![]() |
Okay, hier das OTL: All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Nfitoba deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Max ->Temp folder emptied: 405198 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 7003332 bytes ->Flash cache emptied: 456 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 46616 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 7,00 mb OTL by OldTimer - Version 3.2.26.1 log created on 08072011_201934 Files\Folders moved on Reboot... File\Folder C:\Users\Max\AppData\Local\Temp\~DF22D3.tmp not found! File\Folder C:\Users\Max\AppData\Local\Temp\~DF3FEA.tmp not found! C:\Windows\temp\kvsqsb\setup.exe moved successfully. Registry entries deleted on Reboot... |
Und hier das Bitdefender File: QuickScan Beta 32-bit v0.9.9.99 ------------------------------- Überprüfungsdatum: Sun Aug 07 20:27:53 2011 Computer ID: A8F31D43 C:\Windows\temp\kvsqsb\setup.exe - zugriff nicht möglich --> Vorgang setup.exe (1820) Keine Infizierungen gefunden. ----------------------------- Prozesse -------- AntiVir Desktop 2604 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe AntiVir Desktop 1860 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe AntiVir Desktop 1588 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe AVM AVMWlanService 1888 C:\Program Files (x86)\avmwlanstick\WLanNetService.exe AVM FRITZ!WLAN 2592 C:\Program Files (x86)\avmwlanstick\WLanGUI.exe Betriebssystem Microsoft® Windows® 3924 C:\Windows\SysWOW64\PING.EXE Device Error Recovery SDK 1952 C:\Windows\SysWOW64\dgdersvc.exe DivX Download Manager Service 2956 C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe DivX Update 3016 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe Firefox 4052 C:\Program Files (x86)\Mozilla Firefox\firefox.exe Firefox 3300 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Kies TrayAgent 2076 C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe KiesPDLR 2324 C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Microsoft Office 2003 2368 C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE Pando Media Booster 1200 C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe PnkBstrA.exe 2044 C:\Windows\SysWOW64\PnkBstrA.exe Netzwerkaktivität ----------------- Vorgang setup.exe (1820) verbunden mit Anschluss 3000 --> **.***.***.*** Vorgang plugin-container.exe (3300) verbunden mit Anschluss 80 (HTTP) --> **.**.***.** Vorgang firefox.exe (4052) verbunden mit Anschluss 80 (HTTP) --> ***.**.***.*** Vorgang firefox.exe (4052) verbunden mit Anschluss 80 (HTTP) --> ***.**.***.*** Vorgang firefox.exe (4052) verbunden mit Anschluss 80 (HTTP) --> **.***.***.*** Vorgang firefox.exe (4052) verbunden mit Anschluss 80 (HTTP) --> ***.**.***.*** Vorgang PMB.exe (1200) kontrolliert die Anschlüsse: 443 (HTTP over SSL), 563 (NNTP over SSL), 56735 Autoruns und kritische Dateien ------------------------------ AntiVir Desktop C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe AVM FRITZ!WLAN C:\Program Files (x86)\avmwlanstick\WLanGUI.exe Betriebssystem Microsoft® Windows® c:\windows\system32\browseui.dll Betriebssystem Microsoft® Windows® C:\Windows\system32\ssText3d.scr Catalyst® Control Center C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe DivX Download Manager Service C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe DivX Update C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe Kies C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe Kies TrayAgent C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe KiesPDLR C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Pando Media Booster C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe Windows® Internet Explorer c:\windows\syswow64\webcheck.dll (verifiziert) Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (verifiziert) Betriebssystem Microsoft® Windows® c:\windows\system32\userinit.exe (verifiziert) Google Update C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Browser Plugins --------------- AcroIEHelper Library c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelper.dll Adobe Acrobat C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll BitDefender QuickScan C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\sjrc5bed.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll DivX OVS Helper Plug-in C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll DivX Web Player c:\program files (x86)\divx\divx plus web player\npdivx32.dll Flash® Player Installer/Uninstaller C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe Google Earth Plugin C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll Google Update C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll ICQ C:\Program Files (x86)\ICQ7.2\ICQ.exe Microsoft Office 2003 C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL nppdf32.DEU C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.DEU NPSWF32.dll C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll Pando Web Plugin C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll Skype Toolbars c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll Widgi Toolbar c:\program files (x86)\youtube downloader toolbar\ie\4.5\youtubedownloadertoolbarie.dll Windows Presentation Foundation C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll Windows® Internet Explorer c:\windows\syswow64\ieframe.dll (verifiziert) Betriebssystem Microsoft® Windows® C:\Windows\system32\mswsock.dll (verifiziert) Betriebssystem Microsoft® Windows® C:\Windows\system32\napinsp.dll (verifiziert) Betriebssystem Microsoft® Windows® C:\Windows\system32\pnrpnsp.dll (verifiziert) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll (verifiziert) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll Überprüfen ---------- MD5: 3912f8e7a48a1446e054d1e79da355bc C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MD5: 6159c95aa16e8b2a01b7a001b8c134c3 C:\Program Files (x86)\Avira\AntiVir Desktop\aecore.dll MD5: ee0477f95aaf614c5cb14f324ca48c3d C:\Program Files (x86)\Avira\AntiVir Desktop\aeemu.dll MD5: 99fc44836c9faa66d3dd7f6264c2996b C:\Program Files (x86)\Avira\AntiVir Desktop\aegen.dll MD5: e1805cf3f4739be2311a50966ebe0ce7 C:\Program Files (x86)\Avira\AntiVir Desktop\aehelp.dll MD5: 5d6d771cd7478365926dfe609824b060 C:\Program Files (x86)\Avira\AntiVir Desktop\aeheur.dll MD5: 24af31feed98a2ba8f0649045c05c3bc C:\Program Files (x86)\Avira\AntiVir Desktop\aeoffice.dll MD5: 1ca8605d69c9d53c837bd6ab57c9294b C:\Program Files (x86)\Avira\AntiVir Desktop\aepack.dll MD5: 6510790b36f61d75948e9e001b6775ab C:\Program Files (x86)\Avira\AntiVir Desktop\aerdl.dll MD5: ea8d2dcbadb11928df166a5683d7b524 C:\Program Files (x86)\Avira\AntiVir Desktop\aesbx.dll MD5: 864e4cec9f60c25a8a93ad3784da2e64 C:\Program Files (x86)\Avira\AntiVir Desktop\aescn.dll MD5: 3a0638167d746bcbe06494945943ad30 C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll MD5: 100caaf3542fb51feca9c09db1cb940d C:\Program Files (x86)\Avira\AntiVir Desktop\aevdf.dll MD5: c55ee924474044ca64b473b356e9d080 C:\Program Files (x86)\Avira\AntiVir Desktop\avesvc.dll MD5: 77cf51df00905f2312f41d181056cdcd C:\Program Files (x86)\Avira\AntiVir Desktop\avesvcr.dll MD5: 4c3eed40c3f2a9fc9956b0511d431304 C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll MD5: 5ee5c132d47ba6f331099bff1d1db539 C:\Program Files (x86)\Avira\AntiVir Desktop\AVGIO.DLL MD5: 61941d4566c3b09f377e0e1a97bd0d9a C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe MD5: 72d90e56563165984224493069c69ed4 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe MD5: 5252bb49a0b35e1127d3771e21c7af6d C:\Program Files (x86)\Avira\AntiVir Desktop\AVPREF.DLL MD5: f7263b4e58e0346178cad70eac7f35e6 c:\program files (x86)\avira\antivir desktop\ccgen.dll MD5: 99fadefb3e0cfe592c4cdaccdbae12e5 c:\program files (x86)\avira\antivir desktop\ccgenrc.dll MD5: 86e162677d131e5fa32fb2bff60cfd05 c:\program files (x86)\avira\antivir desktop\ccgrdrc.dll MD5: 4b3a4639dd281b709162a2120b3daefc c:\program files (x86)\avira\antivir desktop\ccguard.dll MD5: c0245ed1f48397d41632cab0afa842ce c:\program files (x86)\avira\antivir desktop\cclic.dll MD5: d17e73d08d3f9bf86778ca32bafea292 c:\program files (x86)\avira\antivir desktop\cclicrc.dll MD5: 05be6a994e936dc58ee3940e0bb46e70 c:\program files (x86)\avira\antivir desktop\ccmainrc.dll MD5: 98d551a16398529f181570a001843231 c:\program files (x86)\avira\antivir desktop\ccmsg.dll MD5: d201762816e297d0eed3b7cf00d64c93 c:\program files (x86)\avira\antivir desktop\ccmsgrc.dll MD5: bd655a8ecaf694c48684b89c745f52fa c:\program files (x86)\avira\antivir desktop\ccupdate.dll MD5: 6bb82348cc5c8d0ac51090f2bf7e0a92 c:\program files (x86)\avira\antivir desktop\ccupdrc.dll MD5: a0ef10de0d455e33adffc39948660899 c:\program files (x86)\avira\antivir desktop\ccupdw.dll MD5: 0014339814c89abf148f49976146941c c:\program files (x86)\avira\antivir desktop\ccwgrd.dll MD5: 3defa178843b7d2cd67f63c1e2119857 c:\program files (x86)\avira\antivir desktop\ccwgrdrc.dll MD5: d41a02871f992a2c47b84a95c2a78b40 c:\program files (x86)\avira\antivir desktop\ccwgrdw.dll MD5: 47766f6b79a25af04ed3f6f2b02aa4cb C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll MD5: d710a6d072bfb305ec0a92b9c79b7a32 C:\Program Files (x86)\Avira\AntiVir Desktop\guardmsg.dll MD5: b54557b71a82e1f9bc914991328cef16 C:\Program Files (x86)\Avira\AntiVir Desktop\onlcfg.dll MD5: befda36cc978316a4b31495364b7e786 C:\Program Files (x86)\Avira\AntiVir Desktop\rcimage.dll MD5: c27d46b06d340293670450fce9dfb166 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe MD5: 11f5a7193b32e6d7d8efe0c17271916c C:\Program Files (x86)\Avira\AntiVir Desktop\schedr.dll MD5: 86fa1ecde6424cf93befd20ba4f2bc55 C:\Program Files (x86)\Avira\AntiVir Desktop\webcat.dll MD5: 8d61c508ea68f9b032d21cc48adfaa8d C:\Program Files (x86)\avmwlanstick\avmsysnet.dll MD5: 99d317ac2ba35b63a50aaafee4c760ed C:\Program Files (x86)\avmwlanstick\avmwlapi.dll MD5: aaa66f4d2b2a0382926f306c5a99440a C:\Program Files (x86)\avmwlanstick\WLanGUI.exe MD5: 9bd46c1d2f33a890b7226edf543f18aa C:\Program Files (x86)\avmwlanstick\WLanNetService.exe MD5: c11f6a1f61481e24be3fdc06ea6f7d2a c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelper.dll MD5: 251c11444f614de5fa47ecf7275e7bf1 C:\Program Files (x86)\Common Files\Microsoft Shared\office11\mso.dll MD5: 8caf5c1748401032efabb3d52e27c1be C:\Program Files (x86)\Common Files\Microsoft Shared\office11\riched20.dll MD5: 89175c7a2984459c0f0b0778f85a2251 C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF\1031\MSGR3EN.DLL MD5: 971ffaf1206d101f2b7875698124ccbf C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF\mslid.dll MD5: 4ad532426cea90f59b5364f7be5f2a86 C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF\MSSP3GE.DLL MD5: f29a80f607703ca1fc5d25993cc7feda C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL MD5: 5252198cf3f45114c6ca27bad1635da0 C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\1031\STINTL.DLL MD5: deaa0f5ff041981e34ca79257ba44414 C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\FNAME.DLL MD5: b5003cb6d91829e33997d7056a534872 C:\Program Files (x86)\Common Files\Steam\SteamService.exe MD5: f4d62a129aaee4a619fce0c03b15e94c C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll MD5: 57d8c4ed26dfd7ef0e2cb196fb8bfb54 C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe MD5: 4b988e3393789572cdb143ddac3a2fc0 C:\Program Files (x86)\DivX\DivX Plus Web Player\DivXDownloadManager.dll MD5: abb7a668b5d11bff77dd00cc2b6c8db0 c:\program files (x86)\divx\divx plus web player\npdivx32.dll MD5: a58e05767687e1e636d160ecea9bc8ed C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe MD5: 6031368292d5e8909fb088b31e183ec8 C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll MD5: 0f445b821549f9ff471bba56c69953d4 C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll MD5: b226054bfa3d3a1920f7b95e54f3e87d C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll MD5: 83ebccc27098b1d1f20f72e10d6bf309 C:\Program Files (x86)\ICQ7.2\ICQ.exe MD5: 63397ff71c1bc450e3d07782dd0c2e0d C:\Program Files (x86)\Microsoft Office\OFFICE11\msostyle.dll MD5: 1eea7dd2f1ea6efef380b99a90228d2f C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE MD5: b957b30090889aa4f887277916f76fe7 C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll MD5: 6c9cd3ecba6732661c8bbe37a877a2bd C:\Program Files (x86)\Mozilla Firefox\firefox.exe MD5: cc5b1a70daa7a04fe15e6d7c54b55d02 C:\Program Files (x86)\Mozilla Firefox\freebl3.dll MD5: ff4040da11ae0d13a0a7778e6022e728 C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll MD5: 96397535f6e4ca499dd659ce76c50746 C:\Program Files (x86)\Mozilla Firefox\MOZCPP19.dll MD5: 411f23aaf331da8b9f0cfd1cada4b8b5 C:\Program Files (x86)\Mozilla Firefox\MOZCRT19.dll MD5: 1919d815996470088d20a59e992a9695 C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MD5: fcd1d9ccc7096dc2210d3096fbdf92cc C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll MD5: c1bf9c9244996aa0607766199d226183 C:\Program Files (x86)\Mozilla Firefox\nspr4.dll MD5: f030ff40b6afb777b9992525800de3ea C:\Program Files (x86)\Mozilla Firefox\nss3.dll MD5: 6689b655ea803be040d95b8ea913249f C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll MD5: 079155b0a7579652dcc2ec7908d9502a C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll MD5: fb4fc7ee2e516063e25887c2e170d893 C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll MD5: 4dfdfb82c4f60beaf88e3c13c01f124a C:\Program Files (x86)\Mozilla Firefox\plc4.dll MD5: 5bff0a2260ab6bf8d9b829d947c5ef6c C:\Program Files (x86)\Mozilla Firefox\plds4.dll MD5: 4486ad32bb05628967695fca1badd46e C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe MD5: 8b07628e389e72b83473383914333ad6 C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL MD5: 1972e3168b6ba0a968a6a4b86e390b38 C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.DEU MD5: 04af8bc83a89d9b71f7e0bcaf9fdd768 C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll MD5: cb2e646a69d347eb0437ab50785cf3bb C:\Program Files (x86)\Mozilla Firefox\smime3.dll MD5: 363f20b791469048b0878dbdfd60e41b C:\Program Files (x86)\Mozilla Firefox\softokn3.dll MD5: b6a4cb50c2c0d7821a604c64a5058ed1 C:\Program Files (x86)\Mozilla Firefox\ssl3.dll MD5: cd05ba08fd35ec561b82f6d1c905a445 C:\Program Files (x86)\Mozilla Firefox\xpcom.dll MD5: 840e1ad2fdeedf482927d4369fb03dac C:\Program Files (x86)\Mozilla Firefox\xul.dll MD5: 904f19d9b38895bd92b67738d8a1facf C:\Program Files (x86)\Pando Networks\Media Booster\BugSplat.dll MD5: 244c2be6546609ee0a627b507ed57699 C:\Program Files (x86)\Pando Networks\Media Booster\freebl3.dll MD5: 0ca99c5acf7d36b6ec8f504a1f11902b C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll MD5: 64f8d5047147c54fc5d524e4513ca327 C:\Program Files (x86)\Pando Networks\Media Booster\nspr4.dll MD5: ac3e2a5b33a035827cb73a6e76d0fe96 C:\Program Files (x86)\Pando Networks\Media Booster\nss3.dll MD5: 84ea29214303fecbae4fbd249d43c54d C:\Program Files (x86)\Pando Networks\Media Booster\plc4.dll MD5: dcf946d365991221dfdd5db29c4bfdf7 C:\Program Files (x86)\Pando Networks\Media Booster\plds4.dll MD5: ad58699da72fff9d87b7cae78964d127 C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe MD5: 8a07ac5a1ec46972288dbd3dffb00cc4 C:\Program Files (x86)\Pando Networks\Media Booster\smime3.dll MD5: 5bd6b446e028af843d9f01eea2185000 C:\Program Files (x86)\Pando Networks\Media Booster\softokn3.dll MD5: 7392461e219cd8384ba07119b17a768c C:\Program Files (x86)\Pando Networks\Media Booster\ssl3.dll MD5: 8793bea49c0aa4afa7800f3c3b3fefc8 C:\Program Files (x86)\Samsung\Kies\External\DeviceModules\UPNPDevice_Kies.dll MD5: 0b8834334450ee1371ee824173af6c41 C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MD5: a40a9388c4dd9a6d7ffe1b2901612761 C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe MD5: ef44b359e520b5b9528ac0b3de9f7dd5 C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MD5: 590c4454a1d36f76da1f636fad139771 c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll MD5: 808ca0e4d7b62e5b3b2d5ac278d3bf8e c:\program files (x86)\youtube downloader toolbar\ie\4.5\youtubedownloadertoolbarie.dll MD5: ab26aa5f24fa96fec4a7b0c70df5af27 C:\Users\Max\AppData\Local\Temp\b01d42a6-0948-4bd0-8dea-54d68f50a791\CliSecureRT.dll MD5: f4a569f89a90205a095965ae628625e1 C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\sjrc5bed.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll MD5: fd647ca82acf232dbe5f20345647b948 C:\Windows\AppPatch\AcGenral.DLL MD5: 5a5dec75f662fbb8e48dd29b2d929473 C:\Windows\AppPatch\AcSpecfc.DLL MD5: 2ce97833ba80e7c319390c4b071bda00 C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\74353039393f68f4c068cc37f759e5be\mscorlib.ni.dll MD5: 2d7617d3143493eb8bd38290e9d2e51a C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\ca8307311e87b234b2faa5ee08332722\PresentationCore.ni.dll MD5: ed51ca800645080bbfdda92c1b172742 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\2250ddb1626087da27fb00f46a679ff5\PresentationFramework.ni.dll MD5: 30a6abfdafc89976c52400665105e805 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b61b31d1f518e9663fc204e7de21215a\PresentationFramework.Aero.ni.dll MD5: f61faa6504ef9939867bc4ca5f50f2c0 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\0d4cdd1b911d6e28b4fd5c43ab39f7ea\System.Core.ni.dll MD5: 63c13a88fb0520a8e2d46fd529680f16 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\53591520988a6ee49924e1efc911df30\System.Drawing.ni.dll MD5: 647c58aa860262ab06c75fec8e3de286 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\76d7e84f5dca7908b45edba58bd12f48\System.Management.ni.dll MD5: db5ea8b98004ec7e0adba7b4f9033d9f C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\1419704737b7f46a48bc854aa2f5597d\System.Runtime.Remoting.ni.dll MD5: 33101aaeff4e876d07f7ecb3616e68db C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f3e016a2e799cfe233b13d88e90c0e0b\System.Windows.Forms.ni.dll MD5: 2bc43a2c4b0b3bc7863fede5031a9037 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\19f85a4f6faaeb87a9055ccf23a9f8b7\System.Xaml.ni.dll MD5: 6ac72593c1244399816bb40f21b41af6 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7cc17b90932adaad5651ceb526cade44\System.Xml.ni.dll MD5: 68f2e9e1ee53b6aa03ab6ec62c43f145 C:\Windows\assembly\NativeImages_v4.0.30319_32\System\5a8bf6ab1a6ba60e7355fa4cc61fd0c5\System.ni.dll MD5: cc16b7c2367f8c4762bf770286b0a0b1 C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\3154b66d01dcd674b256e03d5f359fac\WindowsBase.ni.dll MD5: 632e0ce38fbcadeaae28077f4c9c45d5 C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe MD5: ce07a466201096f021cd09d631b21540 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe MD5: 749f5f8cedca70f2a512945325fc489d C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe MD5: bc5b0be5af3510b0fd8c140ee42c6d3e C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe MD5: ab87eeffd18f2baafc274e7075ea6c67 C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll MD5: 1a11a757d613f8a815b8e30025522628 C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll MD5: 7b1028a754bb63bbfc75b6a94c3f47e5 C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll MD5: 1986443c2f2c0e2a18e908dd241bf84d C:\Windows\Microsoft.NET\Framework\v4.0.30319\culture.dll MD5: f711c8d93a8e4410c284d177b76c7f2b C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll MD5: 9383d302f0d95db0802308cf250727f3 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll MD5: 56d16a44691c0337dd0ef3f3008a9977 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll MD5: ebc6332093aec6a4fbf2c3919d03877a C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpftxt_v0400.dll MD5: 66328b08ef5a9305d8ede36b93930369 C:\Windows\servicing\TrustedInstaller.exe MD5: 378e22d49bea659ef11e6829ed058fc7 C:\Windows\system32\atiumdag.dll MD5: a184e7e06d4d9336ad5cb84e1d8dcb92 C:\Windows\system32\atiumdva.dll MD5: da7478ba9e41b60b3d5da456e253002a C:\Windows\system32\audioeng.dll MD5: 4acf748a8e576761e4c610acab67b1bc C:\Windows\system32\BCRYPT.dll MD5: 74f26fc01b180d4a99a168ed69c30a53 C:\Windows\system32\cmd.exe MD5: 85e861d0b88db2b54acb0839654c09f7 C:\Windows\system32\DNSAPI.dll MD5: 3be1651c63954067940e7f473498ad70 C:\Windows\System32\drivers\dgderdrv.sys MD5: 6843926aff733d46a04f9d4e1c1a6b14 C:\Windows\system32\dwrite.dll MD5: a9542ff2e9a82cf100e5729ec79068f0 C:\Windows\system32\FLTLIB.DLL MD5: dca3fa9f9dd103dc39c24c85ef073db1 C:\Windows\system32\ICMP.DLL MD5: b8fbe5f40b09f5d20e1e5ccfef893d62 C:\Windows\system32\IMM32.DLL MD5: ba7c3e9dd6b1a632124c8659e8014028 C:\Windows\system32\Perfctrs.dll MD5: ab530fdd34c67b497a20171d1234cfe9 C:\Windows\system32\RICHED32.DLL MD5: c7230fbee14437716701c15be02c27b8 C:\Windows\System32\shsvcs.dll MD5: 36a107e19010259fcac647ea2bf94b37 C:\Windows\system32\ssText3d.scr MD5: bfa034aac103d8a6f591ac9364688339 C:\Windows\system32\t2embed.dll MD5: 88b630f6aeb5a11f6ad064930b38c2c0 C:\Windows\system32\uxtheme.dll MD5: f7f4ad3d174cb5ec3c12f04c99478b84 C:\Windows\system32\WindowsCodecs.dll MD5: 2d1179cdec6b7400105e68f6ac9b4efe C:\Windows\system32\WINSPOOL.DRV MD5: 367465dd8e2bffe4c5477c86c8217e8c C:\Windows\SysWOW64\dgderapi.dll MD5: 10b8f89d146d0e20b1284d47bb4ec6c9 C:\Windows\SysWOW64\dgdersvc.exe MD5: 1bd976dd77b31fe0f25708ad5c1351ae C:\Windows\SysWOW64\DIFXAPI.dll MD5: 85e861d0b88db2b54acb0839654c09f7 C:\Windows\Syswow64\DNSAPI.dll MD5: 05c8c8767e29163fc251164ff6839ea5 C:\Windows\syswow64\GDI32.dll MD5: af3db1d3ac2ab52f910b2102447e3564 c:\windows\syswow64\ieframe.dll MD5: 6419081f0f15cb860458515d1a52d560 C:\Windows\syswow64\iertutil.dll MD5: b8fbe5f40b09f5d20e1e5ccfef893d62 C:\Windows\syswow64\IMM32.dll MD5: 7f4caeac24592fa9f574e1f8cd1d0604 C:\Windows\syswow64\kernel32.dll MD5: df37346ea13082e3e1b423b54014e641 C:\Windows\syswow64\LPK.DLL MD5: 21a67095edc11a528f5434d28bb0ef3c C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll MD5: 56007cfc52167c26e4a3f899b8d29ccd C:\Windows\SysWOW64\ntdll.dll MD5: 9586e7cb2255a8b097a7e4538202585e C:\Windows\syswow64\ole32.dll MD5: de4cd76c254e143f40e62952788d3be7 C:\Windows\syswow64\OLEAUT32.dll MD5: 0ed8727ea0172860f47258456c06caea C:\Windows\SysWow64\perfhost.exe MD5: 015e1f472a5633520903353375f7e69d C:\Windows\SysWOW64\PING.EXE MD5: 3a2bdd76e7d2a5f40a7174793d1ba794 C:\Windows\SysWOW64\PnkBstrA.exe MD5: 0abe67004eb4c162f4456e64f90a11fd C:\Windows\syswow64\RPCRT4.dll MD5: 2ab58991862153a248779174d4e4212b C:\Windows\SysWOW64\schannel.dll MD5: 33ae914c24f546aabf281ba7b138186d C:\Windows\syswow64\SHELL32.dll MD5: 9176285122b7b849fec2aa1b72a8f7a8 C:\Windows\syswow64\SHLWAPI.dll MD5: 9188e90d47ba1e68e90c450473fadf5f C:\Windows\syswow64\urlmon.dll MD5: d29fdb5dedbdc1bd882164dc6dc4dd53 C:\Windows\syswow64\USER32.dll MD5: 80fff14f1757b9af8be9d314fc1ae88b C:\Windows\syswow64\USP10.dll MD5: 17413ef7d95632d892b4c914cd7e66f9 C:\Windows\syswow64\WININET.dll MD5: a55e7d0d873b2c97585b3b5926ac6ade C:\Windows\WindowsMobile\rapimgr.dll MD5: 8bda6db43aa54e8bb5e0794541ddc209 C:\Windows\WindowsMobile\wcescomm.dll MD5: 35acd5ea63d75e97dd0e9a1629e582b2 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_88f3a38569c2c436\COMCTL32.dll MD5: be3c082837866c4c291adaf163c10ea6 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll MD5: b5b09091b0e33c396ceec8995515bd41 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll MD5: 914a7156b0c0f10be645a02e13f576b2 D:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe Keine Dateien hochgeladen Scan beendet - Kommunikation hat 1 Sek. gedauert übertragene Daten - 0.02 MB gesendet, 0.63 KB empfangen 349 Dateien und Module geprüft - 19 seconds ============================================================================== |
Schritt 1 Fixen mit OTL
Code: :OTL
|
Hier das OTL: All processes killed ========== OTL ========== No active process named setup.exe was found! Service AMService stopped successfully! Service AMService deleted successfully! File C:\Windows\TEMP\kvsqsb\setup.exe not found. ========== FILES ========== C:\Windows\temp\kvsqsb folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Max ->Temp folder emptied: 92508 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 6890003 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 7192 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 7,00 mb OTL by OldTimer - Version 3.2.26.1 log created on 08082011_091917 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
Wie läuft das System? Update Malwarebytes sund mache erneut einen Scan, poste das Log. |
Sieht gut aus, jetzt wird nur noch 1 Datei als Trojan Banker angezeigt System läuft! Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Datenbank Version: 7409 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 08.08.2011 15:55:54 mbam-log-2011-08-08 (15-55-04).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 170667 Laufzeit: 1 Minute(n), 55 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 5 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A} (PUP.Dealio.TB) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3FEE66E-E034-436A-86E4-9690573BEE8A} (PUP.Dealio.TB) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A} (PUP.Dealio.TB) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F3FEE66E-E034-436A-86E4-9690573BEE8A} (PUP.Dealio.TB) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C689C99E-3A8C-4c87-A79C-C80DC9C81632} (Trojan.Banker) -> No action taken. Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\program files (x86)\youtube downloader toolbar\IE\4.5\youtubedownloadertoolbarie.dll (PUP.Dealio.TB) -> No action taken. |
Kann ich den Trojaner jetzt einfach mit malwarebytes entfernen? |
Ja entferne alles. Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: activex
|
So, hier das OTL. Malwarebytes findet nach dem entfernen der Dateien auch nix mehr. Dürfte jetzt clean sein oder?OTL Logfile: Code: OTL logfile created on: 09.08.2011 14:38:49 - Run 4 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 09:09 Uhr. |
Copyright ©2000-2025, Trojaner-Board