Hallo schrauber,
Dankeschön für die hilfreichen Hinwesie und Anweisungen. Habe alles exakt so durchgeführt.
Hier poste ich nun das Logfile nach Abschluss des
ESET Scanners. Eset Online Scanner habe ich inzwischen deinstalliert, den Ordner gelöscht und den Papierkorb geleert.
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=0a7c4396901dd34cad3ae08f50b31f51
# engine=14941
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-29 12:23:45
# local_time=2013-08-29 02:23:45 (+0100, Westeuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5892 16777213 88 94 235919 15350267 0 0
# scanned=115256
# found=15
# cleaned=0
# scan_time=2881
sh=3E999A7D9738BFAA3F7AE046CCF3BCACC432B600 ft=0 fh=0000000000000000 vn="Win32/Filecoder.BH.Gen trojan" ac=I fn="C:\Dokumente und Einstellungen\User\Anwendungsdaten\Adobe\Acrobat\10.0\rdrmessage.zip"
sh=99B0BCCE3C8D2BB9CCC076F2DAB00DB2C8227E4A ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NAY trojan" ac=I fn="C:\Dokumente und Einstellungen\User\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\40\727b54e8-61050327"
sh=A8FB05A915CFDFDA7DB607A76D25140B5BD9AB01 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\18\43dfd2-2a66c915"
sh=98C50B79C7DE0AAF753FD7DA2FAACF4DB7090A71 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\27\3fe7bb9b-7673d098"
sh=C05844C1817C09DC9CFD1F17162BF98A8AEBFEE8 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\29\1c3a069d-79bfdcd5"
sh=657961CDCD217DA15EDDFAF03B770F07F2888975 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\30\95577de-6db25371"
sh=E287472178BB1D29EF08A197C64AF4856FEF847E ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\35\2dc268a3-121384d0"
sh=657961CDCD217DA15EDDFAF03B770F07F2888975 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\36\87aa864-6ea0a36c"
sh=473E5B37175599506BA5F8179F806A8DF78570A7 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\39\96285a7-3e707a41"
sh=A8FB05A915CFDFDA7DB607A76D25140B5BD9AB01 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\42\187e266a-67cb9750"
sh=C4A58C72684FBA2840B47879AA73BF7400462AEF ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.OVI trojan" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\49\71f8efb1-76d5e1ce"
sh=244E1F37883AEC2AFE2587CF042E1A64AF3C245F ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\63\4e3a9ebf-64095625"
sh=8A4FA7CD822C768A546F4C186EF250C5BF429329 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NQR trojan" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\63\666ba8bf-77f9502c"
sh=3A4D5CF0C188AEE09C5F5475CE321F876C0C61AC ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\7\79184747-713be3c9"
sh=4E52588B3A6EC0FAB40B561F35B6B8F63DB1A620 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NMA trojan" ac=I fn="C:\Dokumente und Einstellungen\User\Lokale Einstellungen\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\9\662bfa09-4267ca33"
Und hier folgt die checkup.txt des
SecurityCheck:
Results of screen317's Security Check version 0.99.72
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
CCleaner
Java 7 Update 25
Adobe Flash Player 11.8.800.94
Adobe Reader 10.1.7
Adobe Reader out of Date!
Mozilla Firefox (23.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Acronis TrueImageHome OnlineBackupStandalone TrueImageMonitor.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
Und schlussendlich auch die aktuelle
FRST.txtFRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013
Ran by User (administrator) on 29-08-2013 15:50:00
Running from C:\Dokumente und Einstellungen\User\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Programme\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(shbox.de) C:\Programme\FreePDF_XP\fpassist.exe
(Acronis) C:\Programme\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe
(Acronis) C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe
(Microsoft Corporation) C:\Programme\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Programme\Windows Desktop Search\WindowsSearch.exe
(Acronis) C:\Programme\Gemeinsame Dateien\Acronis\CDP\afcdpsrv.exe
(Dropbox, Inc.) C:\Dokumente und Einstellungen\User\Anwendungsdaten\Dropbox\bin\Dropbox.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
() C:\Programme\CDBurnerXP\NMSAccessU.exe
(TeamViewer GmbH) C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
(TeamViewer GmbH) C:\Programme\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Programme\TeamViewer\Version8\tv_w32.exe
(ATI Technologies Inc.) C:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [20053096 2011-03-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [FreePDF Assistant] - C:\Programme\FreePDF_XP\fpassist.exe [370176 2010-06-17] (shbox.de)
HKLM\...\Run: [Microsoft Default Manager] - C:\Programme\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM\...\Run: [SAOB Monitor] - C:\Programme\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe [2570688 2010-11-16] (Acronis)
HKLM\...\Run: [TrueImageMonitor.exe] - C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe [5583056 2011-02-01] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe [391232 2011-02-01] (Acronis)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [StartCCC] - C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2011-07-07] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [MSC] - C:\Programme\Microsoft Security Client\msseces.exe [995184 2013-07-18] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Programme\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\User\Startmenü\Programme\Autostart\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Dokumente und Einstellungen\User\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
BHO: TSToolbarBHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Programme\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Programme\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll No File
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\System32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1302643824343
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ipp - No CLSID Value -
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Programme\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll No File
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 83.169.184.161 83.169.184.225
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\2vy7hclb.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Programme\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Programme\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF Extension: Default - C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] C:\Programme\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\
FF Extension: Default Manager - C:\Programme\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\
========================== Services (Whitelisted) =================
R2 AcrSch2Svc; C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe [805024 2011-02-01] (Acronis)
R2 afcdpsrv; C:\Programme\Gemeinsame Dateien\Acronis\CDP\afcdpsrv.exe [3246040 2011-04-22] (Acronis)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2003-06-19] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [117656 2013-08-17] (Mozilla Foundation)
R2 MsMpSvc; C:\Programme\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation)
R2 NMSAccess; C:\Programme\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
S3 odserv; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 TeamViewer8; C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe [4308320 2013-08-07] (TeamViewer GmbH)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
R2 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
S3 gdrv; C:\WINDOWS\gdrv.sys [16608 2011-04-12] (Windows (R) 2000 DDK provider)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R1 MpKsl3d59b66f; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Microsoft Antimalware\Definition Updates\{8CC84B49-BC57-4620-8E9B-6A4732532016}\MpKsl3d59b66f.sys [29904 2013-08-29] (Microsoft Corporation)
S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] ()
S3 catchme; \??\C:\DOKUME~1\User\LOKALE~1\Temp\catchme.sys [x]
S4 IntelIde; No ImagePath
S1 kwzyssnm; \??\C:\WINDOWS\system32\drivers\kwzyssnm.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 15:42 - 2013-08-29 15:42 - 00891115 _____ C:\Dokumente und Einstellungen\User\Desktop\SecurityCheck.exe
2013-08-29 13:33 - 2013-08-29 13:33 - 00000000 ____D C:\Programme\ESET
2013-08-28 20:50 - 2013-08-28 20:50 - 01072975 _____ (Farbar) C:\Dokumente und Einstellungen\User\Desktop\FRST.exe
2013-08-28 20:46 - 2013-08-28 20:46 - 00000580 _____ C:\Dokumente und Einstellungen\User\Desktop\JRT.txt
2013-08-28 20:43 - 2013-08-28 20:43 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-28 20:41 - 2013-08-28 20:41 - 00001826 _____ C:\Dokumente und Einstellungen\User\Desktop\AdwCleaner[S0].txt
2013-08-28 20:41 - 2013-08-28 20:41 - 00000000 __SHD C:\Dokumente und Einstellungen\User\IECompatCache
2013-08-28 20:35 - 2013-08-28 20:37 - 00000000 ____D C:\AdwCleaner
2013-08-27 20:37 - 2013-08-27 20:37 - 00000000 ____D C:\Dokumente und Einstellungen\User\Anwendungsdaten\Malwarebytes
2013-08-27 20:35 - 2013-08-27 20:36 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-27 20:35 - 2013-08-27 20:35 - 00000762 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-27 20:35 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-08-27 20:27 - 2013-08-27 20:27 - 01021434 _____ (Thisisu) C:\Dokumente und Einstellungen\User\Desktop\JRT.exe
2013-08-27 20:26 - 2013-08-27 20:27 - 00994642 _____ C:\Dokumente und Einstellungen\User\Desktop\adwcleaner.exe
2013-08-27 20:26 - 2013-08-27 20:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Dokumente und Einstellungen\User\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-27 19:55 - 2013-08-27 19:55 - 00004583 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-27 19:55 - 2013-08-27 19:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-26 21:01 - 2013-08-29 12:33 - 00000386 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-08-26 19:58 - 2013-08-26 19:58 - 00045190 _____ C:\ComboFix.txt
2013-08-26 19:50 - 2013-08-26 19:50 - 00000000 _RSHD C:\cmdcons
2013-08-26 19:50 - 2011-04-13 00:49 - 00000211 _____ C:\Boot.bak
2013-08-26 19:50 - 2004-08-03 23:00 - 00262448 __RSH C:\cmldr
2013-08-26 19:48 - 2013-08-26 19:58 - 00000000 ____D C:\Qoobox
2013-08-26 19:48 - 2013-08-26 19:57 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ___RD C:\Dokumente und Einstellungen\User\Startmenü\Programme\Verwaltung
2013-08-26 19:48 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-08-26 19:48 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-08-26 19:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-08-26 19:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-08-26 19:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-08-26 19:48 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-08-26 19:48 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-08-26 19:48 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-08-26 19:48 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-08-26 19:25 - 2013-08-26 19:25 - 05113393 ____R (Swearware) C:\Dokumente und Einstellungen\User\Desktop\ComboFix.exe
2013-08-25 19:56 - 2013-08-25 19:56 - 00000000 ____D C:\FRST
2013-08-25 16:17 - 2013-08-25 16:17 - 00000000 ____D C:\{759105A4-E62B-57C6-C860-390BA6AE1DD0}
2013-08-25 16:13 - 2013-08-25 16:17 - 00000000 ____D C:\Programme\Dirty
2013-08-17 16:39 - 2013-08-18 08:16 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-08-14 06:02 - 2013-08-14 06:03 - 00022767 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-14 05:58 - 2013-08-14 05:58 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 05:57 - 2013-08-14 05:58 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 05:57 - 2013-08-14 05:57 - 00005582 _____ C:\WINDOWS\KB2863058.log
2013-08-14 05:57 - 2013-08-14 05:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 05:57 - 2013-08-14 05:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 05:40 - 2013-08-14 05:58 - 00013818 _____ C:\WINDOWS\KB2859537.log
2013-08-14 05:40 - 2013-08-14 05:58 - 00010749 _____ C:\WINDOWS\KB2850869.log
2013-08-03 09:44 - 2013-08-14 06:02 - 00000000 ____D C:\WINDOWS\system32\MRT
==================== One Month Modified Files and Folders =======
2013-08-29 15:45 - 2013-08-29 15:45 - 00001125 _____ C:\Dokumente und Einstellungen\User\Desktop\checkup.txt
2013-08-29 15:42 - 2013-08-29 15:42 - 00891115 _____ C:\Dokumente und Einstellungen\User\Desktop\SecurityCheck.exe
2013-08-29 15:16 - 2012-08-27 19:37 - 01340312 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-29 15:16 - 2011-04-14 01:34 - 00196608 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-08-29 15:13 - 2013-07-05 07:05 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-29 13:33 - 2013-08-29 13:33 - 00000000 ____D C:\Programme\ESET
2013-08-29 13:33 - 2011-04-13 00:04 - 00000000 ___RD C:\Programme
2013-08-29 12:33 - 2013-08-26 21:01 - 00000386 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-08-29 12:24 - 2011-04-14 01:39 - 00000000 ___RD D:\\Dropbox
2013-08-29 12:24 - 2011-04-14 01:37 - 00000000 ____D C:\Dokumente und Einstellungen\User\Anwendungsdaten\Dropbox
2013-08-29 12:24 - 2003-04-02 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-29 12:23 - 2012-08-27 19:36 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-29 12:23 - 2012-08-27 19:36 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-29 12:23 - 2011-04-12 23:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-29 11:38 - 2011-04-12 23:15 - 00000300 ___SH C:\Dokumente und Einstellungen\User\ntuser.ini
2013-08-29 11:38 - 2011-04-12 23:14 - 00032532 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-28 20:50 - 2013-08-28 20:50 - 01072975 _____ (Farbar) C:\Dokumente und Einstellungen\User\Desktop\FRST.exe
2013-08-28 20:46 - 2013-08-28 20:46 - 00000580 _____ C:\Dokumente und Einstellungen\User\Desktop\JRT.txt
2013-08-28 20:43 - 2013-08-28 20:43 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-28 20:41 - 2013-08-28 20:41 - 00001826 _____ C:\Dokumente und Einstellungen\User\Desktop\AdwCleaner[S0].txt
2013-08-28 20:41 - 2013-08-28 20:41 - 00000000 __SHD C:\Dokumente und Einstellungen\User\IECompatCache
2013-08-28 20:37 - 2013-08-28 20:35 - 00000000 ____D C:\AdwCleaner
2013-08-27 20:43 - 2011-04-12 23:14 - 00000000 __SHD C:\Dokumente und Einstellungen\NetworkService
2013-08-27 20:37 - 2013-08-27 20:37 - 00000000 ____D C:\Dokumente und Einstellungen\User\Anwendungsdaten\Malwarebytes
2013-08-27 20:36 - 2013-08-27 20:35 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-27 20:35 - 2013-08-27 20:35 - 00000762 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-27 20:27 - 2013-08-27 20:27 - 01021434 _____ (Thisisu) C:\Dokumente und Einstellungen\User\Desktop\JRT.exe
2013-08-27 20:27 - 2013-08-27 20:26 - 00994642 _____ C:\Dokumente und Einstellungen\User\Desktop\adwcleaner.exe
2013-08-27 20:26 - 2013-08-27 20:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Dokumente und Einstellungen\User\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-27 19:55 - 2013-08-27 19:55 - 00004583 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-27 19:55 - 2013-08-27 19:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-27 19:55 - 2012-09-12 19:23 - 00341620 _____ C:\WINDOWS\iis6.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00317769 _____ C:\WINDOWS\FaxSetup.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00161660 _____ C:\WINDOWS\ocgen.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00150951 _____ C:\WINDOWS\tsoc.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00107219 _____ C:\WINDOWS\comsetup.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00096552 _____ C:\WINDOWS\msmqinst.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00066321 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00057269 _____ C:\WINDOWS\netfxocm.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00022851 _____ C:\WINDOWS\MedCtrOC.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00017774 _____ C:\WINDOWS\ocmsn.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00016243 _____ C:\WINDOWS\msgsocm.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00015861 _____ C:\WINDOWS\tabletoc.log
2013-08-27 19:55 - 2012-09-12 19:23 - 00001374 _____ C:\WINDOWS\imsins.log
2013-08-26 20:51 - 2013-01-05 19:58 - 00000000 ____D C:\Programme\Microsoft Security Client
2013-08-26 20:51 - 2012-08-26 21:25 - 00349520 _____ C:\WINDOWS\setupapi.log
2013-08-26 20:51 - 2011-04-20 23:40 - 00001912 ____C C:\WINDOWS\epplauncher.mif
2013-08-26 19:58 - 2013-08-26 19:58 - 00045190 _____ C:\ComboFix.txt
2013-08-26 19:58 - 2013-08-26 19:48 - 00000000 ____D C:\Qoobox
2013-08-26 19:57 - 2013-08-26 19:48 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-26 19:57 - 2003-04-02 14:00 - 00000227 _____ C:\WINDOWS\system.ini
2013-08-26 19:50 - 2013-08-26 19:50 - 00000000 _RSHD C:\cmdcons
2013-08-26 19:50 - 2011-04-13 01:03 - 00000327 __RSH C:\boot.ini
2013-08-26 19:48 - 2013-08-26 19:48 - 00000000 ___RD C:\Dokumente und Einstellungen\User\Startmenü\Programme\Verwaltung
2013-08-26 19:48 - 2011-04-12 23:15 - 00000000 ___RD C:\Dokumente und Einstellungen\User\Startmenü\Programme
2013-08-26 19:25 - 2013-08-26 19:25 - 05113393 ____R (Swearware) C:\Dokumente und Einstellungen\User\Desktop\ComboFix.exe
2013-08-25 20:57 - 2013-02-24 08:53 - 00000000 ____D C:\Dokumente und Einstellungen\User\Anwendungsdaten\vlc
2013-08-25 19:56 - 2013-08-25 19:56 - 00000000 ____D C:\FRST
2013-08-25 16:17 - 2013-08-25 16:17 - 00000000 ____D C:\{759105A4-E62B-57C6-C860-390BA6AE1DD0}
2013-08-25 16:17 - 2013-08-25 16:13 - 00000000 ____D C:\Programme\Dirty
2013-08-25 16:17 - 2011-04-20 23:39 - 00000000 ____D C:\Programme\Microsoft Sync Framework
2013-08-25 16:17 - 2011-04-12 23:15 - 00000000 ___RD C:\Dokumente und Einstellungen\User\Startmenü\Programme\Autostart
2013-08-20 21:15 - 2013-07-05 07:05 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-08-20 21:15 - 2013-07-05 07:05 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-08-19 19:51 - 2012-05-06 08:23 - 00000000 ____D C:\Programme\Mozilla Maintenance Service
2013-08-18 08:16 - 2013-08-17 16:39 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-08-14 20:57 - 2011-04-13 02:55 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-08-14 19:38 - 2012-08-19 03:03 - 00267800 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-08-14 06:03 - 2013-08-14 06:02 - 00022767 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-14 06:03 - 2012-09-22 06:01 - 00036790 _____ C:\WINDOWS\updspapi.log
2013-08-14 06:03 - 2012-09-12 19:23 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-08-14 06:03 - 2011-04-13 01:34 - 00000000 ____D C:\WINDOWS\ie8updates
2013-08-14 06:02 - 2013-08-03 09:44 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-08-14 06:01 - 2011-04-13 01:24 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-14 05:59 - 2011-04-13 00:04 - 01186882 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-14 05:58 - 2013-08-14 05:58 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 05:58 - 2013-08-14 05:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 05:58 - 2013-08-14 05:40 - 00013818 _____ C:\WINDOWS\KB2859537.log
2013-08-14 05:58 - 2013-08-14 05:40 - 00010749 _____ C:\WINDOWS\KB2850869.log
2013-08-14 05:57 - 2013-08-14 05:57 - 00005582 _____ C:\WINDOWS\KB2863058.log
2013-08-14 05:57 - 2013-08-14 05:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 05:57 - 2013-08-14 05:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 05:57 - 2012-10-10 20:14 - 00018778 _____ C:\WINDOWS\system32\TZLog.log
2013-08-03 01:48 - 2006-10-18 21:47 - 01543680 ____N (Microsoft Corporation) C:\WINDOWS\system32\wmvdecod.dll
Files to move or delete:
====================
C:\DOKUME~1\User\LOKALE~1\Temp\Quarantine.exe
C:\DOKUME~1\User\LOKALE~1\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2003-04-02 14:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2003-04-02 14:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2003-04-02 14:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2003-04-02 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2003-04-02 14:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2003-04-02 14:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2003-04-02 14:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
Klasse, dass die Programme die Bedrohungen zutage fördern und beseitigen können.
Wie immer besten Dank für die wirklich tolle Unterstützung!
Viele Grüße,
Matthias