![]() |
Kasperskay meldet "Gefunden: HEUR: Exploit.Java.CVE-2012-0507.gen" Liste der Anhänge anzeigen (Anzahl: 1) Hallo, seit 2 Tagen meldet Kasperky auf meinem Laptop einen Virenfund. Das Virus lässt sich nicht isolieren. Scheint etwas Schwierigeres zu sein.... Kann mir jemand helfen? Wichtiger Hinweis: Malwarebytes hat von früheren Suchläufen in Quarantäne (Sreenshot "Malwarebytes.pdf" als Dateianhang): PUP.OfferBundler.ST PUP.AdBundle PUP.Bundleinstaller.IB Backdoor.Cycbot.Gen Trojan.Downloader Kann ich die Kameraden einfach löschen????? Die erbetenen Protokolle EXTRAS.txt und GMER.txt musste sich leider als Archiv anhängen, weil das Protokoll OLT.txt zu groß war. Umgekehrt war OLT.txt zur groß, um es als Datei anzuhängen. Hier das OLT-Protokoll: OTL logfile created on: 26.03.2013 16:28:57 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HBG\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,99 Gb Total Physical Memory | 1,15 Gb Available Physical Memory | 57,70% Memory free 4,22 Gb Paging File | 2,81 Gb Available in Paging File | 66,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 89,43 Gb Total Space | 8,16 Gb Free Space | 9,13% Space Free | Partition Type: NTFS Drive D: | 52,78 Gb Total Space | 39,44 Gb Free Space | 74,73% Space Free | Partition Type: NTFS Drive E: | 411,08 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: HBG-MOBIL | User Name: HBG | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.03.26 16:21:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HBG\Downloads\OTL.exe PRC - [2013.03.23 09:23:41 | 001,104,280 | ---- | M] (Spotify Ltd) -- C:\Users\HBG\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2013.02.04 17:21:34 | 001,513,536 | ---- | M] (1und1 Mail und Media GmbH) -- C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe PRC - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.01 11:41:13 | 003,491,792 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe PRC - [2012.10.31 15:39:09 | 000,206,448 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe PRC - [2012.06.28 20:49:22 | 001,173,712 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe PRC - [2012.06.28 20:48:10 | 005,924,712 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe PRC - [2012.06.28 20:47:22 | 000,821,584 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe PRC - [2012.06.28 20:47:12 | 000,403,688 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe PRC - [2012.06.28 20:46:30 | 005,993,216 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe PRC - [2012.04.09 17:43:42 | 001,557,160 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe PRC - [2011.10.03 10:10:12 | 000,189,760 | ---- | M] (Solid Documents, LLC) -- C:\Windows\Installer\MSIB24E.tmp PRC - [2011.09.13 09:16:10 | 000,510,920 | ---- | M] () -- C:\Users\HBG\ALDITALKVerbindungsassistent_Launcher.exe PRC - [2011.09.13 09:16:04 | 000,342,984 | ---- | M] () -- C:\Users\HBG\ALDITALKVerbindungsassistent_Service.exe PRC - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe PRC - [2010.10.19 13:29:03 | 002,011,944 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe PRC - [2009.09.06 06:06:20 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe PRC - [2008.10.24 15:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe PRC - [2008.01.19 08:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2006.12.07 18:51:04 | 001,143,152 | ---- | M] (ASUS) -- C:\Program Files\ASUS\Net4Switch\Net4Switch.exe ========== Modules (No Company Name) ========== MOD - [2012.06.28 20:46:10 | 013,005,184 | ---- | M] () -- C:\Program Files\Acronis\TrueImageHome\Common\ti_managers.dll MOD - [2012.06.28 17:34:28 | 000,018,816 | ---- | M] () -- C:\Program Files\Acronis\TrueImageHome\ti_managers_proxy_stub.dll MOD - [2011.09.13 09:16:10 | 000,510,920 | ---- | M] () -- C:\Users\HBG\ALDITALKVerbindungsassistent_Launcher.exe MOD - [2011.04.24 22:13:30 | 007,008,656 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\QtGui4.dll MOD - [2011.04.24 22:13:28 | 000,192,912 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\QtSql4.dll MOD - [2011.04.24 22:13:26 | 001,270,160 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\QtScript4.dll MOD - [2011.04.24 22:13:26 | 000,758,160 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\QtNetwork4.dll MOD - [2011.04.24 22:13:24 | 002,118,032 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\QtCore4.dll MOD - [2011.04.24 22:13:24 | 002,089,360 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\QtDeclarative4.dll MOD - [2011.04.20 18:56:28 | 000,025,088 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll MOD - [2006.12.09 21:47:40 | 000,208,896 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswui.dll MOD - [2006.12.09 17:34:36 | 000,139,264 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipsw_cfgmgr.dll MOD - [2006.12.07 18:42:48 | 000,188,416 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswsysmon.dll MOD - [2006.12.07 18:41:10 | 000,053,248 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswresmgr.dll MOD - [2006.12.07 18:41:02 | 000,204,800 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswcore.dll MOD - [2006.12.07 17:29:06 | 000,007,168 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\iphelper.dll MOD - [2006.12.07 00:55:32 | 000,053,248 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswhlp.dll MOD - [2006.12.07 00:55:22 | 000,086,016 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswds.dll MOD - [2006.12.07 00:42:26 | 000,094,208 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\cxcmrt.dll MOD - [2006.11.21 22:15:32 | 000,073,728 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswgblset.dll MOD - [2006.11.21 22:15:20 | 000,086,016 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswobj.dll MOD - [2006.11.17 18:17:46 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\LogonStartup.dll MOD - [2006.09.22 21:50:40 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ResItf.dll ========== Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe -- (SymAppCore) SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService) SRV - File not found [Disabled | Stopped] -- C:\Program Files\Norton Internet Security\isPwdSvc.exe -- (ISPwdSvc) SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost) SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (CLTNetCnService) SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (ccSetMgr) SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (ccEvtMgr) SRV - [2013.03.13 16:37:49 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.03.08 09:32:13 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.12.18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.12.01 11:41:13 | 003,491,792 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) SRV - [2012.11.13 14:34:46 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2012.10.31 15:39:09 | 000,206,448 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe -- (AVP) SRV - [2012.06.28 20:48:10 | 005,924,712 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe -- (syncagentsrv) SRV - [2012.06.28 20:47:22 | 000,821,584 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2011.10.03 10:10:12 | 000,189,760 | ---- | M] (Solid Documents, LLC) [Auto | Running] -- C:\Windows\Installer\MSIB24E.tmp -- (SCPDFReadSpool) SRV - [2011.09.13 09:16:04 | 000,342,984 | ---- | M] () [Auto | Running] -- C:\Users\HBG\ALDITALKVerbindungsassistent_Service.exe -- (ALDITALKVerbindungsassistent_Service) SRV - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs) SRV - [2011.04.26 13:54:12 | 002,702,848 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) SRV - [2010.10.19 13:29:03 | 002,011,944 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5) SRV - [2009.09.06 06:06:20 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0) SRV - [2008.10.24 15:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) SRV - [2008.01.22 18:35:52 | 000,103,808 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE -- (IJPLMSVC) SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2007.08.03 20:24:54 | 000,125,496 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- (spmgr) SRV - [2007.03.26 19:43:02 | 000,864,816 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv) SRV - [2007.02.06 02:13:14 | 000,094,208 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\ipswuio.sys -- (ipswuio) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbfake.sys -- (hwusbfake) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2013.02.06 13:19:14 | 001,690,784 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rt2870.sys -- (rt2870) DRV - [2012.12.15 09:02:52 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2012.12.15 09:02:52 | 000,106,880 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2012.12.01 11:41:19 | 000,234,752 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\afcdp.sys -- (afcdp) DRV - [2012.12.01 11:40:49 | 000,775,232 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tdrpman.sys -- (tdrpman) DRV - [2012.12.01 11:40:38 | 000,614,592 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\timntr.sys -- (timounter) DRV - [2012.12.01 11:38:55 | 000,126,880 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vididr.sys -- (vididr) DRV - [2012.12.01 11:38:50 | 000,086,496 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vsflt67.sys -- (vidsflt67) DRV - [2012.06.07 15:00:55 | 000,177,600 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\snapman.sys -- (snapman) DRV - [2012.06.07 15:00:53 | 000,080,416 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\fltsrv.sys -- (fltsrv) DRV - [2011.06.08 14:20:17 | 000,570,160 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF) DRV - [2011.03.10 17:36:18 | 000,023,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6) DRV - [2011.03.04 12:23:20 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kl2.sys -- (kl2) DRV - [2011.03.04 12:23:14 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (KL1) DRV - [2011.02.14 02:42:36 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag) DRV - [2011.02.14 02:42:34 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem) DRV - [2011.02.14 02:42:32 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus) DRV - [2009.11.02 19:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt) DRV - [2009.09.05 14:25:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.06.22 19:26:06 | 000,100,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbdev.sys -- (hwusbdev) DRV - [2007.09.23 19:55:01 | 000,109,744 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent) DRV - [2007.08.03 05:26:21 | 000,020,936 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys -- (ghaio) DRV - [2007.03.26 19:43:00 | 000,039,472 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDRm.sys -- (incdrm) DRV - [2007.03.26 19:42:58 | 000,016,304 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\Windows\System32\drivers\InCDrec.sys -- (InCDrec) DRV - [2007.03.26 19:42:56 | 000,037,040 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDPass.sys -- (InCDPass) DRV - [2007.03.26 19:42:44 | 000,108,592 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\Windows\System32\drivers\InCDfs.sys -- (InCDfs) DRV - [2007.01.23 04:00:59 | 000,050,176 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp) DRV - [2006.12.14 17:41:05 | 000,185,744 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\symtdi.sys -- (SYMTDI) DRV - [2006.12.14 17:41:05 | 000,026,384 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\symredrv.sys -- (SYMREDRV) DRV - [2006.12.14 17:40:53 | 000,275,576 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL) DRV - [2006.12.14 17:40:53 | 000,024,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX) DRV - [2006.12.14 17:40:51 | 000,245,880 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP) DRV - [2006.12.14 17:38:35 | 000,831,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20061106.064\NAVEX15.SYS -- (NAVEX15) DRV - [2006.12.14 17:38:33 | 000,079,240 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20061106.064\NAVENG.SYS -- (NAVENG) DRV - [2006.12.14 17:34:33 | 000,202,872 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20061025.029\IDSvix86.sys -- (IDSvix86) DRV - [2006.12.14 08:11:57 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2006.11.14 12:42:45 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2006.11.02 10:50:17 | 000,041,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM) DRV - [2006.11.02 08:30:56 | 000,044,544 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2006.11.02 08:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) DRV - [2006.10.14 04:04:33 | 004,422,560 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2005.05.26 17:19:18 | 000,839,724 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1351351 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\HBG\Documents IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.web.de/tb/ie_startpage IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes,DefaultScope = {424E1B9E-FD14-4112-A912-CA8330CF5A86} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=109958&tt=4312_7&babsrc=SP_ss&mntrId=fa94a7ac0000000000000015af393853 IE - HKCU\..\SearchScopes\{1F03280F-5D22-4C49-8AC1-48F7928C4988}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=MGX&o=15359&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=JQ&apn_dtid=YYYYYYYYDE&apn_uid=1F133E18-9A44-485B-A608-A3972477F9B8&apn_sauid=BAC84ABF-A12A-4184-A87E-48C15560DDB8 IE - HKCU\..\SearchScopes\{424E1B9E-FD14-4112-A912-CA8330CF5A86}: "URL" = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{8990CAE6-534B-402C-92B8-80EB5E51F484}: "URL" = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{8B3AB5A0-D576-44AF-8753-1B6515CE9F60}: "URL" = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1351351 IE - HKCU\..\SearchScopes\{C61671AD-48CD-4BDD-B37B-77D7DA791967}: "URL" = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:49354 ========== FireFox ========== FF - prefs.js..CT3241949.browser.search.defaultthis.engineName: true FF - prefs.js..browser.startup.homepage: "hxxp://search.conduit.com/?ctid=CT3241949&SearchSource=13" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.) FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012.10.31 15:40:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012.10.31 15:40:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012.10.31 15:40:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.08 09:32:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.08 09:31:58 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.08 09:32:14 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.08 09:31:58 | 000,000,000 | ---D | M] [2010.03.26 19:57:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HBG\AppData\Roaming\mozilla\Extensions [2012.11.22 12:39:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HBG\AppData\Roaming\mozilla\Firefox\Profiles\th4710u9.default-1343061943453\extensions [2012.11.24 20:05:53 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\HBG\AppData\Roaming\mozilla\Firefox\Profiles\th4710u9.default-1343061943453\extensions\toolbar@ask.com [2011.12.28 11:39:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HBG\AppData\Roaming\mozilla\Firefox\Profiles\yp55qh8v.default\extensions [2011.05.17 13:12:44 | 000,002,333 | ---- | M] () -- C:\Users\HBG\AppData\Roaming\mozilla\firefox\profiles\th4710u9.default-1343061943453\searchplugins\askcom.xml [2012.10.28 18:51:27 | 000,001,034 | ---- | M] () -- C:\Users\HBG\AppData\Roaming\mozilla\firefox\profiles\th4710u9.default-1343061943453\searchplugins\fileconverter-13-customized-web-search.xml [2013.03.08 09:31:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2013.03.08 09:31:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions\ffxtlbr@babylon.com [2013.03.08 09:31:50 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files\mozilla firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2013.03.08 09:31:51 | 000,000,000 | ---D | M] (Modul zur Link-Untersuchung) -- C:\Program Files\mozilla firefox\extensions\linkfilter@kaspersky.ru_bak2 [2013.03.08 09:32:14 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.01.23 11:50:38 | 000,170,080 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2013.01.19 13:11:59 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.01.19 13:11:59 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.01.19 13:11:59 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2013.01.19 13:11:59 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.01.19 13:11:59 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.01.19 13:11:59 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - homepage: hxxp://search.babylon.com/?affID=109958&tt=4312_7&babsrc=HP_ss&mntrId=fa94a7ac0000000000000015af393853 CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\plugin/npABPlugin.dll CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_0\plugin/npUrlAdvisor.dll CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_0\plugin/npVKPlugin.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 7 U5 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Java Deployment Toolkit 7.0.50.6 (Enabled) = C:\Windows\system32\npDeployJava1.dll CHR - Extension: YouTube = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Google-Suche = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: Modul zur Link-Untersuchung = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_0\ CHR - Extension: Virtuelle Tastatur = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_0\ CHR - Extension: Google Mail = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ CHR - Extension: Anti-Banner = C:\Users\HBG\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\ O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (WEB.DE MailCheck BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO) O3 - HKLM\..\Toolbar: (WEB.DE MailCheck) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKCU\..\Toolbar\WebBrowser: (WEB.DE MailCheck) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [MailCheck IE Broker] C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe (1und1 Mail und Media GmbH) O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\HBG\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - Startup: C:\Users\HBG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm () O8 - Extra context menu item: Run Context - C:\Program Files\Informatic\Word Explorer 2.0\cnie5.htm () O8 - Extra context menu item: Run Word Explorer - C:\Program Files\Informatic\Word Explorer 2.0\cnie5.htm () O9 - Extra Button: Run Word Explorer - {26231800-6CE9-43d8-9357-5B4DC8CF4561} - C:\Program Files\Informatic\Word Explorer 2.0\cnie5.htm () O9 - Extra 'Tools' menuitem : Run Word Explorer - {26231800-6CE9-43d8-9357-5B4DC8CF4561} - C:\Program Files\Informatic\Word Explorer 2.0\cnie5.htm () O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O13 - gopher Prefix: missing O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.17.2) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{33C356C5-CCE1-4246-BE34-213C78FA0A21}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F952BDE-BBE5-44EB-9339-036F116C8410}: DhcpNameServer = 192.168.1.1 192.168.1.1 O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\progra~2\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{07f0cb47-d153-11df-b568-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{07f0cb47-d153-11df-b568-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{0f5af784-83bf-11df-8c66-ebd6765066d3}\Shell - "" = AutoRun O33 - MountPoints2\{0f5af784-83bf-11df-8c66-ebd6765066d3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{0f5af789-83bf-11df-8c66-ebd6765066d3}\Shell - "" = AutoRun O33 - MountPoints2\{0f5af789-83bf-11df-8c66-ebd6765066d3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{17e7ea36-abab-11df-95a9-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{17e7ea36-abab-11df-95a9-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{17e7ea38-abab-11df-95a9-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{17e7ea38-abab-11df-95a9-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{2433ca01-1b2f-11e1-b7ea-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{2433ca01-1b2f-11e1-b7ea-001d60a340fb}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\index.html O33 - MountPoints2\{2545fd65-39e7-11df-9983-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{2545fd65-39e7-11df-9983-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{2545fd86-39e7-11df-9983-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{2545fd86-39e7-11df-9983-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{3af65f3c-6da7-11e1-8a01-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{3af65f3c-6da7-11e1-8a01-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{3af65f6a-6da7-11e1-8a01-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{3af65f6a-6da7-11e1-8a01-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{415399cd-4641-11e2-a144-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{415399cd-4641-11e2-a144-001d60a340fb}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1 O33 - MountPoints2\{4434fc81-3df6-11df-8ca1-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{4434fc81-3df6-11df-8ca1-001d60a340fb}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{4434fc83-3df6-11df-8ca1-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{4434fc83-3df6-11df-8ca1-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{4434fd27-3df6-11df-8ca1-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{4434fd27-3df6-11df-8ca1-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{4e98ae26-8d11-11e0-9d9d-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{4e98ae26-8d11-11e0-9d9d-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{4e98ae29-8d11-11e0-9d9d-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{4e98ae29-8d11-11e0-9d9d-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{59f07131-65e4-11e1-8f98-001e101f8924}\Shell - "" = AutoRun O33 - MountPoints2\{59f07131-65e4-11e1-8f98-001e101f8924}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{6d1fcbe0-7fbd-11e1-9b14-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{6d1fcbe0-7fbd-11e1-9b14-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{780cc5fe-3606-11e1-a299-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{780cc5fe-3606-11e1-a299-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{780cc613-3606-11e1-a299-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{780cc613-3606-11e1-a299-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{7a3f1380-45d0-11e2-a4f8-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{7a3f1380-45d0-11e2-a4f8-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{7ca3d0e8-458c-11df-8363-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{7ca3d0e8-458c-11df-8363-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{8ddcb8f0-6a2b-11e1-9426-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{8ddcb8f0-6a2b-11e1-9426-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{92dbd9f2-363d-11e1-b68c-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{92dbd9f2-363d-11e1-b68c-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{92dbda21-363d-11e1-b68c-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{92dbda21-363d-11e1-b68c-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{92dbda25-363d-11e1-b68c-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{92dbda25-363d-11e1-b68c-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{92dbda32-363d-11e1-b68c-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{92dbda32-363d-11e1-b68c-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{92dbda33-363d-11e1-b68c-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{92dbda33-363d-11e1-b68c-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{9d7bb166-a895-11e1-b9f3-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{9d7bb166-a895-11e1-b9f3-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{b478a478-51bc-11e1-85e2-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{b478a478-51bc-11e1-85e2-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{b7ca19cb-69f6-11e1-ac62-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{b7ca19cb-69f6-11e1-ac62-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{d0f4e335-3c94-11df-9ca7-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{d0f4e335-3c94-11df-9ca7-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{d0f4e3ad-3c94-11df-9ca7-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{d0f4e3ad-3c94-11df-9ca7-001d60a340fb}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{e6a0422c-514a-11df-ad24-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{e6a0422c-514a-11df-ad24-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f17ccf21-4689-11e2-b672-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{f17ccf21-4689-11e2-b672-001d60a340fb}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1 O33 - MountPoints2\{f17ccf60-4689-11e2-b672-001e101f2b52}\Shell - "" = AutoRun O33 - MountPoints2\{f17ccf60-4689-11e2-b672-001e101f2b52}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1 O33 - MountPoints2\{fa6d3f02-f33c-11e1-8ff6-001d60a340fb}\Shell - "" = AutoRun O33 - MountPoints2\{fa6d3f02-f33c-11e1-8ff6-001d60a340fb}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{fd427367-6374-11e1-aeda-001e101f21c1}\Shell - "" = AutoRun O33 - MountPoints2\{fd427367-6374-11e1-aeda-001e101f21c1}\Shell\AutoRun\command - "" = F:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.03.22 22:38:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2013.03.16 14:20:45 | 000,000,000 | ---D | C] -- C:\Users\HBG\Documents\Bianka [2013.03.15 10:21:29 | 000,000,000 | ---D | C] -- C:\Users\HBG\Documents\PAYBACK_gUTSCHEIN-bis1204-Dateien [2013.03.08 18:37:02 | 000,000,000 | ---D | C] -- C:\Users\HBG\AppData\Local\Spotify [2013.03.08 18:31:58 | 000,000,000 | ---D | C] -- C:\Users\HBG\AppData\Roaming\Spotify [2013.03.08 17:04:06 | 000,000,000 | ---D | C] -- C:\ProgramData\UUdb [2013.03.08 17:04:06 | 000,000,000 | ---D | C] -- C:\Program Files\1und1Softwareaktualisierung [2013.03.08 17:03:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WEB.DE MailCheck [2013.03.08 17:03:58 | 000,000,000 | ---D | C] -- C:\ProgramData\1&1 Mail & Media GmbH [2013.03.08 17:03:55 | 000,000,000 | ---D | C] -- C:\Program Files\WEB.DE MailCheck [2013.03.08 16:56:55 | 000,000,000 | ---D | C] -- C:\Users\HBG\AppData\Local\Apps [2013.03.08 16:56:54 | 000,000,000 | ---D | C] -- C:\Users\HBG\AppData\Local\Deployment [2013.03.08 09:31:42 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.03.05 10:48:49 | 000,000,000 | ---D | C] -- C:\Users\HBG\Documents\HausFrechenAnDerVogtei48 [2012.12.15 00:13:17 | 000,535,496 | ---- | C] (WebToGo Mobiles Internet GmbH) -- C:\Users\HBG\ALDITALKVerbindungsassistent_SMSMMS.exe [2012.12.15 00:13:16 | 000,495,616 | ---- | C] (TODO: <Company name>) -- C:\Users\HBG\WTGAlerts.dll [2012.12.15 00:13:16 | 000,401,462 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\msvcp60.dll [2012.12.15 00:13:16 | 000,286,773 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\msvcrt.dll [2012.12.15 00:13:16 | 000,237,568 | ---- | C] (TODO: <Company name>) -- C:\Users\HBG\WTGSoapUtil.dll [2012.12.15 00:13:16 | 000,233,472 | ---- | C] (TODO: <Company name>) -- C:\Users\HBG\WTGHandOver.dll [2012.12.15 00:13:16 | 000,208,896 | ---- | C] (TODO: <Company name>) -- C:\Users\HBG\WTGHuaweiNDISUtil.dll [2012.12.15 00:13:16 | 000,102,400 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Users\HBG\Del_CD_ROM.exe [2012.12.15 00:13:15 | 000,925,696 | ---- | C] (WebToGo) -- C:\Users\HBG\WtgWiFiCore.dll [2012.12.15 00:13:15 | 000,780,024 | ---- | C] (QUALCOMM, Inc.) -- C:\Users\HBG\QCWWAN2k.dll [2012.12.15 00:13:15 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\msvcr71.dll [2012.12.15 00:13:15 | 000,090,112 | ---- | C] (TODO: <Company name>) -- C:\Users\HBG\WtgWiFiVista.dll [2012.12.15 00:13:14 | 001,093,120 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\mfc80u.dll [2012.12.15 00:13:14 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\msvcr80.dll [2012.12.15 00:13:14 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\msvcp80.dll [2012.12.15 00:13:14 | 000,479,232 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\msvcm80.dll [2012.12.15 00:13:14 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\mfcm80.dll [2012.12.15 00:13:14 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\mfcm80u.dll [2012.12.15 00:13:13 | 001,101,824 | ---- | C] (Microsoft Corporation) -- C:\Users\HBG\mfc80.dll [2012.12.15 00:13:13 | 000,057,344 | ---- | C] (WinAbility® Software Corporation) -- C:\Users\HBG\VistaLib32.dll [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.03.26 16:33:01 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.03.26 15:37:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.03.26 15:06:00 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.26 15:06:00 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.26 15:05:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.03.26 12:01:04 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.03.26 11:11:53 | 000,000,000 | ---- | M] () -- C:\Users\HBG\defogger_reenable [2013.03.26 10:20:34 | 2138,365,952 | -HS- | M] () -- C:\hiberfil.sys [2013.03.25 22:58:24 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.03.25 18:22:50 | 000,000,224 | ---- | M] () -- C:\Windows\tasks\ARO 2012.job [2013.03.18 19:35:14 | 000,045,312 | ---- | M] () -- C:\Users\HBG\Documents\BBK_2410_1_zusammenstellung_aufwendungen_20130319.pdf [2013.03.18 19:35:12 | 000,000,059 | ---- | M] () -- C:\Windows\wpd99.drv [2013.03.17 18:41:39 | 000,642,970 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.03.17 18:41:39 | 000,607,918 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.03.17 18:41:39 | 000,132,284 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.03.17 18:41:39 | 000,109,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.03.16 17:20:00 | 000,306,313 | ---- | M] () -- C:\Users\HBG\Documents\Vorschlag.PDF [2013.03.15 20:43:30 | 000,001,750 | ---- | M] () -- C:\Users\HBG\Desktop\Spotify.lnk [2013.03.15 14:03:33 | 000,089,434 | ---- | M] () -- C:\Users\HBG\Documents\EVA_Terminanfrage_Filmdigitalisieren_Groupon.pdf [2013.03.15 10:21:29 | 000,008,154 | ---- | M] () -- C:\Users\HBG\Documents\PAYBACK_gUTSCHEIN-bis1204.htm [2013.03.12 19:39:05 | 000,001,978 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2013.03.08 17:03:59 | 000,001,906 | ---- | M] () -- C:\Users\HBG\Desktop\Amazon.lnk [2013.03.08 17:03:59 | 000,001,904 | ---- | M] () -- C:\Users\HBG\Desktop\WEB.DE.lnk [2013.03.08 17:03:59 | 000,001,898 | ---- | M] () -- C:\Users\HBG\Desktop\eBay.lnk [2013.02.26 19:07:58 | 000,063,322 | ---- | M] () -- C:\Users\HBG\Documents\Roller Reklamation.pdf [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.03.26 11:11:53 | 000,000,000 | ---- | C] () -- C:\Users\HBG\defogger_reenable [2013.03.18 19:35:11 | 000,045,312 | ---- | C] () -- C:\Users\HBG\Documents\BBK_2410_1_zusammenstellung_aufwendungen_20130319.pdf [2013.03.16 17:20:00 | 000,306,313 | ---- | C] () -- C:\Users\HBG\Documents\Vorschlag.PDF [2013.03.15 14:03:30 | 000,089,434 | ---- | C] () -- C:\Users\HBG\Documents\EVA_Terminanfrage_Filmdigitalisieren_Groupon.pdf [2013.03.15 10:21:27 | 000,008,154 | ---- | C] () -- C:\Users\HBG\Documents\PAYBACK_gUTSCHEIN-bis1204.htm [2013.03.08 18:37:00 | 000,001,750 | ---- | C] () -- C:\Users\HBG\Desktop\Spotify.lnk [2013.03.08 18:37:00 | 000,001,694 | ---- | C] () -- C:\Users\HBG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk [2013.03.08 17:03:59 | 000,001,906 | ---- | C] () -- C:\Users\HBG\Desktop\Amazon.lnk [2013.03.08 17:03:59 | 000,001,904 | ---- | C] () -- C:\Users\HBG\Desktop\WEB.DE.lnk [2013.03.08 17:03:59 | 000,001,898 | ---- | C] () -- C:\Users\HBG\Desktop\eBay.lnk [2013.02.26 19:07:53 | 000,063,322 | ---- | C] () -- C:\Users\HBG\Documents\Roller Reklamation.pdf [2013.02.19 13:37:24 | 000,002,151 | ---- | C] () -- C:\Users\HBG\.recently-used.xbel [2013.02.11 23:51:54 | 000,042,214 | ---- | C] () -- C:\Users\HBG\20130209_165604.jpg [2013.01.15 17:49:48 | 000,014,172 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat [2012.12.15 00:13:20 | 000,158,664 | ---- | C] () -- C:\Users\HBG\Huaweiregcleaner.exe [2012.12.15 00:13:20 | 000,079,436 | ---- | C] () -- C:\Users\HBG\billing_sms.wav [2012.12.15 00:13:20 | 000,007,994 | ---- | C] () -- C:\Users\HBG\Responses.xml [2012.12.15 00:13:20 | 000,002,815 | ---- | C] () -- C:\Users\HBG\network_wifi_disconnect.html [2012.12.15 00:13:20 | 000,002,750 | ---- | C] () -- C:\Users\HBG\network.html [2012.12.15 00:13:20 | 000,002,026 | ---- | C] () -- C:\Users\HBG\network_available.html [2012.12.15 00:13:20 | 000,002,024 | ---- | C] () -- C:\Users\HBG\3Gnetwork_available.html [2012.12.15 00:13:20 | 000,001,887 | ---- | C] () -- C:\Users\HBG\threshold_cut.html [2012.12.15 00:13:20 | 000,001,834 | ---- | C] () -- C:\Users\HBG\general_sms.html [2012.12.15 00:13:20 | 000,001,670 | ---- | C] () -- C:\Users\HBG\error.xml [2012.12.15 00:13:20 | 000,001,490 | ---- | C] () -- C:\Users\HBG\WAPConfig.xml [2012.12.15 00:13:20 | 000,001,205 | ---- | C] () -- C:\Users\HBG\info.html [2012.12.15 00:13:20 | 000,001,201 | ---- | C] () -- C:\Users\HBG\error.html [2012.12.15 00:13:20 | 000,001,153 | ---- | C] () -- C:\Users\HBG\ads.html [2012.12.15 00:13:20 | 000,001,124 | ---- | C] () -- C:\Users\HBG\threshold.html [2012.12.15 00:13:20 | 000,001,122 | ---- | C] () -- C:\Users\HBG\billing_sms.html [2012.12.15 00:13:20 | 000,001,086 | ---- | C] () -- C:\Users\HBG\plain.html [2012.12.15 00:13:20 | 000,001,074 | ---- | C] () -- C:\Users\HBG\brand_sms.html [2012.12.15 00:13:20 | 000,000,983 | ---- | C] () -- C:\Users\HBG\img_ads.html [2012.12.15 00:13:20 | 000,000,809 | ---- | C] () -- C:\Users\HBG\configMedion.ini [2012.12.15 00:13:20 | 000,000,038 | ---- | C] () -- C:\Users\HBG\runOnConnect.ini [2012.12.15 00:13:17 | 000,510,920 | ---- | C] () -- C:\Users\HBG\ALDITALKVerbindungsassistent_Launcher.exe [2012.12.15 00:13:17 | 000,342,984 | ---- | C] () -- C:\Users\HBG\ALDITALKVerbindungsassistent_Service.exe [2012.12.15 00:13:17 | 000,281,544 | ---- | C] () -- C:\Users\HBG\OSU.exe [2012.12.15 00:13:17 | 000,074,884 | ---- | C] () -- C:\Users\HBG\Images_Medion_Asst.xml [2012.12.15 00:13:17 | 000,038,190 | ---- | C] () -- C:\Users\HBG\Strings_Medion_Asst_0007.xml [2012.12.15 00:13:17 | 000,027,353 | ---- | C] () -- C:\Users\HBG\Controls_Medion_Asst_0007.xml [2012.12.15 00:13:17 | 000,018,939 | ---- | C] () -- C:\Users\HBG\Help_Medion_0007.chm [2012.12.15 00:13:17 | 000,009,288 | ---- | C] () -- C:\Users\HBG\Controls_Medion_SMSMMS_0007.xml [2012.12.15 00:13:17 | 000,008,734 | ---- | C] () -- C:\Users\HBG\Images_Medion_Upgrader.xml [2012.12.15 00:13:17 | 000,008,376 | ---- | C] () -- C:\Users\HBG\Images_Medion_SMSMMS.xml [2012.12.15 00:13:17 | 000,007,342 | ---- | C] () -- C:\Users\HBG\Images_Medion_Uninstaller.xml [2012.12.15 00:13:17 | 000,006,471 | ---- | C] () -- C:\Users\HBG\Strings_Medion_SMSMMS_0007.xml [2012.12.15 00:13:17 | 000,006,149 | ---- | C] () -- C:\Users\HBG\Eula_Medion_0007.htm [2012.12.15 00:13:17 | 000,006,069 | ---- | C] () -- C:\Users\HBG\Controls_Medion_Upgrader_0007.xml [2012.12.15 00:13:17 | 000,005,190 | ---- | C] () -- C:\Users\HBG\Controls_Medion_Address_0007.xml [2012.12.15 00:13:17 | 000,002,679 | ---- | C] () -- C:\Users\HBG\Strings_Medion_Address_0007.xml [2012.12.15 00:13:17 | 000,002,568 | ---- | C] () -- C:\Users\HBG\Controls_Medion_Uninstaller_0007.xml [2012.12.15 00:13:17 | 000,002,486 | ---- | C] () -- C:\Users\HBG\Strings_Medion_Upgrader_0007.xml [2012.12.15 00:13:17 | 000,002,037 | ---- | C] () -- C:\Users\HBG\Offers_Medion_0007.xml [2012.12.15 00:13:17 | 000,001,718 | ---- | C] () -- C:\Users\HBG\Strings_Medion_Uninstaller_0007.xml [2012.12.15 00:13:17 | 000,000,282 | ---- | C] () -- C:\Users\HBG\Images_Medion_Address.xml [2012.12.15 00:13:16 | 001,633,224 | ---- | C] () -- C:\Users\HBG\ALDITALKVerbindungsassistent.exe [2012.12.15 00:13:16 | 001,097,728 | ---- | C] () -- C:\Users\HBG\NDISAPI.dll [2012.12.15 00:13:16 | 000,606,208 | ---- | C] () -- C:\Users\HBG\WTGXMLUtil.dll [2012.12.15 00:13:16 | 000,043,976 | ---- | C] () -- C:\Users\HBG\InstallWTGService.exe [2012.12.15 00:13:16 | 000,001,817 | ---- | C] () -- C:\Users\HBG\config.ini [2012.12.15 00:13:16 | 000,001,597 | ---- | C] () -- C:\Users\HBG\KD.xml [2012.12.15 00:13:16 | 000,000,991 | ---- | C] () -- C:\Users\HBG\bn.xml [2012.12.15 00:13:15 | 000,294,912 | ---- | C] () -- C:\Users\HBG\WTGSMSPCClient.dll [2012.12.15 00:13:15 | 000,204,800 | ---- | C] () -- C:\Users\HBG\LiveBoxCM.dll [2012.12.15 00:13:15 | 000,126,976 | ---- | C] () -- C:\Users\HBG\WtgWiFi.dll [2012.12.15 00:13:14 | 000,883,656 | ---- | C] () -- C:\Users\HBG\Setup.exe [2012.12.15 00:13:14 | 000,823,296 | ---- | C] () -- C:\Users\HBG\libeay32.dll [2012.12.15 00:13:14 | 000,094,274 | ---- | C] () -- C:\Users\HBG\WtgZip.dll [2012.12.15 00:13:13 | 004,392,468 | ---- | C] () -- C:\Users\HBG\webtogodb.wdb [2012.12.15 00:13:13 | 000,244,680 | ---- | C] () -- C:\Users\HBG\WTGVistaUtil.exe [2012.12.15 00:13:13 | 000,106,496 | ---- | C] () -- C:\Users\HBG\WtgUtil.dll [2012.12.15 00:13:13 | 000,090,112 | ---- | C] () -- C:\Users\HBG\WtgPorts.dll [2012.12.15 00:13:13 | 000,069,632 | ---- | C] () -- C:\Users\HBG\WTGMMSPCClient.dll [2012.12.15 00:13:13 | 000,012,288 | ---- | C] () -- C:\Users\HBG\WTGDebugs.dll [2012.12.15 00:13:12 | 000,565,248 | ---- | C] () -- C:\Users\HBG\WtgCore.dll [2012.12.15 00:13:12 | 000,306,120 | ---- | C] () -- C:\Users\HBG\Uninstaller.exe [2012.12.15 00:13:12 | 000,196,608 | ---- | C] () -- C:\Users\HBG\WtgDetection.dll [2012.12.15 00:13:12 | 000,139,264 | ---- | C] () -- C:\Users\HBG\WtgBluetooth.dll [2012.12.15 00:13:12 | 000,102,400 | ---- | C] () -- C:\Users\HBG\WtgDatabase.dll [2012.12.15 00:13:12 | 000,086,016 | ---- | C] () -- C:\Users\HBG\WtgDialup.dll [2012.12.15 00:13:12 | 000,073,728 | ---- | C] () -- C:\Users\HBG\WtgDriverInstall.dll [2012.12.15 00:13:12 | 000,012,800 | ---- | C] () -- C:\Users\HBG\WtgDriverInstallX.dll [2012.10.25 17:28:24 | 000,009,322 | ---- | C] () -- C:\Users\HBG\AppData\Roaming\Kommagetrennte Werte (Windows).EML [2012.03.07 13:43:06 | 000,021,857 | ---- | C] () -- C:\Users\HBG\AppData\Roaming\Kommagetrennte Werte (DOS).ADR [2011.12.09 20:36:04 | 000,000,045 | RH-- | C] () -- C:\Windows\PAWSETUP.INI [2011.12.09 20:35:12 | 000,000,306 | ---- | C] () -- C:\Windows\HD.INI [2011.12.08 12:44:05 | 000,048,690 | ---- | C] () -- C:\Users\HBG\P081211_12.42.jpg [2011.12.08 12:43:51 | 001,146,711 | ---- | C] () -- C:\Users\HBG\P081211_12.41.jpg [2011.10.04 22:36:34 | 000,210,944 | ---- | C] () -- C:\Windows\System32\MSVCRT10.DLL [2011.10.03 10:10:21 | 000,027,456 | ---- | C] () -- C:\Windows\System32\solidlocalmon.dll [2011.10.03 10:10:21 | 000,018,752 | ---- | C] () -- C:\Windows\System32\solidlocalui.dll [2011.08.06 10:31:29 | 000,068,640 | ---- | C] () -- C:\Windows\unTMV.exe [2011.07.13 13:27:07 | 000,004,096 | -H-- | C] () -- C:\Users\HBG\AppData\Local\keyfile3.drm [2011.06.08 14:28:50 | 000,017,408 | ---- | C] () -- C:\Users\HBG\AppData\Local\WebpageIcons.db [2011.06.08 14:23:54 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat [2011.06.08 14:23:54 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat [2011.06.01 17:40:28 | 000,012,968 | ---- | C] () -- C:\Users\HBG\AppData\Roaming\Kommagetrennte Werte (Windows).CAL [2011.06.01 08:09:12 | 000,000,091 | ---- | C] () -- C:\Users\HBG\AppData\Local\fusioncache.dat [2011.05.31 20:49:18 | 000,000,310 | ---- | C] () -- C:\Windows\ContWin.ini [2011.05.31 12:58:16 | 000,038,746 | ---- | C] () -- C:\Users\HBG\AppData\Roaming\B8E4.9CB [2011.05.13 12:06:01 | 000,000,321 | ---- | C] () -- C:\Windows\devk.ini [2011.05.13 12:06:01 | 000,000,210 | ---- | C] () -- C:\Windows\easap1.ini [2011.01.28 16:24:04 | 000,012,629 | -H-- | C] () -- C:\Users\HBG\jpeggeri.dat [2011.01.26 17:08:58 | 000,015,499 | -H-- | C] () -- C:\Users\HBG\ZbThumbnail.info [2011.01.26 16:58:23 | 001,391,293 | ---- | C] () -- C:\Users\HBG\IMG_0681.JPG [2011.01.26 16:58:23 | 001,181,975 | ---- | C] () -- C:\Users\HBG\IMG_0682.JPG [2011.01.26 16:58:23 | 001,152,731 | ---- | C] () -- C:\Users\HBG\IMG_0683.JPG [2010.06.10 18:00:00 | 000,000,680 | ---- | C] () -- C:\Users\HBG\AppData\Local\d3d9caps.dat [2010.04.10 20:32:13 | 000,011,264 | ---- | C] () -- C:\Users\HBG\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.03.28 10:08:08 | 000,000,008 | RH-- | C] () -- C:\Users\HBG\hwid ========== ZeroAccess Check ========== [2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2011.11.27 10:01:58 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\514AE669-0FC5-419F-87ED-33748D0FD205 [2011.11.26 17:30:01 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\Acronis [2011.08.20 08:42:08 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\CD-LabelPrint [2012.12.01 11:41:19 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\D7451E7C-964C-4779-BC13-40A2459226E3 [2013.02.06 12:21:47 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\elsterformular [2013.02.19 13:37:24 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\gtk-2.0 [2012.12.16 09:27:09 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\HBG [2012.10.28 18:51:56 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\IrfanView [2011.06.07 11:00:29 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\Leotpu [2011.12.08 12:04:42 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\LG Electronics [2012.11.22 13:13:37 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\MAGIX [2010.04.03 11:19:48 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\pdf995 [2013.03.02 11:31:57 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\SolidDocuments [2013.03.25 08:51:00 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\Spotify [2012.03.13 10:33:47 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\SuperMailer [2010.11.11 12:32:42 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\TeamViewer [2013.03.13 20:07:02 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\TVgenial [2010.03.31 15:09:40 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\Vodafone [2011.06.08 14:51:00 | 000,000,000 | ---D | M] -- C:\Users\HBG\AppData\Roaming\Zeipk ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 304 bytes -> C:\Users\HBG\Documents\Medion-TV2.jpg:Updt_SummaryInformation @Alternate Data Stream - 143 bytes -> C:\Users\HBG\AppData\Roaming\Kommagetrennte Werte (Windows).EML:OECustomProperty < End of report > |
Hallo und :hallo: Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten! ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
Hallo Cosinus, zuerst einmal HERZLICHEN DANK, das ihr euch meines Problems annehmt. Ich habe - wie im Board vorgeschlagen - auch Malwarebytes laufen lassen. Malwarebytes hatte aber keine Funde gemeldet: Malwarebytes Anti-Malware 1.70.0.1100 Malwarebytes : Free anti-malware download Datenbank Version: v2013.03.26.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 HBG :: HBG-MOBIL [Administrator] 26.03.2013 10:34:57 mbam-log-2013-03-26 (10-34-57).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 233454 Laufzeit: 14 Minute(n), 38 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Gruß hrbg |
Du solltest eigentlich noch keine neuen Scans machen, aber ist nicht schlimm, ich wollte im ersten Schritt nur wissen ob du andere Funde eines Virenscanners zu verzeichnen hattest und wenn ja, wollte ich davon die Logs sehen Außerdem solltest du alle folgenden Logs in CODE-Tags posten, das würde auch ausdrücklich erwähnt und haarklein erklärt wie das geht |
Hallo Cosinus, das Log von MALWAREBYTES ist vor Eröffnung des Threads erstellt worden. Die Anweisung bzgl. Code-Tags hatte ich gelesen, dies hatte ich aber bei der Erstellung des Threads vergessen. Sorry, bin halt etwa älter (fast 70). Hatte nur gelesen "Logfiles posten ...". Wie soll ich nun verfahren? Soll ich die Logs in Code-Tags einbetten, soll ich diesen Thread schließen und nach Anweisung neu eröffnen oder soll ich alles so lassen wie es ist? Ein (möglicherweise) wichtiger Hinweis ist mir noch eingefallen: In letzter Zeit gab es öfters Probleme mit dem Firewall. Er kam entweder verspätet hoch (mit Kaspersky) oder manchmal auch garnicht (Kaspersky wurde dann auch in der Taskleiste nicht als aktiv angezeigt). In diesen Fällen habe ich einige Minuten gewartet, den Laptop neu gestartet und alles lief wieder rund. Danke für die Hilfe hrbg |
Zitat:
|
Hallo cosinus, ich habe von kaspersky noch Logs mit positiven Funden eingestellt: Datei-Anti-Virus Code: Datum: Heute (2) erkannte Bedrohungen Code: Typ: trojanisches Programm (1) Programmkontrolle Code: Datum: Heute (2) Schutzcenter Code: Datum: Heute (7) |
Bevor wir uns an die weitere Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
Note: Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread. Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards. Bitte die drei Tools MBAR / aswMBR / TDSSkiller nun ausführen und die Logs in CODE-Tags posten MBAR (Malwarebytes Anti-Rootkit) Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers aswMBR Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). TDSS-Killer Downloade dir bitte ![]()
|
Hier die gewünschten Logs: MBAR (Malwarebytes Anti-Rootkit) Code: Malwarebytes Anti-Rootkit BETA 1.01.0.1022 aswMBR Code: aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Code: 21:02:17.0132 5024 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 |
Hier die gewünschten Logs: MBAR (Malwarebytes Anti-Rootkit) Code: Malwarebytes Anti-Rootkit BETA 1.01.0.1022 aswMBR Code: aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Code: 21:02:17.0132 5024 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 |
JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Im Anschluss: adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen Downloade Dir bitte ![]()
Danach eine Kontrolle mit OTL bitte:
|
Hallo cosinus, Dankefür die schnelle Reaktion. Anbei die gewünschten Logs: JRT JRT Logfile: Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ adwCleaner Code: # AdwCleaner v2.115 - Datei am 02/04/2013 um 11:17:58 erstellt Code: OTL logfile created on: 02.04.2013 11:52:44 - Run 2 Code: OTL Extras logfile created on: 02.04.2013 11:52:44 - Run 2 |
Hallo cosinus, Dankefür die schnelle Reaktion. Anbei die gewünschten Logs: JRT Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code: # AdwCleaner v2.115 - Datei am 02/04/2013 um 11:17:58 erstellt Code: OTL logfile created on: 02.04.2013 11:52:44 - Run 2 Code: OTL Extras logfile created on: 02.04.2013 11:52:44 - Run 2 |
Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes - denk bitte vorher daran, Malwarebytes über den Updatebutton zu aktualisieren Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
|
Hallo cosinus, habe alles gemacht wie gewünscht. Kapersky meldet immer noch eine Bedrohung durch Malware: "Gefunden: HEUR: Exploit.Java.CVE-2012-0507.gen" Auch ESET hat noch einen Virenbefall festgestellt. Hier die Logs: Malwarebytes: Code: Malwarebytes Anti-Malware (Test) 1.70.0.1100 Code: ESETSmartInstaller@High as downloader log: |
Alle Zeitangaben in WEZ +1. Es ist jetzt 09:53 Uhr. |
Copyright ©2000-2025, Trojaner-Board