![]() |
|
Log-Analyse und Auswertung: Gefunden PUP.Optional auf Win 8.1Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Gefunden PUP.Optional auf Win 8.1 Hallo, ich wollte mir im Inet ein Video mit meiner Tochter zusammen anschauen. Beim auf den Start Button des Videos, öffnete sich für ein paar Millisekunden ein neues Fenster. Lesen darin liess sich nichts, aber misstrauisch geworden liess ich Antimailwarebytes einen Quickscann durchführen. Und leider hat es auch etwas gefunden: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.09.07 Windows 8 x64 NTFS Internet Explorer 11.0.9600.16384 drah_000 :: ZOCKER [Administrator] 09.11.2013 21:32:16 mbam-log-2013-11-09 (21-32-16).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 240562 Laufzeit: 1 Minute(n), 33 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\$Recycle.Bin\S-1-5-21-2386030101-495244966-64776779-1001\$RAFP9NF.exe (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\drah_000\AppData\Local\Temp\ev+Iyloj.exe.part (PUP.Optional.Installrex) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\drah_000\AppData\Local\Temp\OCS\ocs_v7f.exe (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\drah_000\Downloads\freeripmp3-setup.exe (PUP.Optional.Spigot.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.09.07 Windows 8 x64 NTFS Internet Explorer 11.0.9600.16384 drah_000 :: ZOCKER [Administrator] 09.11.2013 21:46:22 mbam-log-2013-11-09 (21-46-22).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 375669 Laufzeit: 10 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Zusätzlich habe ich mir noch Mailwarebytes Anti Root Kit runtergeladen und laufen lassen: Code:
ATTFilter --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.07.0.1007 (c) Malwarebytes Corporation 2011-2012 OS version: 6.2.9200 Windows 8 x64 Account is Administrative Internet Explorer version: 11.0.9600.16384 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.400000 GHz Memory total: 8535478272, free: 6576439296 Downloaded database version: v2013.11.10.01 Downloaded database version: v2013.10.11.02 ======================================= Initializing... ------------ Kernel report ------------ 11/10/2013 10:14:24 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\iaStorA.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\SI3112.sys \SystemRoot\System32\drivers\SCSIPORT.SYS \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\drivers\SiWinAcc.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\DRIVERS\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\SiRemFil.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\aswVmm.sys \SystemRoot\System32\Drivers\aswRvrt.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \??\C:\WINDOWS\system32\drivers\aswSnx.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \??\C:\WINDOWS\system32\drivers\aswKbd.sys \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \??\C:\WINDOWS\system32\drivers\aswRdr2.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\aswNdisFlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\uim_vimx64.sys \SystemRoot\System32\Drivers\Uim_IMx64.sys \SystemRoot\System32\Drivers\UimFIO.SYS \SystemRoot\System32\drivers\uimx64.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\Drivers\dfsc.sys \??\C:\WINDOWS\system32\drivers\aswSP.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \??\C:\WINDOWS\system32\drivers\RzDxgk.sys \SystemRoot\system32\DRIVERS\nvlddmkm.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\ucx01000.sys \SystemRoot\System32\drivers\HECIx64.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\system32\DRIVERS\Rt630x64.sys \SystemRoot\system32\drivers\cmudaxp.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\intelppm.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\system32\drivers\nvvad64v.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\system32\drivers\nvhda64v.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_iaStorA.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\kbdhid.sys \SystemRoot\system32\drivers\RzFilter.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\system32\drivers\luafv.sys \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys \??\C:\Windows\system32\drivers\mbam.sys \??\C:\WINDOWS\system32\drivers\aswFsBlk.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \??\C:\Windows\system32\Drivers\SSPORT.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\mslldp.sys \SystemRoot\System32\drivers\rdpvideominiport.sys \SystemRoot\System32\cdd.dll \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffe00003e01670 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\00000032\ Lower Device Object: 0xffffe000010b5060 Lower Device Driver Name: \Driver\iaStorA\ <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffe000029ff450 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\00000031\ Lower Device Object: 0xffffe000010b67f0 Lower Device Driver Name: \Driver\iaStorA\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffe000029ff450, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ --------- Disk Stack ------ DevicePointer: 0xffffe00003e00e00, DeviceName: Unknown, DriverName: \Driver\SiRemFil\ DevicePointer: 0xffffe00003e00040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffe000029ff450, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xffffe000002df760, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffe000010b67f0, DeviceName: \Device\00000031\, DriverName: \Driver\iaStorA\ ------------ End ---------- Alternate DeviceName: Unknown, DriverName: \Driver\partmgr\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Read File: File "C:\Windows\System32\drivers\1394ohci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\1394ohci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpipagr.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpipagr.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpipmi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpipmi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpitime.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpitime.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\AGP440.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\AGP440.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\amdk8.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\amdk8.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\amdppm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\amdppm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\intelpep.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\intelpep.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\intelppm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\intelppm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\isapnp.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\isapnp.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\kbdclass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\kbdclass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\kbdhid.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\kbdhid.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\kdnic.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\kdnic.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BasicRender.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BasicRender.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\battc.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\battc.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BtaMPM.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BtaMPM.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BthAvrcpTg.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BthAvrcpTg.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\bthhfenum.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\bthhfenum.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BthhfHid.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BthhfHid.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\bthmodem.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\bthmodem.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\cdrom.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\cdrom.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\circlass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\circlass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\CmBatt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\CmBatt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\CompositeBus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\CompositeBus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\disk.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\disk.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\drmk.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\drmk.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\drmkaud.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\drmkaud.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\dumpsd.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\dumpsd.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\errdev.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\errdev.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\fdc.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\fdc.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\flpydisk.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\flpydisk.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\parport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\parport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pciide.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pciide.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pciidex.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pciidex.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pcmcia.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pcmcia.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\portcls.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\portcls.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\processr.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\processr.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\monitor.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\monitor.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\mouclass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\mouclass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\mouhid.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\mouhid.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\msgpiowin32.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\msgpiowin32.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\msisadrv.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\msisadrv.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\msiscsi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\msiscsi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BasicDisplay.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BasicDisplay.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sdstor.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sdstor.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\USBSTOR.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\USBSTOR.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\serenum.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\serenum.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\serial.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\serial.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sermouse.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sermouse.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sfloppy.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sfloppy.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\spaceport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\spaceport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\stornvme.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\stornvme.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\swenum.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\swenum.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\terminpt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\terminpt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\tpm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\tpm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\TsUsbGD.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\TsUsbGD.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\uaspstor.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\uaspstor.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\UCX01000.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\UCX01000.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\uefi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\uefi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\umbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\umbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\umpass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\umpass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbccgp.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbccgp.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbcir.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbcir.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbd.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbd.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbehci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbehci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbhub.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbhub.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\USBHUB3.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\USBHUB3.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbohci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbohci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbprint.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbprint.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbuhci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbuhci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\USBXHCI.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\USBXHCI.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\vdrvroot.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\vdrvroot.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\vhdmp.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\vhdmp.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\volmgr.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\volmgr.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\fxppm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\fxppm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hdaudbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hdaudbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidbatt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidbatt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidbth.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidbth.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidclass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidclass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidi2c.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidi2c.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidparse.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidparse.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidusb.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidusb.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\i8042prt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\i8042prt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\mssmbios.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\mssmbios.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\MTConfig.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\MTConfig.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\npsvctrig.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\npsvctrig.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\volsnap.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\volsnap.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\vwifibus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\wacompen.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\wacompen.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\winusb.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\winusb.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\wmiacpi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\wmiacpi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\WSDPrint.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\WSDPrint.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\atapi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\atapi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\ataport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\ataport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\rdpbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\rdpbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sbp2port.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sbp2port.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sdbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sdbus.sys" is compressed (flags = 1) Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 5D237 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 488392704 Partition file system is NTFS Partition is bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 250059350016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-488377168-488397168)... Done! Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffffe00003e01670, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ --------- Disk Stack ------ DevicePointer: 0xffffe00003e01270, DeviceName: Unknown, DriverName: \Driver\SiRemFil\ DevicePointer: 0xffffe00003e21040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffe00003e01670, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ DevicePointer: 0xffffe000010b8ae0, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffe000010b5060, DeviceName: \Device\00000032\, DriverName: \Driver\iaStorA\ ------------ End ---------- Alternate DeviceName: Unknown, DriverName: \Driver\partmgr\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 1 Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: F4ED3BB1 Partition information: Partition 0 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 1985 Partition 1 type is Dynamic (0x42) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 1250254848 Partition file system is NTFS Partition is not bootable Partition 2 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 1250256896 Numsec = 4784 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 640135028736 bytes Sector size: 512 bytes Done! Scan finished ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_0_2048_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_1_1_2048_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam... Removal finished Code:
ATTFilter # AdwCleaner v3.011 - Bericht erstellt am 10/11/2013 um 10:43:58 # Updated 03/11/2013 von Xplode # Betriebssystem : Windows 8.1 Pro (64 bits) # Benutzername : drah_000 - ZOCKER # Gestartet von : C:\Users\drah_000\Downloads\adw311cleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gefunden C:\Program Files (x86)\FreeRIP Ordner Gefunden C:\ProgramData\apn Ordner Gefunden C:\ProgramData\boost_interprocess Ordner Gefunden C:\Users\drah_000\AppData\Local\Temp\OCS ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\OCS Schlüssel Gefunden : [x64] HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16384 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://home.sweetim.com/?crg=3.1010000.10014&barid={6FCABB18-6A48-11E2-BEB1-D43D7E3838C3} -\\ Mozilla Firefox v25.0 (de) [ Datei : C:\Users\drah_000\AppData\Roaming\Mozilla\Firefox\Profiles\sxjj2ymn.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1246 octets] - [09/11/2013 21:43:22] AdwCleaner[R1].txt - [1162 octets] - [10/11/2013 10:43:58] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1222 octets] ########## Nutze Win8.1 64bit mit Firefox und laut Avast SoftwareUpdater ist auch alles auf aktuellstem Stand. Ich finde es schon SEHR erschreckend das ein falscher Klick reicht um sich zu infizieren, trotz aller Updates und ohne das ich eine Datei runtergeladen hätte. ![]() Vielen Dank füe eure Hilfe Schönen Grüss Jens |
Themen zu Gefunden PUP.Optional auf Win 8.1 |
administrator, anti-malware, appdata, autostart, befall, browser, dateien, device driver, explorer, firefox, gelöscht, harddisk, i8042prt.sys, microsoft, pup.optional.downloadsponsor.a, pup.optional.installrex, pup.optional.spigot.a, registrierungsdatenbank, software, system32, updates, win8.1, windows 8.1 |