![]() |
|
Log-Analyse und Auswertung: TR/TDss.bckj.7' und TR/FraudPack.auiv' gefunden! AntiVirWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() ![]() | ![]() TR/TDss.bckj.7' und TR/FraudPack.auiv' gefunden! AntiVir Hallo! da mir mein AntiVir gerade bescheid gegeben hat das ich mir wohl diese zwei Trojaner eingefangen habe (TR/TDss.bckj.7' [trojan] und TR/FraudPack.auiv' [trojan] ), wollte ich mal meine Logs nach dem CCleaner und Malwarebytes checken lassen. Hier meine Logs: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4076 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18904 08.05.2010 12:28:27 mbam-log-2010-05-08 (12-28-27).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 300618 Laufzeit: 25 Minute(n), 55 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 1 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) OTL logfile created on: 08.05.2010 12:32:50 - Run 1 OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\****\Downloads 64bit-Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 48,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 75,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 146,48 Gb Total Space | 98,96 Gb Free Space | 67,56% Space Free | Partition Type: NTFS Drive D: | 151,60 Gb Total Space | 79,16 Gb Free Space | 52,22% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ******* Current User Name: ***** Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Daniel\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Windows\SysWOW64\PnkBstrA.exe () PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Logitech\GamePanel Software\Applets\LCDMedia.exe (Logitech Inc.) PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe () ========== Modules (SafeList) ========== MOD - C:\Users\Daniel\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software) SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation) SRV:64bit: - (O&O Defrag) -- C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH) SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) SRV:64bit: - (BthServ) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation) SRV:64bit: - (wbengine) -- C:\Windows\SysNative\wbengine.exe (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV:64bit: - (Fax) -- C:\Windows\SysNative\fxssvc.exe (Microsoft Corporation) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (TuneUp.Defrag) -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software) SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe (TuneUp Software) SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (Microsoft Office Groove Audit Service) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation) SRV - (AAV UpdateService) -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe () SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006.11.02 15:34:14 | 000,000,000 | ---D | M] SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof () ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH) DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\DRIVERS\atipmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.) DRV:64bit: - (LGVirHid) -- C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.) DRV:64bit: - (LGBusEnum) -- C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.) DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\DRIVERS\usb8023x.sys (Microsoft Corporation) DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation) DRV:64bit: - (WINUSB) -- C:\Windows\SysNative\DRIVERS\WinUSB.SYS (Microsoft Corporation) DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) DRV:64bit: - (cpuz132) -- C:\Windows\SysNative\drivers\cpuz132_x64.sys (Windows (R) Codename Longhorn DDK provider) DRV:64bit: - (pcouffin) -- C:\Windows\SysNative\Drivers\pcouffin.sys (VSO Software) DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys () DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV:64bit: - (ATIAVAIW) -- C:\Windows\SysNative\DRIVERS\atinavt2.sys (ATI Technologies Inc.) DRV:64bit: - (ENTECH64) -- C:\Windows\SysNative\DRIVERS\ENTECH64.sys (EnTech Taiwan) DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation ) DRV:64bit: - (ATITool) -- C:\Windows\SysNative\DRIVERS\ATITool64.sys () DRV:64bit: - (s116unic) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM) -- C:\Windows\SysNative\DRIVERS\s116unic.sys (MCCI Corporation) DRV:64bit: - (s116obex) -- C:\Windows\SysNative\DRIVERS\s116obex.sys (MCCI Corporation) DRV:64bit: - (s116mgmt) Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM) -- C:\Windows\SysNative\DRIVERS\s116mgmt.sys (MCCI Corporation) DRV:64bit: - (s116nd5) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS) -- C:\Windows\SysNative\DRIVERS\s116nd5.sys (MCCI Corporation) DRV:64bit: - (s116mdm) -- C:\Windows\SysNative\DRIVERS\s116mdm.sys (MCCI Corporation) DRV:64bit: - (s116mdfl) -- C:\Windows\SysNative\DRIVERS\s116mdfl.sys (MCCI Corporation) DRV:64bit: - (s116bus) Sony Ericsson Device 116 driver (WDM) -- C:\Windows\SysNative\DRIVERS\s116bus.sys (MCCI Corporation) DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys (TuneUp Software) DRV - (WinRing0_1_1_1) -- C:\C2DtoG15\WinRing0x64.sys (OpenLibSys.org) DRV - (CSC) -- C:\Windows\CSC [2008.06.27 13:03:40 | 000,000,000 | ---D | M] DRV - (FLASHSYS) -- C:\Program Files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys () DRV - (WINUSB) -- C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation) DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (ENTECH64) -- C:\Windows\SysWOW64\drivers\Entech64.sys (EnTech Taiwan) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B3 C4 CA 1E 6B BF C9 01 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Ask" FF - prefs.js..browser.search.order.1: "Ask" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://de.msn.com" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2 FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.4 FF - prefs.js..keyword.URL: "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=" FF - prefs.js..network.proxy.no_proxies_on: "*.local" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.04.02 09:05:35 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.05.08 10:42:07 | 000,000,000 | ---D | M] [2008.07.14 15:22:37 | 000,000,000 | ---D | M] -- C:\Users\Daniel\AppData\Roaming\mozilla\Extensions [2010.05.08 10:46:41 | 000,000,000 | ---D | M] -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\2b4kc0u7.default\extensions [2010.05.01 07:08:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\2b4kc0u7.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} [2010.05.01 07:08:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\2b4kc0u7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010.05.01 07:08:29 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Daniel\AppData\Roaming\mozilla\Firefox\Profiles\2b4kc0u7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009.05.28 10:37:58 | 000,000,682 | ---- | M] () -- C:\Users\Daniel\AppData\Roaming\Mozilla\FireFox\Profiles\2b4kc0u7.default\searchplugins\ask.xml [2008.07.29 17:40:29 | 000,000,523 | ---- | M] () -- C:\Users\Daniel\AppData\Roaming\Mozilla\FireFox\Profiles\2b4kc0u7.default\searchplugins\daemon-search.xml [2009.04.23 07:53:39 | 000,001,744 | ---- | M] () -- C:\Users\Daniel\AppData\Roaming\Mozilla\FireFox\Profiles\2b4kc0u7.default\searchplugins\live-search.xml [2010.03.06 08:09:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2008.06.30 23:02:00 | 000,663,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npOGAPlugin.dll [2010.01.16 03:15:29 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.01.16 03:15:29 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.01.16 03:15:29 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.01.16 03:15:29 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.01.16 03:15:29 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.05.01 08:59:56 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MI1933~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MI1933~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MI1933~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img33.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img33.jpg O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{a933f0ae-0591-11de-97f7-002185029410}\Shell - "" = AutoRun O33 - MountPoints2\{a933f0ae-0591-11de-97f7-002185029410}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found O33 - MountPoints2\{a933f0d8-0591-11de-97f7-002185029410}\Shell - "" = AutoRun O33 - MountPoints2\{a933f0d8-0591-11de-97f7-002185029410}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found O33 - MountPoints2\{f3982d78-b99f-11de-9f5b-002185029410}\Shell - "" = AutoRun O33 - MountPoints2\{f3982d78-b99f-11de-9f5b-002185029410}\Shell\AutoRun\command - "" = F:\Install.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk /p \??\H ![]() O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (OODBS) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.05.08 11:35:39 | 000,000,000 | ---D | C] -- C:\avrescue [2010.05.08 11:33:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner [2010.05.06 17:29:08 | 000,000,000 | ---D | C] -- C:\84e6b7a912312b6446727437d0 [2010.05.01 09:05:03 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.05.01 09:05:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.05.01 08:59:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Enigma Software Group [2010.05.01 08:59:27 | 000,000,000 | ---D | C] -- C:\Windows\61D3AAE1D5214CD7939B37813DE8F955.TMP [2010.05.01 08:59:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2010.05.01 08:09:07 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\jelbltpcp [2010.04.24 12:42:22 | 000,000,000 | ---D | C] -- C:\Users\Daniel\Documents\BFBC2 [2010.04.15 06:31:41 | 004,697,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2010.04.15 06:31:39 | 000,612,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2010.04.15 06:31:39 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll [2010.04.15 06:31:33 | 000,220,672 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\SysWow64\l3codecp.acm [2010.04.15 06:31:33 | 000,181,760 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\SysNative\l3codecp.acm [2010.04.15 06:31:33 | 000,072,192 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\SysNative\l3codeca.acm [2010.04.15 06:31:33 | 000,062,464 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\SysWow64\l3codeca.acm [2010.04.15 06:30:39 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2010.04.15 06:30:39 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll [2010.04.15 06:30:39 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll [2010.04.15 06:30:39 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2010.04.09 16:25:43 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\oodag [2010.04.09 16:24:21 | 000,000,000 | ---D | C] -- C:\Users\Daniel\AppData\Local\O&O [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.05.08 12:34:06 | 004,456,448 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat [2010.05.08 11:33:55 | 000,001,724 | ---- | M] () -- C:\Users\Daniel\Desktop\CCleaner.lnk [2010.05.08 11:31:57 | 001,682,544 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.05.08 11:31:57 | 000,721,592 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.05.08 11:31:57 | 000,665,324 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.05.08 11:31:57 | 000,164,180 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.05.08 11:31:57 | 000,134,806 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.05.08 11:26:23 | 000,004,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.05.08 11:26:23 | 000,004,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.05.08 11:26:20 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.05.08 11:26:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.05.08 11:26:16 | 4294,225,920 | -HS- | M] () -- C:\hiberfil.sys [2010.05.08 11:26:14 | 002,781,067 | ---- | M] () -- C:\Windows\SysNative\oodbs.lor [2010.05.08 10:01:47 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010.05.08 10:01:46 | 000,524,288 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat{24342c1d-5938-11df-8576-002185029410}.TMContainer00000000000000000001.regtrans-ms [2010.05.08 10:01:46 | 000,065,536 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat{24342c1d-5938-11df-8576-002185029410}.TM.blf [2010.05.08 10:01:42 | 003,886,453 | -H-- | M] () -- C:\Users\Daniel\AppData\Local\IconCache.db [2010.05.07 16:25:56 | 000,218,808 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2010.05.07 16:25:56 | 000,218,808 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2010.05.06 20:08:14 | 000,524,288 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat{24342c1d-5938-11df-8576-002185029410}.TMContainer00000000000000000002.regtrans-ms [2010.05.04 06:48:00 | 000,524,288 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat{bbd8bd67-4ef2-11df-9fb6-002185029410}.TMContainer00000000000000000001.regtrans-ms [2010.05.04 06:48:00 | 000,065,536 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat{bbd8bd67-4ef2-11df-9fb6-002185029410}.TM.blf [2010.05.01 09:23:15 | 000,001,928 | ---- | M] () -- C:\Users\Daniel\Desktop\HijackThis.lnk [2010.05.01 09:05:06 | 000,000,848 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.04.29 15:39:28 | 000,024,664 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.04.28 18:33:32 | 000,398,968 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.04.26 18:57:50 | 000,033,280 | ---- | M] () -- C:\Users\Daniel\Documents\KFW.doc [2010.04.24 12:41:43 | 002,434,856 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2010.04.24 12:41:43 | 000,075,064 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe [2010.04.23 19:38:58 | 000,524,288 | -HS- | M] () -- C:\Users\Daniel\ntuser.dat{bbd8bd67-4ef2-11df-9fb6-002185029410}.TMContainer00000000000000000002.regtrans-ms [2010.04.23 07:51:02 | 000,524,288 | -HS- | M] () -- C:\Users\Daniel\NTUSER.DAT{fcfc8c50-9e88-11de-9a6f-002185029410}.TMContainer00000000000000000001.regtrans-ms [2010.04.23 07:51:02 | 000,065,536 | -HS- | M] () -- C:\Users\Daniel\NTUSER.DAT{fcfc8c50-9e88-11de-9a6f-002185029410}.TM.blf [2010.04.17 09:10:18 | 000,010,843 | ---- | M] () -- C:\Users\Daniel\Documents\Einnahman Ausgaben.xlsx [2010.04.09 16:26:34 | 000,123,904 | ---- | M] () -- C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.04.09 16:23:45 | 000,001,900 | ---- | M] () -- C:\Users\Public\Desktop\O&O Defrag.lnk [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.05.08 11:33:55 | 000,001,724 | ---- | C] () -- C:\Users\Daniel\Desktop\CCleaner.lnk [2010.05.06 19:53:10 | 000,524,288 | -HS- | C] () -- C:\Users\Daniel\ntuser.dat{24342c1d-5938-11df-8576-002185029410}.TMContainer00000000000000000002.regtrans-ms [2010.05.06 19:53:10 | 000,524,288 | -HS- | C] () -- C:\Users\Daniel\ntuser.dat{24342c1d-5938-11df-8576-002185029410}.TMContainer00000000000000000001.regtrans-ms [2010.05.06 19:53:10 | 000,065,536 | -HS- | C] () -- C:\Users\Daniel\ntuser.dat{24342c1d-5938-11df-8576-002185029410}.TM.blf [2010.05.01 09:18:21 | 000,001,928 | ---- | C] () -- C:\Users\Daniel\Desktop\HijackThis.lnk [2010.05.01 09:05:06 | 000,000,848 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.04.26 18:43:41 | 000,033,280 | ---- | C] () -- C:\Users\Daniel\Documents\KFW.doc [2010.04.24 12:42:29 | 000,218,808 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2010.04.24 12:41:43 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2010.04.23 18:11:11 | 000,524,288 | -HS- | C] () -- C:\Users\Daniel\ntuser.dat{bbd8bd67-4ef2-11df-9fb6-002185029410}.TMContainer00000000000000000002.regtrans-ms [2010.04.23 18:11:11 | 000,524,288 | -HS- | C] () -- C:\Users\Daniel\ntuser.dat{bbd8bd67-4ef2-11df-9fb6-002185029410}.TMContainer00000000000000000001.regtrans-ms [2010.04.23 18:11:11 | 000,065,536 | -HS- | C] () -- C:\Users\Daniel\ntuser.dat{bbd8bd67-4ef2-11df-9fb6-002185029410}.TM.blf [2010.04.09 16:23:45 | 000,001,900 | ---- | C] () -- C:\Users\Public\Desktop\O&O Defrag.lnk [2010.01.20 18:57:22 | 000,146,432 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2010.01.20 18:57:22 | 000,072,704 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2009.10.25 12:43:43 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll [2009.10.25 12:43:03 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.08.29 10:34:59 | 000,765,952 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2009.08.29 10:34:59 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2009.07.12 12:06:39 | 000,000,170 | ---- | C] () -- C:\Windows\ODBC.INI [2009.07.10 15:31:17 | 000,000,032 | ---- | C] () -- C:\Windows\CD-Start.INI [2009.03.08 11:33:05 | 000,000,336 | ---- | C] () -- C:\Windows\SIERRA.INI [2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll [2008.07.21 16:12:04 | 000,495,616 | ---- | C] () -- C:\Windows\SysWow64\Tx32.dll [2008.07.21 16:12:04 | 000,000,260 | ---- | C] () -- C:\Windows\SysWow64\ic32.ini [2008.07.11 13:11:21 | 000,000,004 | ---- | C] () -- C:\Windows\info147.sys [2008.07.03 20:07:12 | 001,664,928 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2008.06.27 17:03:55 | 000,000,000 | ---- | C] () -- C:\Windows\oodcnt.INI [2008.06.27 14:22:25 | 000,003,972 | ---- | C] () -- C:\Windows\SysWow64\drivers\PciBus.sys [2008.01.21 04:48:25 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini ========== Alternate Data Streams ========== @Alternate Data Stream - 72 bytes -> C:\Windows:76D44167FD72F082 @Alternate Data Stream - 487 bytes -> C:\ProgramData\TEMP:05EE1EEF @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:425D0709 < End of report > |
Themen zu TR/TDss.bckj.7' und TR/FraudPack.auiv' gefunden! AntiVir |
.dll, adblock, alternate, antivir, autorun, avira, avsuite, bho, components, desktop, enigma, error, explorer, firefox, firefox 3.6.3, firefox.exe, fontcache, format, google, hdaudio.sys, helper, hijack, install.exe, installation, langs, launch, location, logfile, mozilla, object, oldtimer, otl.exe, plug-in, programdata, realtek, registry, sched.exe, searchplugins, senden, software, sptd.sys, syswow64, temp, trojaner, trojaner eingefangen, usb, vista, zwei trojaner |