|  | 
| 
 GVU-/Bundespolizei-Trojaner, abgesicherter Modus funktioniert nicht Hallo Experten! Nun hat es auch mich erwischt! Seit heute morgen erscheint auf meinem PC (Win7) nur noch dieser Trojaner-Bildschirm mit Webcam-Foto, "Gesellschaft zur Verfolgung von Urheberrechtsverletzungen e.V."- und "Bundespolizei"-Schriftzug inklusive Zahlungsaufforderung von 100€. Wenn ich das Internetkabel herausziehe, kommt stattdessen nur ein weißer Bildschirm. Öffnen des Taskmanagers ist nicht möglich. Wenn ich versuche, den PC im abgesicherten Modus zu starten, fährt er hoch, nur um dann direkt wieder neu zu starten, ich kann also kein Programm ausführen oder Ähnliches... Da ich auf diesem Gebiet nicht so sehr bewandert bin, hoffe ich, dass ihr mir helfen könnt! Vielen Dank schonmal! | 
| 
 :hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise: 
 Hast du eine 32 oder eine 64 Bit Variante von Windows 7 ? | 
| 
 Hallo Matthias! Vielen Dank, dass du dich so schnell gemeldet hast! Ich glaube, dass es die 32-bit Variante ist (Medion-PC vom Aldi)... | 
| 
 Servus, dann versuchen wir es mal.... :) Downloade dir bitte Farbar Recovery Scan Tool 32-Bit von einem sauberen Computer und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an. Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager 
 Mit Windows CD/DVD 
 Wähle in den Reparaturoptionen Eingabeaufforderung 
 | 
| 
 Den USB-Stick kann ich jetzt einfach umstecken? Oder kann der jetzt auch infiziert sein? Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-02-2013 01 Ran by SYSTEM at 19-02-2013 14:54:00 Running from G:\ Windows 7 Home Premium (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1230704 2011-03-21] () HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.) HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-12-07] (Apple Inc.) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated) HKU\Richard\...\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\Richard\...\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [1305408 2011-01-20] (DT Soft Ltd) HKU\Richard\...\Run: [NBCore] "C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBCore.exe" [1598760 2009-09-23] (Nero AG) HKU\Richard\...\Run: [Device Detection] C:\Program Files\Lidl_Fotos\dd.exe [857600 2013-01-09] () HKU\Richard\...\Run: [Zuagm] C:\Users\Richard\AppData\Roaming\Xegic\beeh.exe [230366 2011-07-20] () HKU\Richard\...\Winlogon: [Shell] explorer.exe,C:\Users\Richard\AppData\Roaming\skype.dat [111104 2011-11-16] () HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$25acc865172795dcb9888bd5cdec6c00\n. ATTENTION! ====> ZeroAccess Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk.disabled ShortcutTarget: McAfee Security Scan Plus.lnk.disabled -> X:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (No File) ==================== Services (Whitelisted) =================== 2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [136360 2011-04-26] (Avira GmbH) 2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [269480 2011-06-28] (Avira GmbH) 3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.) 3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [115608 2013-02-09] (Mozilla Foundation) ==================== Drivers (Whitelisted) ==================== 2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [66616 2011-06-28] (Avira GmbH) 1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [138192 2011-06-28] (Avira GmbH) 0 sptd; C:\Windows\System32\Drivers\sptd.sys [431672 2011-04-04] (Duplex Secure Ltd.) 1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-02-19 14:53 - 2013-02-19 14:53 - 00000000 ____D C:\FRST 2013-02-19 02:38 - 2013-02-19 03:30 - 00000004 ____A C:\Users\Richard\AppData\Roaming\skype.ini 2013-02-19 02:33 - 2013-02-19 02:38 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Keegvy 2013-02-19 02:33 - 2013-02-19 02:33 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Xegic 2013-02-19 02:33 - 2013-02-19 02:33 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Ilewa 2013-02-18 01:19 - 2013-02-18 02:03 - 262144130 ____A C:\Users\Richard\Downloads\lecturio.A1O.a.zip 2013-02-17 14:33 - 2013-02-17 14:33 - 00120727 ____A C:\Users\Richard\Desktop\Urlaub Last Minute Reisen Pauschalreisen Urlaub Familienurlaub Billig Flüge, Hotels, Urlaub, Hotelbewertungen - Lastminute Urlaub buchen bei ab-in-den-urlaub.de.htm 2013-02-16 11:25 - 2013-02-16 11:25 - 00000000 ____D C:\Users\Richard\restore 2013-02-16 11:23 - 2013-02-18 12:01 - 00000000 ____D C:\ProgramData\tmp 2013-02-16 11:23 - 2013-02-16 11:23 - 00001271 ____A C:\Users\Public\Desktop\OnlineFotoservice.lnk 2013-02-16 11:23 - 2013-02-16 11:23 - 00000000 ____D C:\ProgramData\hps 2013-02-16 11:07 - 2013-02-16 11:07 - 00000000 ____D C:\Program Files\OnlineFotoservice 2013-02-16 10:57 - 2013-02-16 10:58 - 01568008 ____A C:\Users\Richard\Downloads\setup_OnlineFotoservice.exe 2013-02-15 14:17 - 2013-01-08 14:23 - 12321280 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-02-15 14:17 - 2013-01-08 14:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-02-15 14:17 - 2013-01-08 14:09 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-02-15 14:17 - 2013-01-08 14:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-02-15 14:17 - 2013-01-08 14:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-02-15 14:17 - 2013-01-08 14:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-02-15 14:17 - 2013-01-08 14:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-02-15 14:17 - 2013-01-08 14:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-02-15 14:17 - 2013-01-08 13:59 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-02-15 14:17 - 2013-01-08 13:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-02-15 14:17 - 2013-01-08 13:58 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-02-15 14:17 - 2013-01-08 13:57 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-02-15 14:17 - 2013-01-08 13:56 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-02-15 14:17 - 2013-01-08 13:56 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-02-15 14:17 - 2013-01-08 13:56 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-02-15 14:17 - 2013-01-08 13:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-02-15 13:37 - 2013-01-04 21:00 - 03967848 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-02-15 13:37 - 2013-01-04 21:00 - 03913064 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-02-15 13:37 - 2013-01-03 20:50 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2013-02-15 13:37 - 2013-01-03 19:00 - 02347008 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-02-15 13:37 - 2013-01-02 21:05 - 01293672 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-02-15 13:37 - 2013-01-02 21:04 - 00187752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2013-02-09 03:00 - 2013-02-10 02:01 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-01-25 01:35 - 2013-01-25 01:35 - 00052922 ____A C:\Users\Richard\Desktop\Tiefgaragenstellplatz in Karlsruhe - Oberreut.htm Bild 1.htm 2013-01-25 01:33 - 2013-01-25 01:33 - 00052659 ____A C:\Users\Richard\Desktop\Tiefgaragenstellplatz in Karlsruhe - Oberreut.htm 2013-01-25 01:33 - 2013-01-25 01:33 - 00051804 ____A C:\Users\Richard\Desktop\Bild 2.htm ==================== One Month Modified Files and Folders ======== 2013-02-19 14:53 - 2013-02-19 14:53 - 00000000 ____D C:\FRST 2013-02-19 03:30 - 2013-02-19 02:38 - 00000004 ____A C:\Users\Richard\AppData\Roaming\skype.ini 2013-02-19 03:20 - 2011-04-01 05:39 - 01498742 ____A C:\Windows\System32\PerfStringBackup.INI 2013-02-19 03:19 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-02-19 03:19 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-02-19 03:17 - 2012-07-15 00:49 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-02-19 03:11 - 2012-07-12 21:00 - 00025412 ____A C:\Windows\setupact.log 2013-02-19 03:11 - 2011-04-14 11:24 - 00001096 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-02-19 03:11 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-02-19 02:56 - 2012-02-26 00:42 - 01378075 ____A C:\Windows\WindowsUpdate.log 2013-02-19 02:39 - 2013-02-19 02:33 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Keegvy 2013-02-19 02:33 - 2013-02-19 02:33 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Xegic 2013-02-19 02:33 - 2013-02-19 02:33 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Ilewa 2013-02-19 02:32 - 2011-04-14 11:24 - 00001100 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-02-19 00:08 - 2012-09-22 00:00 - 00005164 ____A C:\Windows\PFRO.log 2013-02-18 12:01 - 2013-02-16 11:23 - 00000000 ____D C:\ProgramData\tmp 2013-02-18 02:43 - 2011-04-02 01:08 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-02-18 02:09 - 2012-11-04 01:41 - 00000000 ____D C:\Users\Richard\Desktop\14.04 2013-02-18 02:03 - 2013-02-18 01:19 - 262144130 ____A C:\Users\Richard\Downloads\lecturio.A1O.a.zip 2013-02-17 14:33 - 2013-02-17 14:33 - 00120727 ____A C:\Users\Richard\Desktop\Urlaub Last Minute Reisen Pauschalreisen Urlaub Familienurlaub Billig Flüge, Hotels, Urlaub, Hotelbewertungen - Lastminute Urlaub buchen bei ab-in-den-urlaub.de.htm 2013-02-16 11:25 - 2013-02-16 11:25 - 00000000 ____D C:\Users\Richard\restore 2013-02-16 11:25 - 2011-04-01 05:37 - 00000000 ____D C:\users\Richard 2013-02-16 11:23 - 2013-02-16 11:23 - 00001271 ____A C:\Users\Public\Desktop\OnlineFotoservice.lnk 2013-02-16 11:23 - 2013-02-16 11:23 - 00000000 ____D C:\ProgramData\hps 2013-02-16 11:07 - 2013-02-16 11:07 - 00000000 ____D C:\Program Files\OnlineFotoservice 2013-02-16 10:58 - 2013-02-16 10:57 - 01568008 ____A C:\Users\Richard\Downloads\setup_OnlineFotoservice.exe 2013-02-16 01:26 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-02-16 01:04 - 2009-07-13 20:33 - 00301376 ____A C:\Windows\System32\FNTCACHE.DAT 2013-02-15 14:18 - 2011-04-10 09:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-02-15 14:18 - 2011-04-02 13:22 - 67823584 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-02-15 13:25 - 2012-07-28 06:38 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-02-10 02:01 - 2013-02-09 03:00 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-02-09 03:18 - 2012-07-15 00:49 - 00697712 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-02-09 03:18 - 2011-07-03 11:42 - 00074096 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-02-06 14:07 - 2011-01-24 09:06 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Skype 2013-02-01 02:49 - 2011-04-05 11:40 - 00000000 ____D C:\Users\Richard\AppData\Roaming\AIMP 2013-01-25 01:35 - 2013-01-25 01:35 - 00052922 ____A C:\Users\Richard\Desktop\Tiefgaragenstellplatz in Karlsruhe - Oberreut.htm Bild 1.htm 2013-01-25 01:33 - 2013-01-25 01:33 - 00052659 ____A C:\Users\Richard\Desktop\Tiefgaragenstellplatz in Karlsruhe - Oberreut.htm 2013-01-25 01:33 - 2013-01-25 01:33 - 00051804 ____A C:\Users\Richard\Desktop\Bild 2.htm 2013-01-20 02:13 - 2012-10-13 05:11 - 00000000 ____D C:\Program Files\Lidl_Fotos ZeroAccess: C:\$Recycle.Bin\S-1-5-21-4154815888-579199364-2642292094-1000\$25acc865172795dcb9888bd5cdec6c00 ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$25acc865172795dcb9888bd5cdec6c00 ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-02-05 14:02:50 Restore point made on: 2013-02-05 23:10:17 Restore point made on: 2013-02-06 14:09:44 Restore point made on: 2013-02-09 01:40:27 Restore point made on: 2013-02-09 14:11:44 Restore point made on: 2013-02-09 23:37:56 Restore point made on: 2013-02-10 04:28:34 Restore point made on: 2013-02-15 13:32:02 Restore point made on: 2013-02-15 14:14:32 Restore point made on: 2013-02-16 15:19:47 Restore point made on: 2013-02-17 01:42:35 Restore point made on: 2013-02-17 14:33:56 Restore point made on: 2013-02-18 00:25:32 Restore point made on: 2013-02-18 00:47:36 Restore point made on: 2013-02-18 00:53:34 Restore point made on: 2013-02-18 02:23:14 Restore point made on: 2013-02-18 04:09:40 Restore point made on: 2013-02-18 14:16:28 Restore point made on: 2013-02-19 00:13:47 ==================== Memory info =========================== Percentage of memory in use: 15% Total physical RAM: 3071.24 MB Available physical RAM: 2603.91 MB Total Pagefile: 3069.52 MB Available Pagefile: 2603.76 MB Total Virtual: 2047.88 MB Available Virtual: 1960.73 MB ==================== Partitions ============================= 1 Drive c: (Boot) (Fixed) (Total:890.41 GB) (Free:164.75 GB) NTFS 2 Drive e: (Recover) (Fixed) (Total:40 GB) (Free:23.49 GB) NTFS 4 Drive g: (USB DISK) (Removable) (Total:14.9 GB) (Free:14.78 GB) FAT32 6 Drive i: (FZ8) (Removable) (Total:0.93 GB) (Free:0.72 GB) FAT 12 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 13 Drive y: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt -------- ------------- ------- ------- --- --- Disk 0 Online 931 GB 0 B Disk 1 Online 14 GB 0 B Disk 2 No Media 0 B 0 B Disk 3 Online 952 MB 0 B Disk 4 No Media 0 B 0 B Disk 5 No Media 0 B 0 B Disk 6 No Media 0 B 0 B Disk 7 No Media 0 B 0 B Disk 8 No Media 0 B 0 B Partitions of Disk 0: =============== Disk ID: 2BD2C32A Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 100 MB 1024 KB Partition 2 Primary 890 GB 101 MB Partition 3 Primary 40 GB 890 GB Partition 4 OEM 1025 MB 930 GB ========================================================= Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 Y NTFS Partition 100 MB Healthy ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 C Boot NTFS Partition 890 GB Healthy ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 E Recover NTFS Partition 40 GB Healthy ========================================================= Disk: 0 Partition 4 Type : 12 Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 12 NTFS Partition 1025 MB Healthy Hidden ========================================================= Partitions of Disk 1: =============== Disk ID: C3072E18 Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 14 GB 4032 KB ========================================================= Disk: 1 Partition 1 Type : 0C Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 G USB DISK FAT32 Removable 14 GB Healthy ========================================================= Partitions of Disk 3: =============== Disk ID: 00000000 Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 952 MB 64 KB ========================================================= Disk: 3 Partition 1 Type : 06 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 6 I FZ8 FAT Removable 952 MB Healthy ========================================================= Last Boot: 2013-02-15 13:49 ==================== End Of Log ============================ | 
| 
 Servus, da hast du dir aber ganz schön was auf den Rechner geholt. Den USB-Stick kannst du am Ende der Bereinigung formatieren. Es sollte aber damit keine Probleme geben. :) Drücke auf dem sauberen Rechner bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: start
 Berichte mir, ob du wieder in den normalen Modus starten kannst! | 
| 
 Vielen Dank, Matthias, der PC startet wieder normal! :D Hier die fixlog.txt: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-02-2013 01 Ran by SYSTEM at 2013-02-19 15:21:58 Run:1 Running from G:\ ============================================== HKEY_USERS\Richard\Software\Microsoft\Windows\CurrentVersion\Run\\Zuagm Value deleted successfully. HKEY_USERS\Richard\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell Value deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default value was restored successfully . [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}] should be deleted in normal mode (if present). C:\Users\Richard\AppData\Roaming\Xegic\beeh.exe moved successfully. C:\Users\Richard\AppData\Roaming\skype.dat moved successfully. C:\Users\Richard\AppData\Roaming\skype.ini moved successfully. C:\Users\Richard\AppData\Roaming\Keegvy moved successfully. C:\Users\Richard\AppData\Roaming\Xegic moved successfully. C:\Users\Richard\AppData\Roaming\Ilewa moved successfully. C:\$Recycle.Bin\S-1-5-21-4154815888-579199364-2642292094-1000\$25acc865172795dcb9888bd5cdec6c00 moved successfully. C:\$Recycle.Bin\S-1-5-18\$25acc865172795dcb9888bd5cdec6c00 moved successfully. ==== End of Fixlog ==== | 
| 
 Sehr gut gemacht. :daumenhoc Zitat: 
 So geht es weiter: Schritt 1 Scan mit Combofix 
 Schritt 2 Downloade dir bitte  Malwarebytes Anti-Rootkit und speichere es auf deinem   Desktop. 
 Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Bitte poste mit deiner nächsten Antwort 
 | 
| 
 Hallo Matthias! Sorry, dass es so lang gedauert hat, aber die Programme haben ewig zum scannen gebraucht :) So, jetzt hab ich endlich die log-dateien: ComboFix: Combofix Logfile: Code: ComboFix 13-02-18.02 - Richard 19.02.2013  15:39:51.1.2 - x86und MBAR: --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.01.0.1020 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_25 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.000000 GHz Memory total: 3220430848, free: 1933451264 ------------ Kernel report ------------ 02/19/2013 16:00:05 ------------ Loaded modules ----------- \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\halmacpi.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\System32\Drivers\sptd.sys \SystemRoot\System32\Drivers\WMILIB.SYS \SystemRoot\System32\Drivers\SCSIPORT.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\intelide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\sfdrv01.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\ws2ifsl.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \SystemRoot\system32\DRIVERS\ssmdrv.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\avipbb.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\Rt86win7.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys \SystemRoot\System32\Drivers\avixpq4p.SYS \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\AtihdW73.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\RTKVHDA.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_dumpata.sys \SystemRoot\System32\Drivers\dump_msahci.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\system32\DRIVERS\point32.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\avgntflt.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\DRIVERS\RTL8192su.sys \SystemRoot\system32\DRIVERS\vwifibus.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\DRIVERS\vwifimp.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\WUDFRd.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe \Windows\System32\shlwapi.dll \Windows\System32\comdlg32.dll \Windows\System32\Wldap32.dll \Windows\System32\difxapi.dll \Windows\System32\advapi32.dll \Windows\System32\kernel32.dll \Windows\System32\rpcrt4.dll \Program Files\DAEMON Tools Lite\Engine.dll \Windows\System32\lpk.dll \Windows\System32\sechost.dll \Windows\System32\usp10.dll \Windows\System32\psapi.dll \Windows\System32\imm32.dll \Windows\System32\imagehlp.dll \Windows\System32\msvcrt.dll \Windows\System32\ws2_32.dll \Windows\System32\shell32.dll \Windows\System32\setupapi.dll \Windows\System32\user32.dll \Windows\System32\oleaut32.dll \Windows\System32\wininet.dll \Windows\System32\urlmon.dll \Windows\System32\normaliz.dll \Windows\System32\iertutil.dll \Windows\System32\msctf.dll \Windows\System32\clbcatq.dll \Windows\System32\ole32.dll \Windows\System32\gdi32.dll \Windows\System32\nsi.dll \Windows\System32\KernelBase.dll \Windows\System32\cfgmgr32.dll \Windows\System32\wintrust.dll \Windows\System32\crypt32.dll \Windows\System32\devobj.dll \Windows\System32\comctl32.dll \Windows\System32\msasn1.dll ----------- End ----------- <<<1>>> Upper Device Name: \Device\Harddisk8\DR8 Upper Device Object: 0xffffffff87ccb030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000075\ Lower Device Object: 0xffffffff87cc5750 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR Initialization returned 0x0 Load Function returned 0x0 <<<1>>> Upper Device Name: \Device\Harddisk7\DR7 Upper Device Object: 0xffffffff87cca030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000074\ Lower Device Object: 0xffffffff87cc47e8 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk6\DR6 Upper Device Object: 0xffffffff87c78650 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000073\ Lower Device Object: 0xffffffff87cbc030 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk5\DR5 Upper Device Object: 0xffffffff87c78030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000072\ Lower Device Object: 0xffffffff87c511b0 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk4\DR4 Upper Device Object: 0xffffffff87c75030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\00000070\ Lower Device Object: 0xffffffff87c70ca8 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk3\DR3 Upper Device Object: 0xffffffff87c72030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\0000006f\ Lower Device Object: 0xffffffff86fa1c00 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk2\DR2 Upper Device Object: 0xffffffff87c736f0 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\0000006e\ Lower Device Object: 0xffffffff86fa8638 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffffff87a37030 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\0000006a\ Lower Device Object: 0xffffffff87a35308 Lower Device Driver Name: \Driver\USBSTOR\ Driver name found: USBSTOR <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff863b93c8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-4\ Lower Device Object: 0xffffffff862a2908 Lower Device Driver Name: \Driver\atapi\ Driver name found: atapi Initialization returned 0x0 Port sub-driver loaded: \??\C:\Windows\System32\drivers\ataport.sys (0x0) Load Function returned 0x0 No address found Initializing... Done! <<<2>>> Device number: 0, partition: 2 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff863b93c8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff863ba020, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff863b93c8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff862ccc10, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff862a2908, DeviceName: \Device\Ide\IdeDeviceP2T0L0-4\, DriverName: \Driver\atapi\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffffac014388, 0xffffffff863b93c8, 0xffffffff8a7d1ac8 Lower DeviceData: 0xffffffff9f7623b0, 0xffffffff862a2908, 0xffffffff8a7ddad0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\Windows\system32\drivers... <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes File user open failed: C:\Windows\system32\drivers\sptd.sys (0x00000020) Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 2BD2C32A Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 204800 Partition file system is NTFS Partition is bootable Partition 1 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 206848 Numsec = 1867329536 Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 1867536384 Numsec = 83886080 Partition 3 type is Other (0x12) Partition is NOT ACTIVE. Partition starts at LBA: 1951422464 Numsec = 2099200 Disk Size: 1000204886016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1953505168-1953525168)... Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffffffff87a37030, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87a199e8, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87a37030, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff87a35308, DeviceName: \Device\0000006a\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffffa2d3ec00, 0xffffffff87a37030, 0xffffffff8a7daac8 Lower DeviceData: 0xffffffffa34bf7e0, 0xffffffff87a35308, 0xffffffff8a7d4f08 Drive 1 Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: C3072E18 Partition information: Partition 0 type is Other (0xc) Partition is NOT ACTIVE. Partition starts at LBA: 8064 Numsec = 31265664 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 16012148736 bytes Sector size: 512 bytes Physical Sector Size: 0 Drive: 2, DevicePointer: 0xffffffff87c736f0, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87c4fd10, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87c736f0, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff86fa8638, DeviceName: \Device\0000006e\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 512 Drive: 3, DevicePointer: 0xffffffff87c72030, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87c71a78, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87c72030, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff86fa1c00, DeviceName: \Device\0000006f\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ Upper DeviceData: 0xffffffff9f7e7f90, 0xffffffff87c72030, 0xffffffff86c69048 Lower DeviceData: 0xffffffffac57af28, 0xffffffff86fa1c00, 0xffffffff8a7d54c8 Drive 3 Scanning MBR on drive 3... Inspecting partition table: MBR Signature: 55AA Disk Signature: 0 Partition information: Partition 0 type is Other (0x6) Partition is NOT ACTIVE. Partition starts at LBA: 129 Numsec = 1950591 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 998768640 bytes Sector size: 512 bytes Physical Sector Size: 0 Drive: 4, DevicePointer: 0xffffffff87c75030, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87c73d10, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87c75030, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff87c70ca8, DeviceName: \Device\00000070\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 5, DevicePointer: 0xffffffff87c78030, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87c78d10, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87c78030, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff87c511b0, DeviceName: \Device\00000072\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 6, DevicePointer: 0xffffffff87c78650, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87c8a998, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87c78650, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff87cbc030, DeviceName: \Device\00000073\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 7, DevicePointer: 0xffffffff87cca030, DeviceName: \Device\Harddisk7\DR7\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87ccad10, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87cca030, DeviceName: \Device\Harddisk7\DR7\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff87cc47e8, DeviceName: \Device\00000074\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 8, DevicePointer: 0xffffffff87ccb030, DeviceName: \Device\Harddisk8\DR8\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff87ccb718, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff87ccb030, DeviceName: \Device\Harddisk8\DR8\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff87cc5750, DeviceName: \Device\00000075\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Done! Performing system, memory and registry scan... Infected: c:\Users\Richard\Downloads\SoftonicDownloader_fuer_greycs-magic-image-converter.exe --> [PUP.OfferBundler.ST] Infected: c:\Users\Richard\Downloads\SoftonicDownloader_fuer_mcafee-labs-stinger.exe --> [PUP.OfferBundler.ST] Infected: c:\Users\Richard\Downloads\SoftonicDownloader_fuer_trend-micro-housecall.exe --> [PUP.OfferBundler.ST] Infected: c:\Users\Richard\Downloads\SoftonicDownloader_fuer_videopad-video-editor.exe --> [PUP.OfferBundler.ST] Done! Scan finished Creating System Restore point... Scheduling clean up... <<<2>>> Device number: 0, partition: 2 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.01.0.1020 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 Java version: 1.6.0_25 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 3.000000 GHz Memory total: 3220430848, free: 2490253312 Removal queue found; removal started Removing c:\Users\Richard\Downloads\SoftonicDownloader_fuer_greycs-magic-image-converter.exe... Removing c:\Users\Richard\Downloads\SoftonicDownloader_fuer_mcafee-labs-stinger.exe... Removing c:\Users\Richard\Downloads\SoftonicDownloader_fuer_trend-micro-housecall.exe... Removing c:\Users\Richard\Downloads\SoftonicDownloader_fuer_videopad-video-editor.exe... Removal finished ======================================= | 
| 
 Servus, wie läuft dein Rechner derzeit? Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop (falls noch nicht vorhanden). 
 Code: activex
 | 
| 
 Hallo :) momentan läuft der PC super! Dank deiner Hilfe!! OTL.txt:OTL Logfile: Code: OTL logfile created on: 19.02.2013 18:10:57 - Run 1Extras.txt:OTL Logfile: Code: OTL Extras logfile created on: 19.02.2013 18:10:57 - Run 1 | 
| 
 Servus, ich seh noch etwas Adware. Darum kümmern wir uns noch. :daumenhoc Schritt 1 Downloade Dir bitte  AdwCleaner auf deinen Desktop. 
 Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu   vermeiden. 
 Schritt 3 Starte bitte OTL.exe und drücke den Quick Scan Button. Poste die OTL.txt hier in deinen Thread. Bitte poste mit deiner nächsten Antwort 
 | 
| 
 So, hier die drei Logdateien: Nr.1 AdwCleaner:AdwCleaner Logfile: Code: # AdwCleaner v2.112 - Datei am 19/02/2013 um 18:38:03 erstelltNr.2 JRT: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.6.5 (02.18.2013:1) OS: Windows 7 Home Premium x86 Ran by Richard on 19.02.2013 at 18:41:07,05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{6a1806cd-94d4-4689-ba73-e35ea1ea9990} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Richard\AppData\Roaming\dvdvideosoftiehelpers" ~~~ FireFox Successfully deleted: [Folder] C:\Users\Richard\AppData\Roaming\mozilla\firefox\profiles\7wy6t8rj.default\extensions\{acaa314b-eeba-48e4-ad47-84e31c44796c} Successfully deleted the following from C:\Users\Richard\AppData\Roaming\mozilla\firefox\profiles\7wy6t8rj.default\prefs.js user_pref("extensions.enabledItems", "{ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1,{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6,{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22,{ Emptied folder: C:\Users\Richard\AppData\Roaming\mozilla\firefox\profiles\7wy6t8rj.default\minidumps [35 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 19.02.2013 at 18:44:35,40 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Nr.3 OTL:OTL Logfile: Code: OTL logfile created on: 19.02.2013 18:45:03 - Run 2 | 
| 
 Servus, wir kontrollieren nochmal alles. Wenn alles passt, entfernen wir im letzten Schritt alles Tools und ich gebe dir noch ein paar Tipps mit auf den Weg. ;) Schritt 1 Fixen mit OTL 
 Code: :OTL
 Schritt 2 
 Schritt 3 
 Schritt 4 ESET Online Scanner 
 Schritt 5 Downloade Dir bitte  SecurityCheck und: 
 Bitte poste mit deiner nächsten Antwort 
 | 
| 
 Hallo Matthias, endlich habe ich die Zeit gefunden, die log-Dateien zu posten. Entschuldigung für die lange Verspätung! ========== OTL ========== Error: No service named anzet9qb was found to stop! Service\Driver key anzet9qb not found. Prefs.js: "google-feed.net" removed from browser.search.defaultenginename Prefs.js: "GoogleFeed.net" removed from browser.search.selectedEngine C:\Users\Richard\AppData\Roaming\mozilla\firefox\profiles\7wy6t8rj.default\searchplugins\GoogleFeed.xml moved successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube Download\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube to MP3 Converter\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Richard ->Temp folder emptied: 21686237 bytes ->Temporary Internet Files folder emptied: 26885458 bytes ->Java cache emptied: 5631991 bytes ->FireFox cache emptied: 103209932 bytes ->Google Chrome cache emptied: 49989401 bytes ->Flash cache emptied: 57384 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1535576 bytes RecycleBin emptied: 13866215 bytes Total Files Cleaned = 213,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 02212013_134622 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... Malwarebytes Anti-Malware 1.70.0.1100 Malwarebytes : Free anti-malware download Datenbank Version: v2013.02.19.05 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Richard :: RICHARD-PC [Administrator] 21.02.2013 13:52:01 mbam-log-2013-02-21 (13-52-01).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 199539 Laufzeit: 5 Minute(n), 37 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e9bc2d9e2f74af49a4f42feac59837bc # engine=13207 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-02-21 06:39:03 # local_time=2013-02-21 07:39:03 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1797 16775165 100 94 181865 98012364 33529 0 # compatibility_mode=5893 16776573 100 94 213892 113103134 0 0 # scanned=410877 # found=2 # cleaned=0 # scan_time=20315 sh=B38FE6D523D1ADB8C28C4876A191934B483F4B0E ft=1 fh=9ef19668fe1d4890 vn="Win32/Spy.Zbot.AAO trojan" ac=I fn="C:\FRST\Quarantine\beeh.exe" sh=E5F2C7C7EF2C4280BDC83FBF1D45EB6756C3899D ft=1 fh=541efe99b40d869d vn="a variant of Win32/Kryptik.AUSC trojan" ac=I fn="C:\FRST\Quarantine\skype.dat" Results of screen317's Security Check version 0.99.59 Windows 7 Service Pack 1 x86 (UAC is disabled!) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` AntiVir Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 CCleaner Java(TM) 6 Update 25 Java version out of Date! Adobe Flash Player 11.6.602.168 Adobe Reader 10.1.5 Adobe Reader out of Date! Mozilla Firefox (19.0) Mozilla Thunderbird (17.0.3) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` | 
| Alle Zeitangaben in WEZ +1. Es ist jetzt 21:03 Uhr. | 
	Copyright ©2000-2025, Trojaner-Board