|
Plagegeister aller Art und deren Bekämpfung: Malwarebytes 34 Funde Normal ?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.09.2013, 07:08 | #1 |
| Malwarebytes 34 Funde Normal ? Moin Melde mich mal wieder mit einem Problem (Danke nochmal an den letzten Helfer ! ) und zwar hab ich letztens Malwarebytes auf meinem Netbook laufen lassen und es kamen 34 Funde Raus. Ist das Normal ? Hier ist das Log : Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.09.04 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16660 power :: *********** [Administrator] 09.09.2013 15:18:42 MBAM-log-2013-09-09 (15-42-45).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 216364 Laufzeit: 15 Minute(n), 20 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 8 HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr) -> Keine Aktion durchgeführt. HKCU\Software\DataMngr (PUP.Optional.DataMngr) -> Keine Aktion durchgeführt. HKCU\Software\DC3_FEXEC (Malware.Trace) -> Keine Aktion durchgeführt. HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Keine Aktion durchgeführt. HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 2 HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {827A3C6B-BB68-408F-AAF7-450B64E7645A} -> Keine Aktion durchgeführt. HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {827A3C6B-BB68-408F-AAF7-450B64E7645A} -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 3 C:\Users\power\AppData\Roaming\dclogs (Stolen.Data) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\power\Documents\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 21 C:\Users\power\AppData\Roaming\Imgburn.exe (PUP.Optional.AskToolbar) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\5iRh8WP0.exe.part (PUP.Optional.Installex) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\appshat-distribution.exe (PUP.Optional.Somoto.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\ICReinstall_picasa39_inst.exe (PUP.Optional.IronInstall) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\TsuF835D087.dll (PUP.Optional.Tarma.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizePro.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\Optimizer_Pro.exe (PUP.Optional.1ClickDownload.A) -> Keine Aktion durchgeführt. C:\$RECYCLE.BIN\S-1-5-21-3662886436-2550715429-2728409154-1000\$R056H7Y.exe (PUP.Optional.Somoto) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\FDF1B487-BAB0-7891-B710-0136E6BB81EB\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\FDF1B487-BAB0-7891-B710-0136E6BB81EB\Latest\ccp.exe (PUP.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\FDF1B487-BAB0-7891-B710-0136E6BB81EB\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\FDF1B487-BAB0-7891-B710-0136E6BB81EB\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\{E1B77240-2A51-42B6-A05D-62733A5450B6}\Setup.exe (PUP.Optional.Tarma.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\{E1B77240-2A51-42B6-A05D-62733A5450B6}\Addons\assistant_v3.exe (PUP.Optional.SProtect.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\{E1B77240-2A51-42B6-A05D-62733A5450B6}\Addons\ext_setup.exe (PUP.Adware.MultiPlug) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\is1693454730\DeltaTB.exe (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Local\Temp\Crypted.exe (Trojan.Agent) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Roaming\dclogs\2013-08-09-6.dc (Stolen.Data) -> Keine Aktion durchgeführt. C:\Users\power\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\power\Documents\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> Keine Aktion durchgeführt. (Ende) |
12.09.2013, 07:21 | #2 |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
12.09.2013, 13:45 | #3 |
| Malwarebytes 34 Funde Normal ? Danke für die schnelle Hilfe !
__________________Hier die Logs : FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 02 Ran by power (administrator) on ************ on 12-09-2013 14:31:04 Running from C:\Users\power\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Fork Ltd.) C:\Prey\platform\windows\cronsvc.exe (DATA BECKER GmbH & Co KG) C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (www.IslamicFinder.org) C:\Program Files\Athan\Athan.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\windows\system32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Athan] - C:\Program Files\Athan\Athan.exe [1204224 2011-11-20] (www.IslamicFinder.org) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-12-13] (AsusTek Computer Inc.) HKU\Default\...\RunOnce: [IconPatch] - C:\Windows\AP\IconPatch.vbs HKU\Default\...\RunOnce: [AskScreensaver] - C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - Backup.Old.DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKCU - Backup.Old.DefaultScope {22644C40-4FC2-4E7A-BDAD-71EA5ED16FC5} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=8406E0B9A5030800&affID=119357&tt=250613_gr4&tsp=4924 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll No File BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll No File Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" No File Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 FireFox: ======== FF ProfilePath: C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default FF user.js: detected! => C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\user.js FF NewTab: hxxp://www.google.com/firefox FF DefaultSearchEngine: Ask.com FF SearchEngineOrder.1: Ask.com FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Ask.com FF Homepage: https://www.google.de/ FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=100&systemid=473&v=n8883-100&apn_dtid=BND473&apn_ptnrs=AG1&apn_uid=4352935405034440&o=APN10640&q= FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\searchplugins\Ask.xml FF SearchPlugin: C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: saviEnshare - C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\Extensions\nqiz078@kqgdutpmr.co.uk FF Extension: No Name - C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG) R2 CronService; C:\Prey\platform\windows\cronsvc.exe [19968 2011-02-15] (Fork Ltd.) R2 DBService; C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe [189776 2010-10-28] (DATA BECKER GmbH & Co KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1699168 2012-09-19] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 acedrv11; C:\windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH) R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [109960 2010-04-13] (ELAN Microelectronic Corp.) S3 FlashUSB; C:\Windows\System32\DRIVERS\FlashUSB.sys [16896 2010-05-12] (Danish Wireless Design A/S) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [428088 2013-06-25] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-11-09] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-19] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 btwampfl; system32\drivers\btwampfl.sys [x] S3 btwaudio; system32\drivers\btwaudio.sys [x] S3 btwavdt; \SystemRoot\system32\DRIVERS\btwavdt.sys [x] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [x] S3 btwrchid; \SystemRoot\system32\DRIVERS\btwrchid.sys [x] S3 catchme; \??\C:\Users\power\AppData\Local\Temp\catchme.sys [x] S3 cpuz136; \??\C:\windows\TEMP\cpuz136\cpuz136_x32.sys [x] U3 DfSdkS; S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [x] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation) S3 L1C; system32\DRIVERS\L1C62x86.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-12 14:30 - 2013-09-12 14:31 - 01082587 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 19:15 - 2013-09-09 19:15 - 00000000 ____D C:\ProgramData\Browser Manager 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 15:16 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-09-09 15:07 - 2013-09-09 15:07 - 00000000 ____D C:\Users\power\Documents\Optimizer Pro 2013-09-09 14:39 - 2013-09-09 14:56 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 __SHD C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-05 20:35 - 2013-09-12 13:58 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-08-29 19:38 - 2008-01-24 13:44 - 00000000 ____D C:\eeepcfr 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:17 - 2013-08-29 18:17 - 00000000 ____D C:\Users\power\Systemroot 2013-08-29 18:12 - 2013-08-29 18:14 - 00000000 ____D C:\Users\power\OTLPEStd 2013-08-29 18:11 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-08-29 18:09 - 2013-08-29 18:10 - 00000000 ____D C:\Users\power\Musik 2013-08-29 17:50 - 2013-08-29 18:32 - 00000000 ____D C:\Users\power\OTLPE 2013-08-29 16:38 - 2012-03-25 20:19 - 261308720 _____ (Valve) C:\Users\power\cs16full_v7 (2).exe 2013-08-29 12:00 - 2013-08-29 12:01 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:30 - 2013-08-28 16:33 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-28 16:28 - 2013-08-28 16:30 - 12228527 _____ C:\Users\power\HitmanPro_3.7.7.203.zip 2013-08-27 15:49 - 2013-08-27 16:02 - 00000000 __SHD C:\windows\system32\AI_RecycleBin 2013-08-27 15:49 - 2013-08-27 16:01 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 15:45 - 2013-08-27 16:01 - 00000000 ____D C:\ProgramData\Soluto 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-27 16:03 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo 2013-08-17 11:20 - 2013-08-17 11:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 20:12 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-08-14 20:12 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-08-14 20:12 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-08-14 20:12 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-08-14 20:12 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-08-14 20:12 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-08-14 20:12 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-08-14 20:12 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-08-14 19:17 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2013-08-14 19:17 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe 2013-08-14 19:17 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2013-08-14 19:17 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2013-08-14 19:17 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2013-08-14 19:17 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll 2013-08-14 19:17 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2013-08-14 19:17 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll 2013-08-14 19:17 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll 2013-08-14 19:17 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2013-08-14 19:16 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-08-14 19:16 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys 2013-08-13 20:22 - 2013-08-13 20:59 - 1914710788 _____ C:\Users\power\Documents\Bilder für Präsentation.rar ==================== One Month Modified Files and Folders ======= 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-12 14:31 - 2013-09-12 14:30 - 01082587 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-12 14:30 - 2012-04-05 14:58 - 00000029 _____ C:\windows\system32\TempWmicBatchFile.bat 2013-09-12 14:06 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-12 14:06 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-12 14:02 - 2011-08-25 05:19 - 01301866 _____ C:\windows\WindowsUpdate.log 2013-09-12 13:58 - 2013-09-05 20:35 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-09-12 13:58 - 2013-03-18 05:43 - 00046501 _____ C:\windows\setupact.log 2013-09-12 13:57 - 2013-04-20 16:46 - 00065536 _____ C:\windows\system32\Ikeext.etl 2013-09-12 12:24 - 2009-07-14 04:37 - 00000000 ____D C:\windows\tracing 2013-09-12 08:11 - 2013-05-06 20:05 - 00000000 ____D C:\Users\power\AppData\Roaming\Skype 2013-09-11 21:34 - 2013-05-12 11:39 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-10 00:46 - 2013-03-18 05:42 - 00063936 _____ C:\windows\PFRO.log 2013-09-09 21:54 - 2011-08-24 20:23 - 00000000 ____D C:\Users\power 2013-09-09 21:50 - 2009-07-25 09:50 - 00389388 _____ C:\windows\system32\PerfStringBackup.INI 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 19:15 - 2013-09-09 19:15 - 00000000 ____D C:\ProgramData\Browser Manager 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 15:07 - 2013-09-09 15:07 - 00000000 ____D C:\Users\power\Documents\Optimizer Pro 2013-09-09 14:56 - 2013-09-09 14:39 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-08 09:27 - 2012-05-17 17:47 - 00000000 ____D C:\Users\power\Virus 2013-09-07 04:17 - 2013-03-25 18:54 - 00000000 ____D C:\Users\power\AppData\Roaming\vlc 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 __SHD C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-04 16:00 - 2013-05-07 15:47 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2013-08-31 22:43 - 2013-02-09 13:13 - 00000000 ____D C:\Users\power\Schule 2013-08-30 07:44 - 2012-10-18 18:10 - 00000000 ____D C:\Users\power\AppData\Roaming\.minecraft 2013-08-29 18:32 - 2013-08-29 17:50 - 00000000 ____D C:\Users\power\OTLPE 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:17 - 2013-08-29 18:17 - 00000000 ____D C:\Users\power\Systemroot 2013-08-29 18:14 - 2013-08-29 18:12 - 00000000 ____D C:\Users\power\OTLPEStd 2013-08-29 18:11 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-08-29 18:10 - 2013-08-29 18:09 - 00000000 ____D C:\Users\power\Musik 2013-08-29 12:01 - 2013-08-29 12:00 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:33 - 2013-08-28 16:30 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-28 16:30 - 2013-08-28 16:28 - 12228527 _____ C:\Users\power\HitmanPro_3.7.7.203.zip 2013-08-27 16:03 - 2013-08-21 22:44 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-27 16:02 - 2013-08-27 15:49 - 00000000 __SHD C:\windows\system32\AI_RecycleBin 2013-08-27 16:02 - 2013-07-20 16:26 - 00000000 ____D C:\Program Files\NirSoft 2013-08-27 16:01 - 2013-08-27 15:49 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 16:01 - 2013-08-27 15:45 - 00000000 ____D C:\ProgramData\Soluto 2013-08-27 15:54 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo 2013-08-21 14:02 - 2012-05-03 07:54 - 00867240 _____ (Oracle Corporation) C:\windows\system32\npdeployJava1.dll 2013-08-21 14:02 - 2011-08-24 20:57 - 00789416 _____ (Oracle Corporation) C:\windows\system32\deployJava1.dll 2013-08-17 21:40 - 2013-04-21 22:55 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-17 11:20 - 2013-08-17 11:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 21:56 - 2013-08-09 15:56 - 00000000 ____D C:\Program Files\SaveShare 2013-08-14 21:56 - 2013-08-09 15:55 - 00000000 ____D C:\ProgramData\saviEnshare 2013-08-14 21:56 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE 2013-08-14 20:26 - 2013-08-03 18:11 - 00000000 ____D C:\windows\system32\MRT 2013-08-14 20:21 - 2011-11-12 13:31 - 75778376 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-08-14 19:45 - 2012-12-21 13:50 - 00000000 ____D C:\Users\power\AppData\Roaming\ICQ 2013-08-13 20:59 - 2013-08-13 20:22 - 1914710788 _____ C:\Users\power\Documents\Bilder für Präsentation.rar Files to move or delete: ==================== C:\Users\power\cs16full_v7 (2).exe C:\Users\power\AppData\Local\Temp\7z920.exe C:\Users\power\AppData\Local\Temp\appshat-distribution.exe C:\Users\power\AppData\Local\Temp\BundleSweetIMSetup.exe C:\Users\power\AppData\Local\Temp\Crypted.exe C:\Users\power\AppData\Local\Temp\down.5524.OptimizerProInstaller.exe C:\Users\power\AppData\Local\Temp\HitmanPro_x64.exe C:\Users\power\AppData\Local\Temp\i4jdel0.exe C:\Users\power\AppData\Local\Temp\ICReinstall_picasa39_inst.exe C:\Users\power\AppData\Local\Temp\Kickstarter.exe C:\Users\power\AppData\Local\Temp\MoviesToolbarSetup_Somoto.exe C:\Users\power\AppData\Local\Temp\MybabylonTB.exe C:\Users\power\AppData\Local\Temp\OptimizerPro.exe C:\Users\power\AppData\Local\Temp\Optimizer_Pro.exe C:\Users\power\AppData\Local\Temp\propsys.dll C:\Users\power\AppData\Local\Temp\sfamcc00001.dll C:\Users\power\AppData\Local\Temp\sfextra.dll C:\Users\power\AppData\Local\Temp\SkypeSetup.exe C:\Users\power\AppData\Local\Temp\TsuF835D087.dll C:\Users\power\AppData\Local\Temp\UpdateCheckerSetup.exe C:\Users\power\AppData\Local\Temp\vlc-2.0.7-win32.exe C:\Users\power\AppData\Local\Temp\~TMP0714194434000001.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-03 14:57 ==================== End Of Log ============================ Addition : Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-09-2013 02 Ran by power at 2013-09-12 14:32:37 Running from C:\Users\**\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 32 Bit HP CIO Components Installer (Version: 1.1.0) Adobe AIR (Version: 2.5.1.17730) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader XI (11.0.02) - Deutsch (Version: 11.0.02) ASUSUpdate for Eee PC (Version: 1.04.01) Avira Free Antivirus (Version: 13.0.0.4052) Bing Bar (Version: 7.1.391.0) Bing Rewards Client Installer (Version: 16.0.345.0) CounterStrikev47 (Version: 1.00.0000) CPUID CPU-Z 1.66.1 FoxTab PDF Creator Free Studio version 2013 (Version: 6.1.1.430) GeoGebra 4.2 (Version: 4.2.56.0) Google Update Helper (Version: 1.3.21.153) ICQ7.7 (Version: 7.7) Intel(R) Graphics Media Accelerator Driver (Version: 8.14.10.2364) Intel(R) Rapid Storage Technology (Version: 11.0.0.1032) LiveUpdate (Version: 1.25) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) ManyCam 3.1.43 (Version: 3.1.43) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft PowerPoint Viewer (Version: 14.0.6029.1000) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) No-IP DUC (Version: 4.0.1) OpenOffice.org 3.4.1 (Version: 3.41.9593) PhotoScape Realtek High Definition Audio Driver (Version: 6.0.1.6662) Skype™ 6.5 (Version: 6.5.158) StarterBackgroundChanger (Version: 0.8.1.0) Trend Micro Titanium (Version: 1.0) TuneUp Utilities 2013 (Version: 13.0.2020.4) TuneUp Utilities Language Pack (de-DE) (Version: 12.0.3010.1) TuneUp Utilities Language Pack (de-DE) (Version: 13.0.2020.4) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) VLC media player 2.0.5 (Version: 2.0.5) WinRAR 4.01 (32-Bit) (Version: 4.01.0) XMedia Recode Version 3.1.5.4 (Version: 3.1.5.4) ==================== Restore Points ========================= 27-08-2013 13:36:08 Windows Update 27-08-2013 13:46:04 Soluto 27-08-2013 14:00:33 Removed Soluto 27-08-2013 14:03:24 Removed inSSIDer 3 31-08-2013 11:14:14 Windows Update 31-08-2013 11:55:59 Removed Java 7 Update 25 04-09-2013 05:55:49 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-04-19 22:33 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {024F4A5D-51BA-483A-BD6B-D776372A36B3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {0A46379B-364E-413F-817A-1F39F1ABE46A} - System32\Tasks\User_Feed_Synchronization-{E05BD53F-55BE-4FD5-AB3E-AAF284007120} => C:\windows\system32\msfeedssync.exe [2013-04-20] (Microsoft Corporation) Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {0E8B358E-5CF7-4113-9F75-25B2D7605919} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {283055E3-FD9D-4347-941F-764978742BB2} - System32\Tasks\TWIN 7 1-Klick-Optimierung => C:\Program Files\DATA BECKER\TWIN7 2.0\TvDlgSheduler.exe Task: {2B36C791-9773-4124-A9C6-AC48BF88526C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-19] (Google Inc.) Task: {395AB026-F01D-402C-9055-0BDA6A585D73} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03] (Adobe Systems Incorporated) Task: {5D5F8495-6531-49C2-9B4C-E9814AC591A6} - System32\Tasks\0 => Iexplore.exe Task: {6C647406-B94C-4AE1-B9ED-0B8FBAF69AEA} - System32\Tasks\YourFile Update => C:\Program Files\YourFileDownloader\YourFileUpdater.exe Task: {71AA304F-DC80-423E-8B69-807ADE1968DD} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe Task: {7416CCA2-A40E-46E6-B227-02B6D28E4FFD} - System32\Tasks\4738 => C:\Windows\System32\wscript.exe [2009-07-14] (Microsoft Corporation) Task: {74A9F188-333F-47B6-A023-92C4DBB7EE5A} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-07] (Adobe Systems Incorporated) Task: {7FB75863-BEEA-4031-9865-3A9F74B92E6B} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {9AFAC5C2-F7A4-4E63-ABDF-C5BB50BA645B} - System32\Tasks\Google Updater and Installer => C:\Users\power\AppData\Local\Google\Update\GoogleUpdate.exe Task: {AADBCE2C-0785-4625-A16D-1C119503DB8B} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3662886436-2550715429-2728409154-1000 Task: {B5D64A68-F96D-4D55-BEA6-97A048E86277} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe [2012-09-19] (TuneUp Software) Task: {C8C6075B-A978-4E56-86B7-31CD4340FDF8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {D63DA003-4EBC-4083-87B4-7ED1C078240C} - System32\Tasks\RegClean Pro => C:\Program Files\RegClean Pro\RegCleanPro.exe Task: {E250CE8A-B46A-4E62-89E2-B3DBF976FA3A} - System32\Tasks\TWIN 7 Live-Update => C:\Program Files\DATA BECKER\TWIN7 2.0\TvDlgSheduler.exe Task: {E3A15179-5E37-404B-996A-09E8CDDBF2F5} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation) Task: {E53EDB90-415C-4E31-BA5A-CC8165C0E263} - System32\Tasks\Express FilesUpdate => C:\Program Files\ExpressFiles\EFUpdater.exe Task: {FA365C7A-8734-4F77-AD46-63F23E520EF8} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-20] (Microsoft Corporation) Task: {FDF3AB90-6B1F-4336-A558-D04FAF29D29D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-19] (Google Inc.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files\TuneUp Utilities 2013\OneClick.exe ==================== Loaded Modules (whitelisted) ============= 2009-07-14 02:07 - 2009-07-14 03:14 - 00064000 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\System32\l3codeca.acm 2011-02-22 15:32 - 2004-12-25 13:37 - 00258121 _____ () C:\Program Files\Athan\vbh.dll 2011-02-22 15:32 - 2010-03-08 22:08 - 00282697 _____ () C:\Program Files\Athan\vbp.dll 2011-02-22 15:32 - 2004-03-20 14:49 - 00229444 _____ () C:\Program Files\Athan\vbq.dll 2004-03-08 23:00 - 2004-03-08 23:00 - 00132880 _____ (Microsoft Corporation) C:\windows\system32\athan\msinet.ocx 2013-08-17 11:20 - 2013-08-17 11:20 - 03551640 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========== ==================== Faulty Device Manager Devices ============= Name: Ethernet-Controller Description: Ethernet-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/12/2013 02:30:55 PM) (Source: MsiInstaller) (User: power-PC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011004}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (09/12/2013 01:58:42 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0xa38 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (09/12/2013 07:32:55 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0xd30 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (09/10/2013 07:53:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0xd18 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (09/09/2013 09:50:29 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (09/09/2013 09:35:24 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (09/09/2013 07:15:20 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (09/09/2013 03:03:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: SafetyNutManager.exe, Version: 5.0.0.8883, Zeitstempel: 0x52138bbe Name des fehlerhaften Moduls: SafetyNutManager.exe, Version: 5.0.0.8883, Zeitstempel: 0x52138bbe Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004ab76 ID des fehlerhaften Prozesses: 0xa78 Startzeit der fehlerhaften Anwendung: 0xSafetyNutManager.exe0 Pfad der fehlerhaften Anwendung: SafetyNutManager.exe1 Pfad des fehlerhaften Moduls: SafetyNutManager.exe2 Berichtskennung: SafetyNutManager.exe3 Error: (09/09/2013 01:49:17 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0xb80 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (09/09/2013 07:25:07 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version: 13.6.20.2100, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00001487 ID des fehlerhaften Prozesses: 0xd18 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 System errors: ============= Error: (09/12/2013 01:59:02 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (09/12/2013 01:57:53 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 12.09.2013 um 12:53:17 unerwartet heruntergefahren. Error: (09/12/2013 11:45:31 AM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (09/12/2013 07:33:23 AM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (09/11/2013 08:56:33 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/11/2013 08:56:24 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/11/2013 08:56:22 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/11/2013 08:56:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (09/11/2013 07:54:42 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (09/11/2013 07:54:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Microsoft Office Sessions: ========================= Error: (09/12/2013 02:30:55 PM) (Source: MsiInstaller)(User: power-PC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011004}1625(NULL)(NULL)(NULL) Error: (09/12/2013 01:58:42 PM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500001487a3801ceafaf6b68c595C:\Program Files\Avira\AntiVir Desktop\avnotify.exeC:\Program Files\Avira\AntiVir Desktop\avnotify.exeaabd0566-1ba2-11e3-bd25-d6f44493391d Error: (09/12/2013 07:32:55 AM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500001487d3001ceaf7987ed1806C:\Program Files\Avira\AntiVir Desktop\avnotify.exeC:\Program Files\Avira\AntiVir Desktop\avnotify.exec5d9e80e-1b6c-11e3-9f79-a0c11ba1b116 Error: (09/10/2013 07:53:23 PM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500001487d1801ceae4ea456209cC:\Program Files\Avira\AntiVir Desktop\avnotify.exeC:\Program Files\Avira\AntiVir Desktop\avnotify.exee2408f43-1a41-11e3-89a7-e31b34395f15 Error: (09/09/2013 09:50:29 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (09/09/2013 09:35:24 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (09/09/2013 07:15:20 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (09/09/2013 03:03:23 PM) (Source: Application Error)(User: ) Description: SafetyNutManager.exe5.0.0.888352138bbeSafetyNutManager.exe5.0.0.888352138bbec00000050004ab76a7801cead5cc5c834cdC:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exeC:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe349c1b98-1950-11e3-82e1-b56ad204f51d Error: (09/09/2013 01:49:17 PM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500001487b8001cead529c7e00dcC:\Program Files\Avira\AntiVir Desktop\avnotify.exeC:\Program Files\Avira\AntiVir Desktop\avnotify.exedaa4fbeb-1945-11e3-82e1-b56ad204f51d Error: (09/09/2013 07:25:07 AM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500001487d1801cead1cf19ff8f3C:\Program Files\Avira\AntiVir Desktop\avnotify.exeC:\Program Files\Avira\AntiVir Desktop\avnotify.exe2fa1b87f-1910-11e3-a08f-f936ccd8bc18 ==================== Memory info =========================== Percentage of memory in use: 51% Total physical RAM: 2038.12 MB Available physical RAM: 989.98 MB Total Pagefile: 4076.23 MB Available Pagefile: 2638.57 MB Total Virtual: 2047.88 MB Available Virtual: 1913.08 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:100 GB) (Free:53.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:117.87 GB) (Free:63.87 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 82376CA1) Partition 1: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=15 GB) - (Type=1B) Partition 3: (Not Active) - (Size=118 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=16 MB) - (Type=EF) ==================== End Of Log ============================ |
12.09.2013, 17:38 | #4 | |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ?Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.09.2013, 07:44 | #5 |
| Malwarebytes 34 Funde Normal ? Hier ist die Logdatei Code:
ATTFilter ComboFix 13-09-12.01 - ******+13.09.2013 8:07.1.4 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.49.1031.18.2038.1134 [GMT 2:00] ausgeführt von:: c:\users\power\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\SaveShare c:\programdata\saviEnshare c:\users\power\AppData\Roaming\dclogs c:\users\power\AppData\Roaming\dclogs\2013-08-09-6.dc c:\users\power\AppData\Roaming\ImgBurn.exe c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk\bootstrap.js c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk\chrome.manifest c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk\content\bg.js c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk\install.rdf c:\users\power\AppData\Roaming\yuvcodecs-1.3.exe c:\windows\system32\MSDCSC . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-13 bis 2013-09-13 )))))))))))))))))))))))))))))) . . 2013-09-13 06:22 . 2013-09-13 06:22 -------- d-----w- c:\users\Public\AppData\Local\temp 2013-09-13 06:22 . 2013-09-13 06:22 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-13 05:28 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C027B012-0C58-441B-899C-FC2006B6C9E3}\mpengine.dll 2013-09-12 12:31 . 2013-09-12 12:31 -------- d-----w- C:\FRST 2013-09-09 17:15 . 2013-09-09 17:15 -------- d-----w- c:\programdata\Browser Manager 2013-09-09 13:16 . 2013-09-09 13:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-09-09 13:16 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-09-06 07:38 . 2013-09-06 07:38 -------- d-----w- C:\found.001 2013-09-05 18:35 . 2013-09-13 05:21 -------- d-----w- c:\users\power\AppData\Local\CrashDumps 2013-08-31 23:15 . 2013-08-31 23:15 -------- d-----w- c:\users\power\verschicht - klamotten 2013-08-29 17:38 . 2008-01-24 11:44 -------- d-----w- C:\eeepcfr 2013-08-29 16:25 . 2013-08-29 16:25 -------- d-----w- C:\SFX 2013-08-29 16:25 . 2013-08-29 16:25 -------- d-----w- C:\[BOOT] 2013-08-29 16:25 . 2013-08-29 16:25 -------- d-----w- C:\PROGRAMS 2013-08-29 16:25 . 2013-08-29 16:25 -------- d-----w- C:\I386 2013-08-29 16:17 . 2013-08-29 16:17 -------- d-----w- c:\users\power\Systemroot 2013-08-29 16:11 . 2013-08-29 16:11 -------- d-----w- c:\users\power\G 2013-08-29 16:09 . 2013-08-29 16:10 -------- d-----w- c:\users\power\Musik 2013-08-29 15:50 . 2013-08-29 16:32 -------- d-----w- c:\users\power\OTLPE 2013-08-29 14:38 . 2012-03-25 18:19 261308720 ----a-w- c:\users\power\cs16full_v7 (2).exe 2013-08-29 10:00 . 2013-08-29 10:01 -------- d-----w- c:\program files\GeoGebra 4.2 2013-08-28 14:30 . 2013-08-28 14:33 -------- d-----w- c:\programdata\HitmanPro 2013-08-27 13:49 . 2013-08-27 14:02 -------- d-sh--w- c:\windows\system32\AI_RecycleBin 2013-08-27 13:45 . 2013-08-27 14:01 -------- d-----w- c:\programdata\Soluto 2013-08-26 12:56 . 2013-08-26 12:56 -------- d-----w- c:\program files\CPUID 2013-08-21 20:44 . 2013-08-27 14:03 -------- d-----w- c:\program files\SpeedFan 2013-08-14 17:17 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-14 17:17 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll 2013-08-14 17:17 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-14 17:17 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll 2013-08-14 17:17 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-14 17:17 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-14 17:17 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-14 17:17 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll 2013-08-14 17:17 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-14 17:17 . 2013-07-25 08:57 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-08-14 17:16 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll 2013-08-14 17:16 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-13 06:22 . 2012-04-05 12:58 29 ----a-w- c:\windows\system32\TempWmicBatchFile.bat 2013-09-04 14:00 . 2013-05-07 13:47 66144 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-09-04 14:00 . 2012-11-09 06:58 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-09-04 14:00 . 2012-11-09 06:58 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-08-21 12:02 . 2012-05-03 05:54 867240 ----a-w- c:\windows\system32\npdeployJava1.dll 2013-08-21 12:02 . 2011-08-24 18:57 789416 ----a-w- c:\windows\system32\deployJava1.dll 2013-08-07 13:04 . 2012-04-16 14:16 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-08-07 13:04 . 2012-04-16 14:16 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-14 17:43 . 2013-07-14 17:43 152848 --s---r- c:\windows\system32\COMDLG32.OCX 2013-07-14 17:43 . 2013-07-14 17:43 1010720 --s---r- c:\windows\system32\MSCHRT20.OCX 2013-06-25 16:21 . 2013-06-25 16:21 428088 ----a-w- c:\windows\system32\drivers\sptd.sys 2013-06-25 15:26 . 2013-06-25 15:24 7760687 ----a-w- c:\users\power\AppData\Roaming\SetupGFD.exe 2013-06-25 15:24 . 2013-06-25 15:18 5243208 ----a-w- c:\users\power\AppData\Roaming\AvsP.exe 2013-06-25 15:18 . 2013-06-25 15:16 1357348 ----a-w- c:\users\power\AppData\Roaming\MatroskaSplitter.exe 2013-06-25 15:10 . 2013-06-25 15:05 5082084 ----a-w- c:\users\power\AppData\Roaming\Avisynth.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-04 347192] "Athan"="c:\program files\Athan\Athan.exe" [2011-11-20 1204224] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^JumpPad.lnk] backup=c:\windows\pss\JumpPad.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^myBoard.lnk] backup=c:\windows\pss\myBoard.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^MySapce.lnk] backup=c:\windows\pss\MySapce.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RocketDock.lnk] backup=c:\windows\pss\RocketDock.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^UberIcon.lnk] backup=c:\windows\pss\UberIcon.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^YzShadow.lnk] backup=c:\windows\pss\YzShadow.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2000-01-01 00:00 10996368 ------w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "ManyCam"="c:\program files\ManyCam\Bin\ManyCam.exe" /silent "StarterBackgroundChanger"="c:\program files\StarterBackgroundChanger\StarterBackgroundChangerTask.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "ASUSPRP"=c:\program files\ASUS\APRP\APRP.EXE "Persistence"=c:\windows\system32\igfxpers.exe "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "IAStorIcon"=c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-03 162408] R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x32.sys [x] R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [x] R3 FlashUSB;FlashUSB;c:\windows\system32\DRIVERS\FlashUSB.sys [2010-05-12 16896] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2012-11-15 35592] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-03-31 11520] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-29 37352] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-09-04 84024] S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-02-15 19968] S2 DBService;DATA BECKER Update Service;c:\program files\Common Files\DATA BECKER Shared\DBService.exe [2010-10-28 189776] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2012-09-19 1699168] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-13 109960] S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys [2012-10-11 34432] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856] S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv.sys [2013-01-31 22656] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-09-19 10088] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Inhalt des "geplante Tasks" Ordners . 2013-08-08 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 13:04] . 2013-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-19 11:45] . 2013-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-19 11:45] . 2013-08-09 c:\windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job - c:\program files\TuneUp Utilities 2013\OneClick.exe [2012-09-19 10:27] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ uSearchAssistant = hxxp://www.google.com IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 10.0.0.1 FF - ProfilePath - c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ FF - prefs.js: keyword.URL - hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=100&systemid=473&v=n8883-100&apn_dtid=BND473&apn_ptnrs=AG1&apn_uid=4352935405034440&o=APN10640&q= FF - ExtSQL: 2013-08-09 15:55; nqiz078@kqgdutpmr.co.uk; c:\users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - c:\program files\Microsoft\BingBar\7.2.233.0\BingExt.dll Toolbar-10 - (no file) AddRemove-Microsoft .NET Framework 4 Client Profile - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe AddRemove-Microsoft .NET Framework 4 Extended - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2468871 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2487367 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2533523 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2600217 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2656351 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2736428 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2742595 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2836939 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2468871 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2478663 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2518870 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2533523 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2539636 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2572078 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2600217 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2604121 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2633870 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656351 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656368 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656368v2 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656405 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2686827 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2729449 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2736428 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2737019 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2742595 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2789642 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2804576 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2835393 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2836939 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2840628 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2840628v2 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe AddRemove-{2FAA2415-618E-4EC0-8253-3CDA076C84D6} - c:\users\power\AppData\Local\{48C6842D-F02B-4949-92E1-B3FEE51A0811}\Setup.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8, 89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b, 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b "{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"=hex:51,66,7a,6c,4c,1d,38,12,e6,58,38, 83,87,d3,7e,06,c2,c6,ef,58,90,09,a1,e1 "{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea, 34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89 "{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"=hex:51,66,7a,6c,4c,1d,38,12,a2,ea,69, 93,b1,e1,86,00,e1,15,a1,39,87,48,a6,c1 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{58124A0B-DC32-4180-9BFF-E0E21AE34026}"=hex:51,66,7a,6c,4c,1d,38,12,65,49,01, 5c,00,92,ee,04,e4,e9,a3,a2,1f,bd,04,32 "{6EBF7485-159F-4BFF-A14F-B9E3AAC4465B}"=hex:51,66,7a,6c,4c,1d,38,12,eb,77,ac, 6a,ad,5b,91,0e,de,59,fa,a3,af,9a,02,4f "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 "{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce, 9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d "{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}"=hex:51,66,7a,6c,4c,1d,38,12,85,b5,89, a4,87,7f,22,00,e8,fa,d8,69,48,cc,aa,3e "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b, ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3 "{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93, aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83 "{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a, ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49 "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd, d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}"=hex:51,66,7a,6c,4c,1d,38,12,70,05,61, f9,ec,d1,23,0d,da,9c,48,eb,44,0f,8e,cc "{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13, 36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d "{336D0C35-8A85-403a-B9D2-65C292C39087}"=hex:51,66,7a,6c,4c,1d,3b,1b,08,dd,94, 76,82,e9,7c,3d,9d,e9,17,af,ad,b0,e5,ab . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:7a,81,9f,9a,22,94,cc,01 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-09-13 08:26:07 ComboFix-quarantined-files.txt 2013-09-13 06:26 . Vor Suchlauf: 23 Verzeichnis(se), 59.716.726.784 Bytes frei Nach Suchlauf: 25 Verzeichnis(se), 59.624.091.648 Bytes frei . - - End Of File - - 2BC804A5ABFE0A0DD49124B56A9F2460 A36C5E4F47E84449FF07ED3517B43A31 |
13.09.2013, 09:12 | #6 |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Malwarebytes 34 Funde Normal ? |
13.09.2013, 13:56 | #7 |
| Malwarebytes 34 Funde Normal ? Hier Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.13.04 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16660 power :: ********** [Administrator] 13.09.2013 13:21:41 mbam-log-2013-09-13 (13-21-41).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214782 Laufzeit: 13 Minute(n), 59 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 4 HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 2 HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {827A3C6B-BB68-408F-AAF7-450B64E7645A} -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {827A3C6B-BB68-408F-AAF7-450B64E7645A} -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\Users\***\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\******\Documents\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 2 C:\Users\*********\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\***********\Documents\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.003 - Bericht erstellt am 13/09/2013 um 14:10:15 # Updated 07/09/2013 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzername : ****************+ # Gestartet von : C:\Users\power\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\Browser Manager Ordner Gelöscht : C:\ProgramData\Uniblue\DriverScanner Ordner Gelöscht : C:\Program Files\SoftwareUpdater Ordner Gelöscht : C:\Users\power\AppData\Local\cre Ordner Gelöscht : C:\Users\power\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\*****\AppData\Roaming\ExpressFiles Ordner Gelöscht : C:\Users\*******\AppData\Roaming\Systweak Datei Gelöscht : C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\searchplugins\Ask.xml Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\Ask.xml Datei Gelöscht : C:\Users\******\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\searchplugins\Babylon.xml Datei Gelöscht : C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\user.js Datei Gelöscht : C:\windows\System32\Tasks\YourFile Update ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile Update [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C647406-B94C-4AE1-B9ED-0B8FBAF69AEA} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6C647406-B94C-4AE1-B9ED-0B8FBAF69AEA} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\532dedfe16deb12 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_counter-strike-online_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_counter-strike-online_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_microsoft-powerpoint-viewer_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_microsoft-powerpoint-viewer_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_mycolors_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_mycolors_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_starter-background-changer_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_starter-background-changer_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_athan-azan-basic_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_athan-azan-basic_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_avira-antivir_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_avira-antivir_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_battlefield-2_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_battlefield-2_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bluetoothview_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_bluetoothview_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_call-of-duty-4_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_call-of-duty-4_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_chicken-invaders-iii_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_chicken-invaders-iii_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_counter-strike-2d_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_counter-strike-2d_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gta-iv-san-andreas_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gta-iv-san-andreas_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hot-potatoes_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hot-potatoes_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_icq_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_icq_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mac-os-x-lion-skin-pack_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mac-os-x-lion-skin-pack_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_modern-warfare-2d_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_modern-warfare-2d_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photoscape_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photoscape_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_snow-transformation-pack_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_snow-transformation-pack_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_tuneup-utilities-2012_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_tuneup-utilities-2012_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-movie-maker_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-movie-maker_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_wolf-team_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_wolf-team_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\BI Schlüssel Gelöscht : HKCU\Software\ExpressFiles Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\ExpressFiles Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\Software\SP Global Schlüssel Gelöscht : HKLM\Software\SProtector Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Uniblue\DriverScanner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF} ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ Datei : C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\prefs.js ] Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false); Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false); Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0); Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", ""); ************************* AdwCleaner[R0].txt - [9772 octets] - [13/09/2013 13:46:20] AdwCleaner[S0].txt - [9767 octets] - [13/09/2013 14:10:15] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9827 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.0 (09.12.2013:1) OS: Windows 7 Starter x86 Ran by ****** on 13.09.2013 at 14:37:56,83 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\anchorfree Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\IB Updater Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\SweetIM Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\Wajam Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\yuna software Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Ask-Fm-Autolike_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Ask-Fm-Autolike_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\taskhost_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\taskhost_RASMANCS ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\****/appdata\locallow\datamngr" Successfully deleted: [Folder] "C:\windows\system32\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\power\appdata\local\{2C0B29A3-27DF-4742-B1B8-B89F68159780} ~~~ FireFox Successfully deleted the following from C:\Users\*******\AppData\Roaming\mozilla\firefox\profiles\nwe7omcc.default\prefs.js user_pref("keyword.URL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=100&systemid=473&v=n8883-100&apn_dtid=BND473&apn_ptnrs=AG1&apn_uid=4352935405034440&o=APN10640&q=") Emptied folder: C:\Users\*********\AppData\Roaming\mozilla\firefox\profiles\nwe7omcc.default\minidumps [200 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.09.2013 at 14:44:57,50 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 Ran by power (administrator) on POWER-PC on 13-09-2013 14:52:06 Running from C:\Users\*******\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Fork Ltd.) C:\Prey\platform\windows\cronsvc.exe (DATA BECKER GmbH & Co KG) C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (www.IslamicFinder.org) C:\Program Files\Athan\Athan.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Athan] - C:\Program Files\Athan\Athan.exe [1204224 2011-11-20] (www.IslamicFinder.org) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-12-13] (AsusTek Computer Inc.) HKU\Default\...\RunOnce: [IconPatch] - C:\Windows\AP\IconPatch.vbs HKU\Default\...\RunOnce: [AskScreensaver] - C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - Backup.Old.DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} SearchScopes: HKCU - Backup.Old.DefaultScope {22644C40-4FC2-4E7A-BDAD-71EA5ED16FC5} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll No File Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" No File Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default FF NewTab: hxxp://www.google.com/firefox FF DefaultSearchEngine: Ask.com FF SearchEngineOrder.1: Ask.com FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Ask.com FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG) R2 CronService; C:\Prey\platform\windows\cronsvc.exe [19968 2011-02-15] (Fork Ltd.) R2 DBService; C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe [189776 2010-10-28] (DATA BECKER GmbH & Co KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1699168 2012-09-19] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 acedrv11; C:\windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH) R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [109960 2010-04-13] (ELAN Microelectronic Corp.) S3 FlashUSB; C:\Windows\System32\DRIVERS\FlashUSB.sys [16896 2010-05-12] (Danish Wireless Design A/S) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [428088 2013-06-25] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-11-09] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-19] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 btwampfl; system32\drivers\btwampfl.sys [x] S3 btwaudio; system32\drivers\btwaudio.sys [x] S3 btwavdt; \SystemRoot\system32\DRIVERS\btwavdt.sys [x] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [x] S3 btwrchid; \SystemRoot\system32\DRIVERS\btwrchid.sys [x] S3 catchme; \??\C:\Users\power\AppData\Local\Temp\catchme.sys [x] S3 cpuz136; \??\C:\windows\TEMP\cpuz136\cpuz136_x32.sys [x] U3 DfSdkS; S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [x] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation) S3 L1C; system32\DRIVERS\L1C62x86.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-13 14:44 - 2013-09-13 14:50 - 00002562 _____ C:\Users\power\Desktop\JRT.txt 2013-09-13 14:35 - 2013-09-13 14:36 - 01082459 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-13 14:34 - 2013-09-13 14:34 - 01029509 _____ (Thisisu) C:\Users\power\Desktop\JRT.exe 2013-09-13 14:18 - 2013-09-13 14:18 - 00009915 _____ C:\Users\power\Desktop\AdwCleaner[S0].txt 2013-09-13 13:46 - 2013-09-13 14:10 - 00000000 ____D C:\AdwCleaner 2013-09-13 13:45 - 2013-09-13 13:45 - 01037278 _____ C:\Users\power\Desktop\adwcleaner.exe 2013-09-13 13:24 - 2013-09-13 13:24 - 97446370 _____ C:\windows\system32\췳లY 2013-09-13 08:27 - 2013-09-13 08:27 - 00021955 _____ C:\Users\power\Desktop\Combofix datei.txt 2013-09-13 08:26 - 2013-09-13 08:26 - 00021955 _____ C:\ComboFix.txt 2013-09-13 08:04 - 2013-09-13 08:26 - 00000000 ____D C:\ComboFix 2013-09-13 08:04 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe 2013-09-13 08:04 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe 2013-09-13 08:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe 2013-09-13 07:57 - 2013-09-13 08:26 - 00000000 ____D C:\Qoobox 2013-09-13 07:55 - 2013-09-13 07:56 - 05124368 ____R (Swearware) C:\Users\power\Desktop\ComboFix.exe 2013-09-12 19:47 - 2013-09-12 19:47 - 00000000 ____D C:\Users\power\Documents\GTA San Andreas User Files 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 15:16 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-09-09 14:39 - 2013-09-09 14:56 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 ____D C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-05 20:35 - 2013-09-13 07:21 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-08-29 19:38 - 2008-01-24 13:44 - 00000000 ____D C:\eeepcfr 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:17 - 2013-08-29 18:17 - 00000000 ____D C:\Users\power\Systemroot 2013-08-29 18:12 - 2013-08-29 18:14 - 00000000 ____D C:\Users\power\OTLPEStd 2013-08-29 18:11 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-08-29 18:09 - 2013-08-29 18:10 - 00000000 ____D C:\Users\power\Musik 2013-08-29 17:50 - 2013-08-29 18:32 - 00000000 ____D C:\Users\power\OTLPE 2013-08-29 16:38 - 2012-03-25 20:19 - 261308720 _____ (Valve) C:\Users\power\cs16full_v7 (2).exe 2013-08-29 12:00 - 2013-08-29 12:01 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:30 - 2013-08-28 16:33 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-28 16:28 - 2013-08-28 16:30 - 12228527 _____ C:\Users\power\HitmanPro_3.7.7.203.zip 2013-08-27 15:49 - 2013-08-27 16:01 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 15:45 - 2013-08-27 16:01 - 00000000 ____D C:\ProgramData\Soluto 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-27 16:03 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo 2013-08-17 11:20 - 2013-08-17 11:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 20:12 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-08-14 20:12 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-08-14 20:12 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-08-14 20:12 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-08-14 20:12 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-08-14 20:12 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-08-14 20:12 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-08-14 20:12 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-08-14 20:12 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-08-14 19:17 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2013-08-14 19:17 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe 2013-08-14 19:17 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2013-08-14 19:17 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2013-08-14 19:17 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2013-08-14 19:17 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll 2013-08-14 19:17 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2013-08-14 19:17 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll 2013-08-14 19:17 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll 2013-08-14 19:17 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2013-08-14 19:16 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-08-14 19:16 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys ==================== One Month Modified Files and Folders ======= 2013-09-13 14:51 - 2012-04-05 14:58 - 00000029 _____ C:\windows\system32\TempWmicBatchFile.bat 2013-09-13 14:50 - 2013-09-13 14:44 - 00002562 _____ C:\Users\power\Desktop\JRT.txt 2013-09-13 14:37 - 2013-04-21 00:17 - 00000000 ____D C:\windows\ERUNT 2013-09-13 14:36 - 2013-09-13 14:35 - 01082459 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-13 14:34 - 2013-09-13 14:34 - 01029509 _____ (Thisisu) C:\Users\power\Desktop\JRT.exe 2013-09-13 14:19 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-13 14:19 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-13 14:18 - 2013-09-13 14:18 - 00009915 _____ C:\Users\power\Desktop\AdwCleaner[S0].txt 2013-09-13 14:11 - 2013-04-20 16:46 - 00065536 _____ C:\windows\system32\Ikeext.etl 2013-09-13 14:11 - 2013-03-18 05:43 - 00047061 _____ C:\windows\setupact.log 2013-09-13 14:10 - 2013-09-13 13:46 - 00000000 ____D C:\AdwCleaner 2013-09-13 14:10 - 2011-08-25 05:19 - 01508965 _____ C:\windows\WindowsUpdate.log 2013-09-13 14:10 - 2009-07-14 04:37 - 00000000 ____D C:\windows\tracing 2013-09-13 13:45 - 2013-09-13 13:45 - 01037278 _____ C:\Users\power\Desktop\adwcleaner.exe 2013-09-13 13:24 - 2013-09-13 13:24 - 97446370 _____ C:\windows\system32\췳లY 2013-09-13 08:40 - 2013-03-18 05:42 - 00064482 _____ C:\windows\PFRO.log 2013-09-13 08:27 - 2013-09-13 08:27 - 00021955 _____ C:\Users\power\Desktop\Combofix datei.txt 2013-09-13 08:26 - 2013-09-13 08:26 - 00021955 _____ C:\ComboFix.txt 2013-09-13 08:26 - 2013-09-13 08:04 - 00000000 ____D C:\ComboFix 2013-09-13 08:26 - 2013-09-13 07:57 - 00000000 ____D C:\Qoobox 2013-09-13 08:22 - 2009-07-14 04:04 - 00000215 _____ C:\windows\system.ini 2013-09-13 07:56 - 2013-09-13 07:55 - 05124368 ____R (Swearware) C:\Users\power\Desktop\ComboFix.exe 2013-09-13 07:21 - 2013-09-05 20:35 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-09-12 19:47 - 2013-09-12 19:47 - 00000000 ____D C:\Users\power\Documents\GTA San Andreas User Files 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-12 08:11 - 2013-05-06 20:05 - 00000000 ____D C:\Users\power\AppData\Roaming\Skype 2013-09-11 21:34 - 2013-05-12 11:39 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 21:54 - 2011-08-24 20:23 - 00000000 ____D C:\Users\power 2013-09-09 21:50 - 2009-07-25 09:50 - 00389388 _____ C:\windows\system32\PerfStringBackup.INI 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 14:56 - 2013-09-09 14:39 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-08 09:27 - 2012-05-17 17:47 - 00000000 ____D C:\Users\power\Virus 2013-09-07 04:17 - 2013-03-25 18:54 - 00000000 ____D C:\Users\power\AppData\Roaming\vlc 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 ____D C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-04 16:00 - 2013-05-07 15:47 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2013-08-31 22:43 - 2013-02-09 13:13 - 00000000 ____D C:\Users\power\Schule 2013-08-30 07:44 - 2012-10-18 18:10 - 00000000 ____D C:\Users\power\AppData\Roaming\.minecraft 2013-08-29 18:32 - 2013-08-29 17:50 - 00000000 ____D C:\Users\power\OTLPE 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:17 - 2013-08-29 18:17 - 00000000 ____D C:\Users\power\Systemroot 2013-08-29 18:14 - 2013-08-29 18:12 - 00000000 ____D C:\Users\power\OTLPEStd 2013-08-29 18:11 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-08-29 18:10 - 2013-08-29 18:09 - 00000000 ____D C:\Users\power\Musik 2013-08-29 12:01 - 2013-08-29 12:00 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:33 - 2013-08-28 16:30 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-28 16:30 - 2013-08-28 16:28 - 12228527 _____ C:\Users\power\HitmanPro_3.7.7.203.zip 2013-08-27 16:03 - 2013-08-21 22:44 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-27 16:02 - 2013-07-20 16:26 - 00000000 ____D C:\Program Files\NirSoft 2013-08-27 16:01 - 2013-08-27 15:49 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 16:01 - 2013-08-27 15:45 - 00000000 ____D C:\ProgramData\Soluto 2013-08-27 15:54 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo 2013-08-21 14:02 - 2012-05-03 07:54 - 00867240 _____ (Oracle Corporation) C:\windows\system32\npdeployJava1.dll 2013-08-21 14:02 - 2011-08-24 20:57 - 00789416 _____ (Oracle Corporation) C:\windows\system32\deployJava1.dll 2013-08-17 21:40 - 2013-04-21 22:55 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-17 11:20 - 2013-08-17 11:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 21:56 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE 2013-08-14 20:26 - 2013-08-03 18:11 - 00000000 ____D C:\windows\system32\MRT 2013-08-14 20:21 - 2011-11-12 13:31 - 75778376 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-08-14 19:45 - 2012-12-21 13:50 - 00000000 ____D C:\Users\power\AppData\Roaming\ICQ Files to move or delete: ==================== C:\Users\power\cs16full_v7 (2).exe C:\Users\power\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-03 14:57 ==================== End Of Log ============================ Danke |
13.09.2013, 19:38 | #8 |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.09.2013, 20:26 | #9 |
| Malwarebytes 34 Funde Normal ? Sorry kam leider vorher nicht zu den Scans Ich hatte vorher ja auch keine Probleme also ist eigentlich alles gleich Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=890fb00587795f4aa5996a070d7b1aec # engine=15162 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-09-17 07:00:44 # local_time=2013-09-17 09:00:44 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 18067 154856890 10826 0 # compatibility_mode=5893 16776573 100 94 171272 131075635 0 0 # scanned=143518 # found=4 # cleaned=0 # scan_time=17917 sh=363BB90BFDA91AB1F64079B239A3BBB12C268983 ft=1 fh=539e85a8c9d49f3f vn="MSIL/Hoax.FakeHack.B application" ac=I fn="C:\Program Files\Ultimate Facebook Hacker\ufacebookhacker_v351.exe" sh=8FB638B569B93C494808C05641A17E5B8CA7CF3F ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Qoobox\Quarantine\C\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\extensions\nqiz078@kqgdutpmr.co.uk\content\bg.js.vir" sh=4D1236E14B8558F53927DFF348A35AA3CF31AE7F ft=1 fh=6feb8ab151a2249e vn="a variant of Win32/SpeedingUpMyPC.B application" ac=I fn="C:\Users\power\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GTW8453L\OptimizerPro[1].exe" sh=085E37121C529247015A8D15E7C52D1F613D5CB1 ft=1 fh=23f46a56cb3fb42f vn="a variant of Win32/Kryptik.APK trojan" ac=I fn="C:\Users\power\Virus\Wallhack\EnhancedAim Cracked CS1.6\EnhancedAim_CS1.6.dll" Code:
ATTFilter Results of screen317's Security Check version 0.99.73 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 TuneUp Utilities 2013 TuneUp Utilities Language Pack (de-DE) Java 7 Update 40 Java version out of Date! Adobe Flash Player 11.8.800.94 Adobe Reader XI Mozilla Firefox (23.0.1) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03 Ran by power (administrator) on ************on 17-09-2013 21:22:18 Running from C:\Users\power\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Fork Ltd.) C:\Prey\platform\windows\cronsvc.exe (DATA BECKER GmbH & Co KG) C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (www.IslamicFinder.org) C:\Program Files\Athan\Athan.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Athan] - C:\Program Files\Athan\Athan.exe [1204224 2011-11-20] (www.IslamicFinder.org) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-12-13] (AsusTek Computer Inc.) HKU\Default\...\RunOnce: [IconPatch] - C:\Windows\AP\IconPatch.vbs HKU\Default\...\RunOnce: [AskScreensaver] - C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe HKU\Default User\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-12-13] (AsusTek Computer Inc.) HKU\Default User\...\RunOnce: [IconPatch] - C:\Windows\AP\IconPatch.vbs HKU\Default User\...\RunOnce: [AskScreensaver] - C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - Backup.Old.DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} SearchScopes: HKCU - Backup.Old.DefaultScope {22644C40-4FC2-4E7A-BDAD-71EA5ED16FC5} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll No File BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" No File Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default FF NewTab: hxxp://www.google.com/firefox FF DefaultSearchEngine: Ask.com FF SearchEngineOrder.1: Ask.com FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Ask.com FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG) R2 CronService; C:\Prey\platform\windows\cronsvc.exe [19968 2011-02-15] (Fork Ltd.) R2 DBService; C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe [189776 2010-10-28] (DATA BECKER GmbH & Co KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1699168 2012-09-19] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 acedrv11; C:\windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH) R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [109960 2010-04-13] (ELAN Microelectronic Corp.) S3 FlashUSB; C:\Windows\System32\DRIVERS\FlashUSB.sys [16896 2010-05-12] (Danish Wireless Design A/S) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [428088 2013-06-25] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-11-09] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-19] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 btwampfl; system32\drivers\btwampfl.sys [x] S3 btwaudio; system32\drivers\btwaudio.sys [x] S3 btwavdt; \SystemRoot\system32\DRIVERS\btwavdt.sys [x] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [x] S3 btwrchid; \SystemRoot\system32\DRIVERS\btwrchid.sys [x] S3 catchme; \??\C:\Users\power\AppData\Local\Temp\catchme.sys [x] S3 cpuz136; \??\C:\windows\TEMP\cpuz136\cpuz136_x32.sys [x] U3 DfSdkS; S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [x] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation) S3 L1C; system32\DRIVERS\L1C62x86.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-17 21:21 - 2013-09-17 21:21 - 01083437 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-17 21:20 - 2013-09-17 21:20 - 00001074 _____ C:\Users\power\Desktop\checkup.txt 2013-09-17 21:13 - 2013-09-17 21:13 - 00891144 _____ C:\Users\power\Desktop\SecurityCheck.exe 2013-09-16 12:47 - 2013-09-16 12:47 - 97757658 _____ C:\windows\system32\铭e 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\ProgramData\Oracle 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-14 11:44 - 2013-09-14 11:43 - 00264616 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\java.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll 2013-09-14 11:43 - 2013-09-14 11:43 - 00000000 ____D C:\Program Files\Java 2013-09-14 11:35 - 2013-09-14 11:41 - 29036456 _____ (Oracle Corporation) C:\Users\power\Desktop\jre-7u40-windows-i586.exe 2013-09-14 11:20 - 2013-09-14 11:20 - 02347384 _____ (ESET) C:\Users\power\Desktop\esetsmartinstaller_enu.exe 2013-09-14 11:06 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-09-14 11:06 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-09-14 11:06 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-09-14 11:06 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-09-14 11:06 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-09-14 11:06 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-09-14 10:53 - 2013-09-14 10:53 - 97519942 _____ C:\windows\system32\㌜ꮟl 2013-09-13 14:44 - 2013-09-13 14:50 - 00002562 _____ C:\Users\power\Desktop\JRT.txt 2013-09-13 14:34 - 2013-09-13 14:34 - 01029509 _____ (Thisisu) C:\Users\power\Desktop\JRT.exe 2013-09-13 14:18 - 2013-09-13 14:18 - 00009915 _____ C:\Users\power\Desktop\AdwCleaner[S0].txt 2013-09-13 13:46 - 2013-09-13 14:10 - 00000000 ____D C:\AdwCleaner 2013-09-13 13:45 - 2013-09-13 13:45 - 01037278 _____ C:\Users\power\Desktop\adwcleaner.exe 2013-09-13 13:24 - 2013-09-13 13:24 - 97446370 _____ C:\windows\system32\췳లY 2013-09-13 08:27 - 2013-09-13 08:27 - 00021955 _____ C:\Users\power\Desktop\Combofix datei.txt 2013-09-13 08:26 - 2013-09-13 08:26 - 00021955 _____ C:\ComboFix.txt 2013-09-13 08:04 - 2013-09-13 08:26 - 00000000 ____D C:\ComboFix 2013-09-13 08:04 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe 2013-09-13 08:04 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe 2013-09-13 08:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe 2013-09-13 07:57 - 2013-09-13 08:26 - 00000000 ____D C:\Qoobox 2013-09-13 07:55 - 2013-09-13 07:56 - 05124368 ____R (Swearware) C:\Users\power\Desktop\ComboFix.exe 2013-09-13 07:33 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-09-13 07:33 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys 2013-09-13 07:33 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll 2013-09-13 07:33 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2013-09-13 07:33 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe 2013-09-13 07:33 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-13 07:33 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2013-09-13 07:33 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll 2013-09-12 19:47 - 2013-09-12 19:47 - 00000000 ____D C:\Users\power\Documents\GTA San Andreas User Files 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 15:16 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-09-09 14:39 - 2013-09-09 14:56 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 ____D C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-05 20:35 - 2013-09-17 16:00 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-08-29 19:38 - 2008-01-24 13:44 - 00000000 ____D C:\eeepcfr 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:17 - 2013-08-29 18:17 - 00000000 ____D C:\Users\power\Systemroot 2013-08-29 18:12 - 2013-08-29 18:14 - 00000000 ____D C:\Users\power\OTLPEStd 2013-08-29 18:11 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-08-29 18:09 - 2013-08-29 18:10 - 00000000 ____D C:\Users\power\Musik 2013-08-29 17:50 - 2013-08-29 18:32 - 00000000 ____D C:\Users\power\OTLPE 2013-08-29 16:38 - 2012-03-25 20:19 - 261308720 _____ (Valve) C:\Users\power\cs16full_v7 (2).exe 2013-08-29 12:00 - 2013-08-29 12:01 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:30 - 2013-08-28 16:33 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-28 16:28 - 2013-08-28 16:30 - 12228527 _____ C:\Users\power\HitmanPro_3.7.7.203.zip 2013-08-27 15:49 - 2013-08-27 16:01 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 15:45 - 2013-08-27 16:01 - 00000000 ____D C:\ProgramData\Soluto 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-27 16:03 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo ==================== One Month Modified Files and Folders ======= 2013-09-17 21:23 - 2012-04-05 14:58 - 00000029 _____ C:\windows\system32\TempWmicBatchFile.bat 2013-09-17 21:21 - 2013-09-17 21:21 - 01083437 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-17 21:20 - 2013-09-17 21:20 - 00001074 _____ C:\Users\power\Desktop\checkup.txt 2013-09-17 21:13 - 2013-09-17 21:13 - 00891144 _____ C:\Users\power\Desktop\SecurityCheck.exe 2013-09-17 21:11 - 2011-08-25 05:19 - 01741184 _____ C:\windows\WindowsUpdate.log 2013-09-17 20:37 - 2013-05-06 20:05 - 00000000 ____D C:\Users\power\AppData\Roaming\Skype 2013-09-17 20:11 - 2009-07-14 04:37 - 00000000 ____D C:\windows\tracing 2013-09-17 17:44 - 2011-09-19 13:43 - 00000000 ____D C:\ProgramData\Skype 2013-09-17 17:43 - 2013-07-02 15:30 - 00000000 ___RD C:\Program Files\Skype 2013-09-17 16:07 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-17 16:07 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-17 16:00 - 2013-09-05 20:35 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-09-17 15:59 - 2013-04-20 16:46 - 00065536 _____ C:\windows\system32\Ikeext.etl 2013-09-17 15:58 - 2013-03-18 05:43 - 00048586 _____ C:\windows\setupact.log 2013-09-16 12:47 - 2013-09-16 12:47 - 97757658 _____ C:\windows\system32\铭e 2013-09-16 12:42 - 2009-07-25 09:50 - 00389388 _____ C:\windows\system32\PerfStringBackup.INI 2013-09-15 01:06 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-09-14 14:46 - 2013-03-18 05:43 - 00265936 _____ C:\windows\system32\FNTCACHE.DAT 2013-09-14 14:43 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE 2013-09-14 12:36 - 2012-10-18 18:10 - 00000000 ____D C:\Users\power\AppData\Roaming\.minecraft 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\ProgramData\Oracle 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-14 11:43 - 2013-09-14 11:44 - 00264616 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\java.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll 2013-09-14 11:43 - 2013-09-14 11:43 - 00000000 ____D C:\Program Files\Java 2013-09-14 11:43 - 2012-05-03 07:54 - 00868264 _____ (Oracle Corporation) C:\windows\system32\npdeployJava1.dll 2013-09-14 11:43 - 2011-08-24 20:57 - 00790440 _____ (Oracle Corporation) C:\windows\system32\deployJava1.dll 2013-09-14 11:41 - 2013-09-14 11:35 - 29036456 _____ (Oracle Corporation) C:\Users\power\Desktop\jre-7u40-windows-i586.exe 2013-09-14 11:20 - 2013-09-14 11:20 - 02347384 _____ (ESET) C:\Users\power\Desktop\esetsmartinstaller_enu.exe 2013-09-14 11:00 - 2013-08-03 18:11 - 00000000 ____D C:\windows\system32\MRT 2013-09-14 10:57 - 2011-11-12 13:31 - 76725432 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-09-14 10:53 - 2013-09-14 10:53 - 97519942 _____ C:\windows\system32\㌜ꮟl 2013-09-13 14:50 - 2013-09-13 14:44 - 00002562 _____ C:\Users\power\Desktop\JRT.txt 2013-09-13 14:37 - 2013-04-21 00:17 - 00000000 ____D C:\windows\ERUNT 2013-09-13 14:34 - 2013-09-13 14:34 - 01029509 _____ (Thisisu) C:\Users\power\Desktop\JRT.exe 2013-09-13 14:18 - 2013-09-13 14:18 - 00009915 _____ C:\Users\power\Desktop\AdwCleaner[S0].txt 2013-09-13 14:10 - 2013-09-13 13:46 - 00000000 ____D C:\AdwCleaner 2013-09-13 14:10 - 2012-12-16 19:03 - 00000000 ____D C:\ProgramData\Uniblue 2013-09-13 13:45 - 2013-09-13 13:45 - 01037278 _____ C:\Users\power\Desktop\adwcleaner.exe 2013-09-13 13:24 - 2013-09-13 13:24 - 97446370 _____ C:\windows\system32\췳లY 2013-09-13 08:40 - 2013-03-18 05:42 - 00064482 _____ C:\windows\PFRO.log 2013-09-13 08:27 - 2013-09-13 08:27 - 00021955 _____ C:\Users\power\Desktop\Combofix datei.txt 2013-09-13 08:26 - 2013-09-13 08:26 - 00021955 _____ C:\ComboFix.txt 2013-09-13 08:26 - 2013-09-13 08:04 - 00000000 ____D C:\ComboFix 2013-09-13 08:26 - 2013-09-13 07:57 - 00000000 ____D C:\Qoobox 2013-09-13 08:22 - 2009-07-14 04:04 - 00000215 _____ C:\windows\system.ini 2013-09-13 07:56 - 2013-09-13 07:55 - 05124368 ____R (Swearware) C:\Users\power\Desktop\ComboFix.exe 2013-09-12 19:47 - 2013-09-12 19:47 - 00000000 ____D C:\Users\power\Documents\GTA San Andreas User Files 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-11 21:34 - 2013-05-12 11:39 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 21:54 - 2011-08-24 20:23 - 00000000 ____D C:\Users\power 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 14:56 - 2013-09-09 14:39 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-08 09:27 - 2012-05-17 17:47 - 00000000 ____D C:\Users\power\Virus 2013-09-07 04:17 - 2013-03-25 18:54 - 00000000 ____D C:\Users\power\AppData\Roaming\vlc 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 ____D C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-04 16:00 - 2013-05-07 15:47 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2013-08-31 22:43 - 2013-02-09 13:13 - 00000000 ____D C:\Users\power\Schule 2013-08-29 18:32 - 2013-08-29 17:50 - 00000000 ____D C:\Users\power\OTLPE 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:17 - 2013-08-29 18:17 - 00000000 ____D C:\Users\power\Systemroot 2013-08-29 18:14 - 2013-08-29 18:12 - 00000000 ____D C:\Users\power\OTLPEStd 2013-08-29 18:11 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-08-29 18:10 - 2013-08-29 18:09 - 00000000 ____D C:\Users\power\Musik 2013-08-29 12:01 - 2013-08-29 12:00 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:33 - 2013-08-28 16:30 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-28 16:30 - 2013-08-28 16:28 - 12228527 _____ C:\Users\power\HitmanPro_3.7.7.203.zip 2013-08-27 16:03 - 2013-08-21 22:44 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-27 16:02 - 2013-07-20 16:26 - 00000000 ____D C:\Program Files\NirSoft 2013-08-27 16:01 - 2013-08-27 15:49 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 16:01 - 2013-08-27 15:45 - 00000000 ____D C:\ProgramData\Soluto 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo Files to move or delete: ==================== C:\Users\power\cs16full_v7 (2).exe Some content of TEMP: ==================== C:\Users\power\AppData\Local\Temp\i4jdel0.exe C:\Users\power\AppData\Local\Temp\Quarantine.exe C:\Users\power\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-03 14:57 ==================== End Of Log ======= |
17.09.2013, 20:35 | #10 | |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ?Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.09.2013, 06:59 | #11 |
| Malwarebytes 34 Funde Normal ? Also ich geb es zu das mit dem Cs1.6 Hack war ich aber mit dem Facebook war ein Kumpel weil er meinte das geht -.- |
18.09.2013, 10:37 | #12 |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ? Lösch den Dreck oder ich muss den Support einstellen. Ebenso alles was sonst wie geklaut/gecrackt oder so ist. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.09.2013, 19:22 | #13 |
| Malwarebytes 34 Funde Normal ? Hab ich Und hier noch mal ein Frisches FRST Log zum Beweis FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03 Ran by power (administrator) on *********** on 19-09-2013 20:19:28 Running from C:\Users\power\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Fork Ltd.) C:\Prey\platform\windows\cronsvc.exe (DATA BECKER GmbH & Co KG) C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (www.IslamicFinder.org) C:\Program Files\Athan\Athan.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\swriter.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Athan] - C:\Program Files\Athan\Athan.exe [1204224 2011-11-20] (www.IslamicFinder.org) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-12-13] (AsusTek Computer Inc.) HKU\Default\...\RunOnce: [IconPatch] - C:\Windows\AP\IconPatch.vbs HKU\Default\...\RunOnce: [AskScreensaver] - C:\Program Files\Asus\AsusScreensaver\AsusScreensaver.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - Backup.Old.DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} SearchScopes: HKCU - Backup.Old.DefaultScope {22644C40-4FC2-4E7A-BDAD-71EA5ED16FC5} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll No File BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" No File Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default FF NewTab: hxxp://www.google.com/firefox FF DefaultSearchEngine: Ask.com FF SearchEngineOrder.1: Ask.com FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Ask.com FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\power\AppData\Roaming\Mozilla\Firefox\Profiles\nwe7omcc.default\Extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG) R2 CronService; C:\Prey\platform\windows\cronsvc.exe [19968 2011-02-15] (Fork Ltd.) R2 DBService; C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe [189776 2010-10-28] (DATA BECKER GmbH & Co KG) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1699168 2012-09-19] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 acedrv11; C:\windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH) R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [109960 2010-04-13] (ELAN Microelectronic Corp.) S3 FlashUSB; C:\Windows\System32\DRIVERS\FlashUSB.sys [16896 2010-05-12] (Danish Wireless Design A/S) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-10-11] (ManyCam LLC) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [22656 2013-01-31] (ManyCam LLC) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [428088 2013-06-25] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-11-09] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-19] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 btwampfl; system32\drivers\btwampfl.sys [x] S3 btwaudio; system32\drivers\btwaudio.sys [x] S3 btwavdt; \SystemRoot\system32\DRIVERS\btwavdt.sys [x] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [x] S3 btwrchid; \SystemRoot\system32\DRIVERS\btwrchid.sys [x] S3 catchme; \??\C:\Users\power\AppData\Local\Temp\catchme.sys [x] S3 cpuz136; \??\C:\windows\TEMP\cpuz136\cpuz136_x32.sys [x] U3 DfSdkS; S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [x] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation) S3 L1C; system32\DRIVERS\L1C62x86.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-19 20:10 - 2013-09-19 20:10 - 00020845 _____ C:\Users\power\Desktop\Regie Buch(1).odt 2013-09-19 20:10 - 2013-09-19 20:10 - 00000102 ____H C:\Users\power\Desktop\.~lock.Regie Buch(1).odt# 2013-09-19 09:50 - 2013-09-19 09:50 - 98323654 _____ C:\windows\system32\븾␀p 2013-09-18 12:02 - 2013-09-18 12:02 - 00019969 _____ C:\Users\power\Desktop\Regie Buch.odt 2013-09-18 10:22 - 2013-09-18 10:22 - 00019281 _____ C:\Users\power\Desktop\WPK Lüneburger Fragebogen.odt 2013-09-18 10:21 - 2013-09-18 10:21 - 00019335 _____ C:\Users\power\Desktop\Hauke Haien.odt 2013-09-17 21:21 - 2013-09-17 21:21 - 01083437 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-16 12:47 - 2013-09-16 12:47 - 97757658 _____ C:\windows\system32\铭e 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\ProgramData\Oracle 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-14 11:44 - 2013-09-14 11:43 - 00264616 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\java.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll 2013-09-14 11:43 - 2013-09-14 11:43 - 00000000 ____D C:\Program Files\Java 2013-09-14 11:06 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-09-14 11:06 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-09-14 11:06 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-09-14 11:06 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-09-14 11:06 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-09-14 11:06 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-09-14 11:06 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-09-14 10:53 - 2013-09-14 10:53 - 97519942 _____ C:\windows\system32\㌜ꮟl 2013-09-13 13:46 - 2013-09-13 14:10 - 00000000 ____D C:\AdwCleaner 2013-09-13 13:45 - 2013-09-13 13:45 - 01037278 _____ C:\Users\power\Desktop\adwcleaner.exe 2013-09-13 13:24 - 2013-09-13 13:24 - 97446370 _____ C:\windows\system32\췳లY 2013-09-13 08:26 - 2013-09-13 08:26 - 00021955 _____ C:\ComboFix.txt 2013-09-13 08:04 - 2013-09-13 08:26 - 00000000 ____D C:\ComboFix 2013-09-13 08:04 - 2011-06-26 08:45 - 00256000 _____ C:\windows\PEV.exe 2013-09-13 08:04 - 2010-11-07 19:20 - 00208896 _____ C:\windows\MBR.exe 2013-09-13 08:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe 2013-09-13 08:04 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe 2013-09-13 07:57 - 2013-09-13 08:26 - 00000000 ____D C:\Qoobox 2013-09-13 07:33 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-09-13 07:33 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys 2013-09-13 07:33 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll 2013-09-13 07:33 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2013-09-13 07:33 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe 2013-09-13 07:33 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-13 07:33 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-13 07:33 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2013-09-13 07:33 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll 2013-09-12 19:47 - 2013-09-12 19:47 - 00000000 ____D C:\Users\power\Documents\GTA San Andreas User Files 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 15:16 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-09-09 14:39 - 2013-09-09 14:56 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 ____D C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-05 20:35 - 2013-09-19 10:41 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-08-29 19:38 - 2008-01-24 13:44 - 00000000 ____D C:\eeepcfr 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 18:11 - 2013-09-19 07:06 - 00000000 ____D C:\Users\power\G 2013-08-29 18:09 - 2013-09-19 07:13 - 00000000 ____D C:\Users\power\Musik 2013-08-29 16:38 - 2012-03-25 20:19 - 261308720 _____ (Valve) C:\Users\power\cs16full_v7 (2).exe 2013-08-29 12:00 - 2013-08-29 12:01 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:30 - 2013-08-28 16:33 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-27 15:49 - 2013-08-27 16:01 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 15:45 - 2013-08-27 16:01 - 00000000 ____D C:\ProgramData\Soluto 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-27 16:03 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo ==================== One Month Modified Files and Folders ======= 2013-09-19 20:20 - 2012-04-05 14:58 - 00000029 _____ C:\windows\system32\TempWmicBatchFile.bat 2013-09-19 20:19 - 2013-05-06 20:05 - 00000000 ____D C:\Users\power\AppData\Roaming\Skype 2013-09-19 20:13 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-19 20:13 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-19 20:10 - 2013-09-19 20:10 - 00020845 _____ C:\Users\power\Desktop\Regie Buch(1).odt 2013-09-19 20:10 - 2013-09-19 20:10 - 00000102 ____H C:\Users\power\Desktop\.~lock.Regie Buch(1).odt# 2013-09-19 20:04 - 2013-04-20 16:46 - 00065536 _____ C:\windows\system32\Ikeext.etl 2013-09-19 20:04 - 2013-03-18 05:43 - 00049426 _____ C:\windows\setupact.log 2013-09-19 15:53 - 2011-08-25 05:19 - 01870079 _____ C:\windows\WindowsUpdate.log 2013-09-19 15:52 - 2009-07-14 04:37 - 00000000 ____D C:\windows\tracing 2013-09-19 10:41 - 2013-09-05 20:35 - 00000000 ____D C:\Users\power\AppData\Local\CrashDumps 2013-09-19 09:50 - 2013-09-19 09:50 - 98323654 _____ C:\windows\system32\븾␀p 2013-09-19 09:35 - 2009-07-25 09:50 - 00389388 _____ C:\windows\system32\PerfStringBackup.INI 2013-09-19 07:15 - 2011-08-24 20:23 - 00000000 ____D C:\Users\power 2013-09-19 07:13 - 2013-08-29 18:09 - 00000000 ____D C:\Users\power\Musik 2013-09-19 07:13 - 2013-02-09 13:13 - 00000000 ____D C:\Users\power\Schule 2013-09-19 07:06 - 2013-08-29 18:11 - 00000000 ____D C:\Users\power\G 2013-09-18 12:02 - 2013-09-18 12:02 - 00019969 _____ C:\Users\power\Desktop\Regie Buch.odt 2013-09-18 10:22 - 2013-09-18 10:22 - 00019281 _____ C:\Users\power\Desktop\WPK Lüneburger Fragebogen.odt 2013-09-18 10:21 - 2013-09-18 10:21 - 00019335 _____ C:\Users\power\Desktop\Hauke Haien.odt 2013-09-18 00:20 - 2013-03-18 05:42 - 00065272 _____ C:\windows\PFRO.log 2013-09-17 21:21 - 2013-09-17 21:21 - 01083437 _____ (Farbar) C:\Users\power\Desktop\FRST.exe 2013-09-17 17:44 - 2011-09-19 13:43 - 00000000 ____D C:\ProgramData\Skype 2013-09-17 17:43 - 2013-07-02 15:30 - 00000000 ___RD C:\Program Files\Skype 2013-09-16 12:47 - 2013-09-16 12:47 - 97757658 _____ C:\windows\system32\铭e 2013-09-15 01:06 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-09-14 14:46 - 2013-03-18 05:43 - 00265936 _____ C:\windows\system32\FNTCACHE.DAT 2013-09-14 14:43 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE 2013-09-14 12:36 - 2012-10-18 18:10 - 00000000 ____D C:\Users\power\AppData\Roaming\.minecraft 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\ProgramData\Oracle 2013-09-14 11:44 - 2013-09-14 11:44 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-14 11:43 - 2013-09-14 11:44 - 00264616 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00175016 _____ (Oracle Corporation) C:\windows\system32\java.exe 2013-09-14 11:43 - 2013-09-14 11:43 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll 2013-09-14 11:43 - 2013-09-14 11:43 - 00000000 ____D C:\Program Files\Java 2013-09-14 11:43 - 2012-05-03 07:54 - 00868264 _____ (Oracle Corporation) C:\windows\system32\npdeployJava1.dll 2013-09-14 11:43 - 2011-08-24 20:57 - 00790440 _____ (Oracle Corporation) C:\windows\system32\deployJava1.dll 2013-09-14 11:00 - 2013-08-03 18:11 - 00000000 ____D C:\windows\system32\MRT 2013-09-14 10:57 - 2011-11-12 13:31 - 76725432 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-09-14 10:53 - 2013-09-14 10:53 - 97519942 _____ C:\windows\system32\㌜ꮟl 2013-09-13 14:37 - 2013-04-21 00:17 - 00000000 ____D C:\windows\ERUNT 2013-09-13 14:10 - 2013-09-13 13:46 - 00000000 ____D C:\AdwCleaner 2013-09-13 14:10 - 2012-12-16 19:03 - 00000000 ____D C:\ProgramData\Uniblue 2013-09-13 13:45 - 2013-09-13 13:45 - 01037278 _____ C:\Users\power\Desktop\adwcleaner.exe 2013-09-13 13:24 - 2013-09-13 13:24 - 97446370 _____ C:\windows\system32\췳లY 2013-09-13 08:26 - 2013-09-13 08:26 - 00021955 _____ C:\ComboFix.txt 2013-09-13 08:26 - 2013-09-13 08:04 - 00000000 ____D C:\ComboFix 2013-09-13 08:26 - 2013-09-13 07:57 - 00000000 ____D C:\Qoobox 2013-09-13 08:22 - 2009-07-14 04:04 - 00000215 _____ C:\windows\system.ini 2013-09-12 19:47 - 2013-09-12 19:47 - 00000000 ____D C:\Users\power\Documents\GTA San Andreas User Files 2013-09-12 14:31 - 2013-09-12 14:31 - 00000000 ____D C:\FRST 2013-09-11 21:34 - 2013-05-12 11:39 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-09-10 19:54 - 2013-09-10 19:54 - 96985259 _____ C:\windows\system32\㛻芆f 2013-09-09 19:50 - 2013-09-09 19:50 - 96732368 _____ C:\windows\system32\脆f 2013-09-09 15:16 - 2013-09-09 15:16 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-09 15:16 - 2013-09-09 15:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-09 14:56 - 2013-09-09 14:39 - 187865470 _____ C:\Users\power\Counter Strike Global Offensive Full Game.zip 2013-09-08 09:27 - 2012-05-17 17:47 - 00000000 ____D C:\Users\power\Virus 2013-09-07 04:17 - 2013-03-25 18:54 - 00000000 ____D C:\Users\power\AppData\Roaming\vlc 2013-09-06 09:40 - 2013-09-06 09:40 - 00003416 ____N C:\bootsqm.dat 2013-09-06 09:38 - 2013-09-06 09:38 - 00000000 ____D C:\found.001 2013-09-05 20:36 - 2013-09-05 20:36 - 96185213 _____ C:\windows\system32\娶颺d 2013-09-04 16:00 - 2013-05-07 15:47 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2013-09-04 16:00 - 2012-11-09 08:58 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\SFX 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\I386 2013-08-29 18:25 - 2013-08-29 18:25 - 00000000 ____D C:\[BOOT] 2013-08-29 12:01 - 2013-08-29 12:00 - 00000000 ____D C:\Program Files\GeoGebra 4.2 2013-08-28 16:33 - 2013-08-28 16:30 - 00000000 ____D C:\ProgramData\HitmanPro 2013-08-27 16:03 - 2013-08-21 22:44 - 00000000 ____D C:\Program Files\SpeedFan 2013-08-27 16:02 - 2013-07-20 16:26 - 00000000 ____D C:\Program Files\NirSoft 2013-08-27 16:01 - 2013-08-27 15:49 - 00000193 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2013-08-27 16:01 - 2013-08-27 15:45 - 00000000 ____D C:\ProgramData\Soluto 2013-08-26 14:56 - 2013-08-26 14:56 - 00000000 ____D C:\Program Files\CPUID 2013-08-21 22:44 - 2013-08-21 22:44 - 00000045 _____ C:\windows\system32\initdebug.nfo Files to move or delete: ==================== C:\Users\power\cs16full_v7 (2).exe Some content of TEMP: ==================== C:\Users\power\AppData\Local\Temp\i4jdel0.exe C:\Users\power\AppData\Local\Temp\Quarantine.exe C:\Users\power\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-03 14:57 ==================== End Of Log ============================ |
20.09.2013, 10:30 | #14 |
/// the machine /// TB-Ausbilder | Malwarebytes 34 Funde Normal ? Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.09.2013, 12:45 | #15 |
| Malwarebytes 34 Funde Normal ? Ich hatte Combofix schon gelöscht und wenn ich Windows Taste und R eingebe und da deinstallieren will, sagt Windows das Combofix nicht gefunden werden konnte |