![]() |
|
Plagegeister aller Art und deren Bekämpfung: Qv06 VirusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// TB-Ausbilder ![]() ![]() ![]() | ![]() Qv06 Virus Wir haben uns bei der Formulierung der Anleitung sehr viel Mühe gegeben und ich bin sicher, dass du das hinkriegst.
__________________ ![]() ![]() Keine Hilfe per PM! |
![]() | #2 |
| ![]() Qv06 Virus so ich hoffe ich hab das richtig gemacht und habe dasshier entdeckt
__________________HR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=ST1000LM014-1EJ164_W380468FXXXXW380468F&ts=1375409709 will ja auch was lernen :> gefunden habe ich dies nach der anleitung in der FRST bringt uns das weiter? ![]() ----------------FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-08-2013 01 Ran by Itaris at 2013-08-16 19:16:41 Running from C:\Users\Itaris\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Acrobat X Pro - English, Français, Deutsch (x32 Version: 10.1.1) Adobe AIR (x32 Version: 3.7.0.2090) Adobe Creative Suite 6 Master Collection (x32 Version: 6) Adobe Help Manager (x32 Version: 4.0.244) Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133) Adobe Widget Browser (x32 Version: 2.0 Build 348) Adobe Widget Browser (x32 Version: 2.0.348) AMD Accelerated Video Transcoding (Version: 12.10.100.30328) AMD Catalyst Install Manager (Version: 8.0.911.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.80328.2204) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.14.3.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) bl (x32 Version: 1.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2013.0328.2218.38225) Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225) Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225) Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225) CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225) CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225) CCC Help Czech (x32 Version: 2013.0328.2217.38225) CCC Help Danish (x32 Version: 2013.0328.2217.38225) CCC Help Dutch (x32 Version: 2013.0328.2217.38225) CCC Help English (x32 Version: 2013.0328.2217.38225) CCC Help Finnish (x32 Version: 2013.0328.2217.38225) CCC Help French (x32 Version: 2013.0328.2217.38225) CCC Help German (x32 Version: 2013.0328.2217.38225) CCC Help Greek (x32 Version: 2013.0328.2217.38225) CCC Help Hungarian (x32 Version: 2013.0328.2217.38225) CCC Help Italian (x32 Version: 2013.0328.2217.38225) CCC Help Japanese (x32 Version: 2013.0328.2217.38225) CCC Help Korean (x32 Version: 2013.0328.2217.38225) CCC Help Norwegian (x32 Version: 2013.0328.2217.38225) CCC Help Polish (x32 Version: 2013.0328.2217.38225) CCC Help Portuguese (x32 Version: 2013.0328.2217.38225) CCC Help Russian (x32 Version: 2013.0328.2217.38225) CCC Help Spanish (x32 Version: 2013.0328.2217.38225) CCC Help Swedish (x32 Version: 2013.0328.2217.38225) CCC Help Thai (x32 Version: 2013.0328.2217.38225) CCC Help Turkish (x32 Version: 2013.0328.2217.38225) ccc-utility64 (Version: 2013.0328.2218.38225) Combat-Gaming Network 3.5.5.1 (x32 Version: 3.5.5.1) Dota 2 (x32) ffdshow v1.2.4422 [2012-04-09] (x32 Version: 1.2.4422.0) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.153) HDvid Codec V1 (x32 Version: 1.27.153.8) HDVidCodec (x32 Version: 2.1 Build 26473) Inhaltsmanager-Assistent für PlayStation(R) (x32 Version: 2.50.6733.38) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 8.0.4.1441) Intel(R) Rapid Storage Technology (x32 Version: 11.1.0.1006) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220) Intel® Trusted Connect Service Client (Version: 1.23.605.1) itech Gaming Software 8.46 (Version: 8.46.27) Lion Transformation Pack (x32 Version: 1.0) Logitech Gaming Software (Version: 8.45.88) LogMeIn Hamachi (x32 Version: 2.1.0.374) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) NVIDIA PhysX (x32 Version: 9.12.1031) OpenOffice 4.0.0 (x32 Version: 4.00.9702) PDF Settings CS6 (x32 Version: 11.0) ph (x32 Version: 1.0.0) Rainmeter (x32 Version: 3.0 beta r2012) Realtek Ethernet Controller Driver (x32 Version: 7.52.203.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6602) Skype™ 6.6 (x32 Version: 6.6.106) Steam (x32 Version: 1.0.0.0) swMSM (x32 Version: 12.0.0.1) TeamSpeak 3 Client (Version: 3.0.11.1) Virtual Audio Cable 4.10 WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 13-08-2013 07:21:17 Windows Update 13-08-2013 12:54:52 Installed DirectX 13-08-2013 12:55:08 Installed Microsoft XNA Framework Redistributable 3.1 15-08-2013 00:41:25 Windows Update 15-08-2013 18:11:03 Installed DirectX 16-08-2013 16:28:54 Removed Skype Click to Call ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0F85DBAA-EE71-45E9-AD1A-FA1FBEE68282} - System32\Tasks\HDvid Codec V1-enabler => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe [2013-08-02] (installdaddy) Task: {2438A788-1A2B-4075-9BE9-447BB3070151} - System32\Tasks\HDvid Codec V1-updater => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe [2013-08-02] (installdaddy) Task: {53780264-588B-46E2-A648-FD47D45861C0} - System32\Tasks\HDvid Codec V1-codedownloader => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe [2013-08-02] (installdaddy) Task: {62D521D9-1903-47F5-B1AC-D65DFA49434F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17] (Google Inc.) Task: {8A6BBF5C-25EA-480C-8B96-DBF954D6D9C2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {A1599284-AACC-4CED-BCE0-7E1F87DCCCB8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17] (Google Inc.) Task: {A8E5AEE2-1DA1-44EB-BE29-9E4AA7119FDB} - System32\Tasks\AdobeAAMUpdater-1.0-Itaris-PC-Itaris => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {BE81A10D-B95F-4593-B266-BD4E9D2756D6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {E21C43B5-D8A1-43B5-A1A8-7454A319172B} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe No File Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HDvid Codec V1-codedownloader.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe Task: C:\Windows\Tasks\HDvid Codec V1-enabler.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe Task: C:\Windows\Tasks\HDvid Codec V1-updater.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/16/2013 10:17:54 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/15/2013 08:10:20 PM) (Source: Application Hang) (User: ) Description: The program SDTools.exe version 2.1.18.150 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 84c Start Time: 01ce99e29ff9afeb Termination Time: 2 Application Path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTools.exe Report Id: f0e3f504-05d5-11e3-acc7-10bf48881547 Error: (08/15/2013 07:34:42 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/15/2013 00:00:48 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/14/2013 11:32:29 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/13/2013 05:26:22 PM) (Source: Application Error) (User: ) Description: Faulting application name: CMADownloader.exe, version: 2.50.6733.20, time stamp: 0x51b82861 Faulting module name: CMADownloader.exe, version: 2.50.6733.20, time stamp: 0x51b82861 Exception code: 0xc0000417 Fault offset: 0x000105e1 Faulting process id: 0x1974 Faulting application start time: 0xCMADownloader.exe0 Faulting application path: CMADownloader.exe1 Faulting module path: CMADownloader.exe2 Report Id: CMADownloader.exe3 Error: (08/13/2013 10:48:38 AM) (Source: Application Error) (User: ) Description: Faulting application name: eGdpSvc.exe, version: 1.0.0.2598, time stamp: 0x51f8b0ad Faulting module name: ole32.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96f Exception code: 0xc0000005 Fault offset: 0x00039342 Faulting process id: 0x6e0 Faulting application start time: 0xeGdpSvc.exe0 Faulting application path: eGdpSvc.exe1 Faulting module path: eGdpSvc.exe2 Report Id: eGdpSvc.exe3 Error: (08/13/2013 09:05:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 01:48:48 PM) (Source: Application Error) (User: ) Description: Windows cannot access the file for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Rainmeter because of this error. Program: Rainmeter File: The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: 00000000 Disk type: 0 Error: (08/12/2013 01:48:48 PM) (Source: Application Error) (User: ) Description: Faulting application name: Rainmeter.exe, version: 3.0.0.2012, time stamp: 0x51e2ac6a Faulting module name: ole32.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c92c Exception code: 0xc0000096 Fault offset: 0x0000000000182948 Faulting process id: 0x147c Faulting application start time: 0xRainmeter.exe0 Faulting application path: Rainmeter.exe1 Faulting module path: Rainmeter.exe2 Report Id: Rainmeter.exe3 System errors: ============= Error: (08/16/2013 10:17:43 AM) (Source: Service Control Manager) (User: ) Description: The Wsys Service service hung on starting. Error: (08/15/2013 07:34:27 PM) (Source: Service Control Manager) (User: ) Description: The Wsys Service service hung on starting. Error: (08/15/2013 07:33:03 PM) (Source: EventLog) (User: ) Description: The previous system shutdown at 19:26:54 on 15.08.2013 was unexpected. Error: (08/15/2013 00:00:34 PM) (Source: Service Control Manager) (User: ) Description: The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (08/15/2013 00:00:30 PM) (Source: Service Control Manager) (User: ) Description: The Wsys Service service hung on starting. Error: (08/14/2013 11:32:24 AM) (Source: Service Control Manager) (User: ) Description: The Wsys Service service hung on starting. Error: (08/13/2013 10:48:38 AM) (Source: Service Control Manager) (User: ) Description: The Wsys Service service terminated unexpectedly. It has done this 1 time(s). Error: (08/13/2013 09:05:42 AM) (Source: Service Control Manager) (User: ) Description: The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (08/13/2013 09:05:32 AM) (Source: Service Control Manager) (User: ) Description: The Wsys Service service hung on starting. Error: (08/12/2013 00:53:29 PM) (Source: Service Control Manager) (User: ) Description: The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Microsoft Office Sessions: ========================= Error: (08/16/2013 10:17:54 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/15/2013 08:10:20 PM) (Source: Application Hang)(User: ) Description: SDTools.exe2.1.18.15084c01ce99e29ff9afeb2C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTools.exef0e3f504-05d5-11e3-acc7-10bf48881547 Error: (08/15/2013 07:34:42 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/15/2013 00:00:48 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/14/2013 11:32:29 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/13/2013 05:26:22 PM) (Source: Application Error)(User: ) Description: CMADownloader.exe2.50.6733.2051b82861CMADownloader.exe2.50.6733.2051b82861c0000417000105e1197401ce9839765fa1bfC:\Program Files (x86)\Sony\Content Manager Assistant\CMADownloader.exeC:\Program Files (x86)\Sony\Content Manager Assistant\CMADownloader.exeb4d5f7dd-042c-11e3-922b-10bf48881547 Error: (08/13/2013 10:48:38 AM) (Source: Application Error)(User: ) Description: eGdpSvc.exe1.0.0.259851f8b0adole32.dll6.1.7601.175144ce7b96fc0000005000393426e001ce97f350361746C:\ProgramData\eSafe\eGdpSvc.exeC:\Windows\syswow64\ole32.dll2509a38c-03f5-11e3-922b-10bf48881547 Error: (08/13/2013 09:05:52 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 01:48:48 PM) (Source: Application Error)(User: ) Description: Rainmeter000000000 Error: (08/12/2013 01:48:48 PM) (Source: Application Error)(User: ) Description: Rainmeter.exe3.0.0.201251e2ac6aole32.dll6.1.7601.175144ce7c92cc00000960000000000182948147c01ce974a98e96aa9C:\Program Files\Rainmeter\Rainmeter.exeC:\Windows\system32\ole32.dll25a719fe-0345-11e3-8958-10bf48881547 ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 8145.48 MB Available physical RAM: 4944.53 MB Total Pagefile: 16289.15 MB Available Pagefile: 12063.82 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.51 GB) (Free:816.32 GB) NTFS Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (Haupt) (Fixed) (Total:232.88 GB) (Free:56.25 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (old) (Fixed) (Total:232.88 GB) (Free:75.65 GB) NTFS Drive g: (Musik /filme) (Fixed) (Total:297.99 GB) (Free:33.15 GB) NTFS Drive h: (Windows 7 Ultimate - 32 Bit (Aut) (CDROM) (Total:3.48 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: A56A442F) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: E5CAE5CA) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B732B732) Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 2AFF8C51) Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ==================== End Of Log ================== |
![]() |
Themen zu Qv06 Virus |
.html, appdatalow, askbar, chrome, dankbar, eingefangen, gefangen, hilfe, launch, nichts, proplem, qv06 virus, scan, scanner, schei, schritte, seite, virenscan, virenscanner, virus, virus eingefangen |