Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   [Probem] Windows XP: Nach dem "Willkommen"-Screen weißer Bildschirm - Taskmanager lässt sich NICHT öffnen (https://www.trojaner-board.de/138352-probem-windows-xp-willkommen-screen-weisser-bildschirm-taskmanager-laesst-oeffnen.html)

NeedFastHelp 17.07.2013 08:51

[Probem] Windows XP: Nach dem "Willkommen"-Screen weißer Bildschirm - Taskmanager lässt sich NICHT öffnen
 
Schönen guten Morgen,

nach gestrigem surfen im Internet wurde mein kompletter Bildschirm plötzlich weiß. Auch nach mehrmaligem Rebooten ließ sich nach dem Willkommen-Screen keine Aktion mehr durchführen. Ich habe mir in diesem Forum schon einige Threads diesbezüglich durchgelesen, jedoch finde ich keine passgenaue Lösung. Booten kann ich nur im abgesicherten Modus mit Eingabeaufforderung.

Mit freundlichen Grüßen,
NeedFastHelp

schrauber 17.07.2013 08:57

hi,

Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).



Das ganze dann im abgesicherten Modus mit EIngabeaufforderung machen.

NeedFastHelp 17.07.2013 09:34

Danke für die schnelle Antwort. Allerdings steht mir die Auswahlmöglichkeit "Computer reparieren" NICHT zur Verfügung. Ich habe also im abgesicherten Modus mit Eingabeaufforderung gestartet und dort gescannt. Hoffe, dass alles funktioniert hat.


FRST.txt

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2013
Ran by Administrator (administrator) on 17-07-2013 10:30:10
Running from G:\
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Safe Mode (minimal)

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13684736 2009-03-28] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - nwiz.exe /install [x]
HKLM\...\Run: [RTHDCPL] - RTHDCPL.EXE [x]
HKLM\...\Run: [SkyTel] - SkyTel.EXE [x]
HKLM\...\Run: [Alcmtr] - ALCMTR.EXE [x]
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [AVMWlanClient] - C:\Programme\avmwlanstick\wlangui.exe [1748992 2007-12-20] (AVM Berlin)
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [86016 2009-03-28] (NVIDIA Corporation)
HKLM\...\Run: [] -  [x]
HKLM\...\Run: [facemoods] - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodssrv.exe [329432 2011-04-14] (facemoods.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Programme\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x]
HKU\TEMP.USER-A6BFC21F50\...\Run: [H/PC Connection Agent] - "C:\Programme\Microsoft ActiveSync\Wcescomm.exe" [x]
HKU\TEMP.USER-A6BFC21F50\...\Run: [ICQ] - ~"C:\Programme\ICQ7.6\ICQ.exe" silent loginmode=4 [ 2011-10-10] (ICQ, LLC.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [Google Update] - "C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" /c [ 2011-09-28] (Google Inc.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [KiesHelper] - C:\Programme\Samsung\Kies\KiesHelper.exe /s [ 2011-11-29] (Samsung)
HKU\TEMP.USER-A6BFC21F50\...\Run: [KiesPDLR] - C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [ 2011-11-29] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [MSMSGS] - "C:\Programme\Messenger\msmsgs.exe" /background [ 2008-04-14] (Microsoft Corporation)
HKU\TEMP.USER-A6BFC21F50\...\Run: [IExplorer Util] - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\ie_util.exe [ 2013-02-11] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [Skype] - "C:\Programme\Skype\Phone\Skype.exe" /minimized /regrun [ 2013-04-19] (Skype Technologies S.A.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [Pando Media Booster] - C:\Programme\Pando Networks\Media Booster\PMB.exe [ 2013-05-08] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe [ 2013-07-16] (NVIDIA Corporation) <===== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin [ 2013-06-11] (Adobe Systems Incorporated)
HKU\TEMP.USER-A6BFC21F50\...\Winlogon: [Shell] cmd.exe [ 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Command Processor: "C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe" <===== ATTENTION!
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
HKLM SearchScopes: DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - DefaultScope value is missing.
BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programme\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Programme\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: ShopperReports - {100EB1FD-D03E-47fd-81F3-EE91287F9465} - C:\Programme\ShopperReports3\bin\3.0.517.0\ShopperReports.dll (SmartShopper Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
BHO: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Programme\facemoods.com\facemoods\1.4.17.8\bh\facemoods.dll (facemoods.com BHO)
BHO: No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Programme\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent)
BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (webHancer Corporation)
BHO: Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: ICQ Sparberater - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
Toolbar: HKLM - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
Toolbar: HKLM - No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
Toolbar: HKLM - Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
Toolbar: HKLM - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodsTlbr.dll (facemoods.com)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: ipp - No CLSID Value -
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog9 01 C:\WINDOWS\webhdll.dll [40960] (webHancer Corporation)
Winsock: Catalog9 02 C:\WINDOWS\webhdll.dll [40960] (webHancer Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

========================== Services (Whitelisted) =================

S2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [364544 2007-12-20] (AVM Berlin)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S2 ICQ Service; C:\Programme\ICQ6Toolbar\ICQ Service.exe [247608 2010-11-21] ()
S3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [820008 2010-11-17] (Apple Inc.)
S3 McComponentHostService; C:\Programme\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2006-06-01] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [115608 2013-04-10] (Mozilla Foundation)
S2 MyWebSearchService; C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe [28762 2011-03-25] (MyWebSearch.com)
S2 NAUpdate; C:\Programme\Nero\Update\NASvc.exe [690472 2011-07-22] (Nero AG)
S3 npggsvc; C:\WINDOWS\system32\GameMon.des [4023760 2010-12-01] (INCA Internet Co., Ltd.)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2006-06-01] (Microsoft Corporation)
S2 QuestBrowse Service; C:\Programme\QuestBrwSearch\questbrwsearch.dll [573440 2011-04-12] ()
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
S2 StealthInjectorService; C:\Programme\ArchiCrypt Stealth 4\IJStealth4Svc.exe [145920 2006-08-01] (Softwareentwicklung Remus)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-10-24] (Microsoft Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S2 JavaQuickStarterService; "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" [x]

==================== Drivers (Whitelisted) ====================

S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-12-20] (AVM Berlin)
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-12-20] (AVM GmbH)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
S3 NPPTNT2; C:\WINDOWS\system32\npptNT2.sys [4682 2004-12-30] (INCA Internet Co., Ltd.)
S3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [101504 2007-09-19] (Realtek Semiconductor Corporation                          )
R0 sfdrv01a; C:\Windows\System32\drivers\sfdrv01a.sys [63352 2006-07-05] (Protection Technology (StarForce))
R0 sfsync03; C:\Windows\System32\drivers\sfsync03.sys [35328 2005-12-06] (Protection Technology)
R0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [59776 2006-08-11] (Protection Technology (StarForce))
S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [33512 2012-11-08] (AnchorFree Inc)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
S3 cpuz134; \??\C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\cpuz134\cpuz134_x32.sys [x]
S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
S4 IntelIde; No ImagePath
S3 USBAAPL; System32\Drivers\usbaapl.sys [x]
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-17 10:26 - 2013-07-17 10:26 - 00000000 ____D C:\FRST
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-16 23:57 - 2013-07-17 10:22 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 10:22 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 08:54 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2013-07-16 23:57 - 00000000 __SHD C:\DOKUME~1\ADMINI~1.USE\LOKALE~1\Verlauf
2013-07-16 23:57 - 2008-12-19 11:25 - 00001599 _____ C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Remoteunterstützung.lnk
2013-07-16 23:57 - 2008-12-19 11:25 - 00000772 _____ C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Windows Media Player.lnk
2013-07-16 23:57 - 2008-12-19 11:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Zubehör
2013-07-16 23:57 - 2008-12-19 11:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Autostart
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:31 - 2013-07-11 03:32 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 01:44 - 2013-07-11 03:35 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 01:44 - 2013-07-11 03:34 - 00015045 _____ C:\WINDOWS\KB2845187.log

==================== One Month Modified Files and Folders =======

2013-07-17 10:26 - 2013-07-17 10:26 - 00000000 ____D C:\FRST
2013-07-17 10:22 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-17 10:22 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-17 10:22 - 2008-12-19 11:24 - 01663755 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-17 09:33 - 2011-09-15 21:33 - 00000190 ___SH C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\ntuser.ini
2013-07-17 09:33 - 2008-12-19 11:28 - 00032642 _____ C:\WINDOWS\SchedLgU.Txt
2013-07-17 09:33 - 2008-12-19 11:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-17 09:33 - 2008-12-19 11:19 - 00000216 _____ C:\WINDOWS\wiadebug.log
2013-07-17 09:33 - 2008-12-19 11:19 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-07-17 09:32 - 2011-01-02 21:04 - 00001082 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-16 23:57 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2013-07-16 23:57 - 00000000 __SHD C:\DOKUME~1\ADMINI~1.USE\LOKALE~1\Verlauf
2013-07-16 23:55 - 2006-02-28 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-16 23:49 - 2011-09-22 19:41 - 00000416 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{2D336ACC-32A6-4A94-B047-3074AA51D08C}.job
2013-07-16 23:47 - 2013-06-11 21:47 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-16 23:36 - 2011-09-15 19:58 - 00001238 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004UA.job
2013-07-16 23:24 - 2011-01-02 21:04 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-16 23:01 - 2011-08-28 03:23 - 00000224 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-07-16 04:36 - 2011-09-15 19:58 - 00001186 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004Core.job
2013-07-13 23:52 - 2008-12-19 12:46 - 00208477 _____ C:\WINDOWS\system32\nvapps.xml
2013-07-13 05:18 - 2008-12-19 11:17 - 00000000 ___RD C:\Programme
2013-07-13 04:40 - 2011-10-23 23:44 - 00002475 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\Google Chrome.lnk
2013-07-12 18:43 - 2012-12-09 19:10 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\router_reconnect
2013-07-12 18:43 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop
2013-07-11 22:57 - 2010-04-18 14:00 - 00000276 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-11 04:41 - 2008-12-19 11:16 - 00294072 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-11 04:21 - 2009-10-05 17:06 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:35 - 2013-07-11 01:44 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 03:35 - 2013-01-10 02:47 - 00194578 _____ C:\WINDOWS\setupapi.log
2013-07-11 03:35 - 2008-12-19 11:17 - 01921953 _____ C:\WINDOWS\FaxSetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00942003 _____ C:\WINDOWS\ocgen.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00741031 _____ C:\WINDOWS\tsoc.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00648976 _____ C:\WINDOWS\comsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00392944 _____ C:\WINDOWS\ntdtcsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00304236 _____ C:\WINDOWS\iis6.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00106837 _____ C:\WINDOWS\ocmsn.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00096795 _____ C:\WINDOWS\msgsocm.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:34 - 2013-07-11 01:44 - 00015045 _____ C:\WINDOWS\KB2845187.log
2013-07-11 03:34 - 2008-12-19 11:17 - 00006516 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-11 03:32 - 2013-07-11 03:31 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 03:32 - 2008-12-19 16:02 - 00260975 _____ C:\WINDOWS\updspapi.log
2013-07-11 03:31 - 2009-08-15 21:58 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-11 03:01 - 2009-10-05 17:08 - 00000000 ____D C:\WINDOWS\system32\XPSViewer

ZeroAccess:
C:\RECYCLER\S-1-5-21-1993962763-2139871995-839522115-1004\$25f41263902f988117359df6de529b62

ZeroAccess:
C:\RECYCLER\S-1-5-18\$25f41263902f988117359df6de529b62

Files to move or delete:
====================
C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\3094772.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2006-02-28 14:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e

C:\Windows\System32\winlogon.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a

C:\Windows\System32\svchost.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366

C:\Windows\System32\services.exe
[2006-02-28 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc

C:\Windows\System32\User32.dll
[2006-02-28 14:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd

C:\Windows\System32\userinit.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106

C:\Windows\System32\Drivers\volsnap.sys
[2006-02-28 14:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d


==================== End Of Log ============================

--- --- ---


Mit freundlichem Gruß,
NeedFastHelp

schrauber 17.07.2013 09:54

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\TEMP.USER-A6BFC21F50\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe [ 2013-07-16] (NVIDIA Corporation) <===== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Winlogon: [Shell] cmd.exe [ 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Command Processor: "C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe" <===== ATTENTION!
ZeroAccess:
C:\RECYCLER\S-1-5-21-1993962763-2139871995-839522115-1004\$25f41263902f988117359df6de529b62

ZeroAccess:
C:\RECYCLER\S-1-5-18\$25f41263902f988117359df6de529b62

C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\3094772.exe
C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\uvksvecwvfdbjoyti.exe

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.


neu booten, freuen :D

NeedFastHelp 17.07.2013 10:43

Problem besteht leider weiterhin.
FIXLOG:
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-07-2013
Ran by Administrator at 2013-07-17 11:38:32 Run:1
Running from G:\
Boot Mode: Safe Mode (minimal)

==============================================

HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value not found.
HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Command Processor\\AutoRun => Value not found.
C:\RECYCLER\S-1-5-21-1993962763-2139871995-839522115-1004\$25f41263902f988117359df6de529b62 => Moved successfully.
C:\RECYCLER\S-1-5-18\$25f41263902f988117359df6de529b62 => Deleted successfully.
C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\3094772.exe => Moved successfully.
"C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\uvksvecwvfdbjoyti.exe" => File/Directory not found.

==== End of Fixlog ====


schrauber 17.07.2013 11:54

Du willst mich verkacken?

Neues Scanlog bitte. Ich faile bei den Teilen normal nie :)

NeedFastHelp 17.07.2013 12:36

Scanlog:


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2013
Ran by Administrator (administrator) on 17-07-2013 13:32:38
Running from G:\
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Safe Mode (minimal)

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13684736 2009-03-28] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - nwiz.exe /install [x]
HKLM\...\Run: [RTHDCPL] - RTHDCPL.EXE [x]
HKLM\...\Run: [SkyTel] - SkyTel.EXE [x]
HKLM\...\Run: [Alcmtr] - ALCMTR.EXE [x]
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [AVMWlanClient] - C:\Programme\avmwlanstick\wlangui.exe [1748992 2007-12-20] (AVM Berlin)
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [86016 2009-03-28] (NVIDIA Corporation)
HKLM\...\Run: [] -  [x]
HKLM\...\Run: [facemoods] - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodssrv.exe [329432 2011-04-14] (facemoods.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Programme\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x]
HKU\TEMP.USER-A6BFC21F50\...\Run: [H/PC Connection Agent] - "C:\Programme\Microsoft ActiveSync\Wcescomm.exe" [x]
HKU\TEMP.USER-A6BFC21F50\...\Run: [ICQ] - ~"C:\Programme\ICQ7.6\ICQ.exe" silent loginmode=4 [ 2011-10-10] (ICQ, LLC.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [Google Update] - "C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" /c [ 2011-09-28] (Google Inc.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [KiesHelper] - C:\Programme\Samsung\Kies\KiesHelper.exe /s [ 2011-11-29] (Samsung)
HKU\TEMP.USER-A6BFC21F50\...\Run: [KiesPDLR] - C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [ 2011-11-29] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [MSMSGS] - "C:\Programme\Messenger\msmsgs.exe" /background [ 2008-04-14] (Microsoft Corporation)
HKU\TEMP.USER-A6BFC21F50\...\Run: [IExplorer Util] - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\ie_util.exe [ 2013-02-11] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [Skype] - "C:\Programme\Skype\Phone\Skype.exe" /minimized /regrun [ 2013-04-19] (Skype Technologies S.A.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [Pando Media Booster] - C:\Programme\Pando Networks\Media Booster\PMB.exe [ 2013-05-08] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe [ 2013-07-16] (NVIDIA Corporation) <===== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin [ 2013-06-11] (Adobe Systems Incorporated)
HKU\TEMP.USER-A6BFC21F50\...\Winlogon: [Shell] cmd.exe [ 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Command Processor: "C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe" <===== ATTENTION!
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
HKLM SearchScopes: DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - DefaultScope value is missing.
BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programme\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Programme\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: ShopperReports - {100EB1FD-D03E-47fd-81F3-EE91287F9465} - C:\Programme\ShopperReports3\bin\3.0.517.0\ShopperReports.dll (SmartShopper Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
BHO: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Programme\facemoods.com\facemoods\1.4.17.8\bh\facemoods.dll (facemoods.com BHO)
BHO: No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Programme\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent)
BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (webHancer Corporation)
BHO: Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: ICQ Sparberater - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
Toolbar: HKLM - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
Toolbar: HKLM - No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
Toolbar: HKLM - Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
Toolbar: HKLM - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodsTlbr.dll (facemoods.com)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: ipp - No CLSID Value -
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog9 01 C:\WINDOWS\webhdll.dll [40960] (webHancer Corporation)
Winsock: Catalog9 02 C:\WINDOWS\webhdll.dll [40960] (webHancer Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

========================== Services (Whitelisted) =================

S2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [364544 2007-12-20] (AVM Berlin)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S2 ICQ Service; C:\Programme\ICQ6Toolbar\ICQ Service.exe [247608 2010-11-21] ()
S3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [820008 2010-11-17] (Apple Inc.)
S3 McComponentHostService; C:\Programme\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2006-06-01] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [115608 2013-04-10] (Mozilla Foundation)
S2 MyWebSearchService; C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe [28762 2011-03-25] (MyWebSearch.com)
S2 NAUpdate; C:\Programme\Nero\Update\NASvc.exe [690472 2011-07-22] (Nero AG)
S3 npggsvc; C:\WINDOWS\system32\GameMon.des [4023760 2010-12-01] (INCA Internet Co., Ltd.)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2006-06-01] (Microsoft Corporation)
S2 QuestBrowse Service; C:\Programme\QuestBrwSearch\questbrwsearch.dll [573440 2011-04-12] ()
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
S2 StealthInjectorService; C:\Programme\ArchiCrypt Stealth 4\IJStealth4Svc.exe [145920 2006-08-01] (Softwareentwicklung Remus)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-10-24] (Microsoft Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S2 JavaQuickStarterService; "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" [x]

==================== Drivers (Whitelisted) ====================

S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-12-20] (AVM Berlin)
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-12-20] (AVM GmbH)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
S3 NPPTNT2; C:\WINDOWS\system32\npptNT2.sys [4682 2004-12-30] (INCA Internet Co., Ltd.)
S3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [101504 2007-09-19] (Realtek Semiconductor Corporation                          )
R0 sfdrv01a; C:\Windows\System32\drivers\sfdrv01a.sys [63352 2006-07-05] (Protection Technology (StarForce))
R0 sfsync03; C:\Windows\System32\drivers\sfsync03.sys [35328 2005-12-06] (Protection Technology)
R0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [59776 2006-08-11] (Protection Technology (StarForce))
S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [33512 2012-11-08] (AnchorFree Inc)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
S3 cpuz134; \??\C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\cpuz134\cpuz134_x32.sys [x]
S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
S4 IntelIde; No ImagePath
S3 USBAAPL; System32\Drivers\usbaapl.sys [x]
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-17 10:26 - 2013-07-17 11:38 - 00000000 ____D C:\FRST
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-16 23:57 - 2013-07-17 11:39 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 11:39 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 08:54 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2013-07-16 23:57 - 00000000 __SHD C:\DOKUME~1\ADMINI~1.USE\LOKALE~1\Verlauf
2013-07-16 23:57 - 2008-12-19 11:25 - 00001599 _____ C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Remoteunterstützung.lnk
2013-07-16 23:57 - 2008-12-19 11:25 - 00000772 _____ C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Windows Media Player.lnk
2013-07-16 23:57 - 2008-12-19 11:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Zubehör
2013-07-16 23:57 - 2008-12-19 11:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Autostart
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:31 - 2013-07-11 03:32 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 01:44 - 2013-07-11 03:35 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 01:44 - 2013-07-11 03:34 - 00015045 _____ C:\WINDOWS\KB2845187.log

==================== One Month Modified Files and Folders =======

2013-07-17 11:42 - 2011-09-15 21:33 - 00000190 ___SH C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\ntuser.ini
2013-07-17 11:42 - 2008-12-19 11:28 - 00032642 _____ C:\WINDOWS\SchedLgU.Txt
2013-07-17 11:42 - 2008-12-19 11:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-17 11:42 - 2008-12-19 11:24 - 01664901 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-17 11:42 - 2008-12-19 11:19 - 00000216 _____ C:\WINDOWS\wiadebug.log
2013-07-17 11:42 - 2008-12-19 11:19 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-07-17 11:40 - 2011-01-02 21:04 - 00001082 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-17 11:39 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-17 11:39 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-17 11:38 - 2013-07-17 10:26 - 00000000 ____D C:\FRST
2013-07-17 11:38 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-16 23:57 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2013-07-16 23:57 - 00000000 __SHD C:\DOKUME~1\ADMINI~1.USE\LOKALE~1\Verlauf
2013-07-16 23:55 - 2006-02-28 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-16 23:49 - 2011-09-22 19:41 - 00000416 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{2D336ACC-32A6-4A94-B047-3074AA51D08C}.job
2013-07-16 23:47 - 2013-06-11 21:47 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-16 23:36 - 2011-09-15 19:58 - 00001238 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004UA.job
2013-07-16 23:24 - 2011-01-02 21:04 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-16 23:01 - 2011-08-28 03:23 - 00000224 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-07-16 04:36 - 2011-09-15 19:58 - 00001186 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004Core.job
2013-07-13 23:52 - 2008-12-19 12:46 - 00208477 _____ C:\WINDOWS\system32\nvapps.xml
2013-07-13 05:18 - 2008-12-19 11:17 - 00000000 ___RD C:\Programme
2013-07-13 04:40 - 2011-10-23 23:44 - 00002475 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\Google Chrome.lnk
2013-07-12 18:43 - 2012-12-09 19:10 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\router_reconnect
2013-07-12 18:43 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop
2013-07-11 22:57 - 2010-04-18 14:00 - 00000276 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-11 04:41 - 2008-12-19 11:16 - 00294072 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-11 04:21 - 2009-10-05 17:06 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:35 - 2013-07-11 01:44 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 03:35 - 2013-01-10 02:47 - 00194578 _____ C:\WINDOWS\setupapi.log
2013-07-11 03:35 - 2008-12-19 11:17 - 01921953 _____ C:\WINDOWS\FaxSetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00942003 _____ C:\WINDOWS\ocgen.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00741031 _____ C:\WINDOWS\tsoc.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00648976 _____ C:\WINDOWS\comsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00392944 _____ C:\WINDOWS\ntdtcsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00304236 _____ C:\WINDOWS\iis6.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00106837 _____ C:\WINDOWS\ocmsn.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00096795 _____ C:\WINDOWS\msgsocm.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:34 - 2013-07-11 01:44 - 00015045 _____ C:\WINDOWS\KB2845187.log
2013-07-11 03:34 - 2008-12-19 11:17 - 00006516 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-11 03:32 - 2013-07-11 03:31 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 03:32 - 2008-12-19 16:02 - 00260975 _____ C:\WINDOWS\updspapi.log
2013-07-11 03:31 - 2009-08-15 21:58 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-11 03:01 - 2009-10-05 17:08 - 00000000 ____D C:\WINDOWS\system32\XPSViewer

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2006-02-28 14:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e

C:\Windows\System32\winlogon.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a

C:\Windows\System32\svchost.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366

C:\Windows\System32\services.exe
[2006-02-28 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc

C:\Windows\System32\User32.dll
[2006-02-28 14:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd

C:\Windows\System32\userinit.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106

C:\Windows\System32\Drivers\volsnap.sys
[2006-02-28 14:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d


==================== End Of Log ============================

--- --- ---

schrauber 17.07.2013 13:04

Aah, ich hab gar nit gefailed, das war FRST das aus irgendeinem Grund nit fixen kann. Next try:

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\TEMP.USER-A6BFC21F50\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe [ 2013-07-16] (NVIDIA Corporation) <===== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Winlogon: [Shell] cmd.exe [ 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Command Processor: "C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe" <===== ATTENTION!
C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

NeedFastHelp 17.07.2013 16:43

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-07-2013
Ran by Administrator at 2013-07-17 17:40:30 Run:3
Running from G:\
Boot Mode: Safe Mode (minimal)

==============================================

HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value not found.
HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Command Processor\\AutoRun => Value not found.
C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe => Moved successfully.

==== End of Fixlog ====

Nach erneutem Reboot sehe ich meinen Desktophintergrund mit offenem cmd.exe: "Der Befehl 'C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe' ist entweder falsch geschrieben oder konnte nicht gefunden werden." Wenn ich das cmd schließe sehe ich allerdings nur meinen Hintergrund, d.h. ohne Startleiste und Icons. Der Task Manager lässt sich auch wieder per Tastenkombination öffnen.

Bis dahin schonmal vielen Dank und schönen Gruß,
NeedFastHelp

schrauber 18.07.2013 07:20

Öffne taskmanager und Datei > Neuer task > explorer.exe und enter.

kommt der Desktop?

NeedFastHelp 18.07.2013 12:30

Wenn ich explorer.exe öffnen möchte, wird der Bildschirm wieder weiß.

Gruß,
NeedFastHelp

schrauber 18.07.2013 12:45

Dann bitte nochmal ein frisches FRST Scanlog.

NeedFastHelp 18.07.2013 13:45


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2013
Ran by Administrator (administrator) on 18-07-2013 14:42:20
Running from G:\
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Safe Mode (minimal)

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13684736 2009-03-28] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - nwiz.exe /install [x]
HKLM\...\Run: [RTHDCPL] - RTHDCPL.EXE [x]
HKLM\...\Run: [SkyTel] - SkyTel.EXE [x]
HKLM\...\Run: [Alcmtr] - ALCMTR.EXE [x]
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [AVMWlanClient] - C:\Programme\avmwlanstick\wlangui.exe [1748992 2007-12-20] (AVM Berlin)
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [86016 2009-03-28] (NVIDIA Corporation)
HKLM\...\Run: [] -  [x]
HKLM\...\Run: [facemoods] - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodssrv.exe [329432 2011-04-14] (facemoods.com)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Programme\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x]
HKU\TEMP.USER-A6BFC21F50\...\Run: [H/PC Connection Agent] - "C:\Programme\Microsoft ActiveSync\Wcescomm.exe" [x]
HKU\TEMP.USER-A6BFC21F50\...\Run: [ICQ] - ~"C:\Programme\ICQ7.6\ICQ.exe" silent loginmode=4 [ 2011-10-10] (ICQ, LLC.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [Google Update] - "C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" /c [ 2011-09-28] (Google Inc.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [KiesHelper] - C:\Programme\Samsung\Kies\KiesHelper.exe /s [ 2011-11-29] (Samsung)
HKU\TEMP.USER-A6BFC21F50\...\Run: [KiesPDLR] - C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [ 2011-11-29] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [MSMSGS] - "C:\Programme\Messenger\msmsgs.exe" /background [ 2008-04-14] (Microsoft Corporation)
HKU\TEMP.USER-A6BFC21F50\...\Run: [IExplorer Util] - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\ie_util.exe [ 2013-02-11] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [Skype] - "C:\Programme\Skype\Phone\Skype.exe" /minimized /regrun [ 2013-04-19] (Skype Technologies S.A.)
HKU\TEMP.USER-A6BFC21F50\...\Run: [Pando Media Booster] - C:\Programme\Pando Networks\Media Booster\PMB.exe [ 2013-05-08] ()
HKU\TEMP.USER-A6BFC21F50\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe [x] <===== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin [ 2013-06-11] (Adobe Systems Incorporated)
HKU\TEMP.USER-A6BFC21F50\...\Winlogon: [Shell] cmd.exe [ 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Command Processor: "C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe" <===== ATTENTION!
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
HKLM SearchScopes: DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - DefaultScope value is missing.
BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programme\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Programme\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: ShopperReports - {100EB1FD-D03E-47fd-81F3-EE91287F9465} - C:\Programme\ShopperReports3\bin\3.0.517.0\ShopperReports.dll (SmartShopper Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
BHO: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Programme\facemoods.com\facemoods\1.4.17.8\bh\facemoods.dll (facemoods.com BHO)
BHO: No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Programme\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent)
BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (webHancer Corporation)
BHO: Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: ICQ Sparberater - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
Toolbar: HKLM - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
Toolbar: HKLM - No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
Toolbar: HKLM - Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
Toolbar: HKLM - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodsTlbr.dll (facemoods.com)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: ipp - No CLSID Value -
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog9 01 C:\WINDOWS\webhdll.dll [40960] (webHancer Corporation)
Winsock: Catalog9 02 C:\WINDOWS\webhdll.dll [40960] (webHancer Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

========================== Services (Whitelisted) =================

S2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [364544 2007-12-20] (AVM Berlin)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S2 ICQ Service; C:\Programme\ICQ6Toolbar\ICQ Service.exe [247608 2010-11-21] ()
S3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [820008 2010-11-17] (Apple Inc.)
S3 McComponentHostService; C:\Programme\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2006-06-01] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [115608 2013-04-10] (Mozilla Foundation)
S2 MyWebSearchService; C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe [28762 2011-03-25] (MyWebSearch.com)
S2 NAUpdate; C:\Programme\Nero\Update\NASvc.exe [690472 2011-07-22] (Nero AG)
S3 npggsvc; C:\WINDOWS\system32\GameMon.des [4023760 2010-12-01] (INCA Internet Co., Ltd.)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2006-06-01] (Microsoft Corporation)
S2 QuestBrowse Service; C:\Programme\QuestBrwSearch\questbrwsearch.dll [573440 2011-04-12] ()
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
S2 StealthInjectorService; C:\Programme\ArchiCrypt Stealth 4\IJStealth4Svc.exe [145920 2006-08-01] (Softwareentwicklung Remus)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-10-24] (Microsoft Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
S2 JavaQuickStarterService; "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" [x]

==================== Drivers (Whitelisted) ====================

S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-12-20] (AVM Berlin)
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-12-20] (AVM GmbH)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
S3 NPPTNT2; C:\WINDOWS\system32\npptNT2.sys [4682 2004-12-30] (INCA Internet Co., Ltd.)
S3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [101504 2007-09-19] (Realtek Semiconductor Corporation                          )
R0 sfdrv01a; C:\Windows\System32\drivers\sfdrv01a.sys [63352 2006-07-05] (Protection Technology (StarForce))
R0 sfsync03; C:\Windows\System32\drivers\sfsync03.sys [35328 2005-12-06] (Protection Technology)
R0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [59776 2006-08-11] (Protection Technology (StarForce))
S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [33512 2012-11-08] (AnchorFree Inc)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
S3 cpuz134; \??\C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\cpuz134\cpuz134_x32.sys [x]
S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
S4 IntelIde; No ImagePath
S3 USBAAPL; System32\Drivers\usbaapl.sys [x]
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-17 10:26 - 2013-07-17 11:38 - 00000000 ____D C:\FRST
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-16 23:57 - 2013-07-17 17:41 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 17:41 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 08:54 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2013-07-16 23:57 - 00000000 __SHD C:\DOKUME~1\ADMINI~1.USE\LOKALE~1\Verlauf
2013-07-16 23:57 - 2008-12-19 11:25 - 00001599 _____ C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Remoteunterstützung.lnk
2013-07-16 23:57 - 2008-12-19 11:25 - 00000772 _____ C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Windows Media Player.lnk
2013-07-16 23:57 - 2008-12-19 11:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Zubehör
2013-07-16 23:57 - 2008-12-19 11:25 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü\Programme\Autostart
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:31 - 2013-07-11 03:32 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 01:44 - 2013-07-11 03:35 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 01:44 - 2013-07-11 03:34 - 00015045 _____ C:\WINDOWS\KB2845187.log

==================== One Month Modified Files and Folders =======

2013-07-18 13:29 - 2011-09-15 21:33 - 00000190 ___SH C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\ntuser.ini
2013-07-18 13:29 - 2008-12-19 11:28 - 00032642 _____ C:\WINDOWS\SchedLgU.Txt
2013-07-18 13:29 - 2008-12-19 11:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-18 13:29 - 2008-12-19 11:24 - 01667193 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-18 13:29 - 2008-12-19 11:19 - 00000216 _____ C:\WINDOWS\wiadebug.log
2013-07-18 13:29 - 2008-12-19 11:19 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-07-18 13:28 - 2011-01-02 21:04 - 00001082 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-17 17:49 - 2011-09-22 19:41 - 00000416 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{2D336ACC-32A6-4A94-B047-3074AA51D08C}.job
2013-07-17 17:47 - 2013-06-11 21:47 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-17 17:41 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-17 17:41 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-17 11:38 - 2013-07-17 10:26 - 00000000 ____D C:\FRST
2013-07-17 11:38 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-16 23:57 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2013-07-16 23:57 - 00000000 __SHD C:\DOKUME~1\ADMINI~1.USE\LOKALE~1\Verlauf
2013-07-16 23:55 - 2006-02-28 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-16 23:36 - 2011-09-15 19:58 - 00001238 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004UA.job
2013-07-16 23:24 - 2011-01-02 21:04 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-16 23:01 - 2011-08-28 03:23 - 00000224 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-07-16 04:36 - 2011-09-15 19:58 - 00001186 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004Core.job
2013-07-13 23:52 - 2008-12-19 12:46 - 00208477 _____ C:\WINDOWS\system32\nvapps.xml
2013-07-13 05:18 - 2008-12-19 11:17 - 00000000 ___RD C:\Programme
2013-07-13 04:40 - 2011-10-23 23:44 - 00002475 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\Google Chrome.lnk
2013-07-12 18:43 - 2012-12-09 19:10 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\router_reconnect
2013-07-12 18:43 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop
2013-07-11 22:57 - 2010-04-18 14:00 - 00000276 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-11 04:41 - 2008-12-19 11:16 - 00294072 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-11 04:21 - 2009-10-05 17:06 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:35 - 2013-07-11 01:44 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 03:35 - 2013-01-10 02:47 - 00194578 _____ C:\WINDOWS\setupapi.log
2013-07-11 03:35 - 2008-12-19 11:17 - 01921953 _____ C:\WINDOWS\FaxSetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00942003 _____ C:\WINDOWS\ocgen.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00741031 _____ C:\WINDOWS\tsoc.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00648976 _____ C:\WINDOWS\comsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00392944 _____ C:\WINDOWS\ntdtcsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00304236 _____ C:\WINDOWS\iis6.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00106837 _____ C:\WINDOWS\ocmsn.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00096795 _____ C:\WINDOWS\msgsocm.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:34 - 2013-07-11 01:44 - 00015045 _____ C:\WINDOWS\KB2845187.log
2013-07-11 03:34 - 2008-12-19 11:17 - 00006516 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-11 03:32 - 2013-07-11 03:31 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 03:32 - 2008-12-19 16:02 - 00260975 _____ C:\WINDOWS\updspapi.log
2013-07-11 03:31 - 2009-08-15 21:58 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-11 03:01 - 2009-10-05 17:08 - 00000000 ____D C:\WINDOWS\system32\XPSViewer

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2006-02-28 14:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e

C:\Windows\System32\winlogon.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a

C:\Windows\System32\svchost.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366

C:\Windows\System32\services.exe
[2006-02-28 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc

C:\Windows\System32\User32.dll
[2006-02-28 14:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd

C:\Windows\System32\userinit.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106

C:\Windows\System32\Drivers\volsnap.sys
[2006-02-28 14:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d


==================== End Of Log ============================

--- --- ---

schrauber 18.07.2013 13:52

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\TEMP.USER-A6BFC21F50\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe [x] <===== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Winlogon: [Shell] cmd.exe [ 2008-04-14] (Microsoft Corporation) <==== ATTENTION
HKU\TEMP.USER-A6BFC21F50\...\Command Processor: "C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\uvksvecwvfdbjoyti.exe" <===== ATTENTION!

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

NeedFastHelp 18.07.2013 14:03

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-07-2013
Ran by Administrator at 2013-07-18 15:02:07 Run:4
Running from G:\
Boot Mode: Safe Mode (minimal)

==============================================

HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value not found.
HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
HKU\TEMP.USER-A6BFC21F50\Software\Microsoft\Command Processor\\AutoRun => Value not found.

==== End of Fixlog ====



Alle Zeitangaben in WEZ +1. Es ist jetzt 14:00 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55