|
Log-Analyse und Auswertung: Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiteremWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.09.2013, 13:44 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Ein frisches FRST Log bitte. FRST vorher neu runterladen. Alte FRST.exe löschen
__________________ Logfiles bitte immer in CODE-Tags posten |
30.09.2013, 14:14 | #17 |
| Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01 Ran by ***** (administrator) on *****-PC on 30-09-2013 15:04:41 Running from C:\Users\*****\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ABBYY) C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Malwarebytes Corporation) C:\Users\*****\Desktop\Anti-Vius\Malware Anti-Malware\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Secunia) C:\Program Files\Secunia\PSI\PSIA.exe (Softwareentwicklung Remus - ArchiCrypt) C:\Windows\system32\STGRAMDiskHandler32.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (The Eraser Project) C:\Program Files\Eraser\Eraser.exe (Steganos Software GmbH) C:\Program Files\Steganos Privacy Suite 12\SteganosHotKeyService.exe () C:\Program Files\TV IR\shutTask.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Steganos Software GmbH) C:\Program Files\Steganos Privacy Suite 12\SteganosBrowserMonitor.exe (Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe () C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe () C:\Program Files\TV IR\TV IR.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Farbar) C:\Users\*****\Desktop\FRST(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [LifeCam] - C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM\...\Run: [Eraser] - C:\PROGRA~1\Eraser\Eraser.exe [980368 2010-11-04] (The Eraser Project) HKLM\...\Run: [SSS12 HotKeys] - C:\Program Files\Steganos Privacy Suite 12\SteganosHotKeyService.exe [84480 2011-09-30] (Steganos Software GmbH) HKLM\...\Run: [UpdatePDRShortCut] - C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [TVPro Control] - C:\Program Files\TV IR\TV IR.EXE [997376 2012-04-26] () HKLM\...\Run: [TVPro Task] - C:\Program Files\TV IR\shutTask.exe [177664 2012-04-16] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated) HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [TkBellExe] - c:\program files\real\realplayer\Update\realsched.exe [295512 2013-06-20] (RealNetworks, Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-24] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [SSS12 Browser Monitor] - C:\Program Files\Steganos Privacy Suite 12\SteganosBrowserMonitor.exe [57344 2011-09-30] (Steganos Software GmbH) HKCU\...\Run: [Sony PC Companion] - C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449248 2013-05-29] (Sony) HKCU\...\Run: [ABBYY Screenshot Reader Retail] - [x] HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] () HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/webhp?hl=de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files\Steganos Privacy Suite 12\SPMIEToolbar.dll (Steganos Software GmbH) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files\Steganos Privacy Suite 12\SPMIEToolbar.dll (Steganos Software GmbH) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\5loqou7y.default FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Windows\system32\C2MP\npdivx32.dll (DivX,Inc.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\5loqou7y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\5loqou7y.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Anti-Banner - C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 FF Extension: Modul zur Link-Untersuchung - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF HKLM\...\Firefox\Extensions: [{09F060FA-566D-42D7-BF79-97AB30863433}] - C:\Program Files\Steganos Privacy Suite 12\pfplugin FF Extension: Steganos Private Favorites - C:\Program Files\Steganos Privacy Suite 12\pfplugin FF HKLM\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files\Steganos Privacy Suite 12\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files\Steganos Privacy Suite 12\spmplugin3 FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Extension: (Docs) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (RealDownloader) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0 CHR Extension: (Skype Click to Call) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0 CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx ========================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-24] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-09-12] (APN LLC.) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1155072 2009-02-03] (MAGIX AG) S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) R2 MBAMScheduler; C:\Users\*****\Desktop\Anti-Vius\Malware Anti-Malware\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Users\*****\Desktop\Anti-Vius\Malware Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () S4 RemoteAccess; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [247152 2008-12-31] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 Steganos Volatile Disk; C:\Windows\system32\STGRAMDiskHandler32.exe [349184 2011-09-12] (Softwareentwicklung Remus - ArchiCrypt) S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2010-08-06] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1021256 2009-10-30] (TuneUp Software) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-02-26] (Ulead Systems, Inc.) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] () ==================== Drivers (Whitelisted) ==================== S3 AF9035HB; C:\Windows\System32\Drivers\AF9035HB.sys [864384 2011-10-31] (ITE Technologies ) R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11832 2009-07-07] (Advanced Micro Devices Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-09-24] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 mod7700; C:\Windows\System32\DRIVERS\dvb7700all.sys [565440 2009-11-02] (DiBcom) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) R1 SLEE_17_DRIVER; C:\Windows\system32\drivers\Sleen17.sys [94560 2011-09-12] (Softwareentwicklung Remus - ArchiCrypt - ) R3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-24] (Avira GmbH) R1 STGMFEngine32; C:\Windows\system32\drivers\STGMFEngine32.sys [16384 2011-09-12] (Softwareentwicklung Remus - ArchiCrypt.com) S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1579144 2010-06-07] (Syntek) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2009-10-14] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 Bulk1528; System32\Drivers\Bulk1528.sys [x] S2 Ca1528av; System32\Drivers\Ca1528av.sys [x] S3 catchme; \??\C:\Users\*****\AppData\Local\Temp\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-30 14:29 - 2013-09-30 14:28 - 01086873 _____ (Farbar) C:\Users\*****\Desktop\FRST(1).exe 2013-09-30 10:56 - 2013-09-30 10:56 - 98488992 _____ C:\Windows\system32\疠` 2013-09-26 16:31 - 2013-09-26 16:32 - 00000000 ____D C:\AdwCleaner 2013-09-26 16:28 - 2013-09-26 16:28 - 00001112 _____ C:\Users\*****\Desktop\Mozilla Firefox.lnk 2013-09-26 10:10 - 2013-09-26 10:30 - 97892804 _____ C:\Windows\system32\⽍헮] 2013-09-25 09:51 - 2013-09-25 09:51 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-09-24 12:44 - 2013-09-24 12:44 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI 2013-09-24 12:43 - 2013-09-24 12:43 - 00000000 ____D C:\Program Files\Secunia 2013-09-24 12:41 - 2013-09-24 12:43 - 00000000 ____D C:\Users\*****\Downloads\Neuer Ordner 2013-09-24 12:40 - 2013-09-24 12:40 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-09-24 12:36 - 2013-09-24 12:36 - 00002020 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\ProgramData\Avira 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\Program Files\Avira 2013-09-24 12:36 - 2013-09-24 12:33 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-24 12:36 - 2013-09-24 12:33 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-24 12:36 - 2013-09-24 12:33 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-24 12:36 - 2013-09-24 12:33 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-09-24 12:11 - 2013-09-24 12:11 - 00016566 _____ C:\ComboFix.txt 2013-09-24 11:28 - 2013-09-24 12:11 - 00000000 ____D C:\ComboFix 2013-09-24 11:06 - 2013-09-24 11:24 - 00000000 _____ C:\Users\*****\defogger_reenable 2013-09-24 10:58 - 2013-09-24 16:00 - 00102062 _____ C:\Windows\PFRO.log 2013-09-24 10:46 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-24 10:46 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-24 10:46 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-24 10:45 - 2013-09-24 12:11 - 00000000 ____D C:\Qoobox 2013-09-24 10:19 - 2013-09-24 12:10 - 00000000 ____D C:\Windows\erdnt 2013-09-24 10:14 - 2013-09-24 10:14 - 98852061 _____ C:\Windows\system32\߹�d 2013-09-19 12:46 - 2013-09-19 12:46 - 00008256 _____ C:\Windows\DPINST.LOG 2013-09-18 16:49 - 2013-09-18 16:49 - 00000000 ____D C:\FRST 2013-09-18 09:13 - 2013-09-30 10:55 - 00001400 _____ C:\Windows\setupact.log 2013-09-18 09:13 - 2013-09-18 09:13 - 00000000 _____ C:\Windows\setuperr.log 2013-09-17 15:05 - 2013-09-17 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-09-17 13:58 - 2013-09-17 13:59 - 2338848756 _____ C:\avenger.txt 2013-09-17 11:59 - 2013-09-17 11:59 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RemoveIT Pro v4 - SE 2013-09-17 11:50 - 2013-09-26 11:40 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-17 11:49 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-17 11:44 - 2013-09-26 17:14 - 00000000 ____D C:\Users\*****\Desktop\Anti-Vius 2013-09-12 17:44 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 17:44 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 17:44 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 17:44 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 17:44 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 17:44 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-12 10:24 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 10:24 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-12 10:24 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-12 10:24 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-12 10:24 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 10:24 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-12 10:24 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll ==================== One Month Modified Files and Folders ======= 2013-09-30 15:02 - 2010-11-12 12:02 - 00000300 _____ C:\Windows\Tasks\DMEPeriodicTask.job 2013-09-30 14:29 - 2010-08-06 18:37 - 00000000 ____D C:\Users\***** 2013-09-30 14:28 - 2013-09-30 14:29 - 01086873 _____ (Farbar) C:\Users\*****\Desktop\FRST(1).exe 2013-09-30 14:19 - 2010-01-26 16:21 - 01498552 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-30 14:16 - 2013-04-03 14:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-30 11:03 - 2009-07-14 06:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-30 11:03 - 2009-07-14 06:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-30 10:59 - 2012-11-15 11:21 - 01238746 _____ C:\Windows\WindowsUpdate.log 2013-09-30 10:56 - 2013-09-30 10:56 - 98488992 _____ C:\Windows\system32\疠` 2013-09-30 10:55 - 2013-09-18 09:13 - 00001400 _____ C:\Windows\setupact.log 2013-09-30 10:55 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-27 16:43 - 2011-04-14 13:04 - 00000000 ____D C:\Users\*****\AppData\Roaming\vlc 2013-09-26 17:14 - 2013-09-17 11:44 - 00000000 ____D C:\Users\*****\Desktop\Anti-Vius 2013-09-26 16:32 - 2013-09-26 16:31 - 00000000 ____D C:\AdwCleaner 2013-09-26 16:28 - 2013-09-26 16:28 - 00001112 _____ C:\Users\*****\Desktop\Mozilla Firefox.lnk 2013-09-26 11:40 - 2013-09-17 11:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-26 10:30 - 2013-09-26 10:10 - 97892804 _____ C:\Windows\system32\⽍헮] 2013-09-25 09:51 - 2013-09-25 09:51 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-09-24 16:00 - 2013-09-24 10:58 - 00102062 _____ C:\Windows\PFRO.log 2013-09-24 12:44 - 2013-09-24 12:44 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI 2013-09-24 12:43 - 2013-09-24 12:43 - 00000000 ____D C:\Program Files\Secunia 2013-09-24 12:43 - 2013-09-24 12:41 - 00000000 ____D C:\Users\*****\Downloads\Neuer Ordner 2013-09-24 12:40 - 2013-09-24 12:40 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-09-24 12:36 - 2013-09-24 12:36 - 00002020 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\ProgramData\Avira 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\Program Files\Avira 2013-09-24 12:33 - 2013-09-24 12:36 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-24 12:33 - 2013-09-24 12:36 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-24 12:33 - 2013-09-24 12:36 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-24 12:33 - 2013-09-24 12:36 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-09-24 12:11 - 2013-09-24 12:11 - 00016566 _____ C:\ComboFix.txt 2013-09-24 12:11 - 2013-09-24 11:28 - 00000000 ____D C:\ComboFix 2013-09-24 12:11 - 2013-09-24 10:45 - 00000000 ____D C:\Qoobox 2013-09-24 12:10 - 2013-09-24 10:19 - 00000000 ____D C:\Windows\erdnt 2013-09-24 12:09 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2013-09-24 11:28 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-24 11:24 - 2013-09-24 11:06 - 00000000 _____ C:\Users\*****\defogger_reenable 2013-09-24 10:14 - 2013-09-24 10:14 - 98852061 _____ C:\Windows\system32\߹�d 2013-09-23 14:31 - 2011-03-19 17:56 - 00000000 ____D C:\Users\*****\dwhelper 2013-09-23 09:58 - 2011-05-31 14:52 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-20 10:16 - 2013-04-03 14:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-20 10:16 - 2013-04-03 14:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-19 15:47 - 2010-09-13 14:03 - 00000000 ____D C:\Users\*****\AppData\Roaming\Skype 2013-09-19 12:46 - 2013-09-19 12:46 - 00008256 _____ C:\Windows\DPINST.LOG 2013-09-19 12:46 - 2012-10-01 14:26 - 00001976 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-09-19 12:46 - 2010-01-29 11:53 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-09-18 17:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-09-18 16:49 - 2013-09-18 16:49 - 00000000 ____D C:\FRST 2013-09-18 09:13 - 2013-09-18 09:13 - 00000000 _____ C:\Windows\setuperr.log 2013-09-18 09:13 - 2011-03-24 16:17 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-18 09:13 - 2011-03-24 16:17 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-17 15:11 - 2010-01-27 01:09 - 00000000 ____D C:\Windows\Panther 2013-09-17 15:07 - 2011-04-11 10:38 - 00000000 ____D C:\Program Files\CCleaner 2013-09-17 15:05 - 2013-09-17 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-09-17 13:59 - 2013-09-17 13:58 - 2338848756 _____ C:\avenger.txt 2013-09-17 13:56 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Globalization 2013-09-17 11:59 - 2013-09-17 11:59 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RemoveIT Pro v4 - SE 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 10:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-09-13 10:10 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-13 10:03 - 2009-07-14 06:33 - 00542784 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-13 09:59 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-12 17:47 - 2009-07-14 04:04 - 00000777 _____ C:\Windows\win.ini 2013-09-12 17:42 - 2013-08-19 19:57 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 17:40 - 2010-01-26 16:42 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 15:12 - 2011-03-24 16:17 - 00000000 ____D C:\Users\*****\AppData\Local\Google 2013-09-11 15:12 - 2011-03-24 16:17 - 00000000 ____D C:\Program Files\Google Some content of TEMP: ==================== C:\Users\*****\AppData\Local\Temp\catchme.dll C:\Users\*****\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender LastRegBack: 2013-09-23 10:22 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-09-2013 01 Ran by ***** at 2013-09-30 15:05:22 Running from C:\Users\*****\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 1-abc.net File Encrypter (Remove only) 32 Bit HP CIO Components Installer (Version: 7.1.8) ABBYY Screenshot Reader (Version: 9.010.483.59810) Adobe Flash Player 11 ActiveX (Version: 11.8.800.175) Adobe Flash Player 11 Plugin (Version: 11.8.800.168) Adobe Reader X (10.1.0) - Deutsch (Version: 10.1.0) Adobe Shockwave Player 11.5 (Version: 11.5.6.606) AMD USB Filter Driver (Version: 1.0.15.94) ArcSoft TotalMedia 3.5 (Version: 3.5.7.377) ATI Catalyst Install Manager (Version: 3.0.769.0) Avira Free Antivirus (Version: 13.0.0.4052) Avira SearchFree Toolbar (Version: 12.4.0.1130) B109a-m (Version: 130.0.396.000) Bing Bar (Version: 7.0.791.0) Brother MFL-Pro Suite MFC-J5910DW (Version: 1.0.5.0) BufferChm (Version: 130.0.331.000) Catalyst Control Center Core Implementation (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Full Existing (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Full New (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Light (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Previews Vista (Version: 2010.0406.2133.36843) Catalyst Control Center InstallProxy (Version: 2010.0406.2133.36843) Catalyst Control Center Localization All (Version: 2010.0406.2133.36843) CCC Help Danish (Version: 2010.0406.2132.36843) CCC Help Dutch (Version: 2010.0406.2132.36843) CCC Help English (Version: 2010.0406.2132.36843) CCC Help Finnish (Version: 2010.0406.2132.36843) CCC Help French (Version: 2010.0406.2132.36843) CCC Help German (Version: 2010.0406.2132.36843) CCC Help Italian (Version: 2010.0406.2132.36843) CCC Help Japanese (Version: 2010.0406.2132.36843) CCC Help Norwegian (Version: 2010.0406.2132.36843) CCC Help Spanish (Version: 2010.0406.2132.36843) CCC Help Swedish (Version: 2010.0406.2132.36843) ccc-core-static (Version: 2010.0406.2133.36843) ccc-utility (Version: 2010.0406.2133.36843) CCleaner (Version: 4.05) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) COMPUTERBILD Alles-Öffner (Version: 1.0.8) COMPUTERBILD App-Center (Version: 1.1.11) Corel WordPerfect Suite 8 CorelDRAW Essentials 4 - Content (Version: 4.0) CorelDRAW Essentials 4 - Draw (Version: 4.0) CorelDRAW Essentials 4 - Extra Content CorelDRAW Essentials 4 - Extra Content (Version: 4.0) CorelDRAW Essentials 4 - Filters (Version: 4.0) CorelDRAW Essentials 4 - ICA (Version: 4.0) CorelDRAW Essentials 4 - IPM - No VBA (Version: 4.0) CorelDRAW Essentials 4 - Lang BR (Version: 4.0) CorelDRAW Essentials 4 - Lang DE (Version: 4.0) CorelDRAW Essentials 4 - Lang EN (Version: 4.0) CorelDRAW Essentials 4 - Lang ES (Version: 4.0) CorelDRAW Essentials 4 - Lang FR (Version: 4.0) CorelDRAW Essentials 4 - Lang IT (Version: 4.0) CorelDRAW Essentials 4 - Lang NL (Version: 4.0) CorelDRAW Essentials 4 - PHOTO-PAINT (Version: 4.0) CorelDRAW Essentials 4 (Version: 4.0) CyberLink PhotoDirector 3 (Version: 3.0.3618) CyberLink PhotoNow (Version: 1.1.6904) CyberLink PowerDirector (Version: 7.0.4020) Destinations (Version: 140.0.77.000) DeviceDiscovery (Version: 130.0.372.000) DHTML Editing Component (Version: 6.02.0001) Eraser 6.0.8.2273 (Version: 6.0.2273) FILEminimizer Pictures Firebird SQL Server - MAGIX Edition (Version: 2.1.23.0) Formatwandler 2013 (Version: 5.0.12.625) Free Video Flip and Rotate version 2.1.7.422 (Version: 2.1.7.422) Google Chrome (Version: 29.0.1547.76) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4413.1752) GPBaseService2 (Version: 130.0.371.000) holz multimedia HP Customer Participation Program 13.0 (Version: 13.0) HP Imaging Device Functions 13.0 (Version: 13.0) HP Photosmart B109a-m All-In-One Driver Software 13.0 Rel .6 (Version: 13.0) HP Print Projects 1.0 (Version: 1.0) HP Smart Web Printing 4.5 (Version: 4.5) HP Solution Center 13.0 (Version: 13.0) HP Update (Version: 5.003.001.001) HPDiagnosticAlert (Version: 1.00.0000) HPPhotoGadget (Version: 130.0.282.000) hpPrintProjects (Version: 130.0.303.000) HPProductAssistant (Version: 130.0.371.000) HPSSupply (Version: 130.0.371.000) hpWLPGInstaller (Version: 130.0.303.000) Indeo® software Java 7 Update 9 (Version: 7.0.90) Java Auto Updater (Version: 2.1.9.0) Java(TM) 6 Update 20 (Version: 6.0.200) Junk Mail filter update (Version: 14.0.8089.726) K-Lite Codec Pack 7.0.0 (Standard) (Version: 7.0.0) Lidl-Fotos Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) MarketResearch (Version: 130.0.374.000) MD86351 driver install (Version: 6.3.6.1) Media Go (Version: 2.2.223) Media Go Video Playback Engine 1.92.162.06140 (Version: 1.92.162.06140) Mein CeWe Fotobuch Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Choice Guard (Version: 2.0.48.0) Microsoft Corporation (Version: 9.1.0.0) Microsoft LifeCam (Version: 3.60.253.0) Microsoft Office Excel Viewer (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual J# 2.0 Redistributable Package - SE Microsoft Visual J# 2.0 Redistributable Package - SE (Version: 2.0.50728) Microsoft Works (Version: 9.7.0621) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0) Open Freely (Version: 1.0) PhotoFilmStrip 1.5.0 (Version: 1.5.0) PlayReady PC Runtime x86 (Version: 1.3.0) PlayStation(R)Network Downloader (Version: 2.07.00849) PlayStation(R)Store (Version: 4.9.4.14625) PS_AIO_06_B109a-m_SW_Min (Version: 130.0.396.000) RealDownloader (Version: 1.3.2) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0) RealPlayer (Version: 16.0.2) Realtek High Definition Audio Driver (Version: 6.0.1.6083) RealUpgrade 1.1 (Version: 1.1.0) RemoveIT Pro v4 - SE (Version: 4.0) Scan (Version: 140.0.80.000) schrankplaner (Version: 3.600) Scrabble3D (Version: 3.1.0.23) Secunia PSI (3.0.0.7011) (Version: 3.0.0.7011) Shop for HP Supplies (Version: 13.0) Skype Click to Call (Version: 5.9.9216) Skype™ 6.6 (Version: 6.6.106) SmartWebPrinting (Version: 130.0.373.000) SolutionCenter (Version: 130.0.373.000) Sony Ericsson Update Engine (Version: 2.13.7.201306141231) Sony PC Companion 2.10.174 (Version: 2.10.174) SPCA1528 PC Driver (Version: 2.2.4.0) Status (Version: 130.0.373.000) Steganos Privacy Suite 12 (Version: 12.1.1) supra DateSet (Version: 1.0.1.0) TeamViewer 6 (Version: 6.0.10462) Telekom Fotoservice T-Online 6.0 T-Online WLAN-Access Finder Toolbox (Version: 130.0.648.000) TrayApp (Version: 130.0.376.000) TrueCrypt (Version: 7.0a) TuneUp Utilities (Version: 9.0.2000.15) TuneUp Utilities Language Pack (de-DE) (Version: 9.0.2000.15) TV IR (Version: 2.4) Ulead VideoStudio 8.0 SE DVD (Version: 8.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) USB2.0 Grabber (Version: 7.12.000.003) VLC media player 2.0.0 (Version: 2.0.0) WarrantyExtension (Version: 1.00.0000) WebReg (Version: 130.0.132.017) Windows 7 Codec Pack 2.1.0 Windows Live Call (Version: 14.0.8064.0206) Windows Live Communications Platform (Version: 14.0.8064.206) Windows Live Essentials (Version: 14.0.8089.0726) Windows Live Essentials (Version: 14.0.8089.726) Windows Live Fotogalerie (Version: 14.0.8081.709) Windows Live ID-Anmelde-Assistent (Version: 6.500.3146.0) Windows Live Mail (Version: 14.0.8089.0726) Windows Live Messenger (Version: 14.0.8089.0726) Windows Live Movie Maker (Version: 14.0.8091.0730) Windows Live Sync (Version: 14.0.8089.726) Windows Live Writer (Version: 14.0.8089.0726) Windows Live-Uploadtool (Version: 14.0.8014.1029) WinRAR Würth Beschläge Yahoo! Toolbar ==================== Restore Points ========================= 30-08-2013 11:21:52 Windows Update 03-09-2013 06:48:24 Windows Update 07-09-2013 12:00:49 Windows Update 12-09-2013 15:40:24 Windows Update 13-09-2013 15:14:32 Windows Update 16-09-2013 13:56:34 Windows Update 17-09-2013 14:36:44 Windows Update 24-09-2013 09:28:40 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-09-24 12:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0012CE96-EEBB-4821-9692-39FD4E7A2D64} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.) Task: {0C71FC86-3D3C-413E-BD8F-25A533514013} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2009-10-30] (TuneUp Software) Task: {0DE89BB0-96CC-420B-8414-7FBF63634194} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {10DB8BC8-7DED-4702-A34F-3E05A288400F} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] () Task: {17CCFE8D-F573-44A2-9331-691F26B13217} - System32\Tasks\{66DAFD33-919A-4CE0-B1A6-E4F14D4164EE} => C:\Program Files\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {281A2F59-5DC4-4EDE-A414-A6BE14A44DE3} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2010-04-29] (Microsoft Corporation) Task: {2D68E398-EC50-4F8A-8292-73C5E7F66848} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {52EC0488-CFF0-44F4-90D0-CA612FD8C263} - System32\Tasks\Real Networks Scheduler => c:\program files\real\realplayer\Update\realsched.exe [2013-06-20] (RealNetworks, Inc.) Task: {62D3BF4F-EF2B-498B-B2C3-F2B212A660D3} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {887EA725-532E-4247-A9A7-F209423570FF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-20] (Adobe Systems Incorporated) Task: {94053A4A-9081-4442-BF0D-55DED861C3EE} - System32\Tasks\Automatische Problemsuche => C:\Program Files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-10-30] (TuneUp Software) Task: {A52308D2-7CA0-4317-8A79-CE367F1F931A} - System32\Tasks\ArcSoft Connect Daemon => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27] (ArcSoft Inc.) Task: {C3CC70A1-D607-4D8C-9E43-1A22BAD64C6F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-24] (Google Inc.) Task: {CB58A3D2-CACB-47AA-8465-578FA4FCD1F6} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {DFF04FC8-EFA6-4F0B-A371-A60DD9A2D597} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-24] (Google Inc.) Task: {E1AF2A4B-7F91-4798-8465-B6E35B20AF79} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {EA1BB7AE-24AB-4A99-81B3-FDC779C81C2F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd) Task: {F3C49398-5E6E-4525-9558-90D2CDAAFEFE} - System32\Tasks\DMEPeriodicTask => C:\Program Files\HP\Digital Imaging\bin\warrantyextension\HPPromo.exe [2009-06-16] (Hewlett-Packard) Task: {F63D9D82-EDEE-4877-B45C-21A39100F3FB} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DMEPeriodicTask.job => C:\Program Files\HP\Digital Imaging\bin\warrantyextension\HPPromo.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-09-12 15:29 - 2011-09-12 15:29 - 00187904 _____ () C:\Program Files\Steganos Privacy Suite 12\ShellExtension.dll 2010-08-06 19:09 - 2006-08-05 11:34 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll 2010-10-18 11:14 - 2009-08-20 01:19 - 00074984 _____ () C:\Program Files\FILEminimizer Pictures\FILEMShell.dll 2012-10-01 14:26 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files\Sony\Sony PC Companion\TMonitorAPI.dll 2012-10-01 14:26 - 2013-05-17 10:51 - 00207872 _____ () C:\Program Files\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files\Sony\Sony PC Companion\Report.dll 2012-07-17 10:56 - 2012-07-17 10:56 - 00587776 _____ () C:\Program Files\Sony\Sony PC Companion\PhoneUpdate.dll 2012-10-01 14:26 - 2010-01-11 16:44 - 00053248 _____ () C:\Program Files\Sony\Sony PC Companion\VObject.dll 2012-05-04 12:41 - 2007-04-19 10:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll 2009-07-13 23:03 - 2009-07-14 03:15 - 00364544 _____ () C:\Windows\system32\msjetoledb40.dll 2013-01-08 12:01 - 2012-04-15 01:47 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll 2013-01-08 12:01 - 2008-01-15 01:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll 2013-01-08 12:01 - 2009-03-09 12:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll 2013-08-19 19:02 - 2013-08-19 19:02 - 03551640 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/30/2013 11:05:58 AM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "J:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" System errors: ============= Error: (09/30/2013 11:26:31 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:30 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:30 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:29 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:08 AM) (Source: Ntfs) (User: ) Description: Auf dem Volume "Z:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (09/30/2013 10:55:53 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinDefend" wurde mit folgendem Fehler beendet: %%5 Error: (09/30/2013 10:55:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SPCA1528 Video Camera Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (09/27/2013 04:44:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst Steganos Volatile Disk konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (09/27/2013 00:07:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinDefend" wurde mit folgendem Fehler beendet: %%5 Error: (09/27/2013 00:07:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SPCA1528 Video Camera Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (09/30/2013 11:05:58 AM) (Source: Windows Backup)(User: ) Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3326.3 MB Available physical RAM: 1837.95 MB Total Pagefile: 6650.9 MB Available Pagefile: 4891.83 MB Total Virtual: 2047.88 MB Available Virtual: 1913.79 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:792.32 GB) NTFS Drive d: (Recover) (Fixed) (Total:20 GB) (Free:11.66 GB) NTFS Drive f: () (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT Drive m: (HDDRIVE2GO) (Fixed) (Total:931.28 GB) (Free:865.6 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=910 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ======================================================== Disk: 4 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: DA97DC12) Partition 1: (Active) - (Size=2 GB) - (Type=06) ======================================================== Disk: 8 (Size: 932 GB) (Disk ID: 20441D24) Partition 1: (Not Active) - (Size=932 GB) - (Type=0C) ==================== End Of Log ============================ |
30.09.2013, 14:20 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter DeleteJunctionsIndirectory: C:\Program Files\Windows Defender Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ |
30.09.2013, 14:56 | #19 |
| Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiteremCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-09-2013 01 Ran by ***** at 2013-09-30 15:45:26 Run:2 Running from C:\Users\*****\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** DeleteJunctionsIndirectory: C:\Program Files\Windows Defender ***************** "C:\Program Files\Windows Defender" => Deleting reparse point and unlocking started. "C:\Program Files\Windows Defender\de-DE" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpAsDesc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpClient.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpCmdRun.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpCommu.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpEvMsg.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpOAV.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpRTP.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpSvc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MSASCui.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpCom.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpLics.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender" => Deleting reparse point and unlocking completed. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01 Ran by ***** (administrator) on *****-PC on 30-09-2013 15:45:46 Running from C:\Users\*****\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ABBYY) C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Malwarebytes Corporation) C:\Users\*****\Desktop\Anti-Vius\Malware Anti-Malware\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Secunia) C:\Program Files\Secunia\PSI\PSIA.exe (Softwareentwicklung Remus - ArchiCrypt) C:\Windows\system32\STGRAMDiskHandler32.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (The Eraser Project) C:\Program Files\Eraser\Eraser.exe (Steganos Software GmbH) C:\Program Files\Steganos Privacy Suite 12\SteganosHotKeyService.exe () C:\Program Files\TV IR\shutTask.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Steganos Software GmbH) C:\Program Files\Steganos Privacy Suite 12\SteganosBrowserMonitor.exe (Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe () C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe () C:\Program Files\TV IR\TV IR.exe (Microsoft Corporation) C:\PROGRA~1\MIF5BA~1\OFFICE11\WINWORD.EXE (Farbar) C:\Users\*****\Desktop\FRST(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [LifeCam] - C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM\...\Run: [Eraser] - C:\PROGRA~1\Eraser\Eraser.exe [980368 2010-11-04] (The Eraser Project) HKLM\...\Run: [SSS12 HotKeys] - C:\Program Files\Steganos Privacy Suite 12\SteganosHotKeyService.exe [84480 2011-09-30] (Steganos Software GmbH) HKLM\...\Run: [UpdatePDRShortCut] - C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [TVPro Control] - C:\Program Files\TV IR\TV IR.EXE [997376 2012-04-26] () HKLM\...\Run: [TVPro Task] - C:\Program Files\TV IR\shutTask.exe [177664 2012-04-16] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated) HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM\...\Run: [TkBellExe] - c:\program files\real\realplayer\Update\realsched.exe [295512 2013-06-20] (RealNetworks, Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-24] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [SSS12 Browser Monitor] - C:\Program Files\Steganos Privacy Suite 12\SteganosBrowserMonitor.exe [57344 2011-09-30] (Steganos Software GmbH) HKCU\...\Run: [Sony PC Companion] - C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449248 2013-05-29] (Sony) HKCU\...\Run: [ABBYY Screenshot Reader Retail] - [x] HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [ 2009-11-12] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/webhp?hl=de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files\Steganos Privacy Suite 12\SPMIEToolbar.dll (Steganos Software GmbH) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files\Steganos Privacy Suite 12\SPMIEToolbar.dll (Steganos Software GmbH) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\5loqou7y.default FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Windows\system32\C2MP\npdivx32.dll (DivX,Inc.) FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\5loqou7y.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\5loqou7y.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Anti-Banner - C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 FF Extension: Modul zur Link-Untersuchung - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF HKLM\...\Firefox\Extensions: [{09F060FA-566D-42D7-BF79-97AB30863433}] - C:\Program Files\Steganos Privacy Suite 12\pfplugin FF Extension: Steganos Private Favorites - C:\Program Files\Steganos Privacy Suite 12\pfplugin FF HKLM\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files\Steganos Privacy Suite 12\spmplugin3 FF Extension: Steganos Password Manager - C:\Program Files\Steganos Privacy Suite 12\spmplugin3 FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Extension: (Docs) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (RealDownloader) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0 CHR Extension: (Skype Click to Call) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0 CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx ========================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-24] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-24] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-09-12] (APN LLC.) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1155072 2009-02-03] (MAGIX AG) S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) R2 MBAMScheduler; C:\Users\*****\Desktop\Anti-Vius\Malware Anti-Malware\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Users\*****\Desktop\Anti-Vius\Malware Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () S4 RemoteAccess; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [247152 2008-12-31] () R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 Steganos Volatile Disk; C:\Windows\system32\STGRAMDiskHandler32.exe [349184 2011-09-12] (Softwareentwicklung Remus - ArchiCrypt) S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2010-08-06] (TuneUp Software) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1021256 2009-10-30] (TuneUp Software) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-02-26] (Ulead Systems, Inc.) ==================== Drivers (Whitelisted) ==================== S3 AF9035HB; C:\Windows\System32\Drivers\AF9035HB.sys [864384 2011-10-31] (ITE Technologies ) R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11832 2009-07-07] (Advanced Micro Devices Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-09-24] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 mod7700; C:\Windows\System32\DRIVERS\dvb7700all.sys [565440 2009-11-02] (DiBcom) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) R1 SLEE_17_DRIVER; C:\Windows\system32\drivers\Sleen17.sys [94560 2011-09-12] (Softwareentwicklung Remus - ArchiCrypt - ) R3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-24] (Avira GmbH) R1 STGMFEngine32; C:\Windows\system32\drivers\STGMFEngine32.sys [16384 2011-09-12] (Softwareentwicklung Remus - ArchiCrypt.com) S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1579144 2010-06-07] (Syntek) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2009-10-14] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 Bulk1528; System32\Drivers\Bulk1528.sys [x] S2 Ca1528av; System32\Drivers\Ca1528av.sys [x] S3 catchme; \??\C:\Users\*****\AppData\Local\Temp\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-30 14:29 - 2013-09-30 14:28 - 01086873 _____ (Farbar) C:\Users\*****\Desktop\FRST(1).exe 2013-09-30 10:56 - 2013-09-30 10:56 - 98488992 _____ C:\Windows\system32\疠` 2013-09-26 16:31 - 2013-09-26 16:32 - 00000000 ____D C:\AdwCleaner 2013-09-26 16:28 - 2013-09-26 16:28 - 00001112 _____ C:\Users\*****\Desktop\Mozilla Firefox.lnk 2013-09-26 10:10 - 2013-09-26 10:30 - 97892804 _____ C:\Windows\system32\⽍헮] 2013-09-25 09:51 - 2013-09-25 09:51 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-09-24 12:44 - 2013-09-24 12:44 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI 2013-09-24 12:43 - 2013-09-24 12:43 - 00000000 ____D C:\Program Files\Secunia 2013-09-24 12:41 - 2013-09-24 12:43 - 00000000 ____D C:\Users\*****\Downloads\Neuer Ordner 2013-09-24 12:40 - 2013-09-24 12:40 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-09-24 12:36 - 2013-09-24 12:36 - 00002020 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\ProgramData\Avira 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\Program Files\Avira 2013-09-24 12:36 - 2013-09-24 12:33 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-24 12:36 - 2013-09-24 12:33 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-24 12:36 - 2013-09-24 12:33 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-24 12:36 - 2013-09-24 12:33 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-09-24 12:11 - 2013-09-24 12:11 - 00016566 _____ C:\ComboFix.txt 2013-09-24 11:28 - 2013-09-24 12:11 - 00000000 ____D C:\ComboFix 2013-09-24 11:06 - 2013-09-24 11:24 - 00000000 _____ C:\Users\*****\defogger_reenable 2013-09-24 10:58 - 2013-09-24 16:00 - 00102062 _____ C:\Windows\PFRO.log 2013-09-24 10:46 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-24 10:46 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-24 10:46 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-24 10:46 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-24 10:45 - 2013-09-24 12:11 - 00000000 ____D C:\Qoobox 2013-09-24 10:19 - 2013-09-24 12:10 - 00000000 ____D C:\Windows\erdnt 2013-09-24 10:14 - 2013-09-24 10:14 - 98852061 _____ C:\Windows\system32\߹�d 2013-09-19 12:46 - 2013-09-19 12:46 - 00008256 _____ C:\Windows\DPINST.LOG 2013-09-18 16:49 - 2013-09-18 16:49 - 00000000 ____D C:\FRST 2013-09-18 09:13 - 2013-09-30 10:55 - 00001400 _____ C:\Windows\setupact.log 2013-09-18 09:13 - 2013-09-18 09:13 - 00000000 _____ C:\Windows\setuperr.log 2013-09-17 15:05 - 2013-09-17 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-09-17 13:58 - 2013-09-17 13:59 - 2338848756 _____ C:\avenger.txt 2013-09-17 11:59 - 2013-09-17 11:59 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RemoveIT Pro v4 - SE 2013-09-17 11:50 - 2013-09-26 11:40 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-17 11:49 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-17 11:44 - 2013-09-26 17:14 - 00000000 ____D C:\Users\*****\Desktop\Anti-Vius 2013-09-12 17:44 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 17:44 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 17:44 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 17:44 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 17:44 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 17:44 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 17:44 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-12 10:24 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 10:24 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-12 10:24 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-12 10:24 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-12 10:24 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-12 10:24 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 10:24 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-12 10:24 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll ==================== One Month Modified Files and Folders ======= 2013-09-30 15:16 - 2013-04-03 14:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-30 15:02 - 2010-11-12 12:02 - 00000300 _____ C:\Windows\Tasks\DMEPeriodicTask.job 2013-09-30 14:29 - 2010-08-06 18:37 - 00000000 ____D C:\Users\***** 2013-09-30 14:28 - 2013-09-30 14:29 - 01086873 _____ (Farbar) C:\Users\*****\Desktop\FRST(1).exe 2013-09-30 14:19 - 2010-01-26 16:21 - 01498552 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-30 11:03 - 2009-07-14 06:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-30 11:03 - 2009-07-14 06:34 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-30 10:59 - 2012-11-15 11:21 - 01238746 _____ C:\Windows\WindowsUpdate.log 2013-09-30 10:56 - 2013-09-30 10:56 - 98488992 _____ C:\Windows\system32\疠` 2013-09-30 10:55 - 2013-09-18 09:13 - 00001400 _____ C:\Windows\setupact.log 2013-09-30 10:55 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-27 16:43 - 2011-04-14 13:04 - 00000000 ____D C:\Users\*****\AppData\Roaming\vlc 2013-09-26 17:14 - 2013-09-17 11:44 - 00000000 ____D C:\Users\*****\Desktop\Anti-Vius 2013-09-26 16:32 - 2013-09-26 16:31 - 00000000 ____D C:\AdwCleaner 2013-09-26 16:28 - 2013-09-26 16:28 - 00001112 _____ C:\Users\*****\Desktop\Mozilla Firefox.lnk 2013-09-26 11:40 - 2013-09-17 11:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-26 10:30 - 2013-09-26 10:10 - 97892804 _____ C:\Windows\system32\⽍헮] 2013-09-25 09:51 - 2013-09-25 09:51 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-09-24 16:00 - 2013-09-24 10:58 - 00102062 _____ C:\Windows\PFRO.log 2013-09-24 12:44 - 2013-09-24 12:44 - 00000000 ____D C:\Users\*****\AppData\Local\Secunia PSI 2013-09-24 12:43 - 2013-09-24 12:43 - 00000000 ____D C:\Program Files\Secunia 2013-09-24 12:43 - 2013-09-24 12:41 - 00000000 ____D C:\Users\*****\Downloads\Neuer Ordner 2013-09-24 12:40 - 2013-09-24 12:40 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-09-24 12:37 - 2013-09-24 12:37 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-09-24 12:36 - 2013-09-24 12:36 - 00002020 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\ProgramData\Avira 2013-09-24 12:36 - 2013-09-24 12:36 - 00000000 ____D C:\Program Files\Avira 2013-09-24 12:33 - 2013-09-24 12:36 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-24 12:33 - 2013-09-24 12:36 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-24 12:33 - 2013-09-24 12:36 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-09-24 12:33 - 2013-09-24 12:36 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-09-24 12:11 - 2013-09-24 12:11 - 00016566 _____ C:\ComboFix.txt 2013-09-24 12:11 - 2013-09-24 11:28 - 00000000 ____D C:\ComboFix 2013-09-24 12:11 - 2013-09-24 10:45 - 00000000 ____D C:\Qoobox 2013-09-24 12:10 - 2013-09-24 10:19 - 00000000 ____D C:\Windows\erdnt 2013-09-24 12:09 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2013-09-24 11:28 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-24 11:24 - 2013-09-24 11:06 - 00000000 _____ C:\Users\*****\defogger_reenable 2013-09-24 10:14 - 2013-09-24 10:14 - 98852061 _____ C:\Windows\system32\߹�d 2013-09-23 14:31 - 2011-03-19 17:56 - 00000000 ____D C:\Users\*****\dwhelper 2013-09-23 09:58 - 2011-05-31 14:52 - 00002133 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-20 10:16 - 2013-04-03 14:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-20 10:16 - 2013-04-03 14:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-19 15:47 - 2010-09-13 14:03 - 00000000 ____D C:\Users\*****\AppData\Roaming\Skype 2013-09-19 12:46 - 2013-09-19 12:46 - 00008256 _____ C:\Windows\DPINST.LOG 2013-09-19 12:46 - 2012-10-01 14:26 - 00001976 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk 2013-09-19 12:46 - 2010-01-29 11:53 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-09-18 17:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-09-18 16:49 - 2013-09-18 16:49 - 00000000 ____D C:\FRST 2013-09-18 09:13 - 2013-09-18 09:13 - 00000000 _____ C:\Windows\setuperr.log 2013-09-18 09:13 - 2011-03-24 16:17 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-18 09:13 - 2011-03-24 16:17 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-17 15:11 - 2010-01-27 01:09 - 00000000 ____D C:\Windows\Panther 2013-09-17 15:07 - 2011-04-11 10:38 - 00000000 ____D C:\Program Files\CCleaner 2013-09-17 15:05 - 2013-09-17 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-09-17 13:59 - 2013-09-17 13:58 - 2338848756 _____ C:\avenger.txt 2013-09-17 13:56 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Globalization 2013-09-17 11:59 - 2013-09-17 11:59 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RemoveIT Pro v4 - SE 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-09-17 11:49 - 2013-09-17 11:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 10:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-09-13 10:10 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-13 10:03 - 2009-07-14 06:33 - 00542784 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-13 09:59 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-12 17:47 - 2009-07-14 04:04 - 00000777 _____ C:\Windows\win.ini 2013-09-12 17:42 - 2013-08-19 19:57 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 17:40 - 2010-01-26 16:42 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 15:12 - 2011-03-24 16:17 - 00000000 ____D C:\Users\*****\AppData\Local\Google 2013-09-11 15:12 - 2011-03-24 16:17 - 00000000 ____D C:\Program Files\Google Some content of TEMP: ==================== C:\Users\*****\AppData\Local\Temp\catchme.dll C:\Users\*****\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-23 10:22 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-09-2013 01 Ran by ***** at 2013-09-30 15:46:19 Running from C:\Users\*****\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 1-abc.net File Encrypter (Remove only) 32 Bit HP CIO Components Installer (Version: 7.1.8) ABBYY Screenshot Reader (Version: 9.010.483.59810) Adobe Flash Player 11 ActiveX (Version: 11.8.800.175) Adobe Flash Player 11 Plugin (Version: 11.8.800.168) Adobe Reader X (10.1.0) - Deutsch (Version: 10.1.0) Adobe Shockwave Player 11.5 (Version: 11.5.6.606) AMD USB Filter Driver (Version: 1.0.15.94) ArcSoft TotalMedia 3.5 (Version: 3.5.7.377) ATI Catalyst Install Manager (Version: 3.0.769.0) Avira Free Antivirus (Version: 13.0.0.4052) Avira SearchFree Toolbar (Version: 12.4.0.1130) B109a-m (Version: 130.0.396.000) Bing Bar (Version: 7.0.791.0) Brother MFL-Pro Suite MFC-J5910DW (Version: 1.0.5.0) BufferChm (Version: 130.0.331.000) Catalyst Control Center Core Implementation (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Full Existing (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Full New (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Light (Version: 2010.0406.2133.36843) Catalyst Control Center Graphics Previews Vista (Version: 2010.0406.2133.36843) Catalyst Control Center InstallProxy (Version: 2010.0406.2133.36843) Catalyst Control Center Localization All (Version: 2010.0406.2133.36843) CCC Help Danish (Version: 2010.0406.2132.36843) CCC Help Dutch (Version: 2010.0406.2132.36843) CCC Help English (Version: 2010.0406.2132.36843) CCC Help Finnish (Version: 2010.0406.2132.36843) CCC Help French (Version: 2010.0406.2132.36843) CCC Help German (Version: 2010.0406.2132.36843) CCC Help Italian (Version: 2010.0406.2132.36843) CCC Help Japanese (Version: 2010.0406.2132.36843) CCC Help Norwegian (Version: 2010.0406.2132.36843) CCC Help Spanish (Version: 2010.0406.2132.36843) CCC Help Swedish (Version: 2010.0406.2132.36843) ccc-core-static (Version: 2010.0406.2133.36843) ccc-utility (Version: 2010.0406.2133.36843) CCleaner (Version: 4.05) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) COMPUTERBILD Alles-Öffner (Version: 1.0.8) COMPUTERBILD App-Center (Version: 1.1.11) Corel WordPerfect Suite 8 CorelDRAW Essentials 4 - Content (Version: 4.0) CorelDRAW Essentials 4 - Draw (Version: 4.0) CorelDRAW Essentials 4 - Extra Content CorelDRAW Essentials 4 - Extra Content (Version: 4.0) CorelDRAW Essentials 4 - Filters (Version: 4.0) CorelDRAW Essentials 4 - ICA (Version: 4.0) CorelDRAW Essentials 4 - IPM - No VBA (Version: 4.0) CorelDRAW Essentials 4 - Lang BR (Version: 4.0) CorelDRAW Essentials 4 - Lang DE (Version: 4.0) CorelDRAW Essentials 4 - Lang EN (Version: 4.0) CorelDRAW Essentials 4 - Lang ES (Version: 4.0) CorelDRAW Essentials 4 - Lang FR (Version: 4.0) CorelDRAW Essentials 4 - Lang IT (Version: 4.0) CorelDRAW Essentials 4 - Lang NL (Version: 4.0) CorelDRAW Essentials 4 - PHOTO-PAINT (Version: 4.0) CorelDRAW Essentials 4 (Version: 4.0) CyberLink PhotoDirector 3 (Version: 3.0.3618) CyberLink PhotoNow (Version: 1.1.6904) CyberLink PowerDirector (Version: 7.0.4020) Destinations (Version: 140.0.77.000) DeviceDiscovery (Version: 130.0.372.000) DHTML Editing Component (Version: 6.02.0001) Eraser 6.0.8.2273 (Version: 6.0.2273) FILEminimizer Pictures Firebird SQL Server - MAGIX Edition (Version: 2.1.23.0) Formatwandler 2013 (Version: 5.0.12.625) Free Video Flip and Rotate version 2.1.7.422 (Version: 2.1.7.422) Google Chrome (Version: 29.0.1547.76) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4413.1752) GPBaseService2 (Version: 130.0.371.000) holz multimedia HP Customer Participation Program 13.0 (Version: 13.0) HP Imaging Device Functions 13.0 (Version: 13.0) HP Photosmart B109a-m All-In-One Driver Software 13.0 Rel .6 (Version: 13.0) HP Print Projects 1.0 (Version: 1.0) HP Smart Web Printing 4.5 (Version: 4.5) HP Solution Center 13.0 (Version: 13.0) HP Update (Version: 5.003.001.001) HPDiagnosticAlert (Version: 1.00.0000) HPPhotoGadget (Version: 130.0.282.000) hpPrintProjects (Version: 130.0.303.000) HPProductAssistant (Version: 130.0.371.000) HPSSupply (Version: 130.0.371.000) hpWLPGInstaller (Version: 130.0.303.000) Indeo® software Java 7 Update 9 (Version: 7.0.90) Java Auto Updater (Version: 2.1.9.0) Java(TM) 6 Update 20 (Version: 6.0.200) Junk Mail filter update (Version: 14.0.8089.726) K-Lite Codec Pack 7.0.0 (Standard) (Version: 7.0.0) Lidl-Fotos Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) MarketResearch (Version: 130.0.374.000) MD86351 driver install (Version: 6.3.6.1) Media Go (Version: 2.2.223) Media Go Video Playback Engine 1.92.162.06140 (Version: 1.92.162.06140) Mein CeWe Fotobuch Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Choice Guard (Version: 2.0.48.0) Microsoft Corporation (Version: 9.1.0.0) Microsoft LifeCam (Version: 3.60.253.0) Microsoft Office Excel Viewer (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual J# 2.0 Redistributable Package - SE Microsoft Visual J# 2.0 Redistributable Package - SE (Version: 2.0.50728) Microsoft Works (Version: 9.7.0621) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0) Open Freely (Version: 1.0) PhotoFilmStrip 1.5.0 (Version: 1.5.0) PlayReady PC Runtime x86 (Version: 1.3.0) PlayStation(R)Network Downloader (Version: 2.07.00849) PlayStation(R)Store (Version: 4.9.4.14625) PS_AIO_06_B109a-m_SW_Min (Version: 130.0.396.000) RealDownloader (Version: 1.3.2) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0) RealPlayer (Version: 16.0.2) Realtek High Definition Audio Driver (Version: 6.0.1.6083) RealUpgrade 1.1 (Version: 1.1.0) RemoveIT Pro v4 - SE (Version: 4.0) Scan (Version: 140.0.80.000) schrankplaner (Version: 3.600) Scrabble3D (Version: 3.1.0.23) Secunia PSI (3.0.0.7011) (Version: 3.0.0.7011) Shop for HP Supplies (Version: 13.0) Skype Click to Call (Version: 5.9.9216) Skype™ 6.6 (Version: 6.6.106) SmartWebPrinting (Version: 130.0.373.000) SolutionCenter (Version: 130.0.373.000) Sony Ericsson Update Engine (Version: 2.13.7.201306141231) Sony PC Companion 2.10.174 (Version: 2.10.174) SPCA1528 PC Driver (Version: 2.2.4.0) Status (Version: 130.0.373.000) Steganos Privacy Suite 12 (Version: 12.1.1) supra DateSet (Version: 1.0.1.0) TeamViewer 6 (Version: 6.0.10462) Telekom Fotoservice T-Online 6.0 T-Online WLAN-Access Finder Toolbox (Version: 130.0.648.000) TrayApp (Version: 130.0.376.000) TrueCrypt (Version: 7.0a) TuneUp Utilities (Version: 9.0.2000.15) TuneUp Utilities Language Pack (de-DE) (Version: 9.0.2000.15) TV IR (Version: 2.4) Ulead VideoStudio 8.0 SE DVD (Version: 8.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) USB2.0 Grabber (Version: 7.12.000.003) VLC media player 2.0.0 (Version: 2.0.0) WarrantyExtension (Version: 1.00.0000) WebReg (Version: 130.0.132.017) Windows 7 Codec Pack 2.1.0 Windows Live Call (Version: 14.0.8064.0206) Windows Live Communications Platform (Version: 14.0.8064.206) Windows Live Essentials (Version: 14.0.8089.0726) Windows Live Essentials (Version: 14.0.8089.726) Windows Live Fotogalerie (Version: 14.0.8081.709) Windows Live ID-Anmelde-Assistent (Version: 6.500.3146.0) Windows Live Mail (Version: 14.0.8089.0726) Windows Live Messenger (Version: 14.0.8089.0726) Windows Live Movie Maker (Version: 14.0.8091.0730) Windows Live Sync (Version: 14.0.8089.726) Windows Live Writer (Version: 14.0.8089.0726) Windows Live-Uploadtool (Version: 14.0.8014.1029) WinRAR Würth Beschläge Yahoo! Toolbar ==================== Restore Points ========================= 30-08-2013 11:21:52 Windows Update 03-09-2013 06:48:24 Windows Update 07-09-2013 12:00:49 Windows Update 12-09-2013 15:40:24 Windows Update 13-09-2013 15:14:32 Windows Update 16-09-2013 13:56:34 Windows Update 17-09-2013 14:36:44 Windows Update 24-09-2013 09:28:40 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-09-24 12:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0012CE96-EEBB-4821-9692-39FD4E7A2D64} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.) Task: {0C71FC86-3D3C-413E-BD8F-25A533514013} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2009-10-30] (TuneUp Software) Task: {0DE89BB0-96CC-420B-8414-7FBF63634194} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {17CCFE8D-F573-44A2-9331-691F26B13217} - System32\Tasks\{66DAFD33-919A-4CE0-B1A6-E4F14D4164EE} => C:\Program Files\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {281A2F59-5DC4-4EDE-A414-A6BE14A44DE3} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2010-04-29] (Microsoft Corporation) Task: {2D68E398-EC50-4F8A-8292-73C5E7F66848} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {52EC0488-CFF0-44F4-90D0-CA612FD8C263} - System32\Tasks\Real Networks Scheduler => c:\program files\real\realplayer\Update\realsched.exe [2013-06-20] (RealNetworks, Inc.) Task: {62D3BF4F-EF2B-498B-B2C3-F2B212A660D3} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2011-05-10] (Hewlett-Packard) Task: {887EA725-532E-4247-A9A7-F209423570FF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-20] (Adobe Systems Incorporated) Task: {94053A4A-9081-4442-BF0D-55DED861C3EE} - System32\Tasks\Automatische Problemsuche => C:\Program Files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-10-30] (TuneUp Software) Task: {A52308D2-7CA0-4317-8A79-CE367F1F931A} - System32\Tasks\ArcSoft Connect Daemon => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27] (ArcSoft Inc.) Task: {C3CC70A1-D607-4D8C-9E43-1A22BAD64C6F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-24] (Google Inc.) Task: {CB58A3D2-CACB-47AA-8465-578FA4FCD1F6} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {DFF04FC8-EFA6-4F0B-A371-A60DD9A2D597} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-24] (Google Inc.) Task: {E1AF2A4B-7F91-4798-8465-B6E35B20AF79} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: {EA1BB7AE-24AB-4A99-81B3-FDC779C81C2F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd) Task: {F3C49398-5E6E-4525-9558-90D2CDAAFEFE} - System32\Tasks\DMEPeriodicTask => C:\Program Files\HP\Digital Imaging\bin\warrantyextension\HPPromo.exe [2009-06-16] (Hewlett-Packard) Task: {F63D9D82-EDEE-4877-B45C-21A39100F3FB} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1561127288-1042267340-3996502274-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DMEPeriodicTask.job => C:\Program Files\HP\Digital Imaging\bin\warrantyextension\HPPromo.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-24 12:36 - 2013-09-24 12:33 - 00394824 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll 2011-09-12 15:29 - 2011-09-12 15:29 - 00187904 _____ () C:\Program Files\Steganos Privacy Suite 12\ShellExtension.dll 2010-08-06 19:09 - 2006-08-05 11:34 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll 2010-10-18 11:14 - 2009-08-20 01:19 - 00074984 _____ () C:\Program Files\FILEminimizer Pictures\FILEMShell.dll 2012-10-01 14:26 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files\Sony\Sony PC Companion\TMonitorAPI.dll 2012-10-01 14:26 - 2013-05-17 10:51 - 00207872 _____ () C:\Program Files\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files\Sony\Sony PC Companion\Report.dll 2012-07-17 10:56 - 2012-07-17 10:56 - 00587776 _____ () C:\Program Files\Sony\Sony PC Companion\PhoneUpdate.dll 2012-10-01 14:26 - 2010-01-11 16:44 - 00053248 _____ () C:\Program Files\Sony\Sony PC Companion\VObject.dll 2012-05-04 12:41 - 2007-04-19 10:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll 2009-07-13 23:03 - 2009-07-14 03:15 - 00364544 _____ () C:\Windows\system32\msjetoledb40.dll 2013-01-08 12:01 - 2012-04-15 01:47 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll 2013-01-08 12:01 - 2008-01-15 01:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll 2013-01-08 12:01 - 2009-03-09 12:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll 2009-02-26 11:45 - 2009-02-26 11:45 - 00024912 _____ () C:\Program Files\Microsoft Office\Office12\Wordcnvpxy.cnv ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/30/2013 11:05:58 AM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "J:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" System errors: ============= Error: (09/30/2013 11:26:31 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:30 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:30 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:29 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR15 gefunden. Error: (09/30/2013 11:26:08 AM) (Source: Ntfs) (User: ) Description: Auf dem Volume "Z:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (09/30/2013 10:55:53 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinDefend" wurde mit folgendem Fehler beendet: %%5 Error: (09/30/2013 10:55:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SPCA1528 Video Camera Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (09/27/2013 04:44:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst Steganos Volatile Disk konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (09/27/2013 00:07:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinDefend" wurde mit folgendem Fehler beendet: %%5 Error: (09/27/2013 00:07:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SPCA1528 Video Camera Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (09/30/2013 11:05:58 AM) (Source: Windows Backup)(User: ) Description: J:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 3326.3 MB Available physical RAM: 1984.95 MB Total Pagefile: 6650.9 MB Available Pagefile: 5043.32 MB Total Virtual: 2047.88 MB Available Virtual: 1917.79 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:910.41 GB) (Free:792.31 GB) NTFS Drive d: (Recover) (Fixed) (Total:20 GB) (Free:11.66 GB) NTFS Drive f: () (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT Drive m: (HDDRIVE2GO) (Fixed) (Total:931.28 GB) (Free:865.6 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=910 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ======================================================== Disk: 4 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: DA97DC12) Partition 1: (Active) - (Size=2 GB) - (Type=06) ======================================================== Disk: 8 (Size: 932 GB) (Disk ID: 20441D24) Partition 1: (Not Active) - (Size=932 GB) - (Type=0C) ==================== End Of Log ============================ |
30.09.2013, 15:43 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
09.10.2013, 11:49 | #21 |
| Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Endlich hab ichs geschafft die scanner laufen zu lassen und mir die logs zu "mopsen". Eset hab ich abbrechen und am nächsten Tag nochmal laufen lassen müssen, da die Zeit zu knapp wurde. Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.07.06 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16686 ***** :: *****-PC [Administrator] 07.10.2013 13:21:55 mbam-log-2013-10-07 (13-21-55).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 205546 Laufzeit: 7 Minute(n), 46 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=704ec5f9e5143a409f9006e000e972b5 # engine=15386 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-07 12:43:11 # local_time=2013-10-07 02:43:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 95 5089 1131189 0 0 # compatibility_mode=5893 16776573 100 94 4951 132780982 0 0 # scanned=153513 # found=5 # cleaned=0 # scan_time=3921 sh=C5E386D0112DD965DA369519A2AB71D50EEC1957 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.POI trojan" ac=I fn="C:\Dokumente und Einstellungen\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\6775ecd1-423c714b" sh=0936D697AEF9D6354F0D90FDE5ACA49C6FC2F9D3 ft=1 fh=ce3893edd40afbb8 vn="a variant of Win32/Sirefef.GB trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\80000000.@.vir" sh=1FAEB10D00ADBFF104050F3AEB4D951881745E0E ft=1 fh=d1bfb7c7bec20b03 vn="Win32/Sirefef.GA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\80000001.@.vir" sh=6A12817FE7B2EFF67F2E4006BBFA3DD8091008E5 ft=1 fh=a2db5d1462c4448d vn="Win32/Sirefef.GB trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\800000cb.@.vir" sh=C5E386D0112DD965DA369519A2AB71D50EEC1957 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.POI trojan" ac=I fn="C:\Users\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\6775ecd1-423c714b" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=704ec5f9e5143a409f9006e000e972b5 # engine=15398 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-08 10:24:24 # local_time=2013-10-08 12:24:24 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 95 5544 1209262 0 0 # compatibility_mode=5893 16776573 100 94 5260 132859055 0 0 # scanned=231410 # found=5 # cleaned=0 # scan_time=5186 sh=C5E386D0112DD965DA369519A2AB71D50EEC1957 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.POI trojan" ac=I fn="C:\Dokumente und Einstellungen\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\6775ecd1-423c714b" sh=0936D697AEF9D6354F0D90FDE5ACA49C6FC2F9D3 ft=1 fh=ce3893edd40afbb8 vn="a variant of Win32/Sirefef.GB trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\80000000.@.vir" sh=1FAEB10D00ADBFF104050F3AEB4D951881745E0E ft=1 fh=d1bfb7c7bec20b03 vn="Win32/Sirefef.GA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\80000001.@.vir" sh=6A12817FE7B2EFF67F2E4006BBFA3DD8091008E5 ft=1 fh=a2db5d1462c4448d vn="Win32/Sirefef.GB trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\800000cb.@.vir" sh=C5E386D0112DD965DA369519A2AB71D50EEC1957 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.POI trojan" ac=I fn="C:\Users\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\6775ecd1-423c714b" |
09.10.2013, 12:09 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Nur Reste im Cache. Die anderen Funde zu Zeroaccess/Sirefef beziehen sich nur auf Quarantäneordner TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
09.10.2013, 14:37 | #23 |
| Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem TFC laufen lassen Danach nochmal mit Eset gescannt. Nur noch die Quarantäne Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=704ec5f9e5143a409f9006e000e972b5 # engine=15416 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-09 01:14:35 # local_time=2013-10-09 03:14:35 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 95 5334 1305873 0 0 # compatibility_mode=5893 16776573 100 94 101871 132955666 0 0 # scanned=229980 # found=3 # cleaned=0 # scan_time=4801 sh=0936D697AEF9D6354F0D90FDE5ACA49C6FC2F9D3 ft=1 fh=ce3893edd40afbb8 vn="a variant of Win32/Sirefef.GB trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\80000000.@.vir" sh=1FAEB10D00ADBFF104050F3AEB4D951881745E0E ft=1 fh=d1bfb7c7bec20b03 vn="Win32/Sirefef.GA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\80000001.@.vir" sh=6A12817FE7B2EFF67F2E4006BBFA3DD8091008E5 ft=1 fh=a2db5d1462c4448d vn="Win32/Sirefef.GB trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files\Google\Desktop\Install\{87e7496d-519f-3441-1799-14277f337ed4}\9519~1\A535~1\E628~1\{87e7496d-519f-3441-1799-14277f337ed4}\U\800000cb.@.vir" |
09.10.2013, 17:50 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
09.10.2013, 20:01 | #25 |
| Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Erstmal tausend Dank an dich für die geniale Hilfestellung und alles und überhaupt MVPS Hosts File und CookieCuller schau ich mir morgen, wenn ich wieder an seinem Pc bin, gleich mal an. Da werd ich auch evtl. den ein oder anderen scanner erneut laufen lassen... sicher is sicher. Wenn, dann gibt's nur noch ein Problem, aber das gehört nicht mehr in dieses Forum : Meinem Verwandten verständlich zu erklären, dass entweder: - er nicht mehr wahllos auf alles klickt; nicht 3 oder 4 versch. Browser braucht; Programme aktuell hält (und wie) und nicht benötigte Programme deinstalliert (ebenfalls auch 'wie') - oder ich ihm auf die Finger hauen darf Nochmal ganz ganz lieben Dank für die tolle Hilfe LG Jule |
09.10.2013, 22:08 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem Dann wären wir durch! Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Helfen kann dir dabei delfix: Die Reihenfolge ist hier entscheidend.
Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Start, Systemsteuerung, Windows-Update PDF-Reader aktualisieren Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast) Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers: Prüfen => Adobe - Flash Player Downloadlinks findest du hier => Browsers and Plugins - FilePony.de Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind. Java-Update Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Win 7/Avira: Entfernen von TR/Sirefef.A.40 (ZeroAccess) und ggf. weiterem |
4d36e972-e325-11ce-bfc1-08002be10318, antivir, antivirus, avira, bingbar, browser, chromium, computer, crypter, desktop, entfernen, excel, farbar, farbar recovery scan tool, flash player, help, helper, home, homepage, installation, internet, internet explorer, mozilla, plug-in, registry, rootkit, software, svchost.exe, system, tr/sirefef.a., vista, windows, windows xp |