This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

dns.exe trojaner removal [Closed] [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

we have actually a infected Windows 2008 Small Business Server. We have since a few days a very high network load, depending on the service dns.exe. And the Virus Scanner is no more active.

Attached is the Hijack log file. If you need more info, please send me a short info.

Thanks very much for your help!

Stefan


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:53:35, on 24.06.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16490)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\funkwerk WIN-Tools\Eumex 401 WIN-Tools V1.00\ControlCenter.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\stefanrother\Downloads\HiJackThis204.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default….;l=de&s=gen
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default….;l=de&s=gen
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - Global Startup: Control Center.lnk = C:\Program Files (x86)\funkwerk WIN-Tools\Eumex 401 WIN-Tools V1.00\ControlCenter.exe
O4 - Global Startup: MozyPro Status.lnk = C:\Program Files\MozyPro\mozyprostat.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://blogs.technet.com
O15 - ESC Trusted Zone: http://dl.cdn.chip.de
O15 - ESC Trusted Zone: http://www.chip.de
O15 - ESC Trusted Zone: http://mozilla.cdn.leaseweb.com
O15 - ESC Trusted Zone: http://www.mozilla.org
O15 - ESC Trusted Zone: http://*.mozy.com
O15 - ESC Trusted Zone: http://*.mozypro.com
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://downloadeu2.teamviewer.com
O15 - ESC Trusted Zone: http://www.teamviewer.com
O15 - ESC Trusted Zone: http://blogs.technet.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com
O15 - ESC Trusted Zone: http://runonce.msn.com (HKLM)
O15 - ESC Trusted Zone: http://*.windowsupdate.com (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = passreiter.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD76BC8B-31F4-47DB-B9F8-6151AE41DFCC}: NameServer = 192.168.2.253,8.8.8.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = passreiter.local
O17 - HKLM\System\CS1\Services\Tcpip\..\{AD76BC8B-31F4-47DB-B9F8-6151AE41DFCC}: NameServer = 192.168.2.253,8.8.8.8
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = passreiter.local
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apache2.2 - Apache Software Foundation - D:\Program Files (x86)\xampp\xampp\apache\bin\httpd.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: @%systemroot%\system32\certocm.dll,-347 (CertSvc) - Unknown owner - C:\Windows\system32\certsrv.exe (file missing)
O23 - Service: @%systemroot%\system32\dfssvc.exe,-101 (Dfs) - Unknown owner - C:\Windows\system32\dfssvc.exe (file missing)
O23 - Service: @dfsrress.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSRs.exe (file missing)
O23 - Service: @%systemroot%\system32\dns.exe,-49157 (DNS) - Unknown owner - C:\Windows\system32\dns.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30007 (IISADMIN) - Unknown owner - C:\Windows\system32\inetsrv\inetinfo.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ismserv.exe,-1 (IsmServ) - Unknown owner - C:\Windows\System32\ismserv.exe (file missing)
O23 - Service: @%SystemRoot%\System32\kdcsvc.dll,-1 (kdc) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MozyPro Backupdienst (mozyprobackup) - Mozy, Inc. - C:\Program Files\MozyPro\mozyprobackup.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\Windows\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ntdsmsg.dll,-1 (NTDS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Dateireplikationsdienst (NtFrs) - Unknown owner - C:\Windows\system32\ntfrs.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%Systemroot%\system32\rqs.exe,-200 (rqs) - Unknown owner - C:\Windows\system32\rqs.exe (file missing)
O23 - Service: @gpapi.dll,-114 (RSoPProv) - Unknown owner - C:\Windows\system32\RSoPProv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%windir%\system32\srm.dll,-3022 (SrmReports) - Unknown owner - C:\Windows\system32\srmhost.exe (file missing)
O23 - Service: TRANSDATA Gbak Scheduler (TdGbakScheduler) - Unknown owner - C:\Program Files (x86)\TRANSDATA\TdGbakScheduler\TdGBAKScheduler.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-20001 (WMSVC) - Unknown owner - C:\Windows\system32\inetsrv\wmsvc.exe (file missing)

–
End of file - 8437 bytes
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Download DDS and save it to your desktop from here or here or
here.

Disable any script blocker, and then double click dds.scr to run the tool.

When done, DDS will open two (2) logs
DDS.txt
Attach.txt
Save both reports to your desktop.




Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Marius, first of all, thanks very much for your help! I can´t execute any of the dds scripts, the error message say: The operation system is not supported! DDS only runs on: *All Windows clients* So I think it is not the right script for MS SBS 2011? Thanks very much for your help! Stefan
Maybe… let´s try something else:


Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.
Hi Marius,

again, thanks for your help!

FRST.txt:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2013
Ran by [removed] (administrator) on 24-06-2013 19:55:33
Running from C:\Users\[removed]\Downloads
Windows Small Business Server 2011 Standard Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\LogonUI.exe
(Microsoft Corporation) C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe
(Apache Software Foundation) D:\Program Files (x86)\xampp\xampp\apache\bin\httpd.exe
(Microsoft Corporation) C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe
(Microsoft Corporation) C:\Windows\system32\certsrv.exe
(Microsoft Corporation) C:\Windows\system32\DFSRs.exe
(Microsoft Corporation) C:\Windows\system32\dns.exe
(Firebird Project) C:\Program Files\Firebird\bin\fbguard.exe
(Microsoft Corporation) C:\Windows\system32\inetsrv\inetinfo.exe
(Microsoft Corporation) C:\Windows\System32\ismserv.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeADTopologyService.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\ExFBA.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\store.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeMailboxAssistants.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeMailSubmission.exe
(Apache Software Foundation) D:\Program Files (x86)\xampp\xampp\apache\bin\httpd.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.ProtectedServiceHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\msexchangerepl.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.RpcClientAccess.Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\mad.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeThrottling.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeTransport.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeTransportLogSearch.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\edgetransport.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\msftesql.exe
(Microsoft Corporation) C:\Windows\system32\mqsvc.exe
(Microsoft Corporation) C:\Windows\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SBSMONITORING\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\agents\Hygiene\Microsoft.Exchange.ContentFilter.Wrapper.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SHAREPOINT\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\system32\ntfrs.exe
(Microsoft Corporation) C:\Windows\system32\silsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\WSSADMIN.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\wsstracing.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\TRANSDATA\TdGbakScheduler\TdGBAKScheduler.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Update Services\Service\bin\WsusService.exe
(Microsoft Corporation) C:\Program Files\Windows Small Business Server\Bin\DataCollectorSvc.exe
(Microsoft Corporation) C:\Windows\system32\dfssvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.AddressBook.Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.AntispamUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.EdgeSyncSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeFDS.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeMailboxReplication.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.Search.ExSearch.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\OWSTIMER.EXE
(Microsoft Corporation) C:\Windows\system32\iashost.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SHAREPOINT\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SHAREPOINT\MSSQL\Binn\fdhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SBSMONITORING\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SBSMONITORING\MSSQL\Binn\fdhost.exe
(Firebird Project) C:\Program Files\Firebird\bin\fbserver.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\UserCode\SPUCHostService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\usercode\SPUCWorkerProcessProxy.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\usercode\SPUCWorkerProcess.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Funkwerk Enterprise Communications GmbH) C:\Program Files (x86)\funkwerk WIN-Tools\Eumex 401 WIN-Tools V1.00\ControlCenter.exe
(Mozy, Inc.) C:\Program Files\MozyPro\mozyprobackup.exe
(Mozy, Inc.) C:\Program Files\MozyPro\mozyprobackup.exe
(Mozy, Inc.) C:\Program Files\MozyPro\mozyprobackup.exe
(Microsoft Corporation) C:\Windows\system32\srmhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\mssearch.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\bin\mssdmn.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) C:\Windows\system32\taskmgr.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Microsoft Corporation) c:\windows\system32\inetsrv\w3wp.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Enigma Software Group USA, LLC.) C:\PROGRA~1\Enigma Software Group\SpyHunter\SH4Service.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Exchange Server\V14\Bin\MsFTEFD.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [DWPersistentQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE -a [629664 2010-12-21] (Microsoft Corporation)
Lsa: [Notification Packages] scecli rassfm
Startup: C:\ProgramData\Start Menu\Programs\Startup\Control Center.lnk
ShortcutTarget: Control Center.lnk -> C:\Program Files (x86)\funkwerk WIN-Tools\Eumex 401 WIN-Tools V1.00\ControlCenter.exe (Funkwerk Enterprise Communications GmbH)
Startup: C:\ProgramData\Start Menu\Programs\Startup\MozyPro Status.lnk
ShortcutTarget: MozyPro Status.lnk -> C:\Program Files\MozyPro\mozyprostat.exe (Mozy, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default….;l=de&s;=gen
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default….;l=de&s;=gen
Tcpip\..\Interfaces\{AD76BC8B-31F4-47DB-B9F8-6151AE41DFCC}: [NameServer]8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.5
6.26,8.20.247.20,156.154.70.1,156.154.71.1

FireFox:
========
FF ProfilePath: C:\Users\stefanrother\AppData\Roaming\Mozilla\Firefox\Profiles\vtclenu5.default
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Bitdefender QuickScan - C:\Users\stefanrother\AppData\Roaming\Mozilla\Firefox\Profiles\vtclenu5.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360}

==================== Services (Whitelisted) =================

R2 ADWS; C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe [487424 2010-11-20] (Microsoft Corporation)
R2 Apache2.2; D:\Program Files (x86)\xampp\xampp\apache\bin\httpd.exe [29416 2009-12-20] (Apache Software Foundation)
R2 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
R2 CertSvc; C:\Windows\system32\certsrv.exe [746496 2009-07-14] (Microsoft Corporation)
R2 DataCollectorSvc; C:\Program Files\Windows Small Business Server\Bin\DataCollectorSvc.exe [72096 2010-11-08] (Microsoft Corporation)
S4 ddnsclient; C:\Program Files\Windows Small Business Server\Bin\DDnsClient.exe [48544 2010-11-08] (Microsoft Corporation)
R2 Dfs; C:\Windows\system32\dfssvc.exe [377344 2010-11-20] (Microsoft Corporation)
R2 DFSR; C:\Windows\system32\DFSRs.exe [4518400 2010-11-20] (Microsoft Corporation)
R2 DHCPServer; C:\Windows\System32\dhcpssvc.dll [729088 2010-11-20] (Microsoft Corporation)
R2 DNS; C:\Windows\system32\dns.exe [696832 2011-12-26] (Microsoft Corporation)
S3 FCRegSvc; C:\Windows\system32\FCRegSvc.dll [25600 2009-07-14] (Microsoft Corporation)
R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [155136 2011-10-03] (Firebird Project)
R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [5683712 2011-10-03] (Firebird Project)
R2 IAS; C:\Windows\System32\ias.dll [26624 2009-07-14] (Microsoft Corporation)
R2 IAS; C:\Windows\SysWow64\ias.dll [19456 2009-07-14] (Microsoft Corporation)
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation)
R2 IsmServ; C:\Windows\System32\ismserv.exe [59392 2010-11-20] (Microsoft Corporation)
R2 kdc; C:\Windows\System32\lsass.exe [31232 2011-11-17] (Microsoft Corporation)
R2 mozyprobackup; C:\Program Files\MozyPro\mozyprobackup.exe [54632 2012-02-07] (Mozy, Inc.)
R2 MSExchangeAB; C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.AddressBook.Service.exe [151144 2012-11-30] (Microsoft Corporation)
R2 MSExchangeADTopology; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeADTopologyService.exe [113720 2012-11-30] (Microsoft Corporation)
R2 MSExchangeAntispamUpdate; C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.AntispamUpdateSvc.exe [44640 2012-11-30] (Microsoft Corporation)
R2 MSExchangeEdgeSync; C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.EdgeSyncSvc.exe [114240 2012-11-30] (Microsoft Corporation)
R2 MSExchangeFBA; C:\Program Files\Microsoft\Exchange Server\V14\Bin\ExFBA.exe [110560 2012-11-30] (Microsoft Corporation)
R2 MSExchangeFDS; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeFDS.exe [110080 2012-11-30] (Microsoft Corporation)
S3 MSExchangeImap4; C:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\PopImap\Microsoft.Exchange.Imap4Service.exe [28752 2012-11-30] (Microsoft Corporation)
R2 MSExchangeIS; C:\Program Files\Microsoft\Exchange Server\V14\bin\store.exe [6906848 2012-11-30] (Microsoft Corporation)
R2 MSExchangeMailboxAssistants; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeMailboxAssistants.exe [765512 2012-11-30] (Microsoft Corporation)
R2 MSExchangeMailboxReplication; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeMailboxReplication.exe [27200 2012-11-30] (Microsoft Corporation)
R2 MSExchangeMailSubmission; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeMailSubmission.exe [118320 2012-11-30] (Microsoft Corporation)
S3 MSExchangeMonitoring; C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.Monitoring.exe [73296 2012-11-30] (Microsoft Corporation)
S3 MSExchangePop3; C:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\PopImap\Microsoft.Exchange.Pop3Service.exe [28744 2012-11-30] (Microsoft Corporation)
R2 MSExchangeProtectedServiceHost; C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.ProtectedServiceHost.exe [32368 2012-11-30] (Microsoft Corporation)
R2 MSExchangeRepl; C:\Program Files\Microsoft\Exchange Server\V14\bin\msexchangerepl.exe [69128 2012-11-30] (Microsoft Corporation)
R2 MSExchangeRPC; C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.RpcClientAccess.Service.exe [89728 2012-11-30] (Microsoft Corporation)
R2 MSExchangeSA; C:\Program Files\Microsoft\Exchange Server\V14\bin\mad.exe [1368536 2012-11-30] (Microsoft Corporation)
R2 MSExchangeSearch; C:\Program Files\Microsoft\Exchange Server\V14\Bin\Microsoft.Exchange.Search.ExSearch.exe [413272 2012-11-30] (Microsoft Corporation)
R2 MSExchangeServiceHost; C:\Program Files\Microsoft\Exchange Server\V14\bin\Microsoft.Exchange.ServiceHost.exe [35400 2012-11-30] (Microsoft Corporation)
R2 MSExchangeThrottling; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeThrottling.exe [48664 2012-11-30] (Microsoft Corporation)
R2 MSExchangeTransport; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeTransport.exe [81432 2012-11-30] (Microsoft Corporation)
R2 MSExchangeTransportLogSearch; C:\Program Files\Microsoft\Exchange Server\V14\Bin\MSExchangeTransportLogSearch.exe [212536 2012-11-30] (Microsoft Corporation)
R3 msftesql-Exchange; C:\Program Files\Microsoft\Exchange Server\V14\Bin\msftesql.exe [183728 2010-07-31] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R2 MSSQL$MICROSOFT##SSEE; C:\Windows\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn\sqlservr.exe [39627104 2010-12-10] (Microsoft Corporation)
R2 MSSQL$SBSMONITORING; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SBSMONITORING\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation)
R2 MSSQL$SHAREPOINT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SHAREPOINT\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation)
R2 NTDS; C:\Windows\System32\lsass.exe [31232 2011-11-17] (Microsoft Corporation)
R2 NtFrs; C:\Windows\system32\ntfrs.exe [1020416 2010-11-20] (Microsoft Corporation)
S4 Pop3Connector; C:\Program Files\Windows Small Business Server\Bin\Pop3Connector.exe [240032 2010-11-08] (Microsoft Corporation)
R3 RPCHTTPLBS; C:\Windows\System32\RpcProxy\LBService.dll [24576 2010-11-20] (Microsoft Corporation)
S3 rqs; C:\Windows\system32\rqs.exe [41472 2010-11-20] (Microsoft Corporation)
S3 RSoPProv; C:\Windows\system32\RSoPProv.exe [91648 2009-07-14] (Microsoft Corporation)
S3 sacsvr; C:\Windows\system32\sacsvr.dll [14848 2009-07-14] (Microsoft Corporation)
R2 SPAdminV4; C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\WSSADMIN.EXE [16552 2012-08-29] (Microsoft Corporation)
R3 SPSearch4; C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\mssearch.exe [524616 2012-01-18] (Microsoft Corporation)
R2 SPTimerV4; C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\OWSTIMER.EXE [74912 2013-03-07] (Microsoft Corporation)
R2 SPTraceV4; C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\wsstracing.exe [108664 2012-06-08] (Microsoft Corporation)
R2 SPUserCodeV4; C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\UserCode\SPUCHostService.exe [108496 2011-05-22] (Microsoft Corporation)
S4 SPWriterV4; C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\SPWRITER.EXE [42616 2012-08-29] (Microsoft Corporation)
R2 SpyHunter 4 Service; C:\PROGRA~1\Enigma Software Group\SpyHunter\SH4Service.exe [1025408 2013-05-07] (Enigma Software Group USA, LLC.)
S4 SQLAgent$SBSMONITORING; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SBSMONITORING\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation)
S4 SQLAgent$SHAREPOINT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SHAREPOINT\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation)
R3 SrmReports; C:\Windows\system32\srmhost.exe [76288 2010-11-20] (Microsoft Corporation)
R2 SrmSvc; C:\Windows\system32\srmsvc.dll [3489792 2010-11-20] (Microsoft Corporation)
R2 TdGbakScheduler; C:\Program Files (x86)\TRANSDATA\TdGbakScheduler\TdGBAKScheduler.exe [1941008 2011-02-18] ()
R2 TSGateway; C:\Windows\system32\aaedge.dll [306688 2010-11-20] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S3 WMSVC; C:\Windows\system32\inetsrv\wmsvc.exe [10752 2009-07-14] (Microsoft Corporation)
S3 wsbexchange; C:\Program Files\Microsoft\Exchange Server\V14\bin\wsbexchange.exe [130552 2012-11-30] (Microsoft Corporation)
S3 WSusCertServer; C:\Program Files\Update Services\Service\bin\WsusCertServer.exe [77608 2012-06-07] (Microsoft Corporation)
R2 WsusService; C:\Program Files\Update Services\Service\bin\WsusService.exe [34720 2009-08-06] (Microsoft Corporation)
R3 MSSQLFDLauncher$SBSMONITORING; "C:\Program Files\Microsoft SQL Server\MSSQL10_50.SBSMONITORING\MSSQL\Binn\fdlauncher.exe" -s MSSQL10_50.SBSMONITORING [x]
R3 MSSQLFDLauncher$SHAREPOINT; "C:\Program Files\Microsoft SQL Server\MSSQL10_50.SHAREPOINT\MSSQL\Binn\fdlauncher.exe" -s MSSQL10_50.SHAREPOINT [x]

==================== Drivers (Whitelisted) ====================

S3 b06diag; C:\Windows\system32\DRIVERS\bxdiaga.sys [88104 2011-09-02] (Broadcom Corporation)
R3 bccfg; C:\Windows\System32\DRIVERS\bccfg.sys [22256 2011-01-10] (Dell Inc.)
R0 bcraid; C:\Windows\System32\DRIVERS\bcraid.sys [557808 2011-01-10] (Dell Inc.)
S3 bxfcoe; C:\Windows\system32\DRIVERS\bxfcoe.sys [174632 2011-11-10] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\DRIVERS\bxois.sys [538664 2011-10-24] (Broadcom Corporation)
R0 Datascrn; C:\Windows\System32\drivers\datascrn.sys [79936 2009-07-14] (Microsoft Corporation)
R1 DfsDriver; C:\Windows\System32\drivers\dfs.sys [51776 2009-07-14] (Microsoft Corporation)
R0 DfsrRo; C:\Windows\System32\drivers\dfsrro.sys [66944 2010-11-20] (Microsoft Corporation)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] ()
R3 G200ew; C:\Windows\System32\DRIVERS\g200ewm.sys [242176 2009-07-31] (Matrox Graphics Inc.)
S3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
R1 mozyproFilter; C:\Windows\System32\DRIVERS\mozypro.sys [67328 2012-02-07] (Mozy, Inc.)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R0 Quota; C:\Windows\System32\drivers\quota.sys [168016 2009-07-14] (Microsoft Corporation)
S0 sacdrv; C:\Windows\System32\DRIVERS\sacdrv.sys [96320 2009-07-14] (Microsoft Corporation)
R3 VMSMP; C:\Windows\System32\DRIVERS\vmswitch.sys [410624 2010-11-20] (Microsoft Corporation)
S3 VMSP; C:\Windows\System32\DRIVERS\vmswitch.sys [410624 2010-11-20] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)

==================== One Month Created Files and Folders ========

2013-06-24 19:55 - 2013-06-24 19:55 - 00000000 ____D C:\FRST
2013-06-24 19:54 - 2013-06-24 19:54 - 01931364 ____A (Farbar) C:\Users\stefanrother\Downloads\FRST64.exe
2013-06-24 19:45 - 2013-06-24 19:46 - 00377856 ____A C:\Users\stefanrother\Downloads\u2hckgtn.exe
2013-06-24 19:33 - 2013-06-24 19:36 - 00688992 ____A (Swearware) C:\Users\stefanrother\Downloads\dds.com
2013-06-24 19:31 - 2013-06-24 19:31 - 00688992 ____A (Swearware) C:\Users\stefanrother\Downloads\dds.scr
2013-06-24 19:13 - 2013-06-24 19:17 - 86759696 ____A (Microsoft Corporation) C:\Users\stefanrother\Downloads\msert.exe
2013-06-24 18:41 - 2013-06-24 18:41 - 00002288 ____A C:\Users\stefanrother\Desktop\SpyHunter.lnk
2013-06-24 18:41 - 2013-06-24 18:41 - 00000000 ____D C:\sh4ldr
2013-06-24 18:41 - 2013-06-24 18:41 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-06-24 18:41 - 2013-06-24 18:41 - 00000000 ____A C:\autoexec.bat
2013-06-24 18:41 - 2012-06-22 12:01 - 00022704 ____A C:\Windows\System32\Drivers\EsgScanner.sys
2013-06-24 18:40 - 2013-06-24 18:41 - 00000000 ____D C:\Windows\E63D89610BA94CF39E94407ACA42846C.TMP
2013-06-24 18:34 - 2013-06-24 18:36 - 00728960 ____A (Enigma Software Group USA, LLC.) C:\Users\stefanrother\Downloads\SpyHunter-Installer.exe
2013-06-24 17:56 - 2013-06-24 17:56 - 00000020 __ASH C:\Users\TEMP.PASSREITER.008\ntuser.ini
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Vorlagen
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Startmenü
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Netzwerkumgebung
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Lokale Einstellungen
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Eigene Dateien
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Druckumgebung
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Documents\Eigene Musik
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Documents\Eigene Bilder
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\AppData\Local\Verlauf
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\AppData\Local\Anwendungsdaten
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Anwendungsdaten
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 ____D C:\users\TEMP.PASSREITER.008
2013-06-24 17:56 - 2012-09-29 01:29 - 00000000 ____D C:\Users\TEMP.PASSREITER.008\Documents\Visual Studio 2008
2013-06-24 17:56 - 2012-09-29 00:52 - 00000000 ____D C:\Users\TEMP.PASSREITER.008\Documents\Visual Studio 2005
2013-06-24 17:56 - 2012-09-29 00:52 - 00000000 ____D C:\Users\TEMP.PASSREITER.008\AppData\Local\Microsoft Help
2013-06-24 17:42 - 2013-06-24 17:42 - 00007607 ____A C:\Users\stefanrother\AppData\Local\Resmon.ResmonCfg
2013-06-24 17:20 - 2013-06-24 17:25 - 13503464 ____A (Microsoft Corporation) C:\Users\stefanrother\Downloads\mseinstall.exe
2013-06-24 16:39 - 2013-06-24 16:41 - 00000000 ____D C:\Users\stefanrother\AppData\Roaming\QuickScan
2013-06-24 16:17 - 2013-06-24 16:17 - 00008438 ____A C:\Users\stefanrother\Downloads\hijackthis-1.txt
2013-06-24 15:53 - 2013-06-24 16:56 - 00008686 ____A C:\Users\stefanrother\Downloads\hijackthis.log
2013-06-24 15:52 - 2013-06-24 15:52 - 00388608 ____A (Trend Micro Inc.) C:\Users\stefanrother\Downloads\HiJackThis204.exe
2013-06-24 11:40 - 2013-06-24 11:40 - 00007656 ____A C:\Users\marcelamberg\AppData\Local\Resmon.ResmonCfg
2013-06-12 00:25 - 2013-06-24 07:56 - 00000000 ____D C:\users\TEMP.PASSREITER.007
2013-06-12 00:04 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 00:04 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 00:04 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 00:04 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 00:04 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 00:04 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 00:04 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 00:04 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 00:04 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 00:04 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 00:03 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 00:00 - 2013-05-17 06:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 00:00 - 2013-05-17 05:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 00:00 - 2013-05-17 05:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 00:00 - 2013-05-17 05:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 00:00 - 2013-05-17 05:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 00:00 - 2013-05-17 05:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-06-12 00:00 - 2013-05-17 05:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-06-12 00:00 - 2013-05-17 04:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 00:00 - 2013-05-17 04:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-06-12 00:00 - 2013-05-17 04:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-06-12 00:00 - 2013-05-17 04:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 00:00 - 2013-05-17 04:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 00:00 - 2013-05-17 04:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 00:00 - 2013-05-17 04:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 00:00 - 2013-05-17 04:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-06-12 00:00 - 2013-05-17 04:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 00:00 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 00:00 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 00:00 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 00:00 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 00:00 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 00:00 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-06-12 00:00 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-06-12 00:00 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 00:00 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 00:00 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-06-12 00:00 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-06-12 00:00 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 00:00 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 00:00 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-06-12 00:00 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 00:00 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 00:00 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 00:00 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll

==================== One Month Modified Files and Folders =======

2013-06-24 19:55 - 2013-06-24 19:55 - 00000000 ____D C:\FRST
2013-06-24 19:54 - 2013-06-24 19:54 - 01931364 ____A (Farbar) C:\Users\stefanrother\Downloads\FRST64.exe
2013-06-24 19:48 - 2010-11-20 05:32 - 00000000 ____D C:\Windows\System32\dhcp
2013-06-24 19:46 - 2013-06-24 19:45 - 00377856 ____A C:\Users\stefanrother\Downloads\u2hckgtn.exe
2013-06-24 19:36 - 2013-06-24 19:33 - 00688992 ____A (Swearware) C:\Users\stefanrother\Downloads\dds.com
2013-06-24 19:31 - 2013-06-24 19:31 - 00688992 ____A (Swearware) C:\Users\stefanrother\Downloads\dds.scr
2013-06-24 19:17 - 2013-06-24 19:13 - 86759696 ____A (Microsoft Corporation) C:\Users\stefanrother\Downloads\msert.exe
2013-06-24 19:04 - 2012-05-08 02:58 - 01670496 ____A C:\Windows\WindowsUpdate.log
2013-06-24 18:41 - 2013-06-24 18:41 - 00002288 ____A C:\Users\stefanrother\Desktop\SpyHunter.lnk
2013-06-24 18:41 - 2013-06-24 18:41 - 00000000 ____D C:\sh4ldr
2013-06-24 18:41 - 2013-06-24 18:41 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-06-24 18:41 - 2013-06-24 18:41 - 00000000 ____A C:\autoexec.bat
2013-06-24 18:41 - 2013-06-24 18:40 - 00000000 ____D C:\Windows\E63D89610BA94CF39E94407ACA42846C.TMP
2013-06-24 18:40 - 2013-05-14 13:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-24 18:39 - 2012-06-15 14:06 - 00000000 ____D C:\Users\Public\Passreiter-Logistik
2013-06-24 18:39 - 2012-06-11 09:36 - 00000000 ____D C:\ProgramData\firebird
2013-06-24 18:36 - 2013-06-24 18:34 - 00728960 ____A (Enigma Software Group USA, LLC.) C:\Users\stefanrother\Downloads\SpyHunter-Installer.exe
2013-06-24 18:24 - 2012-06-07 12:12 - 00006496 ____A C:\Windows\System32\config\netlogon.dnb
2013-06-24 18:24 - 2012-06-07 12:12 - 00002401 ____A C:\Windows\System32\config\netlogon.dns
2013-06-24 18:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Registration
2013-06-24 17:57 - 2009-07-14 06:49 - 00017808 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-24 17:57 - 2009-07-14 06:49 - 00017808 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-24 17:56 - 2013-06-24 17:56 - 00000020 __ASH C:\Users\TEMP.PASSREITER.008\ntuser.ini
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Vorlagen
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Startmenü
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Netzwerkumgebung
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Lokale Einstellungen
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Eigene Dateien
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Druckumgebung
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Documents\Eigene Musik
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Documents\Eigene Bilder
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\AppData\Local\Verlauf
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\AppData\Local\Anwendungsdaten
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 __SHD C:\Users\TEMP.PASSREITER.008\Anwendungsdaten
2013-06-24 17:56 - 2013-06-24 17:56 - 00000000 ____D C:\users\TEMP.PASSREITER.008
2013-06-24 17:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\inetsrv
2013-06-24 17:48 - 2012-06-07 12:14 - 00000000 ____D C:\Windows\System32\CertLog
2013-06-24 17:48 - 2012-06-07 12:05 - 00000000 ____D C:\Windows\System32\dns
2013-06-24 17:47 - 2012-06-07 12:06 - 00000000 ____D C:\Windows\ntds
2013-06-24 17:47 - 2009-07-14 07:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-24 17:42 - 2013-06-24 17:42 - 00007607 ____A C:\Users\stefanrother\AppData\Local\Resmon.ResmonCfg
2013-06-24 17:25 - 2013-06-24 17:20 - 13503464 ____A (Microsoft Corporation) C:\Users\stefanrother\Downloads\mseinstall.exe
2013-06-24 17:25 - 2013-01-22 10:49 - 00002162 ____A C:\Windows\epplauncher.mif
2013-06-24 17:00 - 2012-06-07 21:40 - 00000000 ____D C:\Users\Public\Scan
2013-06-24 16:56 - 2013-06-24 15:53 - 00008686 ____A C:\Users\stefanrother\Downloads\hijackthis.log
2013-06-24 16:56 - 2012-06-07 13:07 - 00000000 ____D C:\Users\stefanrother\AppData\Local\VirtualStore
2013-06-24 16:41 - 2013-06-24 16:39 - 00000000 ____D C:\Users\stefanrother\AppData\Roaming\QuickScan
2013-06-24 16:37 - 2012-06-11 10:52 - 00000000 ____D C:\Users\Public\KomalogDokumente
2013-06-24 16:17 - 2013-06-24 16:17 - 00008438 ____A C:\Users\stefanrother\Downloads\hijackthis-1.txt
2013-06-24 15:52 - 2013-06-24 15:52 - 00388608 ____A (Trend Micro Inc.) C:\Users\stefanrother\Downloads\HiJackThis204.exe
2013-06-24 15:46 - 2013-04-06 15:37 - 00000000 ____D C:\Windows\System32\FxsTmp
2013-06-24 13:57 - 2013-02-20 18:40 - 00000000 ____D C:\Users\marcelamberg\Desktop\Daten
2013-06-24 13:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-24 12:00 - 2012-06-07 12:14 - 00000362 ____A C:\Windows\Tasks\Schattenkopie-Zeitplan für Datenträgerlaufwerk D.job
2013-06-24 12:00 - 2012-06-07 12:14 - 00000362 ____A C:\Windows\Tasks\Schattenkopie-Zeitplan für Datenträgerlaufwerk C.job
2013-06-24 11:40 - 2013-06-24 11:40 - 00007656 ____A C:\Users\marcelamberg\AppData\Local\Resmon.ResmonCfg
2013-06-24 07:56 - 2013-06-12 00:25 - 00000000 ____D C:\users\TEMP.PASSREITER.007
2013-06-23 00:33 - 2012-06-07 12:51 - 00000000 ____D C:\users\spsearch
2013-06-17 02:58 - 2012-02-07 11:35 - 00016848 ____A C:\Windows\mozypro.flt
2013-06-17 02:58 - 2012-02-07 11:35 - 00007502 ____A C:\Windows\mozypro.blk
2013-06-12 00:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-12 00:14 - 2012-06-21 14:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-12 00:02 - 2013-01-21 14:14 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-03 10:45 - 2012-06-07 12:12 - 00007180 _RASH C:\ProgramData\ntuser.pol
2013-06-03 10:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\security

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-23 00:53

==================== End Of Log ============================






Addition.txt:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2013
Ran by [removed] at 2013-06-24 19:55:56
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Broadcom Drivers and Management Applications (Version: 15.0.14.1)
Eumex RNDIS64 Treiber V1.02 (Version: 1.02.0000)
funkwerk Eumex 401 WIN-Tools V1.00 (x32 Version: 1.00.0000)
Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (x32 Version: 1)
Komalog Datenbank (x32 Version: 12.0.0.0)
Komalog Datenbank Distribution - Server 2.5.1 (64-Bit) (Version: 2.05.0001)
Matrox Graphics Software (remove only) (x32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Anti-Cross Site Scripting Library v3.1 (x32 Version: 3.1.0)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft ASP.NET 2.0 AJAX Extensions 1.0 (x32 Version: 1.0.61025)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (x32 Version: 3.5.30730.0)
Microsoft Exchange 2007 Enterprise Anti-spam Signatures (Version: 3.3.4604.600)
Microsoft Exchange 2007 Enterprise Block List Updates (Version: 3.3.4604.001)
Microsoft Exchange 2007 Standard Anti-spam Filter Updates (Version: 3.3.12610.467)
Microsoft Exchange Client Language Pack - Arabic (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Basque (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Bulgarian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Catalan (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Chinese (Hong Kong S.A.R.) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Chinese (Simplified) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Chinese (Traditional) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Croatian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Czech (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Danish (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Dutch (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - English (Australia) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - English (Canada) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - English (Great Britain) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - English (India) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - English (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Estonian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Filipino (Philippines) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Finnish (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - French (Canada) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - French (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Galician (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - German (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Greek (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Hebrew (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Hindi (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Hungarian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Icelandic (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Indonesian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Italian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Japanese (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Kazakh (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Korean (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Latvian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Lithuanian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Malay (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Norwegian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Persian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Polish (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Portuguese (Portugal) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Portuguese (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Romanian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Russian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Serbian (Cyrillic, Serbia) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Serbian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Slovak (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Slovenian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Spanish (Mexico) (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Spanish (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Swedish (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Thai (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Turkish (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Ukrainian (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Urdu (Version: 14.1.218.15)
Microsoft Exchange Client Language Pack - Vietnamese (Version: 14.1.218.15)
Microsoft Exchange Server (Version: 14.1.218.15)
Microsoft Exchange Server 2010 (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Arabic (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Chinese (Simplified) (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Chinese (Traditional) (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - English (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - French (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - German (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Hebrew (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Italian (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Japanese (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Korean (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Portuguese (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Russian (Version: 14.1.218.15)
Microsoft Exchange Server Language Pack - Spanish (Version: 14.1.218.15)
Microsoft Filter Pack 2.0 (Version: 14.0.6029.1000)
Microsoft Report Viewer Redistributable 2008 (KB971119) (x32 Version: 9.0.30731)
Microsoft Report Viewer Redistributable 2008 SP1 (x32)
Microsoft Report Viewer Redistributable 2008 SP1 Language Pack - DEU (x32 Version: 9.0.30729)
Microsoft Report Viewer Redistributable 2008 SP1 Language Pack - DEU (x32)
Microsoft Server Speech Platform Runtime (x64) (Version: 10.0.7135.0)
Microsoft Server Speech Recognition Language - TELE (de-DE) (x32 Version: 10.0.7135.0)
Microsoft Server Speech Recognition Language - TELE (en-US) (x32 Version: 10.0.7135.0)
Microsoft SharePoint 2010 Service Pack 1 (SP1)
Microsoft SharePoint Foundation 2010 (Version: 14.0.6029.1000)
Microsoft SharePoint Foundation 2010 1031 Lang Pack (Version: 14.0.6029.1000)
Microsoft SharePoint Foundation 2010 Core (Version: 14.0.6029.1000)
Microsoft SQL Server 2008 Analysis Services ADOMD.NET (Version: 10.0.1600.60)
Microsoft SQL Server 2008 R2 (64-bit)
Microsoft SQL Server 2008 R2 Native Client (Version: 10.50.1617.0)
Microsoft SQL Server 2008 R2 RsFx Driver (Version: 10.51.2500.0)
Microsoft SQL Server 2008 R2 Setup (English) (Version: 10.50.1617.0)
Microsoft SQL Server 2008 R2-Richtlinien (x32 Version: 10.50.1600.1)
Microsoft SQL Server Browser (x32 Version: 10.51.2500.0)
Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0)
Microsoft SQL Server Compact 3.5 SP2 Query Tools DEU (x32 Version: 3.5.8080.0)
Microsoft SQL Server VSS Writer (Version: 10.51.2500.0)
Microsoft Sync Framework Runtime v1.0 (x64) de (Version: 1.0.1215.0)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (x32 Version: 9.0.35191)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (x32 Version: 9.0.35191)
Mozilla Firefox 20.0.1 (x86 de) (x32 Version: 20.0.1)
Mozilla Maintenance Service (x32 Version: 20.0.1)
MozyPro (Version: 2.16.0.215)
Service Pack 1 für SQL Server 2008 R2 (KB2528583) (64-bit) (Version: 10.51.2500.0)
SpyHunter (Version: 4.13.6.4253)
SQL 2008 R2 Reporting Services SharePoint 2010 Add-in (Version: 10.50.1600.1)
SQL Server 2008 R2 SP1 Common Files (Version: 10.51.2500.0)
SQL Server 2008 R2 SP1 Database Engine Services (Version: 10.51.2500.0)
SQL Server 2008 R2 SP1 Database Engine Shared (Version: 10.51.2500.0)
SQL Server 2008 R2 SP1 Full text search (Version: 10.51.2500.0)
SQL Server 2008 R2 SP1 Management Studio (Version: 10.51.2500.0)
Sql Server Customer Experience Improvement Program (Version: 10.50.1600.1)
TeamSpeak 3 Client (Version: 3.0.6)
TeamViewer 7 Host (x32 Version: 7.0.12979)
TRANSDATA Gbak Scheduler (x32 Version: 11.01.0002)
Unterstützungsdateien für Microsoft SQL Server 2008-Setup (Version: 10.1.2731.0)
Update for Microsoft SharePoint Foundation 2010 (KB2553014)
Update Rollup 7-v2 for Exchange Server 2010 Service Pack 1 (KB2756496) (Version: 2)
Update Rollup 8 for Exchange Server 2010 Service Pack 1 (KB2787763) (Version: 1)
Updaterollup 3 für Windows Small Business Server 2011 Standard (KB2729100)
Windows Internal Database (MICROSOFT##SSEE) (Version: 9.4.5000.00)
Windows Server Update Services 3.0 SP2 (Version: 3.2.7600.226)
Windows Small Business Server 2011 Standard (Version: 6.1.7900.5)
Windows-Treiberpaket - T-Home Net (06/30/2010 6.0.6000.16384) (Version: 06/30/2010 6.0.6000.16384)

==================== Restore Points =========================

Could not list Restore Points.


==================== Scheduled Tasks (whitelisted) =============

Task: {1E3F3FA4-2E27-4493-AFF1-B2E2AD376F79} - System32\Tasks\Microsoft\Windows\Windows Small Business Server 2011 Standard\MSExchangeSAStartupFailureEventSink => C:\Windows\system32\sc.exe [2009-07-14] (Microsoft Corporation)
Task: {209E606E-338B-463D-85A7-0B607546577B} - System32\Tasks\ts => C:\teamspeak3-server_win64\ts3server_win64.exe No File
Task: {3066C0DD-EA87-4C4E-B7DC-08F94B22686B} - System32\Tasks\Schattenkopie-Zeitplan für Datenträgerlaufwerk C => C:\Windows\System32\vssadmin.exe [2009-07-14] (Microsoft Corporation)
Task: {3E0A3E64-8C79-42E4-9932-B9CC2F586AB7} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2013-05-07] (Enigma Software Group USA, LLC.)
Task: {63EE8552-A444-4BA2-8E1E-C8350D6D412A} - System32\Tasks\Microsoft\Windows\Server Manager\ServerManager => C:\Windows\system32\ServerManagerLauncher.exe [2009-07-14] (Microsoft Corporation)
Task: {69110D7B-41DC-4E9D-BDD3-C826C7DB613B} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerRoleUsageCollector => C:\Windows\system32\ceipdata.exe [2010-11-20] (Microsoft Corporation)
Task: {9693B7AB-EE40-4BB7-9902-E915117AB95E} - System32\Tasks\Schattenkopie-Zeitplan für Datenträgerlaufwerk D => C:\Windows\System32\vssadmin.exe [2009-07-14] (Microsoft Corporation)
Task: {A43D6F80-43C4-4E48-9D10-F9E419D9506C} - System32\Tasks\Microsoft\Windows\Backup\Microsoft-Windows-WindowsBackup => C:\Windows\System32\wbadmin.exe [2009-07-14] (Microsoft Corporation)
Task: {A723AA1B-42C5-441E-91D8-111A2A80169C} - System32\Tasks\Microsoft\Windows\Windows Small Business Server 2011 Standard\WSUSLogCleaner => C:\Program Files\Windows Small Business Server\Bin\WSUSLogCleaner.vbs [2010-10-20] ()
Task: {A84BFFC9-7263-4481-AE39-5E61792DE0BF} - System32\Tasks\Microsoft\Windows\Windows Small Business Server 2011 Standard\Console => C:\Program Files\Windows Small Business Server\Bin\Console.exe [2010-11-19] (Microsoft Corporation)
Task: {AFECE848-8DA2-461B-B5E6-CBEF57A4DF7D} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerRoleCollector => C:\Windows\system32\ceiprole.exe [2010-11-20] (Microsoft Corporation)
Task: {D49A10DA-0F70-4779-BD96-B2D976A4F2E3} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerCeipAssistant => C:\Windows\system32\ceipdata.exe [2010-11-20] (Microsoft Corporation)
Task: {D4E71BAB-CDF6-448B-A8CB-893B6C34EC2B} - System32\Tasks\Database One Copy Alert => C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe [2009-07-14] (Microsoft Corporation)
Task: {E6698A27-E8CB-4D3F-BCD3-32513C5572D1} - System32\Tasks\User_Feed_Synchronization-{21F44ACE-2D43-4714-9EC2-BF6C5F0962DC} => C:\Windows\system32\msfeedssync.exe [2013-01-23] (Microsoft Corporation)

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/24/2013 05:56:39 PM) (Source: W3CTRS) (User: )
Description: Das Aktualisieren der W3SVC-Leistungsindikatoren dauert zu lange. Die alten Leistungsindikatoren werden stattdessen verwendet. Dies ist die zweite Meldung dieser Art innerhalb der letzten 12:00:00 (Stunden, Minuten, Sekunden). Es werden keine weiteren Meldungen über alte Leistungsindikatoren für diese Clientsitzung protokolliert, bis das Zeitlimit abgelaufen ist.
Weitere Informationen über diese Meldung finden Sie auf der Microsoft-Onlinesupportsite unter: http://go.microsoft.com/fwlink?linkid=538.

Error: (06/24/2013 05:56:39 PM) (Source: Microsoft-Windows-User Profiles Service) (User: PASSREITER)
Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren.

Error: (06/24/2013 05:56:37 PM) (Source: W3CTRS) (User: )
Description: Das Aktualisieren der W3SVC-Leistungsindikatoren dauert zu lange. Die alten Leistungsindikatoren werden stattdessen verwendet.

Error: (06/24/2013 05:54:52 PM) (Source: Windows Server Update Services) (User: )
Description: Der Serversynchronisierungs-Webdienst funktioniert nicht.

Error: (06/24/2013 05:48:25 PM) (Source: CertSvc) (User: NT-AUTORITÄT)
Description: Richtlinienmodul "Windows-Standard", Methode "Initialize", hat einen Fehler verursacht. Ein Verzeichnisdienstfehler ist aufgetreten. Zurückgegebener Statuscode: 0x80072095 (8341). Es konnte keine Verbindung mit dem Active Directory, das die Zertifizierungsstelle enthält, hergestellt werden.

Error: (06/24/2013 05:48:21 PM) (Source: CertSvc) (User: NT-AUTORITÄT)
Description: Es konnte keine Verbindung mit Active Directory hergestellt werden. Der Vorgang wird wiederholt, sobald der Zugriff auf Active Directory während der Verarbeitung erneut erforderlich ist.

Error: (06/24/2013 05:45:22 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation) (User: PASSREITER)
Description: -2146893055Es konnte eine Verbindung mit dem Server hergestellt werden, doch während des Handshakes vor der Anmeldung trat ein Fehler auf. (provider: SSL-Provider, error: 0 - Das angegebene Handle ist ungültig.)

Error: (06/24/2013 05:45:16 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation) (User: PASSREITER)
Description: -2146893055Es konnte eine Verbindung mit dem Server hergestellt werden, doch während des Handshakes vor der Anmeldung trat ein Fehler auf. (provider: SSL-Provider, error: 0 - Das angegebene Handle ist ungültig.)

Error: (06/24/2013 05:45:10 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation) (User: PASSREITER)
Description: 6005SHUTDOWN ist in Bearbeitung.
Fehler bei der Anmeldung für den Benutzer 'PASSREITER\spfarm'.
Für den aktuellen Befehl ist ein schwerwiegender Fehler aufgetreten. Löschen Sie eventuelle Ergebnisse.

Error: (06/24/2013 05:45:10 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation) (User: PASSREITER)
Description: 6005SHUTDOWN ist in Bearbeitung.
Fehler bei der Anmeldung für den Benutzer 'PASSREITER\spfarm'.
Für den aktuellen Befehl ist ein schwerwiegender Fehler aufgetreten. Löschen Sie eventuelle Ergebnisse.


System errors:
=============
Error: (06/24/2013 07:28:42 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 1203.

Error: (06/24/2013 07:28:32 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 1203.

Error: (06/24/2013 07:28:26 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 1203.

Error: (06/24/2013 07:28:16 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 1203.

Error: (06/24/2013 07:12:38 PM) (Source: UmrdpService) (User: )
Description: Der für den Drucker Photosmart C5100 series [3F2FD6] erforderliche Treiber HP LaserJet 4350 PS ist unbekannt. Wenden Sie sich an den Administrator, um den Treiber zu installieren, bevor Sie sich erneut anmelden.

Error: (06/24/2013 07:12:12 PM) (Source: TermDD) (User: )
Description: Von der Terminalserver-Sicherheitsschicht wurde ein Fehler im Protokollablauf erkannt, und die Clientverbindung wurde getrennt.
Client-IP: 192.168.2.21.

Error: (06/24/2013 05:54:18 PM) (Source: UmrdpService) (User: )
Description: Der für den Drucker Photosmart C5100 series [3F2FD6] erforderliche Treiber HP LaserJet 4350 PS ist unbekannt. Wenden Sie sich an den Administrator, um den Treiber zu installieren, bevor Sie sich erneut anmelden.

Error: (06/24/2013 05:52:24 PM) (Source: NetBT) (User: )
Description: Der Name "PASSREITER :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.2.253
registriert werden. Der Computer mit IP-Adresse 192.168.2.13 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (06/24/2013 05:52:06 PM) (Source: NetBT) (User: )
Description: Der Name "PASSREITER :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.2.253
registriert werden. Der Computer mit IP-Adresse 192.168.2.13 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (06/24/2013 05:51:41 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SharePoint 2010 User Code Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.


Microsoft Office Sessions:
=========================
Error: (06/24/2013 05:56:39 PM) (Source: W3CTRS)(User: )
Description: 12:00:00

Error: (06/24/2013 05:56:39 PM) (Source: Microsoft-Windows-User Profiles Service)(User: PASSREITER)
Description:

Error: (06/24/2013 05:56:37 PM) (Source: W3CTRS)(User: )
Description:

Error: (06/24/2013 05:54:52 PM) (Source: Windows Server Update Services)(User: )
Description: Der Serversynchronisierungs-Webdienst funktioniert nicht.

Error: (06/24/2013 05:48:25 PM) (Source: CertSvc)(User: NT-AUTORITÄT)
Description: Windows-StandardInitialize0x80072095 (8341)Es konnte keine Verbindung mit dem Active Directory, das die Zertifizierungsstelle enthält, hergestellt werden.
Ein Verzeichnisdienstfehler ist aufgetreten.

Error: (06/24/2013 05:48:21 PM) (Source: CertSvc)(User: NT-AUTORITÄT)
Description:

Error: (06/24/2013 05:45:22 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation)(User: PASSREITER)
Description: -2146893055Es konnte eine Verbindung mit dem Server hergestellt werden, doch während des Handshakes vor der Anmeldung trat ein Fehler auf. (provider: SSL-Provider, error: 0 - Das angegebene Handle ist ungültig.)

Error: (06/24/2013 05:45:16 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation)(User: PASSREITER)
Description: -2146893055Es konnte eine Verbindung mit dem Server hergestellt werden, doch während des Handshakes vor der Anmeldung trat ein Fehler auf. (provider: SSL-Provider, error: 0 - Das angegebene Handle ist ungültig.)

Error: (06/24/2013 05:45:10 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation)(User: PASSREITER)
Description: 6005SHUTDOWN ist in Bearbeitung.
Fehler bei der Anmeldung für den Benutzer 'PASSREITER\spfarm'.
Für den aktuellen Befehl ist ein schwerwiegender Fehler aufgetreten. Löschen Sie eventuelle Ergebnisse.

Error: (06/24/2013 05:45:10 PM) (Source: Microsoft-SharePoint Products-SharePoint Foundation)(User: PASSREITER)
Description: 6005SHUTDOWN ist in Bearbeitung.
Fehler bei der Anmeldung für den Benutzer 'PASSREITER\spfarm'.
Für den aktuellen Befehl ist ein schwerwiegender Fehler aufgetreten. Löschen Sie eventuelle Ergebnisse.


==================== Memory info ===========================

Percentage of memory in use: 56%
Total physical RAM: 16373.71 MB
Available physical RAM: 7166.14 MB
Total Pagefile: 32745.6 MB
Available Pagefile: 12989.85 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:196.97 GB) (Free:51.06 GB) NTFS (Disk=0 Partition=3)
Drive d: (DATAPART1) (Fixed) (Total:730.98 GB) (Free:425.55 GB) NTFS (Disk=1 Partition=1)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 200 GB) (Disk ID: 2BC78965)
Partition 1: (Not Active) - (Size=32 MB) - (Type=DE)
Partition 2: (Active) - (Size=3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=197 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 731 GB) (Disk ID: 2BC78953)

Partition: GPT Partition Type
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 2285EC6B)
Partition 1: (Not Active) - (Size=-198645293056) - (Type=07 NTFS)

==================== End Of Log ============================

Should I go on with Gmer now, or should I wait?

Thanks!

Stefan
Be sure the server isn´t operational at the moment. gmer scans deeply so it may cause the server to crash. Do the system scan with gmer
Oh, das freut mich! :)

Hier noch die ark.txt:


GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-24 20:22:24
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000062 DELL____ rev.2.0_ 200,00GB
Running: m73b9hty.exe; Driver: C:\Users\stefanrother\AppData\Local\Temp\pxloapoc.sys


—- Registry - GMER 2.1 —-

Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\silsvc@ service
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\silsvc@ service
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@DisplayName @%SystemRoot%\system32\silsvc.exe,-103
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@ImagePath %SystemRoot%\system32\silsvc.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@Type 16
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@Description @%SystemRoot%\system32\silsvc.exe,-102
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc@DelayedAutostart 0
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc\Security
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\services\silsvc
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\silsvc@ service
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\silsvc@ service

—- EOF - GMER 2.1 —-

Vielen Dank!

Stefan
Hi, und ich habe vorhin die dns.exe testweise angehalten im Recourcenmonitor und die Netzwerklast ist sofort zurückgegangen. Ich sehe auch, dass die dns.exe die hohe Netzwerklast erzeugt. Vielen Dank für Deine Hilfe! Stefan
Die DNS.exe ist legitimer part vom DNS-Server.

Schritt 1: MBAM vollständig


Downloade Dir bitte Malwarebytes
  • Installiere das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung –> Suche nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere Vollständigen Scan durchführen und drücke auf Scannen. (Hinweis: Alle Festplatten anhaken!)
  • Wenn der Scan beendet ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.



Schritt 2: ESET

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.

  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt als Administrator starten.
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button [external image: Posted Image] (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Hacken bei Yes, i accept the Terms of Use.
  • Drücke den [external image: Posted Image] Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher, dass bei Remove Found Threads kein Haken gesetzt ist.
  • [external image: Posted Image] drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke [external image: Posted Image].
  • Klicke [external image: Posted Image] und speichere das Logfile als ESET.txt auf dem Desktop.
  • Klicke Back und Finish
Bitte poste die Logfile hier.
Hi, ok, läuft vielen Dank! Ich kann auf der gesammten Kiste keinen Virenscanner finden, kann das sein? In der SBS Konsole sagt er mir zwar, dass alles geschützt ist aber einen Virenschutz für den Server finde ich nicht (Es ist nicht mein Server, ich tue nur einem Freund einen Gefallen). Falls wirklich kein Virenscanner da ist, ist es kein Wunder…:( Was hältst Du von der Avira Small Business Security Suite? Kennst Du das? Es sind hier nur drei Clients, ich denke das wäre eine gute Lösung, falls kein Scanner auftaucht, was meinst Du? Danke! Stefan
Ich stimme dir da zu - sehe weit und breit auch nix. Mal gucken, was dabei rauskommt. Die Wahl ist gut, würde ich ihm empfehlen.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI