![]() |
Flacor.dat entdeckt hallo leute, ich habe vor ca. 1 Woche festgestellt, dass sich der pc automatisch hunterfährt nach einem kurzen hinweis. Seit dem kam immer eine Fehlermeldung mit der datei flacor.dat. Nach ein wenig googeln wusste ich dann was ich mir da eingefangen hab, daraufhin einen vollständigen scan mit malwarebytes gemacht und die datei flacor.dat entfernt: Code: Malwarebytes' Anti-Malware 1.46 file1 OTL Logfile: Code: OTL logfile created on: 30.07.2010 20:25:23 - Run 1 file 2 OTL Logfile: Code: OTL Extras logfile created on: 30.07.2010 20:25:23 - Run 1 superantisyware hat nichts mehr gefunden, cc-cleaner hab ich auch durchlaufen lassen, passwörter habe ich alle geändert... kann ich jetzt beruigt weitersurfen oder muss ich mir noch sorgen machen??? ich bedanke mich schonmal für die antworten kann erst am montag wieder antworten da ich morgen übers we weg fahre... grüße Arthur |
Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. |
hab ich wie beschrieben gemacht, hier das logfile: PHP-Code: |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
http://saved.im/mtm0nzyzmzd5/cofi.jpg
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren. |
hallo, hab combofix nun wie beschrieben ausgeführt hier das file: Combofix Logfile: Code: ComboFix 10-08-02.03 - Arthur 03.08.2010 19:20:28.1.2 - x86 |
Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus Anschließend den bootkit_remover herunterladen. Entpacke das Tool in einen eigenen Ordner auf dem Desktop und führe in diesem Ordner die Datei remove.exe aus. Wenn Du Windows Vista oder Windows 7 verwendest, musst Du die remover.exe über ein Rechtsklick => als Administrator ausführen Ein schwarzes Fenster wird sich öffnen und automatisch nach bösartigen Veränderungen im MBR suchen. Poste dann bitte, ob es Veränderungen gibt und wenn ja in welchem device. Am besten alles posten was die remover.exe ausgibt. |
hallo, habe die programme wie beschrieben ausgeführt: gmer: GMER Logfile: Code: GMER 1.0.15.15281 - hxxp://www.gmer.net osam: Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 19:26:05 on 05.08.2010 OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.8 Scanner Settings Rootkits detection (hidden registry) Rootkits detection (hidden files) Retrieve files information Check Microsoft signatures Filters Trusted entries Empty entries Hidden registry entries (rootkit activity) Exclusively opened files Not found files Files without detailed information Existing files Non-startable services Non-startable drivers Active entries Disabled entries Risk Name Publisher Full Path Status AppInit DLLs HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows |||| "AppInit_DLLs" "Google" C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll File exists Control Panel Objects %SystemRoot%\system32 || "DivXControlPanelApplet.cpl" "DivX, Inc." C:\Windows\system32\DivXControlPanelApplet.cpl File exists |||||| "PhysX.cpl" "NVIDIA Corporation" C:\Windows\system32\PhysX.cpl File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls |||||| "QuickTime" "Apple Inc." C:\Program Files\QuickTime\QTSystem\QuickTime.cpl File exists Drivers HKLM\SYSTEM\CurrentControlSet\Services "a7dnvet2" (a7dnvet2) C:\Windows\system32\drivers\a7dnvet2.sys Hidden registry entry, rootkit activity | File not found |||||| "AlfaFF File System mini-filter" (AlfaFF) "Alfa Corporation" C:\Windows\System32\Drivers\AlfaFF.sys File exists |||||| "at7i08x0" (at7i08x0) "Microsoft Corporation" C:\Windows\system32\drivers\at7i08x0.sys Hidden registry entry, rootkit activity | File signed by Microsoft |||||| "atksgt" (atksgt) C:\Windows\System32\DRIVERS\atksgt.sys File found, but it contains no detailed information |||||| "avgio" (avgio) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avgio.sys File exists |||||| "avgntflt" (avgntflt) "Avira GmbH" C:\Windows\System32\DRIVERS\avgntflt.sys File exists |||||| "avipbb" (avipbb) "Avira GmbH" C:\Windows\System32\DRIVERS\avipbb.sys File exists "catchme" (catchme) C:\cofi\catchme.sys File not found |||||| "int15" (int15) C:\Windows\system32\drivers\int15.sys File found, but it contains no detailed information "IP in IP Tunnel Driver" (IpInIp) C:\Windows\System32\DRIVERS\ipinip.sys File not found "IPX Traffic Filter Driver" (NwlnkFlt) C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found "IPX Traffic Forwarder Driver" (NwlnkFwd) C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found |||||| "lirsgt" (lirsgt) C:\Windows\System32\DRIVERS\lirsgt.sys File found, but it contains no detailed information |||||| "NTIPPKernel" (NTIPPKernel) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys File exists "ntnzl" (ntnzl) C:\Windows\system32\drivers\ntnzl.sys File not found |||||| "PSDFilter" (PSDFilter) "Egis Incorporated" C:\Windows\System32\DRIVERS\psdfilter.sys File exists |||||| "PSDNServ" (PSDNServ) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDNServ.sys File exists |||||| "PSDVdisk" (psdvdisk) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDVdisk.sys File exists |||||| "SASDIFSV" (SASDIFSV) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File exists |||||| "SASKUTIL" (SASKUTIL) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS File exists |||||| "sptd" (sptd) "Duplex Secure Ltd." C:\Windows\System32\Drivers\sptd.sys File is exclusively opened, access blocked |||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\Windows\System32\DRIVERS\ssmdrv.sys File exists |||||| "UBHelper" (UBHelper) "NewTech Infosystems Corporation" C:\Windows\system32\drivers\UBHelper.sys File exists |||||| "Upper Class Filter Driver" (NTIDrvr) "NewTech Infosystems, Inc." C:\Windows\System32\DRIVERS\NTIDrvr.sys File exists "vaxscsi" (vaxscsi) C:\Windows\System32\Drivers\vaxscsi.sys File not found |||||| "WSVD" (WSVD) "CyberLink" C:\Windows\system32\drivers\WSVD.sys File exists |||||| "{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}" ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl File exists Explorer HKLM\Software\Classes\Folder\shellex\ColumnHandlers |||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists HKLM\Software\Classes\Protocols\Filter |||| {B1759355-3EEC-4C1E-B0F1-B719FE26E377} "Google Dictionary Compression filter" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists HKLM\Software\Classes\Protocols\Handler |||| {828030A1-22C1-4009-854F-8E305202313F} "livecall" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" "Microsoft Corporation" c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll File exists |||| {828030A1-22C1-4009-854F-8E305202313F} "msnim" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" File not found | COM-object registry key not found HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" File not found | COM-object registry key not found {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" File not found | COM-object registry key not found {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" File not found | COM-object registry key not found |||||| {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" File not found | COM-object registry key not found |||||| {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" "Egis Inc." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll File exists {2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0} "EPM-PO Shell Extensions" epm-po.dll File not found {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" File not found | COM-object registry key not found |||||| {8F9D8FBE-C5C1-4B65-986E-51235C9283E8} "FPLaunchCache" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\FPLaunchCache.dll File exists |||||| {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" "Apple Inc." C:\Program Files\iTunes\iTunesMiniPlayer.dll File exists {00020d75-0000-0000-c000-000000000046} "lnkfile" File not found | COM-object registry key not found |||||| {FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} "Meine freigegebenen Ordner" "Microsoft Corporation" C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" File not found | COM-object registry key not found {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" File not found | COM-object registry key not found |||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\shlext.dll File exists {1C311AAA-D8B1-4A0A-BEE5-2387FEC583DA} "ShellPlusContextMenu" File not found | COM-object registry key not found {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" File not found | COM-object registry key not found |||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Program Files\WinRAR\rarext.dll File found, but it contains no detailed information Internet Explorer HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists "ITBar7Layout" File not found | COM-object registry key not found |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks |||| {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} "Winamp Search Class" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units |||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\npjpi160_20.dll File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions |||||| "Quick-Launching Area" C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar |||||| "Acer eDataSecurity Management" "Egis Incorporated." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll File exists |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects |||||| {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" "Adobe Systems Incorporated" C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File exists |||| {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} "Google Dictionary Compression sdch" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists |||| {AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" "Google Inc." C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll File exists |||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2ssv.dll File exists |||||| {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} "ShowBarObj Class" "Egis" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll File exists |||| {AA61DE26-FA67-4575-9033-918671094293} "TBSB03968 Class" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} "Winamp Toolbar Loader" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists {02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" File not found | COM-object registry key not found {7E853D72-626A-48EC-A868-BA8D5E23E045} "{7E853D72-626A-48EC-A868-BA8D5E23E045}" File not found | COM-object registry key not found Logon %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |||| "AlcoholAutomount" "Alcohol Soft Development Team" "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount File exists |||| "Orb" "Orb Networks" "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background File exists |||||| "SUPERAntiSpyware" "SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File exists |||| "swg" "Google Inc." "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File exists HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd "StartupPrograms" rdpclip File not found HKLM\Software\Microsoft\Windows\CurrentVersion\Run |||| "Adobe Reader Speed Launcher" "Adobe Systems Incorporated" "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" File exists |||| "ArcadeDeluxeAgent" "CyberLink Corp." "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" File exists |||||| "avgnt" "Avira GmbH" "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File exists |||||| "BkupTray" "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" File exists |||| "CLMLServer" "CyberLink" "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" File exists |||| "DAEMON Tools" "DT Soft Ltd." "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 File exists || "DivXUpdate" "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW File exists |||| "eAudio" "Acer Incorporated" "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" File exists |||||| "eDataSecurity Loader" "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe File exists |||||| "ePower_DMC" "Acer Inc." C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe File exists |||| "Google Desktop Search" "Google" "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup File exists |||| "HostManager" "America Online, Inc." C:\Program Files\Common Files\AOL\1223197373\ee\AOLSoftware.exe File exists |||| "IAAnotif" "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe File exists |||| "iTunesHelper" "Apple Inc." "C:\Program Files\iTunes\iTunesHelper.exe" File exists |||| "LexwareInfoService" "Lexware GmbH & Co. KG" C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart File exists |||| "LManager" "Dritek System Inc." C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE File exists |||||| "Malwarebytes Anti-Malware (reboot)" "Malwarebytes Corporation" "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File exists |||| "PlayMovie" "Acer Corp." "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" File exists || "PLFSetI" C:\Windows\PLFSetI.exe File exists |||| "QuickTime Task" "Apple Inc." "C:\Program Files\QuickTime\QTTask.exe" -atboottime File exists |||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Program Files\Common Files\Java\Java Update\jusched.exe" File exists |||| "WarReg_PopUp" "Acer Incorporated" C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe File exists |||| "WinampAgent" "C:\Program Files\Winamp\winampa.exe" File found, but it contains no detailed information |||| "ZPdtWzdVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show File exists Print Monitors HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors |||||| "PDFCreator" C:\Windows\system32\pdfcmnnt.dll File found, but it contains no detailed information Services HKLM\SYSTEM\CurrentControlSet\Services |||||| "AOL Connectivity Service" (AOL ACS) "AOL LLC" C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe File exists |||||| "Apple Mobile Device" (Apple Mobile Device) "Apple Inc." C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe File exists |||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avguard.exe File exists |||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\sched.exe File exists |||||| "CLHNService" (CLHNService) C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe File exists |||||| "Cyberlink RichVideo Service(CRVS)" (RichVideo) C:\Program Files\Cyberlink\Shared files\RichVideo.exe File exists |||||| "Dienst "Bonjour"" (Bonjour Service) "Apple Inc." C:\Program Files\Bonjour\mDNSResponder.exe File exists |||||| "eDataSecurity Service" (eDataSecurity Service) "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe File exists |||||| "Empowering Technology Service" (ETService) C:\Program Files\Acer\Empowering Technology\Service\ETService.exe File exists |||||| "FLEXnet Licensing Service" (FLEXnet Licensing Service) "Macrovision Europe Ltd." C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe File exists |||| "Google Desktop Manager 5.9.911.3589" (GoogleDesktopManager-110309-193829) "Google" C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe File exists |||| "Google Software Updater" (gusvc) "Google" C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File exists |||||| "iGroupTec Service" (IGBASVC) C:\Program Files\Acer\Acer Bio Protection\BASVC.exe File found, but it contains no detailed information |||| "InstallDriver Table Manager" (IDriverT) "Macrovision Corporation" C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe File exists |||||| "Intel(R) Matrix Storage Event Monitor" (IAANTMON) "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe File exists |||||| "iPod-Dienst" (iPod Service) "Apple Inc." C:\Program Files\iPod\bin\iPodService.exe File exists |||||| "LightScribeService Direct Disc Labeling Service" (LightScribeService) "Hewlett-Packard Company" C:\Program Files\Common Files\LightScribe\LSSrvc.exe File exists |||||| "MobilityService" (MobilityService) C:\Acer\Mobility Center\MobilityService.exe File exists |||||| "NMSAccessU" (NMSAccessU) C:\Program Files\CDBurnerXP\NMSAccessU.exe File found, but it contains no detailed information |||||| "NTI Backup Now 5 Agent Service" (BUNAgentSvc) "NewTech Infosystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe File exists |||||| "NTI Backup Now 5 Backup Service" (NTIBackupSvc) "NewTech InfoSystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe File exists |||||| "NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe File found, but it contains no detailed information |||||| "Raw Socket Service" (RS_Service) "Acer Incorporated" C:\Program Files\Acer\Acer VCM\RS_Service.exe File exists || "Sony Ericsson OMSI download service" (OMSI download service) C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe File found, but it contains no detailed information |||||| "StarWind AE Service" (StarWindServiceAE) "Rocket Division Software" C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe File exists Winlogon HKCU\Control Panel\Desktop "SCRNSAVE.EXE" C:\Windows\System32\acer.scr File found, but it contains no detailed information HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify |||||| "AWinNotifyVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll File exists |||||| "spba" "UPEK Inc." C:\Program Files\Common Files\SPBA\homefus2.dll File exists Winsock Providers HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries |||||| "mdnsNSP" "Apple Inc." C:\Program Files\Bonjour\mdnsNSP.dll File exists If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru und HTML-Code: <c> 2009 e Sage Lab |
Zitat:
Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
|
löschen erledigt... OSAM: Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 20:07:22 on 05.08.2010 OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.8 Scanner Settings Rootkits detection (hidden registry) Rootkits detection (hidden files) Retrieve files information Check Microsoft signatures Filters Trusted entries Empty entries Hidden registry entries (rootkit activity) Exclusively opened files Not found files Files without detailed information Existing files Non-startable services Non-startable drivers Active entries Disabled entries Risk Name Publisher Full Path Status AppInit DLLs HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows |||| "AppInit_DLLs" "Google" C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll File exists Control Panel Objects %SystemRoot%\system32 || "DivXControlPanelApplet.cpl" "DivX, Inc." C:\Windows\system32\DivXControlPanelApplet.cpl File exists |||||| "PhysX.cpl" "NVIDIA Corporation" C:\Windows\system32\PhysX.cpl File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls |||||| "QuickTime" "Apple Inc." C:\Program Files\QuickTime\QTSystem\QuickTime.cpl File exists Drivers HKLM\SYSTEM\CurrentControlSet\Services "a7dnvet2" (a7dnvet2) C:\Windows\system32\drivers\a7dnvet2.sys Hidden registry entry, rootkit activity | File not found |||||| "AlfaFF File System mini-filter" (AlfaFF) "Alfa Corporation" C:\Windows\System32\Drivers\AlfaFF.sys File exists |||||| "at7i08x0" (at7i08x0) "Microsoft Corporation" C:\Windows\system32\drivers\at7i08x0.sys Hidden registry entry, rootkit activity | File signed by Microsoft |||||| "atksgt" (atksgt) C:\Windows\System32\DRIVERS\atksgt.sys File found, but it contains no detailed information |||||| "avgio" (avgio) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avgio.sys File exists |||||| "avgntflt" (avgntflt) "Avira GmbH" C:\Windows\System32\DRIVERS\avgntflt.sys File exists |||||| "avipbb" (avipbb) "Avira GmbH" C:\Windows\System32\DRIVERS\avipbb.sys File exists "catchme" (catchme) C:\cofi\catchme.sys File not found |||||| "int15" (int15) C:\Windows\system32\drivers\int15.sys File found, but it contains no detailed information "IP in IP Tunnel Driver" (IpInIp) C:\Windows\System32\DRIVERS\ipinip.sys File not found "IPX Traffic Filter Driver" (NwlnkFlt) C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found "IPX Traffic Forwarder Driver" (NwlnkFwd) C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found |||||| "lirsgt" (lirsgt) C:\Windows\System32\DRIVERS\lirsgt.sys File found, but it contains no detailed information |||||| "NTIPPKernel" (NTIPPKernel) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys File exists |||||| "PSDFilter" (PSDFilter) "Egis Incorporated" C:\Windows\System32\DRIVERS\psdfilter.sys File exists |||||| "PSDNServ" (PSDNServ) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDNServ.sys File exists |||||| "PSDVdisk" (psdvdisk) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDVdisk.sys File exists |||||| "SASDIFSV" (SASDIFSV) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File exists |||||| "SASKUTIL" (SASKUTIL) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS File exists |||||| "sptd" (sptd) "Duplex Secure Ltd." C:\Windows\System32\Drivers\sptd.sys File is exclusively opened, access blocked |||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\Windows\System32\DRIVERS\ssmdrv.sys File exists |||||| "UBHelper" (UBHelper) "NewTech Infosystems Corporation" C:\Windows\system32\drivers\UBHelper.sys File exists |||||| "Upper Class Filter Driver" (NTIDrvr) "NewTech Infosystems, Inc." C:\Windows\System32\DRIVERS\NTIDrvr.sys File exists "vaxscsi" (vaxscsi) C:\Windows\System32\Drivers\vaxscsi.sys File not found |||||| "WSVD" (WSVD) "CyberLink" C:\Windows\system32\drivers\WSVD.sys File exists |||||| "{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}" ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl File exists Explorer HKLM\Software\Classes\Folder\shellex\ColumnHandlers |||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists HKLM\Software\Classes\Protocols\Filter |||| {B1759355-3EEC-4C1E-B0F1-B719FE26E377} "Google Dictionary Compression filter" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists HKLM\Software\Classes\Protocols\Handler |||| {828030A1-22C1-4009-854F-8E305202313F} "livecall" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" "Microsoft Corporation" c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll File exists |||| {828030A1-22C1-4009-854F-8E305202313F} "msnim" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" File not found | COM-object registry key not found HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" File not found | COM-object registry key not found {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" File not found | COM-object registry key not found {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" File not found | COM-object registry key not found |||||| {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" File not found | COM-object registry key not found |||||| {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" "Egis Inc." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll File exists {2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0} "EPM-PO Shell Extensions" epm-po.dll File not found {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" File not found | COM-object registry key not found |||||| {8F9D8FBE-C5C1-4B65-986E-51235C9283E8} "FPLaunchCache" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\FPLaunchCache.dll File exists |||||| {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" "Apple Inc." C:\Program Files\iTunes\iTunesMiniPlayer.dll File exists {00020d75-0000-0000-c000-000000000046} "lnkfile" File not found | COM-object registry key not found |||||| {FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} "Meine freigegebenen Ordner" "Microsoft Corporation" C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" File not found | COM-object registry key not found {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" File not found | COM-object registry key not found |||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\shlext.dll File exists {1C311AAA-D8B1-4A0A-BEE5-2387FEC583DA} "ShellPlusContextMenu" File not found | COM-object registry key not found {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" File not found | COM-object registry key not found |||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Program Files\WinRAR\rarext.dll File found, but it contains no detailed information Internet Explorer HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists "ITBar7Layout" File not found | COM-object registry key not found |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks |||| {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} "Winamp Search Class" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units |||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\npjpi160_20.dll File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions |||||| "Quick-Launching Area" C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar |||||| "Acer eDataSecurity Management" "Egis Incorporated." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll File exists |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects |||||| {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" "Adobe Systems Incorporated" C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File exists |||| {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} "Google Dictionary Compression sdch" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists |||| {AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" "Google Inc." C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll File exists |||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2ssv.dll File exists |||||| {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} "ShowBarObj Class" "Egis" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll File exists |||| {AA61DE26-FA67-4575-9033-918671094293} "TBSB03968 Class" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} "Winamp Toolbar Loader" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists {02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" File not found | COM-object registry key not found {7E853D72-626A-48EC-A868-BA8D5E23E045} "{7E853D72-626A-48EC-A868-BA8D5E23E045}" File not found | COM-object registry key not found Logon %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |||| "AlcoholAutomount" "Alcohol Soft Development Team" "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount File exists |||| "Orb" "Orb Networks" "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background File exists |||||| "SUPERAntiSpyware" "SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File exists |||| "swg" "Google Inc." "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File exists HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd "StartupPrograms" rdpclip File not found HKLM\Software\Microsoft\Windows\CurrentVersion\Run |||| "Adobe Reader Speed Launcher" "Adobe Systems Incorporated" "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" File exists |||| "ArcadeDeluxeAgent" "CyberLink Corp." "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" File exists |||||| "avgnt" "Avira GmbH" "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File exists |||||| "BkupTray" "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" File exists |||| "CLMLServer" "CyberLink" "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" File exists |||| "DAEMON Tools" "DT Soft Ltd." "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 File exists || "DivXUpdate" "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW File exists |||| "eAudio" "Acer Incorporated" "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" File exists |||||| "eDataSecurity Loader" "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe File exists |||||| "ePower_DMC" "Acer Inc." C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe File exists |||| "Google Desktop Search" "Google" "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup File exists |||| "HostManager" "America Online, Inc." C:\Program Files\Common Files\AOL\1223197373\ee\AOLSoftware.exe File exists |||| "IAAnotif" "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe File exists |||| "iTunesHelper" "Apple Inc." "C:\Program Files\iTunes\iTunesHelper.exe" File exists |||| "LexwareInfoService" "Lexware GmbH & Co. KG" C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart File exists |||| "LManager" "Dritek System Inc." C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE File exists |||||| "Malwarebytes Anti-Malware (reboot)" "Malwarebytes Corporation" "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File exists |||| "PlayMovie" "Acer Corp." "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" File exists || "PLFSetI" C:\Windows\PLFSetI.exe File exists |||| "QuickTime Task" "Apple Inc." "C:\Program Files\QuickTime\QTTask.exe" -atboottime File exists |||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Program Files\Common Files\Java\Java Update\jusched.exe" File exists |||| "WarReg_PopUp" "Acer Incorporated" C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe File exists |||| "WinampAgent" "C:\Program Files\Winamp\winampa.exe" File found, but it contains no detailed information |||| "ZPdtWzdVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show File exists Print Monitors HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors |||||| "PDFCreator" C:\Windows\system32\pdfcmnnt.dll File found, but it contains no detailed information Services HKLM\SYSTEM\CurrentControlSet\Services |||||| "AOL Connectivity Service" (AOL ACS) "AOL LLC" C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe File exists |||||| "Apple Mobile Device" (Apple Mobile Device) "Apple Inc." C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe File exists |||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avguard.exe File exists |||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\sched.exe File exists |||||| "CLHNService" (CLHNService) C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe File exists |||||| "Cyberlink RichVideo Service(CRVS)" (RichVideo) C:\Program Files\Cyberlink\Shared files\RichVideo.exe File exists |||||| "Dienst "Bonjour"" (Bonjour Service) "Apple Inc." C:\Program Files\Bonjour\mDNSResponder.exe File exists |||||| "eDataSecurity Service" (eDataSecurity Service) "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe File exists |||||| "Empowering Technology Service" (ETService) C:\Program Files\Acer\Empowering Technology\Service\ETService.exe File exists |||||| "FLEXnet Licensing Service" (FLEXnet Licensing Service) "Macrovision Europe Ltd." C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe File exists |||| "Google Desktop Manager 5.9.911.3589" (GoogleDesktopManager-110309-193829) "Google" C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe File exists |||| "Google Software Updater" (gusvc) "Google" C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File exists |||||| "iGroupTec Service" (IGBASVC) C:\Program Files\Acer\Acer Bio Protection\BASVC.exe File found, but it contains no detailed information |||| "InstallDriver Table Manager" (IDriverT) "Macrovision Corporation" C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe File exists |||||| "Intel(R) Matrix Storage Event Monitor" (IAANTMON) "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe File exists |||||| "iPod-Dienst" (iPod Service) "Apple Inc." C:\Program Files\iPod\bin\iPodService.exe File exists |||||| "LightScribeService Direct Disc Labeling Service" (LightScribeService) "Hewlett-Packard Company" C:\Program Files\Common Files\LightScribe\LSSrvc.exe File exists |||||| "MobilityService" (MobilityService) C:\Acer\Mobility Center\MobilityService.exe File exists |||||| "NMSAccessU" (NMSAccessU) C:\Program Files\CDBurnerXP\NMSAccessU.exe File found, but it contains no detailed information |||||| "NTI Backup Now 5 Agent Service" (BUNAgentSvc) "NewTech Infosystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe File exists |||||| "NTI Backup Now 5 Backup Service" (NTIBackupSvc) "NewTech InfoSystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe File exists |||||| "NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe File found, but it contains no detailed information |||||| "Raw Socket Service" (RS_Service) "Acer Incorporated" C:\Program Files\Acer\Acer VCM\RS_Service.exe File exists || "Sony Ericsson OMSI download service" (OMSI download service) C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe File found, but it contains no detailed information |||||| "StarWind AE Service" (StarWindServiceAE) "Rocket Division Software" C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe File exists Winlogon HKCU\Control Panel\Desktop "SCRNSAVE.EXE" C:\Windows\System32\acer.scr File found, but it contains no detailed information HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify |||||| "AWinNotifyVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll File exists |||||| "spba" "UPEK Inc." C:\Program Files\Common Files\SPBA\homefus2.dll File exists Winsock Providers HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries |||||| "mdnsNSP" "Apple Inc." C:\Program Files\Bonjour\mdnsNSP.dll File exists If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru und MBR check HTML-Code: MBRCheck, version 1.2.3 |
Lösche bitte die vorhandenen MBRCheck.txt. Starte bitte MBRCheck.exe erneut. Diesmal tippe in das Fenster folgendes ein und bestätige jede Eingabe mit Enter bei
http://img831.imageshack.us/img831/5659/mbr.jpg
Nun findest Du 2 MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop. Poste mir den Inhalt von beiden .txt Dokumenten |
schonmal vielen dank für die antworten... hab alles wie beschrieben gemacht nur dass 3 textdokumente auf dem desktop waren...hier die logs: HTML-Code: MBRCheck, version 1.2.3 HTML-Code: MBRCheck, version 1.2.3 HTML-Code: BRCheck, version 1.2.3 |
Wieso denn jetzt drei Logfiles? Du solltest doch nur den Fix auf Platte0 mit MBR-Code für Vista (Option3) machen :confused: Hast Du Windows neugestartet und zur Kontrolle wie in Posting #8 beschrieben nochmal ausgeführt? |
Hallo, Ich hab es so gemacht wie es beschrieben war. Nachdem ich das Programm ausgeführt hatte waren 2 logfiles (die ersten beiden aus meinem post) und ein weiteres file welches sich nicht öffnen lässt auf dem desktop danach hab ich den Neustart gemacht und dann das prog nochmal ausgeführt, dann war das dritte logfiles zu sehen. Soll ich es nochmal machen? |
Ja nochmal machen. Erst den Fix auf PhysicalDrive0 mit dem MBR-Code für Vista. Dann das gleich nochmal für PhysicalDrive1 |
hallo, habe es noch mal gemacht und jetzt sind 2 logfiles auf dem desktop nr.1 vor dem neustart: HTML-Code: MBRCheck, version 1.2.3 und jetzt das logfile was da war nach dem neustart und erneuten programmstart: HTML-Code: MBRCheck, version 1.2.3 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:52 Uhr. |
Copyright ©2000-2025, Trojaner-Board