|
Plagegeister aller Art und deren Bekämpfung: ihavenet Befall?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.10.2013, 11:19 | #1 |
| ihavenet Befall? Hallo, ich wende mich an das Forum, weil ich seit 2 Tagen folgendes Problem habe: Immer wenn ich eine Googlesuche in Mozilla starte, werde ich auf seltsame andere Seiten weitergeleitet. Oft ist es die ihavenet Seite. Nachdem ich hier im Forum einige ähnliche Fälle gelesen habe habe ich versucht mittels Avira und anderen Programmen den Virus zu beseitigen. Leider ist mir das nicht geglückt, meine Suchanfragen werden immernoch umgeleitet. Ich bin leider kein Computerfachmann und würde mich über kompetente Hilfe sehr freuen. Liebe Grüße, anni |
20.10.2013, 11:21 | #2 |
/// TB-Ausbilder | ihavenet Befall?Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
20.10.2013, 11:34 | #3 |
| ihavenet Befall? Danke für die rasche Antwort!
__________________Hier sind die beiden Ergebnisse: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-10-2013 Ran by Annkathrin (administrator) on CLIENT-PC on 20-10-2013 12:28:56 Running from C:\Users\Annkathrin\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Lenovo) C:\Windows\system32\ibmpmsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe (Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe (Andrea Electronics Corporation) C:\Windows\system32\AEADISRV.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe (Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe (Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe (Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Zoom\TpScrex.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Lenovo Group Limited) C:\Program Files\Lenovo\TrackPoint\tp4serv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Spotify Ltd) C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Annkathrin\AppData\Roaming\Spotify\spotify.exe () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe (Dropbox, Inc.) C:\Users\Annkathrin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Lenovo Group Limited) C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyHelper.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [TrackPointSrv] - C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [93032 2009-11-24] (Lenovo Group Limited) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) HKLM\...\Run: [PWMTRV] - rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor HKLM\...\Run: [] - [x] HKLM\...\Run: [TpShocks] - C:\Windows\system32\TpShocks.exe [186248 2012-09-20] (Lenovo.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.) HKLM\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-10-14] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5707544 2013-10-11] (SUPERAntiSpyware) HKCU\...\Run: [Spotify] - C:\Users\Annkathrin\AppData\Roaming\Spotify\Spotify.exe [4752384 2013-10-14] (Spotify Ltd) HKCU\...\Run: [SYHMR] - rundll32 "C:\Users\Annkathrin\AppData\Roaming\ReAgentr.dll",Imja Startup: C:\Users\Annkathrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Annkathrin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Annkathrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk -> C:\Program Files\HP\HP Deskjet 1000 J110 series\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope value is missing. BHO: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL (Microsoft Corporation) ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Hosts: 127.94.0.1 client.openvpn.net Tcpip\Parameters: [DhcpNameServer] 10.3.3.1 FireFox: ======== FF ProfilePath: C:\Users\Annkathrin\AppData\Roaming\Mozilla\Firefox\Profiles\lt0n7xre.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox ========================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [120088 2013-10-11] (SUPERAntiSpyware.com) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG) S2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [101736 2011-07-12] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [127336 2011-07-12] (Lenovo Group Limited) R2 OpenVPNAccessClient; C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe [24064 2012-05-03] () S3 PwmEWSvc; C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE [1665120 2012-05-16] (Lenovo Group Limited) S3 SUService; C:\Program Files\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [131432 2011-07-12] (Lenovo Group Limited) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-05] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-05] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-07] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R3 NETwLv32; C:\Windows\System32\DRIVERS\NETwLv32.sys [6639616 2010-10-07] (Intel Corporation) S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) R3 Tp4Track; C:\Windows\System32\DRIVERS\tp4track.sys [23152 2009-11-24] (Lenovo Group Limited) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-20 12:28 - 2013-10-20 12:28 - 01087515 _____ (Farbar) C:\Users\Annkathrin\Downloads\FRST.exe 2013-10-20 12:28 - 2013-10-20 12:28 - 00000000 ____D C:\FRST 2013-10-20 11:56 - 2013-10-20 11:56 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\Malwarebytes 2013-10-20 11:55 - 2013-10-20 11:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Annkathrin\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-20 11:55 - 2013-10-20 11:55 - 00001073 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-20 11:55 - 2013-10-20 11:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-20 11:55 - 2013-10-20 11:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-20 11:55 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-20 10:14 - 2013-10-20 10:15 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-10-20 10:14 - 2013-10-20 10:14 - 00001967 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2013-10-20 10:13 - 2013-10-20 10:13 - 28114168 _____ (SUPERAntiSpyware) C:\Users\Annkathrin\Downloads\SUPERAntiSpyware(1).exe 2013-10-20 09:09 - 2013-10-20 09:09 - 02347384 _____ (ESET) C:\Users\Annkathrin\Downloads\esetsmartinstaller_deu.exe 2013-10-20 09:09 - 2013-10-20 09:09 - 00000000 ____D C:\Program Files\ESET 2013-10-20 09:01 - 2013-10-20 09:03 - 00000000 ____D C:\AdwCleaner 2013-10-20 09:01 - 2013-10-20 09:01 - 01056666 _____ C:\Users\Annkathrin\Downloads\AdwCleaner.exe 2013-10-17 21:07 - 2013-10-17 21:07 - 00147456 __RSH C:\Users\Annkathrin\AppData\Roaming\ReAgentr.dll 2013-10-15 20:36 - 2013-10-17 21:04 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\vlc 2013-10-15 20:35 - 2013-10-15 20:35 - 00000000 ____D C:\Program Files\VideoLAN 2013-10-15 20:33 - 2013-10-15 20:34 - 25132744 _____ C:\Users\Annkathrin\Downloads\vlc-2.1.0-win32.exe 2013-10-15 08:46 - 2013-10-15 08:46 - 00001759 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-10-15 08:45 - 2013-10-15 08:45 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-15 08:45 - 2013-10-15 08:45 - 00000000 ____D C:\Program Files\iTunes 2013-10-15 08:45 - 2013-10-15 08:45 - 00000000 ____D C:\Program Files\iPod 2013-10-10 21:20 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-10 21:20 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-10 21:20 - 2013-09-23 01:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-10 21:20 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-10 21:20 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-10 21:20 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-10 21:20 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-10 19:07 - 2013-09-14 02:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-10 19:07 - 2013-09-08 04:07 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-10 19:07 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-10 19:07 - 2013-09-04 03:15 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-10 19:07 - 2013-09-04 03:14 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-10 19:07 - 2013-09-04 03:14 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-10 19:07 - 2013-09-04 03:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-10 19:07 - 2013-09-04 03:14 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-10 19:07 - 2013-09-04 03:14 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-10 19:07 - 2013-09-04 03:14 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-10 19:07 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-10-10 19:07 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-10 19:07 - 2013-08-29 03:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-10 19:07 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-10 19:07 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-10 19:07 - 2013-08-28 03:04 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-10 19:07 - 2013-08-28 02:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-10 19:07 - 2013-08-01 13:03 - 00729024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-10 19:07 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 19:07 - 2013-07-12 12:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-10 19:07 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-10 19:07 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-10 19:07 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-10 19:07 - 2013-07-04 11:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-10 19:07 - 2013-07-03 06:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-10 19:07 - 2013-07-03 05:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-10 19:07 - 2013-07-03 05:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-10 19:07 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-10 19:07 - 2013-06-06 06:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-10 19:07 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-10 19:07 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-10 19:07 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-10 19:07 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-08 19:43 - 2013-10-08 19:43 - 00000358 _____ C:\Users\Annkathrin\openvpn-connect.json 2013-10-08 19:35 - 2013-10-20 09:05 - 00002512 _____ C:\Users\Annkathrin\ovpntray.log 2013-10-08 19:34 - 2013-10-08 19:34 - 00001323 _____ C:\Users\Public\Desktop\OpenVPN Connect.lnk 2013-10-08 19:33 - 2013-10-08 19:33 - 00000000 ____D C:\Program Files\OpenVPN Technologies 2013-10-08 19:32 - 2013-10-08 19:32 - 05122891 _____ C:\Users\Annkathrin\Downloads\openvpn-connect.msi 2013-10-01 23:00 - 2013-10-01 23:00 - 00002278 _____ C:\Users\Public\Desktop\HP Deskjet 1000 J110 series.lnk 2013-10-01 22:59 - 2013-10-01 22:59 - 00000057 _____ C:\ProgramData\Ament.ini 2013-10-01 22:59 - 2013-10-01 22:59 - 00000000 ____D C:\ProgramData\HP 2013-10-01 22:59 - 2013-10-01 22:59 - 00000000 ____D C:\Program Files\HP 2013-10-01 22:58 - 2013-10-01 23:00 - 00000000 ____D C:\Users\Annkathrin\AppData\Local\HP 2013-10-01 22:47 - 2013-10-01 22:48 - 48425056 _____ C:\Users\Annkathrin\Downloads\DJ1000_J110_1313.exe 2013-10-01 20:04 - 2013-10-01 20:04 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-10-20 12:28 - 2013-10-20 12:28 - 01087515 _____ (Farbar) C:\Users\Annkathrin\Downloads\FRST.exe 2013-10-20 12:28 - 2013-10-20 12:28 - 00000000 ____D C:\FRST 2013-10-20 12:17 - 2013-01-07 19:21 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-20 11:56 - 2013-10-20 11:56 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\Malwarebytes 2013-10-20 11:55 - 2013-10-20 11:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Annkathrin\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-20 11:55 - 2013-10-20 11:55 - 00001073 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-20 11:55 - 2013-10-20 11:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-20 11:55 - 2013-10-20 11:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-20 11:33 - 2013-01-10 16:46 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\Spotify 2013-10-20 11:15 - 2012-12-17 17:47 - 01107970 _____ C:\Windows\WindowsUpdate.log 2013-10-20 10:15 - 2013-10-20 10:14 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-10-20 10:14 - 2013-10-20 10:14 - 00001967 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2013-10-20 10:13 - 2013-10-20 10:13 - 28114168 _____ (SUPERAntiSpyware) C:\Users\Annkathrin\Downloads\SUPERAntiSpyware(1).exe 2013-10-20 09:12 - 2009-07-14 06:34 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-20 09:12 - 2009-07-14 06:34 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-20 09:10 - 2012-12-17 17:57 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-20 09:09 - 2013-10-20 09:09 - 02347384 _____ (ESET) C:\Users\Annkathrin\Downloads\esetsmartinstaller_deu.exe 2013-10-20 09:09 - 2013-10-20 09:09 - 00000000 ____D C:\Program Files\ESET 2013-10-20 09:06 - 2013-05-27 23:12 - 00000000 ___RD C:\Users\Annkathrin\Dropbox 2013-10-20 09:06 - 2013-05-27 23:10 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\Dropbox 2013-10-20 09:05 - 2013-10-08 19:35 - 00002512 _____ C:\Users\Annkathrin\ovpntray.log 2013-10-20 09:04 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-20 09:04 - 2009-07-14 06:39 - 00048853 _____ C:\Windows\setupact.log 2013-10-20 09:03 - 2013-10-20 09:01 - 00000000 ____D C:\AdwCleaner 2013-10-20 09:01 - 2013-10-20 09:01 - 01056666 _____ C:\Users\Annkathrin\Downloads\AdwCleaner.exe 2013-10-18 17:57 - 2013-01-10 16:47 - 00000000 ____D C:\Users\Annkathrin\AppData\Local\Spotify 2013-10-17 21:07 - 2013-10-17 21:07 - 00147456 __RSH C:\Users\Annkathrin\AppData\Roaming\ReAgentr.dll 2013-10-17 21:04 - 2013-10-15 20:36 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\vlc 2013-10-15 22:22 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2013-10-15 20:35 - 2013-10-15 20:35 - 00000000 ____D C:\Program Files\VideoLAN 2013-10-15 20:34 - 2013-10-15 20:33 - 25132744 _____ C:\Users\Annkathrin\Downloads\vlc-2.1.0-win32.exe 2013-10-15 08:46 - 2013-10-15 08:46 - 00001759 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-10-15 08:45 - 2013-10-15 08:45 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-15 08:45 - 2013-10-15 08:45 - 00000000 ____D C:\Program Files\iTunes 2013-10-15 08:45 - 2013-10-15 08:45 - 00000000 ____D C:\Program Files\iPod 2013-10-15 08:45 - 2013-02-03 16:24 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-10-14 15:34 - 2012-12-17 18:19 - 00000000 ____D C:\ProgramData\Lenovo 2013-10-14 15:34 - 2012-12-17 18:19 - 00000000 ____D C:\Program Files\Lenovo 2013-10-13 21:25 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-10-13 09:14 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-13 09:05 - 2013-05-27 23:12 - 00001041 _____ C:\Users\Annkathrin\Desktop\Dropbox.lnk 2013-10-13 09:05 - 2013-05-27 23:11 - 00000000 ____D C:\Users\Annkathrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-10-10 21:55 - 2013-07-23 15:08 - 00000000 ____D C:\Users\Annkathrin\Documents\FH 2013-10-10 21:31 - 2009-07-14 06:33 - 00413440 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-10 21:28 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-10-10 21:23 - 2013-08-27 20:50 - 00000000 ____D C:\Windows\system32\MRT 2013-10-10 21:20 - 2012-12-17 19:19 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 21:43 - 2013-01-07 19:21 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-09 21:43 - 2013-01-07 19:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 19:43 - 2013-10-08 19:43 - 00000358 _____ C:\Users\Annkathrin\openvpn-connect.json 2013-10-08 19:43 - 2013-01-07 14:13 - 00000000 ____D C:\Users\Annkathrin 2013-10-08 19:34 - 2013-10-08 19:34 - 00001323 _____ C:\Users\Public\Desktop\OpenVPN Connect.lnk 2013-10-08 19:33 - 2013-10-08 19:33 - 00000000 ____D C:\Program Files\OpenVPN Technologies 2013-10-08 19:32 - 2013-10-08 19:32 - 05122891 _____ C:\Users\Annkathrin\Downloads\openvpn-connect.msi 2013-10-02 17:03 - 2012-12-17 20:16 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-02 07:11 - 2013-01-07 14:21 - 00000000 ____D C:\Users\Annkathrin\AppData\Local\Mozilla 2013-10-02 06:53 - 2012-12-17 20:45 - 00097326 _____ C:\Windows\PFRO.log 2013-10-01 23:00 - 2013-10-01 23:00 - 00002278 _____ C:\Users\Public\Desktop\HP Deskjet 1000 J110 series.lnk 2013-10-01 23:00 - 2013-10-01 22:58 - 00000000 ____D C:\Users\Annkathrin\AppData\Local\HP 2013-10-01 22:59 - 2013-10-01 22:59 - 00000057 _____ C:\ProgramData\Ament.ini 2013-10-01 22:59 - 2013-10-01 22:59 - 00000000 ____D C:\ProgramData\HP 2013-10-01 22:59 - 2013-10-01 22:59 - 00000000 ____D C:\Program Files\HP 2013-10-01 22:48 - 2013-10-01 22:47 - 48425056 _____ C:\Users\Annkathrin\Downloads\DJ1000_J110_1313.exe 2013-10-01 20:04 - 2013-10-01 20:04 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-23 01:28 - 2013-10-10 21:20 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 01:28 - 2013-10-10 21:20 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 01:28 - 2013-10-10 21:20 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 01:27 - 2013-10-10 21:20 - 14335488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 01:27 - 2013-10-10 21:20 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-21 05:30 - 2013-10-10 21:20 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 04:39 - 2013-10-10 21:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe Some content of TEMP: ==================== C:\Users\Annkathrin\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\Annkathrin\AppData\Local\Temp\ose00000.exe C:\Users\Annkathrin\AppData\Local\Temp\Quarantine.exe C:\Users\Melanie\AppData\Local\Temp\AskSLib.dll C:\Users\Melanie\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Melanie\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-13 10:59 ==================== End Of Log ============================ --- --- --- --- --- --- und Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-10-2013 Ran by Annkathrin at 2013-10-20 12:29:42 Running from C:\Users\Annkathrin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05) Anzeige am Bildschirm (Version: 6.62.01) Apple Application Support (Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (Version: 2.1.3.127) Avira Free Antivirus (Version: 13.0.0.4052) Bonjour (Version: 3.0.0.10) calibre (Version: 1.3.0) Citavi (Version: 3.4.0.2) Dropbox (HKCU Version: 2.4.2) Energie-Manager (Version: 6.32) ESET Online Scanner v3 GPL Ghostscript 8.71 Lite (Version: 8.71) HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (Version: 28.0.1313.0) Intel PROSet Wireless Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.1867) Intel(R) PROSet/Wireless WiFi-Software (Version: 14.03.0000) Intel(R) TV Wizard IrfanView (remove only) (Version: 4.35) iTunes (Version: 11.1.1.11) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Lenovo Auto Scroll Utility (Version: 1.11) Lenovo Patch Utility (Version: 1.3.0.9) Lenovo System Interface Driver (Version: 1.05) Lenovo System Update (Version: 5.03.0005) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Access MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014) Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014) Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proof (Italian) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Word MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Mozilla Firefox 24.0 (x86 de) (Version: 24.0) Mozilla Maintenance Service (Version: 24.0) OpenVPN Connect (Version: 1.8.3.347) QuickTime (Version: 7.74.80.86) SoundMAX (Version: 6.10.1.7255) Spotify (HKCU Version: 0.9.4.185.g7545a404) SUPERAntiSpyware (Version: 5.6.1040) ThinkPad FullScreen Magnifier (Version: 2.40) ThinkPad Modem (Version: 7.62.00) ThinkPad Power Management Driver (Version: 1.43) ThinkPad TrackPoint Driver (Version: 4.71.0.0) ThinkVantage System für aktiven Festplattenschutz (Version: 1.77.0.9) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) VLC media player 2.1.0 (Version: 2.1.0) Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 6.3.5.430) (Version: 04/08/2010 6.3.5.430) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800) XnView 1.99.6 (Version: 1.99.6) ==================== Restore Points ========================= 18-10-2013 21:49:26 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-10-09 21:22 - 00000945 ____A C:\Windows\system32\Drivers\etc\hosts 127.94.0.1 client.openvpn.net ==================== Scheduled Tasks (whitelisted) ============= Task: {1532DF70-1587-45A4-BF3B-1D1AD077B143} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {6C431B6C-B704-433C-894E-2D17C08C62BB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {88BBA4E1-776F-45A1-A726-88D3E1A1A7A1} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {C90593B4-B14F-40EF-89FC-C72FA4F741A6} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files\Lenovo\System Update\tvsuShim.exe [2013-09-17] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-12-18 09:49 - 2012-05-16 07:32 - 00094208 ____N () C:\Program Files\ThinkPad\Utilities\GR\PWMRT32V.DLL 2012-10-11 22:56 - 2012-10-11 22:56 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2012-10-11 22:56 - 2012-10-11 22:56 - 01242512 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-01-10 16:47 - 2013-10-14 15:24 - 34604032 _____ () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\libcef.dll 2010-08-24 18:48 - 2010-08-24 18:48 - 00153088 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\pyexpat.pyd 2010-08-24 18:47 - 2010-08-24 18:47 - 00040448 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\_socket.pyd 2010-08-24 18:48 - 2010-08-24 18:48 - 00720896 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\_ssl.pyd 2010-08-24 18:48 - 2010-08-24 18:48 - 00011776 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\select.pyd 2012-03-27 16:59 - 2012-03-27 16:59 - 00019968 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\zope.interface._zope_interface_coptimizations.pyd 2012-03-27 17:00 - 2012-03-27 17:00 - 00010240 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.rand.pyd 2012-03-27 17:00 - 2012-03-27 17:00 - 00061440 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.crypto.pyd 2012-03-27 17:00 - 2012-03-27 17:00 - 00039424 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.SSL.pyd 2011-02-26 11:33 - 2011-02-26 11:33 - 00096768 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\win32api.pyd 2011-02-27 10:12 - 2011-02-27 10:12 - 00110080 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\pywintypes26.dll 2010-08-24 18:48 - 2010-08-24 18:48 - 00073728 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\_ctypes.pyd 2010-08-24 18:48 - 2010-08-24 18:48 - 00286208 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\_hashlib.pyd 2011-02-26 11:32 - 2011-02-26 11:32 - 00035840 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\win32process.pyd 2012-03-27 17:00 - 2012-03-27 17:00 - 00006656 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\pyovpnc.pyd 2012-03-27 17:00 - 2012-03-27 17:00 - 00007680 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\twisted.protocols._c_urlarg.pyd 2011-02-26 11:33 - 2011-02-26 11:33 - 00167424 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\win32gui.pyd 2011-02-26 11:31 - 2011-02-26 11:31 - 00017408 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\win32event.pyd 2011-08-19 01:44 - 2011-08-19 01:44 - 00005632 _____ () C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\ovpntray.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Annkathrin\AppData\Roaming\Dropbox\bin\libcef.dll 2013-10-02 06:56 - 2013-10-14 15:24 - 00747008 _____ () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\libglesv2.dll 2013-10-02 06:56 - 2013-10-14 15:24 - 00137216 _____ () C:\Users\Annkathrin\AppData\Roaming\Spotify\Data\libegl.dll 2013-10-01 20:04 - 2013-10-01 20:04 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-01-07 14:31 - 2013-08-01 10:12 - 00122880 _____ () C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\components\CitaviPickerCommunication.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/19/2013 03:54:05 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13432 Error: (10/19/2013 03:54:05 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13432 Error: (10/19/2013 03:54:05 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 03:54:04 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 12418 Error: (10/19/2013 03:54:04 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 12418 Error: (10/19/2013 03:54:04 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 03:54:03 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11372 Error: (10/19/2013 03:54:03 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11372 Error: (10/19/2013 03:54:03 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/19/2013 03:54:02 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10358 System errors: ============= Error: (10/20/2013 09:06:02 AM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (10/20/2013 09:03:23 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Zeitgeber" wurde mit folgendem Fehler beendet: %%1115 Error: (10/20/2013 08:53:46 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht. Error: (10/19/2013 01:38:50 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (10/19/2013 01:38:54 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (10/18/2013 09:42:53 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (10/18/2013 05:56:50 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht. Error: (10/18/2013 02:24:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/18/2013 02:24:03 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Player-Netzwerkfreigabedienst erreicht. Error: (10/17/2013 06:52:39 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 2006.3 MB Available physical RAM: 897.42 MB Total Pagefile: 4012.59 MB Available Pagefile: 2040.59 MB Total Virtual: 2047.88 MB Available Virtual: 1895.45 MB ==================== Drives ================================ Drive c: (SYSTEM) (Fixed) (Total:74.43 GB) (Free:40.03 GB) NTFS Drive e: (MyDrive) (Fixed) (Total:465.76 GB) (Free:136.68 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: 46B65CC4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=74 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 466 GB) (Disk ID: 05F9B334) Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
20.10.2013, 11:41 | #4 |
/// TB-Ausbilder | ihavenet Befall? Servus, Scan mit Combofix
|
20.10.2013, 12:00 | #5 |
| ihavenet Befall? so, ich hoffe ich hab alles richtig gemacht: Code:
ATTFilter ComboFix 13-10-19.02 - Annkathrin 20.10.2013 12:47:28.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.2006.1048 [GMT 2:00] ausgeführt von:: c:\users\Annkathrin\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe c:\programdata\Roaming c:\users\Annkathrin\AppData\Roaming\ReAgentr.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-09-20 bis 2013-10-20 )))))))))))))))))))))))))))))) . . 2013-10-20 10:28 . 2013-10-20 10:28 -------- d-----w- C:\FRST 2013-10-20 09:56 . 2013-10-20 09:56 -------- d-----w- c:\users\Annkathrin\AppData\Roaming\Malwarebytes 2013-10-20 09:55 . 2013-10-20 09:55 -------- d-----w- c:\programdata\Malwarebytes 2013-10-20 09:55 . 2013-10-20 09:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-10-20 09:55 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-10-20 09:55 . 2013-10-20 09:55 -------- d-----w- c:\users\Annkathrin\AppData\Local\Programs 2013-10-20 08:14 . 2013-10-20 08:15 -------- d-----w- c:\program files\SUPERAntiSpyware 2013-10-20 07:09 . 2013-10-20 07:09 -------- d-----w- c:\program files\ESET 2013-10-20 07:01 . 2013-10-20 07:03 -------- d-----w- C:\AdwCleaner 2013-10-15 18:36 . 2013-10-17 19:04 -------- d-----w- c:\users\Annkathrin\AppData\Roaming\vlc 2013-10-15 18:35 . 2013-10-15 18:35 -------- d-----w- c:\program files\VideoLAN 2013-10-15 06:45 . 2013-10-15 06:45 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-10-15 06:45 . 2013-10-15 06:45 -------- d-----w- c:\program files\iTunes 2013-10-15 06:45 . 2013-10-15 06:45 -------- d-----w- c:\program files\iPod 2013-10-10 20:30 . 2013-10-10 20:30 -------- d-----w- c:\users\Annkathrin\AppData\Local\ElevatedDiagnostics 2013-10-10 17:07 . 2013-07-04 11:50 530432 ----a-w- c:\windows\system32\comctl32.dll 2013-10-08 17:33 . 2013-10-08 17:33 -------- d-----w- c:\program files\OpenVPN Technologies 2013-10-01 20:59 . 2013-10-01 20:59 -------- d-----w- c:\programdata\HP 2013-10-01 20:59 . 2013-10-01 20:59 -------- d-----w- c:\program files\HP 2013-10-01 20:58 . 2013-10-01 21:00 -------- d-----w- c:\users\Annkathrin\AppData\Local\HP 2013-09-26 18:00 . 2013-09-26 18:00 208760 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-10-09 19:43 . 2013-01-07 17:21 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-10-09 19:43 . 2013-01-07 17:21 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-09-05 15:20 . 2013-05-07 15:30 66144 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-09-05 15:20 . 2012-12-17 18:19 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-09-05 15:20 . 2012-12-17 18:19 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-08-05 01:56 . 2013-09-12 17:53 133056 ----a-w- c:\windows\system32\drivers\ataport.sys 2013-08-02 01:50 . 2013-09-12 17:53 169984 ----a-w- c:\windows\system32\winsrv.dll 2013-08-02 01:49 . 2013-09-12 17:53 293376 ----a-w- c:\windows\system32\KernelBase.dll 2013-08-02 01:48 . 2013-09-12 17:53 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-08-02 01:48 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-08-02 00:52 . 2013-09-12 17:53 271360 ----a-w- c:\windows\system32\conhost.exe 2013-08-02 00:43 . 2013-09-12 17:53 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-08-02 00:43 . 2013-09-12 17:53 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-08-02 00:43 . 2013-09-12 17:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-08-02 00:43 . 2013-09-12 17:53 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-07-25 08:57 . 2013-08-20 14:49 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Annkathrin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Annkathrin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Annkathrin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\Annkathrin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-10-14 1140736] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-10-10 5707544] "Spotify"="c:\users\Annkathrin\AppData\Roaming\Spotify\Spotify.exe" [2013-10-14 4752384] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-05 347192] "TrackPointSrv"="c:\program files\Lenovo\TrackPoint\tp4serv.exe" [2009-11-24 93032] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-08-06 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-08-06 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-08-06 150552] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816] "PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2012-05-16 4395104] "TpShocks"="TpShocks.exe" [2012-09-20 186248] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-10-01 152392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] " Malwarebytes Anti-Malware "="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040] . c:\users\Annkathrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Annkathrin\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-10-10 29768376] Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk - c:\windows\system32\RunDll32.exe "c:\program files\HP\HP Deskjet 1000 J110 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN18P21MM105D2;CONNECTION=USB;MONITOR=1; [2009-7-14 44544] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880] R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736] R2 OpenVPNAccessClient;OpenVPN Access Client;c:\program files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe [2012-05-03 24064] R3 DozeSvc;Lenovo Doze Mode Service;c:\program files\ThinkPad\Utilities\DOZESVC.EXE [2012-05-16 280640] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2012-09-10 18432] R3 netr73;RT73 USB-Drahtlos-LAN-Kartentreiber für Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792] R3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2012-05-16 1662560] R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files\ThinkPad\Utilities\PWMEWSVC.EXE [2012-05-16 1665120] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] S0 DozeHDD;DozeHDD;c:\windows\System32\DRIVERS\DozeHDD.sys [2012-05-16 25416] S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2012-09-06 20328] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-04-07 37352] S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2010-09-07 13680] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2013-10-10 120088] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-09-05 84024] S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2011-07-12 127336] S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 131432] S2 TPHKSVC;Anzeige am Bildschirm;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2011-07-12 142696] S3 NETwLv32; Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows Vista 32-Bit;c:\windows\system32\DRIVERS\NETwLv32.sys [2010-10-07 6639616] S3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [2011-08-18 26112] S3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [2009-11-24 23152] . . Inhalt des "geplante Tasks" Ordners . 2013-10-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-07 19:43] . . ------- Zusätzlicher Suchlauf ------- . IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.3.3.1 TCP: Interfaces\{15968169-5F7E-4282-BF24-96A7B6A87BA0}: DhcpNameServer = 192.168.0.254 FF - ProfilePath - c:\users\Annkathrin\AppData\Roaming\Mozilla\Firefox\Profiles\lt0n7xre.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-SYHMR - c:\users\Annkathrin\AppData\Roaming\ReAgentr.dll c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\OpenVPN Connect.lnk - c:\program files\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-10-20 12:58:15 ComboFix-quarantined-files.txt 2013-10-20 10:58 . Vor Suchlauf: 9 Verzeichnis(se), 42.975.473.664 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 43.735.244.800 Bytes frei . - - End Of File - - D8864F1F96C9960033CC35A4F9BFBCFB A36C5E4F47E84449FF07ED3517B43A31 |
20.10.2013, 12:09 | #6 |
/// TB-Ausbilder | ihavenet Befall? Servus, wirst du immer noch umgeleitet? wir kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Schritt 1 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
20.10.2013, 14:09 | #7 |
| ihavenet Befall? Wurde jetzt nicht mehr umgeleitet! Toll danke!!!! Hier das Ergebnis aus Schritt 1: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.20.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16721 Annkathrin :: CLIENT-PC [Administrator] 20.10.2013 13:36:00 mbam-log-2013-10-20 (13-36-00).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 244333 Laufzeit: 7 Minute(n), 36 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3dcd606b8ccc784797f0654447b6f838 # engine=15551 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-20 08:03:12 # local_time=2013-10-20 10:03:12 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 4297 247679482 0 0 # compatibility_mode=5893 16776574 100 94 8687801 133887383 0 0 # scanned=146532 # found=1 # cleaned=0 # scan_time=2864 sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="möglicherweise Variante von Win32/Ponmocup.AA Trojaner" ac=I fn="${Memory}" ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3dcd606b8ccc784797f0654447b6f838 # engine=15554 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-20 12:56:52 # local_time=2013-10-20 02:56:52 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 21917 247697102 14692 0 # compatibility_mode=5893 16776574 100 94 8705421 133905003 0 0 # scanned=143310 # found=0 # cleaned=0 # scan_time=2688 Code:
ATTFilter Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` SUPERAntiSpyware Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 25 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader XI Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
21.10.2013, 13:02 | #8 |
/// TB-Ausbilder | ihavenet Befall? Servus, nochmal kurz FRST bitte ausführen: Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. |
24.10.2013, 18:34 | #9 |
/// TB-Ausbilder | ihavenet Befall? Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu ihavenet Befall? |
andere, anderen, avira, befall, compu, folge, folgendes, forum, frage, fragen, freue, googlesuche, immernoch, mozilla, problem, programme, programmen, seite, seiten, seltsame, starte, tagen, versucht, virus, würde |