Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Firefox und IE laden zu langsam die webseiten (https://www.trojaner-board.de/101134-firefox-ie-laden-langsam-webseiten.html)

chaoskomet 08.07.2011 21:19

Firefox und IE laden zu langsam die webseiten
 
guten abend,

ich war seit mittwoch nachmittag bei freunden bis heute abend.

seit dem mittwoch nachmittag sind beide browser firefox und ie so langsam mit laden. wenn ich die browser starte, werden die seiten nicht geladen, erst wenn ich die seite erneut lade geht es.

wenn ich ein neues tab öffne, passiert das gleiche.

wenn ich facebook spiele öffne, wie "gardensoftime" läd das zu lange, oft sehe ich nur eine weise seite. genauso ist es bei famarama.

ich dachte erst das meine freunde probleme mit der leitung haben, aber bei ihnen lief alles ohne probleme.

seit heute abend bin ich wieder zuhause, und es ist immer noch so, also kann es nicht an der internet leitung liegen.
da wir in unterschiedlichen städen wohnen und auch unterschiedliche dsl anbieter haben.

mein system:

Samsung R522 lappi, mit intel core2 duo cpu T6400 2.00 GHz, 4 GB ram, ATI Mobility Radeon HD 4330, ms vista home premium 32 bit sp2.

firefox 3.6.18 - gfk monitor Version: 11.1.506.7.15.14.MEPDE.DE
java 6.0.260.3, shockwave flash 10.2.153.1, roboform 6.9.98,

AVG internet security 10.0.1388, avg pc tuneup 2011 Version 10.0.0.24
ccleaner 3.08.1475

IE9 version 9.0.8112.16421

hoffe habe alle systemdaten die relevant sind aufgeschrieben.
Avg hat keine viren oder ähnliches gefunden.

p.s. auch beim hochladen der logfile kam wieder der seitenabruch.

ich hoffe ihr könnt mir weiterhelfen, das nervt langsam das kaum was geht oder nach mehreren versuchen.

schönes wochenende euch.

cosinus 11.07.2011 10:35

Hallo und :hallo:

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

chaoskomet 11.07.2011 12:05

hallo cosinus,

danke das du mir bei meinem problem hilfst.

hier ist die auswertung von malwarebytes

Zitat:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Datenbank Version: 7069

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

11.07.2011 13:02:37
mbam-log-2011-07-11 (13-02-37).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|F:\|)
Durchsuchte Objekte: 290573
Laufzeit: 1 Stunde(n), 18 Minute(n), 14 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 2

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (PUM.Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\CPUCooL\instser.exe (Adware.Agent) -> Quarantined and deleted successfully.
c:\Users\chaoskomet\documents\incredimail_bonus_und_gold_gallery_pack\incredimail bonus und gold gallery pack\incredimail bonus pack\emotionpack vollversion\incredimail emotioncenter.exe (Adware.Rabio) -> Quarantined and deleted successfully.
was passiert denn jetzt weiter?
ist nun alles behoben?

cosinus 11.07.2011 12:28

Zitat:

O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programme\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Programme\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (produkttests Toolbar) - {dcea9ff9-5c31-40ac-9285-9c25ff04b93a} - C:\Programme\produkttests\prxtbpro0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Programme\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Programme\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (produkttests Toolbar) - {DCEA9FF9-5C31-40AC-9285-9C25FF04B93A} - C:\Programme\produkttests\prxtbpro0.dll (Conduit Ltd.)
Hm, was willst du mit diesen komischen Toolbars auf dem Rechner? Am besten alles entfernen wo Toolbar steht, was in der Systemsteuerung unter Software bzw. Programme und Funktionen zu sehen ist und bei zukünftigen Programminstallation immer die benutzerdefinierte Methode anklicken, damit man bei der Installation mögliche Toolbars abwählen kann.
Deinstalliere bei der Gelegenheit auch alle anderen unnötigen Programme über die Systemsteuerung.


Zitat:

O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
Musst du als Mailclient unbedingt dieses sch... Programm verwenden? :(
Incredimail ist zwar bunt und nett animiert, aber leider als Spyware einzustufen, da es das Nutzerverhalten analysiert und diese an den Hersteller übermittelt.
Ich kann nur die sofortige Deinstallation und Umstieg auf einen anderen Mailclient wie zB Mozilla Thunderbird empfehlen.

chaoskomet 11.07.2011 12:35

okay, toolbars werden entfernt, aber was ist an der avg toolbar falsch.

ist denn mein pc wieder ok und clean?

kannst du mir sagen an was es gelegen hat?

ist denn outlook okay von mircosoft, oder teilt der auch zuviel mit?

cosinus 11.07.2011 12:59

Zitat:

ist denn outlook okay von mircosoft, oder teilt der auch zuviel mit?
Outlook oder Windows-Mail? Ist zwar auch ok, ich persönlich würde aber zu Thunderbird tendieren. Outlook kostet, ist Bestandteil von MS-Office. Windows-Mail ist bei Vista dabei.

Zitat:

ist denn mein pc wieder ok und clean?
mach bitte ein neues custom-log:

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


chaoskomet 11.07.2011 13:24

die otl log hab ich als datei anhang an den beitrag gemacht

cosinus 11.07.2011 13:29

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{634c4165-6148-11e0-a2f2-0c6076dbc066}\Shell - "" = AutoRun
O33 - MountPoints2\{634c4165-6148-11e0-a2f2-0c6076dbc066}\Shell\AutoRun\command - "" = G:\Startme.exe
O33 - MountPoints2\{ea40a5e4-7c00-11e0-b085-0c6076dbc066}\Shell - "" = AutoRun
O33 - MountPoints2\{ea40a5e4-7c00-11e0-b085-0c6076dbc066}\Shell\AutoRun\command - "" = D:\.\Autorun.exe AUTORUN=1
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:036B9593
:Commands
[purity]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

chaoskomet 11.07.2011 13:52

virenscanner konnte ich vor dem fixen nicht abschalten, da die avg benutzeroberfläsche sich nicht öffnen lies, konnte nur die avg firewall abschalten.

Code:

========== OTL ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File C:\autoexec.bat not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{634c4165-6148-11e0-a2f2-0c6076dbc066}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{634c4165-6148-11e0-a2f2-0c6076dbc066}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{634c4165-6148-11e0-a2f2-0c6076dbc066}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{634c4165-6148-11e0-a2f2-0c6076dbc066}\ not found.
File G:\Startme.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea40a5e4-7c00-11e0-b085-0c6076dbc066}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ea40a5e4-7c00-11e0-b085-0c6076dbc066}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea40a5e4-7c00-11e0-b085-0c6076dbc066}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ea40a5e4-7c00-11e0-b085-0c6076dbc066}\ not found.
File D:\.\Autorun.exe AUTORUN=1 not found.
ADS C:\ProgramData\Temp:0B4227B4 deleted successfully.
Unable to delete ADS C:\ProgramData\Temp:036B9593 .
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.26.1 log created on 07112011_145030

nach dem fixen habe ich neustart gemacht, jetzt lässt sich die avg benutzeroberfläche wieder öffnen.

wie geht es denn weiter?

cosinus 11.07.2011 13:54

Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

http://www.trojaner-board.de/attachm...rnen-start.png


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

chaoskomet 11.07.2011 14:05

bitte das kaspersky log:

Code:

2011/07/11 15:01:43.0707 10156        TDSS rootkit removing tool 2.5.9.0 Jul  1 2011 18:45:21
2011/07/11 15:01:45.0007 10156        ================================================================================
2011/07/11 15:01:45.0007 10156        SystemInfo:
2011/07/11 15:01:45.0007 10156       
2011/07/11 15:01:45.0007 10156        OS Version: 6.0.6002 ServicePack: 2.0
2011/07/11 15:01:45.0007 10156        Product type: Workstation
2011/07/11 15:01:45.0007 10156        ComputerName: CHAOSKOMET-PC
2011/07/11 15:01:45.0007 10156        UserName: Chaoskomet
2011/07/11 15:01:45.0007 10156        Windows directory: C:\Windows
2011/07/11 15:01:45.0007 10156        System windows directory: C:\Windows
2011/07/11 15:01:45.0007 10156        Processor architecture: Intel x86
2011/07/11 15:01:45.0007 10156        Number of processors: 2
2011/07/11 15:01:45.0007 10156        Page size: 0x1000
2011/07/11 15:01:45.0007 10156        Boot type: Normal boot
2011/07/11 15:01:45.0007 10156        ================================================================================
2011/07/11 15:01:45.0923 10156        Initialize success
2011/07/11 15:01:48.0865 8368        ================================================================================
2011/07/11 15:01:48.0865 8368        Scan started
2011/07/11 15:01:48.0865 8368        Mode: Manual;
2011/07/11 15:01:48.0865 8368        ================================================================================
2011/07/11 15:01:49.0555 8368        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/07/11 15:01:49.0951 8368        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/07/11 15:01:50.0434 8368        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/07/11 15:01:50.0873 8368        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/07/11 15:01:50.0937 8368        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/07/11 15:01:51.0018 8368        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
2011/07/11 15:01:51.0175 8368        AgereSoftModem  (1cfeba39fc613e45b49d3eddfbcda289) C:\Windows\system32\DRIVERS\AGRSM.sys
2011/07/11 15:01:51.0268 8368        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/07/11 15:01:51.0308 8368        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/07/11 15:01:51.0373 8368        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/07/11 15:01:51.0413 8368        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/07/11 15:01:51.0461 8368        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/07/11 15:01:51.0497 8368        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/07/11 15:01:51.0537 8368        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
2011/07/11 15:01:51.0625 8368        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/07/11 15:01:51.0659 8368        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/07/11 15:01:51.0708 8368        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/11 15:01:51.0774 8368        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/07/11 15:01:51.0990 8368        athr            (99d78248bfd454bfa9b5bec37350fade) C:\Windows\system32\DRIVERS\athr.sys
2011/07/11 15:01:53.0031 8368        atikmdag        (45c45796caad4f3354496530329a7b10) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/07/11 15:01:53.0323 8368        Avgfwfd        (d30b785ab801a0e2b0ad922d66f971f3) C:\Windows\system32\DRIVERS\avgfwd6x.sys
2011/07/11 15:01:53.0398 8368        AVGIDSDriver    (97824e8c95d9717777abd46a7b632310) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
2011/07/11 15:01:53.0431 8368        AVGIDSEH        (c59c9bc3f0612bd207ccdc5d8cb9ce39) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
2011/07/11 15:01:53.0459 8368        AVGIDSFilter    (c5559de2ec66cede15a1664f6d183d8e) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
2011/07/11 15:01:53.0498 8368        AVGIDSShim      (ae5e9667fa40206796d1bd5bd0427a8a) C:\Windows\system32\DRIVERS\AVGIDSShim.Sys
2011/07/11 15:01:53.0573 8368        Avgldx86        (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\Windows\system32\DRIVERS\avgldx86.sys
2011/07/11 15:01:53.0618 8368        Avgmfx86        (5639de66b37d02bd22df4cf3155fba60) C:\Windows\system32\DRIVERS\avgmfx86.sys
2011/07/11 15:01:53.0669 8368        Avgrkx86        (d1baf652eda0ae70896276a1fb32c2d4) C:\Windows\system32\DRIVERS\avgrkx86.sys
2011/07/11 15:01:53.0780 8368        Avgtdix        (aaf0ebcad95f2164cffb544e00392498) C:\Windows\system32\DRIVERS\avgtdix.sys
2011/07/11 15:01:53.0896 8368        bcm4sbxp        (08015d34f6fdd0b355805bad978497c3) C:\Windows\system32\DRIVERS\bcm4sbxp.sys
2011/07/11 15:01:53.0973 8368        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/07/11 15:01:54.0036 8368        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/07/11 15:01:54.0073 8368        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/11 15:01:54.0133 8368        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/07/11 15:01:54.0175 8368        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/07/11 15:01:54.0229 8368        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/07/11 15:01:54.0273 8368        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/07/11 15:01:54.0315 8368        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/07/11 15:01:54.0368 8368        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/07/11 15:01:54.0437 8368        BthEnum        (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys
2011/07/11 15:01:54.0458 8368        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/07/11 15:01:54.0501 8368        BthPan          (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2011/07/11 15:01:54.0535 8368        BTHPORT        (5a3abaa2f8eece7aefb942773766e3db) C:\Windows\system32\Drivers\BTHport.sys
2011/07/11 15:01:54.0567 8368        BTHUSB          (94e2941280e3756a5e0bcb467865c43a) C:\Windows\system32\Drivers\BTHUSB.sys
2011/07/11 15:01:54.0631 8368        btwaudio        (80afcd99f94bb8321f85ebafa28cf0b5) C:\Windows\system32\drivers\btwaudio.sys
2011/07/11 15:01:54.0670 8368        btwavdt        (07bd2be871455231de27bb346f6886e7) C:\Windows\system32\drivers\btwavdt.sys
2011/07/11 15:01:54.0713 8368        btwl2cap        (ecb98391c756a7b9cfbae89d9d1235e1) C:\Windows\system32\DRIVERS\btwl2cap.sys
2011/07/11 15:01:54.0735 8368        btwrchid        (bc53acabccc9946ad508a8737f2a39ea) C:\Windows\system32\DRIVERS\btwrchid.sys
2011/07/11 15:01:54.0786 8368        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/11 15:01:54.0823 8368        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/07/11 15:01:54.0863 8368        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/07/11 15:01:54.0922 8368        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/07/11 15:01:55.0014 8368        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/07/11 15:01:55.0037 8368        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/07/11 15:01:55.0064 8368        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/07/11 15:01:55.0096 8368        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/07/11 15:01:55.0122 8368        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/07/11 15:01:55.0191 8368        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
2011/07/11 15:01:55.0304 8368        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/07/11 15:01:55.0378 8368        Dot4            (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2011/07/11 15:01:55.0422 8368        Dot4Print      (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/07/11 15:01:55.0468 8368        dot4usb        (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/07/11 15:01:55.0529 8368        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/07/11 15:01:55.0610 8368        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/11 15:01:55.0649 8368        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/07/11 15:01:55.0756 8368        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/07/11 15:01:55.0800 8368        ElbyCDIO        (d71233d7ccc2e64f8715a20428d5a33b) C:\Windows\system32\Drivers\ElbyCDIO.sys
2011/07/11 15:01:55.0844 8368        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/07/11 15:01:55.0896 8368        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/07/11 15:01:56.0027 8368        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/07/11 15:01:56.0083 8368        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/07/11 15:01:56.0112 8368        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/11 15:01:56.0171 8368        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/07/11 15:01:56.0195 8368        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/07/11 15:01:56.0216 8368        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/11 15:01:56.0244 8368        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/07/11 15:01:56.0344 8368        FsUsbExDisk    (cbe5f69a5e5b918225f420ba748f3742) C:\Windows\system32\FsUsbExDisk.SYS
2011/07/11 15:01:56.0403 8368        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/11 15:01:56.0425 8368        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/07/11 15:01:56.0523 8368        ggflt          (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
2011/07/11 15:01:56.0572 8368        ggsemc          (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
2011/07/11 15:01:56.0660 8368        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
2011/07/11 15:01:56.0716 8368        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/07/11 15:01:56.0769 8368        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/07/11 15:01:56.0797 8368        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/07/11 15:01:56.0863 8368        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/07/11 15:01:56.0896 8368        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/07/11 15:01:56.0978 8368        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/07/11 15:01:57.0046 8368        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/07/11 15:01:57.0101 8368        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/07/11 15:01:57.0165 8368        ialm            (496db78e6a0c4c44023d9a92b4a7ac31) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/07/11 15:01:57.0222 8368        iaStor          (71ecc07bc7c5e24c3dd01d8a29a24054) C:\Windows\system32\DRIVERS\iaStor.sys
2011/07/11 15:01:57.0253 8368        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/07/11 15:01:57.0286 8368        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/07/11 15:01:57.0401 8368        IntcAzAudAddService (b4fd14f7b231e358bec6c71d1a6c2845) C:\Windows\system32\drivers\RTKVHDA.sys
2011/07/11 15:01:57.0473 8368        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/07/11 15:01:57.0507 8368        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/11 15:01:57.0559 8368        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/11 15:01:57.0602 8368        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/07/11 15:01:57.0625 8368        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/07/11 15:01:57.0660 8368        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/07/11 15:01:57.0687 8368        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/07/11 15:01:57.0731 8368        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/07/11 15:01:57.0755 8368        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/07/11 15:01:57.0786 8368        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/07/11 15:01:57.0808 8368        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/07/11 15:01:57.0847 8368        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/07/11 15:01:57.0896 8368        KMDFMEMIO      (ebc507f129df8f0e0ca270dcfc0cf87f) C:\Windows\system32\DRIVERS\kmdfmemio.sys
2011/07/11 15:01:57.0967 8368        KMWDFILTER      (566c5fd480fdbce3ba5cf9fbcffaea9a) C:\Windows\system32\DRIVERS\KMWDFILTER.sys
2011/07/11 15:01:58.0028 8368        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/11 15:01:58.0088 8368        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/11 15:01:58.0134 8368        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/07/11 15:01:58.0188 8368        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/07/11 15:01:58.0234 8368        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/07/11 15:01:58.0251 8368        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/07/11 15:01:58.0318 8368        MBAMProtector  (3d2c13377763eeac0ca6fb46f57217ed) C:\Windows\system32\drivers\mbam.sys
2011/07/11 15:01:58.0367 8368        MBAMSwissArmy  (b309912717c29fc67e1ba4730a82b6dd) C:\Windows\system32\drivers\mbamswissarmy.sys
2011/07/11 15:01:58.0394 8368        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/07/11 15:01:58.0461 8368        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/07/11 15:01:58.0509 8368        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/07/11 15:01:58.0556 8368        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/11 15:01:58.0585 8368        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/07/11 15:01:58.0618 8368        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/11 15:01:58.0645 8368        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/07/11 15:01:58.0677 8368        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/07/11 15:01:58.0708 8368        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/11 15:01:58.0734 8368        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/07/11 15:01:58.0775 8368        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/07/11 15:01:58.0838 8368        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/11 15:01:58.0889 8368        mrxsmb10        (d4a3c7c580c4ccb5c06f2ada933ad507) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/11 15:01:58.0910 8368        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/11 15:01:58.0940 8368        msahci          (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/07/11 15:01:58.0988 8368        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/07/11 15:01:59.0046 8368        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/07/11 15:01:59.0079 8368        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/07/11 15:01:59.0116 8368        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/11 15:01:59.0153 8368        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/11 15:01:59.0174 8368        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/07/11 15:01:59.0228 8368        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/07/11 15:01:59.0259 8368        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/07/11 15:01:59.0307 8368        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/07/11 15:01:59.0336 8368        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/07/11 15:01:59.0411 8368        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/11 15:01:59.0502 8368        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/07/11 15:01:59.0535 8368        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/11 15:01:59.0558 8368        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/11 15:01:59.0597 8368        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/11 15:01:59.0645 8368        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/07/11 15:01:59.0680 8368        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/11 15:01:59.0707 8368        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/11 15:01:59.0824 8368        NETw3v32        (35d5458d9a1b26b2005abffbf4c1c5e7) C:\Windows\system32\DRIVERS\NETw3v32.sys
2011/07/11 15:01:59.0880 8368        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/07/11 15:01:59.0948 8368        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/07/11 15:02:00.0002 8368        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/11 15:02:00.0051 8368        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/07/11 15:02:00.0095 8368        ntiomin        (8a2788ff5aa0fe75d7231417200406ff) C:\Windows\system32\drivers\ntiomin.sys
2011/07/11 15:02:00.0119 8368        ntiopnp        (5850c28057ddea04390b88f8cc482504) C:\Windows\system32\drivers\ntiopnp.sys
2011/07/11 15:02:00.0142 8368        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/07/11 15:02:00.0173 8368        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/07/11 15:02:00.0199 8368        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/07/11 15:02:00.0221 8368        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/07/11 15:02:00.0264 8368        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/07/11 15:02:00.0348 8368        ohci1394        (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/07/11 15:02:00.0407 8368        optousb        (af312907835a5ea9e56779b22c561268) C:\Windows\system32\DRIVERS\optousb.sys
2011/07/11 15:02:00.0430 8368        optovcm        (a6129c7e757e3e4ee634ccc4ad9cf826) C:\Windows\system32\DRIVERS\optovcm.sys
2011/07/11 15:02:00.0490 8368        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/07/11 15:02:00.0537 8368        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/07/11 15:02:00.0560 8368        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/07/11 15:02:00.0608 8368        pccsmcfd        (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys
2011/07/11 15:02:00.0656 8368        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/07/11 15:02:00.0698 8368        pciide          (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/07/11 15:02:00.0739 8368        pcmcia          (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/07/11 15:02:00.0801 8368        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/07/11 15:02:00.0896 8368        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/11 15:02:00.0927 8368        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/07/11 15:02:00.0987 8368        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/11 15:02:01.0047 8368        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/07/11 15:02:01.0087 8368        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/07/11 15:02:01.0119 8368        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/11 15:02:01.0138 8368        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/11 15:02:01.0165 8368        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/11 15:02:01.0233 8368        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/11 15:02:01.0297 8368        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/11 15:02:01.0326 8368        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/11 15:02:01.0362 8368        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/11 15:02:01.0400 8368        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/07/11 15:02:01.0419 8368        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/11 15:02:01.0462 8368        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/07/11 15:02:01.0600 8368        RFCOMM          (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys
2011/07/11 15:02:01.0652 8368        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/11 15:02:01.0736 8368        RTL8192su      (4b36f90ef3515b986944aa223871e12e) C:\Windows\system32\DRIVERS\RTL8192su.sys
2011/07/11 15:02:01.0774 8368        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/07/11 15:02:01.0836 8368        sdbus          (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/07/11 15:02:01.0878 8368        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/07/11 15:02:01.0908 8368        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/07/11 15:02:01.0939 8368        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/07/11 15:02:01.0964 8368        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/07/11 15:02:02.0030 8368        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/07/11 15:02:02.0050 8368        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/07/11 15:02:02.0070 8368        sffp_sd        (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/07/11 15:02:02.0089 8368        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/07/11 15:02:02.0129 8368        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/07/11 15:02:02.0156 8368        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/07/11 15:02:02.0200 8368        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/07/11 15:02:02.0269 8368        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/07/11 15:02:02.0337 8368        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/07/11 15:02:02.0407 8368        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/07/11 15:02:02.0456 8368        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/11 15:02:02.0480 8368        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/11 15:02:02.0563 8368        ss_bbus        (3f0164fbc0bd1adbd02df9759181451a) C:\Windows\system32\DRIVERS\ss_bbus.sys
2011/07/11 15:02:02.0602 8368        ss_bmdfl        (b89d62206034e5fe573c80a24dd55675) C:\Windows\system32\DRIVERS\ss_bmdfl.sys
2011/07/11 15:02:02.0652 8368        ss_bmdm        (1ed0fcea586fe2a416ee15196e5631dd) C:\Windows\system32\DRIVERS\ss_bmdm.sys
2011/07/11 15:02:02.0710 8368        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/07/11 15:02:02.0744 8368        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/07/11 15:02:02.0775 8368        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/07/11 15:02:02.0802 8368        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/07/11 15:02:02.0876 8368        SynTP          (71837fbce3fd8143953444b3ff7938dc) C:\Windows\system32\DRIVERS\SynTP.sys
2011/07/11 15:02:02.0925 8368        tap0901        (1e89de7a4fb7a854ebb241d0aa8996dd) C:\Windows\system32\DRIVERS\tap0901.sys
2011/07/11 15:02:02.0982 8368        tbhsd          (77bd6143c6dce0a1bf7b5571bed860dc) C:\Windows\system32\drivers\tbhsd.sys
2011/07/11 15:02:03.0044 8368        Tcpip          (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/07/11 15:02:03.0079 8368        Tcpip6          (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/11 15:02:03.0149 8368        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/11 15:02:03.0203 8368        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/07/11 15:02:03.0230 8368        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/07/11 15:02:03.0301 8368        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/11 15:02:03.0357 8368        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/07/11 15:02:03.0433 8368        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/11 15:02:03.0483 8368        TTHID          (fb5e6989a3f6e6378a45406b1c3a0605) C:\Windows\system32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys
2011/07/11 15:02:03.0520 8368        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/07/11 15:02:03.0543 8368        tunnel          (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/11 15:02:03.0571 8368        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/07/11 15:02:03.0604 8368        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/11 15:02:03.0661 8368        UDXTTM6010      (2fcf594487fb01e3648d4a35156d1596) C:\Windows\system32\DRIVERS\UDXTTM6010.sys
2011/07/11 15:02:03.0733 8368        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/07/11 15:02:03.0767 8368        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/07/11 15:02:03.0792 8368        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/07/11 15:02:03.0821 8368        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/07/11 15:02:03.0853 8368        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/07/11 15:02:03.0909 8368        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/11 15:02:03.0941 8368        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/07/11 15:02:04.0000 8368        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/07/11 15:02:04.0078 8368        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/11 15:02:04.0146 8368        usbohci        (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/07/11 15:02:04.0204 8368        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/11 15:02:04.0253 8368        usbscan        (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/07/11 15:02:04.0308 8368        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/07/11 15:02:04.0422 8368        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/07/11 15:02:04.0463 8368        usbvideo        (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/07/11 15:02:04.0514 8368        VClone          (fce98c43b5c5db8e0da8ea0e2b45e044) C:\Windows\system32\DRIVERS\VClone.sys
2011/07/11 15:02:04.0575 8368        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/11 15:02:04.0608 8368        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/07/11 15:02:04.0662 8368        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/07/11 15:02:04.0688 8368        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/07/11 15:02:04.0713 8368        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/07/11 15:02:04.0753 8368        VMC326          (20a559a25c4ae3f9b35f8229636ee5a7) C:\Windows\system32\Drivers\VMC326.sys
2011/07/11 15:02:04.0782 8368        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/07/11 15:02:04.0903 8368        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/07/11 15:02:04.0970 8368        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/07/11 15:02:05.0009 8368        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/07/11 15:02:05.0048 8368        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/07/11 15:02:05.0075 8368        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/11 15:02:05.0089 8368        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/11 15:02:05.0143 8368        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/07/11 15:02:05.0193 8368        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/11 15:02:05.0341 8368        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/07/11 15:02:05.0434 8368        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/11 15:02:05.0502 8368        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/07/11 15:02:05.0586 8368        yukonwlh        (6d16a5c05d4fa06fade1d97580986803) C:\Windows\system32\DRIVERS\yk60x86.sys
2011/07/11 15:02:05.0672 8368        MBR (0x1B8)    (7efe35d60f81b18be2fcd6513e1175d9) \Device\Harddisk0\DR0
2011/07/11 15:02:06.0419 8368        Boot (0x1200)  (edb6ad3dee837da5708070a657c9e38a) \Device\Harddisk0\DR0\Partition0
2011/07/11 15:02:06.0480 8368        Boot (0x1200)  (6d14ac8580fc4260268220eaedfa73ce) \Device\Harddisk0\DR0\Partition1
2011/07/11 15:02:06.0502 8368        ================================================================================
2011/07/11 15:02:06.0502 8368        Scan finished
2011/07/11 15:02:06.0502 8368        ================================================================================
2011/07/11 15:02:06.0517 7296        Detected object count: 0
2011/07/11 15:02:06.0517 7296        Actual detected object count: 0


cosinus 11.07.2011 14:50

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

chaoskomet 11.07.2011 15:28

combo fix möchte das ich avg deinstalliere obwohl ich avg schutz etc. abgeschaltet habe.

soll ich das machen?

cosinus 11.07.2011 15:34

Ja, müsste ich mal in die Anleitung aufnehmen. CF verlngt, dass AVG deinstalliert werden muss :(

chaoskomet 11.07.2011 16:32

so nach paar neustarts - kann ich endlich combofix log schreiben:

Code:

ComboFix 11-07-11.02 - Chaoskomet 11.07.2011  17:10:52.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3036.2123 [GMT 2:00]
ausgeführt von:: c:\users\Chaoskomet\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-06-11 bis 2011-07-11  ))))))))))))))))))))))))))))))
.
.
2011-07-11 15:20 . 2011-07-11 15:20        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\temp
2011-07-11 15:20 . 2011-07-11 15:20        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-07-11 14:25 . 2011-07-11 15:07        --------        d-----w-        C:\32788R22FWJFW
2011-07-11 12:41 . 2011-07-11 12:41        --------        d-----w-        C:\_OTL
2011-07-11 10:29 . 2011-07-11 10:29        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\ABBYY
2011-07-11 10:27 . 2011-07-11 10:28        --------        d-----w-        c:\program files\ABBYY ScanTo Office 1.0
2011-07-11 10:10 . 2011-07-11 10:10        --------        d-----w-        c:\windows\tessdata
2011-07-11 10:10 . 2011-07-11 10:10        --------        d-----w-        c:\program files\Softi Software
2011-07-11 10:08 . 2011-07-11 10:08        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\Softi Software
2011-07-11 10:02 . 2011-07-11 10:10        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\GetRightToGo
2011-07-11 09:40 . 2011-07-11 09:40        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\Malwarebytes
2011-07-11 09:40 . 2011-05-29 07:11        39984        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-11 09:40 . 2011-07-11 09:40        --------        d-----w-        c:\programdata\Malwarebytes
2011-07-11 09:40 . 2011-05-29 07:11        22712        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-07-11 09:40 . 2011-07-11 09:40        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-07-09 20:05 . 2011-07-09 20:05        404640        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-08 21:22 . 2011-07-08 21:22        --------        d-----w-        c:\program files\ESET
2011-07-05 12:10 . 2011-06-21 17:11        17712        ----a-w-        c:\windows\system32\nitrolocalui2.dll
2011-07-05 12:10 . 2011-06-21 17:11        26416        ----a-w-        c:\windows\system32\nitrolocalmon2.dll
2011-07-05 12:10 . 2011-07-05 12:10        --------        d-----w-        c:\program files\Nitro PDF
2011-07-05 12:10 . 2011-07-05 12:10        --------        d-----w-        c:\program files\Common Files\Nitro PDF
2011-06-30 08:54 . 2011-06-30 08:54        --------        d-----w-        c:\users\Default\AppData\Local\Microsoft Help
2011-06-29 16:46 . 2011-06-29 16:51        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\Audacity
2011-06-29 10:58 . 2011-04-29 15:59        276992        ----a-w-        c:\windows\system32\schannel.dll
2011-06-29 06:27 . 2011-06-29 06:27        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\HP
2011-06-28 09:57 . 2011-06-29 06:27        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\HP
2011-06-28 09:57 . 2011-06-28 09:57        --------        d-----w-        c:\programdata\WEBREG
2011-06-28 09:52 . 2011-06-28 09:52        --------        d-----w-        c:\programdata\HP Product Assistant
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\program files\Common Files\HP
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\program files\Hewlett-Packard
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\program files\Common Files\Hewlett-Packard
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\programdata\Hewlett-Packard
2011-06-27 07:50 . 2007-10-20 16:21        278016        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2011-06-27 07:48 . 2007-10-20 16:25        118272        ----a-w-        c:\windows\system32\hpz3l5mu.dll
2011-06-27 07:48 . 2011-06-29 20:39        --------        d-----w-        c:\program files\HP
2011-06-27 07:47 . 2011-06-28 09:53        --------        d-----w-        c:\programdata\HP
2011-06-27 07:47 . 2008-01-25 12:23        271704        ----a-w-        c:\windows\system32\hpzids01.dll
2011-06-27 07:47 . 2008-01-25 12:22        729088        ----a-w-        c:\windows\system32\hpowiax7.dll
2011-06-27 07:47 . 2008-01-25 12:22        303104        ----a-w-        c:\windows\system32\hpovst15.dll
2011-06-27 07:47 . 2008-01-25 12:22        581632        ----a-w-        c:\windows\system32\hpotscl6.dll
2011-06-27 07:47 . 2008-01-25 12:22        372736        ----a-w-        c:\windows\system32\hppldcoi.dll
2011-06-21 15:01 . 2011-07-11 11:02        --------        d-----w-        c:\program files\CPUCooL
2011-06-20 12:37 . 2011-06-20 12:37        --------        d-----w-        c:\programdata\CyberLink
2011-06-20 12:37 . 2011-06-20 12:37        --------        d-----w-        c:\users\Public\CyberLink
2011-06-18 14:18 . 2011-06-18 14:18        --------        d-----w-        c:\windows\Sun
2011-06-18 14:18 . 2011-06-18 14:18        --------        d-----w-        c:\program files\Common Files\Java
2011-06-16 12:45 . 2011-04-25 15:29        141104        ----a-w-        c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 12:45 . 2011-04-22 23:25        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2011-06-16 12:45 . 2011-04-22 23:35        1797632        ----a-w-        c:\windows\system32\jscript9.dll
2011-06-16 06:00 . 2011-04-14 14:59        75264        ----a-w-        c:\windows\system32\drivers\dfsc.sys
2011-06-16 06:00 . 2011-04-21 13:58        273408        ----a-w-        c:\windows\system32\drivers\afd.sys
2011-06-16 06:00 . 2011-04-29 13:25        146432        ----a-w-        c:\windows\system32\drivers\srv2.sys
2011-06-16 06:00 . 2011-04-29 13:25        102400        ----a-w-        c:\windows\system32\drivers\srvnet.sys
2011-06-16 06:00 . 2010-12-20 16:35        563712        ----a-w-        c:\windows\system32\oleaut32.dll
2011-06-16 06:00 . 2011-05-02 17:16        739328        ----a-w-        c:\windows\system32\inetcomm.dll
2011-06-16 06:00 . 2011-04-29 13:24        214016        ----a-w-        c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 06:00 . 2011-04-29 13:24        79872        ----a-w-        c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 06:00 . 2011-04-29 13:24        106496        ----a-w-        c:\windows\system32\drivers\mrxsmb.sys
2011-06-16 06:00 . 2011-05-02 12:02        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-30 12:02 . 2011-05-30 12:02        37920        ----a-w-        c:\windows\system32\drivers\tbhsd.sys
2011-05-29 11:29 . 2011-05-29 11:29        0        ----a-w-        c:\windows\system32\ConduitEngine.tmp
2011-05-04 02:52 . 2011-03-13 13:35        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2011-04-25 12:42 . 2007-10-25 15:26        5632        ----a-w-        c:\windows\system32\drivers\StarOpen.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}"= "c:\program files\produkttests\prxtbpro0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54        175912        ----a-w-        c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
2011-01-17 14:54        175912        ----a-w-        c:\program files\produkttests\prxtbpro0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}"= "c:\program files\produkttests\prxtbpro0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DCEA9FF9-5C31-40AC-9285-9C25FF04B93A}"= "c:\program files\produkttests\prxtbpro0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-03-11 160592]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2011-04-05 353736]
"Remote Control Editor"="c:\program files\Common Files\TerraTec\Remote\TTTvRc.exe" [2010-12-01 1709128]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-06-24 2423608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-03-12 61440]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-02-13 6814240]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-28 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-02-13 1833504]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-23 114688]
"GfK-WatchDog"="c:\program files\GfKLSPService\GfK-WatchDog.exe" [2010-08-29 60928]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-11 752168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 ewsercd;Huawei DataCard USB Serial Port;c:\windows\system32\DRIVERS\ewsercd.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2011-04-07 13224]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-12-27 31124344]
R3 optousb;OPTO ELECTRONICS optousb;c:\windows\system32\DRIVERS\optousb.sys [2009-08-26 18432]
R3 optovcm;OPTO ELECTRONICS optovcm;c:\windows\system32\DRIVERS\optovcm.sys [2009-08-26 26368]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-09-17 535552]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-04-20 152064]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
R3 TTHID;Cinergy Hybrid-Stick HID service;c:\windows\system32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys [2009-11-04 23104]
R3 UDXTTM6010;Cinergy Hybrid-Stick BDA service;c:\windows\system32\DRIVERS\UDXTTM6010.sys [2009-11-04 763584]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 ntiomin;ntiomin; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 GfK-Reporting-Service;GfK-Reporting-Service;c:\program files\GfK Internet-Monitor\GfK-Reporting.exe [2011-01-20 102400]
S2 GfK-Update-Service;GfK-Update-Service;c:\program files\GfK Internet-Monitor\GfK-Updater.exe [2011-01-20 180224]
S2 GfkLSPService;GfkLSPService;c:\program files\GfKLSPService\GfKLSPService.exe [2010-11-17 3506176]
S2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\system32\DRIVERS\kmdfmemio.sys [2008-08-12 13312]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe [2011-06-21 196912]
S2 Rezip;Rezip;c:\windows\SYSTEM32\Rezip.exe [2009-03-05 311296]
S2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2010-09-03 185640]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2008-01-21 21504]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-07-31 29736]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [2008-11-21 238464]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
yksvcs        REG_MULTI_SZ          yksvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt        REG_MULTI_SZ          hpqcxs08
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://mystart.incredimail.com/mb57
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: RF - Formular ausfüllen - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RF - Formular speichern - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: RF - Menü anpassen - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RF - RoboForm-Leiste ein/aus - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\GfKLSPService.DLL
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Chaoskomet\AppData\Roaming\Mozilla\Firefox\Profiles\ajzdxrw5.default\
FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/mb57|hxxp://www.ichbin.nikonwelt.at/galerie/beitrag/4475|hxxp://www.spielesite.com/|https://login.yahoo.com/config/mail?.intl=de&.done=http%3A%2F%2Fde.mg40.mail.yahoo.com%2Fdc%2Flaunch%3F.rand%3D2ob06o83orpl6
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\Siber Systems\AI RoboForm\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: GfK Internet-Monitor: gacela2@nurago.com - c:\program files\GfK Internet-Monitor
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Bigpoint Games DE Community Toolbar: {0e3dbc69-a682-48da-84e1-82c63a5d678e} - %profile%\extensions\{0e3dbc69-a682-48da-84e1-82c63a5d678e}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: Modify Headers: {b749fc7c-e949-447f-926c-3f4eed6accfe} - %profile%\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-07-11 17:20
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-326891830-3036340036-2452681849-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{000670F7-05A4-819B-DE9B-404A08A846E7}*]
"hakpgcikfgigogid"=hex:6a,61,66,6a,6e,62,6f,6a,6c,6a,69,67,67,70,68,70,6b,66,
  68,61,00,00
"iaipaaedbgcoijoiae"=hex:63,61,62,6a,6d,65,00,7f
"iaeaafcepedaadbccb"=hex:6a,61,66,6a,6e,62,6f,6a,6c,6a,69,67,67,70,68,70,6b,66,
  68,61,00,00
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(5176)
c:\windows\system32\btmmhook.dll
.
Zeit der Fertigstellung: 2011-07-11  17:22:54
ComboFix-quarantined-files.txt  2011-07-11 15:22
.
Vor Suchlauf: 2.805.579.776 Bytes frei
Nach Suchlauf: 2.568.339.456 Bytes frei
.
- - End Of File - - 84659B3E5C9A33B3B488AEDE5141F9F8

darf ich jetzt wieder AVG installieren? das windoof defender ding macht mich nicht unbedingt glücklich

kann man eigentlich ersehen, durch was ich die probleme habe, und sass der schon länger bei mir fest, oder habe ich den bei meinen freunden eingefangen? obwohl ich dort bloss im internet war.

cosinus 11.07.2011 21:33

Zitat:

darf ich jetzt wieder AVG installieren? das windoof defender ding macht mich nicht unbedingt glücklich
Nichts voreilig installieren! Wenn wir mitten in einer Bereinigungsphase sind, macht ein Virenscanner im Hintergrund eh keinen Sinn und von alleine kommen auch keine Viren drauf! Und vergiss nicht dass dein Virenscanner den Befall auch nicht verhindert hat!


Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.


Code:

Regnull::
[HKEY_USERS\S-1-5-21-326891830-3036340036-2452681849-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{000670F7-05A4-819B-DE9B-404A08A846E7}*]

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

chaoskomet 11.07.2011 22:13

okay habe ich gemacht:

Code:

ComboFix 11-07-11.02 - Chaoskomet 11.07.2011  22:57:11.2.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3036.1986 [GMT 2:00]
ausgeführt von:: c:\users\Chaoskomet\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Chaoskomet\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-06-11 bis 2011-07-11  ))))))))))))))))))))))))))))))
.
.
2011-07-11 21:04 . 2011-07-11 21:04        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\temp
2011-07-11 21:04 . 2011-07-11 21:04        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-07-11 17:27 . 2011-07-11 17:27        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\AVG Security Toolbar
2011-07-11 17:04 . 2011-07-11 17:04        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\AVG10
2011-07-11 15:32 . 2011-06-20 06:57        7074640        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{6D8DFFEF-D039-448D-A918-F751965894F4}\mpengine.dll
2011-07-11 15:32 . 2011-05-24 17:14        222080        ------w-        c:\windows\system32\MpSigStub.exe
2011-07-11 12:41 . 2011-07-11 12:41        --------        d-----w-        C:\_OTL
2011-07-11 10:29 . 2011-07-11 10:29        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\ABBYY
2011-07-11 10:27 . 2011-07-11 10:28        --------        d-----w-        c:\program files\ABBYY ScanTo Office 1.0
2011-07-11 10:10 . 2011-07-11 10:10        --------        d-----w-        c:\windows\tessdata
2011-07-11 10:10 . 2011-07-11 10:10        --------        d-----w-        c:\program files\Softi Software
2011-07-11 10:08 . 2011-07-11 10:08        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\Softi Software
2011-07-11 10:02 . 2011-07-11 10:10        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\GetRightToGo
2011-07-11 09:40 . 2011-07-11 09:40        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\Malwarebytes
2011-07-11 09:40 . 2011-05-29 07:11        39984        ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-11 09:40 . 2011-07-11 09:40        --------        d-----w-        c:\programdata\Malwarebytes
2011-07-11 09:40 . 2011-05-29 07:11        22712        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-07-11 09:40 . 2011-07-11 09:40        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2011-07-09 20:05 . 2011-07-09 20:05        404640        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-08 21:22 . 2011-07-08 21:22        --------        d-----w-        c:\program files\ESET
2011-07-05 12:10 . 2011-06-21 17:11        17712        ----a-w-        c:\windows\system32\nitrolocalui2.dll
2011-07-05 12:10 . 2011-06-21 17:11        26416        ----a-w-        c:\windows\system32\nitrolocalmon2.dll
2011-07-05 12:10 . 2011-07-05 12:10        --------        d-----w-        c:\program files\Nitro PDF
2011-07-05 12:10 . 2011-07-05 12:10        --------        d-----w-        c:\program files\Common Files\Nitro PDF
2011-06-30 08:54 . 2011-06-30 08:54        --------        d-----w-        c:\users\Default\AppData\Local\Microsoft Help
2011-06-29 16:46 . 2011-06-29 16:51        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\Audacity
2011-06-29 10:58 . 2011-04-29 15:59        276992        ----a-w-        c:\windows\system32\schannel.dll
2011-06-29 06:27 . 2011-06-29 06:27        --------        d-----w-        c:\users\Chaoskomet\AppData\Local\HP
2011-06-28 09:57 . 2011-06-29 06:27        --------        d-----w-        c:\users\Chaoskomet\AppData\Roaming\HP
2011-06-28 09:57 . 2011-06-28 09:57        --------        d-----w-        c:\programdata\WEBREG
2011-06-28 09:52 . 2011-06-28 09:52        --------        d-----w-        c:\programdata\HP Product Assistant
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\program files\Common Files\HP
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\program files\Hewlett-Packard
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\program files\Common Files\Hewlett-Packard
2011-06-27 07:50 . 2011-06-27 07:50        --------        d-----w-        c:\programdata\Hewlett-Packard
2011-06-27 07:50 . 2007-10-20 16:21        278016        ----a-w-        c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2011-06-27 07:48 . 2007-10-20 16:25        118272        ----a-w-        c:\windows\system32\hpz3l5mu.dll
2011-06-27 07:48 . 2011-06-29 20:39        --------        d-----w-        c:\program files\HP
2011-06-27 07:47 . 2011-06-28 09:53        --------        d-----w-        c:\programdata\HP
2011-06-27 07:47 . 2008-01-25 12:23        271704        ----a-w-        c:\windows\system32\hpzids01.dll
2011-06-27 07:47 . 2008-01-25 12:22        729088        ----a-w-        c:\windows\system32\hpowiax7.dll
2011-06-27 07:47 . 2008-01-25 12:22        303104        ----a-w-        c:\windows\system32\hpovst15.dll
2011-06-27 07:47 . 2008-01-25 12:22        581632        ----a-w-        c:\windows\system32\hpotscl6.dll
2011-06-27 07:47 . 2008-01-25 12:22        372736        ----a-w-        c:\windows\system32\hppldcoi.dll
2011-06-21 15:01 . 2011-07-11 11:02        --------        d-----w-        c:\program files\CPUCooL
2011-06-20 12:37 . 2011-06-20 12:37        --------        d-----w-        c:\programdata\CyberLink
2011-06-20 12:37 . 2011-06-20 12:37        --------        d-----w-        c:\users\Public\CyberLink
2011-06-18 14:18 . 2011-06-18 14:18        --------        d-----w-        c:\windows\Sun
2011-06-18 14:18 . 2011-06-18 14:18        --------        d-----w-        c:\program files\Common Files\Java
2011-06-16 12:45 . 2011-04-25 15:29        141104        ----a-w-        c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 12:45 . 2011-04-22 23:25        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2011-06-16 12:45 . 2011-04-22 23:35        1797632        ----a-w-        c:\windows\system32\jscript9.dll
2011-06-16 06:00 . 2011-04-14 14:59        75264        ----a-w-        c:\windows\system32\drivers\dfsc.sys
2011-06-16 06:00 . 2011-04-21 13:58        273408        ----a-w-        c:\windows\system32\drivers\afd.sys
2011-06-16 06:00 . 2011-04-29 13:25        146432        ----a-w-        c:\windows\system32\drivers\srv2.sys
2011-06-16 06:00 . 2011-04-29 13:25        102400        ----a-w-        c:\windows\system32\drivers\srvnet.sys
2011-06-16 06:00 . 2010-12-20 16:35        563712        ----a-w-        c:\windows\system32\oleaut32.dll
2011-06-16 06:00 . 2011-05-02 17:16        739328        ----a-w-        c:\windows\system32\inetcomm.dll
2011-06-16 06:00 . 2011-04-29 13:24        214016        ----a-w-        c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 06:00 . 2011-04-29 13:24        79872        ----a-w-        c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 06:00 . 2011-04-29 13:24        106496        ----a-w-        c:\windows\system32\drivers\mrxsmb.sys
2011-06-16 06:00 . 2011-05-02 12:02        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-30 12:02 . 2011-05-30 12:02        37920        ----a-w-        c:\windows\system32\drivers\tbhsd.sys
2011-05-29 11:29 . 2011-05-29 11:29        0        ----a-w-        c:\windows\system32\ConduitEngine.tmp
2011-05-04 02:52 . 2011-03-13 13:35        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2011-04-25 12:42 . 2007-10-25 15:26        5632        ----a-w-        c:\windows\system32\drivers\StarOpen.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}"= "c:\program files\produkttests\prxtbpro0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54        175912        ----a-w-        c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
2011-01-17 14:54        175912        ----a-w-        c:\program files\produkttests\prxtbpro0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}"= "c:\program files\produkttests\prxtbpro0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DCEA9FF9-5C31-40AC-9285-9C25FF04B93A}"= "c:\program files\produkttests\prxtbpro0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{dcea9ff9-5c31-40ac-9285-9c25ff04b93a}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-03-11 160592]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2011-04-05 353736]
"Remote Control Editor"="c:\program files\Common Files\TerraTec\Remote\TTTvRc.exe" [2010-12-01 1709128]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-06-24 2423608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-03-12 61440]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-02-13 6814240]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-28 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-02-13 1833504]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-23 114688]
"GfK-WatchDog"="c:\program files\GfKLSPService\GfK-WatchDog.exe" [2010-08-29 60928]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-11 752168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 ewsercd;Huawei DataCard USB Serial Port;c:\windows\system32\DRIVERS\ewsercd.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2011-04-07 13224]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-12-27 31124344]
R3 optousb;OPTO ELECTRONICS optousb;c:\windows\system32\DRIVERS\optousb.sys [2009-08-26 18432]
R3 optovcm;OPTO ELECTRONICS optovcm;c:\windows\system32\DRIVERS\optovcm.sys [2009-08-26 26368]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-09-17 535552]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-04-20 152064]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
R3 TTHID;Cinergy Hybrid-Stick HID service;c:\windows\system32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys [2009-11-04 23104]
R3 UDXTTM6010;Cinergy Hybrid-Stick BDA service;c:\windows\system32\DRIVERS\UDXTTM6010.sys [2009-11-04 763584]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 ntiomin;ntiomin; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 GfK-Reporting-Service;GfK-Reporting-Service;c:\program files\GfK Internet-Monitor\GfK-Reporting.exe [2011-01-20 102400]
S2 GfK-Update-Service;GfK-Update-Service;c:\program files\GfK Internet-Monitor\GfK-Updater.exe [2011-01-20 180224]
S2 GfkLSPService;GfkLSPService;c:\program files\GfKLSPService\GfKLSPService.exe [2010-11-17 3506176]
S2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\system32\DRIVERS\kmdfmemio.sys [2008-08-12 13312]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe [2011-06-21 196912]
S2 Rezip;Rezip;c:\windows\SYSTEM32\Rezip.exe [2009-03-05 311296]
S2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2010-09-03 185640]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2008-01-21 21504]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-07-31 29736]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [2008-11-21 238464]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - FSUSBEXDISK
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
yksvcs        REG_MULTI_SZ          yksvc
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt        REG_MULTI_SZ          hpqcxs08
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://mystart.incredimail.com/mb57
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: RF - Formular ausfüllen - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RF - Formular speichern - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: RF - Menü anpassen - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RF - RoboForm-Leiste ein/aus - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\GfKLSPService.DLL
TCP: DhcpNameServer = 192.168.178.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\users\Chaoskomet\AppData\Roaming\Mozilla\Firefox\Profiles\ajzdxrw5.default\
FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/mb57|hxxp://www.ichbin.nikonwelt.at/galerie/beitrag/4475|hxxp://www.spielesite.com/|https://login.yahoo.com/config/mail?.intl=de&.done=http%3A%2F%2Fde.mg40.mail.yahoo.com%2Fdc%2Flaunch%3F.rand%3D2ob06o83orpl6
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\Siber Systems\AI RoboForm\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: GfK Internet-Monitor: gacela2@nurago.com - c:\program files\GfK Internet-Monitor
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Bigpoint Games DE Community Toolbar: {0e3dbc69-a682-48da-84e1-82c63a5d678e} - %profile%\extensions\{0e3dbc69-a682-48da-84e1-82c63a5d678e}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: Modify Headers: {b749fc7c-e949-447f-926c-3f4eed6accfe} - %profile%\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-07-11 23:04
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4296)
c:\windows\system32\btmmhook.dll
.
Zeit der Fertigstellung: 2011-07-11  23:07:18
ComboFix-quarantined-files.txt  2011-07-11 21:07
ComboFix2.txt  2011-07-11 15:22
.
Vor Suchlauf: 8.929.185.792 Bytes frei
Nach Suchlauf: 8.596.529.152 Bytes frei
.
- - End Of File - - 95388486549237987073494202A412BD

was muss ich jetzt noch machen?

was hat combo jetzt eigentlich gemacht?

cosinus 11.07.2011 22:18

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
  • Doppelklick auf die MBRCheck.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Das Tool braucht nur wenige Sekunden.
  • Danach solltest du eine MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop finden.
Poste mir bitte den Inhalt des .txt Dokumentes

chaoskomet 11.07.2011 23:06

der gmer log erstmal:

Code:

GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-07-12 00:04:59
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.2AC1
Running: gvd0bmdb.exe; Driver: C:\Users\CHAOSK~1\AppData\Local\Temp\aftcypow.sys


---- Kernel code sections - GMER 1.0.15 ----

.text          C:\Windows\system32\DRIVERS\atikmdag.sys                                                            section is writeable [0x8EC04000, 0x258606, 0xE8000020]

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                [740B7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                [7410A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]            [740BBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]      [740AF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                [740B75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]              [740AE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [740E8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]    [740BDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]            [740AFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]              [740AFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]              [740A71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]      [7413CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]          [740DC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]            [740AD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                      [740A6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                      [740A687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[3460] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]        [740B2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device          \Driver\BTHUSB \Device\00000070                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\00000070                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\00000072                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\00000072                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e276d4                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e276d8                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e2770b                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e279d5                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0c6076dbc066                         
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e276d4 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e276d8 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e2770b (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e279d5 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0c6076dbc066 (not active ControlSet)     

---- EOF - GMER 1.0.15 ----


chaoskomet 11.07.2011 23:14

osam:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 00:12:05 on 12.07.2011

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.18

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"BrnStiCp.cpl" - "Brother Industries,Ltd." - C:\Windows\system32\BrnStiCp.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLCFG32.CPL

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"aftcypow" (aftcypow) - ? - C:\Users\CHAOSK~1\AppData\Local\Temp\aftcypow.sys  (Hidden registry entry, rootkit activity | File not found)
"catchme" (catchme) - ? - C:\Users\CHAOSK~1\AppData\Local\Temp\catchme.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"FsUsbExDisk" (FsUsbExDisk) - ? - C:\Windows\system32\FsUsbExDisk.SYS  (File found, but it contains no detailed information)
"Huawei DataCard USB Modem and USB Serial" (hwdatacard) - ? - C:\Windows\System32\DRIVERS\ewusbmdm.sys  (File not found)
"Huawei DataCard USB Serial Port" (ewsercd) - ? - C:\Windows\System32\DRIVERS\ewsercd.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\system32\drivers\IpInIp.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\system32\drivers\NwlnkFlt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\system32\drivers\NwlnkFwd.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"MBAMSwissArmy" (MBAMSwissArmy) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbamswissarmy.sys
"ntiomin" (ntiomin) - ? - C:\Windows\system32\drivers\ntiomin.sys
"ntiopnp" (ntiopnp) - ? - C:\Windows\system32\drivers\ntiopnp.sys
"Tunebite High-Speed Dubbing" (tbhsd) - "RapidSolution Software AG" - C:\Windows\System32\drivers\tbhsd.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{F2DDE6B2-9684-4A55-86D4-E255E237B77C} "avgsecuritytoolbar" - ? - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll  (File not found)
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{0DE76E1C-40C5-4fae-A59A-44EF606A0B02} "AbbyyS2O.S2OShellExtension.1" - "ABBYY (BIT Software)" - C:\Program Files\ABBYY ScanTo Office 1.0\STOShellExtension.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLSHEXT.DLL
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
EzCddax extension "{37DDAAA7-7B07-4e1e-8CFF-B46B63AF2925}" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{4A62FAC4-1670-430B-8C6B-9C7B53F51798} "GfK Internet-Monitor" - ? - C:\Program Files\GfK Internet-Monitor\Gacela2.dll
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "&RoboForm" - "Siber Systems Inc." - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
<binary data> "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
<binary data> "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{dcea9ff9-5c31-40ac-9285-9c25ff04b93a} "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
"Ausfüllen" - ? - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
{80A21664-E813-4F79-B965-2058C0F7A84C} "ClsidExtension" - ? - C:\Program Files\GfK Internet-Monitor\Gacela2.dll
"RoboForm" - ? - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
"Speichern" - ? - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "&RoboForm" - "Siber Systems Inc." - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
{dcea9ff9-5c31-40ac-9285-9c25ff04b93a} "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
{AD6E6555-FB2C-47D4-8339-3E2965509877} "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine " - "Conduit Ltd." - C:\Program Files\ConduitEngine\prxConduitEngine.dll
{4BEEA052-726D-4A6E-B65D-A6BD07C263F3} "GfK Internet-Monitor" - ? - C:\Program Files\GfK Internet-Monitor\Gacela2.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
{dcea9ff9-5c31-40ac-9285-9c25ff04b93a} "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" - ? -  (File not found | COM-object registry key not found)
{724d43a9-0d85-11d4-9908-00400523e39a} "{724d43a9-0d85-11d4-9908-00400523e39a}" - "Siber Systems Inc." - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"AutoStartNPSAgent" - "Samsung Electronics Co., Ltd." - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
"ccleaner" - "Piriform Ltd" - "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
"IncrediMail" - "IncrediMail, Ltd." - C:\Program Files\IncrediMail\bin\IncMail.exe /c
"msnmsgr" - "Microsoft Corporation" - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
"Remote Control Editor" - "Elgato Systems" - "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
"RoboForm" - "Siber Systems" - "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"BCSSync" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"BrMfcWnd" - "Brother Industries, Ltd." - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3" - "Brother Industries, Ltd." - C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"GfK-WatchDog" - "GfK" - C:\Program Files\GfKLSPService\GfK-WatchDog.exe /Debug
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"UCam_Menu" - "CyberLink Corp." - "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
"VirtualCloneDrive" - "Elaborate Bytes AG" - "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll
"PCL hpz3l5mu" - "Hewlett-Packard Company" - C:\Windows\system32\hpz3l5mu.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Program Files\Nero\Update\NASvc.exe,-200" (NAUpdate) - "Nero AG" - C:\Program Files\Nero\Update\NASvc.exe
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
"FsUsbExService" (FsUsbExService) - "Teruten" - C:\Windows\system32\FsUsbExService.Exe
"GfK-Reporting-Service" (GfK-Reporting-Service) - ? - C:\Program Files\GfK Internet-Monitor\GfK-Reporting.exe
"GfK-Update-Service" (GfK-Update-Service) - ? - C:\Program Files\GfK Internet-Monitor\GfK-Updater.exe
"GfkLSPService" (GfkLSPService) - "nurago GmbH" - C:\Program Files\GfKLSPService\GfKLSPService.exe
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Rezip" (Rezip) - ? - C:\Windows\SYSTEM32\Rezip.exe
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
"Sony Ericsson PCCompanion" (Sony Ericsson PCCompanion) - "Avanquest Software" - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
"SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"SQL Server-Browser" (SQLBrowser) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
"TeamViewer 4" (TeamViewer4) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - ? - C:\Windows\SHEBA_~1.SCR  (File not found)

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"GacelaLSP" - "nurago GmbH" - C:\Windows\system32\GfKLSPService.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

MBR:

Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:                       
Windows Version:                Windows Vista Home Premium Edition
Windows Information:                Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer:        SAMSUNG ELECTRONICS CO., LTD.
BIOS Manufacturer:                Phoenix Technologies Ltd.
System Manufacturer:                SAMSUNG ELECTRONICS CO., LTD.
System Product Name:                R520/R522/R620
Logical Drives Mask:                0x000000b4

Kernel Drivers (total 153):
  0x8241E000 \SystemRoot\system32\ntoskrnl.exe
  0x827C9000 \SystemRoot\system32\hal.dll
  0x8A001000 \SystemRoot\system32\kdcom.dll
  0x8A008000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
  0x8A078000 \SystemRoot\system32\PSHED.dll
  0x8A089000 \SystemRoot\system32\BOOTVID.dll
  0x8A091000 \SystemRoot\system32\CLFS.SYS
  0x8A0D2000 \SystemRoot\system32\CI.dll
  0x8A1B2000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x8A22E000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x8A23B000 \SystemRoot\system32\drivers\acpi.sys
  0x8A281000 \SystemRoot\system32\drivers\WMILIB.SYS
  0x8A28A000 \SystemRoot\system32\drivers\msisadrv.sys
  0x8A292000 \SystemRoot\system32\drivers\pci.sys
  0x8A2B9000 \SystemRoot\System32\drivers\partmgr.sys
  0x8A2C8000 \SystemRoot\system32\DRIVERS\compbatt.sys
  0x8A2CB000 \SystemRoot\system32\DRIVERS\BATTC.SYS
  0x8A2D5000 \SystemRoot\system32\drivers\volmgr.sys
  0x8A2E4000 \SystemRoot\System32\drivers\volmgrx.sys
  0x8A32E000 \SystemRoot\System32\drivers\mountmgr.sys
  0x8A401000 \SystemRoot\system32\DRIVERS\iaStor.sys
  0x8A4DC000 \SystemRoot\system32\drivers\atapi.sys
  0x8A4E4000 \SystemRoot\system32\drivers\ataport.SYS
  0x8A502000 \SystemRoot\system32\drivers\msahci.sys
  0x8A50C000 \SystemRoot\system32\drivers\PCIIDEX.SYS
  0x8A51A000 \SystemRoot\system32\drivers\fltmgr.sys
  0x8A54C000 \SystemRoot\system32\drivers\fileinfo.sys
  0x8A55C000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x8A5CD000 \SystemRoot\system32\drivers\ndis.sys
  0x8A6D8000 \SystemRoot\system32\drivers\msrpc.sys
  0x8A703000 \SystemRoot\system32\drivers\NETIO.SYS
  0x8A809000 \SystemRoot\System32\drivers\tcpip.sys
  0x8A8F3000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x8A90E000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x8AA1E000 \SystemRoot\system32\drivers\volsnap.sys
  0x8AA57000 \SystemRoot\System32\Drivers\spldr.sys
  0x8AA5F000 \SystemRoot\System32\Drivers\mup.sys
  0x8AA6E000 \SystemRoot\System32\drivers\ecache.sys
  0x8AA95000 \SystemRoot\system32\drivers\disk.sys
  0x8AAA6000 \SystemRoot\system32\drivers\CLASSPNP.SYS
  0x8AAC7000 \SystemRoot\system32\drivers\crcdisk.sys
  0x8ABB8000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x8ABC3000 \SystemRoot\system32\DRIVERS\tunmp.sys
  0x8EC03000 \SystemRoot\system32\DRIVERS\atikmdag.sys
  0x8F085000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x8F125000 \SystemRoot\System32\drivers\watchdog.sys
  0x8F131000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x8F1BE000 \SystemRoot\system32\DRIVERS\usbuhci.sys
  0x8F1C9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x8F207000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x8F216000 \SystemRoot\system32\DRIVERS\athr.sys
  0x8F305000 \SystemRoot\system32\DRIVERS\yk60x86.sys
  0x8F355000 \SystemRoot\system32\DRIVERS\CmBatt.sys
  0x8F359000 \SystemRoot\system32\DRIVERS\i8042prt.sys
  0x8F36C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x8F377000 \SystemRoot\system32\DRIVERS\SynTP.sys
  0x8F3A7000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x8F3A9000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x8F3B4000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x8F3CC000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0x8ABCC000 \SystemRoot\system32\DRIVERS\msiscsi.sys
  0x8A73E000 \SystemRoot\system32\DRIVERS\storport.sys
  0x8F3DB000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x8F3E6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x8A77F000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x8A78A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x8A7AD000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x8A7BC000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x8A7D0000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x8A7E5000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x8A33E000 \SystemRoot\system32\DRIVERS\VClone.sys
  0x8A34A000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
  0x8F3FD000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x8A370000 \SystemRoot\system32\DRIVERS\ks.sys
  0x8A7F5000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x8A39A000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x8A3A7000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x8A3DC000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x9080D000 \SystemRoot\system32\drivers\HdAudio.sys
  0x9084C000 \SystemRoot\system32\drivers\portcls.sys
  0x90879000 \SystemRoot\system32\drivers\drmk.sys
  0x9089E000 \SystemRoot\system32\drivers\RTKVHDA.sys
  0x90AD5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
  0x90ADE000 \SystemRoot\System32\Drivers\Null.SYS
  0x90AE5000 \SystemRoot\System32\Drivers\Beep.SYS
  0x90AF5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x90AFC000 \SystemRoot\System32\drivers\vga.sys
  0x90B08000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x90B29000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x90B31000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x90B39000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x90B44000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x90B52000 \SystemRoot\System32\DRIVERS\rasacd.sys
  0x90B5B000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x90B71000 \SystemRoot\system32\DRIVERS\smb.sys
  0x90B85000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x90BB7000 \SystemRoot\system32\drivers\afd.sys
  0x90800000 \SystemRoot\system32\drivers\ws2ifsl.sys
  0x90409000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x9041F000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x9042D000 \SystemRoot\System32\Drivers\ntiomin.SYS
  0x90430000 \SystemRoot\System32\Drivers\ntiopnp.SYS
  0x90438000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x9044B000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x90487000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x90491000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
  0x9049B000 \SystemRoot\System32\Drivers\dfsc.sys
  0x904B2000 \SystemRoot\System32\Drivers\VMC326.sys
  0x904ED000 \SystemRoot\System32\Drivers\BTHUSB.sys
  0x904FA000 \SystemRoot\System32\Drivers\bthport.sys
  0x9057A000 \SystemRoot\system32\DRIVERS\KMWDFILTER.sys
  0x90583000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x9058C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x9059C000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x905A4000 \SystemRoot\system32\DRIVERS\rfcomm.sys
  0x905CD000 \SystemRoot\system32\DRIVERS\BthEnum.sys
  0x905D7000 \SystemRoot\system32\DRIVERS\bthpan.sys
  0x905F1000 \SystemRoot\system32\drivers\btwavdt.sys
  0x90662000 \SystemRoot\system32\drivers\btwaudio.sys
  0x906E2000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
  0x906EC000 \SystemRoot\system32\DRIVERS\btwrchid.sys
  0x906EF000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x906FC000 \SystemRoot\System32\Drivers\dump_iaStor.sys
  0x9CC00000 \SystemRoot\System32\win32k.sys
  0x907D7000 \SystemRoot\System32\drivers\Dxapi.sys
  0x907E1000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x9CE20000 \SystemRoot\System32\TSDDD.dll
  0x9CE40000 \SystemRoot\System32\cdd.dll
  0x8AAD0000 \SystemRoot\system32\drivers\luafv.sys
  0x907F0000 \SystemRoot\system32\DRIVERS\kmdfmemio.sys
  0x8AAEB000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x8AAFB000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x8AB25000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0x8AB2F000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x81C0B000 \SystemRoot\system32\drivers\spsys.sys
  0x81CBB000 \SystemRoot\system32\drivers\HTTP.sys
  0x81D28000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0x81D45000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x81D5E000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x81D73000 \SystemRoot\system32\drivers\mrxdav.sys
  0x81D94000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x81DB3000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x81DEC000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0x81E04000 \SystemRoot\System32\DRIVERS\srv2.sys
  0x81E2C000 \SystemRoot\System32\DRIVERS\srv.sys
  0x81E93000 \SystemRoot\system32\drivers\peauth.sys
  0x81F71000 \SystemRoot\System32\Drivers\secdrv.SYS
  0x81F7B000 \SystemRoot\System32\drivers\tcpipreg.sys
  0x81F87000 \SystemRoot\system32\DRIVERS\cdfs.sys
  0x81F9F000 \??\C:\Windows\system32\FsUsbExDisk.SYS
  0x81FA8000 \??\C:\Windows\system32\drivers\mbam.sys
  0x81FAC000 \??\C:\Users\CHAOSK~1\AppData\Local\Temp\aftcypow.sys
  0x77510000 \Windows\System32\ntdll.dll

Processes (total 84):
      0 System Idle Process
      4 SYSTEM
    528 C:\Windows\System32\smss.exe
    596 csrss.exe
    652 C:\Windows\System32\wininit.exe
    672 csrss.exe
    704 C:\Windows\System32\services.exe
    720 C:\Windows\System32\lsass.exe
    732 C:\Windows\System32\lsm.exe
    864 C:\Windows\System32\svchost.exe
    928 C:\Windows\System32\svchost.exe
    1020 C:\Windows\System32\Ati2evxx.exe
    1036 C:\Windows\System32\svchost.exe
    1064 C:\Windows\System32\svchost.exe
    1092 C:\Windows\System32\svchost.exe
    1160 C:\Windows\System32\audiodg.exe
    1176 C:\Windows\System32\svchost.exe
    1192 C:\Windows\System32\SLsvc.exe
    1244 C:\Windows\System32\winlogon.exe
    1296 C:\Windows\System32\svchost.exe
    1436 C:\Windows\System32\svchost.exe
    1476 C:\Windows\System32\svchost.exe
    1776 C:\Windows\System32\spoolsv.exe
    1784 C:\Windows\System32\taskeng.exe
    1816 C:\Windows\System32\svchost.exe
    2016 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    2032 C:\Windows\System32\agrsmsvc.exe
    236 C:\Windows\System32\svchost.exe
    304 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    456 C:\Windows\System32\FsUsbExService.Exe
    780 C:\Program Files\GfK Internet-Monitor\GfK-Reporting.exe
    664 C:\Program Files\GfK Internet-Monitor\GfK-Updater.exe
    1888 C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    2188 C:\Program Files\Nero\Update\NASvc.exe
    2208 C:\Windows\System32\svchost.exe
    2236 C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe
    2312 C:\Windows\System32\svchost.exe
    2348 C:\Windows\System32\svchost.exe
    2396 C:\Windows\System32\Ati2evxx.exe
    2420 C:\Windows\System32\Rezip.exe
    2488 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    2512 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    2588 C:\Windows\System32\svchost.exe
    2680 C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
    2712 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
    2904 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
    3428 C:\Windows\System32\dwm.exe
    3460 C:\Windows\explorer.exe
    3588 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    3600 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    3676 C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    3692 C:\Program Files\GfKLSPService\GfK-WatchDog.exe
    3700 C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    3716 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    3724 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    3732 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    3740 C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
    3764 C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
    3772 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
    3780 C:\Program Files\Windows Media Player\wmpnscfg.exe
    3796 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    3916 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    2392 C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
    1288 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    3368 C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
    1680 C:\Windows\System32\taskeng.exe
    3828 C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
    1344 C:\Windows\System32\taskeng.exe
    3092 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
    2804 C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
    4120 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
    4408 WmiPrvSE.exe
    4900 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    5808 C:\Program Files\Windows Media Player\wmpnetwk.exe
    6052 C:\Windows\System32\svchost.exe
    4184 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    3444 C:\Program Files\GfKLSPService\GfKLSPService.exe
    2132 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    7112 C:\Program Files\Mozilla Firefox\firefox.exe
    7160 C:\Program Files\Mozilla Firefox\plugin-container.exe
    5340 dllhost.exe
    5848 dllhost.exe
    6636 C:\Users\Chaoskomet\Desktop\MBRCheck.exe
    7656 C:\Windows\System32\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`40100000  (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000026`c5a00000  (NTFS)

PhysicalDrive0 Model Number: SAMSUNGHM320II, Rev: 2AC101C4

      Size  Device Name          MBR Status
  --------------------------------------------
    298 GB  \\.\PhysicalDrive0  Unknown MBR code
            SHA1: 90AE6712C96E547F52E3EBE382852AA331FA41FC


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!

nun bin ich ja mal gepsannt wie es weiter geht. :kaffee:

cosinus 11.07.2011 23:49

Wir sollten den MBR manuell fixen. Sichere für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Vista installiert?
Wenn nicht: Schau mal hier => Vista Notfall/Recovery-CD 32-Bit - Dr. Windows

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten)

Falls Du eine normale Vista-Installations-DVD hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der Vista-DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Erstell danach wieder neue Logs mit MBRCheck und wenn es geht GMER.

chaoskomet 11.07.2011 23:54

warum was ist denn los? wenn ich fragen darf.

das werde ich morgen, oder bessergesagt heute mittag machen.

müsste jetzt langsam ins bett, muss morgen früh raus.

ich bedank mich für deine hilfe, und die geduld. :abklatsch:

cosinus 11.07.2011 23:56

Zitat:

298 GB \\.\PhysicalDrive0 Unknown MBR code
Das ist los. Unbekannter MBR ist für mich Sorge genug.

chaoskomet 12.07.2011 00:26

ging ja doch schneller mit laden und brennen als ich dachte - mbr:

Code:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:                       
Windows Version:                Windows Vista Home Premium Edition
Windows Information:                Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer:        SAMSUNG ELECTRONICS CO., LTD.
BIOS Manufacturer:                Phoenix Technologies Ltd.
System Manufacturer:                SAMSUNG ELECTRONICS CO., LTD.
System Product Name:                R520/R522/R620
Logical Drives Mask:                0x000000b4

Kernel Drivers (total 153):
  0x8241C000 \SystemRoot\system32\ntoskrnl.exe
  0x827C7000 \SystemRoot\system32\hal.dll
  0x8A00D000 \SystemRoot\system32\kdcom.dll
  0x8A014000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
  0x8A084000 \SystemRoot\system32\PSHED.dll
  0x8A095000 \SystemRoot\system32\BOOTVID.dll
  0x8A09D000 \SystemRoot\system32\CLFS.SYS
  0x8A0DE000 \SystemRoot\system32\CI.dll
  0x8A1BE000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x8A23A000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x8A247000 \SystemRoot\system32\drivers\acpi.sys
  0x8A28D000 \SystemRoot\system32\drivers\WMILIB.SYS
  0x8A296000 \SystemRoot\system32\drivers\msisadrv.sys
  0x8A29E000 \SystemRoot\system32\drivers\pci.sys
  0x8A2C5000 \SystemRoot\System32\drivers\partmgr.sys
  0x8A2D4000 \SystemRoot\system32\DRIVERS\compbatt.sys
  0x8A2D7000 \SystemRoot\system32\DRIVERS\BATTC.SYS
  0x8A2E1000 \SystemRoot\system32\drivers\volmgr.sys
  0x8A2F0000 \SystemRoot\System32\drivers\volmgrx.sys
  0x8A33A000 \SystemRoot\System32\drivers\mountmgr.sys
  0x8A409000 \SystemRoot\system32\DRIVERS\iaStor.sys
  0x8A4E4000 \SystemRoot\system32\drivers\atapi.sys
  0x8A4EC000 \SystemRoot\system32\drivers\ataport.SYS
  0x8A50A000 \SystemRoot\system32\drivers\msahci.sys
  0x8A514000 \SystemRoot\system32\drivers\PCIIDEX.SYS
  0x8A522000 \SystemRoot\system32\drivers\fltmgr.sys
  0x8A554000 \SystemRoot\system32\drivers\fileinfo.sys
  0x8A564000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x8A5D5000 \SystemRoot\system32\drivers\ndis.sys
  0x8A6E0000 \SystemRoot\system32\drivers\msrpc.sys
  0x8A70B000 \SystemRoot\system32\drivers\NETIO.SYS
  0x8A80D000 \SystemRoot\System32\drivers\tcpip.sys
  0x8A8F7000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x8A912000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x8AA22000 \SystemRoot\system32\drivers\volsnap.sys
  0x8AA5B000 \SystemRoot\System32\Drivers\spldr.sys
  0x8AA63000 \SystemRoot\System32\Drivers\mup.sys
  0x8AA72000 \SystemRoot\System32\drivers\ecache.sys
  0x8AA99000 \SystemRoot\system32\drivers\disk.sys
  0x8AAAA000 \SystemRoot\system32\drivers\CLASSPNP.SYS
  0x8AACB000 \SystemRoot\system32\drivers\crcdisk.sys
  0x8ABBC000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x8ABC7000 \SystemRoot\system32\DRIVERS\tunmp.sys
  0x8E803000 \SystemRoot\system32\DRIVERS\atikmdag.sys
  0x8EC85000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x8ED25000 \SystemRoot\System32\drivers\watchdog.sys
  0x8ED31000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x8EDBE000 \SystemRoot\system32\DRIVERS\usbuhci.sys
  0x8EDC9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x8EE07000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x8EE16000 \SystemRoot\system32\DRIVERS\athr.sys
  0x8EF05000 \SystemRoot\system32\DRIVERS\yk60x86.sys
  0x8EF55000 \SystemRoot\system32\DRIVERS\CmBatt.sys
  0x8EF59000 \SystemRoot\system32\DRIVERS\i8042prt.sys
  0x8EF6C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x8EF77000 \SystemRoot\system32\DRIVERS\SynTP.sys
  0x8EFA7000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x8EFA9000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x8EFB4000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x8EFCC000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0x8ABD0000 \SystemRoot\system32\DRIVERS\msiscsi.sys
  0x8A746000 \SystemRoot\system32\DRIVERS\storport.sys
  0x8EFDB000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x8EFE6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x8A800000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x8A787000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x8A7AA000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x8A7B9000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x8A7CD000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x8A7E2000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x8A7F2000 \SystemRoot\system32\DRIVERS\VClone.sys
  0x8A34A000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
  0x8EFFD000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x8A370000 \SystemRoot\system32\DRIVERS\ks.sys
  0x8A39A000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x8A3A4000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x8A3B1000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x8A3E6000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x8E008000 \SystemRoot\system32\drivers\HdAudio.sys
  0x8E047000 \SystemRoot\system32\drivers\portcls.sys
  0x8E074000 \SystemRoot\system32\drivers\drmk.sys
  0x8E099000 \SystemRoot\system32\drivers\RTKVHDA.sys
  0x8E2D0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
  0x8E2D9000 \SystemRoot\System32\Drivers\Null.SYS
  0x8E2E0000 \SystemRoot\System32\Drivers\Beep.SYS
  0x8E2F0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x8E2F7000 \SystemRoot\System32\drivers\vga.sys
  0x8E303000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x8E324000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x8E32C000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x8E334000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x8E33F000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x8E34D000 \SystemRoot\System32\DRIVERS\rasacd.sys
  0x8E356000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x8E36C000 \SystemRoot\system32\DRIVERS\smb.sys
  0x8E380000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x8E3B2000 \SystemRoot\system32\drivers\afd.sys
  0x8E2E7000 \SystemRoot\system32\drivers\ws2ifsl.sys
  0x8F407000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x8F41D000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x8F42B000 \SystemRoot\System32\Drivers\ntiomin.SYS
  0x8F42E000 \SystemRoot\System32\Drivers\ntiopnp.SYS
  0x8F436000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x8F449000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x8F485000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x8F48F000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
  0x8F499000 \SystemRoot\System32\Drivers\dfsc.sys
  0x8F4B0000 \SystemRoot\System32\Drivers\BTHUSB.sys
  0x8F4BD000 \SystemRoot\System32\Drivers\bthport.sys
  0x8F53D000 \SystemRoot\System32\Drivers\VMC326.sys
  0x8F578000 \SystemRoot\system32\DRIVERS\rfcomm.sys
  0x8F5A1000 \SystemRoot\system32\DRIVERS\BthEnum.sys
  0x8F5AB000 \SystemRoot\system32\DRIVERS\bthpan.sys
  0x8F5C5000 \SystemRoot\system32\drivers\btwavdt.sys
  0x8F636000 \SystemRoot\system32\drivers\btwaudio.sys
  0x8F6B6000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
  0x8F6C0000 \SystemRoot\system32\DRIVERS\btwrchid.sys
  0x8F6C3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x8F6D3000 \SystemRoot\system32\DRIVERS\KMWDFILTER.sys
  0x8F6DC000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x8F6E5000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x8F6ED000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x8F6FA000 \SystemRoot\System32\Drivers\dump_iaStor.sys
  0x81860000 \SystemRoot\System32\win32k.sys
  0x8F7D5000 \SystemRoot\System32\drivers\Dxapi.sys
  0x8F7DF000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x81A80000 \SystemRoot\System32\TSDDD.dll
  0x81AA0000 \SystemRoot\System32\cdd.dll
  0x8AAD4000 \SystemRoot\system32\drivers\luafv.sys
  0x8F7EE000 \SystemRoot\system32\DRIVERS\kmdfmemio.sys
  0x8AAEF000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x8AAFF000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x8F7F6000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0x8AB29000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x9B404000 \SystemRoot\system32\drivers\spsys.sys
  0x9B4B4000 \SystemRoot\system32\drivers\HTTP.sys
  0x9B521000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0x9B53E000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x9B557000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x9B56C000 \SystemRoot\system32\drivers\mrxdav.sys
  0x9B58D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x9B5AC000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x9B5E5000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0x9B5FD000 \SystemRoot\System32\DRIVERS\srv2.sys
  0x9B625000 \SystemRoot\System32\DRIVERS\srv.sys
  0x9B68C000 \SystemRoot\system32\drivers\peauth.sys
  0x9B76A000 \SystemRoot\System32\Drivers\secdrv.SYS
  0x9B774000 \SystemRoot\System32\drivers\tcpipreg.sys
  0x9B780000 \SystemRoot\system32\DRIVERS\cdfs.sys
  0x9B796000 \SystemRoot\system32\drivers\MSPQM.sys
  0x9B798000 \??\C:\Windows\system32\FsUsbExDisk.SYS
  0x9B7A1000 \??\C:\Windows\system32\drivers\mbam.sys
  0x772F0000 \Windows\System32\ntdll.dll

Processes (total 88):
      0 System Idle Process
      4 SYSTEM
    496 C:\Windows\System32\smss.exe
    576 csrss.exe
    640 csrss.exe
    648 C:\Windows\System32\wininit.exe
    688 C:\Windows\System32\services.exe
    712 C:\Windows\System32\winlogon.exe
    728 C:\Windows\System32\lsass.exe
    736 C:\Windows\System32\lsm.exe
    896 C:\Windows\System32\svchost.exe
    956 C:\Windows\System32\svchost.exe
    1104 C:\Windows\System32\Ati2evxx.exe
    1124 C:\Windows\System32\svchost.exe
    1152 C:\Windows\System32\svchost.exe
    1172 C:\Windows\System32\svchost.exe
    1272 C:\Windows\System32\audiodg.exe
    1304 C:\Windows\System32\svchost.exe
    1320 C:\Windows\System32\SLsvc.exe
    1388 C:\Windows\System32\svchost.exe
    1408 C:\Windows\System32\Ati2evxx.exe
    1548 C:\Windows\System32\svchost.exe
    1576 C:\Windows\System32\svchost.exe
    1836 C:\Windows\System32\spoolsv.exe
    1844 C:\Windows\System32\taskeng.exe
    1876 C:\Windows\System32\svchost.exe
    256 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    284 C:\Windows\System32\agrsmsvc.exe
    312 C:\Windows\System32\svchost.exe
    516 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    568 C:\Windows\System32\FsUsbExService.Exe
    1404 C:\Program Files\GfK Internet-Monitor\GfK-Reporting.exe
    1456 C:\Program Files\GfK Internet-Monitor\GfK-Updater.exe
    2164 C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    2324 C:\Program Files\Nero\Update\NASvc.exe
    2348 C:\Windows\System32\svchost.exe
    2384 C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe
    2624 C:\Windows\System32\taskeng.exe
    2632 C:\Windows\System32\svchost.exe
    2644 C:\Windows\System32\svchost.exe
    2712 C:\Windows\System32\taskeng.exe
    2728 C:\Windows\System32\Rezip.exe
    2744 C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
    2768 C:\Windows\System32\dwm.exe
    2788 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
    2796 C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe
    2820 C:\Windows\explorer.exe
    2860 C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
    2872 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    2992 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
    3008 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    3028 C:\Windows\System32\svchost.exe
    3084 C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
    3156 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
    3380 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
    3684 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    3692 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    4016 C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    4032 C:\Program Files\GfKLSPService\GfK-WatchDog.exe
    4048 C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    4068 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    4080 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    4088 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    2188 C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
    1624 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    1340 C:\Program Files\IncrediMail\Bin\IncMail.exe
    1704 C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
    2400 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
    2412 C:\Program Files\Windows Media Player\wmpnscfg.exe
    1832 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    2500 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    3812 C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
    1376 WmiPrvSE.exe
    2264 C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
    2340 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    4120 C:\Program Files\IncrediMail\Bin\ImApp.exe
    4276 C:\Windows\servicing\TrustedInstaller.exe
    4368 C:\Program Files\Windows Media Player\wmpnetwk.exe
    4676 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    4868 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    4960 C:\Program Files\Windows Live\Contacts\wlcomm.exe
    5288 C:\Windows\System32\svchost.exe
    6216 C:\Program Files\GfKLSPService\GfKLSPService.exe
    7992 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    4396 dllhost.exe
    4348 dllhost.exe
    5020 C:\Users\Chaoskomet\Desktop\MBRCheck.exe
    4840 C:\Windows\System32\conime.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`40100000  (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000026`c5a00000  (NTFS)

PhysicalDrive0 Model Number: SAMSUNGHM320II, Rev: 2AC101C4

      Size  Device Name          MBR Status
  --------------------------------------------
    298 GB  \\.\PhysicalDrive0  Windows 2008 MBR code detected
            SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!


chaoskomet 12.07.2011 00:40

gmer hat diesmal auf den ersten mal geklappt, und das log ist:

Code:

GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-07-12 01:38:29
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.2AC1
Running: gvd0bmdb.exe; Driver: C:\Users\CHAOSK~1\AppData\Local\Temp\aftcypow.sys


---- Kernel code sections - GMER 1.0.15 ----

.text          C:\Windows\system32\DRIVERS\atikmdag.sys                                                            section is writeable [0x8E804000, 0x258606, 0xE8000020]

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                [74347817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                [7439A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]            [7434BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]      [7433F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                [743475E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]              [7433E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]  [74378395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]    [7434DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]            [7433FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]              [7433FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]              [743371CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]      [743CCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]          [7436C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]            [7433D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                      [74336853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                      [7433687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT            C:\Windows\Explorer.EXE[2820] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]        [74342AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                              Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device          \Driver\BTHUSB \Device\00000070                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\00000070                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\0000006e                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\0000006e                                                                      bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e276d4                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e276d8                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e2770b                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269e279d5                         
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0c6076dbc066                         
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e276d4 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e276d8 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e2770b (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269e279d5 (not active ControlSet)     
Reg            HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0c6076dbc066 (not active ControlSet)     

---- EOF - GMER 1.0.15 ----

so nun gehe ich noch eine rauchen, und warte mal was jetzt noch passiert.

cosinus 12.07.2011 00:45

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


chaoskomet 12.07.2011 08:34

hier der malwarescan:

Code:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Datenbank Version: 7082

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

12.07.2011 04:58:31
mbam-log-2011-07-12 (04-58-31).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|F:\|)
Durchsuchte Objekte: 292242
Laufzeit: 3 Stunde(n), 12 Minute(n), 12 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

und superantispy:


Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/12/2011 at 05:02 AM

Application Version : 4.55.1000

Core Rules Database Version : 7396
Trace Rules Database Version: 5208

Scan type      : Complete Scan
Total Scan Time : 03:04:46

Memory items scanned      : 876
Memory threats detected  : 0
Registry items scanned    : 10037
Registry threats detected : 0
File items scanned        : 31287
File threats detected    : 11

Adware.Tracking Cookie
        C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Cookies\chaoskomet@bs.serving-sys[1].txt
        C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Cookies\chaoskomet@atdmt[2].txt
        C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Cookies\chaoskomet@serving-sys[1].txt
        hottraffic.nl [ C:\Users\Chaoskomet\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YTXQRASK ]
        static1.pornturbo.com [ C:\Users\Chaoskomet\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YTXQRASK ]
        C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chaoskomet@atdmt[2].txt
        C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chaoskomet@avgtechnologies.112.2o7[1].txt
        C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chaoskomet@doubleclick[1].txt

Trojan.Agent/Gen-Falint
        C:\PROGRAM FILES\SAMSUNG\EASY NETWORK MANAGER\ENM.EXE
        C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SAMSUNG\EASY NETWORK MANAGER\EASY NETWORK MANAGER.LNK
        C:\USERS\PUBLIC\DESKTOP\EASY NETWORK MANAGER.LNK

dann eset scan.

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=17b9d81b195ac4429093ad2aa4b2bb9d
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-07-08 11:43:51
# local_time=2011-07-09 01:43:51 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1032 16777213 100 85 52874 53454236 0 0
# compatibility_mode=5892 16776574 100 95 10244821 147692972 0 0
# compatibility_mode=8192 67108863 100 0 115 115 0 0
# scanned=140264
# found=0
# cleaned=0
# scan_time=8387
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=17b9d81b195ac4429093ad2aa4b2bb9d
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-07-12 04:01:09
# local_time=2011-07-12 06:01:09 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1032 16777214 0 1 13257 13257 0 0
# compatibility_mode=5892 16776574 100 100 32327 147963435 0 0
# compatibility_mode=8192 67108863 100 0 270578 270578 0 0
# scanned=141516
# found=0
# cleaned=0
# scan_time=12562


cosinus 12.07.2011 11:37

Nur Cookies und Fehlalarme bei SASW - Rechner wieder im Lot?

chaoskomet 12.07.2011 11:40

der läuft wieder scheenn fleissig - darf ich nun avg wieder installieren.

und kommt noch was?

wenn nicht dann bedanke ich mich ganz herzlich, für die gute hilfe.

kann ich das Malwarebytes weiter installiert lassen zu meinen avg und ab und zu mal durch laufen lassen?

cosinus 12.07.2011 14:01

Dann wären wir durch! :abklatsch:

Ja AVG kann wieder rauf. Du kannst auch statt AVG einen anderen Scanner nehmen, zB MSE oder Avast. Aber entweder oder, nicht mehrere gleichzeitig installieren.

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken. (Malwarebytes kollidiert nicht mit anderen Virenscannern)

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie SumatraPDF oder Foxit PDF Reader, beide sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers, hier der direkte Downloadlink:

Mozilla und andere Browser => http://filepony.de/?q=Flash+Player
Internet Explorer => http://fpdownload.adobe.com/get/flas..._player_ax.exe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 10:50 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129