|
Plagegeister aller Art und deren Bekämpfung: Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.11.2013, 13:49 | #1 |
| Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" Moin, ich habe seit eben gerade das Problem, dass mein Netbook sich wohl diesen Trojaner eingefangen hat, bei dem der Bildschirm erst kurz weiß wird und dann die Meldung kommt, dass der Bundesnachrichtendienst und andere Institutionen diesen gesperrt haben. Ich soll 100 Euro zahlen, damit der Bildschirm wieder frei gegeben wird. Bevor das passiert ist, wurde plötzlich ein Fenster angezeigt: Welche Videoquelle wollen Sie wählen? (oder so ähnlich). Ich habe gar nicht richitg hingeguckt und auf "abbrechen" gedrückt, dann wurde es weiß. Ich hoffe, ihr könnt mir helfen. Leider habe ich persönlich nicht viel Ahnung von Computern und so. Danke schonmal! |
09.11.2013, 17:35 | #2 |
/// the machine /// TB-Ausbilder | Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" hi,
__________________Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ |
09.11.2013, 20:15 | #3 |
| Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst"FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by SYSTEM on MININT-LCALH02 on 09-11-2013 20:05:39 Running from G:\ Windows 7 Starter (X86) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9914984 2010-11-30] (Realtek Semiconductor) HKLM\...\Run: [Norton Online Backup] - C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe [966488 2010-05-31] (Symantec Corporation) HKLM\...\Run: [Microsoft Default Manager] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-09] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1770792 2010-05-20] (Synaptics Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [DivXUpdate] - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-11] (Oracle Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-07] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.) HKU\home\...\Run: [Spotify Web Helper] - C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [ 2013-10-18] (Spotify Ltd) HKU\home\...\Run: [Spotify] - C:\Users\home\AppData\Roaming\Spotify\spotify.exe [ 2013-10-18] (Spotify Ltd) HKU\home\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [ 2013-09-04] (Samsung) HKU\home\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup HKU\home\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [ 2013-09-04] (Samsung) Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe () ========================== Services (Whitelisted) ================= S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-07] (Avira Operations GmbH & Co. KG) S2 NOBU; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2057560 2010-05-31] (Symantec Corporation) S3 Samsung UPD Service; C:\windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.) ==================== Drivers (Whitelisted) ==================== S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-07] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-07] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) S3 BTWAMPFL; C:\Windows\System32\DRIVERS\btwampfl.sys [300584 2010-09-20] (Broadcom Corporation.) S1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2009-05-27] (SAMSUNG ELECTRONICS) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) S3 dgderdrv; System32\drivers\dgderdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-09 13:05 - 2013-11-09 13:05 - 00000000 ____D C:\FRST 2013-10-29 14:28 - 2013-10-31 05:14 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-21 06:17 - 2013-10-21 06:17 - 00841951 _____ C:\Users\home\Desktop\postbank.node21 2013-10-16 08:33 - 2013-10-16 08:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-16 08:31 - 2013-10-16 08:45 - 00000000 ____D C:\Users\home\Handy 2013-10-16 08:27 - 2013-10-16 08:35 - 00000000 ____D C:\Users\home\Documents\SelfMV 2013-10-16 08:12 - 2013-10-16 08:12 - 00000000 ____H C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2013-10-16 07:59 - 2013-06-20 16:07 - 01418432 _____ (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01005.dll 2013-10-16 07:59 - 2013-06-20 16:07 - 01418432 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\WdfCoInstaller01005.dll 2013-10-16 07:59 - 2013-06-20 16:07 - 00153672 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadmdm.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00136904 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadbus.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00130248 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadserd.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00032064 _____ (Google Inc) C:\Windows\System32\Drivers\ssadadb.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00017864 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadmdfl.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00015560 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadcmnt.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00015560 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadcm.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00015304 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadwhnt.sys 2013-10-16 07:59 - 2013-06-20 16:07 - 00015304 _____ (MCCI Corporation) C:\Windows\System32\Drivers\ssadwh.sys 2013-10-16 07:49 - 2013-10-16 07:49 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-10-16 07:48 - 2013-10-16 07:48 - 00000000 ____D C:\Users\home\Documents\samsung 2013-10-16 07:48 - 2013-10-16 07:48 - 00000000 ____D C:\Users\home\AppData\Roaming\Samsung 2013-10-16 07:48 - 2013-10-16 07:48 - 00000000 ____D C:\Users\home\AppData\Local\Samsung 2013-10-16 07:41 - 2013-10-16 07:41 - 00000000 ____D C:\Program Files\MyFree Codec 2013-10-16 07:36 - 2013-07-18 04:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\System32\Redemption.dll 2013-10-16 07:35 - 2013-07-18 04:32 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\System32\dgderapi.dll ==================== One Month Modified Files and Folders ======= 2013-11-09 13:05 - 2013-11-09 13:05 - 00000000 ____D C:\FRST 2013-11-09 04:33 - 2009-07-13 20:34 - 00010272 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-09 04:33 - 2009-07-13 20:34 - 00010272 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-09 04:27 - 2011-01-05 22:40 - 01746307 _____ C:\Windows\WindowsUpdate.log 2013-11-09 04:27 - 2009-07-26 12:06 - 01500294 _____ C:\Windows\System32\PerfStringBackup.INI 2013-11-09 04:23 - 2012-03-13 09:14 - 00000000 ____D C:\Users\home\AppData\Roaming\Spotify 2013-11-09 04:22 - 2012-12-18 02:52 - 00000000 ___RD C:\Users\home\Dropbox 2013-11-09 04:22 - 2012-12-18 02:44 - 00000000 ____D C:\Users\home\AppData\Roaming\Dropbox 2013-11-09 04:18 - 2009-07-13 20:39 - 00069352 _____ C:\Windows\setupact.log 2013-11-07 16:16 - 2012-10-29 14:04 - 00000000 ____D C:\Users\home\Documents\Youcam 2013-11-05 11:44 - 2012-03-13 09:15 - 00000000 ____D C:\Users\home\AppData\Local\Spotify 2013-11-05 07:03 - 2012-05-16 09:03 - 00000000 ____D C:\Users\home\AppData\Local\CrashDumps 2013-11-03 13:42 - 2012-12-18 02:52 - 00000976 _____ C:\Users\home\Desktop\Dropbox.lnk 2013-11-03 13:21 - 2012-05-07 12:21 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-31 05:14 - 2013-10-29 14:28 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-28 14:42 - 2011-12-01 08:45 - 00000000 ____D C:\Users\home\Desktop\Studium 2013-10-21 06:17 - 2013-10-21 06:17 - 00841951 _____ C:\Users\home\Desktop\postbank.node21 2013-10-16 08:45 - 2013-10-16 08:31 - 00000000 ____D C:\Users\home\Handy 2013-10-16 08:35 - 2013-10-16 08:27 - 00000000 ____D C:\Users\home\Documents\SelfMV 2013-10-16 08:33 - 2013-10-16 08:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-16 08:32 - 2011-11-26 06:54 - 00000000 ____D C:\users\home 2013-10-16 08:12 - 2013-10-16 08:12 - 00000000 ____H C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2013-10-16 07:51 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-16 07:49 - 2013-10-16 07:49 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-10-16 07:48 - 2013-10-16 07:48 - 00000000 ____D C:\Users\home\Documents\samsung 2013-10-16 07:48 - 2013-10-16 07:48 - 00000000 ____D C:\Users\home\AppData\Roaming\Samsung 2013-10-16 07:48 - 2013-10-16 07:48 - 00000000 ____D C:\Users\home\AppData\Local\Samsung 2013-10-16 07:43 - 2011-01-05 22:49 - 00000000 ____D C:\Program Files\Samsung 2013-10-16 07:41 - 2013-10-16 07:41 - 00000000 ____D C:\Program Files\MyFree Codec 2013-10-16 07:41 - 2011-01-05 22:57 - 00000000 ____D C:\ProgramData\SAMSUNG 2013-10-16 07:39 - 2012-04-14 10:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-10-16 07:39 - 2011-11-26 10:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-10-16 07:35 - 2011-01-05 22:38 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-16 07:30 - 2011-12-29 09:00 - 00000000 ____D C:\Users\home\AppData\Local\Downloaded Installations 2013-10-16 06:28 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\NDF 2013-10-13 08:33 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache 2013-10-10 08:08 - 2009-07-13 20:33 - 00285496 _____ C:\Windows\System32\FNTCACHE.DAT 2013-10-10 08:06 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE 2013-10-10 08:03 - 2011-01-06 00:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight Some content of TEMP: ==================== C:\Users\home\AppData\Local\Temp\AskSLib.dll C:\Users\home\AppData\Local\Temp\avgnt.exe C:\Users\home\AppData\Local\Temp\InstallAX.exe C:\Users\home\AppData\Local\Temp\install_flash_player_11_active_x_32bit.exe C:\Users\home\AppData\Local\Temp\install_flash_player_11_active_x_64bit.exe C:\Users\home\AppData\Local\Temp\install_flash_player_32bit.exe C:\Users\home\AppData\Local\Temp\install_flash_player_64bit.exe C:\Users\home\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\home\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\home\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\home\AppData\Local\Temp\teeusmidngxxngmlahdeutfj.exe C:\Users\home\AppData\Local\Temp\WmpPluginSetup_2.1.0.6.exe ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 38% Total physical RAM: 1013.3 MB Available physical RAM: 619.27 MB Total Pagefile: 1013.3 MB Available Pagefile: 623.89 MB Total Virtual: 2047.88 MB Available Virtual: 1947.12 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:87 GB) (Free:9.05 GB) NTFS Drive d: () (Fixed) (Total:128.85 GB) (Free:128.75 GB) NTFS Drive f: (SAMSUNG_REC) (Fixed) (Total:16.93 GB) (Free:0.47 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive g: (Intenso) (Removable) (Total:3.75 GB) (Free:2.46 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: C8210F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=87 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=129 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=17 GB) - (Type=27) ======================================================== Disk: 1 (Size: 4 GB) (Disk ID: 61F9514E) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) LastRegBack: 2013-10-22 01:28 ==================== End Of Log ============================ |
10.11.2013, 07:32 | #4 |
/// the machine /// TB-Ausbilder | Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe () C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Rechner normal starten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.11.2013, 10:50 | #5 |
| Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst"Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 31-10-2013 Ran by SYSTEM at 2013-11-10 10:48:40 Run:2 Running from G:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe () C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe ***************** C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe => Moved successfully. "C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Other.exe" => File/Directory not found. ==== End of Fixlog ==== |
10.11.2013, 16:04 | #6 |
/// the machine /// TB-Ausbilder | Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" Startet der Rechner normal?
__________________ --> Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" |
10.11.2013, 17:35 | #7 |
| Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" JA super, danke!! |
11.11.2013, 10:00 | #8 |
/// the machine /// TB-Ausbilder | Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" Kontrollscans im normalen Modus: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.11.2013, 12:18 | #9 |
| Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" malwarebytes Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.11.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16721 home :: YANNICK-PC [Administrator] 11.11.2013 10:21:15 mbam-log-2013-11-11 (10-21-15).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 206418 Laufzeit: 38 Minute(n), 13 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 5 C:\Users\home\AppData\Roaming\Other.res (Trojan.Ransom.BV) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\home\AppData\Local\Temp\0i5i8N9N.exe.part (PUP.Optional.Vid) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\home\AppData\Local\Temp\teeusmidngxxngmlahdeutfj.exe (Trojan.Ransom.BV) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\home\AppData\Local\Temp\Z5nv1X+u.exe.part (PUP.Optional.Bandoo) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\home\Downloads\SoftonicDownloader_fuer_seterra.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleaner Code:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 11/11/2013 um 11:23:15 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzername : home - YANNICK-PC # Gestartet von : C:\Users\home\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files\myfree codec Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Users\home\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\home\AppData\Roaming\dvdvideosoftiehelpers ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_seterra_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_seterra_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v25.0 (de) [ Datei : C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\2bhkq9ra.default\prefs.js ] ************************* AdwCleaner[R0].txt - [2969 octets] - [11/11/2013 11:18:44] AdwCleaner[S0].txt - [2900 octets] - [11/11/2013 11:23:15] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2960 octets] ########## JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Starter x86 Ran by home on 11.11.2013 at 11:34:40,58 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\windows\system32\sho30B3.tmp ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\home\AppData\Roaming\mozilla\firefox\profiles\2bhkq9ra.default\minidumps [198 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.11.2013 at 11:42:10,01 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST frst.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013 01 Ran by home (administrator) on YANNICK-PC on 11-11-2013 11:54:25 Running from C:\Users\home\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Symantec Corporation) C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (CyberLink) C:\Program Files\CyberLink\YouCam\YCMMirage.exe (Spotify Ltd) C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\home\AppData\Roaming\Spotify\spotify.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe (Dropbox, Inc.) C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (SEC) C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe () C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Samsung Electronics) C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Intel Corporation) C:\windows\system32\igfxext.exe (Microsoft Corporation) C:\windows\system32\wuauclt.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9914984 2010-12-01] (Realtek Semiconductor) HKLM\...\Run: [Norton Online Backup] - C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe [966488 2010-06-01] (Symantec Corporation) HKLM\...\Run: [Microsoft Default Manager] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1770792 2010-05-20] (Synaptics Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [DivXUpdate] - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-07] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.) HKCU\...\Run: [Spotify Web Helper] - C:\Users\home\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-10-18] (Spotify Ltd) HKCU\...\Run: [Spotify] - C:\Users\home\AppData\Roaming\Spotify\spotify.exe [4752384 2013-10-18] (Spotify Ltd) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung) Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ecosia.org/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com SearchScopes: HKLM - DefaultScope value is missing. BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll No File BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - @C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\2bhkq9ra.default FF Homepage: hxxp://www.ecosia.org/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @Microsoft.com/NpWinExt,version=5.0 - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\2bhkq9ra.default\searchplugins\ecosia.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\2bhkq9ra.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF HKLM\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\Firefox FF Extension: Bing Bar - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\Firefox FF HKLM\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ FF Extension: Search Helper Extension - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ FF HKLM\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ FF Extension: Default Manager - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-07] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-10-07] (Avira Operations GmbH & Co. KG) R2 NOBU; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2057560 2010-06-01] (Symantec Corporation) S3 Samsung UPD Service; C:\windows\System32\SUPDSvc.exe [131888 2010-08-09] (Samsung Electronics CO., LTD.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-07] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R3 BTWAMPFL; C:\Windows\System32\DRIVERS\btwampfl.sys [300584 2010-09-21] (Broadcom Corporation.) R1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2009-05-28] (SAMSUNG ELECTRONICS) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) S3 dgderdrv; System32\drivers\dgderdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-11 11:53 - 2013-11-11 11:53 - 01090275 _____ (Farbar) C:\Users\home\Desktop\FRST.exe 2013-11-11 11:42 - 2013-11-11 11:42 - 00000815 _____ C:\Users\home\Desktop\JRT.txt 2013-11-11 11:34 - 2013-11-11 11:34 - 00000000 ____D C:\windows\ERUNT 2013-11-11 11:32 - 2013-11-11 11:32 - 01034531 _____ (Thisisu) C:\Users\home\Desktop\JRT.exe 2013-11-11 11:27 - 2013-11-11 11:27 - 00003040 _____ C:\Users\home\Desktop\AdwCleaner[S0].txt 2013-11-11 11:18 - 2013-11-11 11:23 - 00000000 ____D C:\AdwCleaner 2013-11-11 11:16 - 2013-11-11 11:16 - 01085542 _____ C:\Users\home\Desktop\adwcleaner.exe 2013-11-11 11:09 - 2013-11-11 11:09 - 00000000 ____D C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte 2013-11-11 10:18 - 2013-11-11 10:18 - 00000000 ____D C:\Users\home\AppData\Roaming\Malwarebytes 2013-11-11 10:17 - 2013-11-11 10:17 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-11 10:17 - 2013-11-11 10:17 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-11 10:17 - 2013-11-11 10:17 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-11 10:17 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-11-11 10:15 - 2013-11-11 10:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\home\Desktop\mbam-setup-1.75.0.1300.exe 2013-11-09 22:05 - 2013-11-09 22:05 - 00000000 ____D C:\FRST 2013-10-29 23:28 - 2013-10-31 14:14 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-21 15:17 - 2013-10-21 15:17 - 00841951 _____ C:\Users\home\Desktop\postbank.node21 2013-10-16 17:33 - 2013-10-16 17:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-16 17:31 - 2013-10-16 17:45 - 00000000 ____D C:\Users\home\Handy 2013-10-16 17:27 - 2013-10-16 17:35 - 00000000 ____D C:\Users\home\Documents\SelfMV 2013-10-16 17:12 - 2013-10-16 17:12 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2013-10-16 16:59 - 2013-06-21 01:07 - 01418432 _____ (Microsoft Corporation) C:\windows\system32\WdfCoInstaller01005.dll 2013-10-16 16:59 - 2013-06-21 01:07 - 01418432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfCoInstaller01005.dll 2013-10-16 16:59 - 2013-06-21 01:07 - 00153672 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadmdm.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00136904 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadbus.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00130248 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadserd.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00032064 _____ (Google Inc) C:\windows\system32\Drivers\ssadadb.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00017864 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadmdfl.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00015560 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadcmnt.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00015560 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadcm.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00015304 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadwhnt.sys 2013-10-16 16:59 - 2013-06-21 01:07 - 00015304 _____ (MCCI Corporation) C:\windows\system32\Drivers\ssadwh.sys 2013-10-16 16:49 - 2013-10-16 16:49 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-10-16 16:48 - 2013-10-16 16:48 - 00000000 ____D C:\Users\home\Documents\samsung 2013-10-16 16:48 - 2013-10-16 16:48 - 00000000 ____D C:\Users\home\AppData\Roaming\Samsung 2013-10-16 16:48 - 2013-10-16 16:48 - 00000000 ____D C:\Users\home\AppData\Local\Samsung 2013-10-16 16:36 - 2013-07-18 13:33 - 04659712 _____ (Dmitry Streblechenko) C:\windows\system32\Redemption.dll 2013-10-16 16:35 - 2013-07-18 13:32 - 00821824 _____ (Devguru Co., Ltd.) C:\windows\system32\dgderapi.dll ==================== One Month Modified Files and Folders ======= 2013-11-11 11:53 - 2013-11-11 11:53 - 01090275 _____ (Farbar) C:\Users\home\Desktop\FRST.exe 2013-11-11 11:42 - 2013-11-11 11:42 - 00000815 _____ C:\Users\home\Desktop\JRT.txt 2013-11-11 11:41 - 2009-07-14 05:34 - 00010272 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-11 11:41 - 2009-07-14 05:34 - 00010272 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-11 11:39 - 2012-10-12 08:58 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-11-11 11:35 - 2012-03-13 18:14 - 00000000 ____D C:\Users\home\AppData\Roaming\Spotify 2013-11-11 11:35 - 2011-01-06 07:40 - 01808857 _____ C:\windows\WindowsUpdate.log 2013-11-11 11:34 - 2013-11-11 11:34 - 00000000 ____D C:\windows\ERUNT 2013-11-11 11:32 - 2013-11-11 11:32 - 01034531 _____ (Thisisu) C:\Users\home\Desktop\JRT.exe 2013-11-11 11:28 - 2012-12-18 11:52 - 00000000 ___RD C:\Users\home\Dropbox 2013-11-11 11:28 - 2012-12-18 11:44 - 00000000 ____D C:\Users\home\AppData\Roaming\Dropbox 2013-11-11 11:27 - 2013-11-11 11:27 - 00003040 _____ C:\Users\home\Desktop\AdwCleaner[S0].txt 2013-11-11 11:25 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-11 11:25 - 2009-07-14 05:39 - 00069520 _____ C:\windows\setupact.log 2013-11-11 11:23 - 2013-11-11 11:18 - 00000000 ____D C:\AdwCleaner 2013-11-11 11:16 - 2013-11-11 11:16 - 01085542 _____ C:\Users\home\Desktop\adwcleaner.exe 2013-11-11 11:12 - 2009-07-26 21:06 - 01500294 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-11 11:09 - 2013-11-11 11:09 - 00000000 ____D C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte 2013-11-11 11:09 - 2012-03-13 18:15 - 00000000 ____D C:\Users\home\AppData\Local\Spotify 2013-11-11 11:05 - 2011-11-21 09:17 - 00416820 _____ C:\windows\PFRO.log 2013-11-11 11:05 - 2009-07-14 05:52 - 00000000 ____D C:\windows\Performance 2013-11-11 10:18 - 2013-11-11 10:18 - 00000000 ____D C:\Users\home\AppData\Roaming\Malwarebytes 2013-11-11 10:17 - 2013-11-11 10:17 - 00001071 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-11 10:17 - 2013-11-11 10:17 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-11 10:17 - 2013-11-11 10:17 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-11 10:15 - 2013-11-11 10:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\home\Desktop\mbam-setup-1.75.0.1300.exe 2013-11-10 19:52 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\LogFiles 2013-11-09 22:05 - 2013-11-09 22:05 - 00000000 ____D C:\FRST 2013-11-08 01:16 - 2012-10-29 23:04 - 00000000 ____D C:\Users\home\Documents\Youcam 2013-11-05 16:03 - 2012-05-16 18:03 - 00000000 ____D C:\Users\home\AppData\Local\CrashDumps 2013-11-03 22:42 - 2012-12-18 11:52 - 00000976 _____ C:\Users\home\Desktop\Dropbox.lnk 2013-11-03 22:42 - 2012-12-18 11:45 - 00000000 ____D C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-11-03 22:21 - 2012-05-07 21:21 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-31 14:14 - 2013-10-29 23:28 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-28 23:42 - 2011-12-01 17:45 - 00000000 ____D C:\Users\home\Desktop\Studium 2013-10-21 15:17 - 2013-10-21 15:17 - 00841951 _____ C:\Users\home\Desktop\postbank.node21 2013-10-16 17:45 - 2013-10-16 17:31 - 00000000 ____D C:\Users\home\Handy 2013-10-16 17:35 - 2013-10-16 17:27 - 00000000 ____D C:\Users\home\Documents\SelfMV 2013-10-16 17:33 - 2013-10-16 17:33 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-16 17:32 - 2011-11-26 15:54 - 00000000 ____D C:\Users\home 2013-10-16 17:12 - 2013-10-16 17:12 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2013-10-16 16:51 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-10-16 16:49 - 2013-10-16 16:49 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-10-16 16:48 - 2013-10-16 16:48 - 00000000 ____D C:\Users\home\Documents\samsung 2013-10-16 16:48 - 2013-10-16 16:48 - 00000000 ____D C:\Users\home\AppData\Roaming\Samsung 2013-10-16 16:48 - 2013-10-16 16:48 - 00000000 ____D C:\Users\home\AppData\Local\Samsung 2013-10-16 16:43 - 2011-01-06 07:49 - 00000000 ____D C:\Program Files\Samsung 2013-10-16 16:41 - 2011-01-06 07:57 - 00000000 ____D C:\ProgramData\SAMSUNG 2013-10-16 16:39 - 2012-04-14 19:50 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2013-10-16 16:39 - 2011-11-26 19:09 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2013-10-16 16:35 - 2011-01-06 07:38 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-16 16:30 - 2011-12-29 18:00 - 00000000 ____D C:\Users\home\AppData\Local\Downloaded Installations 2013-10-16 15:28 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF 2013-10-13 17:33 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache Some content of TEMP: ==================== C:\Users\home\AppData\Local\Temp\AskSLib.dll C:\Users\home\AppData\Local\Temp\avgnt.exe C:\Users\home\AppData\Local\Temp\InstallAX.exe C:\Users\home\AppData\Local\Temp\install_flash_player_11_active_x_32bit.exe C:\Users\home\AppData\Local\Temp\install_flash_player_11_active_x_64bit.exe C:\Users\home\AppData\Local\Temp\install_flash_player_32bit.exe C:\Users\home\AppData\Local\Temp\install_flash_player_64bit.exe C:\Users\home\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\home\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\home\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\home\AppData\Local\Temp\Quarantine.exe C:\Users\home\AppData\Local\Temp\WmpPluginSetup_2.1.0.6.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-22 10:28 ==================== End Of Log ============================ --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10-11-2013 01 Ran by home at 2013-11-11 11:56:37 Running from C:\Users\home\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== „Messenger“ pagalbinė priemonė (Version: 15.4.3502.0922) „Windows Live Essentials“ (Version: 15.4.3502.0922) „Windows Live Mail“ (Version: 15.4.3502.0922) „Windows Live Messenger“ (Version: 15.4.3502.0922) „Windows Live“ fotogalerija (Version: 15.4.3502.0922) 2XL Games Launcher (Version: 1.00.0000) 2XL Supercross (Version: 1.00.0000) 2XL Trophylite Rally (Version: 1.00.0000) Adobe Flash Player 11 ActiveX (Version: 11.9.900.117) Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8) Alice Greenfingers Atheros Client Installation Program (Version: 9.0) Avira Free Antivirus (Version: 14.0.0.383) BatteryLifeExtender (Version: 1.0.11) Bing Bar (Version: 6.0.2282.0) Bing Bar Platform (Version: 6.0.2282.0) Bing Rewards Client Installer (Version: 16.0.345.0) Bonbon Quest Broadcom 802.11 Network Adapter (Version: 5.60.48.55) Cake Mania ChargeableUSB (Version: 1.0.0.0) Complément Messenger (Version: 15.4.3502.0922) Complemento Messenger (Version: 15.4.3502.0922) CyberLink YouCam (Version: 3.1.3509) D3DX10 (Version: 15.4.2368.0902) Daycare Nightmare DivX-Setup (Version: 2.6.1.5) Doplnok programu Messenger (Version: 15.4.3502.0922) Dropbox (HKCU Version: 2.4.6) Easy Content Share (Version: 1.0) Easy Display Manager (Version: 3.2) Easy Network Manager (Version: 4.4.7) Easy Resolution Manager (Version: 1.1.0) Easy SpeedUp Manager (Version: 2.1.1.1) EasyBatteryManager (Version: 4.0.0.4) EasyFileShare (Version: 1.0.12) Fast Start (Version: 2.2.0.1) Flip Words Fotogalerija Windows Live (Version: 15.4.3502.0922) Free Studio version 5.7.7.1031 (Version: 5.7.7.1031) Galapago Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922) Galería fotográfica de Windows Live (Version: 15.4.3502.0922) Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922) Galerie de photos Windows Live (Version: 15.4.3502.0922) Galerie foto Windows Live (Version: 15.4.3502.0922) Game Pack (Version: 6.3.1.1) Gem Shop Insaniquarium Deluxe Intel(R) Graphics Media Accelerator Driver (Version: 8.14.10.2117) Intel® Matrix Storage Manager Java 7 Update 21 (Version: 7.0.210) Java Auto Updater (Version: 2.1.9.5) Junk Mail filter update (Version: 15.4.3502.0922) Mahjong Escape Ancient China Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Media Go (Version: 2.0.317) Mesh Runtime (Version: 15.4.5722.2) Messenger Assistent (Version: 15.4.3502.0922) Messenger Companion (Version: 15.4.3502.0922) Messenger kísérő (Version: 15.4.3502.0922) Messenger Pratilac (Version: 15.4.3502.0922) Messenger Suradnik (Version: 15.4.3502.0922) Messenger 사이트 공유 (Version: 15.4.3502.0922) Messenger 分享元件 (Version: 15.4.3502.0922) Messenger 浏览器插件 (Version: 15.4.3502.0922) Messenger-kumppani (Version: 15.4.3502.0922) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Default Manager (Version: 2.2.114.0) Microsoft Office 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (Version: 14.0.4763.1000) Microsoft PowerPoint Viewer (Version: 14.0.6029.1000) Microsoft Search Enhancement Pack (Version: 3.0.131.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable - KB2467175 (Version: 8.0.51011) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Movie Color Enhancer (Version: 1.0) Mozilla Firefox 25.0 (x86 de) (Version: 25.0) Mozilla Maintenance Service (Version: 25.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Norton Online Backup (Version: 2.1.17869) NWZ-S760 WALKMAN Guide (Version: 2.0.2.04130) OpenOffice.org 3.4.1 (Version: 3.41.9593) PhoneShare (Version: 9.0.1) PlayStation(R)Network Downloader (Version: 2.07.00849) PlayStation(R)Store (Version: 4.5.16.13625) Poczta usługi Windows Live (Version: 15.4.3502.0922) Podstawowe programy Windows Live (Version: 15.4.3502.0922) Pomocnik Messenger (Version: 15.4.3502.0922) Pošta Windows Live (Version: 15.4.3502.0922) Raccolta foto di Windows Live (Version: 15.4.3502.0922) Realtek Ethernet Controller Driver (Version: 7.33.1125.2010) Realtek High Definition Audio Driver (Version: 6.0.1.6257) Samsung AnyWeb Print (Version: 1.0) Samsung AnyWeb Print (Version: 1.1.21.0) Samsung Kies (Version: 2.6.0.13091_9) Samsung Recovery Solution 5 (Version: 5.0.0.8) Samsung Support Center (Version: 1.1.21) Samsung Universal Print Driver (Version: 2.01.06.00:16) Samsung Universal Scan Driver (Version: 1.2.1.0) Samsung Update Plus (Version: 3.0.0.17) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Skype™ 5.10 (Version: 5.10.116) Slingo Spotify (HKCU Version: 0.9.4.185.g7545a404) Spremljevalec Messenger (Version: 15.4.3502.0922) SRS Premium Sound Control Panel (Version: 1.10.1000) Synaptics Pointing Device Driver (Version: 15.0.22.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) User Guide (Version: 1.0) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0) VLC media player 1.1.11 (Version: 1.1.11) WIDCOMM Bluetooth Software (Version: 6.3.0.7000) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live fotoattēlu galerija (Version: 15.4.3502.0922) Windows Live Fotogaléria (Version: 15.4.3502.0922) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live Foto-galerija (Version: 15.4.3502.0922) Windows Live Fotogalleri (Version: 15.4.3502.0922) Windows Live Fotoğraf Galerisi (Version: 15.4.3502.0922) Windows Live Fotótár (Version: 15.4.3502.0922) Windows Live Galeria de Fotos (Version: 15.4.3502.0922) Windows Live Galerija fotografija (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live Mesh (Version: 15.4.3502.0922) Windows Live Messenger (Version: 15.4.3502.0922) Windows Live Messenger Companion Core (Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3502.0922) Windows Live Pošta (Version: 15.4.3502.0922) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Temel Parçalar (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3502.0922) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Live 메일 (Version: 15.4.3502.0922) Windows Live 사진 갤러리 (Version: 15.4.3502.0922) Windows Live 필수 패키지 (Version: 15.4.3502.0922) Windows Live 影像中心 (Version: 15.4.3502.0922) Windows Live 照片库 (Version: 15.4.3502.0922) Windows Live 程式集 (Version: 15.4.3502.0922) Windows Live 软件包 (Version: 15.4.3502.0922) Windows Liven asennustyökalu (Version: 15.4.3502.0922) Windows Liven sähköposti (Version: 15.4.3502.0922) Windows Liven valokuvavalikoima (Version: 15.4.3502.0922) WinRAR 4.01 (32-Bit) (Version: 4.01.0) WordCaptureX Pro (Version: 4.0.0) Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922) Компаньон Messenger (Version: 15.4.3502.0922) Основные компоненты Windows Live (Version: 15.4.3502.0922) Помощник на Messenger (Version: 15.4.3502.0922) Почта Windows Live (Version: 15.4.3502.0922) Фотоальбом Windows Live (Version: 15.4.3502.0922) Фотогалерия на Windows Live (Version: 15.4.3502.0922) גלריית התמונות של Windows Live (Version: 15.4.3502.0922) מסייע Messenger (Version: 15.4.3502.0922) بريد Windows Live (Version: 15.4.3502.0922) معرض صور Windows Live (Version: 15.4.3502.0922) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {07C6D95A-207F-4578-9DDF-9CA24CF75A4E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {0ADCC74E-988D-4E08-BDAC-7287C0C43C9F} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.) Task: {1253A645-A1AB-4E76-8324-4FEB83806BA9} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-23] (Samsung Electronics Co., Ltd.) Task: {2E9669F6-29FB-4B8F-A461-23720B681426} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics) Task: {339C0E55-02B7-42AB-AF00-87719D7749E5} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe [2010-11-29] (SRS Labs, Inc.) Task: {62545B81-44A4-49FB-B30B-0D104CF21547} - System32\Tasks\MovieColorEnhancer => C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-11-29] (Samsung Electronics Co., Ltd.) Task: {77DA6861-B5F8-4034-92C6-7F0A00585590} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-16] (Adobe Systems Incorporated) Task: {787A967C-73D0-432F-AB22-6B4B515B9BDB} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-11-23] (SAMSUNG Electronics) Task: {896D83FB-3F42-4318-A742-6E0D58DD1E44} - System32\Tasks\IdlePowerSave => C:\Windows\Idle\DetectIdleTask.exe [2010-07-31] (TODO: <회사 이름>) Task: {8AE339A9-9C20-49A4-8F62-51E75F84C8D4} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {9A4560BF-0D3F-41AC-AE84-B24DC3A6E9FE} - System32\Tasks\EasySpeedUpManager => C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [2010-02-10] (Samsung Electronics Co., Ltd.) Task: {AD743FA6-78DA-4D48-B12C-6D1D45018CCD} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-18] (Samsung Electronics. Co. Ltd.) Task: {AE4F5993-4ED8-45E0-B7DC-1906C914B8E3} - System32\Tasks\advSRS5 => C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC) Task: {C89E64DC-1123-41E3-B260-3432DF7F870F} - System32\Tasks\WifiManager => C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe [2011-01-04] (Samsung Electronics Co., Ltd.) Task: {D8D0160E-1AB6-4309-8DB1-C80AD4AF5DD3} - System32\Tasks\MirageAgent => C:\Program Files\CyberLink\YouCam\YCMMirage.exe [2010-11-10] (CyberLink) Task: {E43A9534-00C9-4B16-B5C6-194C0862F420} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2011-01-06 08:14 - 2010-07-05 11:42 - 00203776 _____ () C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll 2011-01-06 07:56 - 2006-08-12 04:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2012-03-13 18:14 - 2013-10-18 10:09 - 34604032 _____ () C:\Users\home\AppData\Roaming\Spotify\Data\libcef.dll 2013-10-16 16:46 - 2013-10-16 16:46 - 01924608 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\bee88fd68a7fbf826e5b13f7d8d90aca\Kies.UI.ni.dll 2013-10-16 16:46 - 2013-10-16 16:46 - 00079360 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\40e1d3d166754a0ee95587d5d7304414\Kies.MVVM.ni.dll 2013-10-16 16:47 - 2013-10-16 16:47 - 00189952 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\7932879d1006f45d6c5837c365ecbcf6\Kies.Common.DeviceServiceLib.Interface.ni.dll 2013-10-16 16:51 - 2013-10-16 16:51 - 00362496 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\b072044f4139d59fe42fef3e9b0bcd4d\DevicePhoto.ni.dll 2013-10-16 16:51 - 2013-10-16 16:51 - 00296960 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\742f94cc8e12d6f5d6f3067c379f5830\DeviceVideo.ni.dll 2013-10-16 16:51 - 2013-10-16 16:51 - 00612352 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\cfa2577a9e9acc5fe958f312a59a1c81\DevicePodcast.ni.dll 2013-10-16 16:51 - 2013-10-16 16:51 - 00307200 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\c001433d3ccb98bd9c3744d8d288d1c5\DummyStorePlugin.ni.dll 2013-10-16 16:51 - 2013-10-16 16:51 - 14972928 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\a0be2c714964d75270c37bd0e57182ee\Kies.Theme.ni.dll 2013-10-16 16:50 - 2013-10-16 16:50 - 00582144 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\a87a3ef65dabe86f36798af6830b7bdc\Kies.Common.DeviceServiceLib.FileService.ni.dll 2013-10-16 16:47 - 2013-10-16 16:47 - 00046592 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\129affa1c25fe7751026f37ac4441abe\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll 2013-10-16 16:49 - 2013-10-16 16:49 - 01002496 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\0a14014a110371a0911719ec4fd24fb2\DeviceCommonLib.ni.dll 2013-10-16 16:50 - 2013-10-16 16:50 - 00232960 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6c2268d21092027249488bb1b5b0b75f\ASF_cSharpAPI.ni.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\home\AppData\Roaming\Dropbox\bin\libcef.dll 2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files\OpenOffice.org 3\program\libxml2.dll 2011-01-06 07:54 - 2010-05-07 15:22 - 01636864 _____ () C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll 2013-09-23 13:03 - 2013-10-18 10:09 - 00747008 _____ () C:\Users\home\AppData\Roaming\Spotify\Data\libglesv2.dll 2013-09-23 13:03 - 2013-10-18 10:09 - 00137216 _____ () C:\Users\home\AppData\Roaming\Spotify\Data\libegl.dll 2013-10-29 23:28 - 2013-10-29 23:28 - 03368048 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 77% Total physical RAM: 1013.3 MB Available physical RAM: 224.96 MB Total Pagefile: 2037.3 MB Available Pagefile: 523.28 MB Total Virtual: 2047.88 MB Available Virtual: 1910.2 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:87 GB) (Free:8.72 GB) NTFS Drive d: () (Fixed) (Total:128.85 GB) (Free:128.75 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: C8210F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=87 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=129 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=17 GB) - (Type=27) ==================== End Of Log ============================ |
11.11.2013, 15:26 | #10 |
/// the machine /// TB-Ausbilder | Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst"ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Videoquelle wählen -> Bildschirm gesperrt durch "BundesNachrichtenDienst" |
abbrechen, ahnung, andere, angezeigt, bildschirm, bundesnachrichtendienst, computer, eingefangen, fenster, gefangen, gesperrt, meldung, netbook, plötzlich, problem, pup.optional.bandoo, pup.optional.softonic.a, pup.optional.vid, schonmal, trojan.ransom.bv, trojaner, zahlen, ähnlich |