|
Log-Analyse und Auswertung: ich bekomme odir.org nicht vom verlauf gelöschtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.01.2014, 08:38 | #16 |
/// the machine /// TB-Ausbilder | ich bekomme odir.org nicht vom verlauf gelöscht Poste bitte nochmal ein frisches FRST log, aber Du wirst warscheinlich nicht drum rum kommen die Einstellungen in Chrome manuell zu durchsuchen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.01.2014, 10:13 | #17 |
| ich bekomme odir.org nicht vom verlauf gelöschtFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2014 03 Ran by Admin (administrator) on ADMIN-PC on 17-01-2014 10:11:39 Running from C:\Users\Admin\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Program Files (x86)\OneClickInternet\WTGService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Sonix) C:\Windows\vsnp2uvc.exe () C:\Windows\snuvcdsm.exe (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Windows\Samsung\PanelMgr\caller64.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Farbar) C:\Users\Admin\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [snp2uvc] - C:\Windows\vsnp2uvc.exe [662016 2009-08-12] (Sonix) HKLM\...\Run: [SNUVCDSM] - C:\Windows\snuvcdsm.exe [24576 2009-05-22] () HKLM\...\Run: [ATSwpNav] - "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-09] (Synaptics Incorporated) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM-x32\...\Run: [snp2uvc] - C:\Windows\vsnp2uvc.exe [662016 2009-08-12] (Sonix) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [47976 2009-10-09] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\ssmmgr.exe [614400 2009-10-10] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE79719D53B12CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\auege6s2.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml Chrome: ======= CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 [2014-01-14] CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2014-01-14] CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2014-01-14] CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 [2014-01-17] CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2014-01-14] ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 WTGService; C:\Program Files (x86)\OneClickInternet\WTGService.exe [312784 2009-11-27] () ==================== Drivers (Whitelisted) ==================== S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation) S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.) S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation) S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation) S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3531776 2009-09-04] () S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-17 09:43 - 2014-01-17 09:43 - 02076160 _____ (Farbar) C:\Users\Admin\Downloads\FRST64(1).exe 2014-01-16 22:08 - 2014-01-16 22:08 - 00169472 _____ C:\Users\Admin\Desktop\160114 bis 150214.xls 2014-01-16 22:07 - 2014-01-16 22:07 - 00162816 _____ C:\Users\Admin\Downloads\160114 bis 150214.xls 2014-01-15 22:48 - 2014-01-17 01:19 - 00000112 _____ C:\Windows\setupact.log 2014-01-15 22:48 - 2014-01-15 22:48 - 00000000 _____ C:\Windows\setuperr.log 2014-01-15 22:47 - 2014-01-17 01:19 - 00388192 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-15 22:47 - 2014-01-15 22:47 - 00001492 _____ C:\Windows\PFRO.log 2014-01-15 22:31 - 2014-01-15 22:31 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2014-01-15 22:31 - 2014-01-15 22:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2014-01-15 22:30 - 2014-01-15 22:30 - 13079688 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\Silverlight_x64.exe 2014-01-15 09:30 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 09:30 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 09:30 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 09:30 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 09:30 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 09:30 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 09:30 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 09:30 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-14 22:27 - 2014-01-14 22:27 - 00092256 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-14 18:19 - 2014-01-16 15:32 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-14 18:18 - 2014-01-17 09:40 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-14 18:18 - 2014-01-17 01:20 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-14 18:18 - 2014-01-14 18:24 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-01-14 18:18 - 2014-01-14 18:24 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-01-14 18:18 - 2014-01-14 18:18 - 00819144 _____ (Google Inc.) C:\Users\Admin\Downloads\chrome_installer_31.0.1650.63(1).exe 2014-01-13 12:23 - 2014-01-13 12:23 - 00819176 _____ (Google Inc.) C:\Users\Admin\Downloads\ChromeSetup.exe 2014-01-11 15:48 - 2014-01-11 16:07 - 58926905 _____ C:\Users\Admin\Downloads\Emre.A.2013. karam82.rar 2014-01-11 15:44 - 2014-01-11 16:00 - 55047762 _____ C:\Users\Admin\Downloads\Nefes.2013.karam82.rar 2014-01-11 15:41 - 2014-01-11 16:12 - 92171165 _____ C:\Users\Admin\Downloads\Pop 2014 - karam82.rar 2014-01-11 14:58 - 2014-01-11 14:59 - 00020370 _____ C:\Users\Admin\Documents\cc_20140111_145826.reg 2014-01-11 14:40 - 2014-01-11 16:16 - 00000000 ____D C:\Users\Admin\Desktop\müzik 1.14 2014-01-11 14:35 - 2014-01-11 14:35 - 00000000 ____D C:\Users\Admin\Downloads\FRST-OlderVersion 2014-01-11 14:32 - 2014-01-11 14:32 - 00819144 _____ (Google Inc.) C:\Users\Admin\Downloads\chrome_installer_31.0.1650.63.exe 2014-01-11 14:25 - 2014-01-11 14:25 - 00987410 _____ C:\Users\Admin\Downloads\SecurityCheck(1).exe 2014-01-11 14:24 - 2014-01-11 14:24 - 00987410 _____ C:\Users\Admin\Downloads\SecurityCheck.exe 2014-01-11 13:03 - 2014-01-11 13:04 - 02347384 _____ (ESET) C:\Users\Admin\Downloads\esetsmartinstaller_enu.exe 2014-01-11 12:51 - 2014-01-11 16:17 - 00000000 ____D C:\Users\Admin\Desktop\OST - Rocky 1 (1976) 2014-01-11 11:52 - 2014-01-11 11:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\WinRAR 2014-01-11 11:52 - 2014-01-11 11:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-11 11:52 - 2014-01-11 11:52 - 00000000 ____D C:\Program Files\WinRAR 2014-01-11 11:51 - 2014-01-11 11:51 - 02087616 _____ C:\Users\Admin\Downloads\winrar-x64-501d.exe 2014-01-11 11:25 - 2014-01-11 12:46 - 320929792 _____ C:\Users\Admin\Downloads\59392217.rar 2014-01-11 11:20 - 2014-01-11 11:47 - 81842514 _____ C:\Users\Admin\Downloads\Hande.Y.2013.karam82.rar 2014-01-11 11:16 - 2014-01-11 11:37 - 66078591 _____ C:\Users\Admin\Downloads\Ugur.I.2014.karam82.rar 2014-01-10 15:29 - 2014-01-10 15:29 - 00000621 _____ C:\Users\Admin\Desktop\JRT.txt 2014-01-10 15:19 - 2014-01-10 15:19 - 00000000 ____D C:\Windows\ERUNT 2014-01-10 15:18 - 2014-01-10 15:18 - 01037068 _____ (Thisisu) C:\Users\Admin\Downloads\JRT.exe 2014-01-10 14:47 - 2014-01-10 14:47 - 01233962 _____ C:\Users\Admin\Downloads\adwcleaner (1).exe 2014-01-09 23:45 - 2014-01-09 23:45 - 00019644 _____ C:\Users\Admin\Downloads\Addition.txt 2014-01-09 23:44 - 2014-01-17 10:11 - 00011655 _____ C:\Users\Admin\Downloads\FRST.txt 2014-01-09 23:44 - 2014-01-11 14:35 - 00000000 ____D C:\FRST 2014-01-09 23:43 - 2014-01-11 14:35 - 02076160 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2014-01-09 16:36 - 2014-01-09 16:36 - 00022429 _____ C:\ComboFix.txt 2014-01-09 16:20 - 2014-01-09 16:36 - 00000000 ____D C:\Qoobox 2014-01-09 16:20 - 2014-01-09 16:33 - 00000000 ____D C:\Windows\erdnt 2014-01-09 16:20 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-09 16:20 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-09 16:20 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-09 16:20 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-09 16:20 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-09 16:20 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-09 16:20 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-09 16:20 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-09 16:18 - 2014-01-09 16:18 - 05162489 ____R (Swearware) C:\Users\Admin\Downloads\ComboFix.exe 2014-01-09 16:08 - 2014-01-09 16:08 - 01281536 _____ C:\Users\Admin\Downloads\zoek (2).exe 2014-01-09 16:05 - 2014-01-09 15:46 - 00024064 _____ C:\Windows\zoek-delete.exe 2014-01-09 15:48 - 2014-01-09 16:06 - 00004812 _____ C:\zoek-results.log 2014-01-09 15:46 - 2014-01-09 15:46 - 01281536 _____ C:\Users\Admin\Downloads\zoek (1).exe 2014-01-09 15:42 - 2014-01-09 15:42 - 01281536 _____ C:\Users\Admin\Downloads\zoek.exe 2014-01-09 15:42 - 2014-01-09 15:42 - 00000000 ____D C:\zoek_backup 2014-01-09 15:32 - 2014-01-11 22:46 - 00000866 _____ C:\Users\Public\Desktop\CCleaner.lnk 2014-01-09 15:32 - 2014-01-09 15:32 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-09 15:32 - 2014-01-09 15:32 - 00000000 ____D C:\Program Files\CCleaner 2014-01-09 15:24 - 2014-01-10 15:14 - 00000000 ____D C:\AdwCleaner 2014-01-09 15:23 - 2014-01-09 15:24 - 04645232 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup409.exe 2014-01-09 15:18 - 2014-01-09 15:18 - 01233962 _____ C:\Users\Admin\Downloads\adwcleaner.exe 2014-01-09 15:17 - 2014-01-09 15:17 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-09 15:17 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-09 15:09 - 2014-01-09 15:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-02 13:50 - 2014-01-02 13:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-31 11:05 - 2013-12-31 11:05 - 00029696 _____ C:\Users\Admin\Desktop\Dienstvorgabe Boztepe 1-2.xls 2013-12-20 10:52 - 2013-12-20 10:52 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-12-19 10:16 - 2013-12-19 10:55 - 00000000 ____D C:\Users\Admin\Desktop\Neuer Ordner 2013-12-18 14:02 - 2013-12-18 14:02 - 00019884 _____ C:\Users\Admin\Downloads\Nicht bestätigt 389066.crdownload 2013-12-18 13:58 - 2013-12-18 13:58 - 00000138 _____ C:\Users\Public\Desktop\SAMSUNG Dr.Printer.url 2013-12-18 13:57 - 2013-12-18 13:57 - 00000000 ____D C:\Windows\Samsung 2013-12-18 13:57 - 2013-12-18 13:57 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdate 2013-12-18 13:57 - 2009-10-07 00:09 - 00081920 _____ (Samsung Electronics) C:\Windows\SysWOW64\ssdevm.dll 2013-12-18 13:57 - 2009-10-07 00:09 - 00074240 _____ (Samsung Electronics) C:\Windows\system32\ssdevm64.dll 2013-12-18 13:57 - 2009-10-06 18:18 - 00482408 _____ () C:\Windows\ssndii.exe 2013-12-18 13:57 - 2007-11-30 05:30 - 00151552 _____ (SS) C:\Windows\system32\ssa1mci.exe 2013-12-18 13:57 - 2007-11-30 05:30 - 00089600 _____ (SS) C:\Windows\system32\ssa1mci.dll 2013-12-18 13:57 - 2007-11-30 05:30 - 00022016 _____ () C:\Windows\system32\ssa1ml6.dll 2013-12-18 13:57 - 2007-11-30 05:30 - 00000357 _____ C:\Windows\system32\ssa1ml6.smt 2013-12-18 13:57 - 2007-11-29 23:38 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml2.dll 2013-12-18 13:57 - 2007-11-29 23:38 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4r.dll 2013-12-18 13:57 - 2007-11-29 23:38 - 00049152 _____ (Samsung Electronics) C:\Windows\SysWOW64\ssusbpn.dll 2013-12-18 13:57 - 2007-11-29 23:38 - 00047104 _____ (Samsung Electronics) C:\Windows\system32\ssusbp64.dll 2013-12-18 13:57 - 2007-11-29 23:38 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4a.dll 2013-12-18 13:57 - 2007-11-29 23:38 - 00038160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml2r.dll 2013-12-18 13:57 - 2007-11-29 23:38 - 00021776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml2a.dll 2013-12-18 13:55 - 2013-12-18 13:55 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-12-18 13:55 - 2007-11-30 02:46 - 00011576 ____N (Samsung Electronics) C:\Windows\system32\Drivers\SSPORT.SYS 2013-12-18 13:54 - 2013-12-18 13:55 - 37261048 _____ (Samsung ) C:\Users\Admin\Downloads\ML-1630W_Print_64bit.exe 2013-12-18 11:49 - 2013-12-12 11:44 - 00163328 _____ C:\Users\Admin\Desktop\161213 bis 150114 (1).xls ==================== One Month Modified Files and Folders ======= 2014-01-17 10:11 - 2014-01-09 23:44 - 00011655 _____ C:\Users\Admin\Downloads\FRST.txt 2014-01-17 10:03 - 2013-10-26 14:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-17 09:45 - 2009-07-14 05:45 - 00026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-17 09:45 - 2009-07-14 05:45 - 00026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-17 09:43 - 2014-01-17 09:43 - 02076160 _____ (Farbar) C:\Users\Admin\Downloads\FRST64(1).exe 2014-01-17 09:40 - 2014-01-14 18:18 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-17 01:20 - 2014-01-14 18:18 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-17 01:19 - 2014-01-15 22:48 - 00000112 _____ C:\Windows\setupact.log 2014-01-17 01:19 - 2014-01-15 22:47 - 00388192 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-17 01:19 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-17 01:17 - 2013-10-12 16:34 - 01834000 _____ C:\Windows\WindowsUpdate.log 2014-01-16 22:08 - 2014-01-16 22:08 - 00169472 _____ C:\Users\Admin\Desktop\160114 bis 150214.xls 2014-01-16 22:07 - 2014-01-16 22:07 - 00162816 _____ C:\Users\Admin\Downloads\160114 bis 150214.xls 2014-01-16 15:32 - 2014-01-14 18:19 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-16 10:28 - 2013-10-12 17:43 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-16 10:28 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2014-01-15 22:48 - 2014-01-15 22:48 - 00000000 _____ C:\Windows\setuperr.log 2014-01-15 22:47 - 2014-01-15 22:47 - 00001492 _____ C:\Windows\PFRO.log 2014-01-15 22:31 - 2014-01-15 22:31 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2014-01-15 22:31 - 2014-01-15 22:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2014-01-15 22:30 - 2014-01-15 22:30 - 13079688 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\Silverlight_x64.exe 2014-01-14 22:27 - 2014-01-14 22:27 - 00092256 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-14 18:24 - 2014-01-14 18:18 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-01-14 18:24 - 2014-01-14 18:18 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-01-14 18:19 - 2013-10-12 17:24 - 00000000 ____D C:\Users\Admin\AppData\Local\Google 2014-01-14 18:19 - 2013-10-12 17:24 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-14 18:18 - 2014-01-14 18:18 - 00819144 _____ (Google Inc.) C:\Users\Admin\Downloads\chrome_installer_31.0.1650.63(1).exe 2014-01-13 12:23 - 2014-01-13 12:23 - 00819176 _____ (Google Inc.) C:\Users\Admin\Downloads\ChromeSetup.exe 2014-01-12 02:52 - 2013-10-26 14:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-11 22:46 - 2014-01-09 15:32 - 00000866 _____ C:\Users\Public\Desktop\CCleaner.lnk 2014-01-11 16:17 - 2014-01-11 12:51 - 00000000 ____D C:\Users\Admin\Desktop\OST - Rocky 1 (1976) 2014-01-11 16:16 - 2014-01-11 14:40 - 00000000 ____D C:\Users\Admin\Desktop\müzik 1.14 2014-01-11 16:12 - 2014-01-11 15:41 - 92171165 _____ C:\Users\Admin\Downloads\Pop 2014 - karam82.rar 2014-01-11 16:07 - 2014-01-11 15:48 - 58926905 _____ C:\Users\Admin\Downloads\Emre.A.2013. karam82.rar 2014-01-11 16:00 - 2014-01-11 15:44 - 55047762 _____ C:\Users\Admin\Downloads\Nefes.2013.karam82.rar 2014-01-11 15:37 - 2013-04-15 16:10 - 00698926 _____ C:\Windows\system32\perfh007.dat 2014-01-11 15:37 - 2013-04-15 16:10 - 00149034 _____ C:\Windows\system32\perfc007.dat 2014-01-11 15:37 - 2009-07-14 06:13 - 01618320 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 14:59 - 2014-01-11 14:58 - 00020370 _____ C:\Users\Admin\Documents\cc_20140111_145826.reg 2014-01-11 14:35 - 2014-01-11 14:35 - 00000000 ____D C:\Users\Admin\Downloads\FRST-OlderVersion 2014-01-11 14:35 - 2014-01-09 23:44 - 00000000 ____D C:\FRST 2014-01-11 14:35 - 2014-01-09 23:43 - 02076160 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe 2014-01-11 14:32 - 2014-01-11 14:32 - 00819144 _____ (Google Inc.) C:\Users\Admin\Downloads\chrome_installer_31.0.1650.63.exe 2014-01-11 14:25 - 2014-01-11 14:25 - 00987410 _____ C:\Users\Admin\Downloads\SecurityCheck(1).exe 2014-01-11 14:24 - 2014-01-11 14:24 - 00987410 _____ C:\Users\Admin\Downloads\SecurityCheck.exe 2014-01-11 13:04 - 2014-01-11 13:03 - 02347384 _____ (ESET) C:\Users\Admin\Downloads\esetsmartinstaller_enu.exe 2014-01-11 12:46 - 2014-01-11 11:25 - 320929792 _____ C:\Users\Admin\Downloads\59392217.rar 2014-01-11 11:52 - 2014-01-11 11:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\WinRAR 2014-01-11 11:52 - 2014-01-11 11:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-11 11:52 - 2014-01-11 11:52 - 00000000 ____D C:\Program Files\WinRAR 2014-01-11 11:51 - 2014-01-11 11:51 - 02087616 _____ C:\Users\Admin\Downloads\winrar-x64-501d.exe 2014-01-11 11:47 - 2014-01-11 11:20 - 81842514 _____ C:\Users\Admin\Downloads\Hande.Y.2013.karam82.rar 2014-01-11 11:37 - 2014-01-11 11:16 - 66078591 _____ C:\Users\Admin\Downloads\Ugur.I.2014.karam82.rar 2014-01-10 15:29 - 2014-01-10 15:29 - 00000621 _____ C:\Users\Admin\Desktop\JRT.txt 2014-01-10 15:19 - 2014-01-10 15:19 - 00000000 ____D C:\Windows\ERUNT 2014-01-10 15:18 - 2014-01-10 15:18 - 01037068 _____ (Thisisu) C:\Users\Admin\Downloads\JRT.exe 2014-01-10 15:14 - 2014-01-09 15:24 - 00000000 ____D C:\AdwCleaner 2014-01-10 14:47 - 2014-01-10 14:47 - 01233962 _____ C:\Users\Admin\Downloads\adwcleaner (1).exe 2014-01-09 23:45 - 2014-01-09 23:45 - 00019644 _____ C:\Users\Admin\Downloads\Addition.txt 2014-01-09 16:36 - 2014-01-09 16:36 - 00022429 _____ C:\ComboFix.txt 2014-01-09 16:36 - 2014-01-09 16:20 - 00000000 ____D C:\Qoobox 2014-01-09 16:36 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-09 16:33 - 2014-01-09 16:20 - 00000000 ____D C:\Windows\erdnt 2014-01-09 16:31 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-09 16:18 - 2014-01-09 16:18 - 05162489 ____R (Swearware) C:\Users\Admin\Downloads\ComboFix.exe 2014-01-09 16:08 - 2014-01-09 16:08 - 01281536 _____ C:\Users\Admin\Downloads\zoek (2).exe 2014-01-09 16:06 - 2014-01-09 15:48 - 00004812 _____ C:\zoek-results.log 2014-01-09 15:46 - 2014-01-09 16:05 - 00024064 _____ C:\Windows\zoek-delete.exe 2014-01-09 15:46 - 2014-01-09 15:46 - 01281536 _____ C:\Users\Admin\Downloads\zoek (1).exe 2014-01-09 15:42 - 2014-01-09 15:42 - 01281536 _____ C:\Users\Admin\Downloads\zoek.exe 2014-01-09 15:42 - 2014-01-09 15:42 - 00000000 ____D C:\zoek_backup 2014-01-09 15:34 - 2013-10-13 02:30 - 00000000 ____D C:\Windows\Panther 2014-01-09 15:32 - 2014-01-09 15:32 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-09 15:32 - 2014-01-09 15:32 - 00000000 ____D C:\Program Files\CCleaner 2014-01-09 15:24 - 2014-01-09 15:23 - 04645232 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup409.exe 2014-01-09 15:18 - 2014-01-09 15:18 - 01233962 _____ C:\Users\Admin\Downloads\adwcleaner.exe 2014-01-09 15:17 - 2014-01-09 15:17 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-09 15:10 - 2014-01-09 15:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-02 13:50 - 2014-01-02 13:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-31 11:05 - 2013-12-31 11:05 - 00029696 _____ C:\Users\Admin\Desktop\Dienstvorgabe Boztepe 1-2.xls 2013-12-25 09:52 - 2013-10-12 16:59 - 00000000 ____D C:\Users\Admin\AppData\Local\VirtualStore 2013-12-20 10:52 - 2013-12-20 10:52 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-12-19 10:55 - 2013-12-19 10:16 - 00000000 ____D C:\Users\Admin\Desktop\Neuer Ordner 2013-12-18 20:51 - 2013-11-19 18:28 - 00000000 ____D C:\Users\Admin\Desktop\iphone4 2013-12-18 14:44 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-18 14:02 - 2013-12-18 14:02 - 00019884 _____ C:\Users\Admin\Downloads\Nicht bestätigt 389066.crdownload 2013-12-18 13:58 - 2013-12-18 13:58 - 00000138 _____ C:\Users\Public\Desktop\SAMSUNG Dr.Printer.url 2013-12-18 13:57 - 2013-12-18 13:57 - 00000000 ____D C:\Windows\Samsung 2013-12-18 13:57 - 2013-12-18 13:57 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdate 2013-12-18 13:55 - 2013-12-18 13:55 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-12-18 13:55 - 2013-12-18 13:54 - 37261048 _____ (Samsung ) C:\Users\Admin\Downloads\ML-1630W_Print_64bit.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 10:53 ==================== End Of Log ============================ |
17.01.2014, 20:46 | #18 |
/// the machine /// TB-Ausbilder | ich bekomme odir.org nicht vom verlauf gelöscht Jap, Du musst leider alles in Chrome manuell durchsuchen, wenn das Konto verbunden ist.
__________________
__________________ |
17.01.2014, 20:59 | #19 |
| ich bekomme odir.org nicht vom verlauf gelöscht ich habs gemacht, weder im verlauf, noch unter einstellungen (auch erweiterte) ist nichts zu finden . . . ich werde wahnsinnig |
18.01.2014, 08:25 | #20 |
/// the machine /// TB-Ausbilder | ich bekomme odir.org nicht vom verlauf gelöscht und dieses odir macht Dir aber keine Probleme, ausser das es im Verlauf steht?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu ich bekomme odir.org nicht vom verlauf gelöscht |
.html, ausgeführt, bräuchte, ccleaner, combofix, eigener, gelöscht, installier, installiert, kraft, leutz, lösen, malwarebytes, problem, programme, verlauf, versuch, versucht |