![]() |
Alle Programme stellen wenn man sie beendet ein Problem fest Hallo Ich bin neu hier und hoffe das ich das hier richtig gepostet habe. Mein problem ist: Seit kurzem kommt dauernd das Naricht: xxx hat ein Problem festgestellt und muss beendet werden. Z.b. wenn ich Itunes schließe kommt das oder wenn ich Internet schließe. Egal ob mozilla oder explorer. Desweiteren kommen immer mal die gleichen meldungen pohne das ich was mache dann mit Programmen wie dostnoted musste beendet werden oder änhliches( mir fällt spontan der Name nicht ein Rundll32.exe oder so) Programme wie Warrock starten dadurch erst gar nicht da ich in den Launcher gehe dann auf Spielstarten. Dann geht der Launcher ja automatisch aus und stellt dann wie oben beschrieben ein Problem fest. Könnt ihr mir sagen woran das liegt? Zu meinem System: Windows Xp professional Amd Semprom(tm) Processor 3400+ 1.80 Ghz 3.00 Gb ram Grafikarte: Nvidia GeForce 9600 GSO 512 500 gb Festplatte |
Hallo und :hallo: Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
|
so..hier das ergebins von der anti maleware Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4605 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 13.09.2010 18:05:51 mbam-log-2010-09-13 (18-05-51).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 223474 Laufzeit: 1 Stunde(n), 8 Minute(n), 18 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 4 Infizierte Registrierungsschlüssel: 147 Infizierte Registrierungswerte: 7 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 22 Infizierte Dateien: 90 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: C:\Programme\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Delete on reboot. C:\Programme\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Delete on reboot. C:\Programme\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot. C:\Programme\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\TypeLib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{8e9cf769-3d3b-40eb-9e2d-76e7a205e4d2} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{819ffe20-35c7-4925-8cda-4e0e2db94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{819ffe21-35c7-4925-8cda-4e0e2db94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{819ffe22-35c7-4925-8cda-4e0e2db94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{799391d3-eb86-4bac-9bd3-cbfea58a0e15} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d858dafc-9573-4811-b323-7011a3aa7e61} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.multiplebutton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.multiplebutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.urlalertbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.urlalertbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar (Adware.MyWebSearch) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: C:\Programme\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\setups (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully. Infizierte Dateien: C:\Programme\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Dokumente und Einstellungen\arme\Eigene Dateien\Downloads\adobe_flash_player(2).exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Dokumente und Einstellungen\arme\Eigene Dateien\Downloads\adobe_flash_player.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Dokumente und Einstellungen\arme\Eigene Dateien\Downloads\myWebFace.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\2.bin\F3EZSETP.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully. C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\2.bin\F3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\2.bin\NPFUNWEB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\Cache\002A3387.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Installr\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\FunWebProducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\CHROME.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\1.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\00022A52 (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\0002384C (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\00023BA7.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\000241E1.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\0002482A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\00024BB5.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\00024C80.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\00024D3B.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Programme\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. |
Die von OTL Extras.txtOTL EXTRAS Logfile: Code: OTL Extras logfile created on: 13.09.2010 18:10:38 - Run 2 |
die OTL.txt datei ist zu groß... wie poste ich die trotzdem? als txt datei anhängen geht nicht da soe 437 kb oder so groß ist |
si hier ist die ander OTL datei |
Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!! Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. |
ich habe versucht das zu machen doch sobald ich auf fix klicke beendet sich der explorer ohne fehlermeldung( der prozess explorer.exe ist im taksmanager nicht mehr ausgeführt) und OTL hängt sich auf.... |
Hast Du aus dem unkenntlich gemachten Benutzernamen Deinen richtigen vorher wieder gemacht? |
ja eig schon... habe den text vorher in einen Editor eingefügt und alle **** durch meinen benutzernamen ersetzen lassen..per funktion ( bearbeiten ersetzen) das geht doch dann oder? |
Genau. Den string "****" durch den mit Deinem Benutzernamen ersetzen ist richtig... Probiers bitte nochmal |
geht nicht...habs mehrmals ausprobiert....hab das **** sogar eigenhändig geändert...geht nicht der bleibt immer bei prosesiing(?) IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = da bleibt der immer hängen... |
Probiers bitte mal mit diesem Text: Code: :OTL |
so hat geklappt hier das ergebnis=) All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{9565115d-c7d6-46d3-bd63-b67b481a4368} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9565115d-c7d6-46d3-bd63-b67b481a4368}\ deleted successfully. C:\Programme\PageRage\tbPage.dll moved successfully. Prefs.js: "SweetIM Search" removed from browser.search.defaultenginename Prefs.js: "PageRage Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.sweetim.com/search.asp?src=2&q=" removed from browser.search.defaulturl Prefs.js: "SweetIM Search" removed from browser.search.selectedEngine Prefs.js: "hxxp://home.sweetim.com" removed from browser.startup.homepage Prefs.js: plugin@yontoo.com:1.10.01 removed from extensions.enabledItems Prefs.js: {9565115d-c7d6-46d3-bd63-b67b481a4368}:2.7.2.0 removed from extensions.enabledItems Prefs.js: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10 removed from extensions.enabledItems Prefs.js: ffxtlbr@Facemoods.com:1.1.0 removed from extensions.enabledItems Prefs.js: "hxxp://search.sweetim.com/search.asp?src=2&q=" removed from keyword.URL Prefs.js: 0 removed from network.proxy.type Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.defaultenginename Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}" removed from sweetim.toolbar.previous.browser.search.defaulturl Prefs.js: "PageRage Customized Web Search" removed from sweetim.toolbar.previous.browser.search.selectedEngine Prefs.js: "hxxp://search.conduit.com/?ctid=CT2418376&SearchSource=13" removed from browser.startup.homepage Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&q=" removed from sweetim.toolbar.previous.keyword.URL Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ deleted successfully. C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9565115d-c7d6-46d3-bd63-b67b481a4368}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9565115d-c7d6-46d3-bd63-b67b481a4368}\ not found. File C:\Programme\PageRage\tbPage.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully. C:\Programme\Yontoo Layers Client\YontooIEClient.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{9565115d-c7d6-46d3-bd63-b67b481a4368} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9565115d-c7d6-46d3-bd63-b67b481a4368}\ not found. File C:\Programme\PageRage\tbPage.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9565115D-C7D6-46D3-BD63-B67B481A4368} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9565115D-C7D6-46D3-BD63-B67B481A4368}\ not found. File C:\Programme\PageRage\tbPage.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\4StoryPrePatch deleted successfully. C:\Programme\Gameforge4D\4Story\PrePatch.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Reskbd deleted successfully. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\Adobe\Update\bltgdi.exe moved successfully. File move failed. D:\autorun.exe scheduled to be moved on reboot. File move failed. D:\Autorun.inf scheduled to be moved on reboot. File move failed. D:\AutorunText.txt scheduled to be moved on reboot. C:\eeb7506cac83c1cf561b0ac9b9128f\update folder moved successfully. C:\eeb7506cac83c1cf561b0ac9b9128f folder moved successfully. C:\tmp folder moved successfully. C:\KoFuMa1.9\Videos folder moved successfully. C:\KoFuMa1.9\Musik folder moved successfully. C:\KoFuMa1.9\meinelieder folder moved successfully. C:\KoFuMa1.9\Lizenzen folder moved successfully. C:\KoFuMa1.9\Fonts folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Zufallwappen\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Zufallwappen\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Zufallwappen\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Zufallwappen folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Deutschland\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Deutschland\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Deutschland\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Deutschland folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Amateure\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Amateure\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Amateure\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\Amateure folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\9\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\9\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\9\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\9 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\6\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\6\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\6\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\6 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\48\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\48\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\48\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\48 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\47\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\47\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\47\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\47 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\45\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\45\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\45\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\45 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\41\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\41\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\41\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\41 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\37\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\37\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\37\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\37 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\36\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\36\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\36\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\36 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\34\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\34\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\34\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\34 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\29\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\29\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\29\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\29 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\20\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\20\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\20\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\17\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\17\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\17\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\17 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\15\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\15\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\15\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\15 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\11\schwarz60 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\11\schwarz208 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\11\20 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen\11 folder moved successfully. C:\KoFuMa1.9\Daten\Wappen folder moved successfully. C:\KoFuMa1.9\Daten\Spielstand folder moved successfully. C:\KoFuMa1.9\Daten\Namen\int_zufallsnamen folder moved successfully. C:\KoFuMa1.9\Daten\Namen folder moved successfully. C:\KoFuMa1.9\Daten\int_vereine folder moved successfully. C:\KoFuMa1.9\Daten\hi_score folder moved successfully. C:\KoFuMa1.9\Daten folder moved successfully. C:\KoFuMa1.9\Bilder\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\werbung folder moved successfully. C:\KoFuMa1.9\Bilder\Logo\a folder moved successfully. C:\KoFuMa1.9\Bilder\Logo folder moved successfully. C:\KoFuMa1.9\Bilder\Live folder moved successfully. C:\KoFuMa1.9\Bilder\Leiste_unten folder moved successfully. C:\KoFuMa1.9\Bilder\1.8\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.8 folder moved successfully. C:\KoFuMa1.9\Bilder\1.7\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.7 folder moved successfully. C:\KoFuMa1.9\Bilder\1.6\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.6 folder moved successfully. C:\KoFuMa1.9\Bilder\1.5\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.5 folder moved successfully. C:\KoFuMa1.9\Bilder\1.4\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.4 folder moved successfully. C:\KoFuMa1.9\Bilder\1.3\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.3 folder moved successfully. C:\KoFuMa1.9\Bilder\1.2\_extraload\trikot_gross folder moved successfully. C:\KoFuMa1.9\Bilder\1.2\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.2 folder moved successfully. C:\KoFuMa1.9\Bilder\1.1\_extraload\trikots\18_tabelle folder moved successfully. C:\KoFuMa1.9\Bilder\1.1\_extraload\trikots\18_live folder moved successfully. C:\KoFuMa1.9\Bilder\1.1\_extraload\trikots folder moved successfully. C:\KoFuMa1.9\Bilder\1.1\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.1 folder moved successfully. C:\KoFuMa1.9\Bilder\1.0\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\1.0 folder moved successfully. C:\KoFuMa1.9\Bilder\0.9\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.9 folder moved successfully. C:\KoFuMa1.9\Bilder\0.8\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.8 folder moved successfully. C:\KoFuMa1.9\Bilder\0.7\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.7 folder moved successfully. C:\KoFuMa1.9\Bilder\0.6\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.6 folder moved successfully. C:\KoFuMa1.9\Bilder\0.5\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.5\Fahnen folder moved successfully. C:\KoFuMa1.9\Bilder\0.5 folder moved successfully. C:\KoFuMa1.9\Bilder\0.4\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.4 folder moved successfully. C:\KoFuMa1.9\Bilder\0.3\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.3 folder moved successfully. C:\KoFuMa1.9\Bilder\0.2\_extraload folder moved successfully. C:\KoFuMa1.9\Bilder\0.2 folder moved successfully. C:\KoFuMa1.9\Bilder folder moved successfully. C:\KoFuMa1.9 folder moved successfully. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\Ryvuiw folder moved successfully. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\Lofee folder moved successfully. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\Kiisz folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{A4B500C8-F3EB-4AD9-9762-515CCA35FD16} folder moved successfully. C:\KP501\USB_Driver\FlashUSBAGOLD folder moved successfully. C:\KP501\USB_Driver\FlashUSB folder moved successfully. C:\KP501\USB_Driver folder moved successfully. C:\KP501 folder moved successfully. C:\Programme\ICQ6Toolbar folder moved successfully. C:\WINDOWS\NV7481136.TMP folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86 folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\PriceGong\Data folder moved successfully. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\PriceGong folder moved successfully. Folder C:\Dokumente und Einstellungen\arme\Anwendungsdaten\Ryvuiw\ not found. C:\Dokumente und Einstellungen\arme\Anwendungsdaten\Ymqo folder moved successfully. C:\WINDOWS\Tasks\PCConfidential.job moved successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: arme ->Temp folder emptied: 1008332235 bytes ->Temporary Internet Files folder emptied: 201816179 bytes ->FireFox cache emptied: 93214194 bytes ->Flash cache emptied: 6957353 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 635407 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2114764 bytes %systemroot%\System32 .tmp files removed: 4118407 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 15988074 bytes RecycleBin emptied: 35070719 bytes Total Files Cleaned = 1.305,00 mb OTL by OldTimer - Version 3.2.12.0 log created on 09142010_222534 Files\Folders moved on Reboot... File move failed. D:\autorun.exe scheduled to be moved on reboot. File move failed. D:\Autorun.inf scheduled to be moved on reboot. File move failed. D:\AutorunText.txt scheduled to be moved on reboot. Registry entries deleted on Reboot... |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
http://saved.im/mtm0nzyzmzd5/cofi.jpg
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! |
es klappt wieder danke=) woran lag das den jetzt? bis her kam keine fehlermeldung mehr und warrock und so lässt sich auch wiede rproblemlos starten=) vielen vielen dank=) |
Bitte poste das Log von CF!! |
so hier das ergebnis Combofix Logfile: Code: ComboFix 10-09-14.04 - arme 15.09.2010 12:38:13.1.1 - x86 |
Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus Anschließend den bootkit_remover herunterladen. Entpacke das Tool in einen eigenen Ordner auf dem Desktop und führe in diesem Ordner die Datei remove.exe aus. Wenn Du Windows Vista oder Windows 7 verwendest, musst Du die remover.exe über ein Rechtsklick => als Administrator ausführen Ein schwarzes Fenster wird sich öffnen und automatisch nach bösartigen Veränderungen im MBR suchen. Poste dann bitte, ob es Veränderungen gibt und wenn ja in welchem device. Am besten alles posten was die remover.exe ausgibt. |
hier von GMER GMER Logfile: Code: GMER 1.0.15.15281 - hxxp://www.gmer.net |
hier von OSAM OSAM Logfile: Code: Report of OSAM: Autorun Manager v5.0.11926.0 If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru |
Und der Bootkit Remover? |
also ich habe die datein boot_remover ausgeführt hat sich fentser geöffnet und so... jetzt steht da system volum is c und so.... size device name mbr status 456 gb \\.\PhysicalDevice0 Unknow boot comand to inspekt the boot code manual dump the master boot sector... und unten dann Done. to exit üree any key |
Downloade Dir bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
|
MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 112): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806CF000 \WINDOWS\system32\hal.dll 0xBA5A8000 \WINDOWS\system32\KDCOM.DLL 0xBA4B8000 \WINDOWS\system32\BOOTVID.dll 0xB9F78000 ACPI.sys 0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xB9F67000 pci.sys 0xBA0A8000 isapnp.sys 0xBA670000 pciide.sys 0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xBA0B8000 MountMgr.sys 0xB9F48000 ftdisk.sys 0xBA5AC000 dmload.sys 0xB9F22000 dmio.sys 0xBA330000 PartMgr.sys 0xBA0C8000 VolSnap.sys 0xB9F0A000 atapi.sys 0xBA0D8000 disk.sys 0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xB9EEB000 fltMgr.sys 0xB9ED9000 sr.sys 0xBA0F8000 PxHelp20.sys 0xB9EC2000 KSecDD.sys 0xB9E35000 Ntfs.sys 0xB9E08000 NDIS.sys 0xB9DED000 Mup.sys 0xBA128000 \SystemRoot\system32\DRIVERS\AmdK8.sys 0xB902C000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xB9018000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xB9003000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys 0xBA3D8000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xB8FE0000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xBA3E0000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xBA138000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xBA148000 \SystemRoot\system32\DRIVERS\redbook.sys 0xB8FBD000 \SystemRoot\system32\DRIVERS\ks.sys 0xBA3E8000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xB8F98000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xB8F87000 \SystemRoot\system32\DRIVERS\serial.sys 0xBA56C000 \SystemRoot\system32\DRIVERS\serenum.sys 0xB8F73000 \SystemRoot\system32\DRIVERS\parport.sys 0xB9696000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xBA3F0000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xBA5C4000 \SystemRoot\system32\DRIVERS\ASACPI.sys 0xBA6D9000 \SystemRoot\system32\DRIVERS\audstub.sys 0xB9686000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xBA570000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xB8F3D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xB9676000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xB9666000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xBA3F8000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xB8F2C000 \SystemRoot\system32\DRIVERS\psched.sys 0xB9656000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xBA400000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xBA408000 \SystemRoot\system32\DRIVERS\raspti.sys 0xB8EFB000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xB9636000 \SystemRoot\system32\DRIVERS\termdd.sys 0xBA410000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xBA5CA000 \SystemRoot\system32\DRIVERS\swenum.sys 0xB8EC7000 \SystemRoot\system32\DRIVERS\update.sys 0xBA58C000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xBA168000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBA1B8000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xBA604000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xB690B000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xB68E9000 \SystemRoot\system32\drivers\portcls.sys 0xBA1C8000 \SystemRoot\system32\drivers\drmk.sys 0xBA60C000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xBA7C8000 \SystemRoot\System32\Drivers\Null.SYS 0xBA60E000 \SystemRoot\System32\Drivers\Beep.SYS 0xBA470000 \SystemRoot\System32\drivers\vga.sys 0xBA610000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xBA612000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xBA478000 \SystemRoot\System32\Drivers\Msfs.SYS 0xBA480000 \SystemRoot\System32\Drivers\Npfs.SYS 0xBA53C000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xB6866000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xB680E000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xB67E6000 \SystemRoot\system32\DRIVERS\netbt.sys 0xB67C4000 \SystemRoot\System32\drivers\afd.sys 0xBA1D8000 \SystemRoot\system32\DRIVERS\netbios.sys 0xBA488000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0xB6798000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xB6729000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xBA208000 \SystemRoot\System32\Drivers\Fips.SYS 0xB6708000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xBA218000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xB66E6000 \SystemRoot\system32\DRIVERS\avipbb.sys 0xBA62A000 \??\C:\Programme\Avira\AntiVir Desktop\avgio.sys 0xB6D7F000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xBA258000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xBA360000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xBA268000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xB6D7B000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xB66A6000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xBA62C000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xB68D5000 \SystemRoot\System32\drivers\Dxapi.sys 0xBA378000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xBA73C000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xB6379000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0xB6392000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xB5FDC000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xB5F9F000 \SystemRoot\system32\drivers\wdmaud.sys 0xB60E9000 \SystemRoot\system32\drivers\sysaudio.sys 0xBA620000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xB5123000 \SystemRoot\system32\DRIVERS\srv.sys 0xB4E62000 \SystemRoot\System32\Drivers\HTTP.sys 0x7C910000 \WINDOWS\system32\ntdll.dll Processes (total 37): 0 System Idle Process 4 System 632 C:\WINDOWS\system32\smss.exe 696 csrss.exe 720 C:\WINDOWS\system32\winlogon.exe 772 C:\WINDOWS\system32\services.exe 784 C:\WINDOWS\system32\lsass.exe 956 C:\WINDOWS\system32\svchost.exe 1032 svchost.exe 1128 C:\WINDOWS\system32\svchost.exe 1204 svchost.exe 1316 svchost.exe 1684 C:\WINDOWS\system32\spoolsv.exe 1708 C:\WINDOWS\explorer.exe 1772 C:\Programme\Avira\AntiVir Desktop\sched.exe 1940 svchost.exe 1972 C:\WINDOWS\RTHDCPL.exe 2008 C:\WINDOWS\system32\rundll32.exe 2016 C:\Programme\Avira\AntiVir Desktop\avgnt.exe 2028 C:\Programme\DivX\DivX Update\DivXUpdate.exe 2036 C:\Programme\SweetIM\Messenger\SweetIM.exe 124 C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe 180 C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe 228 C:\Programme\iTunes\iTunesHelper.exe 1068 C:\Programme\Avira\AntiVir Desktop\avguard.exe 1080 C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1112 C:\Programme\Bonjour\mDNSResponder.exe 1356 C:\WINDOWS\system32\nvsvc32.exe 1612 C:\Programme\Avira\AntiVir Desktop\avshadow.exe 600 C:\WINDOWS\system32\wuauclt.exe 2256 C:\Programme\iPod\bin\iPodService.exe 2616 alg.exe 3080 C:\WINDOWS\system32\wuauclt.exe 3164 C:\Programme\ICQ7.2\ICQ.exe 3520 C:\Programme\Mozilla Firefox\firefox.exe 3804 C:\Programme\Mozilla Firefox\plugin-container.exe 4016 C:\Dokumente und Einstellungen\arme\Desktop\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: WDCWD5000AADS-00S9B0, Rev: 01.00A01 Size Device Name MBR Status -------------------------------------------- 465 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 Done! |
Zitat:
Denk dran beide Tools zu updaten vor dem Scan!! |
SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 09/16/2010 at 10:18 PM Application Version : 4.43.1000 Core Rules Database Version : 5520 Trace Rules Database Version: 3332 Scan type : Complete Scan Total Scan Time : 01:31:22 Memory items scanned : 444 Memory threats detected : 0 Registry items scanned : 4952 Registry threats detected : 0 File items scanned : 97908 File threats detected : 51 Adware.Tracking Cookie C:\Dokumente und Einstellungen\arme\Cookies\arme@doubleclick[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@www.zanox-affiliate[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@content.yieldmanager[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@atwola[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@ad.yieldmanager[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@zanox-affiliate[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@mediaplex[2].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@apmebf[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@tradedoubler[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@zanox[1].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@ak[2].txt C:\Dokumente und Einstellungen\arme\Cookies\arme@media.warrock[1].txt Trojan.Agent/Gen-Nullo[Short] C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016041.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016029.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016030.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016031.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016032.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016033.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016034.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016035.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016036.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016037.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016038.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016039.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016040.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016059.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016042.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016043.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016044.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016045.SCR C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016046.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016047.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016048.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016049.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016050.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016051.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016052.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016053.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016054.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016055.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016056.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016057.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016058.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016060.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016061.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016062.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016063.SCR C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016064.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016065.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016069.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{B440DA09-4772-4CE8-AF55-12313C8DF0C5}\RP85\A0016070.DLL |
Deaktiviere die Systemwiederherstellung, im Verlauf der Infektion wurden auch Malwaredateien in Wiederherstellungspunkten mitgesichert - die sind alle nun unbrauchbar, da ein Zurücksetzen des Systems durch einen Wiederherstellungspunkt wahrscheinlich wieder eine Infektion nach sich ziehen würde. Sieht sonst soweit ok aus. Noch Probleme oder weitere Funde in der Zwischenzeit? |
vielen vielen dank nein ansonsten nichts bisher=) klappt alles weider bestens vielen dank=) |
Dann wären wir durch! :abklatsch: Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern. Microsoftupdate Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren. Windows Vista/7: Anleitung Windows-Update PDF-Reader aktualisieren Dein Adobe Reader ist nicht aktuell, was ein großes Sicherheitsrisiko darstellt. Du solltest daher besser die alte Version über Systemsteuerung => Software deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader. Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink => http://filepony.de/?q=Flash+Player Java-Update Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:34 Uhr. |
Copyright ©2000-2025, Trojaner-Board