![]() |
| |||||||
Log-Analyse und Auswertung: Windows 7 - Ausschließlich Verknüpfungen auf USB-SpeichernWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7 - Ausschließlich Verknüpfungen auf USB-Speichern Der Mist ist da immer noch drin. Dann bitte jetzt Combofix ausführen: Scan mit Combofix
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #2 |
![]() | Windows 7 - Ausschließlich Verknüpfungen auf USB-Speichern Hier die logfile:
__________________Code:
ATTFilter ComboFix 14-06-30.01 - A 01.07.2014 13:00:05.2.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3067.2152 [GMT 2:00]
ausgeführt von:: c:\users\A\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-06-01 bis 2014-07-01 ))))))))))))))))))))))))))))))
.
.
2014-07-01 11:06 . 2014-07-01 11:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-01 08:00 . 2014-07-01 08:00 -------- d-----w- c:\users\A\AppData\Roaming\phonostar GmbH
2014-07-01 08:00 . 2014-07-01 08:00 -------- d-----w- c:\program files\dradio-Recorder
2014-06-30 19:23 . 2014-06-30 19:23 -------- d-----w- c:\program files\ESET
2014-06-30 14:53 . 2014-07-01 09:36 -------- d-----w- C:\FRST
2014-06-27 10:00 . 2014-06-27 10:00 -------- d-----w- c:\programdata\Panda Security
2014-06-27 10:00 . 2014-06-27 10:00 -------- d-----w- c:\program files\Panda USB Vaccine
2014-06-27 09:37 . 2014-06-30 19:09 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-06-27 09:37 . 2014-06-30 19:09 -------- d-----w- c:\program files\ Malwarebytes Anti-Malware
2014-06-27 09:37 . 2014-06-27 09:37 -------- d-----w- c:\programdata\Malwarebytes
2014-06-27 09:37 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-06-27 09:37 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-06-27 09:37 . 2014-05-12 05:25 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-06-26 07:14 . 2013-12-06 18:01 389290 ----a-w- c:\users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\java ska.vbs
2014-06-15 11:33 . 2014-05-30 09:18 696832 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2014-06-11 23:00 . 2014-05-08 09:06 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-11 23:00 . 2014-05-08 09:06 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-24 09:52 . 2014-03-18 16:02 97648 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-06-20 04:45 . 2014-04-13 10:17 588496 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2014-06-13 08:25 . 2014-03-18 16:22 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-13 08:25 . 2014-03-18 16:22 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-05-20 08:07 . 2014-03-18 16:02 136216 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-04-30 18:29 . 2014-03-18 16:31 1081112 ----a-w- c:\windows\system32\nvspcap.dll
2014-04-17 18:50 . 2014-03-18 17:40 155136 ----a-w- c:\windows\system32\unrar.dll
2014-04-12 02:15 . 2014-05-17 18:24 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:15 . 2014-05-17 18:24 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:12 . 2014-05-17 18:24 15872 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:12 . 2014-05-17 18:24 100352 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:12 . 2014-05-17 18:24 22016 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:11 . 2014-05-17 18:24 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:11 . 2014-05-17 18:24 22528 ----a-w- c:\windows\system32\lsass.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-06-20 04:45 1730264 ----a-w- c:\program files\Microsoft Office 15\root\office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-06-20 04:45 1730264 ----a-w- c:\program files\Microsoft Office 15\root\office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-06-20 04:45 1730264 ----a-w- c:\program files\Microsoft Office 15\root\office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dradio-RecorderTimer"="c:\program files\dradio-Recorder\phonostarTimer.exe" [2012-10-13 42496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-06-24 750160]
.
c:\users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
java ska.vbs [2013-12-6 389290]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-05-30 108032]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2014-02-25 37352]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-06-24 430160]
S2 ClickToRunSvc;Microsoft Office-Klick-und-Los-Dienst;c:\program files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [2014-05-21 1565880]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-04-30 1618888]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-04-30 19701080]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
S3 k57nd60x;Broadcom NetLink (TM)-Gigabit-Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 NETw5s32;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 32-Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-04-30 19400]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2014-03-31 34080]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
.
------- Zusätzlicher Suchlauf -------
.
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 141.30.217.10 141.30.66.135
FF - ProfilePath - c:\users\A\AppData\Roaming\Mozilla\Firefox\Profiles\qo9lgtqg.default\
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-07-01 13:11:17
ComboFix-quarantined-files.txt 2014-07-01 11:11
ComboFix2.txt 2014-07-01 10:46
.
Vor Suchlauf: 10 Verzeichnis(se), 385.464.000.512 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 385.418.326.016 Bytes frei
.
- - End Of File - - 2C186EE04505BAB4CFEC0F3EAF8AEAF6
A36C5E4F47E84449FF07ED3517B43A31
An dieser Stelle schon mal ein "Zwischen-Danke" für die hohe Frequenz deiner Posts! ![]() edit: Keine Probleme beim Neustart. Geändert von Karlo12 (01.07.2014 um 12:13 Uhr) |
![]() |
| Themen zu Windows 7 - Ausschließlich Verknüpfungen auf USB-Speichern |
| association, converter, defender, desktop, dvdvideosoft ltd., firefox, flash player, neustart, office 365, panda usb vaccine, programm, registry, services.exe, software, svchost.exe, temp, tracker, updates, vbs/kryptik.af, warnung, win32/bundled.toolbar.ask.d, win32/downloadsponsor.a, windows, winlogon.exe |