![]() |
|
Plagegeister aller Art und deren Bekämpfung: Ärgerliches Textdokument (Agent.log)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Ärgerliches Textdokument (Agent.log) Hi, Screenshot bitte, ebenso einen Screenshot von Rechtsklick/Eigenschaften von dem Dokument. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #2 |
![]() | ![]() Ärgerliches Textdokument (Agent.log)Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by Alex at 2013-10-04 10:14:09 Running from D:\Bilder Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: FireWall (Enabled) {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57} ==================== Installed Programs ====================== ASRock App Charger v1.0.5 Avira Internet Security (x32 Version: 13.0.0.4052) Battlefield 4™ Beta (x32 Version: 1.0.0.0) Battlelog Web Plugins (x32 Version: 2.3.0) CyberLink Media Suite 10 (x32 Version: 10.0) CyberLink Media Suite 10 (x32 Version: 10.2021) CyberLink Power2Go 7 (x32 Version: 7.0.0.3126b) CyberLink PowerDVD 10 (x32 Version: 10.0.4125.52) ESN Sonar (x32 Version: 0.70.4) FIFA 14 (x32 Version: 1.0.0.1) Google Chrome (x32 Version: 30.0.1599.66) Google Update Helper (x32 Version: 1.3.21.153) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.36702) Intel(R) Management Engine Components (x32 Version: 9.0.0.1323) Intel(R) Network Connections 18.2.63.0 (Version: 18.2.63.0) Intel(R) Rapid Storage Technology (Version: 12.6.0.1033) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 2.0.0.102) Intel® Trusted Connect Service Client (Version: 1.27.798.1) Metro: Last Light (x32) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) NVIDIA Grafiktreiber 331.40 (Version: 331.40) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.133.902) NVIDIA PhysX (x32 Version: 9.12.1031) NVIDIA Systemsteuerung 331.40 (Version: 331.40) Open Broadcaster Software (x32) Origin (x32 Version: 9.3.1.4482) PunkBuster Services (x32 Version: 0.993) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6873) Spotify (HKCU Version: 0.9.4.169.gc0399df6) Steam (x32 Version: 1.0.0.0) TeamSpeak 3 Client (Version: 3.0.13) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) VC_CRT_x64 (Version: 1.02.0000) ==================== Restore Points ========================= 03-10-2013 09:14:09 Windows Update 03-10-2013 09:14:29 Windows Update 03-10-2013 09:16:41 Windows Update 03-10-2013 11:00:46 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte 03-10-2013 16:14:05 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {B36C6E83-8D7E-4052-B1EA-94454BF293CD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-09] (Google Inc.) Task: {C770CBDB-7427-4753-B756-1ACCEB42D7FD} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-14] (Intel Corporation) Task: {E996C53F-37CB-40EC-BA3E-63D0F55271E8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-09] (Google Inc.) Task: {F9E43F8C-1848-4EF7-8D3B-FE2C9C6482F1} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-14] (Intel Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-09 23:17 - 2013-09-09 23:15 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2011-03-09 14:21 - 2011-03-09 14:21 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2011-03-09 14:21 - 2011-03-09 14:21 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-09-09 23:17 - 2013-09-09 23:15 - 00447848 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\libxml2.dll 2013-09-09 23:17 - 2013-09-09 23:15 - 00060264 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\cares.dll 2013-10-02 23:59 - 2013-09-26 21:07 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.66\libglesv2.dll 2013-10-02 23:59 - 2013-09-26 21:07 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.66\libegl.dll 2013-10-02 23:59 - 2013-09-26 21:08 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.66\pdf.dll 2013-10-02 23:59 - 2013-09-26 21:08 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.66\ppGoogleNaClPluginChrome.dll 2013-10-02 23:59 - 2013-09-26 21:07 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.66\ffmpegsumo.dll 2013-10-02 23:59 - 2013-09-26 21:08 - 13611984 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.66\PepperFlash\pepflashplayer.dll 2013-09-09 21:53 - 2013-03-12 13:19 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/04/2013 10:07:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 01:04:07 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 00:41:05 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 00:32:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:19:19 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:16:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:13:20 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:12:13 AM) (Source: Windows Search Service) (User: ) Description: Die Liste der eingeschlossenen und ausgeschlossenen Adressen konnte vvon Windows Search nicht verarbeitet werden. Fehler: <30, 0x80040d07, "iehistory://{S-1-5-21-1535985635-845200926-562689151-1000}/">. Error: (10/03/2013 10:34:00 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/02/2013 08:51:58 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.0.0.0, Zeitstempel: 0x5242fdca Name des fehlerhaften Moduls: bf4.exe, Version: 1.0.0.0, Zeitstempel: 0x5242fdca Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000cddbee ID des fehlerhaften Prozesses: 0x1444 Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 System errors: ============= Error: (10/03/2013 10:32:15 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (10/03/2013 10:32:15 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (10/03/2013 10:32:15 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (10/03/2013 10:32:15 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (10/03/2013 10:32:15 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (10/01/2013 10:56:39 PM) (Source: MEIx64) (User: ) Description: Intel(R) Management Engine Interface driver has failed to perform handshake with the Firmware. Error: (09/24/2013 06:55:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (09/24/2013 06:55:03 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (09/22/2013 06:18:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira FireWall" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/22/2013 09:59:25 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= Error: (10/04/2013 10:07:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 01:04:07 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 00:41:05 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 00:32:35 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:19:19 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:16:52 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:13:20 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/03/2013 11:12:13 AM) (Source: Windows Search Service)(User: ) Description: 300x80040d07iehistory://{S-1-5-21-1535985635-845200926-562689151-1000}/ Error: (10/03/2013 10:34:00 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/02/2013 08:51:58 PM) (Source: Application Error)(User: ) Description: bf4.exe1.0.0.05242fdcabf4.exe1.0.0.05242fdcac00000050000000000cddbee144401cebf9e2578cba7C:\Program Files (x86)\Origin Games\Battlefield 4 Beta\bf4.exeC:\Program Files (x86)\Origin Games\Battlefield 4 Beta\bf4.exeb6c82e46-2b93-11e3-a37e-bc5ff4c857e2 ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 8122.58 MB Available physical RAM: 6355.22 MB Total Pagefile: 16243.34 MB Available Pagefile: 14181.84 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:41.15 GB) NTFS Drive d: (Volume) (Fixed) (Total:931.39 GB) (Free:884.61 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 65E97034) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 932 GB) (Disk ID: 1452E9E6) Partition: GPT Partition Type ==================== End Of Log ============================ |
![]() | #3 |
![]() | ![]() Ärgerliches Textdokument (Agent.log) Hier noch die 2 Screenshots , aber bei dem FRST Dokument wird mir gesagt das ich es nicht posten könnte weil es zu lang wäre
__________________ |
![]() |
Themen zu Ärgerliches Textdokument (Agent.log) |
agent, antwort, antworten, benutzer, bereits, dicken, dokument, einfach, erklären, gelöscht, guten, interne, internet, leer, löschen, nennt, neu, nicht löschen, ordner, rechner, riesig, textdokument, thema, titel, warum, worte |