![]() |
| |||||||
Log-Analyse und Auswertung: Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| | #1 | |||
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Hallo :-) Seit gestern habe ich das Problem dass meine Standard Startseiten im Internetexplorer sowie im Firefox auf Qv06 umgeleitet werden. (Habe mir ein Programm runtergeladen das Spider.exe heißt, dabei hab ich mir wohl was eingefangen. Ich habe bereits euer Forum durchsucht und dabei diesen Beitrag gefunden http://www.trojaner-board.de/135264-...mgeleitet.html , die vorgeschlagenen Schritte habe ich bereits durchgeführt aber es hat nix gebracht:-( Hier die .txt-Dateien: Zitat:
Zitat:
Zitat:
|
| | #2 | ||
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Habe dann noch die "Standartprozedur" durchgeführt, anbei die Logfiles:
__________________Zitat:
Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-08-2013
Ran by User (administrator) on 06-08-2013 13:27:42
Running from C:\Users\User\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\AtService.exe
(AMD) C:\windows\system32\atiesrxx.exe
(Hewlett-Packard) C:\windows\system32\Hpservice.exe
(AMD) C:\windows\system32\atieclxx.exe
(Wsys Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe
(ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Bioscrypt Inc.) C:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(ActivIdentity) C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
(ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\windows\system32\AEADISRV.EXE
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
() C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Users\User\Desktop\Defogger.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [PDF Complete] - C:\Program Files\PDF Complete\pdfsty.exe [563736 2009-06-18] (PDF Complete Inc)
HKLM\...\Run: [WirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [MVS Splash] - C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe [x]
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1721640 2010-08-17] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-01-11] ()
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [acevents] - C:\Program Files\ActivIdentity\ActivClient\acevents.exe [153640 2009-06-03] (ActivIdentity)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [accrdsub] - C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [400936 2009-06-03] (ActivIdentity)
HKLM\...\Run: [PTHOSTTR] - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start [x]
HKLM\...\Run: [CognizanceTS] - C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [24848 2009-07-23] (Bioscrypt Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [462920 2012-07-03] (Malwarebytes Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
Winlogon\Notify\!SASWinLogon: G:\Neuer Ordner\SASWINLO.DLL [X]
HKCU\...\Run: [SUPERAntiSpyware] - G:\Neuer Ordner\SUPERAntiSpyware.exe [x]
HKCU\...\Run: [Google Update] - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-08-15] (Google Inc.)
HKCU\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe [825808 2013-05-29] (Google Inc.)
HKCU\...\Policies\system: [DisableCMD] 0
MountPoints2: {3464dca5-900b-11e0-8fb6-18a905e37ce7} - D:\Autorun.exe
MountPoints2: {e1b32d32-07b4-11df-ac17-806e6f6e6963} - F:\Launcher.exe
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-07-16] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-07-16] (Hewlett-Packard)
Lsa: [Notification Packages] scecli ASWLNPkg
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
URLSearchHook: (No Name) - {b80f591e-fe9a-46cf-a13e-180377240586} - No File
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU -No Name - {B80F591E-FE9A-46CF-A13E-180377240586} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: myrm - {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\myRmProt4.9.2.329.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - G:\Neuer Ordner\SASSEH.DLL No File [ ]
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default
FF NewTab: hxxp://search.babylon.com/?affID=119292&babsrc=NT_ss&mntrId=2690001E648DB6DD
FF SelectedSearchEngine: qvo6
FF Homepage: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143
FF Keyword.URL: hxxp://search.babylon.com/?babsrc=toolbar2&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 - C:\windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\User\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\User\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Babylon - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default\Extensions\ffxtlbr@babylon.com
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default\Extensions\ich@maltegoetz.de
FF Extension: No Name - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF Extension: pencil - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default\Extensions\pencil@evolus.vn.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF HKLM\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF Extension: DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
Chrome:
=======
CHR HomePage: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143
CHR RestoreOnStartup: "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143"
CHR DefaultSearchURL: (qvo6) - hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143&type=default&q={searchTerms}
CHR DefaultSuggestURL: (qvo6) - "suggest_url": "",
CHR Plugin: (Shockwave Flash) - C:\Users\User\AppData\Local\Google\Chrome\Application\21.0.1180.79\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Veetle TV Player) - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (TVU Web Player for FireFox) - C:\windows\system32\TVUAx\npTVUAx.dll (TVU networks)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (ProxTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.3_0
CHR Extension: (DivX HiQ) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0
CHR Extension: (Citavi Picker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio\2013.4.29_0
CHR HKLM\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\User\AppData\LocalLow\proxtube\CHROME\proxtube.crx
CHR HKLM\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx
CHR HKLM\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx
========================== Services (Whitelisted) =================
R2 ac.sharedstore; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [207400 2009-06-03] (ActivIdentity)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
S2 appdrvrem01; C:\Windows\System32\appdrvrem01.exe [316888 2012-05-09] (Protection Technology)
R2 ASBroker; C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [192784 2009-07-23] (Bioscrypt Inc.)
R2 ASChannel; C:\Program Files\Hewlett-Packard\IAM\Bin\AsChnl.dll [150288 2009-07-23] (Bioscrypt Inc.)
R2 ATService; C:\Program Files\Fingerprint Sensor\AtService.exe [1201400 2009-07-29] (AuthenTec, Inc.)
R2 HpFkCryptService; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [256544 2009-07-29] (McAfee, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [655944 2012-07-03] (Malwarebytes Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-06-18] (PDF Complete Inc)
R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [891456 2013-08-05] (Wsys Co., Ltd.)
R2 yksvc; C:\Windows\System32\yk62x86.dll [282624 2009-07-20] (Marvell)
S2 !SASCORE; "G:\Neuer Ordner\SASCORE.EXE" [x]
S2 EngineServer; C:\PROGRA~1\McAfee\MANAGE~1\VScan\ENGINE~1.EXE [x]
S3 HP ProtectTools Service; "C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe" [x]
S2 myAgtSvc; "C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe" /ServiceStart [x]
==================== Drivers (Whitelisted) ====================
R3 5U876UVC; C:\Windows\System32\DRIVERS\5U876.sys [118656 2009-06-30] (Ricoh co.,Ltd.)
R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [3332784 2012-05-09] (Protection Technology)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2011-01-16] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-01] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [101248 2011-10-17] (AVM Berlin)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [218688 2011-06-06] (DT Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-01-16] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
R1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S3 NETw1v32; C:\Windows\System32\DRIVERS\NETw1v32.sys [5958656 2009-07-21] (Intel Corporation)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [12528 2009-07-29] (SafeBoot International)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [109216 2009-07-29] ()
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [51408 2009-07-29] (SafeBoot N.V.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [12960 2009-07-29] (SafeBoot International)
S0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [66560 2005-05-16] (Protection Technology)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-03] (Avira GmbH)
S1 SASDIFSV; \??\G:\Neuer Ordner\SASDIFSV.SYS [x]
S1 SASKUTIL; \??\G:\Neuer Ordner\SASKUTIL.SYS [x]
U3 mbr; \??\C:\Users\User\AppData\Local\Temp\mbr.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-06 13:27 - 2013-08-06 13:27 - 00000000 ____D C:\FRST
2013-08-06 13:26 - 2013-08-06 13:26 - 01228808 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2013-08-06 13:19 - 2013-08-06 13:19 - 00000598 _____ C:\Users\User\Desktop\defogger_disable.log
2013-08-06 13:19 - 2013-08-06 13:19 - 00000156 _____ C:\Users\User\defogger_reenable
2013-08-06 13:18 - 2013-08-06 13:18 - 00050477 _____ C:\Users\User\Desktop\Defogger.exe
2013-08-06 13:13 - 2013-08-06 13:13 - 00022262 _____ C:\Users\User\Desktop\dds.txt
2013-08-06 13:13 - 2013-08-06 13:13 - 00009873 _____ C:\Users\User\Desktop\attach.txt
2013-08-06 13:10 - 2013-08-06 13:10 - 00700783 ____R (Swearware) C:\Users\User\Desktop\dds+.exe
2013-08-06 13:07 - 2013-08-06 13:07 - 00015362 _____ C:\Users\User\Desktop\AdwCleaner[S1].txt
2013-08-06 13:02 - 2013-08-06 13:06 - 00015362 _____ C:\AdwCleaner[S1].txt
2013-08-06 13:02 - 2013-08-06 13:02 - 00791488 _____ C:\Users\User\Downloads\ImageEditorSetup.exe
2013-08-06 13:02 - 2013-08-06 13:02 - 00666633 _____ C:\Users\User\Downloads\adwcleaner.exe
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\windows\system32\MRT
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\6e3ffb7815cbe27a668914aacbca93
2013-08-05 21:49 - 2013-08-06 13:04 - 00000000 ____D C:\ProgramData\eSafe
2013-08-05 21:48 - 2013-08-05 21:48 - 00000000 ____D C:\Users\User\AppData\Roaming\eIntaller
2013-08-03 04:44 - 2013-08-05 21:37 - 00000000 ____D C:\Users\User\Desktop\maria
2013-08-01 23:38 - 2013-08-01 23:38 - 00262515 _____ C:\Users\User\Downloads\Altklausuren.zip
2013-07-31 13:48 - 2013-07-31 13:48 - 00435712 _____ C:\Users\User\Downloads\awp11bg.ppt
2013-07-29 16:42 - 2013-07-31 19:40 - 00125275 ____H C:\Users\User\Documents\~WRL2837.tmp
2013-07-29 14:33 - 2013-07-29 14:33 - 00166400 _____ C:\Users\User\Downloads\wipol 2 - allokatives marktversagen.ppt
2013-07-28 14:11 - 2013-07-28 14:11 - 10120704 _____ C:\Users\User\Downloads\Int_Ec_Rel_and_Reg_Integr_SS_2013_17072013.ppt
2013-07-23 14:22 - 2013-07-23 14:23 - 00000000 ____D C:\Users\User\Downloads\VBL
2013-07-18 00:35 - 2013-07-24 22:51 - 00000000 ____D C:\Users\User\Downloads\externe
2013-07-15 10:52 - 2013-07-23 01:00 - 00000000 ____D C:\Users\User\Downloads\Informationsmanagment
2013-07-12 10:00 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-07-12 10:00 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-07-12 10:00 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-07-12 10:00 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-07-11 15:14 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-07-11 15:14 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2013-07-11 15:14 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-07-11 15:14 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-06 13:27 - 2013-08-06 13:27 - 00000000 ____D C:\FRST
2013-08-06 13:26 - 2013-08-06 13:26 - 01228808 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2013-08-06 13:19 - 2013-08-06 13:19 - 00000598 _____ C:\Users\User\Desktop\defogger_disable.log
2013-08-06 13:19 - 2013-08-06 13:19 - 00000156 _____ C:\Users\User\defogger_reenable
2013-08-06 13:18 - 2013-08-06 13:18 - 00050477 _____ C:\Users\User\Desktop\Defogger.exe
2013-08-06 13:13 - 2013-08-06 13:13 - 00022262 _____ C:\Users\User\Desktop\dds.txt
2013-08-06 13:13 - 2013-08-06 13:13 - 00009873 _____ C:\Users\User\Desktop\attach.txt
2013-08-06 13:13 - 2009-07-14 06:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-06 13:13 - 2009-07-14 06:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-06 13:10 - 2013-08-06 13:10 - 00700783 ____R (Swearware) C:\Users\User\Desktop\dds+.exe
2013-08-06 13:07 - 2013-08-06 13:07 - 00015362 _____ C:\Users\User\Desktop\AdwCleaner[S1].txt
2013-08-06 13:06 - 2013-08-06 13:02 - 00015362 _____ C:\AdwCleaner[S1].txt
2013-08-06 13:04 - 2013-08-05 21:49 - 00000000 ____D C:\ProgramData\eSafe
2013-08-06 13:04 - 2013-06-11 21:58 - 00010316 _____ C:\windows\setupact.log
2013-08-06 13:04 - 2012-02-15 13:38 - 00001090 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-06 13:04 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-06 13:03 - 2012-08-15 11:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-08-06 13:03 - 2011-05-13 21:34 - 00001007 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-06 13:03 - 2010-01-23 02:21 - 01621726 _____ C:\windows\WindowsUpdate.log
2013-08-06 13:03 - 2010-01-22 17:59 - 00001146 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-08-06 13:02 - 2013-08-06 13:02 - 00791488 _____ C:\Users\User\Downloads\ImageEditorSetup.exe
2013-08-06 13:02 - 2013-08-06 13:02 - 00666633 _____ C:\Users\User\Downloads\adwcleaner.exe
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\windows\system32\MRT
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\6e3ffb7815cbe27a668914aacbca93
2013-08-05 22:39 - 2012-08-15 11:55 - 00001116 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4234438737-965128108-3711115987-1001UA.job
2013-08-05 22:36 - 2012-07-31 10:36 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-05 22:36 - 2012-02-15 13:38 - 00001094 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-05 21:49 - 2012-08-15 11:57 - 00002552 _____ C:\Users\User\Desktop\chrome.lnk
2013-08-05 21:49 - 2010-01-31 18:23 - 00001573 _____ C:\Users\User\Desktop\Internet Explorer.lnk
2013-08-05 21:48 - 2013-08-05 21:48 - 00000000 ____D C:\Users\User\AppData\Roaming\eIntaller
2013-08-05 21:37 - 2013-08-03 04:44 - 00000000 ____D C:\Users\User\Desktop\maria
2013-08-05 21:35 - 2012-08-15 11:55 - 00001064 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4234438737-965128108-3711115987-1001Core.job
2013-08-05 12:08 - 2012-11-15 15:11 - 00000000 ____D C:\Users\User\Downloads\alt
2013-08-04 21:25 - 2009-09-20 16:47 - 00909458 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-03 04:27 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\wfp
2013-08-03 04:26 - 2010-02-02 19:37 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2013-08-03 04:26 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\NDF
2013-08-03 04:26 - 2009-07-14 04:37 - 00000000 ____D C:\windows\registration
2013-08-03 04:26 - 2009-07-14 04:37 - 00000000 ____D C:\windows\AppCompat
2013-08-01 23:38 - 2013-08-01 23:38 - 00262515 _____ C:\Users\User\Downloads\Altklausuren.zip
2013-08-01 06:41 - 2009-09-20 16:49 - 00000000 ____D C:\ProgramData\PDFC
2013-07-31 19:40 - 2013-07-29 16:42 - 00125275 ____H C:\Users\User\Documents\~WRL2837.tmp
2013-07-31 14:08 - 2010-01-31 18:52 - 00000052 _____ C:\windows\system32\DOErrors.log
2013-07-31 14:07 - 2011-10-26 16:49 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-07-31 13:48 - 2013-07-31 13:48 - 00435712 _____ C:\Users\User\Downloads\awp11bg.ppt
2013-07-31 13:31 - 2013-01-31 14:47 - 00000136 ____H C:\Users\User\Downloads\.picasa.ini
2013-07-29 20:40 - 2011-05-13 20:35 - 00000000 ____D C:\Program Files\Google
2013-07-29 14:33 - 2013-07-29 14:33 - 00166400 _____ C:\Users\User\Downloads\wipol 2 - allokatives marktversagen.ppt
2013-07-28 14:11 - 2013-07-28 14:11 - 10120704 _____ C:\Users\User\Downloads\Int_Ec_Rel_and_Reg_Integr_SS_2013_17072013.ppt
2013-07-26 20:30 - 2010-01-22 18:24 - 00248388 _____ C:\windows\PFRO.log
2013-07-24 22:51 - 2013-07-18 00:35 - 00000000 ____D C:\Users\User\Downloads\externe
2013-07-23 14:23 - 2013-07-23 14:22 - 00000000 ____D C:\Users\User\Downloads\VBL
2013-07-23 01:00 - 2013-07-15 10:52 - 00000000 ____D C:\Users\User\Downloads\Informationsmanagment
2013-07-15 14:07 - 2010-04-27 12:00 - 01161216 ___SH C:\Users\User\Desktop\Thumbs.db
2013-07-13 00:17 - 2012-12-11 17:35 - 00000000 ___RD C:\Program Files\Skype
2013-07-13 00:17 - 2010-01-22 17:41 - 00000000 ____D C:\ProgramData\Skype
2013-07-12 11:45 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-07-12 10:20 - 2009-07-14 06:33 - 00475216 _____ C:\windows\system32\FNTCACHE.DAT
2013-07-12 10:19 - 2010-07-22 16:22 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-12 10:17 - 2009-07-27 13:09 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 10:17 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 09:59 - 2009-09-20 16:54 - 00000000 ____D C:\ProgramData\Microsoft Help
Files to move or delete:
====================
C:\ProgramData\ism_0_llatsni.pad
C:\ProgramData\kcap_0paos.pad
C:\Users\User\AppData\Roaming\skype.dat
C:\Users\User\AppData\Roaming\skype.ini
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-02 08:50
==================== End Of Log ============================
Zitat:
Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-08-06 14:12:24
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.0006 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\User\AppData\Local\Temp\kxldapob.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 8304C9F5 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830861F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? C:\windows\System32\Drivers\SafeBoot.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9662B000, 0x2D51CE, 0xE8000020]
.text C:\windows\system32\DRIVERS\atksgt.sys section is writeable [0x9E1B7300, 0x3B6D8, 0xE8000020]
.text C:\windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9E1FA300, 0x1BEE, 0xE8000020]
? C:\Users\User\AppData\Local\Temp\mbr.sys Das System kann die angegebene Datei nicht finden. !
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\tdx \Device\Tcp mfetdik.sys
AttachedDevice \Driver\tdx \Device\Udp mfetdik.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002713591c59
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002713591c59 (not active ControlSet)
---- EOF - GMER 2.1 ----
So mehr habe ich noch nicht gemacht. Achja Avira hat natürlich nix gefunden. Würde mich sehr über eure Hilfe freuen. Vielen Dank schonmal im Vorraus |
| | #3 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Hallo und
__________________![]() JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Danach eine neues Log mit Farbars Tool bitte: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
| | #4 | |
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Nach dem starten von JRT kommt die folgende Meldung: Zitat:
|
| | #5 | |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet y drücken, das wird deinen Rechner neustarten und JRT sollte weitermachen, ansonsten bitte posten was passiert ist Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #6 | |
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Vielen Dank für die schnelle Hilfe :-) Hier die Logdateien: Zitat:
Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-08-2013
Ran by User (administrator) on 06-08-2013 17:14:13
Running from C:\Users\User\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\AtService.exe
(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
(Hewlett-Packard) C:\windows\system32\Hpservice.exe
(Bioscrypt Inc.) C:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe
(ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(ActivIdentity) C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
(ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\windows\system32\AEADISRV.EXE
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [PDF Complete] - C:\Program Files\PDF Complete\pdfsty.exe [563736 2009-06-18] (PDF Complete Inc)
HKLM\...\Run: [WirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [MVS Splash] - C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe [x]
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1721640 2010-08-17] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-01-11] ()
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [acevents] - C:\Program Files\ActivIdentity\ActivClient\acevents.exe [153640 2009-06-03] (ActivIdentity)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [accrdsub] - C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [400936 2009-06-03] (ActivIdentity)
HKLM\...\Run: [PTHOSTTR] - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start [x]
HKLM\...\Run: [CognizanceTS] - C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [24848 2009-07-23] (Bioscrypt Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [462920 2012-07-03] (Malwarebytes Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
Winlogon\Notify\!SASWinLogon: G:\Neuer Ordner\SASWINLO.DLL [X]
HKCU\...\Run: [SUPERAntiSpyware] - G:\Neuer Ordner\SUPERAntiSpyware.exe [x]
HKCU\...\Run: [Google Update] - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-08-15] (Google Inc.)
HKCU\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe [825808 2013-05-29] (Google Inc.)
HKCU\...\Policies\system: [DisableCMD] 0
MountPoints2: {3464dca5-900b-11e0-8fb6-18a905e37ce7} - D:\Autorun.exe
MountPoints2: {e1b32d32-07b4-11df-ac17-806e6f6e6963} - F:\Launcher.exe
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-07-16] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2009-07-16] (Hewlett-Packard)
Lsa: [Notification Packages] scecli ASWLNPkg
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
URLSearchHook: (No Name) - {b80f591e-fe9a-46cf-a13e-180377240586} - No File
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU -No Name - {B80F591E-FE9A-46CF-A13E-180377240586} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: myrm - {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\myRmProt4.9.2.329.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - G:\Neuer Ordner\SASSEH.DLL No File [ ]
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default
FF SelectedSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 - C:\windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\User\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\User\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default\Extensions\ich@maltegoetz.de
FF Extension: pencil - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\r9xl3eaq.default\Extensions\pencil@evolus.vn.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF HKLM\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF Extension: DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
Chrome:
=======
CHR HomePage: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143
CHR RestoreOnStartup: "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143"
CHR DefaultSearchURL: (qvo6) - hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST9500420AS_5VJ2ZAL9&ts=1375732143&type=default&q={searchTerms}
CHR DefaultSuggestURL: (qvo6) - "suggest_url": "",
CHR Plugin: (Shockwave Flash) - C:\Users\User\AppData\Local\Google\Chrome\Application\21.0.1180.79\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Veetle TV Player) - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (TVU Web Player for FireFox) - C:\windows\system32\TVUAx\npTVUAx.dll (TVU networks)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (ProxTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.3_0
CHR Extension: (DivX HiQ) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0
CHR Extension: (Citavi Picker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\piehhloihgjjiomhieeddiidpekaajio\2013.4.29_0
CHR HKLM\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\User\AppData\LocalLow\proxtube\CHROME\proxtube.crx
CHR HKLM\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx
CHR HKLM\...\Chrome\Extension: [piehhloihgjjiomhieeddiidpekaajio] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Chrome\ChromePicker.crx
========================== Services (Whitelisted) =================
R2 ac.sharedstore; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [207400 2009-06-03] (ActivIdentity)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
S2 appdrvrem01; C:\Windows\System32\appdrvrem01.exe [316888 2012-05-09] (Protection Technology)
R2 ASBroker; C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [192784 2009-07-23] (Bioscrypt Inc.)
R2 ASChannel; C:\Program Files\Hewlett-Packard\IAM\Bin\AsChnl.dll [150288 2009-07-23] (Bioscrypt Inc.)
R2 ATService; C:\Program Files\Fingerprint Sensor\AtService.exe [1201400 2009-07-29] (AuthenTec, Inc.)
R2 HpFkCryptService; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [256544 2009-07-29] (McAfee, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [655944 2012-07-03] (Malwarebytes Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-06-18] (PDF Complete Inc)
R2 yksvc; C:\Windows\System32\yk62x86.dll [282624 2009-07-20] (Marvell)
S2 !SASCORE; "G:\Neuer Ordner\SASCORE.EXE" [x]
S2 EngineServer; C:\PROGRA~1\McAfee\MANAGE~1\VScan\ENGINE~1.EXE [x]
S3 HP ProtectTools Service; "C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe" [x]
S2 myAgtSvc; "C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe" /ServiceStart [x]
S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x]
==================== Drivers (Whitelisted) ====================
R3 5U876UVC; C:\Windows\System32\DRIVERS\5U876.sys [118656 2009-06-30] (Ricoh co.,Ltd.)
R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [3332784 2012-05-09] (Protection Technology)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2011-01-16] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-01] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [101248 2011-10-17] (AVM Berlin)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [218688 2011-06-06] (DT Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-01-16] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation)
R1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
S3 NETw1v32; C:\Windows\System32\DRIVERS\NETw1v32.sys [5958656 2009-07-21] (Intel Corporation)
R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [12528 2009-07-29] (SafeBoot International)
R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [109216 2009-07-29] ()
R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [51408 2009-07-29] (SafeBoot N.V.)
R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [12960 2009-07-29] (SafeBoot International)
S0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [66560 2005-05-16] (Protection Technology)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-03] (Avira GmbH)
S1 SASDIFSV; \??\G:\Neuer Ordner\SASDIFSV.SYS [x]
S1 SASKUTIL; \??\G:\Neuer Ordner\SASKUTIL.SYS [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-06 17:12 - 2013-08-06 17:12 - 00004782 _____ C:\Users\User\Desktop\JRT.txt
2013-08-06 16:55 - 2013-08-06 16:55 - 00000000 ____D C:\windows\ERUNT
2013-08-06 16:54 - 2013-08-06 16:55 - 00000000 ____D C:\Users\User\Desktop\Trojaner
2013-08-06 16:53 - 2013-08-06 16:53 - 00563461 _____ (Oleg N. Scherbakov) C:\Users\User\Desktop\JRT.exe
2013-08-06 13:27 - 2013-08-06 13:27 - 00000000 ____D C:\FRST
2013-08-06 13:26 - 2013-08-06 13:26 - 01228808 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2013-08-06 13:19 - 2013-08-06 13:19 - 00000156 _____ C:\Users\User\defogger_reenable
2013-08-06 13:02 - 2013-08-06 13:06 - 00015362 _____ C:\AdwCleaner[S1].txt
2013-08-06 13:02 - 2013-08-06 13:02 - 00791488 _____ C:\Users\User\Downloads\ImageEditorSetup.exe
2013-08-06 13:02 - 2013-08-06 13:02 - 00666633 _____ C:\Users\User\Downloads\adwcleaner.exe
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\windows\system32\MRT
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\6e3ffb7815cbe27a668914aacbca93
2013-08-05 21:48 - 2013-08-05 21:48 - 00000000 ____D C:\Users\User\AppData\Roaming\eIntaller
2013-08-03 04:44 - 2013-08-05 21:37 - 00000000 ____D C:\Users\User\Desktop\maria
2013-08-01 23:38 - 2013-08-01 23:38 - 00262515 _____ C:\Users\User\Downloads\Altklausuren.zip
2013-07-31 13:48 - 2013-07-31 13:48 - 00435712 _____ C:\Users\User\Downloads\awp11bg.ppt
2013-07-29 16:42 - 2013-07-31 19:40 - 00125275 ____H C:\Users\User\Documents\~WRL2837.tmp
2013-07-29 14:33 - 2013-07-29 14:33 - 00166400 _____ C:\Users\User\Downloads\wipol 2 - allokatives marktversagen.ppt
2013-07-28 14:11 - 2013-07-28 14:11 - 10120704 _____ C:\Users\User\Downloads\Int_Ec_Rel_and_Reg_Integr_SS_2013_17072013.ppt
2013-07-23 14:22 - 2013-07-23 14:23 - 00000000 ____D C:\Users\User\Downloads\VBL
2013-07-18 00:35 - 2013-07-24 22:51 - 00000000 ____D C:\Users\User\Downloads\externe
2013-07-15 10:52 - 2013-07-23 01:00 - 00000000 ____D C:\Users\User\Downloads\Informationsmanagment
2013-07-12 10:00 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-07-12 10:00 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-07-12 10:00 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-07-12 10:00 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-07-12 10:00 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-07-12 10:00 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-07-11 15:14 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-07-11 15:14 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2013-07-11 15:14 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-07-11 15:14 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-06 17:12 - 2013-08-06 17:12 - 00004782 _____ C:\Users\User\Desktop\JRT.txt
2013-08-06 17:12 - 2012-08-15 11:57 - 00002358 _____ C:\Users\User\Desktop\chrome.lnk
2013-08-06 17:12 - 2010-01-31 18:23 - 00001379 _____ C:\Users\User\Desktop\Internet Explorer.lnk
2013-08-06 17:08 - 2012-02-15 13:38 - 00001090 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-06 17:07 - 2013-06-11 21:58 - 00010484 _____ C:\windows\setupact.log
2013-08-06 17:07 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-06 17:06 - 2010-01-23 02:21 - 01627958 _____ C:\windows\WindowsUpdate.log
2013-08-06 16:55 - 2013-08-06 16:55 - 00000000 ____D C:\windows\ERUNT
2013-08-06 16:55 - 2013-08-06 16:54 - 00000000 ____D C:\Users\User\Desktop\Trojaner
2013-08-06 16:53 - 2013-08-06 16:53 - 00563461 _____ (Oleg N. Scherbakov) C:\Users\User\Desktop\JRT.exe
2013-08-06 16:39 - 2012-08-15 11:55 - 00001116 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4234438737-965128108-3711115987-1001UA.job
2013-08-06 16:36 - 2012-07-31 10:36 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-06 16:36 - 2012-02-15 13:38 - 00001094 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-06 13:27 - 2013-08-06 13:27 - 00000000 ____D C:\FRST
2013-08-06 13:26 - 2013-08-06 13:26 - 01228808 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2013-08-06 13:19 - 2013-08-06 13:19 - 00000156 _____ C:\Users\User\defogger_reenable
2013-08-06 13:13 - 2009-07-14 06:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-06 13:13 - 2009-07-14 06:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-06 13:06 - 2013-08-06 13:02 - 00015362 _____ C:\AdwCleaner[S1].txt
2013-08-06 13:03 - 2012-08-15 11:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-08-06 13:03 - 2011-05-13 21:34 - 00001007 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-06 13:03 - 2010-01-22 17:59 - 00001146 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-08-06 13:02 - 2013-08-06 13:02 - 00791488 _____ C:\Users\User\Downloads\ImageEditorSetup.exe
2013-08-06 13:02 - 2013-08-06 13:02 - 00666633 _____ C:\Users\User\Downloads\adwcleaner.exe
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\windows\system32\MRT
2013-08-06 08:08 - 2013-08-06 08:08 - 00000000 ____D C:\6e3ffb7815cbe27a668914aacbca93
2013-08-05 21:48 - 2013-08-05 21:48 - 00000000 ____D C:\Users\User\AppData\Roaming\eIntaller
2013-08-05 21:37 - 2013-08-03 04:44 - 00000000 ____D C:\Users\User\Desktop\maria
2013-08-05 21:35 - 2012-08-15 11:55 - 00001064 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4234438737-965128108-3711115987-1001Core.job
2013-08-05 12:08 - 2012-11-15 15:11 - 00000000 ____D C:\Users\User\Downloads\alt
2013-08-04 21:25 - 2009-09-20 16:47 - 00909458 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-03 04:27 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\wfp
2013-08-03 04:26 - 2010-02-02 19:37 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2013-08-03 04:26 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\NDF
2013-08-03 04:26 - 2009-07-14 04:37 - 00000000 ____D C:\windows\registration
2013-08-03 04:26 - 2009-07-14 04:37 - 00000000 ____D C:\windows\AppCompat
2013-08-01 23:38 - 2013-08-01 23:38 - 00262515 _____ C:\Users\User\Downloads\Altklausuren.zip
2013-08-01 06:41 - 2009-09-20 16:49 - 00000000 ____D C:\ProgramData\PDFC
2013-07-31 19:40 - 2013-07-29 16:42 - 00125275 ____H C:\Users\User\Documents\~WRL2837.tmp
2013-07-31 14:08 - 2010-01-31 18:52 - 00000052 _____ C:\windows\system32\DOErrors.log
2013-07-31 14:07 - 2011-10-26 16:49 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-07-31 13:48 - 2013-07-31 13:48 - 00435712 _____ C:\Users\User\Downloads\awp11bg.ppt
2013-07-31 13:31 - 2013-01-31 14:47 - 00000136 ____H C:\Users\User\Downloads\.picasa.ini
2013-07-29 20:40 - 2011-05-13 20:35 - 00000000 ____D C:\Program Files\Google
2013-07-29 14:33 - 2013-07-29 14:33 - 00166400 _____ C:\Users\User\Downloads\wipol 2 - allokatives marktversagen.ppt
2013-07-28 14:11 - 2013-07-28 14:11 - 10120704 _____ C:\Users\User\Downloads\Int_Ec_Rel_and_Reg_Integr_SS_2013_17072013.ppt
2013-07-26 20:30 - 2010-01-22 18:24 - 00248388 _____ C:\windows\PFRO.log
2013-07-24 22:51 - 2013-07-18 00:35 - 00000000 ____D C:\Users\User\Downloads\externe
2013-07-23 14:23 - 2013-07-23 14:22 - 00000000 ____D C:\Users\User\Downloads\VBL
2013-07-23 01:00 - 2013-07-15 10:52 - 00000000 ____D C:\Users\User\Downloads\Informationsmanagment
2013-07-15 14:07 - 2010-04-27 12:00 - 01161216 ___SH C:\Users\User\Desktop\Thumbs.db
2013-07-13 00:17 - 2012-12-11 17:35 - 00000000 ___RD C:\Program Files\Skype
2013-07-13 00:17 - 2010-01-22 17:41 - 00000000 ____D C:\ProgramData\Skype
2013-07-12 11:45 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-07-12 10:20 - 2009-07-14 06:33 - 00475216 _____ C:\windows\system32\FNTCACHE.DAT
2013-07-12 10:19 - 2010-07-22 16:22 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-12 10:17 - 2009-07-27 13:09 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 10:17 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 09:59 - 2009-09-20 16:54 - 00000000 ____D C:\ProgramData\Microsoft Help
Files to move or delete:
====================
C:\ProgramData\ism_0_llatsni.pad
C:\ProgramData\kcap_0paos.pad
C:\Users\User\AppData\Roaming\skype.dat
C:\Users\User\AppData\Roaming\skype.ini
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-02 08:50
==================== End Of Log ============================
Die Version habe ich mal geschenkt bekommen KP :-) |
| | #7 | |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitetZitat:
![]() Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #8 |
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet So habe das jetzt deinstalliert, habe das halt geschenkt bekommen, hat funktioniert, hab mir nix dabei gedacht :-( |
| | #9 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\ProgramData\ism_0_llatsni.pad
C:\ProgramData\kcap_0paos.pad
C:\Users\User\AppData\Roaming\skype.dat
C:\Users\User\AppData\Roaming\skype.ini
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #10 | |
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Vielen Dank :-) Anbei die Fixlog-Datei: Zitat:
|
| | #11 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #12 | ||
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet DANKE! Hier die Logfiles: Zitat:
Zitat:
|
| | #13 | |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitetZitat:
NICHTS voreilig aus der Quarantäne löschen!
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #14 |
| | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Sry hab die Logdatei vorher gespeichert, habe natürlich alles gelöscht. Wars das dann? Auf diesem Wege nochmal tausend Dank für die schnelle und perfekte Hilfe!!! |
| | #15 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet Bitte nochmal TFC ausführen um die TEMPs zu leeren: Lade dir
__________________ Logfiles bitte immer in CODE-Tags posten |
![]() |
| Themen zu Windows 7: Startseiten im IE und Firefox werden auf QV06 umgeleitet |
| antivir, appdatalow, avira, browser, converter, desktop, email, error, firefox, flash player, google, helper, home, iexplore.exe, internet browser, internet explorer, launch, mcafee virus, mozilla, mp3, officejet, picasa, plug-in, problem, programm, registrierungsdatenbank, rootkit, rundll, security, software, svchost.exe, vista, windows |