![]() |
Trojaner beim Online-Banking Hallo zusammen, ich habe gestern festgestellt, dass ich einen Trojaner auf dem Rechner habe. Beim Einloggen für das Online-Banking wurde ich aufgefordert, meine Tan-Liste einzugeben. Das hatte ich nicht gemacht und ich habe dann antivir laufen lassen, die Dateien in die Quarantäne verschoben und gelöscht. Nun habe ich gehört, dass dies nicht ausreicht. Könnt Ihr mir helfen meinen Rechner zu säubern? OTL:OTL Logfile: Code: OTL logfile created on: 10.06.2013 17:12:20 - Run 1 Extras:OTL Logfile: Code: OTL Extras logfile created on: 10.06.2013 17:12:20 - Run 1 GMER: GMER Logfile: Code: GMER 2.1.19163 - hxxp://www.gmer.net Wenn Ihr helfen könntet wäre ich sehr dankbar!!! |
Hi, Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
|
Hallo Schrauber, danke für die schnelle Antwort!!! FRST: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-06-2013 02 Ran by Huthmann (administrator) on 10-06-2013 21:33:23 Running from C:\Users\Huthmann\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Hewlett-Packard Co.) C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Software Update\hpwuschd2.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (1und1 Mail und Media GmbH) C:\Program Files (x86)\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Co.) C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_202_ActiveX.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (Nero AG) c:\Program Files (x86)\Nero\Update\NASvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation) HKLM\...\Run: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH) HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-10-28] (TOSHIBA Corporation) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11580520 2010-11-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2181224 2010-11-03] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2387752 2010-09-30] (Synaptics Incorporated) HKLM\...\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation) HKLM\...\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation) HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-22] (Toshiba Europe GmbH) HKCU\...\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STAR [846936 2011-05-16] (TOSHIBA) HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-22] (Google Inc.) HKCU\...\Run: [Ytobfo] C:\Users\Huthmann\AppData\Roaming\Ysih\uvmi.exe [x] HKCU\...\Run: [brah] "C:\Users\Huthmann\AppData\Roaming\brah\sit.bat" [193 2013-06-02] () HKLM-x32\...\Run: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart [1409424 2011-06-29] (Nero AG) HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-06-29] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL [532480 2010-11-09] (TOSHIBA) HKLM-x32\...\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP [423936 2010-03-04] (TOSHIBA Electronics, Inc.) HKLM-x32\...\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM [34160 2010-08-15] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [2475384 2010-11-02] (TOSHIBA CORPORATION.) HKLM-x32\...\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [1295224 2010-07-01] (TOSHIBA Corporation) HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1648264 2013-04-30] (Ask) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-06-10] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [MailCheck IE Broker] "C:\Program Files (x86)\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe" [1516608 2013-05-27] (1und1 Mail und Media GmbH) HKU\Default\...\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STAR [846936 2011-05-16] (TOSHIBA) HKU\Default User\...\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STAR [846936 2011-05-16] (TOSHIBA) Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Start Menu\Programs\Startup\hpoddt01.exe.lnk ShortcutTarget: hpoddt01.exe.lnk -> C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard) Startup: C:\ProgramData\Start Menu\Programs\Startup\Toshiba Places Icon Utility.lnk ShortcutTarget: Toshiba Places Icon Utility.lnk -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (Toshiba) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search Free: Avira Search Free powered by Ask.com URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: (No Name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File SearchScopes: HKCU - {2C85BFB1-9AFE-47A4-BE14-87755B3ED67D} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKCU - {36D28309-7E16-4884-B7F9-2F4745334787} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKCU - {421D42E9-DE13-43BA-B84F-CDD4F5ED31B6} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=c1d0c625-41f3-4be6-aa09-45c35c780d96&apn_sauid=1E7E84FB-B3BF-4E4A-ACC2-CC1E0612CC7C SearchScopes: HKCU - {756D3384-B88A-4A23-92C3-305FE75B6446} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie SearchScopes: HKCU - {B3A25B8E-87C6-43FC-9A3B-BD5E037A0D32} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: WEB.DE MailCheck BHO - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) BHO-x32: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: WEB.DE MailCheck BHO - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM - WEB.DE MailCheck - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - WEB.DE MailCheck - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - WEB.DE MailCheck - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) Handler: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Handler-x32: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files (x86)\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH) Winsock: Catalog9 01 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [260832] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 01 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 02 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 03 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 04 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 05 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 06 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 07 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 08 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Winsock: Catalog9-x64 19 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [234208] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=TEUA&bmod=TEUA CHR RestoreOnStartup: "hxxp://www.google.com/ig/redirectdomain?brand=TEUA&bmod=TEUA" CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.94\pdf.dll No File CHR Plugin: (registryAccess) - C:\Users\Huthmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangmfdabjilefmognkgcebjgcojek\7.14.1.20932_0\background/registryAccess.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.200.2) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U20) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Extension: (Avira Toolbar) - C:\Users\Huthmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangmfdabjilefmognkgcebjgcojek\7.15.4.24329_0 ==================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [657120 2013-06-10] (Avira Operations GmbH & Co. KG) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [371768 2013-06-10] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-06-10] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-06-10] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [562744 2013-06-10] (Avira Operations GmbH & Co. KG) R3 hpqcxs08; C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) R2 hpqddsvc; C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) R2 HPSLPSVC; C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC64.DLL [923136 2009-05-21] (Hewlett-Packard Co.) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) ==================== Drivers (Whitelisted) ==================== R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-06-10] (Avira GmbH) R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-06-10] (Avira GmbH) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-28] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-28] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-28] (Avira Operations GmbH & Co. KG) S0 AFS; No ImagePath ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-10 21:33 - 2013-06-10 21:33 - 00000000 ____D C:\FRST 2013-06-10 21:31 - 2013-06-10 21:31 - 01920126 ____A (Farbar) C:\Users\Huthmann\Desktop\FRST64.exe 2013-06-10 19:40 - 2013-06-10 19:41 - 00007194 ____A C:\Users\Huthmann\Desktop\GMER.log 2013-06-10 17:31 - 2013-06-10 17:31 - 00377856 ____A C:\Users\Huthmann\Desktop\gmer_2.1.19163.exe 2013-06-10 17:30 - 2013-06-10 17:30 - 00100434 ____A C:\Users\Huthmann\Desktop\OTL1.Txt 2013-06-10 17:30 - 2013-06-10 17:30 - 00077914 ____A C:\Users\Huthmann\Desktop\Extras1.Txt 2013-06-10 17:29 - 2013-06-10 17:29 - 00077914 ____A C:\Users\Huthmann\Desktop\Extras.Txt 2013-06-10 17:25 - 2013-06-10 17:25 - 00100434 ____A C:\Users\Huthmann\Desktop\OTL.Txt 2013-06-10 17:11 - 2013-06-10 17:11 - 00602112 ____A (OldTimer Tools) C:\Users\Huthmann\Desktop\OTL.exe 2013-06-10 17:11 - 2013-06-10 17:11 - 00000478 ____A C:\Users\Huthmann\Desktop\defogger_disable.log 2013-06-10 17:11 - 2013-06-10 17:11 - 00000000 ____A C:\Users\Huthmann\defogger_reenable 2013-06-10 17:10 - 2013-06-10 17:10 - 00050477 ____A C:\Users\Huthmann\Desktop\Defogger.exe 2013-06-10 11:45 - 2013-06-10 11:42 - 00141376 ____A (Avira GmbH) C:\Windows\System32\Drivers\avfwot.sys 2013-06-10 11:45 - 2013-06-10 11:42 - 00114608 ____A (Avira GmbH) C:\Windows\System32\Drivers\avfwim.sys 2013-06-07 17:32 - 2013-06-10 12:16 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\Anymko 2013-06-07 17:32 - 2013-06-09 11:48 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\Ikavow 2013-06-07 17:32 - 2013-06-07 17:32 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\Esadu 2013-06-07 17:28 - 2013-06-07 17:28 - 00037376 ____A C:\Users\Huthmann\Documents\Einsatzplan Junior Cup 2013.xls 2013-06-02 18:56 - 2013-06-02 18:56 - 00739856 ____A (Google Inc.) C:\Users\Huthmann\AppData\Roaming\chromebrowser.exe 2013-06-02 18:56 - 2013-06-02 18:56 - 00012240 ____A C:\Program Files (x86)\PJQ.dat 2013-06-02 18:56 - 2013-06-02 18:56 - 00000000 _RSHD C:\Users\Huthmann\AppData\Roaming\Paaspgty 2013-06-02 18:56 - 2013-06-02 18:56 - 00000000 _RSHD C:\Program Files (x86)\Myan 2013-06-02 18:55 - 2013-06-07 20:25 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\brah 2013-06-02 18:55 - 2013-06-02 18:55 - 00030720 ____A C:\Users\Huthmann\0lz7g3zb5jb8o.exe 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\ProgramData\UUdb 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\ProgramData\DesktopIcons 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\ProgramData\1&1 Mail & Media GmbH 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\Program Files\WEB.DE MailCheck 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\Program Files (x86)\WEB.DE MailCheck 2013-05-18 15:02 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-18 15:00 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-18 15:00 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-05-18 15:00 - 2013-04-01 08:03 - 00078680 ____A (Microsoft Corporation) C:\Windows\System32\mcupdate_AuthenticAMD.dll 2013-05-18 15:00 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-05-18 15:00 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-05-18 15:00 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-18 15:00 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-18 15:00 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-18 15:00 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-18 15:00 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-18 15:00 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-18 15:00 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-18 15:00 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-18 15:00 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-05-18 14:05 - 2013-04-05 08:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-18 14:05 - 2013-04-05 08:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-18 14:05 - 2013-04-05 08:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-18 14:05 - 2013-04-05 08:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-18 14:05 - 2013-04-05 08:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-18 14:05 - 2013-04-05 08:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-18 14:05 - 2013-04-05 08:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-18 14:05 - 2013-04-05 08:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-18 14:05 - 2013-04-05 07:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-18 14:05 - 2013-04-05 07:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-18 14:05 - 2013-04-05 07:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-18 14:05 - 2013-04-05 07:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-18 14:05 - 2013-04-05 07:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-18 14:05 - 2013-04-05 07:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-18 14:05 - 2013-04-05 07:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-18 14:05 - 2013-04-05 06:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-18 14:05 - 2013-04-05 06:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-18 14:05 - 2013-04-05 05:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-05-18 14:05 - 2013-04-05 05:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-05-18 14:04 - 2013-04-05 08:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-18 14:04 - 2013-04-05 08:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-18 14:04 - 2013-04-05 08:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-18 14:04 - 2013-04-05 08:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-18 14:04 - 2013-04-05 08:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-18 14:04 - 2013-04-05 08:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-18 14:04 - 2013-04-05 07:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-18 14:04 - 2013-04-05 07:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-18 14:04 - 2013-04-05 07:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-18 14:04 - 2013-04-05 07:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-18 14:04 - 2013-04-05 07:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-18 14:04 - 2013-04-05 07:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-12 14:29 - 2013-05-12 14:31 - 00000004 ____A C:\Users\Huthmann\AppData\Roaming\skype.ini ==================== One Month Modified Files and Folders ======= 2013-06-10 21:33 - 2013-06-10 21:33 - 00000000 ____D C:\FRST 2013-06-10 21:31 - 2013-06-10 21:31 - 01920126 ____A (Farbar) C:\Users\Huthmann\Desktop\FRST64.exe 2013-06-10 21:24 - 2009-07-14 06:51 - 00087154 ____A C:\Windows\setupact.log 2013-06-10 20:08 - 2012-03-01 19:15 - 01478604 ____A C:\Windows\WindowsUpdate.log 2013-06-10 19:41 - 2013-06-10 19:40 - 00007194 ____A C:\Users\Huthmann\Desktop\GMER.log 2013-06-10 17:31 - 2013-06-10 17:31 - 00377856 ____A C:\Users\Huthmann\Desktop\gmer_2.1.19163.exe 2013-06-10 17:30 - 2013-06-10 17:30 - 00100434 ____A C:\Users\Huthmann\Desktop\OTL1.Txt 2013-06-10 17:30 - 2013-06-10 17:30 - 00077914 ____A C:\Users\Huthmann\Desktop\Extras1.Txt 2013-06-10 17:29 - 2013-06-10 17:29 - 00077914 ____A C:\Users\Huthmann\Desktop\Extras.Txt 2013-06-10 17:25 - 2013-06-10 17:25 - 00100434 ____A C:\Users\Huthmann\Desktop\OTL.Txt 2013-06-10 17:11 - 2013-06-10 17:11 - 00602112 ____A (OldTimer Tools) C:\Users\Huthmann\Desktop\OTL.exe 2013-06-10 17:11 - 2013-06-10 17:11 - 00000478 ____A C:\Users\Huthmann\Desktop\defogger_disable.log 2013-06-10 17:11 - 2013-06-10 17:11 - 00000000 ____A C:\Users\Huthmann\defogger_reenable 2013-06-10 17:11 - 2012-04-06 13:05 - 00000000 ____D C:\users\Huthmann 2013-06-10 17:10 - 2013-06-10 17:10 - 00050477 ____A C:\Users\Huthmann\Desktop\Defogger.exe 2013-06-10 15:04 - 2009-07-14 06:45 - 00024912 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-10 15:04 - 2009-07-14 06:45 - 00024912 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-10 12:25 - 2010-11-21 08:50 - 00654844 ____A C:\Windows\System32\perfh007.dat 2013-06-10 12:25 - 2010-11-21 08:50 - 00130426 ____A C:\Windows\System32\perfc007.dat 2013-06-10 12:25 - 2009-07-14 07:13 - 01500254 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-10 12:19 - 2012-04-06 15:45 - 00000000 ___RD C:\Users\Huthmann\Desktop\Verknüpfungen 2013-06-10 12:16 - 2013-06-07 17:32 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\Anymko 2013-06-10 12:12 - 2012-04-30 06:53 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-10 11:50 - 2011-08-22 11:52 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-10 11:50 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-10 11:48 - 2012-04-06 13:37 - 00000000 ____D C:\ProgramData\Avira 2013-06-10 11:47 - 2013-02-24 17:33 - 00002077 ____A C:\Users\Public\Desktop\Avira Control Center.lnk 2013-06-10 11:47 - 2013-02-24 17:32 - 00000000 ____D C:\Program Files (x86)\Ask.com 2013-06-10 11:42 - 2013-06-10 11:45 - 00141376 ____A (Avira GmbH) C:\Windows\System32\Drivers\avfwot.sys 2013-06-10 11:42 - 2013-06-10 11:45 - 00114608 ____A (Avira GmbH) C:\Windows\System32\Drivers\avfwim.sys 2013-06-10 11:31 - 2011-08-22 11:52 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-09 11:48 - 2013-06-07 17:32 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\Ikavow 2013-06-07 20:25 - 2013-06-02 18:55 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\brah 2013-06-07 17:32 - 2013-06-07 17:32 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\Esadu 2013-06-07 17:28 - 2013-06-07 17:28 - 00037376 ____A C:\Users\Huthmann\Documents\Einsatzplan Junior Cup 2013.xls 2013-06-04 11:31 - 2009-07-14 07:08 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-03 10:17 - 2012-12-04 18:39 - 00000000 ____D C:\Users\Huthmann\Documents\Beihilfe 2013-06-03 10:17 - 2012-09-22 16:06 - 00000000 ____D C:\Users\Huthmann\Documents\Bewerbung 2013-06-02 19:00 - 2012-04-06 13:22 - 00000000 ____D C:\Users\Huthmann\AppData\Local\Google 2013-06-02 18:56 - 2013-06-02 18:56 - 00739856 ____A (Google Inc.) C:\Users\Huthmann\AppData\Roaming\chromebrowser.exe 2013-06-02 18:56 - 2013-06-02 18:56 - 00012240 ____A C:\Program Files (x86)\PJQ.dat 2013-06-02 18:56 - 2013-06-02 18:56 - 00000000 _RSHD C:\Users\Huthmann\AppData\Roaming\Paaspgty 2013-06-02 18:56 - 2013-06-02 18:56 - 00000000 _RSHD C:\Program Files (x86)\Myan 2013-06-02 18:55 - 2013-06-02 18:55 - 00030720 ____A C:\Users\Huthmann\0lz7g3zb5jb8o.exe 2013-06-02 09:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-05-31 15:22 - 2012-12-25 11:09 - 00000000 ____D C:\Users\Huthmann\Documents\Fußball 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\ProgramData\UUdb 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\ProgramData\DesktopIcons 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\ProgramData\1&1 Mail & Media GmbH 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\Program Files\WEB.DE MailCheck 2013-05-28 17:52 - 2013-05-28 17:52 - 00000000 ____D C:\Program Files (x86)\WEB.DE MailCheck 2013-05-28 17:52 - 2013-05-05 13:49 - 00000000 ____D C:\Program Files (x86)\1und1Softwareaktualisierung 2013-05-27 18:27 - 2012-12-17 18:32 - 00000000 ____D C:\Users\Huthmann\Documents\Rechnungen 2013-05-26 17:56 - 2012-11-01 21:01 - 00000000 ____D C:\Users\Huthmann\AppData\Roaming\HpUpdate 2013-05-19 12:08 - 2009-07-14 06:45 - 00343616 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-18 15:25 - 2012-09-09 10:46 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-05-18 15:22 - 2012-04-09 20:01 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-05-18 15:13 - 2012-04-30 06:53 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-05-18 15:13 - 2012-04-30 06:53 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-05-12 14:31 - 2013-05-12 14:29 - 00000004 ____A C:\Users\Huthmann\AppData\Roaming\skype.ini Files to move or delete: ==================== C:\Users\Huthmann\0lz7g3zb5jb8o.exe C:\Users\Huthmann\ActiveSetupN.exe C:\Users\Huthmann\avira_free_antivirus_898de.exe C:\Users\Huthmann\winmail_opener.exe C:\Users\Huthmann\AppData\Roaming\skype.ini ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-05-29 14:16 ==================== End Of Log ============================ Addition:FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-06-2013 02 |
Hi, Fix mit FRST Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Users\Huthmann\0lz7g3zb5jb8o.exe
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
|
Hallo Schrauber, hier ist die Fixlog.txt Datei Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-06-2013 02 hier nun die nächste Log. Danke bisweilen. Code: ComboFix 13-06-08.02 - Huthmann 11.06.2013 18:53:20.3.2 - x64 |
Hi, Combofix-Skript
|
Hallo Schrauber, hier nun das Log. Suspect oder Collect ist nicht erschienen, daher kein upload. Code: ComboFix 13-06-08.02 - Huthmann 11.06.2013 21:12:45.4.2 - x64 |
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches OTL log. Noch Probleme? |
Hallo Schrauber, hier die Dateien. Derzeit habe sind keine Probleme mehr aufgetreten, Danke. ADW: Code: # AdwCleaner v2.303 - Datei am 12/06/2013 um 18:33:08 erstellt Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code: OTL logfile created on: 12.06.2013 19:25:26 - Run 2 |
Supi, noch nen Onlinscan, dann sind wir durch :) ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches OTL log bitte. |
Guten Morgen Schrauber, hier nun die Log`s: Eset: Code: ESETSmartInstaller@High as downloader log: Code: Results of screen317's Security Check version 0.99.64 Code: OTL logfile created on: 13.06.2013 05:34:20 - Run 3 |
Java bitte updaten. Fixen mit OTL
Code: :OTL
Noch Probleme? :) |
Hallo Schrauber, nach dem Java update kam die Meldung Launch Error E4 und gestern wurden dann nochmal beim letzten online scan Trojaner gefunden. Ich gehe davon aus, dass dies normal ist? Sind die jetzt weg? Hier das OTL Log: Code: All processes killed |
von obigem ESET Scan? Die sind weg, die waren in den Temps oder bereits in Quarantäne. Wenn keine Probleme mehr sind sind wir fertig und räumen auf. |
Hallo Schrauber, die waren vom Eset Scan. Also ich bemerke ansonsten keine Probleme mehr. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:01 Uhr. |
Copyright ©2000-2025, Trojaner-Board