![]() |
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dll (Trojan.Agent) -> Daten: C:\Users\Papa\AppData\Roaming\dll\svchost.exe -> Keine Aktio Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.01.09.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Papa :: PAPA-PC [Administrator] 09.01.2013 18:41:18 log neu.txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|I:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 414581 Laufzeit: 1 Stunde(n), 9 Minute(n), 45 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dll (Trojan.Agent) -> Daten: C:\Users\Papa\AppData\Roaming\dll\svchost.exe -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Papa\AppData\Roaming\dll\svchost.exe (Backdoor.IRCBot) -> Keine Aktion durchgeführt. (Ende) Kennt wer diese dinger und weis was die anrichten können ? Wie kann ich diese entfernen ohne mein system neu aufsetzen zu müssen? Danke euch |
:hallo: Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. ![]() Bitte Lesen: Regeln für die Bereinigung Damit die Bereinigung funktioniert bitte ich dich, die folgenden Punkte aufmerksam zu lesen:
Gelesen und verstanden? Schritt 1: Laufwerksemulationen abschalten mit Defogger Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop und starte es:Schritt 2: Scan mit GMER Bitte lade dir GMER herunter: (Dateiname zufällig) Schritt 3: Scan mit DDS+ (mit attach) Downloade dir bitte DDS (von sUBs) und speichere die Datei auf deinem Desktop. |
defogger_disable by jpshortstuff (23.02.10.1) Log created at 20:53 on 09/01/2013 (Papa) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:DAEMON Tools Pro Agent -> Removed Checking for services/drivers... SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- GMER 2.0.18444 - GMER - Rootkit Detector and Remover Rootkit scan 2013-01-09 21:03:27 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-6 WDC_WD10EURS-630AB1 rev.80.00A80 931,51GB Running: gmer-2.0.18444.exe; Driver: C:\Users\Papa\AppData\Local\Temp\kxldapow.sys ---- User code sections - GMER 2.0 ---- .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes [E0, 75] .text ... * 9 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes [E0, 75] .text ... * 9 .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes [E0, 75] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[124] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82 00000000728e17fa 2 bytes [8E, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88 00000000728e1860 2 bytes [8E, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98 00000000728e1942 2 bytes [8E, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109 00000000728e194d 2 bytes [8E, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes [E0, 75] .text ... * 9 .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes [E0, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e01401 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e01419 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e01431 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e0144a 2 bytes [E0, 75] .text ... * 9 .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e014dd 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e014f5 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e0150d 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e01525 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e0153d 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e01555 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e0156d 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e01585 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e0159d 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e015b5 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e015cd 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e016b2 2 bytes [E0, 75] .text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[4136] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e016bd 2 bytes [E0, 75] ---- Threads - GMER 2.0 ---- Thread C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe [4488:4492] 00000000004748da Thread C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [4864:4184] 000007fefb512a7c Thread C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [4864:712] 000000006c96d068 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1132] 000000006574fee5 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:912] 0000000076f93e45 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1140] 0000000065748f6c Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1204] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4092] 0000000076f92e25 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4204] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4200] 00000000721162ee Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4156] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4160] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4168] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4152] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4108] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:3236] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:3620] 00000000742727e1 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1500] 0000000076f97111 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4624] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4604] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4664] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4608] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4596] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4640] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4592] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4580] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4588] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4516] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4564] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1260] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4996] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:5000] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4652] 0000000076f93e45 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1220] 0000000076f93e45 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:1732] 00000000734b32fb Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:2484] 00000000767be44f Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:3700] 0000000076a0d864 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:4740] 000000006f6cc724 Thread C:\Program Files (x86)\Mozilla Firefox\firefox.exe [5064:920] 0000000076f93e45 ---- Processes - GMER 2.0 ---- Library ? (*** suspicious ***) @ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [3684] 000007fef17a0000 Library ? (*** suspicious ***) @ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [4864] 000007fef03c0000 ---- Registry - GMER 2.0 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xFE 0x28 0x3E 0xE6 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x91 0x6A 0x0D 0xF3 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x43 0x46 0xA6 0x33 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xFE 0x28 0x3E 0xE6 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x91 0x6A 0x0D 0xF3 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x43 0x46 0xA6 0x33 ... ---- EOF - GMER 2.0 ----DDS Logfile: Code: DDS (Ver_2012-11-20.01) - NTFS_AMD64 . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 23.09.2011 20:41:14 System Uptime: 09.01.2013 20:54:02 (1 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | GA-MA78LM-S2H Processor: AMD Phenom(tm) II X4 965 Processor | Socket M2 | 2686/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 468 GiB total, 281,53 GiB free. D: is FIXED (NTFS) - 114 GiB total, 92,753 GiB free. E: is FIXED (NTFS) - 78 GiB total, 52,076 GiB free. F: is FIXED (NTFS) - 273 GiB total, 251,326 GiB free. G: is CDROM () H: is CDROM () I: is FIXED (NTFS) - 463 GiB total, 445,188 GiB free. J: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {36fc9e60-c465-11cf-8056-444553540000} Description: Unknown Device Device ID: USB\VID_0000&PID_0000\5&2D71D9D&0&3 Manufacturer: (Standard-USB-Hostcontroller) Name: Unknown Device PNP Device ID: USB\VID_0000&PID_0000\5&2D71D9D&0&3 Service: . Class GUID: {997b5d8d-c442-4f2e-baf3-9c8e671e9e21} Description: Logitech GamePanel-Geräte (Mono) Device ID: ROOT\SIDESHOW\0001 Manufacturer: Logitech Inc Name: Logitech GamePanel-Geräte (Mono) PNP Device ID: ROOT\SIDESHOW\0001 Service: WUDFRd . ==== System Restore Points =================== . RP203: 01.01.2013 10:58:10 - Windows Update RP204: 08.01.2013 14:48:10 - Windows Update . ==== Installed Programs ====================== . 7-Zip 9.20 7-Zip 9.20 (x64 edition) AAVUpdateManager Adobe AIR Adobe Community Help Adobe Download Assistant Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop CS5.1 Adobe Reader X (10.1.1) - Deutsch AMD Accelerated Video Transcoding AMD APP SDK Runtime AMD Catalyst Install Manager AMD Drag and Drop Transcoding AMD Fuel AMD Media Foundation Decoders AMD VISION Engine Control Center Apple Application Support Avira Free Antivirus Battlefield: Bad Company™ 2 Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner Curse Client DAEMON Tools Pro DAEMON Tools Toolbar Druckerdeinstallation für EPSON BX305 Series EPSON BX305 Series Handbuch Epson Easy Photo Print 2 Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) Epson FAX Utility EPSON Scan FightMouse Elite Google Chrome Google Earth Google Update Helper High-Definition Video Playback Java 7 Update 7 Java Auto Updater Java(TM) 6 Update 27 (64-bit) LightScribe System Software Logitech GamePanel Software 3.06.109 Malwarebytes Anti-Malware Version 1.70.0.1100 MediaMonkey 3.2 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft_VC80_ATL_x86 Microsoft_VC80_ATL_x86_x64 Microsoft_VC80_CRT_x86 Microsoft_VC80_CRT_x86_x64 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFC_x86_x64 Microsoft_VC80_MFCLOC_x86 Microsoft_VC80_MFCLOC_x86_x64 Microsoft_VC90_ATL_x86 Microsoft_VC90_ATL_x86_x64 Microsoft_VC90_CRT_x86 Microsoft_VC90_CRT_x86_x64 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFC_x86_x64 Microsoft_VC90_MFCLOC_x86 Microsoft_VC90_MFCLOC_x86_x64 Mozilla Firefox 17.0.1 (x86 de) Mozilla Maintenance Service MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 11 Cliparts Nero 11 Disc Menus 1 Nero 11 Disc Menus 2 Nero 11 Disc Menus 3 Nero 11 Disc Menus Basic Nero 11 Effects Basic Nero 11 Image Samples Nero 11 Kwik Themes 1 Nero 11 Kwik Themes 2 Nero 11 Kwik Themes 3 Nero 11 Kwik Themes 4 Nero 11 Kwik Themes Basic Nero 11 PiP Effects 1 Nero 11 PiP Effects Basic Nero 11 Platinum Nero 11 Video Samples Nero 11 Video Transitions 1 Nero Audio Pack 1 Nero BackItUp 11 Nero BackItUp 11 Help (CHM) Nero Backup Drivers Nero Burning ROM 11 Nero Burning ROM 11 Help (CHM) Nero ControlCenter 11 Nero ControlCenter 11 Help (CHM) Nero Core Components 11 Nero CoverDesigner 11 Nero CoverDesigner 11 Help (CHM) Nero Express 11 Nero Express 11 Help (CHM) Nero Kwik Media Nero Kwik Media Help (CHM) Nero Recode 11 Nero Recode 11 Help (CHM) Nero RescueAgent 11 Nero RescueAgent 11 Help (CHM) Nero SharedVideoCodecs Nero SoundTrax 11 Nero SoundTrax 11 Help (CHM) Nero Update Nero Video 11 Nero Video 11 Help (CHM) Nero WaveEditor 11 Nero WaveEditor 11 Help (CHM) nero.prerequisites.msi NVIDIA PhysX OpenOffice.org 3.3 Origin PDF Settings CS5 QuickStores-Toolbar 1.1.0 QuickTime Realtek Ethernet Controller Driver Realtek HDMI Audio Driver for ATI Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) SmartFTP Client German (Germany) MUI Steuer-Sparer 2011 Steuersparer 2012 TeamSpeak 3 Client TortoiseSVN 1.7.6.22632 (64 bit) Unity Web Player Unlocker 1.9.1-x64 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) UseNeXT Version 1.0.0.5 VLC media player 1.1.11 Welcome App (Start-up experience) Windows Media Center Add-in for Silverlight Windows Media Player Firefox Plugin WinRAR 4.01 (32-Bit) WinZip 16.5 World of Warcraft XMedia Recode Version 3.1.3.6 Yahoo! Detect Yontoo 1.10.02 . ==== End Of File =========================== |
Also dann weiter: Schritt 1: Deinstallation von Programmen Schritt 2: Windows-Defender abschalten Da du einen anderen Virenscanner benutzt solltest du dringend den windowseigenen Scanner abschalten:
Schritt 3: Temporäre Dateien löschen mit TFC Schritt 4: Scan mit Combofix
|
Combofix Logfile: Code: ComboFix 13-01-08.01 - Papa 09.01.2013 21:40:59.1.4 - x64 |
Du solltest mir zu jedem Schritt schreiben ob das geklappt hat. Du hast Schritt 2 durchgeführt? |
Ausserdem bitte Dateien zur Analyse einsenden. Upload zur Analyse bei Trojaner-Board
|
ups sorry nee habe die win firewall abgeschaltet Malwarebytes Anti-Malware 1.70.0.1100 Malwarebytes : Free anti-malware download Datenbank Version: v2013.01.09.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Papa :: PAPA-PC [Administrator] 09.01.2013 21:55:54 mbam-log-2013-01-09 (21-55-54).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 232512 Laufzeit: 2 Minute(n), 53 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) 7-Zip 9.20 Adobe AIR Adobe Community Help Adobe Download Assistant Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop CS5.1 Adobe Reader X (10.1.1) - Deutsch AMD VISION Engine Control Center Apple Application Support Avira Free Antivirus Battlefield: Bad Company™ 2 Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish DAEMON Tools Pro DAEMON Tools Toolbar EPSON BX305 Series Handbuch Epson Easy Photo Print 2 Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) Epson FAX Utility EPSON Scan FightMouse Elite Google Earth Google Update Helper High-Definition Video Playback Java 7 Update 7 Java Auto Updater LightScribe System Software Malwarebytes Anti-Malware Version 1.70.0.1100 MediaMonkey 3.2 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFCLOC_x86 Mozilla Firefox 17.0.1 (x86 de) Mozilla Maintenance Service MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 11 Cliparts Nero 11 Disc Menus 1 Nero 11 Disc Menus 2 Nero 11 Disc Menus 3 Nero 11 Disc Menus Basic Nero 11 Effects Basic Nero 11 Image Samples Nero 11 Kwik Themes 1 Nero 11 Kwik Themes 2 Nero 11 Kwik Themes 3 Nero 11 Kwik Themes 4 Nero 11 Kwik Themes Basic Nero 11 PiP Effects 1 Nero 11 PiP Effects Basic Nero 11 Platinum Nero 11 Video Samples Nero 11 Video Transitions 1 Nero Audio Pack 1 Nero BackItUp 11 Nero BackItUp 11 Help (CHM) Nero Burning ROM 11 Nero Burning ROM 11 Help (CHM) Nero ControlCenter 11 Nero ControlCenter 11 Help (CHM) Nero Core Components 11 Nero CoverDesigner 11 Nero CoverDesigner 11 Help (CHM) Nero Express 11 Nero Express 11 Help (CHM) Nero Kwik Media Nero Kwik Media Help (CHM) Nero Recode 11 Nero Recode 11 Help (CHM) Nero RescueAgent 11 Nero RescueAgent 11 Help (CHM) Nero SharedVideoCodecs Nero SoundTrax 11 Nero SoundTrax 11 Help (CHM) Nero Update Nero Video 11 Nero Video 11 Help (CHM) Nero WaveEditor 11 Nero WaveEditor 11 Help (CHM) nero.prerequisites.msi NVIDIA PhysX OpenOffice.org 3.3 Origin PDF Settings CS5 QuickTime Realtek Ethernet Controller Driver Realtek HDMI Audio Driver for ATI Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Steuer-Sparer 2011 Steuersparer 2012 Unity Web Player Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) UseNeXT Version 1.0.0.5 VLC media player 1.1.11 Welcome App (Start-up experience) Windows Media Center Add-in for Silverlight Windows Media Player Firefox Plugin WinRAR 4.01 (32-Bit) World of Warcraft Yahoo! Detect 2013-01-09 20:47:50 . 2013-01-09 20:47:50 1,404 ----a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-UnityWebPlayer.reg.dat 2013-01-09 20:47:42 . 2013-01-09 20:47:42 131 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-10.reg.dat 2013-01-09 20:47:28 . 2013-01-09 20:47:28 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-Football News.reg.dat 2013-01-09 20:47:27 . 2013-01-09 20:47:27 231 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-Win Final.reg.dat 2013-01-09 20:47:26 . 2013-01-09 20:47:26 207 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-10.reg.dat 2013-01-09 20:47:26 . 2013-01-09 20:47:26 132 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0}.reg.dat 2013-01-09 20:44:56 . 2013-01-09 20:44:56 5,673 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2013-01-09 20:39:02 . 2013-01-09 20:39:02 51 ----a-w- C:\Qoobox\Quarantine\catchme.log 2013-01-09 18:34:54 . 2013-01-09 18:34:54 75,264 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\543419912013a.exe.vir 2013-01-09 17:16:26 . 2013-01-09 17:16:26 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\261618912013Build.exe.vir 2013-01-07 19:01:48 . 2013-01-07 19:01:48 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\48120712013Build.exe.vir 2013-01-05 14:18:18 . 2013-01-05 14:18:18 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\171815512013Build.exe.vir 2013-01-01 19:55:12 . 2013-01-01 19:55:12 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\125520112013Build.exe.vir 2013-01-01 18:02:53 . 2013-01-01 18:02:53 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\53219112013Build.exe.vir 2012-12-31 17:48:29 . 2012-12-31 17:48:29 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\29481831122012Build.exe.vir 2012-12-30 20:15:58 . 2012-12-30 20:15:58 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\58152130122012Build.exe.vir 2012-12-29 18:41:26 . 2012-12-29 18:41:26 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\26411929122012Build.exe.vir 2012-12-29 11:10:27 . 2012-12-29 11:10:27 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\26101229122012Build.exe.vir 2012-12-28 20:42:33 . 2012-12-28 20:42:33 256,512 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\33422128122012cryptedrev.exe.vir 2012-12-28 20:22:22 . 2012-12-28 20:22:22 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\22222128122012Build.exe.vir 2012-12-23 20:31:18 . 2012-12-23 20:31:18 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\18312123122012Build.exe.vir 2012-12-23 19:21:57 . 2012-12-23 19:21:57 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\57212023122012Build.exe.vir 2012-12-22 19:21:25 . 2012-12-22 19:21:25 179,712 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Local\25212022122012Build.exe.vir 2012-12-16 12:32:25 . 2012-11-18 10:22:10 99,614,720 ----a-w- C:\Qoobox\Quarantine\C\Users\Papa\AppData\Roaming\Win Final.exe.vir 2012-03-11 07:29:15 . 2012-03-11 07:29:15 262,144 ----a-w- C:\Qoobox\Quarantine\C\ProgramData\ntuser.dat.vir |
Sag mal, was postest du mir da eigentlich? Ich wollte wissen ob du den Defender abgeschalten hast oder nicht und du sollst mir bitte die genannten Dateien zur Analyse einschicken. |
Hallo, benötigst Du noch weiterhin Hilfe ? Sollte ich innerhalb der nächsten 24 Stunden keine Antwort von dir erhalten, werde ich dein Thema aus meinen Abos nehmen und bekomme dadurch keine Nachricht über neue Antworten. Das Verschwinden der Symptome bedeutet nicht, dass dein System schon sauber ist |
Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomm ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Keine Logfiles einsenden, nur kurzer Hinweis. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen |
Alle Zeitangaben in WEZ +1. Es ist jetzt 09:13 Uhr. |
Copyright ©2000-2025, Trojaner-Board