![]() |
|
Plagegeister aller Art und deren Bekämpfung: Virenscans hängen sich auf, verseuchter PC?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() Virenscans hängen sich auf, verseuchter PC? Hallo! Vorgestern habe ich mal wieder Antivir durchlaufen lassen, weil man Laptop gerne einfach mal so abgestürzt ist. Dieses hat jedoch nur bis zu, ich glaube 70%, des Systems geschafft und hat sich dann aufhangen, jedoch wurden noch 4 Java-Viren gefunden. Darüber habe ich mich schlau gemacht und diese auch entfernt, natürlich wollte ich jetzt aber nochmal einen kompletten Scan, doch dieser hängte sich wieder auf, Funde gab es zwar keine, aber es wurde ja auch nicht alles durchsucht. Danach habe ich versucht mit Malwarebytes einen Komplettscan zu machen, dieser hat sich aber nach 40 Minuten Laufzeit auch verabschiedet. Der Laptop hängt sich auf, Maus stockt, Strg+Alt+Entf ist auch nicht mehr möglich, mir bleibt immer noch der Aus-Knopf. Danach hat Vista die Festplatte C schon einige Male auf Konsistenz geprüft, jedoch nichts gravierendes angezeigt. Antivir läuft an sich, updatet auch, der Laptop läuft so aktuell auch in Ordnung. Er scheint mir nur langsamer geworden zu sein, wobei dies auch meiner unendlichen Panik liegen kann. Jedoch konnte ich RSIT benutzen und habe hier auch die Logs: Code:
ATTFilter Logfile of random's system information tool 1.06 (written by random/random) Run by *** at 2010-02-27 13:46:55 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 92 GB (77%) free of 119 GB Total RAM: 2038 MB (64% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:47:04, on 27.02.2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v7.00 (7.00.6002.18005) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\ASUS\ASUS Live Update\ALU.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\ATKOSD2\ATKOSD2.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Users\***\Downloads\RSIT.exe C:\Program Files\Trend Micro\HijackThis\Merle.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Softonic Deutsch FF Toolbar - {9d81af43-de53-48d0-a199-42c2a226b24c} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Softonic Deutsch FF Toolbar - {9d81af43-de53-48d0-a199-42c2a226b24c} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe" O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7.0\ICQ.exe" silent loginmode=4 O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O13 - Gopher Prefix: O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- End of file - 6485 bytes ======Scheduled tasks folder====== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d81af43-de53-48d0-a199-42c2a226b24c}] Softonic Deutsch FF Toolbar - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll [2009-11-09 2331672] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {9d81af43-de53-48d0-a199-42c2a226b24c} - Softonic Deutsch FF Toolbar - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll [2009-11-09 2331672] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184] "ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-18 7737344] "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-31 4702208] "Skytel"=C:\Windows\Skytel.exe [2007-10-11 1826816] "SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-02-26 141848] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-02-26 173592] "Persistence"=C:\Windows\system32\igfxpers.exe [2009-02-26 150552] "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280] "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2009-10-03 39792] "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-03-18 2289664] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952] "Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2009-06-23 434176] "ICQ"=D:\Program Files\ICQ7.0\ICQ.exe [2010-02-11 133368] "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2009-02-26 210432] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1143a93e-285a-11de-843a-002215568405}] shell\1\command - F:\.\recycled\info.exe shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\.\recycled\info.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd8f27dd-2acc-11de-aded-002215568405}] shell\1\command - F:\.\recycled\info.exe shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\.\recycled\info.exe ======List of files/folders created in the last 1 months====== 2010-02-27 13:46:55 ----D---- C:\rsit 2010-02-27 13:00:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2010-02-27 12:54:18 ----D---- C:\Program Files\CCleaner 2010-02-27 12:42:15 ----D---- C:\Program Files\Trend Micro 2010-02-26 00:02:48 ----D---- C:\Program Files\ESET 2010-02-25 22:24:51 ----D---- C:\Users\Merle\AppData\Roaming\Malwarebytes 2010-02-25 22:24:42 ----D---- C:\ProgramData\Malwarebytes 2010-02-25 00:28:59 ----A---- C:\Windows\system32\tzres.dll 2010-02-25 00:28:02 ----A---- C:\Windows\system32\secproc_isv.dll 2010-02-25 00:28:02 ----A---- C:\Windows\system32\secproc.dll 2010-02-25 00:28:00 ----A---- C:\Windows\system32\RMActivate_isv.exe 2010-02-25 00:27:59 ----A---- C:\Windows\system32\secproc_ssp_isv.dll 2010-02-25 00:27:59 ----A---- C:\Windows\system32\secproc_ssp.dll 2010-02-25 00:27:59 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe 2010-02-25 00:27:59 ----A---- C:\Windows\system32\RMActivate_ssp.exe 2010-02-25 00:27:59 ----A---- C:\Windows\system32\RMActivate.exe 2010-02-25 00:27:59 ----A---- C:\Windows\system32\msdrm.dll 2010-02-25 00:27:52 ----A---- C:\Windows\system32\gameux.dll 2010-02-25 00:27:51 ----A---- C:\Windows\system32\Apphlpdm.dll 2010-02-25 00:27:50 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll 2010-02-24 19:17:56 ----D---- C:\Program Files\Windows Portable Devices 2010-02-24 01:47:41 ----A---- C:\Windows\system32\UIAnimation.dll 2010-02-24 01:47:40 ----A---- C:\Windows\system32\UIRibbonRes.dll 2010-02-24 01:47:40 ----A---- C:\Windows\system32\UIRibbon.dll 2010-02-24 01:47:02 ----A---- C:\Windows\system32\WMPhoto.dll 2010-02-24 01:47:01 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll 2010-02-24 01:47:01 ----A---- C:\Windows\system32\d3d10warp.dll 2010-02-24 01:47:01 ----A---- C:\Windows\system32\cdd.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\xpsservices.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\XpsRasterService.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\XpsPrint.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\XpsGdiConverter.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\WindowsCodecsExt.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\WindowsCodecs.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe 2010-02-24 01:47:00 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\OpcServices.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\dxdiagn.dll 2010-02-24 01:47:00 ----A---- C:\Windows\system32\dxdiag.exe 2010-02-24 01:47:00 ----A---- C:\Windows\system32\d2d1.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\FntCache.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\dxgi.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\DWrite.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\d3d11.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\d3d10level9.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\d3d10core.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\d3d10_1core.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\d3d10_1.dll 2010-02-24 01:46:59 ----A---- C:\Windows\system32\d3d10.dll 2010-02-24 01:46:31 ----A---- C:\Windows\system32\WPDShextAutoplay.exe 2010-02-24 01:46:31 ----A---- C:\Windows\system32\wpdbusenum.dll 2010-02-24 01:46:31 ----A---- C:\Windows\system32\BthMtpContextHandler.dll 2010-02-24 01:46:28 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\WPDSp.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\WPDShServiceObj.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\wpdshext.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\WpdMtpUS.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\WpdMtp.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\WpdConns.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\wpd_ci.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\PortableDeviceTypes.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll 2010-02-24 01:46:26 ----A---- C:\Windows\system32\PortableDeviceApi.dll 2010-02-24 01:45:16 ----A---- C:\Windows\system32\UIAutomationCore.dll 2010-02-24 01:45:16 ----A---- C:\Windows\system32\oleaccrc.dll 2010-02-24 01:45:16 ----A---- C:\Windows\system32\oleacc.dll 2010-02-22 21:35:33 ----D---- C:\Windows\system32\eu-ES 2010-02-22 21:35:33 ----D---- C:\Windows\system32\ca-ES 2010-02-22 21:35:31 ----D---- C:\Windows\system32\vi-VN 2010-02-15 16:25:50 ----D---- C:\Program Files\iPod 2010-02-15 16:21:46 ----D---- C:\Program Files\QuickTime 2010-02-15 01:08:57 ----A---- C:\Windows\movexe.exe 2010-02-10 18:19:51 ----A---- C:\Windows\system32\ntoskrnl.exe 2010-02-10 18:19:51 ----A---- C:\Windows\system32\ntkrnlpa.exe 2010-02-10 18:19:42 ----A---- C:\Windows\system32\tsbyuv.dll 2010-02-10 18:19:42 ----A---- C:\Windows\system32\quartz.dll 2010-02-10 18:19:42 ----A---- C:\Windows\system32\msyuv.dll 2010-02-10 18:19:42 ----A---- C:\Windows\system32\msvidc32.dll 2010-02-10 18:19:42 ----A---- C:\Windows\system32\msrle32.dll 2010-02-10 18:19:41 ----A---- C:\Windows\system32\msvfw32.dll 2010-02-10 18:19:41 ----A---- C:\Windows\system32\mciavi32.dll 2010-02-10 18:19:41 ----A---- C:\Windows\system32\iyuv_32.dll 2010-02-10 18:19:41 ----A---- C:\Windows\system32\avifil32.dll 2010-02-01 14:51:31 ----D---- C:\Program Files\DVDVideoSoft ======List of files/folders modified in the last 1 months====== 2010-02-27 13:46:57 ----D---- C:\Windows\Temp 2010-02-27 13:46:35 ----D---- C:\Users\Merle\AppData\Roaming\ICQ 2010-02-27 13:37:15 ----A---- C:\Windows\system32\acovcnt.exe 2010-02-27 13:01:03 ----D---- C:\Windows\system32\drivers 2010-02-27 13:00:59 ----RD---- C:\Program Files 2010-02-27 12:59:00 ----D---- C:\Windows\Minidump 2010-02-27 12:59:00 ----D---- C:\Windows\Debug 2010-02-27 12:59:00 ----D---- C:\Windows 2010-02-27 12:41:13 ----D---- C:\Windows\System32 2010-02-27 12:41:13 ----D---- C:\Windows\inf 2010-02-27 12:41:13 ----A---- C:\Windows\system32\PerfStringBackup.INI 2010-02-26 15:11:45 ----SHD---- C:\Windows\Installer 2010-02-26 00:02:50 ----SD---- C:\Windows\Downloaded Program Files 2010-02-25 22:24:42 ----HD---- C:\ProgramData 2010-02-25 22:09:09 ----D---- C:\Program Files\Mozilla Firefox 2010-02-25 20:32:25 ----SHD---- C:\System Volume Information 2010-02-25 20:09:53 ----D---- C:\Windows\Prefetch 2010-02-25 16:36:01 ----D---- C:\Windows\rescache 2010-02-25 16:18:38 ----D---- C:\Windows\system32\de-DE 2010-02-25 16:18:38 ----D---- C:\Windows\AppPatch 2010-02-25 16:18:37 ----RSD---- C:\Windows\Fonts 2010-02-25 13:52:17 ----D---- C:\Windows\winsxs 2010-02-25 13:50:52 ----D---- C:\Windows\system32\catroot 2010-02-25 00:27:18 ----D---- C:\Windows\system32\catroot2 2010-02-24 22:47:31 ----D---- C:\Users\Merle\AppData\Roaming\gtk-2.0 2010-02-24 19:20:19 ----D---- C:\Windows\system32\Tasks 2010-02-24 19:17:56 ----D---- C:\Windows\system32\wbem 2010-02-24 19:17:52 ----D---- C:\Windows\system32\zh-TW 2010-02-24 19:17:52 ----D---- C:\Windows\system32\zh-HK 2010-02-24 19:17:52 ----D---- C:\Windows\system32\zh-CN 2010-02-24 19:17:52 ----D---- C:\Windows\system32\uk-UA 2010-02-24 19:17:52 ----D---- C:\Windows\system32\tr-TR 2010-02-24 19:17:52 ----D---- C:\Windows\system32\th-TH 2010-02-24 19:17:52 ----D---- C:\Windows\system32\sv-SE 2010-02-24 19:17:52 ----D---- C:\Windows\system32\sr-Latn-CS 2010-02-24 19:17:52 ----D---- C:\Windows\system32\sl-SI 2010-02-24 19:17:52 ----D---- C:\Windows\system32\sk-SK 2010-02-24 19:17:52 ----D---- C:\Windows\system32\ru-RU 2010-02-24 19:17:52 ----D---- C:\Windows\system32\ro-RO 2010-02-24 19:17:52 ----D---- C:\Windows\system32\pt-PT 2010-02-24 19:17:52 ----D---- C:\Windows\system32\pt-BR 2010-02-24 19:17:52 ----D---- C:\Windows\system32\pl-PL 2010-02-24 19:17:52 ----D---- C:\Windows\system32\nl-NL 2010-02-24 19:17:52 ----D---- C:\Windows\system32\nb-NO 2010-02-24 19:17:52 ----D---- C:\Windows\system32\lv-LV 2010-02-24 19:17:52 ----D---- C:\Windows\system32\lt-LT 2010-02-24 19:17:52 ----D---- C:\Windows\system32\ko-KR 2010-02-24 19:17:52 ----D---- C:\Windows\system32\ja-JP 2010-02-24 19:17:52 ----D---- C:\Windows\system32\it-IT 2010-02-24 19:17:52 ----D---- C:\Windows\system32\hu-HU 2010-02-24 19:17:52 ----D---- C:\Windows\system32\hr-HR 2010-02-24 19:17:52 ----D---- C:\Windows\system32\he-IL 2010-02-24 19:17:52 ----D---- C:\Windows\system32\fr-FR 2010-02-24 19:17:52 ----D---- C:\Windows\system32\fi-FI 2010-02-24 19:17:52 ----D---- C:\Windows\system32\et-EE 2010-02-24 19:17:52 ----D---- C:\Windows\system32\es-ES 2010-02-24 19:17:52 ----D---- C:\Windows\system32\en-US 2010-02-24 19:17:52 ----D---- C:\Windows\system32\el-GR 2010-02-24 19:17:52 ----D---- C:\Windows\system32\da-DK 2010-02-24 19:17:52 ----D---- C:\Windows\system32\cs-CZ 2010-02-24 19:17:52 ----D---- C:\Windows\system32\bg-BG 2010-02-24 19:17:52 ----D---- C:\Windows\system32\ar-SA 2010-02-24 09:16:06 ----N---- C:\Windows\system32\MpSigStub.exe 2010-02-24 01:48:00 ----D---- C:\Windows\Microsoft.NET 2010-02-24 01:47:45 ----RSD---- C:\Windows\assembly 2010-02-22 21:44:55 ----SHD---- C:\Boot 2010-02-22 21:37:28 ----D---- C:\Program Files\Windows Calendar 2010-02-22 21:37:27 ----D---- C:\Program Files\Windows Mail 2010-02-22 21:37:27 ----D---- C:\Program Files\Movie Maker 2010-02-22 21:37:24 ----D---- C:\Program Files\Windows Sidebar 2010-02-22 21:37:24 ----D---- C:\Program Files\Windows Media Player 2010-02-22 21:37:24 ----D---- C:\Program Files\Internet Explorer 2010-02-22 21:37:23 ----D---- C:\Program Files\Windows Journal 2010-02-22 21:37:23 ----D---- C:\Program Files\Windows Collaboration 2010-02-22 21:37:20 ----D---- C:\Program Files\Windows Photo Gallery 2010-02-22 21:37:20 ----D---- C:\Program Files\Common Files\System 2010-02-22 21:37:14 ----D---- C:\Windows\servicing 2010-02-22 21:37:14 ----D---- C:\Program Files\Windows Defender 2010-02-22 21:37:13 ----D---- C:\Windows\ehome 2010-02-22 21:36:54 ----D---- C:\Windows\IME 2010-02-22 21:36:53 ----D---- C:\Windows\system32\XPSViewer 2010-02-22 21:36:46 ----D---- C:\Windows\system32\oobe 2010-02-22 21:36:45 ----D---- C:\Windows\system32\migration 2010-02-22 21:36:40 ----D---- C:\Windows\system32\SLUI 2010-02-22 21:36:40 ----D---- C:\Windows\system32\setup 2010-02-22 21:36:40 ----D---- C:\Windows\system32\AdvancedInstallers 2010-02-22 21:36:37 ----D---- C:\Windows\system32\manifeststore 2010-02-22 21:36:29 ----D---- C:\Windows\system32\migwiz 2010-02-22 21:35:31 ----D---- C:\Windows\system32\Boot 2010-02-22 21:33:42 ----D---- C:\Windows\system32\RTCOM 2010-02-15 16:25:47 ----D---- C:\Program Files\Common Files\Apple 2010-02-15 01:13:46 ----A---- C:\Windows\win.ini 2010-02-06 16:46:20 ----D---- C:\Users\***\AppData\Roaming\vlc 2010-02-04 22:00:09 ----D---- C:\Users\***\AppData\Roaming\Apple Computer 2010-02-01 20:26:20 ----A---- C:\Windows\system32\mrt.exe 2010-02-01 14:51:53 ----D---- C:\Program Files\Common Files\DVDVideoSoft ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608] R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-06-25 96104] R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-06-25 28520] R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880] R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-12-12 56816] R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936] R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-09 45568] R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-12-06 761856] R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-02-26 4569088] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-11-01 2011224] R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632] R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680] R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2007-07-13 50688] R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088] R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632] R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-22 982272] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400] S3 BthEnum;Bluetooth-Auflistungsdienst; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528] S3 BthPan;Bluetooth-Gerät (PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160] S3 BTHPORT;Bluetooth-Porttreiber; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904] S3 BTHUSB;USB-Treiber für Bluetooth-Funkgerät; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696] S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632] S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520] S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2010-01-07 38224] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192] S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888] S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016] S3 RFCOMM;Bluetooth-Gerät (RFCOMM-Protokoll-TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992] S3 s0017bus;Sony Ericsson Device 0017 driver (WDM); C:\Windows\system32\DRIVERS\s0017bus.sys [2008-10-21 86824] S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 15016] S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 114600] S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 108328] S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS); C:\Windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 26024] S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0017obex.sys [2008-10-21 104616] S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM); C:\Windows\system32\DRIVERS\s0017unic.sys [2008-10-21 109736] S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys [] S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448] S3 usbaudio;USB-Audiotreiber (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-21 73088] S3 usbvideo;USB-Videogerät (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328] S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048] S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656] S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616] S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2007-05-18 73728] R2 AntiVirSchedulerService;Avira AntiVir Planer; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-06-25 108289] R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-05 185089] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672] R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208] R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208] R2 Bonjour Service;Bonjour-Dienst; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888] R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504] R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728] R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112] R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496] S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-08-16 133104] S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504] S3 iPod Service;iPod-Dienst; C:\Program Files\iPod\bin\iPodService.exe [2010-01-22 545576] -----------------EOF----------------- Geändert von Gwendoline (27.02.2010 um 14:16 Uhr) Grund: Code der übersichthalber |
Themen zu Virenscans hängen sich auf, verseuchter PC? |
antivir, antivir guard, avgntflt.sys, avira, bho, browser, c:\windows\system32\rundll32.exe, desktop, device driver, error, festplatte, festplatte c, fontcache, google, gupdate, hdaudio.sys, hijack, hijackthis, home, home premium, hängen, hängt sich auf, internet, internet explorer, java-viren, laptop hängt, laptop hängt sich auf, laufzeit, maus, mozilla, plug-in, programdata, realtek, registry, scan, security, shell32.dll, softonic, softonic deutsch ff toolbar, software, svchost.exe, usbvideo.sys, vista, windows, wireless lan |