Was für eine Geburt nach fast 3 Stunden Scan... hier die Logfile
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=7a926438505ef744ba9e6c35645a7712
# engine=14680
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-06 10:08:23
# local_time=2013-08-07 12:08:23 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1797 16775165 100 93 894016 112360124 10253 0
# scanned=182409
# found=3
# cleaned=0
# scan_time=10191
sh=740E73A9271E01CFEEBFE54E0156D374A7AEFD7F ft=1 fh=c71c001177bf4673 vn="Win32/BadJoke.AN trojan" ac=I fn="G:\Porno\Bilder\Alte Bilder\Bilder\Blond 1.exe"
sh=4E048A2C4BA6E8A87475E44956367E149A93E599 ft=1 fh=f89cb68b2a069d04 vn="probably a variant of Win32/Agent.KJVNHOY trojan" ac=I fn="G:\System\Inst\PLAYER\POWER_DVD_50___SERIAL\KEYGEN.EXE"
sh=589F9048D6FD43DF9B33CBA2166397FD06811602 ft=1 fh=67bd6b1b722bcd72 vn="Win32/Adware.Toolbar.Yahoo.A application" ac=I fn="G:\Alte Dateien\Alte Bootpartition\me alt\Yahoo!\Companion\ycomp5_0_2_7.dll"
Results of screen317's Security Check version 0.99.71
Windows XP Service Pack 2 x86
Out of date service pack!!
Internet Explorer 6
Out of date! ``````````````Antivirus/Firewall Check:``````````````
Warten Sie, w„hrend WMIC installiert wird.d
i
s
p
l
a
y
N
a
m
e
ECHO ist ausgeschaltet (OFF).
A
n
t
i
V
i
r
ECHO ist ausgeschaltet (OFF).
D
e
s
k
t
o
p
ECHO ist ausgeschaltet (OFF).
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
TuneUp Utilities 2003
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (Firefox.)
Mozilla Thunderbird (17.0.7)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-08-2013
Ran by Administrator (administrator) on 07-08-2013 00:20:23
Running from C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Downloads
Microsoft Windows XP Professional Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 6
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\WINDOWS\System32\SCardSvr.exe
(Avira GmbH) C:\Programme\Avira\AntiVir Desktop\sched.exe
(Avira GmbH) C:\Programme\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Avira GmbH) C:\Programme\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Avira GmbH) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Ocs_SM] - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\OCS\SM\SearchAnonymizer.exe [106496 2012-08-29] (OCS)
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [281768 2011-03-28] (Avira GmbH)
Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
SearchScopes: HKCU - {99A06EB5-CDF1-47CC-8322-E79BED516C87} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=6157a41e-5da6-4dc6-b2ae-6edd8d59c730&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {AC5A877A-66F9-4BFB-880D-75D13F111766} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=6157a41e-5da6-4dc6-b2ae-6edd8d59c730&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {BBB0487F-C295-43DE-88F6-5DA392694C54} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=6157a41e-5da6-4dc6-b2ae-6edd8d59c730&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {C94E92EB-E393-4F55-A831-F44F0FAF39D9} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=6157a41e-5da6-4dc6-b2ae-6edd8d59c730&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {D390E3E4-CD7D-4F7E-A956-20DD8157C9AA} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=6157a41e-5da6-4dc6-b2ae-6edd8d59c730&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {D5D5F7DA-800B-466B-AD61-C1D0E2F59DBF} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=6157a41e-5da6-4dc6-b2ae-6edd8d59c730&pid=freewarede&mode=bounce&k=0
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @videolan.org/vlc,version=2.0.3 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\searchplugins\{1A6572C2-0348-46F4-ADBB-00C8916F116F}.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\searchplugins\{5FB24447-EF4C-4A42-A29B-E21F10A78AC0}.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\searchplugins\{645F6A1E-B544-495B-BD48-B39465B4583E}.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\Search_Results.xml
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF Extension: Ant Video Downloader - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\anttoolbar@ant.com
FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\de_DE@dicts.j3e.de
FF Extension: WOT - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: adblockpopups - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\adblockpopups@jessehakanen.net.xpi
FF Extension: firefox - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\firefox@ghostery.com.xpi
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\firejump_1027.zip
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\{6bdc61ae-7b80-44a3-9476-e1d121ec2238}.xpi
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\{aee74dd0-6dc9-11db-9fe1-0800200c9a66}.xpi
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF Extension: No Name - C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: No Name - C:\Programme\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF Extension: Default - C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKCU\...\Firefox\Extensions: [mail@shopping-preise.de] C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\extensions\mail@shopping-preise.de
FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\g31g8l6i.default\extensions\firejump@firejump.net
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [136360 2011-03-28] (Avira GmbH)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [269480 2013-03-20] (Avira GmbH)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [117144 2013-07-04] (Mozilla Foundation)
R2 SearchAnonymizer; C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\OCS\SM\SearchAnonymizerHelper.exe [40960 2012-08-29] ()
S3 ServiceLayer; C:\Programme\PC Connectivity Solution\ServiceLayer.exe [657408 2009-10-27] (Nokia)
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
==================== Drivers (Whitelisted) ====================
R3 AR9271; C:\Windows\System32\DRIVERS\athuw.sys [1756384 2010-07-28] (Atheros Communications, Inc.)
R1 avgio; C:\Programme\Avira\AntiVir Desktop\avgio.sys [11608 2010-06-17] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2013-03-20] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2013-03-20] (Avira GmbH)
S3 brfilt; C:\Windows\System32\Drivers\Brfilt.sys [2944 2001-08-17] (Brother Industries Ltd.)
S3 BrUsbScn; C:\Windows\System32\Drivers\BrUsbScn.sys [10368 2001-08-17] (Brother Industries Ltd.)
R3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [93979 2003-10-08] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 mf; C:\Windows\System32\DRIVERS\mf.sys [63744 2004-08-04] (Microsoft Corporation)
S3 Secdrv; C:\Windows\System32\DRIVERS\secdrv.sys [27440 2004-07-17] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH)
R1 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5632 2006-07-24] ()
R3 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\Windows\System32\drivers\ialmsbw.sys [120830 2003-10-08] (Intel Corporation)
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\Windows\System32\drivers\ialmkchw.sys [98842 2003-10-08] (Intel Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U2 CertPropSvc;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-06 21:14 - 2013-08-06 21:14 - 00000000 ____D C:\Programme\ESET
2013-08-06 18:56 - 2013-08-06 18:56 - 00021401 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\FRST.txt
2013-08-06 18:54 - 2013-08-06 18:54 - 01228808 _____ (Farbar) C:\Dokumente und Einstellungen\Administrator\Desktop\FRST.exe
2013-08-06 18:50 - 2013-08-06 18:50 - 00003347 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\JRT.txt
2013-08-06 18:45 - 2013-08-06 18:45 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-06 18:44 - 2013-08-06 18:44 - 00005334 _____ C:\AdwCleaner[R1].txt
2013-08-06 18:21 - 2013-08-06 18:21 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-05 22:19 - 2013-08-05 22:19 - 00059897 _____ C:\ComboFix.txt
2013-08-05 22:14 - 2013-08-05 22:14 - 00008192 ____H C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\system.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\software.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\SAM.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\default.tmp.LOG
2013-08-05 22:07 - 2013-08-05 22:07 - 00000000 _RSHD C:\cmdcons
2013-08-05 22:07 - 2013-06-11 01:05 - 00000211 _____ C:\Boot.bak
2013-08-05 22:07 - 2004-08-03 23:00 - 00262448 __RSH C:\cmldr
2013-08-05 22:05 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-08-05 22:05 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-08-05 22:05 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-08-05 22:05 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-08-05 22:05 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-08-05 22:05 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-08-05 22:05 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-08-05 22:05 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-08-05 22:05 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-08-05 21:57 - 2013-08-05 22:19 - 00000000 ____D C:\Qoobox
2013-08-05 21:57 - 2013-08-05 22:18 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-05 21:57 - 2013-08-05 21:57 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Verwaltung
2013-08-05 21:57 - 2013-08-05 21:57 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Eigene Musik
2013-08-05 15:52 - 2013-08-05 15:52 - 00000000 ____D C:\FRST
2013-08-05 00:15 - 2013-08-06 18:21 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-05 00:15 - 2013-08-05 00:15 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Malwarebytes
2013-08-05 00:15 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-07-14 05:23 - 2013-07-14 05:23 - 00000000 ____D C:\Programme\Mozilla Thunderbird
2013-07-14 05:23 - 2013-07-14 05:23 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Thunderbird
2013-07-13 19:37 - 2013-07-13 19:37 - 00090112 _____ C:\WINDOWS\Minidump\Mini071313-02.dmp
2013-07-13 19:36 - 2013-07-13 19:37 - 00000000 ____D C:\WINDOWS\Minidump
2013-07-13 19:36 - 2013-07-13 19:35 - 00090112 _____ C:\WINDOWS\Minidump\Mini071313-01.dmp
==================== One Month Modified Files and Folders =======
2013-08-06 21:14 - 2013-08-06 21:14 - 00000000 ____D C:\Programme\ESET
2013-08-06 21:14 - 2002-08-16 21:34 - 00000000 ___RD C:\Programme
2013-08-06 20:58 - 2012-08-24 20:44 - 00464268 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-06 19:20 - 2012-08-24 20:50 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-06 19:20 - 2002-08-16 21:37 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-06 19:20 - 2002-08-16 21:37 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-06 19:18 - 2012-08-24 20:51 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator\ntuser.ini
2013-08-06 19:18 - 2012-08-24 20:51 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator
2013-08-06 19:18 - 2012-08-24 20:50 - 00032644 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-06 19:18 - 2002-08-16 22:22 - 00000327 __RSH C:\boot.ini
2013-08-06 19:18 - 2001-08-23 12:00 - 00000604 _____ C:\WINDOWS\win.ini
2013-08-06 19:18 - 2001-08-23 12:00 - 00000435 _____ C:\WINDOWS\system.ini
2013-08-06 19:15 - 2012-08-24 20:50 - 00000000 __SHD C:\Dokumente und Einstellungen\LocalService
2013-08-06 18:56 - 2013-08-06 18:56 - 00021401 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\FRST.txt
2013-08-06 18:54 - 2013-08-06 18:54 - 01228808 _____ (Farbar) C:\Dokumente und Einstellungen\Administrator\Desktop\FRST.exe
2013-08-06 18:50 - 2013-08-06 18:50 - 00003347 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\JRT.txt
2013-08-06 18:45 - 2013-08-06 18:45 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-06 18:44 - 2013-08-06 18:44 - 00005334 _____ C:\AdwCleaner[R1].txt
2013-08-06 18:21 - 2013-08-06 18:21 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-06 18:21 - 2013-08-05 00:15 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-06 01:41 - 2013-03-07 04:51 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\vlc
2013-08-06 00:53 - 2013-02-09 19:58 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Desktop\Verschiedenes
2013-08-05 23:59 - 2012-08-28 23:27 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Adobe
2013-08-05 23:58 - 2012-08-29 05:52 - 00000000 ____D C:\Programme\Google
2013-08-05 23:52 - 2012-08-28 23:15 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-08-05 23:52 - 2012-08-28 23:15 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-08-05 23:48 - 2012-08-30 00:12 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Adobe
2013-08-05 23:48 - 2011-01-28 23:16 - 00000000 ____D C:\Programme\Adobe
2013-08-05 22:19 - 2013-08-05 22:19 - 00059897 _____ C:\ComboFix.txt
2013-08-05 22:19 - 2013-08-05 21:57 - 00000000 ____D C:\Qoobox
2013-08-05 22:18 - 2013-08-05 21:57 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-05 22:14 - 2013-08-05 22:14 - 00008192 ____H C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\system.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\software.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\SAM.tmp.LOG
2013-08-05 22:14 - 2013-08-05 22:14 - 00000000 ____H C:\WINDOWS\system32\config\default.tmp.LOG
2013-08-05 22:14 - 2002-08-16 22:32 - 18612224 _____ C:\WINDOWS\system32\config\software.bak
2013-08-05 22:14 - 2002-08-16 22:32 - 03407872 _____ C:\WINDOWS\system32\config\system.bak
2013-08-05 22:14 - 2002-08-16 22:32 - 00262144 _____ C:\WINDOWS\system32\config\default.bak
2013-08-05 22:14 - 2002-08-16 21:33 - 00262144 _____ C:\WINDOWS\system32\config\SECURITY.bak
2013-08-05 22:14 - 2002-08-16 21:33 - 00262144 _____ C:\WINDOWS\system32\config\SAM.bak
2013-08-05 22:07 - 2013-08-05 22:07 - 00000000 _RSHD C:\cmdcons
2013-08-05 21:57 - 2013-08-05 21:57 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Verwaltung
2013-08-05 21:57 - 2013-08-05 21:57 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Eigene Musik
2013-08-05 21:57 - 2012-08-24 20:51 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme
2013-08-05 15:52 - 2013-08-05 15:52 - 00000000 ____D C:\FRST
2013-08-05 15:49 - 2001-08-23 12:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-05 15:47 - 2002-08-16 21:34 - 00400026 _____ C:\WINDOWS\setupapi.log
2013-08-05 00:15 - 2013-08-05 00:15 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Malwarebytes
2013-08-04 16:00 - 2012-08-24 20:51 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Eigene Bilder
2013-08-03 21:05 - 2012-08-27 12:34 - 00000000 ____D C:\WINDOWS\system32\NtmsData
2013-08-03 20:11 - 2012-08-24 20:42 - 00000000 ____D C:\WINDOWS\Registration
2013-07-31 15:33 - 2002-08-16 21:33 - 00193197 _____ C:\WINDOWS\setupact.log
2013-07-14 21:35 - 2012-08-24 21:26 - 00000000 ____D C:\Programme\Mozilla Maintenance Service
2013-07-14 05:23 - 2013-07-14 05:23 - 00000000 ____D C:\Programme\Mozilla Thunderbird
2013-07-14 05:23 - 2013-07-14 05:23 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Thunderbird
2013-07-13 21:38 - 2013-07-04 00:26 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-07-13 21:38 - 2013-06-18 01:00 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\koyotesofttoolbarnew
2013-07-13 21:38 - 2013-04-12 01:59 - 00000000 ____D C:\Programme\IrfanView
2013-07-13 21:38 - 2013-02-07 22:53 - 00000000 ____D C:\Programme\WinX_Free_MOV_to_MP4_Converter
2013-07-13 21:38 - 2002-08-16 22:19 - 00000000 ____D C:\WINDOWS\Help
2013-07-13 19:37 - 2013-07-13 19:37 - 00090112 _____ C:\WINDOWS\Minidump\Mini071313-02.dmp
2013-07-13 19:37 - 2013-07-13 19:36 - 00000000 ____D C:\WINDOWS\Minidump
2013-07-13 19:35 - 2013-07-13 19:36 - 00090112 _____ C:\WINDOWS\Minidump\Mini071313-01.dmp
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-04 00:57] - [2004-08-04 00:57] - 1035264 ____A (Microsoft Corporation) 22fe1be02eadde1632e478e4125639e0
C:\Windows\System32\winlogon.exe
[2004-08-04 00:58] - [2004-08-04 00:58] - 0507392 ____A (Microsoft Corporation) 2b6a0baf33a9918f09442d873848ff72
C:\Windows\System32\svchost.exe
[2004-08-04 00:58] - [2004-08-04 00:58] - 0014336 ____A (Microsoft Corporation) 65a819b121eb6fdab4400ea42bdffe64
C:\Windows\System32\services.exe
[2004-08-04 00:58] - [2004-08-04 00:58] - 0108544 ____A (Microsoft Corporation) edb6b81761bd60f32f740bbc40afb676
C:\Windows\System32\User32.dll
[2004-08-04 00:57] - [2004-08-04 00:57] - 0578560 ____A (Microsoft Corporation) 56785fd5236d7b22cf471a6da9db46d8
C:\Windows\System32\userinit.exe
[2004-08-04 00:58] - [2004-08-04 00:58] - 0025088 ____A (Microsoft Corporation) d1e53dc57143f2584b1dd53b036c0633
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-04 00:44] - [2004-08-04 00:44] - 0053760 ____A (Microsoft Corporation) d6888520ff56d72a50437e371ca25fc9
==================== End Of Log ============================
--- --- ---
So alles erledigt, und wie gehts weiter?