Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Festplatte beschädigt Das System hat mit einem oder mehreren installierten... (https://www.trojaner-board.de/97826-festplatte-beschaedigt-system-hat-mehreren-installierten.html)

sandra23 21.04.2011 15:37

Festplatte beschädigt Das System hat mit einem oder mehreren installierten...
 
Ich habe vorhin eine Virenmeldung von antivir gekriegt. Dann habe ich auf Virus entfernen geklickt und nichts passierte. Dann kam die Meldung: "Festplatte beschädigt Das System hat mit einem oder mehreren installierten
IDE/SATA Festplatten erkannt. Es wird empfohlen, das System neu zu starten."
Nach dem Neustart ist mein Destop schwarz geworden und alle persönlichen Daten wie Bilder, Dokumente, Musik ect. sind weg/bzw. werden nicht mehr angezeigt ("Ordner ist leer"). Weiterhin ploppt die obrige Meldung auf: "Festplatte beschädigt..."
Außerdem ist dann noch folgende Meldung aufgeploppt: "Windows - Datenverlust beim Schreiben - Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern. Daten verloren. Dieser Fehler kann durch einen Ausfall der Hardware verursacht werde."
Dann habe ich mbam heruntergeladen und den Suchlauf gestartet.
Ergebnis: 5 Trojaner! 3 aus der Kategorie "File", 1 aus der Kategorie "Registry Value" und 1 aus der Kategorie "Memory Process"

Soll ich diese Trojaner jetzt einfach löschen? Wer kann mir helfen?

sandra23 21.04.2011 16:36

Hat vielleicht irgendjemand eine Idee?

cosinus 21.04.2011 16:52

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

sandra23 21.04.2011 16:58

Danke schon mal! Habe ja schon einen scan gemacht. Soll ich die 5 Trojaner jetzt in der Liste entfernen, also "Entferne Auswahl" klicken? Sonst kann ich auf Logdateien nicht klicken und diese nicht einsehen...

Gruß, Sandra

cosinus 21.04.2011 17:00

Steht doch alles in der Anleitung! Ja du sollst alle Funde entfernen!

sandra23 21.04.2011 17:18

Hier schon mal die Log-Datei von Malware, die anderen folgen gleich:

Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes

Datenbank Version: 6412

Windows 6.0.6000
Internet Explorer 8.0.6001.18904

21.04.2011 18:06:23
mbam-log-2011-04-21 (18-06-23).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 303982
Laufzeit: 1 Stunde(n), 8 Minute(n), 2 Sekunde(n)

Infizierte Speicherprozesse: 1
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 3

Infizierte Speicherprozesse:
c:\programdata\mrtpnafmrsnt.exe (Trojan.FakeAlert) -> 3760 -> Unloaded process successfully.

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MRtPNAFMRSnT (Trojan.FakeAlert) -> Value: MRtPNAFMRSnT -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\programdata\mrtpnafmrsnt.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\***\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\S69Y5UX3\contacts[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\***\AppData\Local\microsoft\Windows\temporary internet files\virtualized\C\Users\***\Desktop\null0.22724736110667743.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

sandra23 21.04.2011 17:46

Hier die 1. Log-File von OTL:OTL Logfile:
Code:

OTL logfile created on: 21.04.2011 18:23:21 - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\***\Desktop
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 61,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 303,35 Gb Total Space | 113,21 Gb Free Space | 37,32% Space Free | Partition Type: NTFS
Drive D: | 150,69 Gb Total Space | 147,31 Gb Free Space | 97,75% Space Free | Partition Type: NTFS
 
Computer Name: *** | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\***\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10o_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Handy\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
PRC - C:\Programme\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Programme\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Programme\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Picasa2\PicasaMediaDetector.exe (Google Inc.)
PRC - C:\Programme\Java\jre1.5.0_12\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
PRC - C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Windows\System32\PSIService.exe ()
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - c:\Programme\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Programme\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\***\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.20656_none_463680b8218be5a3\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WDDMService) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (WDSmartWareBackgroundService) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (Symantec Core LC) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (UPnPService) -- C:\Programme\Common Files\MAGIX Shared\UPnPService\UPnPService.exe (Magix AG)
SRV - (TestHandler) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
SRV - (LiveUpdate) -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatisches LiveUpdate - Scheduler) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (ProtexisLicensing) -- C:\Windows\System32\PSIService.exe ()
SRV - (ISPwdSvc) -- c:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (CLTNetCnService) -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (comHost) -- c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (SymAppCore) -- c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\DJing\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (WDC_SAM) -- C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvrd32) -- C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) -- C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (JRAID) -- C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (NAVEX15) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20061106.064\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20061106.064\NAVENG.SYS (Symantec Corporation)
DRV - (SRTSPL) -- C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (IDSvix86) -- C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20061025.029\IDSvix86.sys (Symantec Corporation)
DRV - (SPBBCDrv) -- C:\Programme\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.prosieben.de/index.php?icqpath=icq
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,736 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1            localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Programme\Common Files\Symantec Shared\coShared\Browser\1.0\NppBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_12\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Programme\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll (Symantec Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe (Symantec Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [osCheck] c:\Program Files\Norton Internet Security\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [recinfo781] c:\RecInfo\RecInfo.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (Fujitsu Siemens Computers)
O4 - HKCU..\Run: [ICQ]  File not found
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Handy\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Öffnen mit WordPerfect - C:\Programme\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_12\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: beatport.com ([www] https in Vertrauenswürdige Sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5-windows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{a67e2bd3-adf6-11df-a61e-e83336762d64}\Shell - "" = AutoRun
O33 - MountPoints2\{a67e2bd3-adf6-11df-a61e-e83336762d64}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.04.21 18:20:01 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2011.04.21 14:26:25 | 000,000,000 | -H-D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2011.04.21 14:25:42 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.21 14:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.21 14:25:41 | 000,000,000 | -H-D | C] -- C:\ProgramData\Malwarebytes
[2011.04.21 14:25:38 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.04.21 14:25:38 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.21 14:23:59 | 007,734,208 | -H-- | C] (Malwarebytes Corporation                                    ) -- C:\Users\***\Desktop\mbam-setup.exe
[2011.03.28 20:13:59 | 000,000,000 | -H-D | C] -- C:\Users\***\Desktop\Handy-Bilder
[2011.03.27 21:38:36 | 000,000,000 | -H-D | C] -- C:\Users\***\Desktop\Friends
[2011.03.27 21:35:21 | 000,000,000 | -H-D | C] -- C:\Users\***\Desktop\Bilder neu
 
========== Files - Modified Within 30 Days ==========
 
[2011.04.21 18:25:06 | 000,000,438 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E7E0B6B1-1A3B-4C4E-B4C8-551C4C89B1E4}.job
[2011.04.21 18:20:06 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2011.04.21 18:18:56 | 000,641,106 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.21 18:18:56 | 000,609,944 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.21 18:18:56 | 000,116,500 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.21 18:18:56 | 000,103,726 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.21 18:11:59 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.04.21 18:11:38 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.21 18:11:38 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.21 18:11:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.21 18:11:24 | 3220,496,384 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.21 17:45:00 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.04.21 14:25:42 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.21 14:24:09 | 007,734,208 | -H-- | M] (Malwarebytes Corporation                                    ) -- C:\Users\***\Desktop\mbam-setup.exe
[2011.04.17 22:20:57 | 001,100,214 | -H-- | M] () -- C:\Users\***\Desktop\sechs.bmp
[2011.04.16 11:16:29 | 000,021,406 | -H-- | M] () -- C:\Users\***\Desktop\14054343.jpg
[2011.04.16 10:59:53 | 000,069,120 | -H-- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.15 09:38:14 | 010,784,549 | -H-- | M] () -- C:\Users\***\Desktop\räume.wmv
[2011.03.28 20:20:06 | 000,423,924 | -H-- | M] () -- C:\Users\***\Desktop\EKick-off.jpg
[2011.03.23 23:35:48 | 000,045,401 | -H-- | M] () -- C:\Users\***\Desktop\Kurzkonzept.pdf
[2011.03.23 23:35:08 | 000,046,466 | -H-- | M] () -- C:\Users\***\Desktop\Logo.jpg
[2011.03.22 22:47:13 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
 
========== Files Created - No Company Name ==========
 
[2011.04.21 14:25:42 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.17 22:20:57 | 001,100,214 | -H-- | C] () -- C:\Users\***\Desktop\sechs.bmp
[2011.04.16 11:22:26 | 000,021,406 | -H-- | C] () -- C:\Users\***\Desktop\14054343.jpg
[2011.04.15 09:37:57 | 010,784,549 | -H-- | C] () -- C:\Users\***\Desktop\räume.wmv
[2011.03.28 20:20:04 | 000,423,924 | -H-- | C] () -- C:\Users\***\Desktop\EKick-off.jpg
[2011.03.23 23:35:48 | 000,045,401 | -H-- | C] () -- C:\Users\***\Desktop\Kurzkonzept.pdf
[2011.03.23 23:35:07 | 000,046,466 | -H-- | C] () -- C:\Users\***\Desktop\Logo.jpg
[2010.07.26 12:16:03 | 000,000,680 | -H-- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat
[2009.10.31 12:48:05 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2009.10.31 12:48:04 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2009.05.23 10:35:01 | 000,119,479 | ---- | C] () -- C:\Windows\hpqins00.dat
[2008.09.28 18:31:50 | 000,039,095 | ---- | C] () -- C:\Windows\iccsigs.dat
[2008.09.28 18:31:49 | 000,112,688 | ---- | C] () -- C:\Windows\System32\shw32.dll
[2008.09.12 15:01:05 | 000,069,120 | -H-- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.08.12 00:05:14 | 000,000,848 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2008.08.04 23:29:50 | 000,146,217 | ---- | C] () -- C:\Windows\hpoins18.dat.temp
[2008.08.04 23:29:50 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2008.08.04 23:01:36 | 000,145,713 | ---- | C] () -- C:\Windows\hpoins18.dat
[2008.07.10 12:33:47 | 000,000,000 | -H-- | C] () -- C:\Users\***\AppData\Roaming\wklnhst.dat
[2008.06.11 23:20:15 | 000,000,049 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.06.11 23:15:46 | 000,000,000 | ---- | C] () -- C:\Windows\musiceditor.INI
[2008.06.11 22:51:02 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2008.06.11 22:49:35 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2008.06.02 21:31:01 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.05.31 22:46:09 | 000,000,342 | ---- | C] () -- C:\Windows\{9A3BC157-B94F-4EFD-ABA9-1E56DEB00655}_WiseFW.ini
[2007.03.01 01:52:43 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2006.11.02 20:40:12 | 000,174,656 | ---- | C] () -- C:\Windows\System32\PSIService.exe
[2006.11.02 17:33:31 | 000,641,106 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,116,500 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,335,824 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,609,944 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,103,726 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.11.02 09:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2006.11.02 09:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006.08.11 10:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll

< End of report >

--- --- ---

sandra23 21.04.2011 17:50

Es ist ist nur dieser eine Log-File aufgeploppt. Wo finde ich den zweiten?

Vielen vielen Dank für Deine Bemühungen!!!

sandra23 21.04.2011 18:47

Habe den 2. Log-File gefunden:OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 21.04.2011 18:23:21 - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\***\Desktop
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 61,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 303,35 Gb Total Space | 113,21 Gb Free Space | 37,32% Space Free | Partition Type: NTFS
Drive D: | 150,69 Gb Total Space | 147,31 Gb Free Space | 97,75% Space Free | Partition Type: NTFS
 
Computer Name: *** | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1D8C401B-A916-4D59-9A59-A120FDDC4E51}" = lport=139 | protocol=6 | dir=in | app=system |
"{20A6C0A5-01FD-434F-AC08-77CA41EADA42}" = lport=1900 | protocol=17 | dir=in | name=microsoft upnp-port (udp) |
"{3DEBD2E3-482E-4489-80F2-A03BE7A58782}" = lport=2869 | protocol=6 | dir=in | name=microsoft upnp-port (tcp) |
"{4FB05E7A-BE54-4C99-B012-CE9C68A5B62E}" = lport=445 | protocol=6 | dir=in | app=system |
"{593EBE03-E0DF-466C-84DD-EE2C2003F43E}" = lport=137 | protocol=17 | dir=in | app=system |
"{6E82A42E-E06A-432C-927B-C2478672E401}" = rport=138 | protocol=17 | dir=out | app=system |
"{76FD1B4F-675D-471F-9727-DB56C52B565B}" = rport=445 | protocol=6 | dir=out | app=system |
"{7D39CF8E-30C0-4994-BA89-27E2593A2B19}" = lport=138 | protocol=17 | dir=in | app=system |
"{80CA0DAA-1E73-4545-B03A-692AE925189A}" = lport=0 | protocol=6 | dir=in | name=magix upnp media server |
"{A072808F-4EEA-4803-8117-0A6904438E5E}" = lport=2869 | protocol=6 | dir=in | name=microsoft upnp-port (tcp) |
"{B4B7C4FC-3296-4178-86F9-A2B3AB9CE134}" = rport=139 | protocol=6 | dir=out | app=system |
"{C5E86467-EEEE-4FF6-8502-3F5D5C7912E1}" = lport=0 | protocol=6 | dir=in | name=magix upnp media server |
"{D436E7F6-CB75-4F7A-A5A1-2EAEC31377E8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{DED37F74-77A3-4BF3-8E33-5BF0C0265EB6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E7608150-990E-470A-B5FF-7C1DFC8408B4}" = rport=137 | protocol=17 | dir=out | app=system |
"{E8537BBE-403A-476C-A37D-023B81E3E5B4}" = lport=1900 | protocol=17 | dir=in | name=microsoft upnp-port (udp) |
"{E9846C40-A17F-4C82-9946-1C4638381469}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{050524E1-807D-4501-9FB7-666C34ED7A3C}" = protocol=6 | dir=in | app=c:\program files\common files\magix shared\upnpservice\upnpservice.exe |
"{334CC953-7C14-4DD7-ACD6-ABC92B140BF6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4AA4E5A7-070F-4E6C-A2F7-83346AE72D45}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\anno4web.exe |
"{5455D59D-68ED-4823-8550-9F23F6191843}" = protocol=6 | dir=in | app=c:\program files\common files\magix shared\upnpservice\upnpservice.exe |
"{55968F2C-B751-428E-BCD3-192819683E1E}" = protocol=17 | dir=in | app=c:\program files\common files\magix shared\upnpservice\upnpservice.exe |
"{6047FC39-9EA2-4C4F-8639-39AEEAD3155A}" = protocol=17 | dir=in | app=c:\program files\common files\magix shared\upnpservice\upnpservice.exe |
"{77920152-499B-44E4-BA66-D07DF1462F67}" = protocol=6 | dir=in | app=c:\program files\fujitsu siemens computers\fsclounge\fscwbaseupdaterservice\2\fscwbaseupdaterservice.exe |
"{7A03C5AB-D007-4E6B-9924-D052996546D5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7AF2E1E6-F942-4FE6-94EE-A5B72F39726C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7D27C1A4-1DDC-4C83-B2CD-B828C6ACAEB2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{89119B2E-398D-45D5-B926-987199BD05F7}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\anno4web.exe |
"{9C902E33-7928-4133-B715-FEF71A53D5F1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A4517B84-1024-498B-ACAA-C857C5FE2503}" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\anno4.exe |
"{AB8E464E-19E9-4D5F-8F2D-A3DC1205E69C}" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\anno4.exe |
"{AC3725E2-B1D9-4352-AECC-37257226DAE2}" = protocol=17 | dir=in | app=c:\program files\fujitsu siemens computers\fsclounge\fscwbaseupdaterservice\2\fscwbaseupdaterservice.exe |
"{C74096BE-5BF4-464E-BF2A-03E4F127D18E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{D3EB370B-56A1-4847-A35B-B719612291C8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"TCP Query User{2236296A-8425-4832-9D07-86ED9A5ED9C5}C:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe" = protocol=6 | dir=in | app=c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe |
"TCP Query User{22E4A13E-4928-4059-AC2C-86D854BA054A}C:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe |
"TCP Query User{35C69B3D-A8D6-4B5E-94E3-22D8C070AFEA}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{362F3AC9-37C3-436E-B996-CB326D69C164}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{444D999B-D763-41ED-B8A8-E0FB6E47E31B}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{86B72D08-9C94-4A2E-AFAD-54B2A6637940}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{9BAAD689-3A8A-41F3-A2FE-9DF48E72256D}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B684A30E-82F0-4813-8D0E-03A0586D3ADF}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{BA7AB1D6-9B9B-45E8-ADA3-323642E89044}C:\program files\common files\ahead\nero web\setupx.exe" = protocol=6 | dir=in | app=c:\program files\common files\ahead\nero web\setupx.exe |
"TCP Query User{E169985E-EDDD-4A64-8801-03A6959FDCE0}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{E3C1A9D9-8EE9-4992-A234-34CB6190FAA5}C:\program files\ubisoft\related designs\anno 1404\tools\anno4web.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\anno4web.exe |
"TCP Query User{F8DA720D-D953-4257-AED1-52F592B1F6A8}C:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe |
"UDP Query User{21B7A8CE-6EF2-419F-9653-D86C81317646}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{5CCCDA65-884B-40D4-82F8-C40D128F6C12}C:\program files\ubisoft\related designs\anno 1404\tools\anno4web.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\anno4web.exe |
"UDP Query User{7BEA113B-5CD3-445E-960C-EBEEF2C40779}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{858CE71F-82DB-41E5-B77A-CE7077B18B2D}C:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe |
"UDP Query User{8DDADB10-E92A-4314-A4E3-6C855C612F14}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{A59FE4FB-9CEE-4CBF-9897-9F5D0076A5ED}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{AA1D9738-1F1E-4FB6-ACBA-4A512E5A9377}C:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe" = protocol=17 | dir=in | app=c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe |
"UDP Query User{BB02B385-B354-42CE-81BD-76F046C09416}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{ECA9A945-51DC-4F0A-A17A-F60E2E4A4201}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{FAAF0189-9BEF-45BE-85A1-5580FEBEFDF4}C:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\related designs\anno 1404\tools\addonweb.exe |
"UDP Query User{FB45CA9B-27ED-4E08-8FD9-7A7953D1F815}C:\program files\common files\ahead\nero web\setupx.exe" = protocol=17 | dir=in | app=c:\program files\common files\ahead\nero web\setupx.exe |
"UDP Query User{FEF88BFA-BC9B-4466-B9E4-882D4A5D8242}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{0513EE35-E0FB-4166-B663-BD1AE3A803DE}" = Anno 1404
"{0A2A5039-B37F-489D-B1DC-A5258DF9E697}" = FIFA 08
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}" = WD SmartWare
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{282E5AB2-8E47-4571-B6FA-6B512555B557}" = HP Photosmart.All-In-One Driver Software 8.0 .A
"{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}" = SymNet
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{3672B097-EA69-4bfe-B92F-29AE6D9D2B34}" = Norton Internet Security
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}" = ccCommon
"{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}" = ANNO 1404
"{4216D328-0FE8-48B8-85B8-BD300E6F080F}" = Nokia Connectivity Cable Driver
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{48185814-A224-447A-81DA-71BD20580E1B}" = Norton Internet Security
"{4843B611-8FCB-4428-8C23-31D0A5EAE164}" = Norton Confidential Browser Component
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{50D69C54-6963-49A6-B762-A9FF8F56AF0F}" = Brockhaus multimedial 2008
"{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3
"{55FA89BD-21D3-42F7-9249-C94C0094A83C}" = Apple Software Update
"{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}" = Norton Internet Security
"{5D9B17E4-5C34-45B2-9C95-8B9DB4CF7AF3}" = HP_Network_UserGuide
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{81CD6232-10F5-4832-B3DA-1B88B1571031}" = Nero 7 Essentials
"{830D8CBD-C668-49e2-A969-C2C2106332E0}" = Norton AntiVirus
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}" = FirstSteps Diagnostics
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}" = Norton Protection Center
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A3BC157-B94F-4EFD-ABA9-1E56DEB00655}" = FSCLounge
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{A07B2C21-863B-47AB-AE7E-20BB00BD7D33}" = ANNO 1404 - Venedig
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-A81300000003}" = Adobe Reader 8.1.4 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF1C9345-B53D-4110-BFBF-A0DD83AEAB83}" = AIO_CDA_Software
"{B480BD2A-F1BA-4FE6-8C8E-34C6111B72C9}" = ElsterFormular 2007/2008
"{B7C61755-DB48-4003-948F-3D34DB8EAF69}" = MSRedist
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D353CC51-430D-4C6F-9B7E-52003DA1E05A}" = Norton Confidential Web Protection Component
"{D4AEC53C-1720-41D9-B6D7-6A60DE62D444}" = PC Connectivity Solution
"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}" = Symantec Real Time Storage Protection Component
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton Internet Security
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}" = QuickTime
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F38FD0E4-B991-462B-873D-F2115EADD093}" = Nokia PC Suite
"{F4DB525F-A986-4249-B98B-42A8066251CA}" = AV
"{F95F178B-56AD-4fab-87F8-FA81E66C7D68}" = Network
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"6DA48AFDE796708D5A4C9121A83E7617A63A9A15" = Windows-Treiberpaket - Nokia Modem  (10/07/2010 4.6)
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2006
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Alice Software" = Alice Software 4.10.0
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Big Fish Games Center" = Big Fish Games Center (remove only)
"Big Fish Games Sudoku" = Big Fish Games Sudoku (remove only)
"Corel Applications" = Corel Applications
"Cradle of Rome" = Cradle of Rome (remove only)
"E5372C32E8562C76C24DBA6525002B1031495F34" = Windows-Treiberpaket - Nokia Modem  (06/09/2010 7.01.0.8)
"FileZilla Client" = FileZilla Client 3.2.7.1
"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition
"Google Desktop" = Google Desktop
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"ICQToolbar" = ICQ Toolbar
"Inkscape" = Inkscape 0.46
"Live 8.0.1" = Live 8.0.1
"Live 8.2.1" = Live 8.2.1
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Luxor Amun Rising" = Luxor Amun Rising (remove only)
"MAGIX Foto Manager 2007 D" = MAGIX Foto Manager 2007 4.2.0.176 (D)
"MAGIX MP3 Maker 12 D" = MAGIX MP3 Maker 12 8.2.1.238 (D)
"MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D)
"Mahjong Towers Eternity EU" = Mahjong Towers Eternity EU (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mystery Case Files - Prime Suspects" = Mystery Case Files - Prime Suspects (remove only)
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa2" = Picasa 2
"Poker Superstars II" = Poker Superstars II (remove only)
"Shockwave" = Shockwave
"SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}" = Norton Internet Security (Symantec Corporation)
"Virtual Villagers" = Virtual Villagers (remove only)
"WinRAR archiver" = WinRAR
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 09.10.2009 09:21:07 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18813, Zeitstempel
 0x4a6621ae, fehlerhaftes Modul ole32.dll, Version 6.0.6000.20581, Zeitstempel 0x4626d0c3,
 Ausnahmecode 0xc0000005, Fehleroffset 0x00065552,  Prozess-ID 0x1564, Anwendungsstartzeit
 01ca48dbed7a3847.
 
Error - 09.10.2009 13:33:17 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18813, Zeitstempel
 0x4a6621ae, fehlerhaftes Modul Flash10c.ocx, Version 10.0.32.18, Zeitstempel 0x4a613d79,
 Ausnahmecode 0xc0000005, Fehleroffset 0x001579a2,  Prozess-ID 0x1324, Anwendungsstartzeit
 01ca4900e4ba99de.
 
Error - 10.10.2009 08:37:24 | Computer Name = *** | Source = WerSvc | ID = 5007
Description =
 
Error - 10.10.2009 16:52:56 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18813, Zeitstempel
 0x4a6621ae, fehlerhaftes Modul Flash10c.ocx, Version 10.0.32.18, Zeitstempel 0x4a613d79,
 Ausnahmecode 0xc0000005, Fehleroffset 0x001579a2,  Prozess-ID 0x17b4, Anwendungsstartzeit
 01ca49eb754ee39c.
 
Error - 10.10.2009 16:53:09 | Computer Name = *** | Source = WerSvc | ID = 5007
Description =
 
Error - 11.10.2009 05:40:07 | Computer Name = *** | Source = WerSvc | ID = 5007
Description =
 
Error - 11.10.2009 06:02:16 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18813, Zeitstempel
 0x4a6621ae, fehlerhaftes Modul Flash10c.ocx, Version 10.0.32.18, Zeitstempel 0x4a613d79,
 Ausnahmecode 0xc0000005, Fehleroffset 0x001579a2,  Prozess-ID 0x948, Anwendungsstartzeit
 01ca4a5951904507.
 
Error - 11.10.2009 06:02:23 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18813, Zeitstempel
 0x4a6621ae, fehlerhaftes Modul ole32.dll, Version 6.0.6000.20581, Zeitstempel 0x4626d0c3,
 Ausnahmecode 0xc0000005, Fehleroffset 0x00065552,  Prozess-ID 0x948, Anwendungsstartzeit
 01ca4a5951904507.
 
Error - 11.10.2009 10:00:48 | Computer Name = *** | Source = WerSvc | ID = 5007
Description =
 
Error - 11.10.2009 11:24:09 | Computer Name = *** | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18813, Zeitstempel
 0x4a6621ae, fehlerhaftes Modul Flash10c.ocx, Version 10.0.32.18, Zeitstempel 0x4a613d79,
 Ausnahmecode 0xc0000005, Fehleroffset 0x001579a2,  Prozess-ID 0x1218, Anwendungsstartzeit
 01ca4a86d7ce6706.
 
[ System Events ]
Error - 29.03.2011 04:04:56 | Computer Name = *** | Source = Service Control Manager | ID = 7026
Description =
 
Error - 03.04.2011 16:05:11 | Computer Name = *** | Source = DCOM | ID = 10016
Description =
 
Error - 07.04.2011 15:07:19 | Computer Name = *** | Source = Service Control Manager | ID = 7022
Description =
 
Error - 07.04.2011 15:07:19 | Computer Name = *** | Source = Service Control Manager | ID = 7026
Description =
 
Error - 11.04.2011 11:41:13 | Computer Name = *** | Source = DCOM | ID = 10005
Description =
 
Error - 13.04.2011 03:33:35 | Computer Name = *** | Source = Service Control Manager | ID = 7022
Description =
 
Error - 13.04.2011 03:33:35 | Computer Name = *** | Source = Service Control Manager | ID = 7026
Description =
 
Error - 16.04.2011 14:21:39 | Computer Name = *** | Source = DCOM | ID = 10016
Description =
 
Error - 16.04.2011 15:42:54 | Computer Name = *** | Source = Service Control Manager | ID = 7022
Description =
 
Error - 16.04.2011 15:42:58 | Computer Name = *** | Source = Service Control Manager | ID = 7026
Description =
 
 
< End of report >

--- --- ---

cosinus 21.04.2011 18:59

Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.

sandra23 21.04.2011 19:03

Festplatte beschädigt Das System hat mit einem oder mehreren installierten...
 
Nein, bloß der eine!

Nein, nur der eine.

cosinus 21.04.2011 19:15

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

sandra23 22.04.2011 16:02

Hey Arne,

ich habe alles so gemacht. Bei TDSSKiller gab es keine Funde und daher auch keinen Log-File (habe zumindest keinen gefunden). Die Daten sind jetzt auch alle wieder sichtbar, nur der Destop ist noch komplett schwarz (aber das kann ich ja manuell wieder umstellen). Ist das System jetzt wieder komplett Viren/Trojaner frei?! Mache vielleicht nochmal einen Suchlauf mit malewarebytes...

Dir jedenfalls besten Dank! Ist echt ein tolles Forum! Vor allem ist es echt super, dass einem so schnell geholfen wird!!! Frohe Ostern!

:dankeschoen:

cosinus 23.04.2011 14:23

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

sandra23 27.04.2011 21:32

Hey Arne,

sorry, war über Ostern weg und bin jetzt erst wieder zurück. Habe mir CCleaner heruntergeladen und bin auch der Anleitung gefolgt - bis zum Punkt analysieren. Was mich jetzt stutzig macht: CCleaner schlägt mir jetzt solche Sachen wie temporäre Internetdateien und ähnliches zum löschen vor, aber ich soll auch einige Anwendungen wie google earth und ähnliche entfernen. Insgesamt fast 2 Gigabyte. Soll ich das wirklich alles entfernen?

LG,
Sandra

cosinus 28.04.2011 10:06

Ja bitte alles entfernen so wie es in der Anleitung steht! Das sind alles alte temp-Dateien!

sandra23 28.04.2011 20:38

Hier meine Log-Datei von combofix:
Combofix Logfile:
Code:

ComboFix 11-04-28.01 - *** 28.04.2011  21:27:25.1.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6000.0.1252.49.1031.18.3071.1684 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\cofi.exe
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\firststeps\FirstSteps.exe
c:\users\J. Vakalopoulos\Desktop\Setup.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-03-28 bis 2011-04-28  ))))))))))))))))))))))))))))))
.
.
2011-04-28 19:32 . 2011-04-28 19:32        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-04-21 12:26 . 2011-04-21 12:26        --------        d-----w-        c:\users\***\AppData\Roaming\Malwarebytes
2011-04-21 12:25 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-21 12:25 . 2011-04-21 12:25        --------        d-----w-        c:\programdata\Malwarebytes
2011-04-21 12:25 . 2011-04-21 12:25        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-04-21 12:25 . 2010-12-20 16:08        20952        ----a-w-        c:\windows\system32\drivers\mbam.sys
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-22 20:47 . 2009-03-18 08:27        137656        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-02-02 16:11 . 2009-10-03 12:36        222080        ------w-        c:\windows\system32\MpSigStub.exe
2011-04-14 16:40 . 2011-04-28 15:17        142296        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-02-07 1232896]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 533264]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-09-02 13351304]
"PC Suite Tray"="c:\program files\Handy\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
"BrowserChoice"="c:\windows\System32\browserchoice.exe" [2010-02-12 293376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-11-07 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-07 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-07 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-17 4718592]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-07 1831936]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-05-02 366400]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-10-24 107112]
"IS CfgWiz"="c:\program files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe" [2006-10-24 46728]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-10-27 22696]
"recinfo781"="c:\recinfo\RecInfo.exe" [2007-10-23 2764800]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2007-01-02 83568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_12\bin\jusched.exe" [2007-05-02 75520]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-28 281768]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 136176]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\DJing\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
R3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-10-20 202872]
R3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-28 136360]
S2 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler;c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-11-08 194240]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - COMHOST
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
HPService        REG_MULTI_SZ          HPSLPSVC
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2009-12-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 12:21]
.
2011-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 10:14]
.
2011-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 10:14]
.
2011-04-28 c:\windows\Tasks\User_Feed_Synchronization-{E7E0B6B1-1A3B-4C4E-B4C8-551C4C89B1E4}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.prosieben.de/index.php?icqpath=icq
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Öffnen mit WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
Trusted Zone: beatport.com\www
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\j5bzcb3d.default\
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-ICQ - c:\program files\ICQ6\ICQ.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2011-04-28 21:32
Windows 6.0.6000  NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2011-04-28  21:33:34
ComboFix-quarantined-files.txt  2011-04-28 19:33
.
Vor Suchlauf: 21 Verzeichnis(se), 126.720.327.680 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 126.654.779.392 Bytes frei
.
- - End Of File - - EDE6007AEEBE00D8DA26413DFE849E64

--- --- ---

cosinus 28.04.2011 20:56

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.


Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

sandra23 01.05.2011 16:41

Hier ist der Log von GMER:

GMER Logfile:
Code:

GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-05-01 17:35:39
Windows 6.0.6000  Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD5000AAKS-07YGA0 rev.12.01C02
Running: tnswlcqt.exe; Driver: C:\Users\JA316~1.***\AppData\Local\Temp\pwryruod.sys


---- System - GMER 1.0.15 ----

SSDT            86F094C8                                                                                            ZwConnectPort
SSDT            8D4F3678                                                                                            ZwOpenProcess
SSDT            8D4F367D                                                                                            ZwOpenThread

---- Kernel code sections - GMER 1.0.15 ----

.text          ntoskrnl.exe!_alloca_probe + 104                                                                    82455FFC 4 Bytes  [C8, 94, F0, 86] {ENTER 0xf094, 0x86}
.text          ntoskrnl.exe!_alloca_probe + 334                                                                    8245622C 4 Bytes  [78, 36, 4F, 8D]
.text          ntoskrnl.exe!_alloca_probe + 350                                                                    82456248 4 Bytes  [7D, 36, 4F, 8D]
.text          C:\Windows\system32\DRIVERS\nvlddmkm.sys                                                            section is writeable [0x8EC26340, 0x39B137, 0xE8000020]
.text          C:\Windows\system32\DRIVERS\atksgt.sys                                                              section is writeable [0x9EF4D300, 0x3B6D8, 0xE8000020]
.text          C:\Windows\system32\DRIVERS\lirsgt.sys                                                              section is writeable [0x8D775300, 0x1BEE, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!DialogBoxIndirectParamW            7712147A 5 Bytes  JMP 6B61473F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!CreateWindowExW                    77128588 2 Bytes  JMP 6B51DAC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!CreateWindowExW + 3                7712858B 2 Bytes  [3F, F4] {AAS ; HLT }
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!MessageBoxExA                      77135683 5 Bytes  JMP 6B6145A4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!DialogBoxParamA                    77136537 5 Bytes  JMP 6B6146DC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!MessageBoxIndirectW                7713F12B 5 Bytes  JMP 6B614606 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!DialogBoxParamW                    77141217 5 Bytes  JMP 6B445505 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!DialogBoxIndirectParamA            7716296F 5 Bytes  JMP 6B6147A2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!MessageBoxIndirectA                7716FA9F 5 Bytes  JMP 6B614671 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text          C:\Program Files\Internet Explorer\iexplore.exe[5768] USER32.dll!MessageBoxExW                      7716FB99 5 Bytes  JMP 6B614542 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                [73CCFBC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]            [73C9B9AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]      [73C8A31F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]        [73C8CBFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]              [73C88AB2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]    [73C9CF28] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]            [73C87D98] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]              [73C87CFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]              [73C86A64] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]      [73D1C1D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]          [73CA7F56] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]            [73C890CD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                      [73C92179] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                      [73C921A4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                [73C97F1C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                [73C97D3E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3476] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [73CC83D5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\tdx \Device\Tcp                                                                              SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice  \Driver\tdx \Device\Udp                                                                              SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

---- EOF - GMER 1.0.15 ----

--- --- ---

sandra23 01.05.2011 17:18

Hier ist der Log von OSAM:

OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:15:21 on 01.05.2011

OS: Windows Vista Home Premium Edition (Build 6000), 32-bit
Default Browser: Mozilla Corporation Firefox 4.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Computer, Inc." - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"bdeadmin.cpl" - "Borland Software Corporation" - C:\Windows\system32\bdeadmin.cpl
"jpicpl32.cpl" - "Sun Microsystems, Inc." - C:\Windows\system32\jpicpl32.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
"NokiaConnectionManager" - "Nokia" - C:\PROGRA~1\Handy\Nokia\NOKIAP~1\CONNEC~1.CPL
"QuickTime" - "Apple Computer, Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\JA316~1.VAK\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"NAVENG" (NAVENG) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20061106.064\NAVENG.SYS
"NAVEX15" (NAVEX15) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20061106.064\NAVEX15.SYS
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"SPBBCDrv" (SPBBCDrv) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
"SRTSP" (SRTSP) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSP.SYS
"SRTSPL" (SRTSPL) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSPL.SYS
"SRTSPX" (SRTSPX) - "Symantec Corporation" - C:\Windows\System32\Drivers\SRTSPX.SYS
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Symantec Eraser Control driver" (eeCtrl) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
"Symantec Intrusion Prevention Driver" (IDSvix86) - "Symantec Corporation" - C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys
"SymEvent" (SymEvent) - "Symantec Corporation" - C:\Windows\system32\Drivers\SYMEVENT.SYS
"SYMREDRV" (SYMREDRV) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMREDRV.SYS
"SYMTDI" (SYMTDI) - "Symantec Corporation" - C:\Windows\System32\Drivers\SYMTDI.SYS

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} "Nokia Phone Browser" - "Nokia" - C:\Program Files\Handy\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
 "{855F3B16-6D32-4fe6-8A56-BBB695989046}" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.5.0_12" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.5.0_12\bin\npjpi150_12.dll / hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5-windows-i586.cab
{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} "Java Plug-in 1.5.0_12" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.5.0_12" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.5.0_12\bin\npjpi150_12.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10p.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC} "ClsidExtension" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
"ICQ6" - "ICQ, LLC." - C:\Program Files\ICQ6.5\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" - "ICQ" - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
{90222687-F593-4738-B738-FBEE9C7B26DF} "Show Norton Toolbar" - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
{1E8A6170-7264-4D0F-BEAE-D42A53123C75} "{1E8A6170-7264-4D0F-BEAE-D42A53123C75}" - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"HP Digital Imaging Monitor.lnk" - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe  (Shortcut exists | File exists)
"WDDMStatus.lnk" - "WDC" - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe  (Shortcut exists | File exists)
"WDSmartWare.lnk" - "Western Digital" - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"fsc-reg" - "Fujitsu Siemens Computers" - C:\ProgramData\fsc-reg\fscreg.exe 20110427
"PC Suite Tray" - "Nokia" - "C:\Program Files\Handy\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"ccApp" - "Symantec Corporation" - "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
"Google Desktop Search" - "Google" - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"HP Software Update" - "Hewlett-Packard Co." - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"IS CfgWiz" - "Symantec Corporation" - "c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe" /MODULE CfgWiz /GUID {BC8D3EAF-F864-4d4b-AB4D-B3D0C32E2840} /MODE CfgWiz /CMDLINE "REBOOT"
"Malwarebytes' Anti-Malware (reboot)" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"NeroFilterCheck" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"osCheck" - "Symantec Corporation" - "c:\Program Files\Norton Internet Security\osCheck.exe"
"Picasa Media Detector" - "Google Inc." - C:\Program Files\Picasa2\PicasaMediaDetector.exe
"QuickFinder Scheduler" - "Corel Corporation" - "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
"QuickTime Task" - "Apple Computer, Inc." - "C:\Program Files\QuickTime\qttask.exe" -atboottime
"recinfo781" - ? - c:\RecInfo\RecInfo.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PCL hpz3l4pi" - "Hewlett-Packard Company" - C:\Windows\system32\hpz3l4pi.dll
"PCL hpz3l4v2" - "Hewlett-Packard Company" - C:\Windows\system32\hpz3l4v2.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Automatisches LiveUpdate - Scheduler" (Automatisches LiveUpdate - Scheduler) - "Symantec Corporation" - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"COM Host" (comHost) - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\DJing\MAGIX\Common\Database\bin\fbserver.exe
"Fujitsu Siemens Computers Diagnostic Testhandler" (TestHandler) - "Fujitsu Siemens Computers" - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleDesktopManager" (GoogleDesktopManager) - "Google" - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
"HP Network Devices Support" (HPSLPSVC) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"ICQ Service" (ICQ Service) - ? - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
"LiveUpdate" (LiveUpdate) - "Symantec Corporation" - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"ProtexisLicensing" (ProtexisLicensing) - ? - C:\Windows\system32\PSIService.exe
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
"Symantec AppCore Service" (SymAppCore) - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
"Symantec Core LC" (Symantec Core LC) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
"Symantec Event Manager" (ccEvtMgr) - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"Symantec IS Kennwortprüfung" (ISPwdSvc) - "Symantec Corporation" - c:\Program Files\Norton Internet Security\isPwdSvc.exe
"Symantec Lic NetConnect service" (CLTNetCnService) - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"Symantec Settings Manager" (ccSetMgr) - "Symantec Corporation" - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
"UPnPService" (UPnPService) - "Magix AG" - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe
"WD SmartWare Background Service" (WDSmartWareBackgroundService) - "Memeo" - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
"WD SmartWare Drive Manager" (WDDMService) - "WDC" - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

sandra23 01.05.2011 17:26

Hier der Inhalt von MBRcheck:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: (build 6000), 32-bit
Base Board Manufacturer: FUJITSU SIEMENS
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: FUJITSU SIEMENS
System Product Name: G31T-M2
Logical Drives Mask: 0x00000fdc

Kernel Drivers (total 153):
0x82400000 \SystemRoot\system32\ntoskrnl.exe
0x82795000 \SystemRoot\system32\hal.dll
0x806C6000 \SystemRoot\system32\kdcom.dll
0x80666000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8065D000 \SystemRoot\system32\PSHED.dll
0x80655000 \SystemRoot\system32\BOOTVID.dll
0x8061A000 \SystemRoot\system32\CLFS.SYS
0x80539000 \SystemRoot\system32\CI.dll
0x804C8000 \SystemRoot\system32\drivers\Wdf01000.sys
0x804BA000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80477000 \SystemRoot\system32\drivers\acpi.sys
0x8046E000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80466000 \SystemRoot\system32\drivers\msisadrv.sys
0x80441000 \SystemRoot\system32\drivers\pci.sys
0x80432000 \SystemRoot\system32\drivers\volmgr.sys
0x80422000 \SystemRoot\System32\drivers\mountmgr.sys
0x8041B000 \SystemRoot\system32\drivers\intelide.sys
0x8040D000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x82FE7000 \SystemRoot\system32\drivers\nvraid.sys
0x82FC6000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x82F7C000 \SystemRoot\System32\drivers\volmgrx.sys
0x80405000 \SystemRoot\system32\drivers\atapi.sys
0x82F5E000 \SystemRoot\system32\drivers\ataport.SYS
0x82F40000 \SystemRoot\system32\drivers\vsmraid.sys
0x82F00000 \SystemRoot\system32\drivers\storport.sys
0x82ECF000 \SystemRoot\system32\drivers\fltmgr.sys
0x82EBF000 \SystemRoot\system32\drivers\fileinfo.sys
0x82EB6000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x82DB2000 \SystemRoot\system32\drivers\ndis.sys
0x82D87000 \SystemRoot\system32\drivers\msrpc.sys
0x82D4E000 \SystemRoot\system32\drivers\NETIO.SYS
0x82C46000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8AB96000 \SystemRoot\System32\Drivers\ksecdd.sys
0x82C10000 \SystemRoot\system32\drivers\volsnap.sys
0x82C08000 \SystemRoot\System32\Drivers\spldr.sys
0x8AB87000 \SystemRoot\System32\drivers\partmgr.sys
0x8AB78000 \SystemRoot\System32\Drivers\mup.sys
0x8AB53000 \SystemRoot\System32\drivers\ecache.sys
0x8AB42000 \SystemRoot\system32\drivers\disk.sys
0x8AB39000 \SystemRoot\system32\drivers\crcdisk.sys
0x8B805000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8E78B000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8BA84000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8EC26000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8E581000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8B888000 \SystemRoot\System32\drivers\watchdog.sys
0x8B876000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8B859000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x8B84E000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8E544000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8E620000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8BB90000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8E62E000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8E52C000 \SystemRoot\system32\DRIVERS\parport.sys
0x8E512000 \SystemRoot\system32\DRIVERS\serial.sys
0x8B810000 \SystemRoot\system32\DRIVERS\serenum.sys
0x8E4FA000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8E4CF000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8B843000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8E4B8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8B8B8000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8E495000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8A931000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8E482000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8F710000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8B919000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8B92F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8BABC000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8E458000 \SystemRoot\system32\DRIVERS\ks.sys
0x8B985000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8E44B000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8E417000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8BBE0000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8FA11000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8F623000 \SystemRoot\system32\drivers\portcls.sys
0x8EC01000 \SystemRoot\system32\drivers\drmk.sys
0x8E779000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8E700000 \SystemRoot\System32\Drivers\Null.SYS
0x8E707000 \SystemRoot\System32\Drivers\Beep.SYS
0x8E70E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F650000 \SystemRoot\System32\drivers\vga.sys
0x8F5C2000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8BA24000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8BA2C000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8E40C000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8E64A000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8E794000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F4CC000 \SystemRoot\System32\drivers\tcpip.sys
0x8F4B3000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8F49E000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F48A000 \SystemRoot\system32\DRIVERS\smb.sys
0x8F443000 \SystemRoot\system32\drivers\afd.sys
0x8F411000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8F9FB000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8E658000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8F9E8000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F9BC000 \SystemRoot\System32\Drivers\SYMTDI.SYS
0x8F99A000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
0x8B9C0000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8F400000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0x8F95F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8E402000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8F8BD000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x8F8A6000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F880000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8BAB6000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x90330000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8B81A000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8BA14000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x8E7F7000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8BB70000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8BAAC000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8BA0C000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x90229000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x901FF000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x901ED000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x8E770000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x97A00000 \SystemRoot\System32\win32k.sys
0x901E3000 \SystemRoot\System32\drivers\Dxapi.sys
0x8F72E000 \SystemRoot\system32\DRIVERS\monitor.sys
0x97800000 \SystemRoot\System32\TSDDD.dll
0x97810000 \SystemRoot\System32\cdd.dll
0x81AF3000 \SystemRoot\system32\drivers\luafv.sys
0x81ADE000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x8185E000 \SystemRoot\system32\drivers\spsys.sys
0x9A440000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9A8F3000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9A476000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9A840000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9DB27000 \SystemRoot\system32\drivers\HTTP.sys
0x9A825000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9B801000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9DAD3000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9DAB3000 \SystemRoot\system32\drivers\mrxdav.sys
0x9DA55000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9DA1C000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9DA0A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9D9E6000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9D995000 \SystemRoot\System32\DRIVERS\srv.sys
0x8E762000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x9E37D000 \SystemRoot\system32\DRIVERS\atksgt.sys
0x8B904000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0x9E1DF000 \SystemRoot\system32\drivers\peauth.sys
0x9A871000 \SystemRoot\System32\Drivers\secdrv.SYS
0x902D8000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9D814000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x9D802000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x9BB8A000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x9B9DA000 \SystemRoot\System32\Drivers\SYMREDRV.SYS
0xA7EC5000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xA7DBB000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20061106.064\NAVEX15.SYS
0xA7DA9000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20061106.064\NAVENG.SYS
0x77CE0000 \Windows\System32\ntdll.dll

Processes (total 77):
0 System Idle Process
4 System
440 C:\Windows\System32\smss.exe
512 csrss.exe
560 C:\Windows\System32\wininit.exe
572 csrss.exe
608 C:\Windows\System32\services.exe
620 C:\Windows\System32\lsass.exe
632 C:\Windows\System32\lsm.exe
796 C:\Windows\System32\winlogon.exe
824 C:\Windows\System32\svchost.exe
916 C:\Windows\System32\svchost.exe
968 C:\Windows\System32\svchost.exe
1000 C:\Windows\System32\svchost.exe
1032 C:\Windows\System32\svchost.exe
1044 C:\Windows\System32\svchost.exe
1196 C:\Windows\System32\audiodg.exe
1228 C:\Windows\System32\svchost.exe
1244 C:\Windows\System32\SLsvc.exe
1328 C:\Windows\System32\svchost.exe
1500 C:\Windows\System32\svchost.exe
1688 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
1764 C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
1876 C:\Windows\System32\spoolsv.exe
1900 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1912 C:\Windows\System32\svchost.exe
1492 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
1616 C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
1136 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
1156 C:\Windows\System32\svchost.exe
744 C:\Program Files\ICQ6Toolbar\ICQ Service.exe
2140 C:\Windows\System32\svchost.exe
2192 C:\Windows\System32\svchost.exe
2204 C:\Windows\System32\svchost.exe
2220 C:\Windows\System32\PSIService.exe
2276 C:\Windows\System32\svchost.exe
2324 C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
2388 C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
2452 C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
2496 C:\Windows\System32\svchost.exe
2520 C:\Windows\System32\SearchIndexer.exe
2752 WUDFHost.exe
3064 C:\Windows\System32\dwm.exe
3084 C:\Windows\System32\taskeng.exe
3140 C:\Windows\System32\taskeng.exe
3164 C:\Windows\explorer.exe
3196 C:\Program Files\Google\Update\GoogleUpdate.exe
3592 C:\Windows\System32\rundll32.exe
3600 C:\Windows\RtHDVCpl.exe
3620 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
3648 C:\Program Files\Picasa2\PicasaMediaDetector.exe
3704 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
3756 C:\Windows\System32\rundll32.exe
3804 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
3860 C:\Program Files\QuickTime\qttask.exe
3880 C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe
3892 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
3956 C:\Program Files\Windows Sidebar\sidebar.exe
3984 C:\Windows\ehome\ehtray.exe
3992 C:\Program Files\Handy\Nokia\Nokia PC Suite 7\PCSuite.exe
4000 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
4008 C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
4016 C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
4032 C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
3924 C:\Windows\ehome\ehmsas.exe
5384 C:\Windows\System32\svchost.exe
5796 C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
5936 C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
5972 C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
4372 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
4388 C:\Windows\System32\conime.exe
5676 C:\Windows\System32\taskeng.exe
3364 C:\Windows\servicing\TrustedInstaller.exe
2352 C:\Program Files\Mozilla Firefox\firefox.exe
4800 C:\Windows\System32\SearchProtocolHost.exe
4988 C:\Windows\System32\SearchFilterHost.exe
1324 C:\Users\***\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`ee100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000004e`c4400000 (NTFS)

PhysicalDrive0 Model Number: WDCWD5000AAKS-07YGA0, Rev: 12.01C02

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!

sandra23 01.05.2011 17:27

Wie gehts jetzt weiter?

LG,

Sandra

cosinus 01.05.2011 18:54

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

sandra23 01.05.2011 22:00

Hier der Log von Malewarebytes:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Datenbank Version: 6484

Windows 6.0.6000
Internet Explorer 8.0.6001.18904

01.05.2011 22:46:37
mbam-log-2011-05-01 (22-46-37).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 288473
Laufzeit: 58 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Big Fish Games Center (Adware.Dropper.Gen) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\big fish games\uninstall.exe (Adware.Dropper.Gen) -> Quarantined and deleted successfully.

sandra23 02.05.2011 00:18

So, und hier nun das Log von SASW:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 05/02/2011 at 01:09 AM

Application Version : 4.51.1000

Core Rules Database Version : 6966
Trace Rules Database Version: 4778

Scan type : Complete Scan
Total Scan Time : 01:46:13

Memory items scanned : 785
Memory threats detected : 0
Registry items scanned : 9635
Registry threats detected : 0
File items scanned : 141734
File threats detected : 1

Trojan.Agent/Gen-FakeAV
C:\PROGRAM FILES\WINRAR\DEFAULT.SFX

cosinus 02.05.2011 12:10

Sie nur nach Fehlalarmen aus.
Noch Probleme?

sandra23 02.05.2011 14:30

Nö, Probleme habe ich eigentlich keine mehr!
Ich hoffe nur, dass die Festplatte jetzt sauber ist, damit ich meine Daten endlich wieder sichern kann. Ist das jetzt der Fall? :-)

cosinus 02.05.2011 15:16

Dann wären wir durch! :abklatsch:

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update



PDF-Reader aktualisieren
Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst.

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

sandra23 02.05.2011 15:32

Ich danke Dir wirklich vielmals!!!!!!!!! :abklatsch:


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:43 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19