Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.29.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Nutzer :: NUTZER-910299E3 [Administrator]
Schutz: Aktiviert
29.08.2013 14:34:07
mbam-log-2013-08-29 (14-34-07).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 208499
Laufzeit: 3 Minute(n), 53 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.001 - Report created 29/08/2013 at 14:42:10
# Updated 24/08/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Nutzer - NUTZER-910299E3
# Running from : C:\Dokumente und Einstellungen\Nutzer\desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ask
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ\ICQToolbar
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Covus Freemium
Folder Deleted : C:\Programme\Covus Freemium
Folder Deleted : C:\Programme\GutscheinFinder
Folder Deleted : C:\Programme\Mail.Ru
Folder Deleted : C:\Programme\SoftwareUpdater
Folder Deleted : C:\Programme\Gemeinsame Dateien\DVDVideoSoft\TB
Folder Deleted : C:\Dokumente und Einstellungen\Nutzer\IECompatCache
Folder Deleted : C:\Dokumente und Einstellungen\Nutzer\Lokale Einstellungen\Anwendungsdaten\Mail.Ru
Folder Deleted : C:\Dokumente und Einstellungen\Nutzer\Anwendungsdaten\dvdvideosoftiehelpers
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Key Deleted : HKCU\Software\Ciuvo
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Google Chrome v
[ File : C:\Dokumente und Einstellungen\Nutzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2924 octets] - [29/08/2013 14:41:31]
AdwCleaner[S0].txt - [2851 octets] - [29/08/2013 14:42:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2911 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Microsoft Windows XP x86
Ran by Nutzer on 29.08.2013 at 14:50:05,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{ABD00A44-FEB7-479D-977D-4E1F176FC028}
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\0e12f736682067fde4d1158d5940a82e"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\1a24b5bb8521b03e0c8d908f5abc0ae6"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\2b0d56c4f4c46d844a57ffed6f0d2852"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\49d4375fe41653242aea4c969e4e65e0"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\6aa0923513360135b272e8289c5f13fa"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\6f7467af8f29c134cbbab394eccfde96"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\922525dcc5199162f8935747ca3d8e59"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\bcda179d619b91648538e3394cac94cc"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\d677b1a9671d4d4004f6f2a4469e86ea"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\dd1402a9dd4215a43abde169a41afa0e"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\e36e114a0ead2ad46b381d23ad69cddf"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\ef8e618db3aedfbb384561b5c548f65e"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products\a28b4d68debaa244eb686953b7074fef"
~~~ Files
~~~ Folders
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.08.2013 at 14:53:51,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013
Ran by Nutzer (administrator) on 29-08-2013 14:56:06
Running from C:\Dokumente und Einstellungen\Nutzer\desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Microsoft Corporation) c:\Programme\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ABBYY) C:\Programme\Gemeinsame Dateien\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVM Berlin) C:\Programme\avmwlanstick\WlanNetService.exe
(Apple Inc.) C:\Programme\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Programme\Motorola\MotoHelper\MotoHelperService.exe
() C:\Programme\RealNetworks\RealDownloader\rndlresolversvc.exe
(TomTom) C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
() C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Alcor Micro, Corp.) C:\WINDOWS\WebCam\S6000\S6000Mnt.exe
(Microsoft Corporation) C:\Programme\Microsoft Security Client\msseces.exe
(Hewlett-Packard) C:\Programme\HP\HP Software Update\HPWuSchd2.exe
(RealNetworks, Inc.) C:\programme\real\realplayer\update\realsched.exe
(Advanced Micro Devices Inc.) c:\Programme\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(TomTom) C:\Programme\TomTom HOME 2\TomTomHOMERunner.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.bin
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqSTE08.exe
(ATI Technologies Inc.) c:\Programme\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Programme\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) c:\Programme\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) c:\Programme\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(RealNetworks, Inc.) C:\Programme\RealNetworks\RealDownloader\recordingmanager.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [20053608 2011-05-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [StartCCC] - c:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2011-07-07] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [S6000Mnt] - C:\Windows\System32\S6000Rmv.dll [72280 2011-07-28] (Alcor)
HKLM\...\Run: [APSDaemon] - C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [MSC] - c:\Programme\Microsoft Security Client\msseces.exe [931200 2012-03-26] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] - C:\Programme\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [hpqSRMon] - C:\Programme\HP\Digital Imaging\bin\hpqSRMon.exe [80896 2007-08-22] (Hewlett-Packard)
HKLM\...\Run: [TkBellExe] - C:\programme\real\realplayer\update\realsched.exe [295512 2013-06-24] (RealNetworks, Inc.)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [Steam] - C:\Programme\Steam\steam.exe [1811880 2013-08-28] (Valve Corporation)
HKCU\...\Run: [TomTomHOME.exe] - C:\Programme\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-03-22] (TomTom)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Dokumente und Einstellungen\Nutzer\Startmenü\Programme\Autostart\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?utf8in=1&fr=ietb&q={SearchTerms}
SearchScopes: HKCU - {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?utf8in=1&fr=ietb&q={SearchTerms}
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No File
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -No Name - {09900DE8-1DCA-443F-9243-26FF581438AF} - No File
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1311689327968
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} hxxp://battlefieldheroes.prosiebengames.de/static/updater/BFHUpdater_5.0.140.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Winsock: Catalog5 04 C:\Programme\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR HomePage: hxxp://mail.ru/cnt/7993/
CHR RestoreOnStartup: "hxxp://mail.ru/cnt/7993/"
CHR Extension: (RealDownloader) - C:\DOKUME~1\Nutzer\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Programme\Gemeinsame Dateien\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 Apple Mobile Device; C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184 2012-05-24] (Apple Inc.)
R2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 Bonjour Service; C:\Programme\Bonjour\mDNSResponder.exe [390504 2011-08-30] (Apple Inc.)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2012-02-13] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2012-02-13] (Google Inc.)
R3 hpqcxs08; C:\Programme\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\Programme\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MotoHelper; C:\Programme\Motorola\MotoHelper\MotoHelperService.exe [227184 2011-08-10] ()
R2 MsMpSvc; c:\Programme\Microsoft Security Client\MsMpEng.exe [11552 2012-03-26] (Microsoft Corporation)
S3 npggsvc; C:\WINDOWS\system32\GameMon.des [4122968 2011-06-19] (INCA Internet Co., Ltd.)
R2 RealNetworks Downloader Resolver Service; C:\Programme\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 TomTomHOMEService; C:\Programme\TomTom HOME 2\TomTomHOMEService.exe [93072 2013-03-22] (TomTom)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
==================== Drivers (Whitelisted) ====================
S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-01] (AVM Berlin)
S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [926080 2010-10-01] (AVM GmbH)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtKHDMI.sys [4104488 2011-04-26] (Realtek Semiconductor Corp.)
S3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3328472 2011-07-28] (Windows (R) Win 7 DDK provider)
S3 catchme; \??\C:\DOKUME~1\Nutzer\LOKALE~1\Temp\catchme.sys [x]
S4 IntelIde; No ImagePath
S1 ljbyeuas; \??\C:\WINDOWS\system32\drivers\ljbyeuas.sys [x]
S1 mipunezx; \??\C:\WINDOWS\system32\drivers\mipunezx.sys [x]
S1 ohzaxjvo; \??\C:\WINDOWS\system32\drivers\ohzaxjvo.sys [x]
S1 rabwubmo; \??\C:\WINDOWS\system32\drivers\rabwubmo.sys [x]
S1 raiopqrc; \??\C:\WINDOWS\system32\drivers\raiopqrc.sys [x]
S1 thrftzrh; \??\C:\WINDOWS\system32\drivers\thrftzrh.sys [x]
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 14:55 - 2013-08-29 14:55 - 00004404 _____ C:\WINDOWS\KB2780091.log
2013-08-29 14:55 - 2013-08-29 14:55 - 00004403 _____ C:\WINDOWS\KB2845187.log
2013-08-29 14:54 - 2013-08-29 14:54 - 00004299 _____ C:\WINDOWS\KB2850869.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004632 _____ C:\WINDOWS\KB2859537.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004203 _____ C:\WINDOWS\KB2820917.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004107 _____ C:\WINDOWS\KB2757638.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004003 _____ C:\WINDOWS\KB2749655.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00003900 _____ C:\WINDOWS\KB2727528.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00003197 _____ C:\Dokumente und Einstellungen\Nutzer\Desktop\JRT.txt
2013-08-29 14:52 - 2013-08-29 14:52 - 00004141 _____ C:\WINDOWS\KB2813345.log
2013-08-29 14:52 - 2013-08-29 14:52 - 00003846 _____ C:\WINDOWS\KB2661254-v2.log
2013-08-29 14:52 - 2013-08-29 14:52 - 00000000 ____D C:\WINDOWS\LastGood
2013-08-29 14:50 - 2013-08-29 14:50 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-29 14:48 - 2013-08-29 14:48 - 01023533 _____ (Thisisu) C:\Dokumente und Einstellungen\Nutzer\Desktop\JRT.exe
2013-08-29 14:46 - 2013-08-29 14:46 - 00000000 __SHD C:\Dokumente und Einstellungen\Nutzer\IECompatCache
2013-08-29 14:41 - 2013-08-29 14:42 - 00000000 ____D C:\AdwCleaner
2013-08-29 14:39 - 2013-08-29 14:40 - 00994642 _____ C:\Dokumente und Einstellungen\Nutzer\Desktop\adwcleaner.exe
2013-08-29 14:32 - 2013-08-29 14:32 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 14:32 - 2013-08-29 14:32 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-29 14:32 - 2013-08-29 14:32 - 00000000 ____D C:\Dokumente und Einstellungen\Nutzer\Anwendungsdaten\Malwarebytes
2013-08-29 14:32 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-08-29 14:31 - 2013-08-29 14:31 - 10285040 _____ (Malwarebytes Corporation ) C:\Dokumente und Einstellungen\Nutzer\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-29 14:18 - 2013-08-29 14:18 - 00024916 _____ C:\ComboFix.txt
2013-08-29 14:11 - 2011-07-26 07:50 - 00000211 _____ C:\Boot.bak
2013-08-29 14:10 - 2013-08-29 14:11 - 00000000 _RSHD C:\cmdcons
2013-08-29 14:10 - 2004-08-03 23:00 - 00262448 __RSH C:\cmldr
2013-08-29 14:09 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-08-29 14:09 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-08-29 14:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-08-29 14:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-08-29 14:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-08-29 14:09 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-08-29 14:09 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-08-29 14:09 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-08-29 14:09 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-08-29 14:08 - 2013-08-29 14:18 - 00000000 ____D C:\Qoobox
2013-08-29 14:08 - 2013-08-29 14:17 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-29 14:08 - 2013-08-29 14:08 - 00000000 ___RD C:\Dokumente und Einstellungen\Nutzer\Startmenü\Programme\Verwaltung
2013-08-29 14:07 - 2013-08-29 14:07 - 05115711 ____R (Swearware) C:\Dokumente und Einstellungen\Nutzer\Desktop\ComboFix.exe
2013-08-28 20:50 - 2013-08-28 20:50 - 00030083 _____ C:\Dokumente und Einstellungen\Nutzer\Desktop\Addition.txt
2013-08-28 20:49 - 2013-08-28 20:49 - 00000000 ____D C:\FRST
2013-08-28 20:48 - 2013-08-28 20:48 - 01072975 _____ (Farbar) C:\Dokumente und Einstellungen\Nutzer\Desktop\FRST.exe
==================== One Month Modified Files and Folders =======
2013-08-29 14:56 - 2013-04-24 22:32 - 00740994 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-29 14:56 - 2012-02-13 16:16 - 00001090 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-29 14:56 - 2011-07-26 16:09 - 00000000 ___HD C:\WINDOWS\$hf_mig$
2013-08-29 14:55 - 2013-08-29 14:55 - 00004404 _____ C:\WINDOWS\KB2780091.log
2013-08-29 14:55 - 2013-08-29 14:55 - 00004403 _____ C:\WINDOWS\KB2845187.log
2013-08-29 14:54 - 2013-08-29 14:54 - 00004299 _____ C:\WINDOWS\KB2850869.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004632 _____ C:\WINDOWS\KB2859537.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004203 _____ C:\WINDOWS\KB2820917.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004107 _____ C:\WINDOWS\KB2757638.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00004003 _____ C:\WINDOWS\KB2749655.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00003900 _____ C:\WINDOWS\KB2727528.log
2013-08-29 14:53 - 2013-08-29 14:53 - 00003197 _____ C:\Dokumente und Einstellungen\Nutzer\Desktop\JRT.txt
2013-08-29 14:53 - 2012-09-06 09:36 - 00000386 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-08-29 14:52 - 2013-08-29 14:52 - 00004141 _____ C:\WINDOWS\KB2813345.log
2013-08-29 14:52 - 2013-08-29 14:52 - 00003846 _____ C:\WINDOWS\KB2661254-v2.log
2013-08-29 14:52 - 2013-08-29 14:52 - 00000000 ____D C:\WINDOWS\LastGood
2013-08-29 14:50 - 2013-08-29 14:50 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-29 14:48 - 2013-08-29 14:48 - 01023533 _____ (Thisisu) C:\Dokumente und Einstellungen\Nutzer\Desktop\JRT.exe
2013-08-29 14:47 - 2011-07-25 19:49 - 01210632 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-29 14:46 - 2013-08-29 14:46 - 00000000 __SHD C:\Dokumente und Einstellungen\Nutzer\IECompatCache
2013-08-29 14:46 - 2011-07-27 12:47 - 00000000 ____D C:\Programme\Steam
2013-08-29 14:46 - 2011-07-26 09:12 - 00000000 ____D C:\Dokumente und Einstellungen\Nutzer
2013-08-29 14:45 - 2012-12-24 11:44 - 00000280 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1078081533-2025429265-839522115-1004.job
2013-08-29 14:45 - 2012-12-24 11:44 - 00000272 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1078081533-2025429265-839522115-1004.job
2013-08-29 14:45 - 2012-09-04 14:31 - 00000272 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1078081533-2025429265-839522115-1004.job
2013-08-29 14:43 - 2013-03-10 00:49 - 00000294 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1078081533-2025429265-839522115-1004.job
2013-08-29 14:43 - 2012-12-17 11:22 - 00000308 _____ C:\WINDOWS\Tasks\GlaryInitialize.job
2013-08-29 14:43 - 2012-02-13 16:16 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-29 14:43 - 2011-07-26 08:18 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-29 14:43 - 2011-07-25 19:51 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-29 14:43 - 2011-07-25 19:51 - 00000000 _____ C:\WINDOWS\wiaservc.log
2013-08-29 14:42 - 2013-08-29 14:41 - 00000000 ____D C:\AdwCleaner
2013-08-29 14:42 - 2011-07-27 08:57 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-08-29 14:42 - 2011-07-26 09:12 - 00000190 ___SH C:\Dokumente und Einstellungen\Nutzer\ntuser.ini
2013-08-29 14:42 - 2011-07-26 08:18 - 00032366 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-29 14:42 - 2011-07-25 19:49 - 00000000 ___RD C:\Programme
2013-08-29 14:40 - 2013-08-29 14:39 - 00994642 _____ C:\Dokumente und Einstellungen\Nutzer\Desktop\adwcleaner.exe
2013-08-29 14:33 - 2013-04-24 23:32 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-29 14:32 - 2013-08-29 14:32 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 14:32 - 2013-08-29 14:32 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-29 14:32 - 2013-08-29 14:32 - 00000000 ____D C:\Dokumente und Einstellungen\Nutzer\Anwendungsdaten\Malwarebytes
2013-08-29 14:31 - 2013-08-29 14:31 - 10285040 _____ (Malwarebytes Corporation ) C:\Dokumente und Einstellungen\Nutzer\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-29 14:18 - 2013-08-29 14:18 - 00024916 _____ C:\ComboFix.txt
2013-08-29 14:18 - 2013-08-29 14:08 - 00000000 ____D C:\Qoobox
2013-08-29 14:17 - 2013-08-29 14:08 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-29 14:17 - 2011-07-26 09:12 - 00000000 ___RD C:\Dokumente und Einstellungen\Nutzer\Startmenü\Programme\Autostart
2013-08-29 14:17 - 2004-08-04 14:00 - 00000227 _____ C:\WINDOWS\system.ini
2013-08-29 14:11 - 2013-08-29 14:10 - 00000000 _RSHD C:\cmdcons
2013-08-29 14:11 - 2011-07-25 20:47 - 00000327 __RSH C:\boot.ini
2013-08-29 14:08 - 2013-08-29 14:08 - 00000000 ___RD C:\Dokumente und Einstellungen\Nutzer\Startmenü\Programme\Verwaltung
2013-08-29 14:08 - 2011-07-26 09:12 - 00000000 ___RD C:\Dokumente und Einstellungen\Nutzer\Startmenü\Programme
2013-08-29 14:07 - 2013-08-29 14:07 - 05115711 ____R (Swearware) C:\Dokumente und Einstellungen\Nutzer\Desktop\ComboFix.exe
2013-08-29 14:07 - 2013-01-27 17:16 - 00000420 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{5985ECB6-4083-456B-8454-6635CE3EED9A}.job
2013-08-28 20:50 - 2013-08-28 20:50 - 00030083 _____ C:\Dokumente und Einstellungen\Nutzer\Desktop\Addition.txt
2013-08-28 20:49 - 2013-08-28 20:49 - 00000000 ____D C:\FRST
2013-08-28 20:48 - 2013-08-28 20:48 - 01072975 _____ (Farbar) C:\Dokumente und Einstellungen\Nutzer\Desktop\FRST.exe
2013-08-28 20:36 - 2004-08-04 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-26 02:22 - 2013-06-22 00:40 - 01632768 ___SH C:\Dokumente und Einstellungen\Nutzer\Eigene Dateien\Thumbs.db
2013-08-22 13:48 - 2013-01-05 18:20 - 00000302 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1078081533-2025429265-839522115-1004.job
2013-08-19 10:39 - 2012-04-23 21:39 - 00000280 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1078081533-2025429265-839522115-1004.job
2013-08-16 00:13 - 2013-05-05 05:38 - 00012933 _____ C:\WINDOWS\wmsetup.log
2013-08-12 21:06 - 2012-06-12 16:37 - 00000276 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-31 19:57 - 2011-08-09 22:16 - 00000000 ____D C:\Programme\Google
ZeroAccess:
C:\Windows\Installer\{652707bf-940f-6cc9-12aa-5c5191aa4aee}
C:\Windows\Installer\{652707bf-940f-6cc9-12aa-5c5191aa4aee}\L\00000004.@
C:\Windows\Installer\{652707bf-940f-6cc9-12aa-5c5191aa4aee}\L\201d3dde
C:\Windows\Installer\{652707bf-940f-6cc9-12aa-5c5191aa4aee}\L\55490ac4
Files to move or delete:
====================
C:\DOKUME~1\Nutzer\LOKALE~1\Temp\Quarantine.exe
C:\DOKUME~1\Nutzer\LOKALE~1\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-08-04 14:00] - [2008-04-14 07:52] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2004-08-04 14:00] - [2008-04-14 07:53] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2004-08-04 14:00] - [2008-04-14 07:53] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2004-08-04 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2004-08-04 14:00] - [2008-04-14 07:52] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2004-08-04 14:00] - [2008-04-14 07:53] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2004-08-04 14:00] - [2008-04-14 07:22] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
und wie sieht es jetzt bei dem pc aus?