Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: CMD öffnet sich bei Systemstart kurz.

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 22.05.2012, 14:27   #16
fafel
 
CMD öffnet sich bei Systemstart kurz. - Standard

CMD öffnet sich bei Systemstart kurz.



OTL Extras-Logfile:

Code:
ATTFilter
OTL Extras logfile created on: 22.05.2012 15:01:06 - Run 1
OTL by OldTimer - Version 3.2.43.1     Folder = C:\Users\Kevin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,66 Gb Available Physical Memory | 66,44% Memory free
8,00 Gb Paging File | 6,14 Gb Available in Paging File | 76,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 221,50 Gb Free Space | 47,57% Space Free | Partition Type: NTFS
 
Computer Name: FAFEL-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-3474171957-944776419-1613854139-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00C7181C-D537-4137-9484-72CA592E4041}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{010AFC5F-E3E3-4BE0-85F6-77591ED1FE06}" = rport=445 | protocol=6 | dir=out | app=system | 
"{01A74C5F-BA2E-4C98-9193-8E81125692EB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{13C37DC7-AE5B-4FEA-AF25-2C51B076F5D7}" = lport=137 | protocol=17 | dir=in | app=system | 
"{29294F8F-D8F7-40C5-96D2-502B13A0AD0E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{2EFB87BA-8749-4B21-889D-C7DB0018E7C7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{2F2D0A05-0B5C-4916-BE71-E6B81A0CE14C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{3481874A-5070-4A12-9D10-6D77E6383F9E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{42ED0C6A-C49C-4E64-8AE4-BB75D27594A5}" = lport=445 | protocol=6 | dir=in | app=system | 
"{75697D30-D120-427B-854C-DE4482152A6B}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{8BA64F27-4008-4D65-A4D1-A8A4A4A45622}" = lport=139 | protocol=6 | dir=in | app=system | 
"{9BA1B9C2-C2D8-4E1D-9583-5B8B30F33F79}" = rport=137 | protocol=17 | dir=out | app=system | 
"{9CC8D299-4DE3-4716-8023-2EC2B9EF2F52}" = lport=138 | protocol=17 | dir=in | app=system | 
"{9F327FCA-79E1-4859-B51B-0CD65AC7D027}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{A3971B67-4F74-4C03-8CFB-DAB38058B3AF}" = rport=139 | protocol=6 | dir=out | app=system | 
"{ABD209E9-5680-4C4A-881F-40F66E27EDC9}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | 
"{AD29853F-DA8C-4483-A5A3-70C1D117D644}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B96365A9-048A-4542-87E2-C03946FDEE2B}" = rport=138 | protocol=17 | dir=out | app=system | 
"{C58B2FA5-9038-4CFC-8DC2-EB58E7F96B0A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{DD7DD600-383B-4D49-9755-A70BC200FA87}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{F4649CA2-BECA-4F80-A133-0A7584417448}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{FF89C52D-3515-484E-8CE8-7205D711DB4D}" = rport=10243 | protocol=6 | dir=out | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05F6E50B-7615-4C70-84FB-76DF79F44A3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe | 
"{0629DB25-7C4F-4217-B540-E1C6223EA49E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{08AAC1B5-A74E-4466-BCCA-57551CED750C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{092FF1BC-EB2B-4B21-B8B6-2A782928240D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{0C26DF0E-AFFD-4459-A567-B99746B08D9E}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{110C1AEF-8C6D-41B0-912C-8EDA78DFE8B0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{12D88572-0E60-4996-AB0E-28A0EF7C00F5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sniper elite v2\bin\sniperelitev2.exe | 
"{1C2C502C-0C40-4A0F-A2F7-C002A7A744DD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{2050EAB1-A8D6-4846-9D42-7315A834E357}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{360B5699-CB6A-4046-9FD7-45C9FA5153FC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{38EAD140-79AE-4465-99C5-B15905605A48}" = protocol=6 | dir=in | app=c:\program files (x86)\searchresults1\dtuser.exe | 
"{3974A5B0-D920-478B-930F-3B5107EFD708}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{4316D412-922D-47C7-AAA7-31F26EA171F9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{48871961-477A-4054-B7D6-08530DD809E5}" = protocol=58 | dir=in | app=system | 
"{4B231EAE-7E74-46E2-9E39-2F381F4BC9C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{4B3FC7A1-353A-4627-9602-B876AF0CEC26}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{4F26D11E-87D4-4CF0-8F11-F831B9161C1B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{5446EFE1-C110-418C-BE2C-EDDFE7248F38}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | 
"{56AF61F4-3ACB-4146-84CD-1C368E5F1D9D}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | 
"{57C51AF0-A916-46B4-93A7-407C35FF90FC}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | 
"{588926AE-C3AD-49F8-9393-E1F110652367}" = protocol=6 | dir=out | app=system | 
"{5B467939-1908-447F-AC99-3DA4C76D6D1A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{5F4C60ED-839B-4C34-BECE-8E99338CE74C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\kevinfaf\garrysmod\hl2.exe | 
"{685E8571-3059-48F2-96A9-E233EBE18CF2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{6B6FD037-4974-4775-994A-F9D7DDBDD761}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{71D1D320-9D16-4E67-8B25-3B7C3E932E92}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | 
"{7DFC3388-E9E4-465B-8F35-CCF45CBB2321}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{7FA50A35-B9FA-4002-A77C-52FEF3358C31}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\kevinfaf\garrysmod\hl2.exe | 
"{81719653-516B-4C29-B6F8-D0B751FFF989}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{848DFF9F-829A-4C5B-AFBA-2B543860F4A1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{868D41E2-F87A-4127-A05D-7AF666A8C59C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{8715418F-7F41-4316-AFB7-804C1701985E}" = protocol=17 | dir=in | app=c:\program files (x86)\searchresults1\dtuser.exe | 
"{8B1E706A-C072-40F6-8836-4065AE230AA4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{8DD696FB-6618-4572-9C48-15F7B771F3C7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\halo 2\halo2.exe | 
"{9B06B13D-5596-43C7-911C-95164BE66B05}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\halo 2\halo2.exe | 
"{A4B4021E-CDBB-423A-92E6-205CAA0F595F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{A5D8E656-5065-43F5-8F61-AF30F9FA809D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{AC1BC0E6-7018-4115-80EE-D09F96ACCC49}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{B1D74777-CD8D-4CA7-BC12-32266AC8BB88}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | 
"{B8AA081A-3BF0-4157-BB37-BB039E4D21D4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{B93B5FAF-C750-4544-A9EE-CA9A1907C335}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{C07D473C-6859-4F03-8F6E-1396E223EF2C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{C6199960-8BAF-41D1-A628-B41F1A8C4AB6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{C7BE8222-D40F-40C8-B7C9-463545336C9D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{C9555B2C-CE8C-4A50-82E1-92F42A083133}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe | 
"{D10ABBB6-A255-457E-96AD-87A42E803EB5}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D5ADDD38-00E8-4AA6-B7B9-11006458748A}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | 
"{D5D719A8-D17A-4EE4-B09C-A386FE68E353}" = dir=in | app=c:\brickforce\brickforce.exe | 
"{D61BA247-3CDB-4FDE-9971-7F2CA851D3B9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sniper elite v2\bin\sniperelitev2.exe | 
"{DB5618FF-BBDD-42D2-A7C8-0E4EBF989C13}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | 
"{E6009570-57A7-4F4D-84CA-30F884C4CF79}" = dir=in | app=c:\brickforce\bflauncher.exe | 
"{E973E8DB-5373-4877-8CF2-155CFA67F7FE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{EFF9F2A9-1508-406C-8D59-43A22D6A8600}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{F978BBAB-9903-482D-BC93-E16A29458B7E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CC4F67D-D41D-8C1A-C605-39154DDEAC63}" = AMD Fuel
"{119B2F5A-2A06-DB96-FF28-992EC2A10BDF}" = AMD Accelerated Video Transcoding
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{251481E4-723F-492F-F5C1-3424FB2EF44E}" = AMD Drag and Drop Transcoding
"{26A24AE4-039D-4CA4-87B4-2F86416031FF}" = Java(TM) 6 Update 31 (64-bit)
"{26A24AE4-039D-4CA4-87B4-2F86417003FF}" = Java(TM) 7 Update 3 (64-bit)
"{2E8D6204-D656-8355-1ED3-2988AC52EB0F}" = ccc-utility64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5831C6D6-309D-DBB5-14F7-FEE57086CEE7}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{63CE6C32-1EB3-4C51-89FC-9FD96A661A9C}" = AMD Media Foundation Decoders
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"{DA2737A4-B639-96F4-1CC2-30D2919EE1FB}" = AMD Steady Video Plug-In 
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"NVIDIA Drivers" = NVIDIA Drivers
"PDF-XChange 3_is1" = PDF-XChange 3
"WinRAR archiver" = WinRAR 4.11 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D4C700-2BFE-43E0-A0B4-9512B43C5B9F}" = Catalyst Control Center - Branding
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2(TM)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0CA38F52-F0FA-4B9F-8A36-EC8A9609FBBC}" = Halo 2 for Windows Vista
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{19D614EB-D62A-AEE7-2391-E74126601D59}" = CCC Help Italian
"{1C373820-B9C8-0F7F-8F84-FC1B76A85F27}" = CCC Help Portuguese
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20B1B020-DEAE-48D1-9960-D4C3185D758B}" = Phase 5 HTML-Editor
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{2775C25A-DF39-44AA-8E59-E0447DC164C2}" = Call of Duty - World at War
"{2D35BC33-7D08-D529-DF91-8A15FBF2600E}" = CCC Help Polish
"{337788D1-43D1-9A0F-9787-DD00DB512D41}" = Catalyst Control Center Localization All
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"{4725833D-4325-5C34-57D4-1FE23E5AE578}" = CCC Help Chinese Standard
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B271648-43CB-DD31-FF24-E7B06D3EE72A}" = Catalyst Control Center InstallProxy
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4DC37F33-7AEC-A4CB-56B1-69A402828763}" = CCC Help Japanese
"{5710DAC2-8F2A-503C-CFC2-A973ADE0EA4C}" = CCC Help Czech
"{5C763682-4C40-86DA-9C46-31924D7D2C34}" = CCC Help Thai
"{60E5022D-FA4B-C6A2-1E80-B46EC39096F3}" = CCC Help Chinese Traditional
"{60F34FDF-267C-408F-290E-EC90D841C8CB}" = CCC Help German
"{66B79AE1-C6E2-B958-689C-D0812DE86BAB}" = CCC Help Greek
"{6B39BE0F-0F5E-A8FA-33E4-8481AE39D96C}" = CCC Help Russian
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8E19F2AF-7145-51DE-E395-7729A9374973}" = Catalyst Control Center Graphics Previews Common
"{924FBAC4-60D2-7981-3C3E-979DF9CBB346}" = CCC Help Finnish
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DC939DC-B7A4-D0E2-C582-A442DF1B3EBE}" = CCC Help Spanish
"{A1BD938B-F006-6E6D-70B2-47E1DD56F7DE}" = CCC Help Swedish
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{BABF7852-C2DD-6A8A-9956-101720C715C7}" = CCC Help Turkish
"{BB7C2A56-9706-43B8-5A8C-210AF5816106}" = CCC Help French
"{CFC2CB60-5654-05A7-4D30-C661800A3A92}" = CCC Help Korean
"{D04CE005-D1D2-80F3-84C8-B3524FCD39C3}" = CCC Help Norwegian
"{D544AE4C-4152-225B-A897-6756C8986B14}" = AMD VISION Engine Control Center
"{D81E9069-3CCC-4405-3751-71E4AFEACC52}" = CCC Help Hungarian
"{E2494AD8-314D-44F8-B39C-4358A60DC184}" = LogMeIn Hamachi
"{E93FF166-DF14-2537-8FB4-96BB5810A96C}" = CCC Help Danish
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{FA9827E1-8A8E-C176-4923-0840A67ED4DE}" = CCC Help Dutch
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe AIR" = Adobe AIR
"BF2ALL64" = BF2ALL64
"BrickForce" = BrickForce 1.4.40
"Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2(CREATED BY XEONKING©)
"Call of Duty: Black Ops_is1" = Call of Duty: Black Ops
"DAEMON Tools Lite" = DAEMON Tools Lite
"DivX Setup" = DivX-Setup
"ESET Online Scanner" = ESET Online Scanner v3
"FileZilla Client" = FileZilla Client 3.5.3
"Halo 2" = Halo 2 for Windows Vista
"HotspotShield" = Hotspot Shield 2.53
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"Mozilla Thunderbird 10.0.2 (x86 de)" = Mozilla Thunderbird 10.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NSIS" = Nullsoft Install System
"Origin" = Origin
"Panzers2_is1" = Codename: Panzers - Faza 2
"PunkBusterSvc" = PunkBuster Services
"Samsung CLP-320 Series" = Wartung Samsung CLP-320 Series
"searchresults1" = Search Results Toolbar
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 400" = Portal
"Steam App 4000" = Garry's Mod
"Steam App 42680" = Call of Duty: Modern Warfare 3
"Steam App 42690" = Call of Duty: Modern Warfare 3 - Multiplayer
"Steam App 440" = Team Fortress 2
"Steam App 63380" = Sniper Elite V2
"Sudden Strike 3" = Sudden Strike 3
"VLC media player" = VLC media player 2.0.1
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >
         

Alt 22.05.2012, 18:18   #17
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
CMD öffnet sich bei Systemstart kurz. - Standard

CMD öffnet sich bei Systemstart kurz.



Zitat:
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
Deswegen hier öffnet sich die cmd.exe => schwarze Konsole
Scheint ein legitimer Eintrag von AMD zu sein
Und Schädlinge haben wir nicht gefunden
__________________

__________________

Alt 22.05.2012, 21:29   #18
fafel
 
CMD öffnet sich bei Systemstart kurz. - Standard

CMD öffnet sich bei Systemstart kurz.



Ok vielen Dank für die schnelle Hilfe.

Wie gesagt, war wegen dem "Angriff" auf mein Facebook Konto misstrauisch.
__________________

Antwort

Themen zu CMD öffnet sich bei Systemstart kurz.
acrobat update, call of duty, cmd, cmd-fenster, freue, home, home premium, hotspot, hotspot shield, meldung, plug-in, premium, search results toolbar, systems, systemstart, troja, trojaner, vermute, weiterhelfen, windows, windows 7, windows 7 home, windows 7 home premium, öffnet




Ähnliche Themen: CMD öffnet sich bei Systemstart kurz.


  1. Bei Systemstart und bei eingabe via Ausführen öffnet sich der Browser und ein bestimmter Link
    Plagegeister aller Art und deren Bekämpfung - 17.08.2015 (1)
  2. Win7 : Dos-Fenster öffnet sich ganz kurz
    Log-Analyse und Auswertung - 27.07.2015 (11)
  3. Ab und zu öffnet sich bei Systemstart eine Site: Malaha.net
    Log-Analyse und Auswertung - 28.03.2015 (9)
  4. Windows 7 (64bit) Farmaster.net öffnet sich nach Systemstart
    Log-Analyse und Auswertung - 25.09.2014 (11)
  5. cmd.exe bzw. Eingabeaufforderung öffnet sich nicht/nur kurz!
    Plagegeister aller Art und deren Bekämpfung - 11.02.2014 (11)
  6. Windows Vista: SoftwareUpdater.Ui.exe öffnet sich bei jedem Systemstart
    Plagegeister aller Art und deren Bekämpfung - 20.10.2013 (9)
  7. Softwareupdater.ui.exe öffnet sich bei jedem Systemstart
    Plagegeister aller Art und deren Bekämpfung - 28.06.2013 (16)
  8. -Internet Seite öffnet sich selbsständig nach Systemstart-
    Log-Analyse und Auswertung - 16.04.2013 (1)
  9. cmd.exe öffnet sich für eine kurze Zeit beim Systemstart
    Log-Analyse und Auswertung - 26.07.2012 (1)
  10. CMD Fenster öffnet sich nach pc start ganz kurz. Virus?
    Plagegeister aller Art und deren Bekämpfung - 06.03.2012 (18)
  11. Brennerlaufwerk öffnet sich bei Systemstart - pls LOG-Analyse
    Log-Analyse und Auswertung - 02.10.2011 (1)
  12. Beim Start öffnet sich immer kurz ein scwarzes fenster + Opera öffnet immer eine Seite
    Log-Analyse und Auswertung - 06.06.2011 (10)
  13. nach Systemstart öffnet sich Firefox und zeigt Werbung
    Plagegeister aller Art und deren Bekämpfung - 26.11.2010 (11)
  14. Programme starten nicht, nur eine Shell öffnet sich kurz
    Plagegeister aller Art und deren Bekämpfung - 02.04.2009 (25)
  15. JAVA/BlackBox.AA.2/dos-fenster öffnet sich kurz
    Plagegeister aller Art und deren Bekämpfung - 18.12.2007 (6)
  16. unbekannter task öffnet sich kurz in taskleiste
    Plagegeister aller Art und deren Bekämpfung - 17.05.2006 (6)
  17. unbekannter task öffnet sich kurz in taskleiste
    Log-Analyse und Auswertung - 12.05.2006 (1)

Zum Thema CMD öffnet sich bei Systemstart kurz. - OTL Extras-Logfile: Code: Alles auswählen Aufklappen ATTFilter OTL Extras logfile created on: 22.05.2012 15:01:06 - Run 1 OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Kevin\Downloads 64bit- Home Premium Edition - CMD öffnet sich bei Systemstart kurz....
Archiv
Du betrachtest: CMD öffnet sich bei Systemstart kurz. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.