Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   google rocketnews (https://www.trojaner-board.de/115128-google-rocketnews.html)

cosinus 20.05.2012 20:45

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

da_tschaemp 20.05.2012 21:35

ich habe gerade das Problem dass ich mein AntiVir nicht vollständig abschalten kann. ich habe zwar den echtzeitscanner deaktiviert, aber das Programm an sich läuft noch. und da fängt das ComboFix dann an zu meckern. Wie kann ich denn das AnitVir komplett beenden? Im Programm selber finde ich nichts. Und wenn ich im Taskmanager den Prozess beenden will, kommt die Fehlermeldung, dass der Zugriff verweigert wird. Dabei habe ich eigentlich ein Admin-Benutzerkonto. Hättest du eine Idee wie ich das beheben kann? So will und soll ich das ComboFix ja nicht ausführen...

cosinus 21.05.2012 09:37

Wenn der Regenschirm geschlossen ist (Echtzeitscanner deaktiviert) kannst du diese Meldung ignorieren

da_tschaemp 21.05.2012 12:19

so jetzt hat alles geklappt
hier das log:

Code:

ComboFix 12-05-20.10 - da_tschaemp2 21.05.2012  12:53:01.1.2 - x86
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.2047.1408 [GMT 2:00]
ausgeführt von:: c:\users\da_tschaemp2\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-04-21 bis 2012-05-21  ))))))))))))))))))))))))))))))
.
.
2012-05-21 10:57 . 2012-05-21 10:57        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2012-05-21 10:57 . 2012-05-21 10:57        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-05-16 15:11 . 2012-05-17 10:05        --------        d-----w-        C:\_OTL
2012-05-14 19:52 . 2012-05-14 19:52        --------        d-----w-        c:\program files\ESET
2012-05-14 18:37 . 2012-05-14 18:37        --------        d-----w-        c:\users\da_tschaemp2\AppData\Roaming\Malwarebytes
2012-05-14 18:37 . 2012-05-14 18:37        --------        d-----w-        c:\programdata\Malwarebytes
2012-05-14 18:37 . 2012-04-04 13:56        22344        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-05-13 15:18 . 2012-03-30 10:23        1291632        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-05-13 15:18 . 2012-03-31 04:29        936960        ----a-w-        c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-13 15:18 . 2012-03-31 04:30        1221632        ----a-w-        c:\program files\Windows Journal\NBDoc.DLL
2012-05-13 15:18 . 2012-03-31 04:29        989184        ----a-w-        c:\program files\Windows Journal\JNTFiltr.dll
2012-05-13 15:18 . 2012-03-31 04:29        969216        ----a-w-        c:\program files\Windows Journal\JNWDRV.dll
2012-05-13 15:18 . 2012-03-31 04:39        3968368        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-05-13 15:18 . 2012-03-31 04:39        3913072        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-05-13 15:18 . 2012-03-31 02:36        2343424        ----a-w-        c:\windows\system32\win32k.sys
2012-05-13 15:17 . 2012-03-17 07:27        56176        ----a-w-        c:\windows\system32\drivers\partmgr.sys
2012-05-13 15:17 . 2012-03-03 05:31        1077248        ----a-w-        c:\windows\system32\DWrite.dll
2012-05-13 15:17 . 2012-04-13 07:36        6734704        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{F3392A44-DFE9-4359-A1A3-1BFE5EBBE914}\mpengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-08 15:30 . 2012-02-29 18:13        83392        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-05-08 15:30 . 2012-02-29 18:13        137928        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-05-04 17:11 . 2012-03-29 05:18        419488        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-05-04 17:11 . 2012-02-29 18:15        70304        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-04 12:43 . 2009-07-14 02:05        152576        ----a-w-        c:\windows\system32\msclmd.dll
2012-03-01 22:50 . 2012-03-01 22:45        2829        ----a-w-        c:\windows\War3Unin.pif
2012-03-01 22:50 . 2012-03-01 22:45        139264        ----a-w-        c:\windows\War3Unin.exe
2012-03-01 13:10 . 2012-03-01 13:10        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2012-03-01 05:46 . 2012-04-12 17:03        19824        ----a-w-        c:\windows\system32\drivers\fs_rec.sys
2012-03-01 05:37 . 2012-04-12 17:03        172544        ----a-w-        c:\windows\system32\wintrust.dll
2012-03-01 05:33 . 2012-04-12 17:03        159232        ----a-w-        c:\windows\system32\imagehlp.dll
2012-03-01 05:29 . 2012-04-12 17:03        5120        ----a-w-        c:\windows\system32\wmi.dll
2012-02-23 22:33 . 2012-02-29 18:10        27640        ----a-w-        c:\windows\system32\nitrolocalmon2.dll
2012-02-23 22:33 . 2012-02-29 18:10        18936        ----a-w-        c:\windows\system32\nitrolocalui2.dll
2012-02-23 08:18 . 2012-02-29 16:28        237072        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="e:\avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"3200 Scan2PC"="c:\windows\twain_32\Samsung\SCX3200\Scan2Pc.exe" [2010-05-18 1989120]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"iTunesHelper"="e:\itunes\iTunesHelper.exe" [2012-03-27 421736]
"PDFPrint"="e:\pdf24\pdf24.exe" [2012-05-07 160840]
"Malwarebytes' Anti-Malware"="e:\malwarebytes' anti-malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2012-3-6 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Users^da_tschaemp2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Trillian.lnk]
path=c:\users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk
backup=c:\windows\pss\Trillian.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-02-15 12:35        17146504        ----a-r-        c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
2012-03-14 20:33        4011184        ----a-w-        c:\users\da_tschaemp2\AppData\Roaming\Spotify\spotify.exe
.
R1 CXAVSAUD;Prolink 2388x Audio Capture;c:\windows\system32\DRIVERS\pvavsaud.sys [2005-10-25 11008]
R1 SWIPsec;SonicWALL IPsec Driver;c:\windows\system32\Drivers\SWIPsec.sys [2009-03-05 87064]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-02-15 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 257696]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [2006-05-27 147009]
R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [2006-05-27 497216]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\HCW88BAR.sys [2006-05-27 23104]
R3 SWVNIC;SonicWALL Virtual Miniport;c:\windows\system32\DRIVERS\swvnic.sys [2009-03-04 21016]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 13824]
R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-09 382272]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-16 36000]
S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 17920]
S2 AntiVirSchedulerService;Avira Planer;e:\avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
S2 dtpd;ShrewSoft DNS Proxy Daemon;e:\vpn\dtpd.exe [2010-10-08 54544]
S2 iked;ShrewSoft IKE Daemon;e:\vpn\iked.exe [2010-10-08 726288]
S2 ipsecd;ShrewSoft IPSEC Daemon;e:\vpn\ipsecd.exe [2010-10-08 541968]
S2 MBAMService;MBAMService;e:\malwarebytes' anti-malware\mbamservice.exe [2012-04-04 654408]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;e:\nitroreader\NitroPDFReaderDriverService2.exe [2012-02-23 198136]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-11-17 5120]
S2 SWGVCSvc;SonicWALL Global VPN Client Service;e:\sonicwall\SWGVCSvc.exe [2009-03-05 227352]
S2 TeamViewer7;TeamViewer 7;e:\teamviewer\TeamViewer_Service.exe [2012-02-23 2886528]
S3 AtcL001;NDIS-Miniporttreiber für L1-Gigabit-Ethernet-Controller von Atheros;c:\windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-12-16 25088]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 17:11]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\da_tschaemp2\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.178.1
TCP: Interfaces\{C17C8B53-9781-4D18-BEE2-DBFAD179FA5E}: NameServer = 193.174.193.80
FF - ProfilePath - c:\users\da_tschaemp2\AppData\Roaming\Mozilla\Firefox\Profiles\uhkxh89i.default\
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(1460)
c:\users\da_tschaemp2\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
Zeit der Fertigstellung: 2012-05-21  12:59:02
ComboFix-quarantined-files.txt  2012-05-21 10:59
.
Vor Suchlauf: 9 Verzeichnis(se), 30.494.744.576 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 30.271.483.904 Bytes frei
.
- - End Of File - - F3FA58C043A921C1755899531E588FFA


cosinus 21.05.2012 12:48

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

da_tschaemp 21.05.2012 20:08

so, also das mit dem GMER hat nicht wirklich funktioniert, deswegen hier das OSAM log:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:06:46 on 21.05.2012

OS: Windows 7  Service Pack 1 (Build 7601), 32-bit
Default Browser: Opera Software Opera Internet Browser 11.64

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\DA_TSC~1\AppData\Local\Temp\catchme.sys  (File not found)
"Cisco Systems Inc. IPSec Driver" (CVPNDRVA) - "Cisco Systems, Inc." - C:\Windows\system32\Drivers\CVPNDRVA.sys
"DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys  (File not found)
"fwtyqpog" (fwtyqpog) - ? - C:\Users\DA_TSC~1\AppData\Local\Temp\fwtyqpog.sys  (Hidden registry entry, rootkit activity | File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys
"SonicWALL IPsec Driver" (SWIPsec) - "SonicWALL, Inc." - C:\Windows\system32\Drivers\SWIPsec.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\Display\nvui.dll
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - E:\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\shlext.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - E:\WinRAR\rarext.dll

[Internet Explorer]
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
{48E73304-E1D6-4330-914C-F5F514E3486C} "Send to OneNote" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\da_tschaemp2\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"VPN Client.lnk" - "Cisco Systems, Inc." - E:\Cisco\vpngui.exe  (Shortcut exists | File exists)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"3200 Scan2PC" - ? - "C:\Windows\twain_32\Samsung\SCX3200\Scan2Pc.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "E:\Avira\AntiVir Desktop\avgnt.exe" /min
"GrooveMonitor" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"iTunesHelper" - "Apple Inc." - "E:\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "E:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"PDFPrint" - "Geek Software GmbH" - E:\PDF24\pdf24.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\sched.exe
"Cisco Systems, Inc. VPN Service" (CVPND) - "Cisco Systems, Inc." - E:\Cisco\cvpnd.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - E:\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
"NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - E:\NitroReader\NitroPDFReaderDriverService2.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files\WinPcap\rpcapd.exe
"ShrewSoft DNS Proxy Daemon" (dtpd) - ? - E:\VPN\dtpd.exe  (File found, but it contains no detailed information)
"ShrewSoft IKE Daemon" (iked) - ? - E:\VPN\iked.exe  (File found, but it contains no detailed information)
"ShrewSoft IPSEC Daemon" (ipsecd) - ? - E:\VPN\ipsecd.exe  (File found, but it contains no detailed information)
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"SonicWALL Global VPN Client Service" (SWGVCSvc) - "SonicWALL, Inc." - E:\SonicWall\SWGVCSvc.exe
"TeamViewer 7" (TeamViewer7) - "TeamViewer GmbH" - E:\TeamViewer\TeamViewer_Service.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

und hier noch das log von aswMBR:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-05-21 21:09:11
-----------------------------
21:09:11.130    OS Version: Windows 6.1.7601 Service Pack 1
21:09:11.130    Number of processors: 2 586 0x4303
21:09:11.131    ComputerName: DA_TSCHAEMP2-PC  UserName: da_tschaemp2
21:09:12.380    Initialize success
21:12:37.333    AVAST engine defs: 12052100
21:12:55.736    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:12:55.738    Disk 0 Vendor: SAMSUNG_HD501LJ CR100-12 Size: 476940MB BusType: 3
21:12:56.050    Disk 0 MBR read successfully
21:12:56.057    Disk 0 MBR scan
21:12:56.082    Disk 0 Windows 7 default MBR code
21:12:56.089    Disk 0 Partition 1 00    42          SFS              100 MB offset 14
21:12:56.112    Disk 0 Partition 2 80 (A) 42          SFS NTFS        51200 MB offset 206848
21:12:56.133    Disk 0 Partition 3 00    42          SFS NTFS      425638 MB offset 105064448
21:12:56.264    Disk 0 scanning sectors +976771120
21:12:56.327    Disk 0 scanning C:\Windows\system32\drivers
21:12:56.331    Service scanning
21:13:12.501    Modules scanning
21:13:13.323    Disk 0 trace - called modules:
21:13:13.366    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
21:13:13.371    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85658a00]
21:13:13.376    3 CLASSPNP.SYS[88da559e] -> nt!IofCallDriver -> [0x851c6918]
21:13:13.381    5 ACPI.sys[887b53d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x848a9610]
21:13:13.602    AVAST engine scan C:\Windows
21:13:13.617    AVAST engine scan C:\Windows\system32
21:13:13.632    AVAST engine scan C:\Windows\system32\drivers
21:13:13.645    AVAST engine scan C:\Users\da_tschaemp2
21:13:13.651    AVAST engine scan C:\ProgramData
21:13:13.658    Scan finished successfully
21:13:39.848    Disk 0 MBR has been saved successfully to "C:\Users\da_tschaemp2\Desktop\MBR.dat"
21:13:39.856    The log file has been saved successfully to "C:\Users\da_tschaemp2\Desktop\aswMBR.txt"


cosinus 21.05.2012 20:53

Zitat:

"DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys (File not found)
Bitte mit OSAM deaktivieren und löschen; mach danach ein frisches Log mit OSAM

da_tschaemp 21.05.2012 21:10

hier das neue OSAM log:

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 22:09:10 on 21.05.2012

OS: Windows 7  Service Pack 1 (Build 7601), 32-bit
Default Browser: Opera Software Opera Internet Browser 11.64

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\DA_TSC~1\AppData\Local\Temp\catchme.sys  (File not found)
"Cisco Systems Inc. IPSec Driver" (CVPNDRVA) - "Cisco Systems, Inc." - C:\Windows\system32\Drivers\CVPNDRVA.sys
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys
"SonicWALL IPsec Driver" (SWIPsec) - "SonicWALL, Inc." - C:\Windows\system32\Drivers\SWIPsec.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
(Disabled) "DgiVecp" (DgiVecp) - ? - C:\Windows\system32\Drivers\DgiVecp.sys  (File not found)

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{88FED34C-F0CA-4636-A375-3CB6248B04CD} "Local Groove Web Services Protocol" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\Display\nvui.dll
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - E:\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\shlext.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - E:\WinRAR\rarext.dll

[Internet Explorer]
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - E:\java\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
{48E73304-E1D6-4330-914C-F5F514E3486C} "Send to OneNote" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - E:\java\bin\ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\da_tschaemp2\AppData\Roaming\Dropbox\bin\Dropbox.exe  (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"VPN Client.lnk" - "Cisco Systems, Inc." - E:\Cisco\vpngui.exe  (Shortcut exists | File exists)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"3200 Scan2PC" - ? - "C:\Windows\twain_32\Samsung\SCX3200\Scan2Pc.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "E:\Avira\AntiVir Desktop\avgnt.exe" /min
"GrooveMonitor" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"iTunesHelper" - "Apple Inc." - "E:\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "E:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"PDFPrint" - "Geek Software GmbH" - E:\PDF24\pdf24.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - E:\Avira\AntiVir Desktop\sched.exe
"Cisco Systems, Inc. VPN Service" (CVPND) - "Cisco Systems, Inc." - E:\Cisco\cvpnd.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - E:\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Microsoft Office Groove Audit Service" (Microsoft Office Groove Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
"NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - E:\NitroReader\NitroPDFReaderDriverService2.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files\WinPcap\rpcapd.exe
"ShrewSoft DNS Proxy Daemon" (dtpd) - ? - E:\VPN\dtpd.exe  (File found, but it contains no detailed information)
"ShrewSoft IKE Daemon" (iked) - ? - E:\VPN\iked.exe  (File found, but it contains no detailed information)
"ShrewSoft IPSEC Daemon" (ipsecd) - ? - E:\VPN\ipsecd.exe  (File found, but it contains no detailed information)
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"SonicWALL Global VPN Client Service" (SWGVCSvc) - "SonicWALL, Inc." - E:\SonicWall\SWGVCSvc.exe
"TeamViewer 7" (TeamViewer7) - "TeamViewer GmbH" - E:\TeamViewer\TeamViewer_Service.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 22.05.2012 10:46

Ok, probier bitte nochmal GMER aus

da_tschaemp 22.05.2012 12:18

so ich denke diesmal hats geklappt...

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-05-22 13:15:33
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD501LJ rev.CR100-12
Running: 2po7kjfe.exe; Driver: C:\Users\DA_TSC~1\AppData\Local\Temp\fwtyqpog.sys


---- System - GMER 1.0.15 ----

SSDT            8E1D3CBE                                                                                                ZwCreateSection
SSDT            8E1D3CC8                                                                                                ZwRequestWaitReplyPort
SSDT            8E1D3CC3                                                                                                ZwSetContextThread
SSDT            8E1D3CCD                                                                                                ZwSetSecurityObject
SSDT            8E1D3CD2                                                                                                ZwSystemDebugControl
SSDT            8E1D3C5F                                                                                                ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!ZwRollbackEnlistment + 140D                                                                82A873C9 1 Byte  [06]
.text          ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                  82AC0D52 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 11F7                                                                      82AC7EAC 4 Bytes  [BE, 3C, 1D, 8E]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1553                                                                      82AC8208 4 Bytes  [C8, 3C, 1D, 8E] {ENTER 0x1d3c, 0x8e}
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1597                                                                      82AC824C 4 Bytes  [C3, 3C, 1D, 8E]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1613                                                                      82AC82C8 4 Bytes  [CD, 3C, 1D, 8E]
.text          ntkrnlpa.exe!KeRemoveQueueEx + 1667                                                                      82AC831C 4 Bytes  [D2, 3C, 1D, 8E]
.text          ...                                                                                                     

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]    [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]    [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress]  [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT            C:\Windows\system32\rundll32.exe[1456] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]  [75B3FFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device          \Driver\ACPI_HAL \Device\00000057                                                                        halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume5                                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume6                                                                  fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \FileSystem\fastfat \Fat                                                                                fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----


cosinus 22.05.2012 13:19

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

da_tschaemp 22.05.2012 19:42

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.05.22.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
da_tschaemp2 :: DA_TSCHAEMP2-PC [Administrator]

Schutz: Deaktiviert

22.05.2012 19:42:27
mbam-log-2012-05-22 (19-42-27).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 325592
Laufzeit: 51 Minute(n), 36 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 22.05.2012 19:46

Das ist schon mal ok :daumenhoc

da_tschaemp 22.05.2012 20:05

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 05/22/2012 at 08:53 PM

Application Version : 5.0.1150

Core Rules Database Version : 8632
Trace Rules Database Version: 6444

Scan type      : Quick Scan
Total Scan Time : 00:03:49

Operating System Information
Windows 7 Professional 32-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 699
Memory threats detected  : 0
Registry items scanned    : 27453
Registry threats detected : 1
File items scanned        : 7661
File threats detected    : 75

Adware.Tracking Cookie
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\XBXRKGU4.txt [ /mediaplex.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\E3EV5O16.txt [ /ad.yieldmanager.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\U60X147P.txt [ /track.adform.net ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\FN70AM1W.txt [ /invitemedia.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\YFZS01LZ.txt [ /smartadserver.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\VDP4E7SM.txt [ /c.atdmt.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\R1QZ7PF2.txt [ /dyntracker.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\L8A0YQGT.txt [ /atdmt.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\HDGR0L02.txt [ /apmebf.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\MQ3WI5W4.txt [ /adform.net ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\MNCADX1N.txt [ /fastclick.net ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\4ZZHMMP9.txt [ /imrworldwide.com ]
        .doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .ad-emea.doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\RPPGIHD0.txt [ /serving-sys.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\EILJ14BJ.txt [ /bs.serving-sys.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\M3FZM7YP.txt [ /eas.apm.emediate.eu ]
        .a.revenuemax.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\13DG6UXZ.txt [ /tracking.quisma.com ]
        C:\Users\da_tschaemp2\AppData\Roaming\Microsoft\Windows\Cookies\UX97VHG2.txt [ /zanox.com ]
        .atdmt.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        xml.trafficno.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        xml.trafficno.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        ox-d.enveromedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\XBXRKGU4.txt [ Cookie:da_tschaemp2@mediaplex.com/ ]
        .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\E3EV5O16.txt [ Cookie:da_tschaemp2@ad.yieldmanager.com/ ]
        .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\U60X147P.txt [ Cookie:da_tschaemp2@track.adform.net/ ]
        C:\USERS\DA_TSCHAEMP2\Cookies\FN70AM1W.txt [ Cookie:da_tschaemp2@invitemedia.com/ ]
        .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\YFZS01LZ.txt [ Cookie:da_tschaemp2@smartadserver.com/ ]
        C:\USERS\DA_TSCHAEMP2\Cookies\VDP4E7SM.txt [ Cookie:da_tschaemp2@c.atdmt.com/ ]
        .tracking.quisma.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\L8A0YQGT.txt [ Cookie:da_tschaemp2@atdmt.com/ ]
        .invitemedia.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\HDGR0L02.txt [ Cookie:da_tschaemp2@apmebf.com/ ]
        ad.yieldmanager.com [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\DA_TSCHAEMP2\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UHKXH89I.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\DA_TSCHAEMP2\Cookies\EILJ14BJ.txt [ Cookie:da_tschaemp2@bs.serving-sys.com/ ]
        C:\USERS\DA_TSCHAEMP2\Cookies\M3FZM7YP.txt [ Cookie:da_tschaemp2@eas.apm.emediate.eu/ ]
        C:\USERS\DA_TSCHAEMP2\Cookies\13DG6UXZ.txt [ Cookie:da_tschaemp2@tracking.quisma.com/ ]
        C:\USERS\DA_TSCHAEMP2\Cookies\UX97VHG2.txt [ Cookie:da_tschaemp2@zanox.com/ ]

System.BrokenFileAssociation
        HKCR\.exe


cosinus 22.05.2012 20:24

Zitat:

Scan type : Quick Scan
Da solltest du auch einen Vollscan machen :wtf:


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:17 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131