![]() |
|
Plagegeister aller Art und deren Bekämpfung: Awesomehp.com Virus entfernenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() Awesomehp.com Virus entfernenCode:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.02.03 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Guido :: GUIDO-PC [Administrator] 02.02.2014 17:31:55 mbam-log-2014-02-02 (17-31-55).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 243773 Laufzeit: 13 Minute(n), 27 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 6 C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon (PUP.Optional.ValueApps) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0 (PUP.Optional.ValueApps) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\js (PUP.Optional.ValueApps) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam (PUP.Optional.ValueApps) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts (PUP.Optional.ValueApps) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\contentScripts (PUP.Optional.ValueApps) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 02/02/2014 um 19:49:29 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Guido - GUIDO-PC # Gestartet von : C:\Users\Guido\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PYU2FKXQ\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 ************************* AdwCleaner[R0].txt - [10269 octets] - [26/01/2014 20:46:01] AdwCleaner[R1].txt - [864 octets] - [02/02/2014 19:46:20] AdwCleaner[S0].txt - [8970 octets] - [26/01/2014 20:48:10] AdwCleaner[S1].txt - [786 octets] - [02/02/2014 19:49:29] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [845 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Guido on 02.02.2014 at 21:50:15,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Windows\Tasks\wise registry cleaner schedule task.job" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Users\Guido\AppData\Roaming\getrighttogo" Successfully deleted: [Folder] "C:\Users\Guido\appdata\locallow\datamngr" Successfully deleted: [Folder] "C:\Program Files\bearshare applications" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.02.2014 at 21:53:27,79 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2014 03 Ran by Guido (administrator) on GUIDO-PC on 03-02-2014 18:34:53 Running from C:\Users\Guido\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6SRFJE6T Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe () C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Freemake) C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe ( ) C:\Windows\System32\lxbkcoms.exe (NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (FS) C:\Program Files\FS\Spyro Portal\FlashPortal.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (CyberLink Corp.) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\PLFSetI.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe (NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe () C:\Program Files\Steganos Safe OEM\SteganosHotKeyService.exe (Lexmark International, Inc.) C:\Program Files\Lexmark X1100 Series\LXBKbmgr.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.) C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Lexmark International, Inc.) C:\Program Files\Lexmark X1100 Series\LXBKbmon.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Realtek Semiconductor Corp.) C:\Users\Guido\AppData\Local\temp\RtkBtMnt.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ArcadeDeluxeAgent] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [156968 2009-01-21] (CyberLink Corp.) HKLM\...\Run: [CLMLServer] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [202024 2009-01-21] (CyberLink) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-06-02] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6793760 2009-02-19] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-02-19] (Realtek Semiconductor Corp.) HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [200704 2009-07-26] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1410344 2008-12-05] (Synaptics, Inc.) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1069576 2009-06-25] (Dritek System Inc.) HKLM\...\Run: [BackupManagerTray] - C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [249600 2009-04-11] (NewTech Infosystems, Inc.) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [440864 2009-06-23] (Acer Incorporated) HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-18] (Google) HKLM\...\Run: [Ulead AutoDetector v2] - C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2006-11-29] (Ulead Systems, Inc.) HKLM\...\Run: [SAFEOEM HotKeys] - C:\Program Files\Steganos Safe OEM\SteganosHotKeyService.exe [26112 2008-12-11] () HKLM\...\Run: [lxbkbmgr.exe] - C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe [74408 2008-02-28] (Lexmark International, Inc.) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2516296 2010-03-24] (CANON INC.) HKLM\...\Run: [CanonSolutionMenuEx] - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.) HKLM\...\Run: [IJNetworkScanUtility] - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2010-03-02] (CANON INC.) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKU\S-1-5-21-2479292056-3449645492-3974709493-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-2479292056-3449645492-3974709493-1000\...\Run: [AVMUSBFernanschluss] - C:\Users\Guido\AppData\Local\Apps\2.0\6337A3YP.CHY\46NALXCR.NB1\frit..tion_1acae14e4778b8d2_0002.0003_7c9366a34786c7f9\AVMAutoStart.exe [139264 2013-12-14] (AVM Berlin) HKU\S-1-5-21-2479292056-3449645492-3974709493-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 Startup: C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.freenet.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1390734465&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXA0A69E5802E5802 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1390734465&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXA0A69E5802E5802 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1390734465&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXA0A69E5802E5802&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1390734465&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXA0A69E5802E5802&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1390734465&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXA0A69E5802E5802 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1390734465&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXA0A69E5802E5802 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [75048 2008-12-18] () R2 DAZContentManagementService; C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe [18432 2011-05-05] () R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [707104 2009-06-23] (Acer Incorporated) R2 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [8704 2012-09-07] (Freemake) S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-09-18] (Google) S2 gupdate1ca3255a4e7fb60; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-09-10] (Google Inc.) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] () R2 lxbk_device; C:\Windows\system32\lxbkcoms.exe [537256 2008-02-19] ( ) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [61184 2009-04-11] (NewTech Infosystems, Inc.) R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-23] (NewTech Infosystems, Inc.) R2 SpyroService; C:\Program Files\FS\Spyro Portal\FlashPortal.exe [50688 2012-09-20] (FS) ==================== Drivers (Whitelisted) ==================== S3 AF05BDA; C:\Windows\System32\drivers\AF05BDA.sys [117376 2006-12-05] (AfaTech ) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG) R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2013-12-14] (AVM Berlin) S3 hcw95bda; C:\Windows\System32\Drivers\hcw95bda.sys [560640 2008-04-17] (Hauppauge Computer Works, Inc.) S3 hcw95rc; C:\Windows\System32\DRIVERS\hcw95rc.sys [15616 2008-04-17] (Hauppauge Computer Works, Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [154272 2008-11-12] (Realtek Semiconductor Corp.) S3 s1029bus; C:\Windows\System32\DRIVERS\s1029bus.sys [90280 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\System32\DRIVERS\s1029mdfl.sys [15016 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\System32\DRIVERS\s1029mdm.sys [122280 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\System32\DRIVERS\s1029mgmt.sys [115880 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\System32\DRIVERS\s1029nd5.sys [26024 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\System32\DRIVERS\s1029obex.sys [111912 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\DRIVERS\s1029unic.sys [116904 2009-05-25] (MCCI Corporation) R1 SLEE_16_DRIVER; C:\Windows\system32\drivers\Sleen16.sys [79104 2008-10-01] (Softwareentwicklung Remus - ArchiCrypt ) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-04] (Avira GmbH) S3 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [7168 2009-09-28] () S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2010-01-21] (LG Electronics Inc.) S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [20864 2010-01-21] (LG Electronics Inc.) S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24960 2010-01-21] (LG Electronics Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-02 21:53 - 2014-02-02 21:53 - 00001007 _____ () C:\Users\Guido\Desktop\JRT.txt 2014-02-02 12:33 - 2014-02-02 17:30 - 00000870 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-02 12:33 - 2014-02-02 17:30 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-02 12:33 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-28 19:53 - 2014-02-03 18:34 - 00000000 ____D () C:\FRST 2014-01-26 20:45 - 2014-02-02 19:49 - 00000000 ____D () C:\AdwCleaner 2014-01-26 19:40 - 2014-01-26 19:40 - 00212992 _____ () C:\Windows\system32\config\DEFAULT.rhk 2014-01-26 19:40 - 2014-01-26 19:40 - 00090112 _____ () C:\Windows\system32\config\SAM.rhk 2014-01-26 19:38 - 2014-01-26 19:40 - 52482048 _____ () C:\Windows\system32\config\SOFTWARE.rhk 2014-01-26 19:38 - 2014-01-26 19:38 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk 2014-01-26 12:08 - 2014-02-02 13:08 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\VOPackage 2014-01-26 12:08 - 2014-01-26 12:15 - 00000000 ____D () C:\ProgramData\IePluginService 2014-01-25 16:53 - 2014-01-25 16:53 - 00133842 _____ () C:\Users\Guido\Documents\Tasche Karnevalsjeans.pptx 2014-01-25 14:43 - 2014-01-25 14:43 - 00003466 _____ () C:\Users\Guido\AppData\Local\recently-used.xbel 2014-01-25 11:21 - 2014-01-26 12:16 - 00000000 ____D () C:\Program Files\AmiExt 2014-01-22 20:04 - 2014-01-22 20:04 - 00000000 ____D () C:\Users\Guido\Documents\Mixpad Projects 2014-01-22 17:10 - 2014-01-22 17:10 - 00000000 ____D () C:\Users\Guido\Desktop\Backup 2014-01-21 20:27 - 2014-01-21 20:30 - 00000604 _____ () C:\Users\Guido\Desktop\Schatti's AudioMixer.lnk 2014-01-21 20:27 - 2014-01-21 20:30 - 00000000 ____D () C:\AudioMixer 2014-01-18 14:11 - 2014-01-18 14:11 - 00000000 ____D () C:\Users\Public\Pixologic 2014-01-18 13:39 - 2014-01-18 13:39 - 00000000 ____D () C:\Users\Public\Documents\DAZ 3D 2014-01-16 17:25 - 2014-01-16 17:25 - 00000000 ____D () C:\Program Files\Common Files\DAZ 2014-01-16 17:24 - 2014-01-18 14:44 - 00000000 ____D () C:\Users\Public\Documents\My DAZ 3D Library 2014-01-16 17:23 - 2014-01-18 14:10 - 00000000 ____D () C:\ProgramData\DAZ 3D 2014-01-16 17:23 - 2014-01-18 14:07 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D 2014-01-16 17:23 - 2014-01-18 14:06 - 00000000 ____D () C:\Program Files\DAZ 3D 2014-01-16 17:21 - 2014-01-18 13:39 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\DAZ 3D 2014-01-13 21:06 - 2014-01-13 21:06 - 00052206 _____ () C:\Users\Guido\Documents\Overather Coffee.pptx ==================== One Month Modified Files and Folders ======= 2014-02-03 18:34 - 2014-01-28 19:53 - 00000000 ____D () C:\FRST 2014-02-03 18:31 - 2009-09-10 21:38 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-03 18:28 - 2012-05-28 19:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-03 18:28 - 2009-09-10 21:38 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-03 03:51 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-03 03:51 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-03 01:40 - 2009-07-26 16:05 - 02009037 _____ () C:\Windows\WindowsUpdate.log 2014-02-02 21:53 - 2014-02-02 21:53 - 00001007 _____ () C:\Users\Guido\Desktop\JRT.txt 2014-02-02 19:51 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-02 19:49 - 2014-01-26 20:45 - 00000000 ____D () C:\AdwCleaner 2014-02-02 19:49 - 2006-11-02 14:01 - 00032560 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-02 17:30 - 2014-02-02 12:33 - 00000870 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-02 17:30 - 2014-02-02 12:33 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-02 13:08 - 2014-01-26 12:08 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\VOPackage 2014-02-02 12:55 - 2013-09-04 18:07 - 00000000 ____D () C:\Users\Guido\Documents\VirtualDJ 2014-02-02 09:53 - 2012-03-31 21:22 - 00000000 ____D () C:\Users\Guido\Documents\UseNeXT 2014-02-02 09:53 - 2012-03-31 21:22 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\UseNeXT 2014-02-02 09:26 - 2013-01-24 16:52 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\.minecraft 2014-02-02 08:54 - 2012-07-10 14:16 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-02-02 08:49 - 2011-01-05 15:01 - 00002591 _____ () C:\Users\Guido\Desktop\Microsoft Office Word 2007.lnk 2014-01-31 07:23 - 2011-01-05 15:01 - 00002633 _____ () C:\Users\Guido\Desktop\Microsoft Office PowerPoint 2007.lnk 2014-01-30 18:38 - 2009-09-10 21:31 - 00002137 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-28 20:08 - 2012-12-27 16:27 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\Audacity 2014-01-27 18:25 - 2009-09-10 17:27 - 00245760 _____ () C:\Users\Guido\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-27 15:58 - 2012-07-19 18:37 - 00000000 ____D () C:\Users\Guido\Alicia 2014-01-26 20:17 - 2008-01-21 03:47 - 01242720 _____ () C:\Windows\PFRO.log 2014-01-26 19:40 - 2014-01-26 19:40 - 00212992 _____ () C:\Windows\system32\config\DEFAULT.rhk 2014-01-26 19:40 - 2014-01-26 19:40 - 00090112 _____ () C:\Windows\system32\config\SAM.rhk 2014-01-26 19:40 - 2014-01-26 19:38 - 52482048 _____ () C:\Windows\system32\config\SOFTWARE.rhk 2014-01-26 19:38 - 2014-01-26 19:38 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk 2014-01-26 17:34 - 2006-11-02 11:33 - 01445546 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-01-26 12:16 - 2014-01-25 11:21 - 00000000 ____D () C:\Program Files\AmiExt 2014-01-26 12:15 - 2014-01-26 12:08 - 00000000 ____D () C:\ProgramData\IePluginService 2014-01-26 12:08 - 2012-03-30 13:07 - 00001133 _____ () C:\Users\Guido\Desktop\Internet Explorer.lnk 2014-01-26 12:08 - 2009-09-10 17:17 - 00001163 _____ () C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-25 16:53 - 2014-01-25 16:53 - 00133842 _____ () C:\Users\Guido\Documents\Tasche Karnevalsjeans.pptx 2014-01-25 15:11 - 2012-07-10 10:57 - 00000000 ____D () C:\Users\Guido\.gimp-2.8 2014-01-25 14:43 - 2014-01-25 14:43 - 00003466 _____ () C:\Users\Guido\AppData\Local\recently-used.xbel 2014-01-25 12:14 - 2012-12-28 20:35 - 00000000 ____D () C:\ProgramData\Nitro 2014-01-25 11:45 - 2012-05-28 19:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-01-25 11:45 - 2012-05-28 19:52 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-01-25 11:45 - 2009-10-04 11:25 - 00000000 ____D () C:\Users\Guido\AppData\Local\Adobe 2014-01-24 16:35 - 2010-03-05 02:05 - 00001474 _____ () C:\Users\Guido\AppData\Local\RecConfig.xml 2014-01-23 18:16 - 2012-05-28 14:31 - 00000000 ____D () C:\Users\Guido\AppData\Local\Deployment 2014-01-22 20:04 - 2014-01-22 20:04 - 00000000 ____D () C:\Users\Guido\Documents\Mixpad Projects 2014-01-22 17:10 - 2014-01-22 17:10 - 00000000 ____D () C:\Users\Guido\Desktop\Backup 2014-01-21 20:44 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2014-01-21 20:30 - 2014-01-21 20:27 - 00000604 _____ () C:\Users\Guido\Desktop\Schatti's AudioMixer.lnk 2014-01-21 20:30 - 2014-01-21 20:27 - 00000000 ____D () C:\AudioMixer 2014-01-20 19:38 - 2011-12-10 16:43 - 00000000 ___RD () C:\Users\Guido\Celina 2014-01-19 19:41 - 2009-09-10 17:16 - 00000000 ____D () C:\Users\Guido 2014-01-18 14:44 - 2014-01-16 17:24 - 00000000 ____D () C:\Users\Public\Documents\My DAZ 3D Library 2014-01-18 14:11 - 2014-01-18 14:11 - 00000000 ____D () C:\Users\Public\Pixologic 2014-01-18 14:10 - 2014-01-16 17:23 - 00000000 ____D () C:\ProgramData\DAZ 3D 2014-01-18 14:07 - 2014-01-16 17:23 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D 2014-01-18 14:06 - 2014-01-16 17:23 - 00000000 ____D () C:\Program Files\DAZ 3D 2014-01-18 13:39 - 2014-01-18 13:39 - 00000000 ____D () C:\Users\Public\Documents\DAZ 3D 2014-01-18 13:39 - 2014-01-16 17:21 - 00000000 ____D () C:\Users\Guido\AppData\Roaming\DAZ 3D 2014-01-17 12:57 - 2013-12-02 18:35 - 00000000 ___RD () C:\Users\Guido\Karneval 2008-2009 2014-01-16 17:36 - 2009-10-02 22:40 - 00007160 _____ () C:\Users\Guido\AppData\Local\d3d9caps.dat 2014-01-16 17:25 - 2014-01-16 17:25 - 00000000 ____D () C:\Program Files\Common Files\DAZ 2014-01-16 03:06 - 2013-08-15 02:06 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 03:02 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-01-15 18:05 - 2009-10-06 15:30 - 00000000 ____D () C:\Users\Guido\Desktop\Musik 2014-01-14 20:38 - 2010-10-04 20:22 - 00056898 _____ () C:\Windows\setupact.log 2014-01-13 21:06 - 2014-01-13 21:06 - 00052206 _____ () C:\Users\Guido\Documents\Overather Coffee.pptx Files to move or delete: ==================== C:\Users\Guido\Minecraft.exe C:\Users\Guido\PhotoZoom Pro 4 Setup.exe Some content of TEMP: ==================== C:\Users\Guido\AppData\Local\temp\avgnt.exe C:\Users\Guido\AppData\Local\temp\BackupSetup.exe C:\Users\Guido\AppData\Local\temp\EnableExtDll.dll C:\Users\Guido\AppData\Local\temp\i4jdel0.exe C:\Users\Guido\AppData\Local\temp\mpsetup.exe C:\Users\Guido\AppData\Local\temp\plus-hd.exe C:\Users\Guido\AppData\Local\temp\Quarantine.exe C:\Users\Guido\AppData\Local\temp\rtdrvmon.exe C:\Users\Guido\AppData\Local\temp\RtkBtMnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-02 20:07 ==================== End Of Log ============================ 'hoffe, dass das so richtig war |
![]() |
Themen zu Awesomehp.com Virus entfernen |
awesomehp, awesomehp.com, awesomehp.com virus entfernen, befreien, entferne, entfernen, explorers, freeware, heulen, inter, interne, seite, startseite, virus, virus entfernen |