Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   NTRedirect BABSolution (https://www.trojaner-board.de/138796-ntredirect-babsolution.html)

daslicht 27.07.2013 12:37

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-07-2013
Ran by uwe (administrator) on 27-07-2013 11:38:26
Running from C:\Users\uwe\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(CrossLoop) C:\Users\uwe\AppData\Local\CrossLoop\CrossLoopService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
() C:\Windows\Samsung\PanelMgr\caller64.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe

==================== Registry (Whitelisted) ==================

HKCU\...\Run: [NTRedirect] - C:\Windows\SysWOW64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation) <===== ATTENTION
HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [606208 2009-12-09] ()
HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKU\Default\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
StartMenuInternet: IEXPLORE.EXE - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {E034DA88-FABA-480E-A52B-17FAE15365ED} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADRA_de
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIC30F~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: ipp - No CLSID Value -
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIC30F~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIC30F~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: ftd - C:\Users\uwe\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi
FF Extension: gophoto - C:\Users\uwe\AppData\Roaming\Mozilla\Firefox\profiles\extensions\gophoto@gophoto.it.xpi
FF Extension: trtv3 - C:\Users\uwe\AppData\Roaming\Mozilla\Firefox\profiles\extensions\trtv3@trtv.com.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{DEDAF650-12B8-48f5-A843-BBA100716106}] C:\Program Files\Updater By Sweetpacks\Firefox

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2011-09-29] (Adobe Systems)
R2 CrossLoopService; C:\Users\uwe\AppData\Local\CrossLoop\CrossLoopService.exe [569072 2012-01-06] (CrossLoop)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
S3 tvnserver; C:\Users\uwe\AppData\Local\CrossLoop\tvnserver.exe [814080 2010-07-21] (GlavSoft LLC.)

==================== Drivers (Whitelisted) ====================

S3 bdfsfltr; C:\Windows\System32\DRIVERS\bdfsfltr.sys [442088 2011-08-16] (BitDefender)
R3 evserial; C:\Windows\System32\DRIVERS\evserial.sys [68608 2009-06-23] (ELTIMA Software)
R3 evserial7; C:\Windows\System32\DRIVERS\evserial7.sys [69704 2010-07-15] (ELTIMA Software)
R3 flex1500; C:\Windows\System32\drivers\flex1500.sys [265312 2012-11-29] (Jungo)
S3 FlexRadio; C:\Windows\System32\Drivers\FlexRadio.sys [211536 2013-04-04] (FlexRadio Systems)
S3 FlexRadioAudio; C:\Windows\System32\drivers\FlexRadioAudio.sys [48336 2013-04-04] (FlexRadio Systems)
S3 FlexRadioMidi; C:\Windows\System32\drivers\FlexRadioMidi.sys [35408 2013-04-04] (FlexRadio Systems)
R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2011-04-07] (Highresolution Enterprises [www.highrez.co.uk])
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [329800 2011-10-27] (BitDefender S.R.L.)
R3 VSBC; C:\Windows\System32\DRIVERS\evsbc.sys [34816 2009-06-23] (ELTIMA Software)
R3 VSBC7; C:\Windows\System32\DRIVERS\evsbc7.sys [35912 2010-07-15] (ELTIMA Software)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2010-08-31] (Jungo)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x]
S3 MSICDSetup; \??\D:\CDriver64.sys [x]
S2 TVicPort; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-27 11:38 - 2013-07-27 11:38 - 01780407 _____ (Farbar) C:\Users\uwe\Downloads\FRST64.exe
2013-07-27 11:36 - 2013-07-27 11:36 - 00199458 _____ C:\Users\uwe\Desktop\JRT.txt
2013-07-27 11:34 - 2013-07-27 11:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-27 11:33 - 2013-07-27 11:33 - 00000951 _____ C:\AdwCleaner[R2].txt
2013-07-27 11:32 - 2013-07-27 11:32 - 00031541 _____ C:\AdwCleaner[S1].txt
2013-07-27 11:30 - 2013-07-27 11:30 - 00032688 _____ C:\AdwCleaner[R1].txt
2013-07-27 11:30 - 2013-07-27 11:30 - 00000000 ____D C:\Users\uwe\Desktop\TROJAN
2013-07-26 15:40 - 2013-07-26 15:40 - 00023339 _____ C:\ComboFix.txt
2013-07-26 15:22 - 2013-07-26 15:40 - 00000000 ____D C:\Qoobox
2013-07-26 15:22 - 2013-07-26 15:28 - 00000000 ____D C:\Windows\erdnt
2013-07-26 15:22 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-26 15:22 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-26 15:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-26 15:21 - 2013-07-25 19:00 - 05093969 ____R (Swearware) C:\Users\uwe\Desktop\ComboFix.exe
2013-07-26 12:11 - 2013-07-26 12:24 - 00046869 _____ C:\Users\uwe\Desktop\FRST.txt
2013-07-26 12:11 - 2013-07-26 12:11 - 00023334 _____ C:\Users\uwe\Desktop\Addition.txt
2013-07-26 12:10 - 2013-07-26 12:10 - 00000000 ____D C:\FRST
2013-07-26 12:10 - 2013-07-25 23:16 - 01779853 _____ (Farbar) C:\Users\uwe\Desktop\FRST64.exe
2013-07-26 11:50 - 2013-07-26 11:57 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-26 11:49 - 2013-07-26 11:57 - 00000000 ____D C:\Users\uwe\Desktop\mbar
2013-07-26 11:49 - 2013-07-26 11:49 - 13399154 _____ C:\Users\uwe\Downloads\mbar-1.06.0.1004.zip
2013-07-26 11:09 - 2013-07-26 11:09 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2 (1).crx
2013-07-26 11:07 - 2013-07-26 11:08 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2.crx
2013-07-26 09:42 - 2013-07-26 09:42 - 00003376 _____ C:\Windows\System32\Tasks\EPUpdater
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-07-19 19:07 - 2013-07-19 19:08 - 00000000 ____D C:\Windows\system32\MRT
2013-07-17 09:46 - 2013-07-17 09:46 - 00000000 ____D C:\Users\uwe\AppData\Local\Cool_Mirage
2013-07-16 11:27 - 2013-07-16 11:27 - 01067456 _____ (Solid State Networks) C:\Users\uwe\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe
2013-07-16 10:52 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-16 10:52 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-16 10:52 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-16 10:52 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-16 10:52 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-16 10:52 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-16 10:52 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-16 10:52 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-16 10:52 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-15 19:58 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-15 19:58 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-15 19:57 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-15 19:57 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-15 19:57 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-15 19:57 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-15 19:55 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-09 09:18 - 2013-07-27 11:33 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-09 09:18 - 2013-07-27 11:28 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-09 09:18 - 2013-07-16 10:23 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-09 09:18 - 2013-07-16 10:23 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Roaming\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Local\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\ProgramData\www.rene-zeidler.de
2013-07-08 19:58 - 2013-07-08 19:58 - 00090624 _____ (Eugene V. Muzychenko) C:\Windows\system32\Drivers\vrtaucbl.sys
2013-07-08 19:57 - 2013-07-27 11:33 - 00004023 _____ C:\Windows\setupact.log
2013-07-08 19:57 - 2013-07-26 18:20 - 00011526 _____ C:\Windows\PFRO.log
2013-07-08 19:57 - 2013-07-08 19:57 - 00000000 _____ C:\Windows\setuperr.log
2013-07-08 19:50 - 2013-07-08 19:50 - 29403457 _____ (SRWare                                                      ) C:\Users\uwe\Downloads\srware_iron.exe
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Users\uwe\AppData\Local\Chromium
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Program Files (x86)\SRWare Iron
2013-07-08 19:21 - 2013-07-08 19:21 - 00617312 _____ (www.download-sponsor.de) C:\Users\uwe\Downloads\CCleaner 4.01.4093.exe
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Users\uwe\AppData\Roaming\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-08 19:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-08 18:54 - 2013-07-08 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 12:29 - 2013-07-02 12:29 - 00000000 ____D C:\Program Files (x86)\NOXON Media
2013-07-02 12:27 - 2013-07-02 12:27 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-07-02 12:25 - 2012-03-01 13:24 - 00225152 _____ (REALTEK SEMICONDUCTOR Corp.) C:\Windows\system32\Drivers\RTL2832UBDA.sys
2013-07-02 12:25 - 2012-03-01 13:24 - 00045056 _____ (Realtek) C:\Windows\system32\Drivers\RTL2832U_IRHID.sys
2013-07-02 12:25 - 2012-03-01 13:24 - 00039680 _____ (REALTEK SEMICONDUCTOR Corp.) C:\Windows\system32\Drivers\RTL2832UUSB.sys
2013-07-01 15:22 - 2013-07-01 15:22 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fldigi
2013-06-29 13:57 - 2013-06-29 13:57 - 00000306 __RSH C:\Users\uwe\ntuser.pol
2013-06-29 11:54 - 2013-06-29 11:54 - 00279379 _____ C:\Users\uwe\Downloads\VirtualAudioCable409.zip
2013-06-29 11:39 - 2013-06-29 11:39 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2013-06-28 17:22 - 2013-06-28 17:22 - 00421109 _____ C:\Users\uwe\Downloads\ASIO4ALL_2_11_Beta2_English(1).exe
2013-06-28 16:40 - 2013-06-29 11:36 - 00000000 ____D C:\Program Files (x86)\ASIO4ALL v2
2013-06-28 16:39 - 2013-06-28 16:39 - 00421109 _____ C:\Users\uwe\Downloads\ASIO4ALL_2_11_Beta2_English.exe
2013-06-28 16:39 - 2013-06-28 16:39 - 00420251 _____ C:\Users\uwe\Downloads\ASIO4ALL_2_10_Deutsch.exe
2013-06-28 16:36 - 2013-07-08 19:58 - 00000000 ____D C:\Program Files\Virtual Audio Cable
2013-06-28 15:51 - 2013-06-28 15:51 - 01117976 _____ C:\Users\uwe\Downloads\virtual audio cable setup(1).exe
2013-06-28 15:50 - 2013-06-28 15:50 - 01117976 _____ C:\Users\uwe\Downloads\virtual audio cable setup.exe
2013-06-28 10:26 - 2013-06-28 10:26 - 01459426 _____ C:\Users\uwe\Downloads\rf
2013-06-27 12:28 - 2013-07-16 11:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-06-27 12:28 - 2013-07-16 11:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-06-27 10:14 - 2013-06-27 10:14 - 00000000 ____D C:\ProgramData\MixW
2013-06-27 10:13 - 2013-06-27 10:13 - 08088182 _____ C:\Users\uwe\Downloads\MixW3_1_1h.exe

==================== One Month Modified Files and Folders =======

2013-07-27 11:38 - 2013-07-27 11:38 - 01780407 _____ (Farbar) C:\Users\uwe\Downloads\FRST64.exe
2013-07-27 11:37 - 2010-11-21 08:50 - 00696832 _____ C:\Windows\system32\perfh007.dat
2013-07-27 11:37 - 2010-11-21 08:50 - 00148128 _____ C:\Windows\system32\perfc007.dat
2013-07-27 11:37 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-27 11:36 - 2013-07-27 11:36 - 00199458 _____ C:\Users\uwe\Desktop\JRT.txt
2013-07-27 11:34 - 2013-07-27 11:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-27 11:33 - 2013-07-27 11:33 - 00000951 _____ C:\AdwCleaner[R2].txt
2013-07-27 11:33 - 2013-07-09 09:18 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-27 11:33 - 2013-07-08 19:57 - 00004023 _____ C:\Windows\setupact.log
2013-07-27 11:33 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-27 11:32 - 2013-07-27 11:32 - 00031541 _____ C:\AdwCleaner[S1].txt
2013-07-27 11:32 - 2011-02-20 05:07 - 00000991 _____ C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-27 11:32 - 2011-02-20 05:06 - 01593096 _____ C:\Windows\WindowsUpdate.log
2013-07-27 11:30 - 2013-07-27 11:30 - 00032688 _____ C:\AdwCleaner[R1].txt
2013-07-27 11:30 - 2013-07-27 11:30 - 00000000 ____D C:\Users\uwe\Desktop\TROJAN
2013-07-27 11:30 - 2009-07-14 06:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-27 11:30 - 2009-07-14 06:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-27 11:28 - 2013-07-09 09:18 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-26 18:20 - 2013-07-08 19:57 - 00011526 _____ C:\Windows\PFRO.log
2013-07-26 15:40 - 2013-07-26 15:40 - 00023339 _____ C:\ComboFix.txt
2013-07-26 15:40 - 2013-07-26 15:22 - 00000000 ____D C:\Qoobox
2013-07-26 15:39 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-07-26 15:28 - 2013-07-26 15:22 - 00000000 ____D C:\Windows\erdnt
2013-07-26 15:27 - 2009-07-14 04:34 - 81264640 _____ C:\Windows\system32\config\software.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 44040192 _____ C:\Windows\system32\config\components.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 18087936 _____ C:\Windows\system32\config\system.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 02883584 _____ C:\Windows\system32\config\default.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-07-26 15:24 - 2011-02-20 06:08 - 00001912 _____ C:\Windows\epplauncher.mif
2013-07-26 12:24 - 2013-07-26 12:11 - 00046869 _____ C:\Users\uwe\Desktop\FRST.txt
2013-07-26 12:11 - 2013-07-26 12:11 - 00023334 _____ C:\Users\uwe\Desktop\Addition.txt
2013-07-26 12:10 - 2013-07-26 12:10 - 00000000 ____D C:\FRST
2013-07-26 11:57 - 2013-07-26 11:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-26 11:57 - 2013-07-26 11:49 - 00000000 ____D C:\Users\uwe\Desktop\mbar
2013-07-26 11:49 - 2013-07-26 11:49 - 13399154 _____ C:\Users\uwe\Downloads\mbar-1.06.0.1004.zip
2013-07-26 11:09 - 2013-07-26 11:09 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2 (1).crx
2013-07-26 11:08 - 2013-07-26 11:07 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2.crx
2013-07-26 09:42 - 2013-07-26 09:42 - 00003376 _____ C:\Windows\System32\Tasks\EPUpdater
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-07-26 09:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-25 23:16 - 2013-07-26 12:10 - 01779853 _____ (Farbar) C:\Users\uwe\Desktop\FRST64.exe
2013-07-25 19:00 - 2013-07-26 15:21 - 05093969 ____R (Swearware) C:\Users\uwe\Desktop\ComboFix.exe
2013-07-19 19:08 - 2013-07-19 19:07 - 00000000 ____D C:\Windows\system32\MRT
2013-07-17 12:48 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-07-17 09:46 - 2013-07-17 09:46 - 00000000 ____D C:\Users\uwe\AppData\Local\Cool_Mirage
2013-07-17 09:46 - 2011-02-20 00:03 - 00420944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2013-07-17 09:46 - 2011-02-19 01:40 - 00773712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2013-07-16 11:27 - 2013-07-16 11:27 - 01067456 _____ (Solid State Networks) C:\Users\uwe\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe
2013-07-16 11:27 - 2013-06-27 12:28 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-16 11:27 - 2013-06-27 12:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-16 11:27 - 2011-02-20 05:02 - 00000000 ____D C:\Windows\Panther
2013-07-16 10:23 - 2013-07-09 09:18 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-16 10:23 - 2013-07-09 09:18 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-16 09:40 - 2009-07-14 06:45 - 00451056 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-16 09:39 - 2010-11-21 09:00 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-16 09:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-16 09:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-15 20:08 - 2013-05-30 10:59 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-08 20:18 - 2011-02-20 05:07 - 00000000 ____D C:\Users\uwe\AppData\Local\VirtualStore
2013-07-08 20:07 - 2011-02-20 05:06 - 00000000 ___RD C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Roaming\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Local\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\ProgramData\www.rene-zeidler.de
2013-07-08 19:58 - 2013-07-08 19:58 - 00090624 _____ (Eugene V. Muzychenko) C:\Windows\system32\Drivers\vrtaucbl.sys
2013-07-08 19:58 - 2013-06-28 16:36 - 00000000 ____D C:\Program Files\Virtual Audio Cable
2013-07-08 19:57 - 2013-07-08 19:57 - 00000000 _____ C:\Windows\setuperr.log
2013-07-08 19:54 - 2011-02-20 06:07 - 01590298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-07-08 19:50 - 2013-07-08 19:50 - 29403457 _____ (SRWare                                                      ) C:\Users\uwe\Downloads\srware_iron.exe
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Users\uwe\AppData\Local\Chromium
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Program Files (x86)\SRWare Iron
2013-07-08 19:45 - 2011-03-21 14:13 - 00000000 ____D C:\Users\uwe\AppData\Local\Google
2013-07-08 19:44 - 2013-07-08 18:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-08 19:44 - 2012-04-23 19:40 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Mozilla
2013-07-08 19:30 - 2013-04-26 12:23 - 00000000 ____D C:\Users\uwe\AppData\Roaming\FileZilla
2013-07-08 19:29 - 2013-02-13 17:01 - 00000000 ____D C:\Program Files\CCleaner
2013-07-08 19:21 - 2013-07-08 19:21 - 00617312 _____ (www.download-sponsor.de) C:\Users\uwe\Downloads\CCleaner 4.01.4093.exe
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Users\uwe\AppData\Roaming\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-08 18:51 - 2011-10-02 15:27 - 00000000 ___HD C:\Program Files (x86)\InstallJammer Registry
2013-07-08 18:48 - 2011-02-20 05:06 - 00000000 ____D C:\Users\uwe
2013-07-08 18:41 - 2011-04-13 12:17 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{22AE3CF3-0503-4C69-9351-572E12CF9FBA}
2013-07-08 11:07 - 2011-03-22 11:47 - 00000000 ____D C:\Program Files\Swisslog
2013-07-06 09:00 - 2012-05-30 20:57 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-07-02 12:29 - 2013-07-02 12:29 - 00000000 ____D C:\Program Files (x86)\NOXON Media
2013-07-02 12:27 - 2013-07-02 12:27 - 00000000 ____D C:\Program Files (x86)\DVBViewer TERRATEC Edition
2013-07-01 15:22 - 2013-07-01 15:22 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fldigi
2013-07-01 15:22 - 2012-05-16 11:40 - 00000000 ____D C:\Program Files (x86)\Fldigi-3.21.41
2013-06-29 19:04 - 2011-10-02 16:42 - 00000000 ____D C:\Users\uwe\fldigi.files
2013-06-29 18:43 - 2013-01-08 19:20 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Afreet
2013-06-29 13:57 - 2013-06-29 13:57 - 00000306 __RSH C:\Users\uwe\ntuser.pol
2013-06-29 13:57 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-06-29 13:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-06-29 11:54 - 2013-06-29 11:54 - 00279379 _____ C:\Users\uwe\Downloads\VirtualAudioCable409.zip
2013-06-29 11:39 - 2013-06-29 11:39 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2013-06-29 11:36 - 2013-06-28 16:40 - 00000000 ____D C:\Program Files (x86)\ASIO4ALL v2
2013-06-28 17:22 - 2013-06-28 17:22 - 00421109 _____ C:\Users\uwe\Downloads\ASIO4ALL_2_11_Beta2_English(1).exe
2013-06-28 16:39 - 2013-06-28 16:39 - 00421109 _____ C:\Users\uwe\Downloads\ASIO4ALL_2_11_Beta2_English.exe
2013-06-28 16:39 - 2013-06-28 16:39 - 00420251 _____ C:\Users\uwe\Downloads\ASIO4ALL_2_10_Deutsch.exe
2013-06-28 15:51 - 2013-06-28 15:51 - 01117976 _____ C:\Users\uwe\Downloads\virtual audio cable setup(1).exe
2013-06-28 15:50 - 2013-06-28 15:50 - 01117976 _____ C:\Users\uwe\Downloads\virtual audio cable setup.exe
2013-06-28 15:44 - 2012-11-10 20:58 - 00000000 ____D C:\Users\uwe\AppData\Local\JT65-HF
2013-06-28 10:26 - 2013-06-28 10:26 - 01459426 _____ C:\Users\uwe\Downloads\rf
2013-06-27 10:23 - 2011-10-03 18:49 - 00000000 ____D C:\Users\uwe\AppData\Roaming\MixW
2013-06-27 10:17 - 2013-06-25 20:24 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MixW
2013-06-27 10:14 - 2013-06-27 10:14 - 00000000 ____D C:\ProgramData\MixW
2013-06-27 10:14 - 2011-10-03 18:49 - 00000000 ____D C:\Program Files (x86)\MixW
2013-06-27 10:13 - 2013-06-27 10:13 - 08088182 _____ C:\Users\uwe\Downloads\MixW3_1_1h.exe

Files to move or delete:
====================
C:\Windows\SysWOW64\rundll32.exe
C:\Users\uwe\juma-tx136-500-control.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-23 11:29

==================== End Of Log ============================

--- --- ---

--- --- ---


jetzt haben wir nen doublepost. Bitte das eine Log einfach loeschen

schrauber 27.07.2013 17:29

Passt schon :)


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?

daslicht 02.08.2013 13:21

Entschuldige die späte Antwort, aber zwischenzeitlich war mal wieder unser Internet und Telefon komplett tot.

Eset:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=940be5e4c12d0142ba47c06c4837d866
# engine=14554
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-27 05:36:09
# local_time=2013-07-27 07:36:09 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 4400 126576419 0 0
# scanned=286880
# found=0
# cleaned=0
# scan_time=2976
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=940be5e4c12d0142ba47c06c4837d866
# engine=14617
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-02 11:28:40
# local_time=2013-08-02 01:28:40 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 10488 127072770 0 0
# scanned=507818
# found=1
# cleaned=0
# scan_time=9968
sh=DB3689997A50187D10BB486B16EDD4F452039104 ft=1 fh=a37b7ad8e4154430 vn="multiple threats" ac=I fn="E:\20081024_182232_DK1KQ_Backup1\C\RECYCLER\S-1-5-21-45430952-3936675657-2195099286-1006\Dc4.exe"

Security Check:
Code:

Results of screen317's Security Check version 0.99.70 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 10 
``````````````Antivirus/Firewall Check:``````````````
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware Version 1.75.0.1300 
 Wise Registry Cleaner 7.62 
 Java(TM) 6 Update 29 
 Java version out of Date!
 Adobe Flash Player 11.7.700.224 
 Adobe Reader 10.1.7 Adobe Reader out of Date! 
````````Process Check: objlist.exe by Laurent```````` 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

FRST:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-08-2013
Ran by uwe (administrator) on 02-08-2013 10:27:37
Running from C:\Users\uwe\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(CrossLoop) C:\Users\uwe\AppData\Local\CrossLoop\CrossLoopService.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
() C:\Windows\Samsung\PanelMgr\caller64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [606208 2009-12-09] ()
HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {E034DA88-FABA-480E-A52B-17FAE15365ED} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADRA_de
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {E034DA88-FABA-480E-A52B-17FAE15365ED} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADRA_de
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIC30F~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: ipp - No CLSID Value -
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIC30F~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIC30F~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: ftd - C:\Users\uwe\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi
FF Extension: gophoto - C:\Users\uwe\AppData\Roaming\Mozilla\Firefox\profiles\extensions\gophoto@gophoto.it.xpi
FF Extension: trtv3 - C:\Users\uwe\AppData\Roaming\Mozilla\Firefox\profiles\extensions\trtv3@trtv.com.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{DEDAF650-12B8-48f5-A843-BBA100716106}] C:\Program Files\Updater By Sweetpacks\Firefox

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2011-09-29] (Adobe Systems)
R2 CrossLoopService; C:\Users\uwe\AppData\Local\CrossLoop\CrossLoopService.exe [569072 2012-01-06] (CrossLoop)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
S3 tvnserver; C:\Users\uwe\AppData\Local\CrossLoop\tvnserver.exe [814080 2010-07-21] (GlavSoft LLC.)

==================== Drivers (Whitelisted) ====================

S3 bdfsfltr; C:\Windows\System32\DRIVERS\bdfsfltr.sys [442088 2011-08-16] (BitDefender)
R3 evserial; C:\Windows\System32\DRIVERS\evserial.sys [68608 2009-06-23] (ELTIMA Software)
R3 evserial7; C:\Windows\System32\DRIVERS\evserial7.sys [69704 2010-07-15] (ELTIMA Software)
R3 flex1500; C:\Windows\System32\drivers\flex1500.sys [265312 2012-11-29] (Jungo)
S3 FlexRadio; C:\Windows\System32\Drivers\FlexRadio.sys [211536 2013-04-04] (FlexRadio Systems)
S3 FlexRadioAudio; C:\Windows\System32\drivers\FlexRadioAudio.sys [48336 2013-04-04] (FlexRadio Systems)
S3 FlexRadioMidi; C:\Windows\System32\drivers\FlexRadioMidi.sys [35408 2013-04-04] (FlexRadio Systems)
R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2011-04-07] (Highresolution Enterprises [www.highrez.co.uk])
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [329800 2011-10-27] (BitDefender S.R.L.)
R3 VSBC; C:\Windows\System32\DRIVERS\evsbc.sys [34816 2009-06-23] (ELTIMA Software)
R3 VSBC7; C:\Windows\System32\DRIVERS\evsbc7.sys [35912 2010-07-15] (ELTIMA Software)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2010-08-31] (Jungo)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-02 08:14 - 2013-08-02 08:14 - 00000000 ____D C:\Users\uwe\AppData\Local\{87417EF7-5F00-4D9F-BF65-D79628147EFF}
2013-07-31 08:05 - 2013-07-31 08:05 - 00000000 ____D C:\Users\uwe\AppData\Local\{31987A15-A81D-4ECD-8054-17602932F1F0}
2013-07-30 09:08 - 2013-07-30 09:08 - 00000000 ____D C:\Users\uwe\AppData\Local\{AE1EF0DC-FBAF-4C37-B62E-E663ADD8D1EC}
2013-07-29 20:55 - 2013-07-29 20:56 - 00000000 ____D C:\Users\uwe\AppData\Local\{58BF68AD-B640-40AA-AF24-066C07555514}
2013-07-29 08:30 - 2013-07-29 08:30 - 00000000 ____D C:\Users\uwe\AppData\Local\{8EBA7802-90B2-4096-971D-75A349ADEAC6}
2013-07-28 08:21 - 2013-07-28 08:21 - 00000000 ____D C:\Users\uwe\AppData\Local\{BA23CAFD-D5BF-443B-977B-E16B717F3070}
2013-07-27 18:58 - 2013-07-27 18:58 - 00891062 _____ C:\Users\uwe\Desktop\SecurityCheck.exe
2013-07-27 18:45 - 2013-07-27 18:45 - 00000000 ____D C:\Program Files (x86)\ESET
2013-07-27 18:44 - 2013-07-27 18:44 - 02347384 _____ (ESET) C:\Users\uwe\Downloads\esetsmartinstaller_enu.exe
2013-07-27 18:42 - 2013-08-02 08:14 - 00001568 _____ C:\Windows\setupact.log
2013-07-27 18:42 - 2013-07-27 18:42 - 00000000 _____ C:\Windows\setuperr.log
2013-07-27 18:39 - 2013-07-27 18:39 - 00550151 _____ C:\Users\uwe\Downloads\Autoruns.zip
2013-07-27 18:39 - 2013-06-27 23:20 - 00660160 _____ (Sysinternals - www.sysinternals.com) C:\Users\uwe\Desktop\autoruns.exe
2013-07-27 18:38 - 2013-08-02 10:06 - 00716948 _____ C:\Windows\WindowsUpdate.log
2013-07-27 11:38 - 2013-08-02 10:27 - 01781485 _____ (Farbar) C:\Users\uwe\Desktop\FRST64.exe
2013-07-27 11:38 - 2013-07-27 11:38 - 00033603 _____ C:\Users\uwe\Downloads\FRST.txt
2013-07-27 11:36 - 2013-07-27 11:36 - 00199458 _____ C:\Users\uwe\Desktop\JRT.txt
2013-07-27 11:34 - 2013-07-27 11:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-27 11:33 - 2013-07-27 11:33 - 00000951 _____ C:\AdwCleaner[R2].txt
2013-07-27 11:32 - 2013-07-27 11:32 - 00031541 _____ C:\AdwCleaner[S1].txt
2013-07-27 11:30 - 2013-07-27 11:30 - 00032688 _____ C:\AdwCleaner[R1].txt
2013-07-27 11:30 - 2013-07-27 11:30 - 00000000 ____D C:\Users\uwe\Desktop\TROJAN
2013-07-26 15:40 - 2013-07-26 15:40 - 00023339 _____ C:\ComboFix.txt
2013-07-26 15:22 - 2013-07-26 15:40 - 00000000 ____D C:\Qoobox
2013-07-26 15:22 - 2013-07-26 15:28 - 00000000 ____D C:\Windows\erdnt
2013-07-26 15:22 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-26 15:22 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-26 15:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-26 15:22 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-26 15:21 - 2013-07-25 19:00 - 05093969 ____R (Swearware) C:\Users\uwe\Desktop\ComboFix.exe
2013-07-26 12:11 - 2013-07-26 12:11 - 00023334 _____ C:\Users\uwe\Desktop\Addition.txt
2013-07-26 12:10 - 2013-07-26 12:10 - 00000000 ____D C:\FRST
2013-07-26 11:50 - 2013-07-26 11:57 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-26 11:49 - 2013-07-26 11:57 - 00000000 ____D C:\Users\uwe\Desktop\mbar
2013-07-26 11:49 - 2013-07-26 11:49 - 13399154 _____ C:\Users\uwe\Downloads\mbar-1.06.0.1004.zip
2013-07-26 11:09 - 2013-07-26 11:09 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2 (1).crx
2013-07-26 11:07 - 2013-07-26 11:08 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2.crx
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-07-19 19:07 - 2013-07-19 19:08 - 00000000 ____D C:\Windows\system32\MRT
2013-07-17 09:46 - 2013-07-17 09:46 - 00000000 ____D C:\Users\uwe\AppData\Local\Cool_Mirage
2013-07-16 11:27 - 2013-07-16 11:27 - 01067456 _____ (Solid State Networks) C:\Users\uwe\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe
2013-07-16 10:52 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-16 10:52 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-16 10:52 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-16 10:52 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-16 10:52 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-16 10:52 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-16 10:52 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-16 10:52 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-16 10:52 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-16 10:52 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-16 10:52 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-16 10:52 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-15 19:58 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-15 19:58 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-15 19:57 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-15 19:57 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-15 19:57 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-15 19:57 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-15 19:55 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Roaming\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Local\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\ProgramData\www.rene-zeidler.de
2013-07-08 19:58 - 2013-07-08 19:58 - 00090624 _____ (Eugene V. Muzychenko) C:\Windows\system32\Drivers\vrtaucbl.sys
2013-07-08 19:50 - 2013-07-08 19:50 - 29403457 _____ (SRWare                                                      ) C:\Users\uwe\Downloads\srware_iron.exe
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Users\uwe\AppData\Local\Chromium
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Program Files (x86)\SRWare Iron
2013-07-08 19:21 - 2013-07-08 19:21 - 00617312 _____ (www.download-sponsor.de) C:\Users\uwe\Downloads\CCleaner 4.01.4093.exe
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Users\uwe\AppData\Roaming\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-08 19:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-08 18:54 - 2013-07-08 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
133

==================== One Month Modified Files and Folders =======

2013-08-02 10:23 - 2013-08-02 10:23 - 00000878 _____ C:\Users\uwe\Desktop\SecurityCheck.txt
2013-08-02 10:06 - 2013-07-27 18:38 - 00716948 _____ C:\Windows\WindowsUpdate.log
2013-08-02 09:52 - 2010-11-21 08:50 - 00696832 _____ C:\Windows\system32\perfh007.dat
2013-08-02 09:52 - 2010-11-21 08:50 - 00148128 _____ C:\Windows\system32\perfc007.dat
2013-08-02 09:52 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-02 09:36 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-08-02 08:21 - 2009-07-14 06:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-02 08:21 - 2009-07-14 06:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-02 08:14 - 2013-08-02 08:14 - 00000000 ____D C:\Users\uwe\AppData\Local\{87417EF7-5F00-4D9F-BF65-D79628147EFF}
2013-08-02 08:14 - 2013-07-27 18:42 - 00001568 _____ C:\Windows\setupact.log
2013-08-02 08:14 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-31 08:05 - 2013-07-31 08:05 - 00000000 ____D C:\Users\uwe\AppData\Local\{31987A15-A81D-4ECD-8054-17602932F1F0}
2013-07-30 09:08 - 2013-07-30 09:08 - 00000000 ____D C:\Users\uwe\AppData\Local\{AE1EF0DC-FBAF-4C37-B62E-E663ADD8D1EC}
2013-07-29 20:56 - 2013-07-29 20:55 - 00000000 ____D C:\Users\uwe\AppData\Local\{58BF68AD-B640-40AA-AF24-066C07555514}
2013-07-29 08:30 - 2013-07-29 08:30 - 00000000 ____D C:\Users\uwe\AppData\Local\{8EBA7802-90B2-4096-971D-75A349ADEAC6}
2013-07-28 08:21 - 2013-07-28 08:21 - 00000000 ____D C:\Users\uwe\AppData\Local\{BA23CAFD-D5BF-443B-977B-E16B717F3070}
2013-07-27 18:58 - 2013-07-27 18:58 - 00891062 _____ C:\Users\uwe\Desktop\SecurityCheck.exe
2013-07-27 18:45 - 2013-07-27 18:45 - 00000000 ____D C:\Program Files (x86)\ESET
2013-07-27 18:44 - 2013-07-27 18:44 - 02347384 _____ (ESET) C:\Users\uwe\Downloads\esetsmartinstaller_enu.exe
2013-07-27 18:42 - 2013-07-27 18:42 - 00000000 _____ C:\Windows\setuperr.log
2013-07-27 18:39 - 2013-07-27 18:39 - 00550151 _____ C:\Users\uwe\Downloads\Autoruns.zip
2013-07-27 18:38 - 2011-02-20 05:02 - 00000000 ____D C:\Windows\Panther
2013-07-27 11:38 - 2013-07-27 11:38 - 00033603 _____ C:\Users\uwe\Downloads\FRST.txt
2013-07-27 11:36 - 2013-07-27 11:36 - 00199458 _____ C:\Users\uwe\Desktop\JRT.txt
2013-07-27 11:34 - 2013-07-27 11:34 - 00000000 ____D C:\Windows\ERUNT
2013-07-27 11:33 - 2013-07-27 11:33 - 00000951 _____ C:\AdwCleaner[R2].txt
2013-07-27 11:32 - 2013-07-27 11:32 - 00031541 _____ C:\AdwCleaner[S1].txt
2013-07-27 11:32 - 2011-02-20 05:07 - 00000991 _____ C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-27 11:30 - 2013-07-27 11:30 - 00032688 _____ C:\AdwCleaner[R1].txt
2013-07-27 11:30 - 2013-07-27 11:30 - 00000000 ____D C:\Users\uwe\Desktop\TROJAN
2013-07-26 15:40 - 2013-07-26 15:40 - 00023339 _____ C:\ComboFix.txt
2013-07-26 15:40 - 2013-07-26 15:22 - 00000000 ____D C:\Qoobox
2013-07-26 15:39 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-07-26 15:28 - 2013-07-26 15:22 - 00000000 ____D C:\Windows\erdnt
2013-07-26 15:27 - 2009-07-14 04:34 - 81264640 _____ C:\Windows\system32\config\software.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 44040192 _____ C:\Windows\system32\config\components.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 18087936 _____ C:\Windows\system32\config\system.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 02883584 _____ C:\Windows\system32\config\default.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\security.bak
2013-07-26 15:27 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\sam.bak
2013-07-26 15:24 - 2011-02-20 06:08 - 00001912 _____ C:\Windows\epplauncher.mif
2013-07-26 12:11 - 2013-07-26 12:11 - 00023334 _____ C:\Users\uwe\Desktop\Addition.txt
2013-07-26 12:10 - 2013-07-26 12:10 - 00000000 ____D C:\FRST
2013-07-26 11:57 - 2013-07-26 11:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-26 11:57 - 2013-07-26 11:49 - 00000000 ____D C:\Users\uwe\Desktop\mbar
2013-07-26 11:49 - 2013-07-26 11:49 - 13399154 _____ C:\Users\uwe\Downloads\mbar-1.06.0.1004.zip
2013-07-26 11:09 - 2013-07-26 11:09 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2 (1).crx
2013-07-26 11:08 - 2013-07-26 11:07 - 00328332 _____ C:\Users\uwe\Downloads\extension_1_5_2.crx
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-07-26 09:42 - 2013-07-26 09:42 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-07-26 09:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-25 19:00 - 2013-07-26 15:21 - 05093969 ____R (Swearware) C:\Users\uwe\Desktop\ComboFix.exe
2013-07-19 19:08 - 2013-07-19 19:07 - 00000000 ____D C:\Windows\system32\MRT
2013-07-17 09:46 - 2013-07-17 09:46 - 00000000 ____D C:\Users\uwe\AppData\Local\Cool_Mirage
2013-07-17 09:46 - 2011-02-20 00:03 - 00420944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2013-07-17 09:46 - 2011-02-19 01:40 - 00773712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2013-07-16 11:27 - 2013-07-16 11:27 - 01067456 _____ (Solid State Networks) C:\Users\uwe\Downloads\install_flashplayer11x32au_mssa_aaa_aih.exe
2013-07-16 11:27 - 2013-06-27 12:28 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-16 11:27 - 2013-06-27 12:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-16 09:40 - 2009-07-14 06:45 - 00451056 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-16 09:39 - 2010-11-21 09:00 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-16 09:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-16 09:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-15 20:08 - 2013-05-30 10:59 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-08 20:18 - 2011-02-20 05:07 - 00000000 ____D C:\Users\uwe\AppData\Local\VirtualStore
2013-07-08 20:07 - 2011-02-20 05:06 - 00000000 ___RD C:\Users\uwe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Roaming\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\Users\uwe\AppData\Local\www.rene-zeidler.de
2013-07-08 20:05 - 2013-07-08 20:05 - 00000000 ____D C:\ProgramData\www.rene-zeidler.de
2013-07-08 19:58 - 2013-07-08 19:58 - 00090624 _____ (Eugene V. Muzychenko) C:\Windows\system32\Drivers\vrtaucbl.sys
2013-07-08 19:58 - 2013-06-28 16:36 - 00000000 ____D C:\Program Files\Virtual Audio Cable
2013-07-08 19:54 - 2011-02-20 06:07 - 01590298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-07-08 19:50 - 2013-07-08 19:50 - 29403457 _____ (SRWare                                                      ) C:\Users\uwe\Downloads\srware_iron.exe
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Users\uwe\AppData\Local\Chromium
2013-07-08 19:50 - 2013-07-08 19:50 - 00000000 ____D C:\Program Files (x86)\SRWare Iron
2013-07-08 19:45 - 2011-03-21 14:13 - 00000000 ____D C:\Users\uwe\AppData\Local\Google
2013-07-08 19:44 - 2013-07-08 18:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-08 19:44 - 2012-04-23 19:40 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Mozilla
2013-07-08 19:30 - 2013-04-26 12:23 - 00000000 ____D C:\Users\uwe\AppData\Roaming\FileZilla
2013-07-08 19:29 - 2013-02-13 17:01 - 00000000 ____D C:\Program Files\CCleaner
2013-07-08 19:21 - 2013-07-08 19:21 - 00617312 _____ (www.download-sponsor.de) C:\Users\uwe\Downloads\CCleaner 4.01.4093.exe
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Users\uwe\AppData\Roaming\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-07-08 19:10 - 2013-07-08 19:10 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Users\uwe\AppData\Roaming\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-08 19:09 - 2013-07-08 19:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-08 18:51 - 2011-10-02 15:27 - 00000000 ___HD C:\Program Files (x86)\InstallJammer Registry
2013-07-08 18:48 - 2011-02-20 05:06 - 00000000 ____D C:\Users\uwe
2013-07-08 18:41 - 2011-04-13 12:17 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{22AE3CF3-0503-4C69-9351-572E12CF9FBA}
2013-07-08 11:07 - 2011-03-22 11:47 - 00000000 ____D C:\Program Files\Swisslog
2013-07-06 09:00 - 2012-05-30 20:57 - 00000000 ____D C:\ProgramData\CanonIJPLM

Files to move or delete:
====================
C:\Users\uwe\juma-tx136-500-control.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-02 08:48

==================== End Of Log ============================

--- --- ---

--- --- ---

[/CODE]

schrauber 02.08.2013 23:05

Java und Adobe updaten.

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\uwe\juma-tx136-500-control.exe

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Alle Zeitangaben in WEZ +1. Es ist jetzt 23:30 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58