![]() |
"Mediashifting.com" Virus Hallo! :) Ich habe ein Problem mit meinem Laptop. Immer wenn ich in Google etwas suche und dann auf den Link drücke, werde ich durch "www.mediashifting.com" auf verschiedene Seiten weitergeleitet. Seit neustem kommt jetzt auch der Link "www.95p.com" Wie kann ich den Virus beheben? Da ich eine große Laie bin bitte ich euch mir alles Schritt für Schritt zu schildern was ich machen soll. Danke im Vorraus :D |
Hi, OTL OTL Lade Dir OTL von Oldtimer herunter (http://filepony.de/download-otl/) und speichere es auf Deinem Desktop
Malwarebytes Antimalware (MAM) Anleitung&Download hier: http://www.trojaner-board.de/51187-m...i-malware.html Falls der Download nicht klappt, bitte hierüber eine generische Version runterladen: http://filepony.de/download-chameleon/ Danach bitte update der Signaturdateien (Reiter "Update" -> Suche nach Aktualisierungen") Fullscan und alles bereinigen lassen! Log posten. MBR-Check Lade Dir http://ad13.geekstogo.com/MBRCheck.exe und speichere die Datei auf dem Desktop.
chris |
OTL Logfile: Code: OTL logfile created on: 28.12.2011 20:03:19 - Run 1 Hier der OTL.txt |
OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 28.12.2011 20:03:19 - Run 1 Hier der Extras.txt |
Hi, Bitte folgende Files prüfen: Dateien Online überprüfen lassen:
Code: C:\Windows\System32\drivers\tdx.sys
Code:
MBCHeck und MAM-Log noch... chris |
Zitat:
|
[SPOILER]Antivirus Version Last Update Result AhnLab-V3 2011.12.28.03 2011.12.28 - AntiVir 7.11.20.59 2011.12.28 - Antiy-AVL 2.0.3.7 2011.12.28 - Avast 6.0.1289.0 2011.12.28 - AVG 10.0.0.1190 2011.12.28 - BitDefender 7.2 2011.12.28 - ByteHero 1.0.0.1 2011.12.07 - CAT-QuickHeal 12.00 2011.12.28 - ClamAV 0.97.3.0 2011.12.28 - Commtouch 5.3.2.6 2011.12.28 - Comodo 11122 2011.12.28 - DrWeb 5.0.2.03300 2011.12.28 - Emsisoft 5.1.0.11 2011.12.28 - eSafe 7.0.17.0 2011.12.25 - eTrust-Vet 37.0.9650 2011.12.28 - F-Prot 4.6.5.141 2011.12.28 - F-Secure 9.0.16440.0 2011.12.28 - Fortinet 4.3.388.0 2011.12.28 - GData 22.323/22.610 2011.12.28 - Ikarus T3.1.1.109.0 2011.12.28 - Jiangmin 13.0.900 2011.12.28 - K7AntiVirus 9.120.5796 2011.12.28 - Kaspersky 9.0.0.837 2011.12.28 - McAfee 5.400.0.1158 2011.12.28 - McAfee-GW-Edition 2010.1E 2011.12.28 - Microsoft 1.7903 2011.12.28 - NOD32 6750 2011.12.28 - Norman 6.07.13 2011.12.28 - nProtect 2011-12-28.01 2011.12.28 - Panda 10.0.3.5 2011.12.28 - PCTools 8.0.0.5 2011.12.28 - Prevx 3.0 2011.12.28 - Rising 23.90.02.02 2011.12.28 - Sophos 4.72.0 2011.12.28 - SUPERAntiSpyware 4.40.0.1006 2011.12.27 - Symantec 20111.2.0.82 2011.12.28 - TheHacker 6.7.0.1.366 2011.12.27 - TrendMicro 9.500.0.1008 2011.12.28 - TrendMicro-HouseCall 9.500.0.1008 2011.12.28 - VBA32 3.12.16.4 2011.12.28 - VIPRE 11317 2011.12.28 - ViRobot 2011.12.28.4851 2011.12.28 - VirusBuster 14.1.138.0 2011.12.28 - Additional informationShow all MD5 : cb39e896a2a83702d1737bfd402b3542 SHA1 : 8b529b5c51c7bd0e7c5a4ff6b0e7a64abde649ce SHA256: fa77d98ea3606ca2fcef0e0949fde2c32a080b47cafde46ce903ca3cbfc5df35 ssdeep: 1536:9klJmrevoqvFyQ9/ffrQWxo953f4kTPeV1i5/sqOJFdl5w8xJXO3O:OlN3sc5AQkie5/sp JFdlq8x0e File size : 74240 bytes First seen: 2009-07-19 02:12:11 Last seen : 2011-12-28 19:51:34 TrID: Win32 Executable Generic (68.0%) Generic Win/DOS Executable (15.9%) DOS Executable Generic (15.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher....: Microsoft Corporation copyright....: (c) Microsoft Corporation. All rights reserved. product......: Microsoft_ Windows_ Operating System description..: TDI Translation Driver original name: tdx.sys internal name: tdx.sys file version.: 6.1.7600.16385 (win7_rtm.090713-1255) comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x1303E timedatestamp....: 0x4A5BBF4A (Mon Jul 13 23:12:10 2009) machinetype......: 0x14c (I386) [[ 7 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0xE8B3, 0xEA00, 6.41, 12b2ae36fea8454f6e82aff577dd708c .rdata, 0x10000, 0x6EC, 0x800, 4.21, b80f2bcd1969979c6f9b482d727a021f .data, 0x11000, 0x3A0, 0x200, 2.77, bc7cad3945605ccc34a21697e84021b3 PAGE, 0x12000, 0x4DC, 0x600, 5.27, ec945ab7bb158456785f47acb1c85d34 INIT, 0x13000, 0xCBC, 0xE00, 5.29, 9e8be2845d580dde6a1e865be349fcab .rsrc, 0x14000, 0x3E8, 0x400, 3.36, f779ea3904cd7bbd404544e89e7218a8 .reloc, 0x15000, 0x100C, 0x1200, 6.18, d8ef5378864e86186167874ce25a9c07 [[ 5 import(s) ]] ntoskrnl.exe: KeSetTimer, IoFreeWorkItem, IoQueueWorkItem, ZwQueryValueKey, ZwOpenKey, _vsnwprintf, KeFlushQueuedDpcs, KeCancelTimer, KeDelayExecutionThread, KeInitializeDpc, KeInitializeTimer, IoAllocateWorkItem, KeInitializeMutex, KeSetEvent, IoGetIrpExtraCreateParameter, MmUnlockPages, IoFreeMdl, KeReleaseSemaphore, KeReleaseMutex, IoAllocateMdl, ExAllocatePoolWithTagPriority, IoWMIWriteEvent, MmGetSystemRoutineAddress, IoWMIRegistrationControl, IoGetCurrentProcess, KeQueryMaximumProcessorCountEx, KeQuerySystemTime, RtlCopyUnicodeString, KeTickCount, KeBugCheckEx, RtlUnwind, KefAcquireSpinLockAtDpcLevel, KefReleaseSpinLockFromDpcLevel, ObfDereferenceObject, RtlInitUnicodeString, ExCreateCallback, RtlCompareMemory, IoCreateDevice, IoCreateSymbolicLink, IoDeleteSymbolicLink, IoDeleteDevice, KeInitializeSemaphore, IoFileObjectType, ObReferenceObjectByHandle, MmMapLockedPagesSpecifyCache, KeGetCurrentProcessorNumberEx, IoAcquireCancelSpinLock, IoReleaseCancelSpinLock, memcpy, ExAllocatePoolWithTag, ObDereferenceSecurityDescriptor, SeLockSubjectContext, IoGetFileObjectGenericMapping, SeAssignSecurity, SeUnlockSubjectContext, ObLogSecurityDescriptor, ExFreePoolWithTag, IoGetTopLevelIrp, memset, KeInitializeEvent, ExNotifyCallback, PsGetCurrentProcess, KeWaitForSingleObject, IofCompleteRequest, RtlUnicodeStringToInteger, RtlGetCallersAddress, KeReleaseInStackQueuedSpinLockFromDpcLevel, KeAcquireInStackQueuedSpinLockAtDpcLevel, IoInitializeWorkItem, IoSizeofWorkItem, IoUninitializeWorkItem, IoQueueWorkItemEx, MmProbeAndLockPages, KeGetCurrentThread HAL.dll: KeAcquireInStackQueuedSpinLock, KeGetCurrentIrql, KfLowerIrql, KfAcquireSpinLock, KfReleaseSpinLock, KeReleaseInStackQueuedSpinLock NETIO.SYS: NmrRegisterProvider, RtlCopyMdlToMdl, RtlCopyBufferToMdl, NsiGetParameter, NsiFreeTable, NsiAllocateAndGetTable, NmrClientDetachProviderComplete, NmrClientAttachProvider, NsiDeregisterChangeNotification, NsiSetAllParameters, NmrProviderDetachClientComplete, NmrDeregisterProvider, NmrWaitForProviderDeregisterComplete, RtlCopyMdlToBuffer, NmrRegisterClient, NsiRegisterChangeNotification, NsiGetAllParameters, NmrDeregisterClient, NmrWaitForClientDeregisterComplete TDI.SYS: TdiDeregisterProvider, TdiProviderReady, TdiRegisterProvider, TdiDeregisterDeviceObject, TdiDeregisterNetAddress, TdiRegisterDeviceObject, TdiRegisterNetAddress, TdiPnPPowerRequest, TdiMapUserRequest NDIS.SYS: NdisIfGetInterfaceIndexFromNetLuid ExifTool: file metadata CharacterSet: Unicode CodeSize: 65024 CompanyName: Microsoft Corporation EntryPoint: 0x1303e FileDescription: TDI Translation Driver FileFlagsMask: 0x003f FileOS: Windows NT 32-bit FileSize: 72 kB FileSubtype: 6 FileType: Win32 EXE FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255) FileVersionNumber: 6.1.7600.16385 ImageVersion: 6.1 InitializedDataSize: 8704 InternalName: tdx.sys LanguageCode: English (U.S.) LegalCopyright: Microsoft Corporation. All rights reserved. LinkerVersion: 9.0 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OSVersion: 6.1 ObjectFileType: Driver OriginalFilename: tdx.sys PEType: PE32 ProductName: Microsoft Windows Operating System ProductVersion: 6.1.7600.16385 ProductVersionNumber: 6.1.7600.16385 Subsystem: Native SubsystemVersion: 6.1 TimeStamp: 2009:07:14 01:12:10+02:00 UninitializedDataSize: 0 [/SPOILER] Das ist hier ist von VirusTotal das erste |
Hi, ja, auf jeden Fall... Poste noch das Log der zweiten Datei... chris |
[SPOILER] Antivirus Version Last Update Result AhnLab-V3 2011.12.28.03 2011.12.28 - AntiVir 7.11.20.59 2011.12.28 - Antiy-AVL 2.0.3.7 2011.12.28 - Avast 6.0.1289.0 2011.12.28 - AVG 10.0.0.1190 2011.12.28 - BitDefender 7.2 2011.12.28 - ByteHero 1.0.0.1 2011.12.07 - CAT-QuickHeal 12.00 2011.12.28 - ClamAV 0.97.3.0 2011.12.28 - Commtouch 5.3.2.6 2011.12.28 - Comodo 11122 2011.12.28 - DrWeb 5.0.2.03300 2011.12.28 - Emsisoft 5.1.0.11 2011.12.28 - eSafe 7.0.17.0 2011.12.25 - eTrust-Vet 37.0.9650 2011.12.28 - F-Prot 4.6.5.141 2011.12.28 - F-Secure 9.0.16440.0 2011.12.28 - Fortinet 4.3.388.0 2011.12.28 - GData 22 2011.12.28 - Ikarus T3.1.1.109.0 2011.12.28 - Jiangmin 13.0.900 2011.12.28 - K7AntiVirus 9.120.5796 2011.12.28 - Kaspersky 9.0.0.837 2011.12.28 - McAfee 5.400.0.1158 2011.12.28 - McAfee-GW-Edition 2010.1E 2011.12.28 - Microsoft 1.7903 2011.12.28 - NOD32 6750 2011.12.28 - Norman 6.07.13 2011.12.28 - nProtect 2011-12-28.01 2011.12.28 - Panda 10.0.3.5 2011.12.28 - PCTools 8.0.0.5 2011.12.28 - Prevx 3.0 2011.12.28 - Rising 23.90.02.02 2011.12.28 - Sophos 4.72.0 2011.12.28 - SUPERAntiSpyware 4.40.0.1006 2011.12.27 - Symantec 20111.2.0.82 2011.12.28 - TheHacker 6.7.0.1.366 2011.12.27 - TrendMicro 9.500.0.1008 2011.12.28 - TrendMicro-HouseCall 9.500.0.1008 2011.12.28 - VBA32 3.12.16.4 2011.12.28 - VIPRE 11317 2011.12.28 - ViRobot 2011.12.28.4851 2011.12.28 - VirusBuster 14.1.138.0 2011.12.28 - Additional informationShow all MD5 : 42669885e097c23ab7e7ac6fb00abc42 SHA1 : e70089fbbc32bf0a6b8ad7d70e84ade0427e245d SHA256: fabe121dd06046f9329b37e9fbe1324dfc6de48f8c24a00591d4f4e97851ed89 ssdeep: 12288:i0QfKb7nH5lrPo37AzHTA63I0ihE4qE7prN9cgKARpkZXYnXExy8gs9g:SfKbT5lrPo37 AzHTA63/cfqAcgKckZIh File size : 709724 bytes First seen: 2010-02-13 08:55:13 Last seen : 2011-12-28 19:56:03 TrID: Windows OCX File (86.8%) Win32 Executable Delphi generic (10.3%) Generic Win/DOS Executable (1.4%) DOS Executable Generic (1.4%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: Setup/Uninstall original name: n/a internal name: n/a file version.: 51.50.0.0 comments.....: n/a signers......: - signing date.: - verified.....: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x933C0 timedatestamp....: 0x2A425E19 (Fri Jun 19 22:22:17 1992) machinetype......: 0x14c (I386) [[ 8 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 CODE, 0x1000, 0x925F8, 0x92600, 6.58, 950e9bffdff8b1afc7f81fed8584f3b1 DATA, 0x94000, 0x103C, 0x1200, 4.11, cddbf029146d500daccb5db3f93f79b3 BSS, 0x96000, 0x1488, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e .idata, 0x98000, 0x25A4, 0x2600, 5.03, 466bb5755f9b35bcf5c5ea65669d018f .tls, 0x9B000, 0x8, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e .rdata, 0x9C000, 0x18, 0x200, 0.20, c69afab126bf434e49f23fb46e4baac7 .reloc, 0x9D000, 0x8730, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e .rsrc, 0xA6000, 0x13E00, 0x13E00, 4.93, c5b5704710f4d4cb1f72326efbb96735 [[ 17 import(s) ]] kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetSystemTime, GetFileType, ExitProcess, CreateFileA, CloseHandle user32.dll: MessageBoxA oleaut32.dll: SafeArrayPutElement, SafeArrayCreate, VariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen advapi32.dll: RegSetValueExA, RegQueryValueExA, RegQueryInfoKeyA, RegOpenKeyExA, RegEnumValueA, RegEnumKeyExA, RegDeleteValueA, RegDeleteKeyA, RegCreateKeyExA, RegCloseKey, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueA, GetUserNameA, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid kernel32.dll: lstrcmpA, WriteProfileStringA, WritePrivateProfileStringA, WriteFile, WaitForSingleObject, VirtualFree, VirtualAlloc, UnmapViewOfFile, TransactNamedPipe, TerminateThread, TerminateProcess, Sleep, SizeofResource, SetNamedPipeHandleState, SetLastError, SetFileTime, SetFilePointer, SetFileAttributesA, SetErrorMode, SetEndOfFile, SetCurrentDirectoryA, RemoveDirectoryA, ReleaseMutex, ReadFile, QueryPerformanceCounter, OpenProcess, OpenMutexA, MultiByteToWideChar, MulDiv, MoveFileExA, MoveFileA, MapViewOfFile, LockResource, LocalFree, LocalFileTimeToFileTime, LoadResource, LoadLibraryExA, LoadLibraryA, IsDBCSLeadByte, IsBadWritePtr, GlobalUnlock, GlobalReAlloc, GlobalHandle, GlobalLock, GlobalFree, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetWindowsDirectoryA, GetVersionExA, GetVersion, GetUserDefaultLangID, GetTickCount, GetSystemTimeAsFileTime, GetSystemInfo, GetSystemDirectoryA, GetSystemDefaultLCID, GetShortPathNameA, GetProfileStringA, GetProcAddress, GetPrivateProfileStringA, GetOverlappedResult, GetModuleHandleA, GetModuleFileNameA, GetLogicalDrives, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetDriveTypeA, GetDiskFreeSpaceA, GetCurrentThreadId, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetCurrentDirectoryA, GetComputerNameA, GetCommandLineA, GetACP, FreeResource, InterlockedExchange, FreeLibrary, FormatMessageA, FlushFileBuffers, FindResourceA, FindNextFileA, FindFirstFileA, FindClose, FileTimeToSystemTime, FileTimeToLocalFileTime, DeviceIoControl, DeleteFileA, CreateThread, CreateProcessA, CreateNamedPipeA, CreateMutexA, CreateFileMappingA, CreateFileA, CreateEventA, CreateDirectoryA, CopyFileA, CompareStringA, CompareFileTime, CloseHandle mpr.dll: WNetOpenEnumA, WNetGetUniversalNameA, WNetGetConnectionA, WNetEnumResourceA, WNetCloseEnum version.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA gdi32.dll: UnrealizeObject, TextOutA, StretchDIBits, StretchBlt, SetWindowOrgEx, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RoundRect, RestoreDC, RemoveFontResourceA, Rectangle, RectVisible, RealizePalette, Polyline, Pie, PatBlt, MoveToEx, LineTo, LineDDA, IntersectClipRect, GetWindowOrgEx, GetTextMetricsA, GetTextExtentPointA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetPixel, GetPaletteEntries, GetObjectA, GetDeviceCaps, GetDIBits, GetCurrentPositionEx, GetClipBox, GetBitmapBits, ExtFloodFill, ExcludeClipRect, EnumFontsA, Ellipse, DeleteObject, DeleteDC, CreateSolidBrush, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateFontIndirectA, CreateDIBitmap, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, Chord, BitBlt, Arc, AddFontResourceA user32.dll: WindowFromPoint, WinHelpA, WaitMessage, WaitForInputIdle, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowOwnedPopups, ShowCursor, SetWindowRgn, SetWindowsHookExA, SetWindowTextA, SetWindowPos, SetWindowPlacement, SetWindowLongW, SetWindowLongA, SetTimer, SetScrollPos, SetScrollInfo, SetRectEmpty, SetRect, SetPropA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetCapture, SetActiveWindow, SendNotifyMessageA, SendMessageTimeoutA, SendMessageW, SendMessageA, ScrollWindowEx, ScrollWindow, ScreenToClient, ReplyMessage, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClassA, PtInRect, PostQuitMessage, PostMessageA, PeekMessageA, OffsetRect, OemToCharBuffA, OemToCharA, MsgWaitForMultipleObjects, MessageBoxA, MessageBeep, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRgn, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetSystemMetrics, GetSystemMenu, GetSysColor, GetSubMenu, GetScrollPos, GetPropA, GetParent, GetWindow, GetMessagePos, GetMessageA, GetMenuStringA, GetMenuState, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClientRect, GetClassInfoW, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, ExitWindowsEx, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableMenuItem, DrawTextW, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawFocusRect, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreateWindowExA, CreatePopupMenu, CreateMenu, CreateIcon, ClientToScreen, CheckMenuItem, CallWindowProcW, CallWindowProcA, CallNextHookEx, BringWindowToTop, BeginPaint, AppendMenuA, CharPrevA, CharNextA, CharLowerBuffA, CharLowerA, CharUpperBuffA, CharToOemBuffA, AdjustWindowRectEx comctl32.dll: ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Destroy, ImageList_Create, InitCommonControls ole32.dll: CoTaskMemFree, CLSIDFromProgID, CoCreateInstance, CoFreeUnusedLibraries, CoUninitialize, CoInitialize, IsEqualGUID oleaut32.dll: GetActiveObject, RegisterTypeLib, LoadTypeLib, SysFreeString shell32.dll: ShellExecuteExA, ShellExecuteA, SHGetFileInfoA, ExtractIconA shell32.dll: SHChangeNotify, SHBrowseForFolder, SHGetPathFromIDList, SHGetMalloc comdlg32.dll: GetSaveFileNameA, GetOpenFileNameA ole32.dll: CoDisconnectObject advapi32.dll: AdjustTokenPrivileges ExifTool: file metadata CharacterSet: Unicode CodeSize: 599552 EntryPoint: 0x933c0 FileDescription: Setup/Uninstall FileFlagsMask: 0x003f FileOS: Win32 FileSize: 693 kB FileSubtype: 0 FileType: Win32 EXE FileVersion: 51.50.0.0 FileVersionNumber: 51.50.0.0 ImageVersion: 6.0 InitializedDataSize: 131072 LanguageCode: Neutral LinkerVersion: 2.25 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OSVersion: 1.0 ObjectFileType: Executable application PEType: PE32 ProductVersionNumber: 0.0.0.0 Subsystem: Windows GUI SubsystemVersion: 4.0 TimeStamp: 1992:06:20 00:22:17+02:00 UninitializedDataSize: 0 [/SPOILER] Das hier ist die zweite von VirusTotal. |
Hi, Okay sieht sauber aus.... Kannst auch den MBRCheck vorziehen vor MAM, geht nicht so lange.. chris |
Nachdem ich die Textdatei in OTL reinkopiert habe musste ich nach dem 'Fix' mein Laptop neu starten. Dann kam diese Textdatei [SPOILER]All processes killed ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"UacDisableNotify" | dword:0x00 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"InternetSettingsDisableNotify" | dword:0x00 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AutoUpdateDisableNotify" |dword:0x00 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\\"DisableMonitoring" |dword:0x00 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\"DisableMonitoring" |dword:0x00 /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\\"DisableMonitoring" | dword:0x00 /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 2270642 bytes ->Temporary Internet Files folder emptied: 16993018 bytes ->Java cache emptied: 11327 bytes ->Google Chrome cache emptied: 340469915 bytes ->Flash cache emptied: 91886 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3596 bytes RecycleBin emptied: 534599727 bytes Total Files Cleaned = 853,00 mb OTL by OldTimer - Version 3.2.31.0 log created on 12282011_212953 Files\Folders moved on Reboot... File move failed. C:\Windows\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb scheduled to be moved on reboot. Registry entries deleted on Reboot... [/SPOILER] |
[SPOILER] MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows 7 Ultimate Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: Acer BIOS Manufacturer: Phoenix Technologies LTD System Manufacturer: Acer System Product Name: Extensa 5230 Logical Drives Mask: 0x0000003c Kernel Drivers (total 156): 0x82C54000 \SystemRoot\system32\ntkrnlpa.exe 0x82C1D000 \SystemRoot\system32\halmacpi.dll 0x80BA3000 \SystemRoot\system32\kdcom.dll 0x83213000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x8328B000 \SystemRoot\system32\PSHED.dll 0x8329C000 \SystemRoot\system32\BOOTVID.dll 0x832A4000 \SystemRoot\system32\CLFS.SYS 0x832E6000 \SystemRoot\system32\CI.dll 0x8702C000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8709D000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x870AB000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x870F3000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x870FC000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x87104000 \SystemRoot\system32\DRIVERS\pci.sys 0x8712E000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x87139000 \SystemRoot\System32\drivers\partmgr.sys 0x8714A000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x87152000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x8715D000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x8716D000 \SystemRoot\System32\drivers\volmgrx.sys 0x871B8000 \SystemRoot\system32\DRIVERS\pciide.sys 0x871BF000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x871CD000 \SystemRoot\system32\DRIVERS\pcmcia.sys 0x87000000 \SystemRoot\System32\drivers\mountmgr.sys 0x87016000 \SystemRoot\system32\DRIVERS\atapi.sys 0x83391000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x8701F000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x833B4000 \SystemRoot\system32\drivers\fltmgr.sys 0x87207000 \SystemRoot\system32\drivers\N360\0500000.07D\SYMDS.SYS 0x8725E000 \SystemRoot\system32\drivers\fileinfo.sys 0x8726F000 \SystemRoot\system32\drivers\N360\0500000.07D\SYMEFA.SYS 0x87411000 \SystemRoot\System32\Drivers\Ntfs.sys 0x87540000 \SystemRoot\System32\Drivers\msrpc.sys 0x8756B000 \SystemRoot\System32\Drivers\ksecdd.sys 0x8757E000 \SystemRoot\System32\Drivers\cng.sys 0x875DB000 \SystemRoot\System32\drivers\pcw.sys 0x875E9000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x87313000 \SystemRoot\system32\drivers\ndis.sys 0x8762C000 \SystemRoot\system32\drivers\NETIO.SYS 0x8766A000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8768F000 \SystemRoot\System32\drivers\tcpip.sys 0x873CA000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x877D8000 \SystemRoot\system32\DRIVERS\vmstorfl.sys 0x8780E000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x8784D000 \SystemRoot\System32\Drivers\spldr.sys 0x87855000 \SystemRoot\System32\drivers\rdyboost.sys 0x87882000 \SystemRoot\System32\Drivers\mup.sys 0x87892000 \SystemRoot\System32\drivers\hwpolicy.sys 0x8789A000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x878CC000 \SystemRoot\system32\DRIVERS\disk.sys 0x878DD000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x87934000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x87953000 \SystemRoot\System32\Drivers\Null.SYS 0x8795A000 \SystemRoot\System32\drivers\vga.sys 0x87966000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x87987000 \SystemRoot\System32\drivers\watchdog.sys 0x87994000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8799C000 \SystemRoot\system32\drivers\rdpencdd.sys 0x879A4000 \SystemRoot\system32\drivers\rdprefmp.sys 0x879AC000 \SystemRoot\System32\Drivers\Msfs.SYS 0x879B7000 \SystemRoot\System32\Drivers\Npfs.SYS 0x879D3000 \SystemRoot\system32\DRIVERS\tdx.sys 0x879EA000 \systemroot\system32\drivers\TDI.SYS 0x8CA2A000 \SystemRoot\system32\drivers\afd.sys 0x8CA84000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8CAB6000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x8CABD000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8CADC000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x8CAED000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8CAFB000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8CB0E000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8CB1E000 \SystemRoot\system32\drivers\N360\0500000.07D\SYMNETS.SYS 0x8CB6D000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS 0x8CB93000 \SystemRoot\system32\drivers\N360\0500000.07D\Ironx86.SYS 0x8CBB7000 \SystemRoot\system32\drivers\N360\0500000.07D\SRTSPX.SYS 0x8D015000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8D056000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8D060000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8D06A000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20101201.001\IDSVix86.sys 0x8D0C5000 \SystemRoot\System32\drivers\discache.sys 0x8D0D1000 \SystemRoot\system32\drivers\csc.sys 0x8D135000 \SystemRoot\System32\Drivers\dfsc.sys 0x8D14D000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x8C037000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20101123.003\BHDrvx86.sys 0x8E617000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x8EB14000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8C0E3000 \SystemRoot\System32\drivers\dxgmms1.sys 0x8EBCB000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8C11C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8EBD6000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8C167000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8C186000 \SystemRoot\system32\DRIVERS\b57nd60x.sys 0x8DA1C000 \SystemRoot\system32\DRIVERS\athr.sys 0x8DB2C000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x8DB36000 \SystemRoot\system32\DRIVERS\sdbus.sys 0x8DB4F000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x8DB53000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x8DB6B000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8DB78000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8DB85000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x8DB8B000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x8DB94000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8DBA6000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x8DBB3000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x8DBC5000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8DBDD000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8C1C2000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8DBE8000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8DA00000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8EBE5000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8E600000 \SystemRoot\system32\DRIVERS\rdpbus.sys 0x8DA17000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8C000000 \SystemRoot\system32\DRIVERS\ks.sys 0x8C1E4000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8D15B000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8D19F000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8D1B0000 \SystemRoot\system32\drivers\HdAudio.sys 0x8CBC2000 \SystemRoot\system32\drivers\portcls.sys 0x8CA00000 \SystemRoot\system32\drivers\drmk.sys 0x9363C000 \SystemRoot\system32\DRIVERS\VSTAZL3.SYS 0x93679000 \SystemRoot\system32\DRIVERS\VSTDPV3.SYS 0x93A3D000 \SystemRoot\system32\DRIVERS\VSTCNXT3.SYS 0x93AF2000 \SystemRoot\system32\drivers\modem.sys 0x93AFF000 \SystemRoot\System32\Drivers\crashdmp.sys 0x93B0C000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x93B17000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x93B20000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x82600000 \SystemRoot\System32\win32k.sys 0x93B31000 \SystemRoot\System32\drivers\Dxapi.sys 0x93B3B000 \SystemRoot\system32\DRIVERS\monitor.sys 0x82860000 \SystemRoot\System32\TSDDD.dll 0x82890000 \SystemRoot\System32\cdd.dll 0x828B0000 \SystemRoot\System32\ATMFD.DLL 0x93B46000 \SystemRoot\system32\drivers\WudfPf.sys 0x93B60000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x93B70000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x93BB6000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x93BC6000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x93BD9000 \SystemRoot\system32\DRIVERS\vwifimp.sys 0x93BE2000 \SystemRoot\system32\DRIVERS\bowser.sys 0x93A00000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x9377B000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x937B6000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x96E05000 \SystemRoot\system32\drivers\peauth.sys 0x96E9C000 \SystemRoot\System32\Drivers\secdrv.SYS 0x96EA6000 \SystemRoot\System32\drivers\tcpipreg.sys 0x96EB3000 \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys 0x96EB4000 \SystemRoot\System32\drivers\rdpdr.sys 0x96ED9000 \SystemRoot\system32\drivers\tdtcp.sys 0x96EE3000 \SystemRoot\System32\DRIVERS\tssecsrv.sys 0x96EF0000 \SystemRoot\System32\Drivers\RDPWD.SYS 0x96F21000 \SystemRoot\system32\drivers\HTTP.sys 0x77640000 \Windows\System32\ntdll.dll 0x483F0000 \Windows\System32\smss.exe 0x77880000 \Windows\System32\apisetschema.dll 0x00280000 \Windows\System32\autochk.exe Processes (total 42): 0 System Idle Process 4 System 280 C:\Windows\System32\smss.exe 372 csrss.exe 424 C:\Windows\System32\wininit.exe 436 csrss.exe 492 C:\Windows\System32\winlogon.exe 532 C:\Windows\System32\services.exe 540 C:\Windows\System32\lsass.exe 548 C:\Windows\System32\lsm.exe 656 C:\Windows\System32\svchost.exe 732 C:\Windows\System32\svchost.exe 848 C:\Windows\System32\svchost.exe 916 C:\Windows\System32\svchost.exe 944 C:\Windows\System32\svchost.exe 1144 C:\Windows\System32\svchost.exe 1248 C:\Windows\System32\svchost.exe 1376 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 1408 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1452 C:\Program Files\Bonjour\mDNSResponder.exe 1484 C:\Windows\System32\svchost.exe 1572 C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe 1596 C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe 1700 C:\Windows\System32\dwm.exe 1716 C:\Windows\explorer.exe 1756 C:\Windows\System32\PSIService.exe 1804 C:\Windows\System32\svchost.exe 1872 C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe 1924 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 2020 C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe 584 C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe 964 C:\Program Files\Common Files\Java\Java Update\jusched.exe 904 C:\Program Files\Windows Live\Messenger\msnmsgr.exe 684 C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe 2168 C:\Windows\System32\svchost.exe 2432 [/SPOILER] Hier der MBR Check :) |
Bin gerade dabei den Malwarebytes Fullscan durchzuführen... Ich poste dann die .log-Datei hier rein. Hast du schon etwas gefunden? :) Wie lange dauert der Scan ca? |
Hi, der MBRCheck ist abgeschnitten bitte packen und als Anhang reinhängen.. chris |
Hier nochmal der MBR Check als .zip-Datei |
Alle Zeitangaben in WEZ +1. Es ist jetzt 02:03 Uhr. |
Copyright ©2000-2025, Trojaner-Board