Hallöchen
Leider bin ich schon wieder hier. Ich hatte vor ca. 2 Wochen schon das Problem und aus lauter Dummheit, nachdem der PC wieder funktionierte, unter
http://www.trojaner-board.de/137677-...-erwischt.html nicht weitergelesen...
Ich habe immer noch Win7 64 bit und wieder einen Scan laufen lassen:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 (ATTENTION: FRST version is 19 days old)
Ran by SYSTEM on 23-07-2013 22:38:43
Running from L:\
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [7560296 2011-12-12] (Realtek Semiconductor)
HKLM\...\Run: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" [415816 2010-08-03] (Logitech Inc.)
HKLM\...\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2412616 2010-08-03] (Logitech Inc.)
HKLM\...\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE [4725320 2010-08-03] (Logitech Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35768 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291608 2012-01-04] (Intel Corporation)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup [336992 2012-12-09] (Power Software Ltd)
HKU\Bibl\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19875432 2013-06-21] (Skype Technologies S.A.)
HKU\Bibl\...\Winlogon: [Shell] explorer.exe,C:\Users\Bibl\AppData\Roaming\cache.dat [94208 2011-11-17] () <==== ATTENTION
Startup: C:\Users\Bibl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\Bibl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Bibl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) =================
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-01] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [465360 2012-05-01] (Avira Operations GmbH & Co. KG)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2012-11-23] ()
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [743320 2012-10-02] (Tunngle.net GmbH)
S2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-24] (Avira GmbH)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH)
S2 DgiVecp; C:\windows\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
S2 DgiVecp; C:\windows\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-30] (DT Soft Ltd)
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-23 17:00 - 2013-07-23 21:00 - 00000004 ____A C:\Users\Bibl\AppData\Roaming\cache.ini
2013-07-22 22:22 - 2013-07-22 22:22 - 02008516 ____A C:\Users\Bibl\Desktop\Norwegen.odp
2013-07-21 22:30 - 2013-07-23 16:07 - 00000000 ____D C:\Program Files (x86)\The Mighty Quest For Epic Loot
2013-07-21 22:30 - 2013-07-21 22:30 - 00001407 ____A C:\Users\Public\Desktop\The Mighty Quest For Epic Loot.lnk
2013-07-21 22:28 - 2013-07-21 22:28 - 27981336 ____A ( ) C:\Users\Bibl\Downloads\MightyQuestSetup_210883.exe
2013-07-20 13:35 - 2013-07-20 13:35 - 00000222 ____A C:\Users\Bibl\Desktop\FTL Faster Than Light.url
2013-07-12 17:42 - 2013-06-12 00:43 - 14329856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-12 17:42 - 2013-06-12 00:43 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-12 17:42 - 2013-06-12 00:43 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-12 17:42 - 2013-06-12 00:43 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-12 17:42 - 2013-06-12 00:43 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-12 17:42 - 2013-06-12 00:43 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-12 17:42 - 2013-06-12 00:43 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-12 17:42 - 2013-06-12 00:42 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-12 17:42 - 2013-06-12 00:42 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-12 17:42 - 2013-06-12 00:42 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-12 17:42 - 2013-06-12 00:42 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-12 17:42 - 2013-06-12 00:42 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-12 17:42 - 2013-06-12 00:42 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-12 17:42 - 2013-06-12 00:26 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-07-12 17:42 - 2013-06-12 00:26 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-07-12 17:42 - 2013-06-12 00:26 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-07-12 17:42 - 2013-06-12 00:25 - 19238912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 02648576 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-07-12 17:42 - 2013-06-12 00:25 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-07-12 17:42 - 2013-06-11 23:51 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-12 17:42 - 2013-06-11 23:50 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-12 17:42 - 2013-06-07 04:22 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-07-12 17:42 - 2013-06-07 03:37 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-12 13:48 - 2013-06-05 04:34 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-07-12 13:48 - 2013-06-04 07:00 - 00624128 ____A (Microsoft Corporation) C:\Windows\System32\qedit.dll
2013-07-12 13:48 - 2013-06-04 05:53 - 00509440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-12 13:48 - 2013-05-06 07:03 - 01887744 ____A (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-07-12 13:48 - 2013-05-06 05:56 - 01620480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-12 13:48 - 2013-04-10 00:34 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-12 13:48 - 2013-04-02 23:51 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2013-07-04 13:01 - 2013-07-04 13:01 - 00000000 ____D C:\Users\Bibl\AppData\Local\FLT
2013-07-04 12:42 - 2013-07-04 12:58 - 00000000 ____D C:\Program Files (x86)\Remember Me
2013-07-04 09:08 - 2013-07-04 09:08 - 00000000 ____D C:\FRST
2013-07-03 16:41 - 2013-07-03 16:41 - 00000000 ____D C:\Windows\pss
2013-07-02 22:06 - 2013-07-02 22:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-28 11:31 - 2013-06-28 11:31 - 00016733 ____A C:\Users\Bibl\Desktop\STATS_DIABLO.ods
2013-06-26 16:29 - 2013-06-26 20:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
==================== One Month Modified Files and Folders =======
2013-07-23 21:00 - 2013-07-23 17:00 - 00000004 ____A C:\Users\Bibl\AppData\Roaming\cache.ini
2013-07-23 21:00 - 2012-06-25 06:29 - 00000000 ___RD C:\Users\Bibl\Dropbox
2013-07-23 21:00 - 2012-06-24 21:03 - 00000000 ____D C:\Users\Bibl\AppData\Roaming\Dropbox
2013-07-23 21:00 - 2012-06-11 12:35 - 00000000 ____D C:\Users\Bibl\AppData\Local\Deployment
2013-07-23 21:00 - 2012-05-25 15:09 - 00000000 ____D C:\Users\Bibl\AppData\Roaming\Skype
2013-07-23 20:59 - 2012-04-23 17:50 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-23 20:59 - 2009-07-14 06:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-23 20:59 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-23 20:59 - 2009-07-14 05:51 - 00090151 ____A C:\Windows\setupact.log
2013-07-23 17:01 - 2012-05-25 14:59 - 01513293 ____A C:\Windows\WindowsUpdate.log
2013-07-23 16:47 - 2012-05-30 00:32 - 00000000 ____D C:\Users\Bibl\AppData\Roaming\vlc
2013-07-23 16:11 - 2009-07-14 05:45 - 00016976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-23 16:11 - 2009-07-14 05:45 - 00016976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-23 16:07 - 2013-07-21 22:30 - 00000000 ____D C:\Program Files (x86)\The Mighty Quest For Epic Loot
2013-07-22 23:10 - 2012-05-30 16:53 - 00000000 ____D C:\Users\Bibl\AppData\Roaming\uTorrent
2013-07-22 22:22 - 2013-07-22 22:22 - 02008516 ____A C:\Users\Bibl\Desktop\Norwegen.odp
2013-07-22 11:04 - 2012-07-08 21:57 - 00000000 ____D C:\Program Files (x86)\Steam
2013-07-22 11:04 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
2013-07-21 22:30 - 2013-07-21 22:30 - 00001407 ____A C:\Users\Public\Desktop\The Mighty Quest For Epic Loot.lnk
2013-07-21 22:28 - 2013-07-21 22:28 - 27981336 ____A ( ) C:\Users\Bibl\Downloads\MightyQuestSetup_210883.exe
2013-07-20 13:37 - 2012-05-30 21:18 - 00000000 ____D C:\Users\Bibl\Documents\My Games
2013-07-20 13:35 - 2013-07-20 13:35 - 00000222 ____A C:\Users\Bibl\Desktop\FTL Faster Than Light.url
2013-07-13 00:16 - 2012-06-14 21:56 - 00000000 ____D C:\Users\Bibl\AppData\Local\PMB Files
2013-07-12 23:39 - 2012-06-14 21:56 - 00000000 ____D C:\ProgramData\PMB Files
2013-07-12 23:06 - 2009-07-14 05:45 - 00294136 ____A C:\Windows\System32\FNTCACHE.DAT
2013-07-12 23:05 - 2010-11-21 08:00 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 23:05 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 23:05 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-12 17:43 - 2010-11-21 07:50 - 00767670 ____A C:\Windows\System32\perfh007.dat
2013-07-12 17:43 - 2010-11-21 07:50 - 00173144 ____A C:\Windows\System32\perfc007.dat
2013-07-12 17:43 - 2009-07-14 06:13 - 01812408 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-10 19:41 - 2013-02-12 09:44 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-10 19:41 - 2012-05-25 15:09 - 00000000 ____D C:\ProgramData\Skype
2013-07-08 17:13 - 2012-12-05 09:58 - 00000000 ___AD C:\Users\Bibl\Desktop\Sc2gears
2013-07-08 04:43 - 2012-09-01 10:23 - 00000000 ____D C:\Users\Bibl\AppData\Roaming\TS3Client
2013-07-05 14:17 - 2013-03-06 00:25 - 00000000 ____D C:\Users\Bibl\Desktop\Games
2013-07-04 13:01 - 2013-07-04 13:01 - 00000000 ____D C:\Users\Bibl\AppData\Local\FLT
2013-07-04 12:58 - 2013-07-04 12:42 - 00000000 ____D C:\Program Files (x86)\Remember Me
2013-07-04 12:48 - 2012-05-25 15:01 - 00440325 ____A C:\Windows\DirectX.log
2013-07-04 09:08 - 2013-07-04 09:08 - 00000000 ____D C:\FRST
2013-07-03 16:41 - 2013-07-03 16:41 - 00000000 ____D C:\Windows\pss
2013-07-03 16:40 - 2012-06-11 18:43 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2013-07-03 12:10 - 2012-05-25 15:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-02 22:06 - 2013-07-02 22:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-30 20:08 - 2012-05-26 15:13 - 00000000 ____D C:\Users\Bibl\AppData\Local\Adobe
2013-06-30 20:07 - 2012-04-23 17:48 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-30 20:07 - 2012-04-23 17:48 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-30 14:20 - 2012-06-11 12:30 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-06-28 11:31 - 2013-06-28 11:31 - 00016733 ____A C:\Users\Bibl\Desktop\STATS_DIABLO.ods
2013-06-26 20:09 - 2013-06-26 16:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-07-04 12:47:48
Restore point made on: 2013-07-12 17:39:00
Restore point made on: 2013-07-21 22:30:36
==================== Memory info ===========================
Percentage of memory in use: 10%
Total physical RAM: 8147.59 MB
Available physical RAM: 7267.55 MB
Total Pagefile: 8145.74 MB
Available Pagefile: 7268.92 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:906.61 GB) (Free:237.99 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)]
Drive e: (Recovery) (Fixed) (Total:24.41 GB) (Free:10.14 GB) NTFS (Disk=0 Partition=2)
Drive f: (User Manual) (CDROM) (Total:0.4 GB) (Free:0 GB) CDFS
Drive l: () (Removable) (Total:3.62 GB) (Free:3.43 GB) FAT32 (Disk=6 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System) (Fixed) (Total:0.49 GB) (Free:0.44 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 512963E8)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=24 GB) - (Type=27)
Partition 3: (Not Active) - (Size=907 GB) - (Type=07 NTFS)
========================================================
Disk: 6 (Size: 4 GB) (Disk ID: 12B2B0E7)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)
LastRegBack: 2013-07-23 07:29
==================== End Of Log ============================
Ich hoffe jemand hat Lust mir noch einmal bis zum Schluss zur Seite zu stehen