![]() |
| |||||||
Log-Analyse und Auswertung: Ebay Mahnung Mail Anhang geöffnetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| | Ebay Mahnung Mail Anhang geöffnet Hallo, meine Freundin hat an eine Mail mit einer angeblichen Mahnung von Ebay-Anwälten bekommen, hat aus Panik natürlich direkt den Anhang geöffnet und jetzt evtl nen Trojaner drauf? Ich habe bis jetzt wie in eurer Anleitung beschrieben defogger, frst und GMER drüberlaufen lassen. Die Logs dazu: FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Puschel (administrator) on KÖÖRRRT on 26-06-2014 23:13:36
Running from C:\Users\Puschel\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-2799476594-3240853191-3070442433-1002\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323895&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFC3980F7-DD7B-4E02-9782-CE5F08F4EC13&q={searchTerms}&SSPV=
SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default
FF NewTab: about:blank
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js
FF SearchPlugin: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19]
FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-26 23:13 - 2014-06-26 23:13 - 00011904 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:11 - 2014-06-26 23:13 - 00000000 ____D () C:\FRST
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:00 - 2014-06-26 22:01 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-06-26 23:13 - 2014-06-26 23:13 - 00011904 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:13 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST
2014-06-26 23:11 - 2013-09-16 15:13 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002
2014-06-26 23:11 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat
2014-06-26 23:11 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat
2014-06-26 23:11 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 23:10 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel
2014-06-26 23:07 - 2014-01-19 17:36 - 00000000 ____D () C:\Users\Puschel\AppData\Roaming\newnext.me
2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-26 23:06 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 23:04 - 2013-09-16 15:06 - 01681996 _____ () C:\Windows\WindowsUpdate.log
2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-26 23:02 - 2012-10-19 22:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew
2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini
2014-06-26 22:58 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:02 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-26 22:01 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore
2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe
C:\Users\Puschel\AppData\Local\Temp\avgnt.exe
C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe
C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe
C:\Users\Puschel\AppData\Local\Temp\nse6761.exe
C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe
C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe
C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe
C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe
C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe
C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe
C:\Users\Puschel\AppData\Local\Temp\ose00000.exe
C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-26 21:59
==================== End Of Log ============================
GMER Beim Start von GMER kam direkt die Fehlermeldung "C:\Windows\System32\config\system Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird." Ich konnte danach aber ganz normal scannen. Nach dem Scan kam die gleiche Fehlermeldung für den Pfad C:\Users\Puschel\ntuser.dat Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-26 23:39:37
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002e TOSHIBA_MQ01ABD100 rev.AX001C 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Puschel\AppData\Local\Temp\kfroqpob.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [576:612] fffff9600092c5e8
Thread [1512:1528] 00000000773d50a7
Thread [1512:1536] 00000000749c8064
Thread [1512:1560] 00000000746bbfb4
Thread [1512:1576] 00000000746bbfb4
Thread [1512:1580] 00000000746bbfb4
Thread [1512:1584] 00000000746bbfb4
Thread [1512:1600] 00000000745f304c
---- Processes - GMER 2.1 ----
Library C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll (*** suspicious ***) @ C:\Windows\SysWOW64\rundll32.exe [2532] (NewNext Helper Engine/NewNextDotMe)(2014-01-19 15:36:14) 0000000072000000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.06.2014 Scan Time: 00:07:28 Logfile: mbam.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.26.09 Rootkit Database: v2014.06.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8 CPU: x64 File System: NTFS User: Puschel Scan Type: Threat Scan Result: Completed Objects Scanned: 265594 Time Elapsed: 10 min, 30 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 7 PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [ce439edf7b0087afb1df182ef012659b], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, , [7a97b7c6a8d3e6503680f5dae220f60a], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT2, , [b25f88f5691264d2a2155f70e81ae020], Registry Values: 3 PUP.Optional.NextLive.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, , [62af077605763105851e9abf31d04cb4] PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, , [7a97b7c6a8d3e6503680f5dae220f60a] PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2799476594-3240853191-3070442433-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT2|Install, 1, , [b25f88f5691264d2a2155f70e81ae020] Registry Data: 0 (No malicious items detected) Folders: 3 PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\cache, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.BuzzIT.A, C:\Program Files (x86)\Buzz-it, , [3fd2bcc14437e056554da9fb4bb746ba], Files: 21 PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll, , [62af077605763105851e9abf31d04cb4], PUP.Optional.OutBrowse, C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe, , [69a8a0dd9ddeb58199bcea6172909e62], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6761.exe, , [20f1e39adc9f5fd7275215193fc247b9], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe, , [f51c601da7d4191df188929cac55e917], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe, , [25ec7b02ff7cde58a7d26ec034cda45c], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe, , [d43d017c1d5e50e69bde1519fe039c64], PUP.Optional.SnapDo.A, C:\Users\Puschel\AppData\Local\Temp\Installer.msi, , [2de41469403bb2849eee0088a25f7789], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe, , [21f086f78bf0e94ddacd26fb877a857b], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe, , [32dfcfae1f5c96a0f881b27c986945bb], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe, , [36db2d50017a64d2ef8a4ee08879f907], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe, , [e52cfd8044371c1a9edb4fdfd62bd729], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe, , [739e86f75625f244354463cb5da4cd33], PUP.Optional.SearchProtect.A, C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe, , [838e196442390b2bd6a371bd9d649070], PUP.Optional.Outbrowse, C:\Users\Puschel\AppData\Local\Temp\l0ox0hvJ.exe.part, , [759ca3da1a612e08755211fe4bb9eb15], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Local\genienext\nengine.dll, , [db36ed907efd40f62a79154436cb3ac6], PUP.Optional.Conduit.A, C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml, , [a46d75083b403105425714b1c73b26da], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\etxbsbelsd.pre, , [a9682f4eef8c360050eae8f11ce606fa], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\luahfxqpmy.pre, , [1df4aecf8eede94dd06a42970ef40df3], Trojan.Downloader.Gen, C:\Users\Puschel\AppData\Local\Temp\tyuhssockk.pre, , [c34e5429057691a5be7ce6f31de5c23e], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.cookie, , [ec252a53e794ca6ca0f5bed6ff038c74], PUP.Optional.NextLive.A, C:\Users\Puschel\AppData\Roaming\newnext.me\cache\spark.bin, , [ec252a53e794ca6ca0f5bed6ff038c74], Physical Sectors: 0 (No malicious items detected) (end) Grüße |
| | #2 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet![]() Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das... ![]()
Hinweis:Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst.Los geht's: Bitte auch die Addition.txt posten... Schritt 1 ![]() Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________ |
| | #3 |
| | Ebay Mahnung Mail Anhang geöffnet Hier die Addition.txt
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2014
Ran by Puschel at 2014-06-27 10:01:43
Running from C:\Users\Puschel\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.)
AMD Accelerated Video Transcoding (Version: 12.5.100.20918 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{3CEC10BE-CD7C-8E99-E3AC-DD31F4416C1C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden
AMD VISION Engine Control Center (x32 Version: 2012.0918.260.3365 - Ihr Firmenname) Hidden
AutomationML Editor (HKLM-x32\...\{1FF9E567-7A33-4278-87D3-2CB2E0E07DC9}) (Version: 3.0.0 - AutomationML)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.0918.0259.3365 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.0918.260.3365 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.2.5712 - CyberLink Corp.) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.)
CyberLink Media Suite 10 (x32 Version: 10.0.2.2114 - CyberLink Corp.) Hidden
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.)
CyberLink PhotoDirector (x32 Version: 2.0.2.3317 - CyberLink Corp.) Hidden
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.2.2110 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.2.2126 - CyberLink Corp.) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.7.4528 - CyberLink Corp.)
CyberLink PowerDVD (x32 Version: 10.0.7.4528 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.5.5811 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{2DEDBE5B-D538-43F3-83A7-B037D6B51A89}) (Version: 4.2.8.1 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Postscript Converter (Version: 3.1.3591 - Hewlett-Packard) Hidden
HP Recovery Manager (x32 Version: 8.00 - Hewlett-Packard) Hidden
HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.6.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Language Pack 2007 - German/Deutsch (HKLM-x32\...\OMUI.de-de) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)
VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
==================== Restore Points =========================
04-05-2014 14:04:18 Geplanter Prüfpunkt
26-06-2014 20:51:10 Microsoft Office wird entfernt
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2A12643D-F816-4B74-9A8C-BFDEBD2F94C3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {665ABA0F-C344-4F9D-84DF-A4B54EE8BFAA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company)
Task: {6A135F4B-F40B-450A-B411-6107AE3BE08F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink)
Task: {75FDDF18-9E8C-4DAA-A853-5DDA76EBAAE7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-18] (Adobe Systems Incorporated)
Task: {77D9D4FF-08A3-4CBB-A530-D72BA2C5AC46} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe
Task: {895E8F71-0D37-41A9-BC80-F6880C747D2C} - System32\Tasks\HPGenoobeReminder => C:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HP GenOOBE\HPGenOOBE.exe
Task: {8C8824B8-BBAE-4997-A40C-5DBB12B8122A} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AF8D4BBF-73F2-46FC-A798-06875FBCD3ED} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {B81FF858-55E7-4D9F-A91D-751724FD10BB} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {C515F61B-3573-490A-B552-98081D50927C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-09-18 04:12 - 2012-09-18 04:12 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2012-09-18 04:11 - 2012-09-18 04:11 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-09-18 03:58 - 2012-09-18 03:58 - 00369664 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-09-24 12:40 - 2014-06-11 14:33 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-03-27 04:46 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e78
Startzeit: 01cf9187bafb614c
Endzeit: 0
Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
Berichts-ID: 3faa6cf6-fd80-11e3-be8b-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/26/2014 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77045f8c
ID des fehlerhaften Prozesses: 0xed0
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (06/26/2014 10:01:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77045f8c
ID des fehlerhaften Prozesses: 0x898
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (06/26/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77045f8c
ID des fehlerhaften Prozesses: 0xbe8
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (05/15/2014 08:40:17 AM) (Source: MsiInstaller) (EventID: 1024) (User: Köörrrt)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011007}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
Error: (03/16/2014 07:21:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: b28
Startzeit: 01cf2ff0d0a57d80
Endzeit: 4294967295
Anwendungspfad: C:\Windows\syswow64\wwahost.exe
Berichts-ID: 4bc14c45-ad2f-11e3-be81-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (03/16/2014 06:26:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Das Paket „Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (02/03/2014 04:33:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 440
Startzeit: 01cf20037ea29089
Endzeit: 4294967295
Anwendungspfad: C:\Windows\syswow64\wwahost.exe
Berichts-ID: bd83e931-8cdf-11e3-be80-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (02/03/2014 04:30:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Das Paket „Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (02/01/2014 08:40:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 58c
Startzeit: 01cf1f638ae820c7
Endzeit: 4294967295
Anwendungspfad: C:\Windows\syswow64\wwahost.exe
Berichts-ID: 4e339a66-8b70-11e3-be80-7446a0822eb5
Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
System errors:
=============
Error: (06/27/2014 09:53:01 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 27.06.2014 um 00:27:12 unerwartet heruntergefahren.
Error: (06/26/2014 11:33:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Audio Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/26/2014 11:28:22 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 26.06.2014 um 23:15:30 unerwartet heruntergefahren.
Error: (06/17/2014 08:22:12 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (05/14/2014 10:16:26 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 13.05.2014 um 17:21:33 unerwartet heruntergefahren.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/03/2014 09:16:56 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (05/01/2014 09:16:42 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Microsoft Office Sessions:
=========================
Error: (06/27/2014 00:21:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: mbam.exe1.0.0.532e7801cf9187bafb614c0C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe3faa6cf6-fd80-11e3-be8b-7446a0822eb5
Error: (06/26/2014 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8ced001cf917967b2de1fC:\Windows\SysWOW64\svchost.exeunknowna731f674-fd6c-11e3-be88-7446a0822eb5
Error: (06/26/2014 10:01:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8c89801cf91795f05f585C:\Windows\SysWOW64\svchost.exeunknown9e82ac94-fd6c-11e3-be88-7446a0822eb5
Error: (06/26/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000577045f8cbe801cf91794a8f9f9fC:\Windows\SysWOW64\svchost.exeunknown8a3672cb-fd6c-11e3-be88-7446a0822eb5
Error: (05/15/2014 08:40:17 AM) (Source: MsiInstaller) (EventID: 1024) (User: Köörrrt)
Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011007}1625(NULL)(NULL)(NULL)
Error: (03/16/2014 07:21:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.2.9200.16420b2801cf2ff0d0a57d804294967295C:\Windows\syswow64\wwahost.exe4bc14c45-ad2f-11e3-be81-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp
Error: (03/16/2014 06:26:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Error: (02/03/2014 04:33:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.2.9200.1642044001cf20037ea290894294967295C:\Windows\syswow64\wwahost.exebd83e931-8cdf-11e3-be80-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp
Error: (02/03/2014 04:30:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Köörrrt)
Description: Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5c
Error: (02/01/2014 08:40:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.2.9200.1642058c01cf1f638ae820c74294967295C:\Windows\syswow64\wwahost.exe4e339a66-8b70-11e3-be80-7446a0822eb5Microsoft.SkypeApp_1.9.0.2016_x86__kzf8qxf38zg5cApp
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 7650.26 MB
Available physical RAM: 6198.35 MB
Total Pagefile: 9954.26 MB
Available Pagefile: 8404.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:914.06 GB) (Free:876.14 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:16.68 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: D4AD0251)
Partition: GPT Partition Type.
==================== End Of Log ============================
Die neue FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Puschel (administrator) on KÖÖRRRT on 27-06-2014 10:01:10
Running from C:\Users\Puschel\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-2799476594-3240853191-3070442433-1002\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Puschel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323895&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFC3980F7-DD7B-4E02-9782-CE5F08F4EC13&q={searchTerms}&SSPV=
SearchScopes: HKCU - {04897A7A-AB7F-4DDF-9318-0B5088CF50D2} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default
FF NewTab: about:blank
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\user.js
FF SearchPlugin: C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-19]
FF Extension: Adblock Plus - C:\Users\Puschel\AppData\Roaming\Mozilla\Firefox\Profiles\j7a7i4b6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-17] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-17] (Avira Operations GmbH & Co. KG)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-28] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-10] (Disc Soft Ltd)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-27] (Malwarebytes Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-25] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-25] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt
2014-06-26 23:43 - 2014-06-27 00:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-26 23:43 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-26 23:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt
2014-06-26 23:14 - 2014-06-27 09:59 - 00025923 _____ () C:\Users\Puschel\Desktop\Addition.txt
2014-06-26 23:13 - 2014-06-27 10:01 - 00011745 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-26 23:11 - 2014-06-27 10:01 - 00000000 ____D () C:\FRST
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:00 - 2014-06-26 22:01 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
==================== One Month Modified Files and Folders =======
2014-06-27 10:01 - 2014-06-26 23:13 - 00011745 _____ () C:\Users\Puschel\Desktop\FRST.txt
2014-06-27 10:01 - 2014-06-26 23:11 - 00000000 ____D () C:\FRST
2014-06-27 10:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-27 09:59 - 2014-06-26 23:14 - 00025923 _____ () C:\Users\Puschel\Desktop\Addition.txt
2014-06-27 09:59 - 2012-10-20 07:07 - 00830120 _____ () C:\Windows\system32\perfh007.dat
2014-06-27 09:59 - 2012-10-20 07:07 - 00188224 _____ () C:\Windows\system32\perfc007.dat
2014-06-27 09:59 - 2012-07-26 09:28 - 01949368 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-27 09:53 - 2014-01-19 17:36 - 00000000 ____D () C:\Users\Puschel\AppData\Roaming\newnext.me
2014-06-27 09:53 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-27 00:21 - 2014-06-27 00:21 - 00005709 _____ () C:\mbam.txt
2014-06-27 00:21 - 2014-06-26 23:43 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-27 00:18 - 2013-09-16 15:13 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2799476594-3240853191-3070442433-1002
2014-06-26 23:43 - 2014-06-26 23:43 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-26 23:43 - 2014-06-26 23:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-26 23:41 - 2013-09-16 15:06 - 01812375 _____ () C:\Windows\WindowsUpdate.log
2014-06-26 23:39 - 2014-06-26 23:39 - 00002446 _____ () C:\Users\Puschel\Desktop\GMER.txt
2014-06-26 23:37 - 2014-04-14 18:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-26 23:19 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-26 23:10 - 2014-06-26 23:10 - 00000546 _____ () C:\Users\Puschel\Desktop\defogger_disable.log
2014-06-26 23:10 - 2014-06-26 23:10 - 00000168 _____ () C:\Users\Puschel\defogger_reenable
2014-06-26 23:10 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel
2014-06-26 23:06 - 2014-03-18 15:33 - 00437408 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 23:05 - 2013-09-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 23:04 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-26 23:03 - 2014-04-10 19:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-26 23:02 - 2012-08-04 00:37 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-26 23:00 - 2012-07-26 09:52 - 00000000 ____D () C:\Windows\ShellNew
2014-06-26 23:00 - 2012-07-26 07:26 - 00000076 _____ () C:\Windows\win.ini
2014-06-26 22:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 22:48 - 2014-06-26 22:48 - 02082816 _____ (Farbar) C:\Users\Puschel\Desktop\FRST64.exe
2014-06-26 22:48 - 2014-06-26 22:48 - 00380416 _____ () C:\Users\Puschel\Desktop\Gmer-19357.exe
2014-06-26 22:47 - 2014-06-26 22:47 - 00050477 _____ () C:\Users\Puschel\Desktop\Defogger.exe
2014-06-26 22:28 - 2014-06-26 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Puschel\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-26 22:01 - 2014-06-26 22:00 - 00000000 ____D () C:\Users\Puschel\AppData\Local\CrashDumps
2014-06-26 22:00 - 2013-09-16 15:06 - 00000000 ____D () C:\Users\Puschel\AppData\Local\VirtualStore
2014-06-17 20:03 - 2013-09-24 12:47 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-17 20:03 - 2013-09-24 12:47 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Puschel\AppData\Local\Temp\6_Offer_15.exe
C:\Users\Puschel\AppData\Local\Temp\avgnt.exe
C:\Users\Puschel\AppData\Local\Temp\BackupSetup.exe
C:\Users\Puschel\AppData\Local\Temp\DownloadManager.exe
C:\Users\Puschel\AppData\Local\Temp\nse6761.exe
C:\Users\Puschel\AppData\Local\Temp\nse6BB5.exe
C:\Users\Puschel\AppData\Local\Temp\nse8D89.exe
C:\Users\Puschel\AppData\Local\Temp\nsq2AAE.exe
C:\Users\Puschel\AppData\Local\Temp\nsu64B2.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6C52.exe
C:\Users\Puschel\AppData\Local\Temp\nsu6E75.exe
C:\Users\Puschel\AppData\Local\Temp\nsy69C0.exe
C:\Users\Puschel\AppData\Local\Temp\nsy8B94.exe
C:\Users\Puschel\AppData\Local\Temp\ose00000.exe
C:\Users\Puschel\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\Puschel\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-27 00:27
==================== End Of Log ============================
|
| | #4 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet Schritt 1
__________________ Gruß deeprybka ![]() Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
| | #5 |
| | Ebay Mahnung Mail Anhang geöffnet Inhalt der MBRMastr_2014.06.27_14.47.55: Code:
ATTFilter Detected Windows version: 6.2 Build 9200
Driver connection handle: 0x00000148
1 valid drive(s) found.
Details for Disk 0 - TOSHIBA MQ01ABD100 Rev AX001C:
Device name : \\.\PhysicalDrive0
Geometry (C/H/S) : 121601/255/63
Boot loader reputation : Unknown
Cross view comparison : Passed
Partition table integrity: Passed
Boot loader hashes
SHA-1 : 639AC5CDF8A5CF3245975932C6A4215450A7B98F
MD5 : 5FB38429D5D77768867C76DCBDB35194
|
| | #6 |
| /// TB-Ausbilder /// Anleitungs-Guru ![]() ![]() ![]() ![]() ![]() | Ebay Mahnung Mail Anhang geöffnet Schritt 1 Downloade Dir bitte
Schritt 2 Scan mit Unter Erkennung und Schutz setze bitte einen Haken bei "Suche nach Rootkits". Klicke im Anschluss auf "Suchlauf", wähle den Bedrohungssuchlauf aus, aktualisiere die Datenbanken und klicke auf "Suchlauf jetzt starten". Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. (geht so...) Poste mir den Inhalt der Logdatei. Klicke dazu auf Verlauf und dann auf Anwendungsprotokolle. Wähle das neueste Suchlauf-Protokoll aus und klicke auf Ansicht. Klicke auf "In Zwischenablage kopieren" poste mir den Inhalt in Code-Tags als Antwort in den Thread. Schritt 3 ESET Online Scanner
Schritt 4 ![]() Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden. Gibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?
__________________ --> Ebay Mahnung Mail Anhang geöffnet |
![]() |