![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Hive Cluster\49600\Megalomon_swarmWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| | #16 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Hive Cluster\49600\Megalomon_swarm Dann beende das mal. Starte Windows danach neu, lösch die alte cofi.exe, lade CF neu als cofi.exe runter und probier es bitte nochmal.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #17 |
![]() | Hive Cluster\49600\Megalomon_swarm Und hier Combofix log:
__________________Combofix Logfile: Code:
ATTFilter ComboFix 11-06-10.09 - Megalomon 11.06.2011 2:40.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4063.2487 [GMT 2:00]
ausgeführt von:: c:\users\Megalomon\Desktop\Cofi.exe
AV: Norton 360 Online *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 Online *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 Online *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Images
c:\users\Megalomon\Documents\mspaint.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-05-11 bis 2011-06-11 ))))))))))))))))))))))))))))))
.
.
2011-06-11 00:48 . 2011-06-11 00:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-06-11 00:48 . 2011-06-11 00:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-10 22:29 . 2011-06-10 22:29 -------- d-----w- C:\Cofi
2011-06-10 16:19 . 2011-06-10 16:19 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-06-09 20:35 . 2011-06-09 20:35 -------- d-----w- C:\_OTL
2011-06-09 10:46 . 2011-06-09 10:46 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Malwarebytes
2011-06-09 10:46 . 2011-05-29 07:11 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-06-09 10:46 . 2011-06-09 10:46 -------- d-----w- c:\programdata\Malwarebytes
2011-06-09 10:46 . 2011-06-09 20:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-06-09 10:46 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-07 17:37 . 2011-06-07 17:37 -------- d-----w- c:\program files (x86)\Microsoft XNA
2011-06-07 17:14 . 2011-06-07 22:35 -------- d-----w- c:\program files (x86)\Terraria
2011-06-06 14:44 . 2011-06-06 14:44 -------- d-----w- c:\program files (x86)\Common Files\EZB Systems
2011-06-06 12:00 . 2011-06-06 14:44 -------- d-----w- c:\program files (x86)\UltraISO
2011-06-06 11:36 . 2011-06-06 11:36 -------- d-----w- c:\program files (x86)\Smart Projects
2011-06-06 11:24 . 2011-06-11 00:26 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Bitcoin
2011-06-06 11:24 . 2011-06-06 11:24 -------- d-----w- c:\program files (x86)\Bitcoin
2011-06-06 08:45 . 2011-05-20 11:49 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-06-06 08:45 . 2011-05-20 11:43 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-06-06 08:45 . 2011-05-20 11:43 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-06-06 08:45 . 2011-05-20 11:43 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-06-06 08:45 . 2011-05-20 11:43 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-06-06 08:44 . 2011-06-06 08:44 -------- d-----w- c:\users\Megalomon\AppData\Roaming\TuneUp Software
2011-06-06 08:44 . 2011-06-06 08:45 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011
2011-06-06 08:43 . 2011-06-06 08:45 -------- d-----w- c:\programdata\TuneUp Software
2011-06-06 08:43 . 2011-06-06 08:43 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-06-05 22:30 . 2011-06-10 22:33 -------- d-----w- c:\programdata\SecTaskMan
2011-06-05 22:30 . 2011-06-05 22:30 -------- d-----w- c:\program files (x86)\Security Task Manager
2011-06-05 12:24 . 2011-06-05 12:25 -------- d-----w- c:\program files (x86)\TweakMe!
2011-06-04 13:14 . 2011-06-04 13:14 -------- d-sh--w- c:\programdata\DSS
2011-06-04 13:12 . 2011-05-19 20:30 446976 ----a-w- c:\program files (x86)\Microsoft Games\Fable III\paul.dll
2011-06-04 13:11 . 2011-06-04 13:11 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Lionhead Studios
2011-06-04 13:08 . 2011-05-17 19:42 79648 ----a-r- c:\program files (x86)\Microsoft Games\Fable III\UPDATE\setup.exe
2011-06-03 15:24 . 2011-06-03 15:24 -------- d-----w- c:\program files (x86)\Lionhead Studios Ltd
2011-06-03 15:11 . 2011-06-03 15:18 -------- d-----w- c:\program files\CCleaner
2011-06-03 12:33 . 2011-06-03 12:33 -------- d-----w- c:\program files (x86)\Visual Basic 6.0 Runtime&Steuerelemente
2011-06-03 12:32 . 2011-06-03 12:32 290816 ------w- c:\windows\Setup1.exe
2011-06-03 12:32 . 2011-06-03 12:32 74752 ----a-w- c:\windows\ST6UNST.EXE
2011-06-02 17:32 . 2011-06-02 17:32 53248 ----a-r- c:\users\Megalomon\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-06-02 17:32 . 2011-06-02 17:32 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Leadertech
2011-06-02 17:32 . 2011-06-02 17:32 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2011-06-02 17:32 . 2011-06-02 17:32 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-06-02 17:31 . 2011-06-02 17:44 -------- d-----w- c:\programdata\Logishrd
2011-06-02 17:31 . 2011-06-02 17:31 -------- d-----w- c:\program files\Logitech
2011-06-02 17:31 . 2011-06-02 17:32 -------- d-----w- c:\program files\Common Files\Logishrd
2011-06-02 17:21 . 2011-06-02 17:44 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Logitech
2011-06-02 17:21 . 2011-06-02 17:21 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Logishrd
2011-06-02 16:44 . 2011-06-02 16:49 -------- d-----w- c:\users\Megalomon\ThingZ
2011-06-02 14:15 . 2011-06-02 14:15 -------- d-----w- c:\program files (x86)\XMedia Recode
2011-06-01 23:52 . 2002-07-19 18:27 122350 ----a-w- c:\windows\system32\xbadpcm.acm
2011-06-01 23:37 . 2011-06-01 23:37 -------- d-----w- c:\program files (x86)\Software4u
2011-05-31 03:36 . 2011-05-31 03:36 -------- d-----w- c:\program files (x86)\MAGIX
2011-05-31 03:36 . 2011-05-31 03:36 -------- d-----w- c:\programdata\MAGIX
2011-05-31 03:36 . 2011-05-31 03:36 -------- d-----w- c:\program files (x86)\Common Files\MAGIX Services
2011-05-30 13:15 . 2009-03-18 15:35 33856 ---ha-w- c:\windows\system32\hamachi.sys
2011-05-30 13:15 . 2011-05-30 13:15 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2011-05-29 19:16 . 2011-05-31 03:37 -------- d-----w- c:\users\Megalomon\AppData\Roaming\MAGIX
2011-05-29 18:17 . 2001-04-12 16:00 182272 ----a-w- c:\windows\patchw32.dll
2011-05-26 10:49 . 2009-07-14 01:41 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\LXKPTPRC.DLL
2011-05-26 09:43 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-26 05:18 . 2011-05-26 05:18 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2011-05-26 05:18 . 2011-05-26 05:18 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-05-26 05:18 . 2011-05-26 05:18 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-05-26 05:18 . 2011-05-26 05:18 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-05-26 05:18 . 2011-05-26 05:18 -------- d-----w- c:\program files (x86)\OpenAL
2011-05-26 05:16 . 2011-05-26 05:18 -------- d-----w- c:\program files (x86)\Penumbra Overture
2011-05-25 15:22 . 2011-05-25 20:19 -------- d-----w- c:\users\Megalomon\.revenge_of_the_titans_1.80
2011-05-25 15:22 . 2011-05-25 15:22 -------- d-----w- c:\program files (x86)\Revenge Of The Titans HIB
2011-05-25 14:34 . 2009-10-27 17:31 3982240 ----a-w- c:\windows\SysWow64\Flash10d.ocx
2011-05-25 14:34 . 2011-05-25 14:34 -------- d-----w- c:\program files (x86)\StreamTransport
2011-05-25 10:22 . 2011-05-25 10:22 -------- d-----w- c:\program files (x86)\Data Realms
2011-05-25 07:47 . 2011-05-25 07:47 -------- d-----w- c:\users\Public\CyberLink
2011-05-25 07:47 . 2011-05-25 07:47 -------- d-----w- c:\users\Megalomon\AppData\Roaming\CyberLink
2011-05-25 06:34 . 2011-05-25 06:35 -------- d-----w- c:\users\Megalomon\AppData\Roaming\Teeworlds
2011-05-24 10:23 . 2011-05-24 10:23 -------- d-----w- c:\program files (x86)\TeamViewer
2011-05-24 10:18 . 2011-05-24 10:18 -------- d-----w- c:\users\Megalomon\AppData\Roaming\TeamViewer
2011-05-24 09:36 . 2011-05-24 10:52 -------- d-----w- c:\users\Megalomon\AppData\Local\Temporary Projects
2011-05-23 13:56 . 2011-05-23 13:56 -------- d-----w- c:\program files (x86)\EA
2011-05-23 13:54 . 2011-05-23 13:54 -------- d-----w- c:\windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2011-05-22 16:40 . 2011-05-22 16:40 -------- d-----w- C:\Sierra
2011-05-19 17:39 . 2011-05-19 17:39 -------- d-----w- c:\programdata\NexonEU
2011-05-19 06:28 . 2011-06-10 13:31 -------- d-----w- C:\Downloads
2011-05-18 14:05 . 2011-05-18 14:06 -------- d-----w- c:\windows\msdownld.tmp
2011-05-18 14:05 . 2011-05-18 14:34 -------- d-----w- c:\program files (x86)\N8
2011-05-16 12:59 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-05-16 12:59 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2011-05-15 20:41 . 2011-05-15 20:41 -------- d-----w- c:\programdata\CanonBJ
2011-05-15 20:41 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL
2011-05-15 02:18 . 2011-05-15 02:18 -------- d-----w- c:\program files (x86)\Croteam
2011-05-13 06:09 . 2011-05-15 21:02 -------- d-----w- c:\users\Megalomon\AppData\Local\ElevatedDiagnostics
2011-05-12 10:24 . 2011-04-09 07:02 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 10:24 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-05-12 10:24 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-05-12 10:24 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 10:24 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 10:24 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 10:24 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 10:24 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 10:24 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 08:49 . 2011-06-07 17:30 -------- d-----w- c:\users\Megalomon\AppData\Local\CrashDumps
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-19 13:17 . 2011-05-01 07:24 235 ----a-w- c:\windows\SysWow64\nxEuUninstall.bat
2011-05-19 13:17 . 2011-05-01 07:24 446464 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2011-05-12 07:15 . 2011-04-30 09:45 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-05-06 19:50 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-05-06 19:50 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-04-30 10:00 . 2011-04-30 10:01 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-04-30 03:39 . 2011-04-30 03:39 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-30 03:39 . 2011-04-30 03:39 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-30 03:39 . 2011-04-30 03:39 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-04-30 03:39 . 2011-04-30 03:39 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-04-30 03:39 . 2011-04-30 03:39 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-04-30 03:39 . 2011-04-30 03:39 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-04-30 03:39 . 2011-04-30 03:39 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-04-30 03:39 . 2011-04-30 03:39 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-04-30 03:39 . 2011-04-30 03:39 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-04-30 03:39 . 2011-04-30 03:39 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-04-30 03:39 . 2011-04-30 03:39 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-04-30 03:39 . 2011-04-30 03:39 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-04-30 03:39 . 2011-04-30 03:39 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-30 03:39 . 2011-04-30 03:39 448512 ----a-w- c:\windows\system32\html.iec
2011-04-30 03:39 . 2011-04-30 03:39 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-04-30 03:39 . 2011-04-30 03:39 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-04-30 03:39 . 2011-04-30 03:39 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-04-30 03:39 . 2011-04-30 03:39 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-30 03:39 . 2011-04-30 03:39 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-04-30 03:39 . 2011-04-30 03:39 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-30 03:39 . 2011-04-30 03:39 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-04-30 03:39 . 2011-04-30 03:39 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-04-30 03:39 . 2011-04-30 03:39 222208 ----a-w- c:\windows\system32\msls31.dll
2011-04-30 03:39 . 2011-04-30 03:39 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-04-30 03:39 . 2011-04-30 03:39 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-30 03:39 . 2011-04-30 03:39 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-04-30 03:39 . 2011-04-30 03:39 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-04-30 03:39 . 2011-04-30 03:39 160256 ----a-w- c:\windows\system32\wextract.exe
2011-04-30 03:39 . 2011-04-30 03:39 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-04-30 03:39 . 2011-04-30 03:39 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-04-30 03:39 . 2011-04-30 03:39 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-30 03:39 . 2011-04-30 03:39 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-04-30 03:39 . 2011-04-30 03:39 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-04-30 03:39 . 2011-04-30 03:39 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-04-30 03:39 . 2011-04-30 03:39 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-30 03:39 . 2011-04-30 03:39 12288 ----a-w- c:\windows\system32\mshta.exe
2011-04-30 03:39 . 2011-04-30 03:39 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-04-30 03:39 . 2011-04-30 03:39 114176 ----a-w- c:\windows\system32\admparse.dll
2011-04-30 03:39 . 2011-04-30 03:39 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-04-30 03:39 . 2011-04-30 03:39 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-30 03:39 . 2011-04-30 03:39 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-04-30 03:39 . 2011-04-30 03:39 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-30 03:07 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-30 03:07 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-04-30 01:37 . 2009-11-07 20:54 588472 ----a-w- c:\windows\SysWow64\ezsvc7x.dll
2011-04-18 07:15 . 2011-04-30 02:00 8802128 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B0804166-B8DE-46CB-A80C-C36F9FC4C858}\mpengine.dll
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2011-04-08 05:14 . 2011-04-30 09:31 8411752 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-04-08 05:14 . 2011-04-30 09:31 6974056 ----a-w- c:\windows\system32\nvcuda.dll
2011-04-08 05:14 . 2011-04-30 09:31 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-04-08 05:14 . 2011-04-30 09:31 6299752 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-04-08 05:14 . 2011-04-30 09:31 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-04-08 05:14 . 2011-04-30 09:31 5183080 ----a-w- c:\windows\SysWow64\nvcuda.dll
2011-04-08 05:14 . 2011-04-30 09:31 2893416 ----a-w- c:\windows\system32\nvcuvid.dll
2011-04-08 05:14 . 2011-04-30 09:31 2765928 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2011-04-08 05:14 . 2011-04-30 09:31 2273896 ----a-w- c:\windows\system32\nvapi64.dll
2011-04-08 05:14 . 2011-04-30 09:31 2204264 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-04-08 05:14 . 2011-04-30 09:31 2074216 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2011-04-08 05:14 . 2011-04-30 09:31 20700264 ----a-w- c:\windows\system32\nvoglv64.dll
2011-04-08 05:14 . 2011-04-30 09:31 2034280 ----a-w- c:\windows\SysWow64\nvapi.dll
2011-04-08 05:14 . 2011-04-30 09:31 18578536 ----a-w- c:\windows\system32\nvcompiler.dll
2011-04-08 05:14 . 2011-04-30 09:31 1619048 ----a-w- c:\windows\system32\nvdispco6420140.dll
2011-04-08 05:14 . 2011-04-30 09:31 15227496 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2011-04-08 05:14 . 2011-04-30 09:31 1404008 ----a-w- c:\windows\system32\nvgenco642060.dll
2011-04-08 05:14 . 2011-04-30 09:31 13262184 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-04-08 05:14 . 2011-04-30 09:31 13007464 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2011-04-08 05:14 . 2011-04-30 09:31 12934248 ----a-w- c:\windows\system32\nvd3dumx.dll
2011-04-08 05:14 . 2011-04-30 09:31 10071656 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2011-04-07 21:19 . 2011-04-07 21:19 61032 ----a-w- c:\windows\system32\nvshext.dll
2011-04-07 21:19 . 2011-04-07 21:19 318056 ----a-w- c:\windows\system32\nvhotkey.dll
2011-04-07 21:19 . 2011-04-07 21:19 2582120 ----a-w- c:\windows\system32\nvsvcr.dll
2011-04-07 21:19 . 2011-04-07 21:19 117864 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-07 21:19 . 2011-04-07 21:19 1012328 ----a-w- c:\windows\system32\nvvsvc.exe
2011-04-07 21:19 . 2011-04-07 21:19 797288 ----a-w- c:\windows\system32\easyUpdatusAPIU64.dll
2011-04-07 21:19 . 2011-04-07 21:19 6338152 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-07 21:18 . 2011-04-07 21:18 3041384 ----a-w- c:\windows\system32\nvsvc64.dll
2011-04-06 14:26 . 2011-04-06 14:26 96544 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 14:26 . 2011-04-06 14:26 69408 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 14:26 . 2011-04-06 14:26 237856 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 14:26 . 2011-04-06 14:26 119584 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-03-31 03:00 . 2011-05-10 06:36 744568 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\srtsp64.sys
2011-03-31 03:00 . 2011-05-10 06:36 40568 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\srtspx64.sys
2011-03-22 00:39 . 2011-05-10 06:36 382584 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\symnets.sys
2011-03-15 02:31 . 2011-05-10 06:36 912504 ----a-w- c:\windows\system32\drivers\N360x64\0501000.01D\symefa64.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-28 843072]
"iTeleportConnect"="c:\program files (x86)\iTeleport\iTeleport Connect\iTeleportConnect.exe" [2011-04-11 1989120]
"ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 89600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"iTeleportService"="c:\program files (x86)\iTeleport\iTeleport Connect\iTeleportService.exe" [2011-04-11 20480]
.
c:\users\Megalomon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
BatteryBar.lnk - c:\program files\BatteryBar\BatteryBar.exe [N/A]
Bitcoin.lnk - c:\program files (x86)\Bitcoin\bitcoin.exe [2011-4-27 7490048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"LogMeIn Hamachi Ui"=-"c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 DAUpdaterSvc;Dragon Age: Origins - Inhaltsupdater;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 NETw1v64;Intel(R) Wireless WiFi Link 1000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw1v64.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110519.002\BHDrvx64.sys [2011-05-19 1143416]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110604.001\IDSvia64.sys [2011-06-03 488056]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\0501000.01D\SYMNETS.SYS [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
S2 iTeleportService;iTeleportService;c:\program files (x86)\iTeleport\iTeleport Connect\iTeleportService.exe [2011-04-11 20480]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 NetBalancer Windows Service;NetBalancer Windows Service;c:\program files\NetBalancer\SeriousBit.NetBalancer.Service.exe [2010-11-22 10240]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-05-20 2026304]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-10 136824]
S3 Nbdrv;NetBalancer Service;c:\windows\system32\DRIVERS\nbdrv.sys [x]
S3 NETw5s64;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-04-26 11856]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2011-06-09 c:\windows\Tasks\HPCeeScheduleForMegalomon.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 03:22]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-05-13 487424]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Megalomon\AppData\Roaming\Mozilla\Firefox\Profiles\vem6yn1k.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-QlbCtrl.exe - -c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\xampp\mysql\bin\mysqld.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
c:\program files\NORTON 360\ENGINE\5.1.0.29\cltLMH.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-06-11 03:06:25 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2011-06-11 01:06
.
Vor Suchlauf: 27 Verzeichnis(se), 108.097.830.912 Bytes frei
Nach Suchlauf: 33 Verzeichnis(se), 107.947.724.800 Bytes frei
.
- - End Of File - - 009DB80BEF683B6FF28E1A447236829A
Ich bin grad etwas verwirrt, wieso wurde mspaint und der images ordner gelöscht? |
| | #18 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Hive Cluster\49600\Megalomon_swarm Downloade Dir bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________
__________________ |
| | #19 | |
![]() | Hive Cluster\49600\Megalomon_swarm Scan lief ohne Probleme. Zitat:
|
| | #20 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Hive Cluster\49600\Megalomon_swarm Wir sollten den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten. Hast Du noch andere Betriebssysteme außer Win7 (64-Bit) installiert? Wenn nicht: Schau mal hier => RescueDisc-Win7-64-Bit Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten) Falls Du eine normale Win7-Installations-DVD (64-Bit) hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten. Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #21 |
![]() | Hive Cluster\49600\Megalomon_swarm Ich hätte sone DVD-Sammlung von HP zu der ich aufgefordert wurde diese zu brennen nachdem ich das Laptop das erste mal in betrieb genommen habe. Es sind 4 DVD's. Sind wohl dafür da, falls die recovery-partition nen schaden hat. Könnte einen von denen auch gehen? |
| | #22 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Hive Cluster\49600\Megalomon_swarm Nein, nimm lieber die ISO und brenn es.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #23 | |
![]() | Hive Cluster\49600\Megalomon_swarm Beides Problemlos verlaufen: MBRCheck: Zitat:
GMER Logfile: Code:
ATTFilter GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-06-12 00:30:15
Windows 6.1.7601 Service Pack 1
Running: 1208ky31.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4D 0x54 0x5E 0x06 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0xC2 0x0F 0x9E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x61 0x65 0x23 0xC5 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDA 0x0A 0x48 0xAC ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x79 0x7D 0x0A 0x41 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0x57 0x56 0x05 0x6A ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4D 0x54 0x5E 0x06 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0xC2 0x0F 0x9E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x61 0x65 0x23 0xC5 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDA 0x0A 0x48 0xAC ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x79 0x7D 0x0A 0x41 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0x57 0x56 0x05 0x6A ...
---- EOF - GMER 1.0.15 ----
|
| | #24 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Hive Cluster\49600\Megalomon_swarm Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SUPERAntiSpyware und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #25 |
![]() | Hive Cluster\49600\Megalomon_swarm Die Explorer.exe stürzt leider immernoch von Zeit zu Zeit ab. |
![]() |
| Themen zu Hive Cluster\49600\Megalomon_swarm |
| aller dateien, allgemeine, allgemeinen, andere, anderen, appdata, befinden, besondere, bewusst, cluster, dateien, frage, inhalt, installier, installierte, ordner, programm, punkt, roaming, servus, suche, unterverzeichnis, users, warscheinlich, winrar, zuordnen |