![]() |
Mahnungsmail von Norton Hallo, ich habe eine Mail bekommen von inkassobuy.norton.com. Sehr geehrte/r Rabea Wilke, mit Bezug auf unsere Rechnung Nr.: 3369042158 und unsere 1. sowie auch unsere zweite Abmahnung mussten wir soeben festellen, dass Ihre Zahlung bei uns noch immer nicht eingegangen ist. Dies ist ein gesetzlicher Vertragsbruch Ihrerseits. Nach geltendem Recht könnten wir die offene Forderung bereits jetzt bei Gericht anklagen. Wir schenken Ihnen trotzdem noch eine letzte Möglichkeit, Ihre vertragliche Verpflichtung zu erfüllen, indem Sie unverzüglich die ausstehende Summe in Höhe von 654,00 EU an uns zur Zahlung bringen. Die Kontodaten ersehen Sie im beigefügtem Vertrag. Mail-Support@norton.de Tel. 0800 0700 / 2702 buy.norton.com Geschäftsführer Max Schulz Umsatzsteuer DE 1942868845 diese mail hatte einen zip anhang. leider habe ich darauf geklickt. jetzt weiß ich nicht, ob ich mir nen trojaner eingefangen habe. lt. trojaner remover ist da nix. was muss ich jetzt am besten machen? lg rabea |
:hallo: Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers dann: Systemscan mit OTL (bebilderte Anleitung) Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)- Doppelklick auf die OTL.exe
|
OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 13.05.2013 23:41:54 - Run 1 OTL Logfile: Code: OTL logfile created on: 13.05.2013 23:41:54 - Run 1 |
|
erledigt! --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.05.0.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_37 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, F:\ DRIVE_FIXED, Q:\ DRIVE_FIXED CPU speed: 2.294000 GHz Memory total: 4240293888, free: 534315008 ------------ Kernel report ------------ 05/14/2013 00:50:24 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\system32\DRIVERS\kl1.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\DRIVERS\iaStor.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\avgrkx64.sys \SystemRoot\system32\DRIVERS\avgloga.sys \SystemRoot\system32\DRIVERS\avgmfx64.sys \SystemRoot\system32\DRIVERS\avgidsha.sys \SystemRoot\system32\drivers\cdrom.sys \SystemRoot\System32\Drivers\aswSnx.SYS \SystemRoot\system32\DRIVERS\klif.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \??\C:\Windows\system32\drivers\avgtpx64.sys \SystemRoot\System32\Drivers\aswKbd.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\kl2.sys \SystemRoot\System32\Drivers\aswTdi.SYS \SystemRoot\system32\DRIVERS\avgtdia.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\Drivers\aswrdr2.sys \SystemRoot\system32\DRIVERS\vsdatant.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\avkmgr.sys \SystemRoot\system32\DRIVERS\avipbb.sys \SystemRoot\system32\DRIVERS\avgldx64.sys \SystemRoot\system32\DRIVERS\avgidsdrivera.sys \SystemRoot\System32\Drivers\aswSP.SYS \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\system32\DRIVERS\igdpmd64.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\DRIVERS\HECIx64.sys \SystemRoot\system32\drivers\usbehci.sys \SystemRoot\system32\drivers\USBPORT.SYS \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\netr28x.sys \SystemRoot\system32\DRIVERS\vwifibus.sys \SystemRoot\system32\DRIVERS\Rt64win7.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\drivers\mouclass.sys \SystemRoot\system32\drivers\wmiacpi.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\clwvd.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\stwrt64.sys \SystemRoot\system32\DRIVERS\portcls.sys \SystemRoot\system32\DRIVERS\drmk.sys \SystemRoot\system32\DRIVERS\IntcDAud.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\DRIVERS\cdfs.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_iaStor.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \??\C:\Windows\system32\drivers\aswMonFlt.sys \SystemRoot\system32\DRIVERS\avgntflt.sys \SystemRoot\System32\Drivers\aswFsBlk.SYS \SystemRoot\system32\DRIVERS\Sftvollh.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\system32\DRIVERS\Sftfslh.sys \SystemRoot\system32\DRIVERS\Sftplaylh.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\DRIVERS\Sftredirlh.sys \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\monitor.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll ----------- End ----------- <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa8006c36060 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IAAStorageDevice-1\ Lower Device Object: 0xfffffa80050bf050 Lower Device Driver Name: \Driver\iaStor\ Driver name found: iaStor Initialization returned 0x0 Load Function returned 0x0 Downloaded database version: v2013.05.13.08 Downloaded database version: v2013.05.07.01 Initializing... Done! <<<2>>> Device number: 0, partition: 2 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8006c36060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8006ad39d0, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8006c36060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80050bf050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0xfffff8a00a9ba5f0, 0xfffffa8006c36060, 0xfffffa800902d790 Lower DeviceData: 0xfffff8a00bb669a0, 0xfffffa80050bf050, 0xfffffa800b9fbe40 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\Windows\system32\drivers... <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: FBCCF9BA Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 407552 Partition file system is NTFS Partition is bootable Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 409600 Numsec = 1434046464 Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 1434456064 Numsec = 30480384 Partition 3 type is Other (0xc) Partition is NOT ACTIVE. Partition starts at LBA: 1464936448 Numsec = 210672 Disk Size: 750156374016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1465129168-1465149168)... Done! Performing system, memory and registry scan... Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{597A9974-8CB0-4f41-B61F-ED065738A397} --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\RewardsArcade.dll --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{25514C64-8321-494e-BD3E-3DBAB3F8CEBA} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\TYPELIB\{60BE6B2E-F2F5-4404-AA1E-4381D4A6EEA2} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\INTERFACE\{6427058B-217C-4C7F-A6CE-C7934C0BDCEB} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\INTERFACE\{E788D914-2C76-4D67-A8CD-ECC7ED0D0748} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\INTERFACE\{F30C03B4-104E-4FD4-842B-B9E9F52ED415} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6427058B-217C-4C7F-A6CE-C7934C0BDCEB} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E788D914-2C76-4D67-A8CD-ECC7ED0D0748} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F30C03B4-104E-4FD4-842B-B9E9F52ED415} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{60BE6B2E-F2F5-4404-AA1E-4381D4A6EEA2} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\RewardsArcade.FBApi.1 --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\RewardsArcade.FBApi --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.FBApi --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.FBApi.1 --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BDA89DCD-8B25-48c7-B1E2-07CA622E0CA8} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\RewardsArcade.Sandbox.1 --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\RewardsArcade.Sandbox --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.Sandbox --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.Sandbox.1 --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\RewardsArcade.BHO.1 --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{597A9974-8CB0-4F41-B61F-ED065738A397} --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\CLASSES\RewardsArcade.BHO --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.BHO --> [PUP.RewardsArcade] Infected: HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.BHO.1 --> [PUP.RewardsArcade] Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{597A9974-8CB0-4F41-B61F-ED065738A397} --> [PUP.RewardsArcade] Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{597A9974-8CB0-4F41-B61F-ED065738A397} --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\fb.js --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\appAPIinternalWrapper.js --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\jquery.js --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\json.js --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\RewardsArcade.exe --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\Uninstall.exe --> [PUP.RewardsArcade] Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RewardsArcade --> [PUP.RewardsArcade] Infected: c:\Program Files (x86)\RewardsArcade\UserConfirmation.exe --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498 --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\uninstall.ico --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Chrome --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Chrome\rewardsarcade.crx --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome.manifest --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\install.rdf --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\background.html --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\browser.xul --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\crossrider.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\crossriderapi.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\manage-apps-style.css --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\manage-apps.html --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\messaging.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\options.xul --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\push.html --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\socialapi.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\update.html --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\utilityapi.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\workers_chain.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\faye-browser-min.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\jquery-1.4.2.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\facebox.css --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\facebox.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\b.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\bl.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\br.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\closelabel.gif --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\loading.gif --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\tl.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\tr.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults\preferences --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults\preferences\prefs.js --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale\en-US --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale\en-US\translations.dtd --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button1.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button2.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button3.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button4.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button5.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\crossrider_statusbar.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\icon24.png --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\skin.css --> [PUP.RewardsArcade] Infected: c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\update.css --> [PUP.RewardsArcade] Done! Scan finished Creating System Restore point... Scheduling clean up... <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.05.0.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_37 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, F:\ DRIVE_FIXED, Q:\ DRIVE_FIXED CPU speed: 2.294000 GHz Memory total: 4240293888, free: 2367803392 Removal queue found; removal started Removing c:\Program Files (x86)\RewardsArcade\RewardsArcade.dll... Removing c:\Program Files (x86)\RewardsArcade\fb.js... Removing c:\Program Files (x86)\RewardsArcade... Removing c:\Program Files (x86)\RewardsArcade\appAPIinternalWrapper.js... Removing c:\Program Files (x86)\RewardsArcade\jquery.js... Removing c:\Program Files (x86)\RewardsArcade\json.js... Removing c:\Program Files (x86)\RewardsArcade\RewardsArcade.exe... Removing c:\Program Files (x86)\RewardsArcade\Uninstall.exe... Removing c:\Program Files (x86)\RewardsArcade\UserConfirmation.exe... Removing c:\Users\Königskind\AppData\Local\RewardsArcade... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\uninstall.ico... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Chrome... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Chrome\rewardsarcade.crx... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome.manifest... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\install.rdf... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\background.html... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\browser.xul... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\crossrider.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\crossriderapi.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\manage-apps-style.css... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\manage-apps.html... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\messaging.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\options.xul... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\push.html... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\socialapi.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\update.html... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\utilityapi.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\workers_chain.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\faye-browser-min.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\jquery-1.4.2.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\facebox.css... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\facebox.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\b.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\bl.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\br.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\closelabel.gif... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\loading.gif... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\tl.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\tr.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults\preferences... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults\preferences\prefs.js... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale\en-US... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale\en-US\translations.dtd... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button1.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button2.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button3.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button4.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button5.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\crossrider_statusbar.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\icon24.png... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\skin.css... Removing c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\update.css... Removal finished ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.05.0.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_37 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, F:\ DRIVE_FIXED, Q:\ DRIVE_FIXED CPU speed: 2.294000 GHz Memory total: 4240293888, free: 1376759808 ------------ Kernel report ------------ 05/14/2013 07:12:30 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\system32\DRIVERS\kl1.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\DRIVERS\iaStor.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\avgrkx64.sys \SystemRoot\system32\DRIVERS\avgloga.sys \SystemRoot\system32\DRIVERS\avgmfx64.sys \SystemRoot\system32\DRIVERS\avgidsha.sys \SystemRoot\system32\drivers\cdrom.sys \SystemRoot\System32\Drivers\aswSnx.SYS \SystemRoot\system32\DRIVERS\klif.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \??\C:\Windows\system32\drivers\avgtpx64.sys \SystemRoot\System32\Drivers\aswKbd.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\kl2.sys \SystemRoot\System32\Drivers\aswTdi.SYS \SystemRoot\system32\DRIVERS\avgtdia.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\Drivers\aswrdr2.sys \SystemRoot\system32\DRIVERS\vsdatant.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\avkmgr.sys \SystemRoot\system32\DRIVERS\avipbb.sys \SystemRoot\system32\DRIVERS\avgldx64.sys \SystemRoot\system32\DRIVERS\avgidsdrivera.sys \SystemRoot\System32\Drivers\aswSP.SYS \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\system32\DRIVERS\igdpmd64.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\DRIVERS\HECIx64.sys \SystemRoot\system32\drivers\usbehci.sys \SystemRoot\system32\drivers\USBPORT.SYS \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\netr28x.sys \SystemRoot\system32\DRIVERS\vwifibus.sys \SystemRoot\system32\DRIVERS\Rt64win7.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\drivers\mouclass.sys \SystemRoot\system32\drivers\wmiacpi.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\clwvd.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\stwrt64.sys \SystemRoot\system32\DRIVERS\portcls.sys \SystemRoot\system32\DRIVERS\drmk.sys \SystemRoot\system32\DRIVERS\IntcDAud.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\DRIVERS\cdfs.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_iaStor.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \??\C:\Windows\system32\drivers\aswMonFlt.sys \SystemRoot\system32\DRIVERS\avgntflt.sys \SystemRoot\System32\Drivers\aswFsBlk.SYS \SystemRoot\system32\DRIVERS\Sftvollh.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\system32\DRIVERS\Sftfslh.sys \SystemRoot\system32\DRIVERS\Sftplaylh.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\DRIVERS\Sftredirlh.sys \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll ----------- End ----------- <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa8006c36060 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IAAStorageDevice-1\ Lower Device Object: 0xfffffa80050c8050 Lower Device Driver Name: \Driver\iaStor\ Driver name found: iaStor Initialization returned 0x0 Load Function returned 0x0 Downloaded database version: v2013.05.13.09 Downloaded database version: v2013.05.14.01 Downloaded database version: v2013.05.13.01 Initializing... Done! <<<2>>> Device number: 0, partition: 2 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8006c36060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8006c36b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8006c36060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80050c8050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0xfffff8a0109831d0, 0xfffffa8006c36060, 0xfffffa8009d65500 Lower DeviceData: 0xfffff8a009eccb10, 0xfffffa80050c8050, 0xfffffa800a4243a0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\Windows\system32\drivers... <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: FBCCF9BA Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 407552 Partition file system is NTFS Partition is bootable Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 409600 Numsec = 1434046464 Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 1434456064 Numsec = 30480384 Partition 3 type is Other (0xc) Partition is NOT ACTIVE. Partition starts at LBA: 1464936448 Numsec = 210672 Disk Size: 750156374016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1465129168-1465149168)... Done! Performing system, memory and registry scan... Done! Scan finished ======================================= und jetzt? |
bitte das richtige Logfile posten! Siehe Anleitung! Bitte an die Reihenfolge halten. Downloade Dir bitte ![]()
Systemscan mit OTL (bebilderte Anleitung) Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)- Doppelklick auf die OTL.exe
|
AdwCleaner Logfile: Code: # AdwCleaner v2.300 - Datei am 14/05/2013 um 14:48:21 erstellt habe jetzt nochmal mit otl.exe gescannt bekomme aber keine logfiles. wo finde ich die? gestern öffneten die sich automatisch. heute nicht. |
wer lesen und gucken kann ist klar im vorteil! ;-)OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 14.05.2013 14:58:32 - Run 2 wer lesen und gucken kann ist klar im vorteil! ;-)OTL EXTRAS Logfile: |
OTL Logfile: Code: OTL logfile created on: 14.05.2013 14:58:32 - Run 2 |
Es geht mir um dieses Logfile: Das Tool (MBAR) wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier. Du solltest Zonalarm und Spybot deinstallieren. |
Malwarebytes Anti-Rootkit BETA 1.05.0.1001 Malwarebytes : Free anti-malware download Database version: v2013.05.14.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Königskind :: KÖNIGSKIND-HP [administrator] 14.05.2013 07:31:19 mbar-log-2013-05-14 (07-31-19).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 30219 Time elapsed: 18 minute(s), 33 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ist das jetzt richtig? zonealarm und spybot sind runter |
Ich wollte kein neues, sondern das von gestern mit den Funden. |
Malwarebytes Anti-Rootkit BETA 1.05.0.1001 Malwarebytes : Free anti-malware download Database version: v2013.05.13.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Königskind :: KÖNIGSKIND-HP [administrator] 14.05.2013 01:16:12 mbar-log-2013-05-14 (01-16-12).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 30421 Time elapsed: 25 minute(s), 5 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 27 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{597A9974-8CB0-4f41-B61F-ED065738A397} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{25514C64-8321-494e-BD3E-3DBAB3F8CEBA} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\TYPELIB\{60BE6B2E-F2F5-4404-AA1E-4381D4A6EEA2} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{6427058B-217C-4C7F-A6CE-C7934C0BDCEB} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{E788D914-2C76-4D67-A8CD-ECC7ED0D0748} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{F30C03B4-104E-4FD4-842B-B9E9F52ED415} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6427058B-217C-4C7F-A6CE-C7934C0BDCEB} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E788D914-2C76-4D67-A8CD-ECC7ED0D0748} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F30C03B4-104E-4FD4-842B-B9E9F52ED415} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{60BE6B2E-F2F5-4404-AA1E-4381D4A6EEA2} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\RewardsArcade.FBApi.1 (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\RewardsArcade.FBApi (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.FBApi (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.FBApi.1 (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BDA89DCD-8B25-48c7-B1E2-07CA622E0CA8} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\RewardsArcade.Sandbox.1 (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\RewardsArcade.Sandbox (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.Sandbox (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.Sandbox.1 (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\RewardsArcade.BHO.1 (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{597A9974-8CB0-4F41-B61F-ED065738A397} (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\RewardsArcade.BHO (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.BHO (PUP.RewardsArcade) -> Delete on reboot. HKLM\SOFTWARE\WOW6432NODE\CLASSES\RewardsArcade.BHO.1 (PUP.RewardsArcade) -> Delete on reboot. HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{597A9974-8CB0-4F41-B61F-ED065738A397} (PUP.RewardsArcade) -> Delete on reboot. HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{597A9974-8CB0-4F41-B61F-ED065738A397} (PUP.RewardsArcade) -> Delete on reboot. HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RewardsArcade (PUP.RewardsArcade) -> Delete on reboot. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 15 c:\Program Files (x86)\RewardsArcade (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498 (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Chrome (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults\preferences (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale\en-US (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin (PUP.RewardsArcade) -> Delete on reboot. Files Detected: 47 c:\Program Files (x86)\RewardsArcade\RewardsArcade.dll (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\fb.js (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\appAPIinternalWrapper.js (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\jquery.js (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\json.js (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\RewardsArcade.exe (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\Uninstall.exe (PUP.RewardsArcade) -> Delete on reboot. c:\Program Files (x86)\RewardsArcade\UserConfirmation.exe (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\uninstall.ico (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Chrome\rewardsarcade.crx (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome.manifest (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\install.rdf (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\background.html (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\browser.xul (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\crossrider.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\crossriderapi.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\manage-apps-style.css (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\manage-apps.html (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\messaging.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\options.xul (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\push.html (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\socialapi.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\update.html (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\utilityapi.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\workers_chain.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\faye-browser-min.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\jquery-1.4.2.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\facebox.css (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\facebox.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\b.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\bl.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\br.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\closelabel.gif (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\loading.gif (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\tl.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\chrome\content\lib\facebox\Images\tr.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\defaults\preferences\prefs.js (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\locale\en-US\translations.dtd (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button1.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button2.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button3.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button4.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\button5.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\crossrider_statusbar.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\icon24.png (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\skin.css (PUP.RewardsArcade) -> Delete on reboot. c:\Users\Königskind\AppData\Local\RewardsArcade\498\Firefox\skin\update.css (PUP.RewardsArcade) -> Delete on reboot. (end) |
Sehr gut! :daumenhoc Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
dann: Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). danach: ESET Online Scanner
danach: Downloade Dir bitte ![]()
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by *** on 14.05.2013 at 21:44:52,08 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B45794A0-63E5-4723-8BF2-6AD1914E67E1} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\sho14BF.tmp Successfully deleted: [File] C:\Windows\syswow64\sho20B7.tmp Successfully deleted: [File] C:\Windows\syswow64\sho56DA.tmp Successfully deleted: [File] C:\Windows\syswow64\sho5EEE.tmp Successfully deleted: [File] C:\Windows\syswow64\sho5FE2.tmp Successfully deleted: [File] C:\Windows\syswow64\sho92E0.tmp Successfully deleted: [File] C:\Windows\syswow64\sho99BE.tmp Successfully deleted: [File] C:\Windows\syswow64\shoA13A.tmp Successfully deleted: [File] C:\Windows\syswow64\shoA2AB.tmp Successfully deleted: [File] C:\Windows\syswow64\shoD09.tmp Successfully deleted: [File] C:\Windows\syswow64\shoD706.tmp ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\systweak" Successfully deleted: [Folder] "C:\Users\***\AppData\Roaming\systweak" Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{0191740C-1690-478C-A14A-6E4291517EAC} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{08C2969D-9F37-4C04-A9D4-FD556A389215} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{08FE46C7-7CB2-43D4-A64A-2FBF98A50880} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{0FC4955C-C95A-4F27-8B8D-39E55EEEC2A5} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{14BCE7F4-D1D8-4EB0-AB93-22D12E67FA65} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{2A6EA73B-7B3A-43DE-AE26-70B8DB3580B9} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{3193E6E7-37D3-4C50-91DE-BAC7EFDC43EA} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{344F88C2-8FA6-41B1-B122-0BBC9D395547} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{362747BC-413E-40CC-AF13-E8F909DFCFFB} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{4CCF5AA6-5908-4F11-B1B1-BBEF94CF2C9E} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{59968AB5-EAE2-49C2-8AC0-A16068DAFD60} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{5A48F32D-9939-48A1-A1DB-9F775C1DC182} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{5BE654A8-1E99-44B1-B4D8-708B6557F8BE} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{7015B0F2-B87F-4CA9-BF39-552171CC4501} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{786F48A4-0617-4BE4-B3AA-DD65D08E17A1} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{85363AA7-D054-467E-9872-48D0D4DA521F} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{8E8C9EBF-164D-455F-BBAA-3248DC295971} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{9E07837E-0D2A-41F2-ACC2-57480BD34BCB} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{BAFBCF0D-39A2-492F-AEBB-70109065F058} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{BB280A8C-DA37-4A30-9110-6AB7D849B272} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{C17AE1A6-AC78-4345-8173-07C6862192B4} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{C22F6C21-6190-4533-B2FF-21939137832D} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{C2849784-1748-438D-93D7-240A6B1153D1} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{CAB3779A-9781-4913-9D86-82BA337EF53C} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{CBF809FA-2F04-4E35-BE33-1AA6D9BAA2F1} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{CF42017C-4B6C-4F59-BE5C-B00C101517BC} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{D2B7673E-8801-40FB-AE65-81604FEFAF6B} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{D9F8C53C-0E79-4D41-B189-DB6F2688D507} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{E2D11AA4-BCFE-4E14-B0EF-5A29DE453BBC} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{EC29AAD7-179C-4B42-9CF2-782B6D2E67CD} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{F07DFEE2-13A1-43B7-9644-E74B056A284D} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{F9986E6E-3DC5-495A-9C6E-81296D7F9AE8} Successfully deleted: [Empty Folder] C:\Users\***\appdata\local\{FB2BC10C-3418-4ACD-AB5E-27A0AB1A511D} ~~~ FireFox Emptied folder: C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\7rrm6a6g.default\minidumps [24 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 14.05.2013 at 21:50:39,10 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-05-14 22:03:32 ----------------------------- 22:03:32.416 OS Version: Windows x64 6.1.7601 Service Pack 1 22:03:32.416 Number of processors: 4 586 0x2A07 22:03:32.416 ComputerName: ***-HP UserName: *** 22:03:34.676 Initialize success 22:03:35.676 AVAST engine defs: 13051400 22:04:34.576 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:04:34.576 Disk 0 Vendor: TOSHIBA_ GN00 Size: 715404MB BusType: 3 22:04:34.696 Disk 0 MBR read successfully 22:04:34.696 Disk 0 MBR scan 22:04:34.706 Disk 0 Windows 7 default MBR code 22:04:34.726 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 22:04:34.746 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 700218 MB offset 409600 22:04:34.776 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 14883 MB offset 1434456064 22:04:34.786 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1464936448 22:04:34.936 Disk 0 scanning C:\Windows\system32\drivers 22:04:48.556 Service scanning 22:05:25.556 Modules scanning 22:05:25.576 Disk 0 trace - called modules: 22:05:25.956 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 22:05:25.966 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004fee060] 22:05:25.976 3 CLASSPNP.SYS[fffff88001c0143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ceb050] 22:05:26.946 AVAST engine scan C:\Windows 22:05:29.416 AVAST engine scan C:\Windows\system32 22:08:33.259 AVAST engine scan C:\Windows\system32\drivers 22:08:46.199 AVAST engine scan C:\Users\*** 22:16:48.080 AVAST engine scan C:\ProgramData 22:19:09.382 Scan finished successfully 22:30:44.387 Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\MBR.dat" 22:30:44.401 The log file has been saved successfully to "C:\Users\***\Desktop\aswMBR.txt" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ecb9cb48b711d648a33d6ce53f8b6beb # engine=13831 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-15 06:58:23 # local_time=2013-05-15 08:58:23 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 100 94 7685020 145307375 0 0 # compatibility_mode=1045 16777213 100 95 4731084 55735087 0 0 # compatibility_mode=1799 16775165 100 96 43109 234024393 35887 0 # compatibility_mode=5893 16776574 66 85 25910636 120230953 0 0 # scanned=195765 # found=1 # cleaned=0 # scan_time=37233 sh=0ADB7380EB4D577635DF02DA6CA061B94D1BF192 ft=0 fh=0000000000000000 vn="Win32/Trustezeb.C trojan" ac=I fn="C:\Users\Königskind\AppData\Local\Temp\****** Mahnbescheid 13.05.2013 3369042158 buy.norton.com.zip" Unsupported operating system! Aborted! |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:47 Uhr. |
Copyright ©2000-2025, Trojaner-Board