combofix Logfile: Code:
ATTFilter ComboFix 13-09-19.01 - shikha 21.09.2013 9:51.4.2 - x64 ausgeführt von:: c:\users\shikha\Desktop\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Vorheriger Suchlauf ------- . c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bl c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\dm c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\bprotector.js c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\00 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\01 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\02 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\03 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\10 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\11 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\12 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\13 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\20 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\21 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\22 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\23 c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe c:\users\shikha\AppData\Local\temp\JNISupport59886.dll c:\users\shikha\AppData\Roaming\Alluoz\ecus.exe c:\users\shikha\GoToAssistDownloadHelper.exe c:\windows\IsUn0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-21 bis 2013-09-21 )))))))))))))))))))))))))))))) . . 2013-09-21 07:58 . 2013-09-21 07:58 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-09-21 07:58 . 2013-09-21 07:58 -------- d-----w- c:\users\shikha\AppData\Local\temp 2013-09-21 07:58 . 2013-09-21 07:58 -------- d-----w- c:\users\Public\AppData\Local\temp 2013-09-21 07:58 . 2013-09-21 07:58 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-21 07:49 . 2013-09-21 07:50 -------- d-----w- C:\32788R22FWJFW 2013-09-17 10:15 . 2013-09-19 13:05 -------- d-----w- c:\users\shikha\AppData\Roaming\Zaelt 2013-09-17 10:15 . 2013-09-17 16:02 -------- d-----w- c:\users\shikha\AppData\Roaming\Ezqalo 2013-09-17 10:15 . 2013-09-17 10:15 -------- d-----w- c:\users\shikha\AppData\Roaming\Yfopa 2013-09-13 08:11 . 2013-07-31 13:09 96768 ----a-w- c:\windows\system32\mshtmled.dll 2013-09-13 08:11 . 2013-07-31 13:08 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2013-09-13 08:11 . 2013-07-31 09:45 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-09-12 08:08 . 2013-08-08 02:03 2775552 ----a-w- c:\windows\system32\win32k.sys 2013-09-12 08:08 . 2013-07-16 09:25 689152 ----a-w- c:\windows\system32\themeui.dll 2013-09-12 08:08 . 2013-07-16 04:35 615936 ----a-w- c:\windows\SysWow64\themeui.dll 2013-08-30 08:47 . 2013-08-30 15:13 -------- d-----w- c:\users\shikha\AppData\Roaming\Acco 2013-08-30 08:47 . 2013-08-30 08:47 -------- d-----w- c:\users\shikha\AppData\Roaming\Omehuc 2013-08-28 08:07 . 2013-08-02 14:06 1706496 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-08-28 08:07 . 2013-08-02 04:09 1548288 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-13 08:11 . 2006-11-02 12:35 79143768 ----a-w- c:\windows\system32\mrt.exe 2013-09-04 08:13 . 2013-04-11 16:36 132088 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-09-04 08:13 . 2013-04-11 16:36 105344 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-07-17 20:01 . 2013-08-14 08:45 2048 ----a-w- c:\windows\system32\tzres.dll 2013-07-17 19:41 . 2013-08-14 08:45 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2013-07-10 09:47 . 2013-08-14 08:45 677888 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2013-07-10 09:42 . 2013-08-14 08:45 1303552 ----a-w- c:\windows\system32\rpcrt4.dll 2013-07-09 12:04 . 2013-08-14 08:45 1168088 ----a-w- c:\windows\SysWow64\ntdll.dll 2013-07-09 12:04 . 2013-08-14 08:45 1585256 ----a-w- c:\windows\system32\ntdll.dll 2013-07-08 04:51 . 2013-08-14 08:45 4691904 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-07-08 04:20 . 2013-08-14 08:45 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-07-08 04:20 . 2013-08-14 08:45 172544 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-07-08 04:18 . 2013-08-14 08:45 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-07-08 04:16 . 2013-08-14 08:45 98304 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-07-08 04:16 . 2013-08-14 08:45 133120 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-07-08 04:16 . 2013-08-14 08:45 992768 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-07-08 04:16 . 2013-08-14 08:45 43008 ----a-w- c:\windows\apppatch\acwow64.dll 2013-07-08 04:15 . 2013-08-14 08:45 234496 ----a-w- c:\windows\system32\wow64.dll 2013-07-08 04:15 . 2013-08-14 08:45 218624 ----a-w- c:\windows\system32\wintrust.dll 2013-07-08 04:14 . 2013-08-14 08:45 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2013-07-08 04:12 . 2013-08-14 08:45 174592 ----a-w- c:\windows\system32\cryptsvc.dll 2013-07-08 04:12 . 2013-08-14 08:45 132096 ----a-w- c:\windows\system32\cryptnet.dll 2013-07-08 04:12 . 2013-08-14 08:45 1276416 ----a-w- c:\windows\system32\crypt32.dll 2013-07-08 01:39 . 2013-08-14 08:45 26112 ----a-w- c:\windows\SysWow64\setup16.exe 2013-07-08 01:39 . 2013-08-14 08:45 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-07-08 01:39 . 2013-08-14 08:45 2560 ----a-w- c:\windows\SysWow64\user.exe 2013-07-05 04:45 . 2013-08-14 08:45 1423808 ----a-w- c:\windows\system32\drivers\tcpip.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] 2013-05-20 10:02 295832 ----a-w- c:\program files (x86)\Delta\delta\1.8.21.5\bh\delta.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{82E1477C-B154-48D3-9891-33D83C26BCD3}"= "c:\program files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll" [2013-05-20 284056] . [HKEY_CLASSES_ROOT\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}] [HKEY_CLASSES_ROOT\delta.deltadskBnd.1] [HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] [HKEY_CLASSES_ROOT\delta.deltadskBnd] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-04 21:38 121392 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PCMMediaSharing"="c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908] "WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-04 347192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices] "Sabre Task Tray Icon"="c:\sabre\Sabstart.exe" [2001-05-25 20992] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe;c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes mfnqlu . Inhalt des "geplante Tasks" Ordners . 2013-09-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-03 14:22] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-04 21:39 51248 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RAVCpl64.exe" [2008-03-25 6150656] "Skytel"="Skytel.exe" [2007-11-20 1826816] "Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2008-01-09 326176] "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-03-04 560688] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-06-06 333344] . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://web.de/ uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=1&o=vp64&d=0809&m=aspire_m3641 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=1&o=vp64&d=0809&m=aspire_m3641 mLocal Page = c:\windows\SysWOW64\blank.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 Trusted Zone: agentware.net Trusted Zone: akamaiedge.net Trusted Zone: cibt.com Trusted Zone: etraveladisories.com Trusted Zone: getthere.com Trusted Zone: merlin.com Trusted Zone: merlinx2.de Trusted Zone: midoffice.sabre-merlin.com Trusted Zone: mysabremerlin.de Trusted Zone: onthesnow.com Trusted Zone: pathlore.net Trusted Zone: portpromotions.com Trusted Zone: sabre.com Trusted Zone: sabre.com\eservices Trusted Zone: sabreconsolidator.com Trusted Zone: softvoyage.com Trusted Zone: theluggageclub.com Trusted Zone: travelpn.com Trusted Zone: travisa.com Trusted Zone: vacationstudio.net Trusted Zone: vaxvacationaccess.com Trusted Zone: virtuallythere.com Trusted Zone: vtitin.com Trusted Zone: wcities.com Trusted Zone: wctravel.com Trusted Zone: wellwishers.com Trusted Zone: whatsonwhen.com Trusted Zone: worktopia.com TCP: DhcpNameServer = 192.168.2.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-Ihadivoz - c:\users\shikha\AppData\Roaming\Alluoz\ecus.exe Notify-noknovy - (no file) AddRemove-MySabre - c:\windows\ISUN0407.EXE AddRemove-Open Systems Client - c:\windows\ISUN0407.EXE AddRemove-Sabre Device Manager - c:\windows\ISUN0407.EXE AddRemove-Sabre Print Module - c:\windows\ISUN0407.EXE AddRemove-{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} - c:\programdata\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . Zeit der Fertigstellung: 2013-09-21 10:01:07 ComboFix-quarantined-files.txt 2013-09-21 08:01 ComboFix2.txt 2013-05-25 12:37 ComboFix3.txt 2013-05-22 16:26 . Vor Suchlauf: 22 Verzeichnis(se), 265.054.613.504 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 265.175.752.704 Bytes frei . - - End Of File - - 0D95E0F1C1B9E80AD53802C51C5E8D2B A863475757CC50891AA8458C415E4B25 |
21.09.2013, 16:20 | #6 |
/// the machine /// TB-Ausbilder | Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% |
Themen zu Virenproblem-30 verschiedene Meldungen mit Antivirenscanner,Scanner stopt immer bei 98% |
adware, adware/bprotect.d, anwendung, fund, gen, gestartet, heulen, meldungen, neu, pc beeinträchtigung, scan, scanner, sobald, stopt, verschiedene, viren |