|
Plagegeister aller Art und deren Bekämpfung: Fund auf neuem LabtopWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
24.07.2010, 01:02 | #1 | ||
| Fund auf neuem Labtop Habe einen neuen Acer Labtop mit Windows 7. Als ich heute dabei war, die kostenlose Sofware Testversionen zu löschen, hat mein gerade erst installiertes AntiVir dann etwas gefunden: C:\Windows\Temp\Temporary Internet Files\Content.IE5\A48GG9V8\utils[1].vbs Habe jetzt natürlich Angst, da ich erst nach dem Löschen und Installieren der Standardprogramme eine Systemsicherung machen wollte. Könnt ihr mir weiterhelfen? Bin echt am verzweifeln, gerade neu und war nur auf google und chip.de, um sichere Software zu installieren und überflüssige zu löschen. Da ich totaler Laie bin, entschuldige ich mich jetzt schon einmal falls ich mich etwas dumm anstelle und danke, dass ihr mir hoffentlich helft. Also, wie vorgesehen habe ich einige Scans durchgeführt: OTL, beide Logs: OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 24.07.2010 01:48:48 - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Sebastian\Downloads 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 285,99 Gb Total Space | 260,17 Gb Free Space | 90,97% Space Free | Partition Type: NTFS Drive D: | 228,22 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: Sebastian Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support "{8F790958-2107-48F2-88E0-B352A0C225AB}" = iTunes "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour "{F68310EC-B615-4044-B7D7-1A6349758D42}" = Microsoft SQL Server VSS Writer "{F90F5A11-53E6-4045-ACB1-BC03D71FB06C}" = Microsoft SQL Server Native Client "CNXT_AUDIO_HDA" = Conexant HD Audio "HDMI" = Intel(R) Graphics Media Accelerator Driver "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) "{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM "{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) "{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard "{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime "{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management "{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{4cb9f93c-9edc-4be9-ae61-af128ddbecfa}" = Business Contact Manager für Outlook 2007 SP1 "{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}" = InterVideo WinDVD 8 "{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync "{7760D94E-B1B5-40A0-9AA0-ABF942108755}" = Acer Crystal Eye Webcam "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0017-0407-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-0100-0407-0000-0000000FF1CE}" = Microsoft Office O MUI (German) 2007 "{90120000-0101-0407-0000-0000000FF1CE}" = Microsoft Office X MUI (German) 2007 "{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage "{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components "{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI "{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "7-Zip" = 7-Zip 4.65 "Acer Registration" = Acer Registration "Acer Screensaver" = Acer ScreenSaver "Acer Welcome Center" = Welcome Center "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Business Contact Manager" = Business Contact Manager für Outlook 2007 SP1 "CCleaner" = CCleaner "DivX Setup.divx.com" = DivX-Setup "GridVista" = Acer GridVista "Identity Card" = Identity Card "InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5 "InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2 "InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "InstallShield_{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}" = InterVideo WinDVD 8 "LManager" = Launch Manager "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "Mozilla Firefox (3.6.7)" = Mozilla Firefox (3.6.7) "OMUI.de-de" = Microsoft Office Language Pack 2007 - German/Deutsch "WinLiveSuite_Wave3" = Windows Live Essentials ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 15.07.2009 18:28:54 | Computer Name = WIN-NPPHOFALDD1 | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 15.07.2009 18:28:54 | Computer Name = WIN-NPPHOFALDD1 | Source = SideBySide | ID = 16842787 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile 8. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error - 23.07.2010 18:11:52 | Computer Name = PC | Source = SideBySide | ID = 16842785 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Users\SEBAST~1\AppData\Local\Temp\RarSFX0\redist.dll". Die abhängige Assemblierung "Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error - 23.07.2010 18:25:52 | Computer Name = PC | Source = MsiInstaller | ID = 10005 Description = Produkt: iTunes -- Dieses iTunes-Installationsprogramm ist für 32-Bit-Versionen von Windows vorgesehen. Bitte laden und installieren Sie stattdessen die 64-Bit-Version des iTunes-Installationsprogramms. Möchten Sie mit der Installation fortfahren? [ System Events ] Error - 23.07.2010 17:56:19 | Computer Name = PC | Source = bowser | ID = 8003 Description = Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{39AF46C6-8312-4B01-9997-7B51AE583F51}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error - 23.07.2010 18:15:49 | Computer Name = PC | Source = Service Control Manager | ID = 7006 Description = Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen: %%5 < End of report > OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.07.2010 01:48:48 - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Sebastian\Downloads 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 285,99 Gb Total Space | 260,17 Gb Free Space | 90,97% Space Free | Partition Type: NTFS Drive D: | 228,22 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: Sebastian Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Sebastian\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH) PRC - C:\Windows\PLFSetI.exe () PRC - C:\Program Files (x86)\Launch Manager\LManager.EXE (Dritek System Inc.) PRC - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated) PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated) PRC - C:\Programme\Acer\Acer Updater\UpdaterService.exe (Acer) PRC - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.) PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation) PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) PRC - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) ========== Modules (SafeList) ========== MOD - C:\Users\Sebastian\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\sfc_os.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msacm32.dll (Microsoft Corporation) MOD - C:\Windows\AppPatch\AcGenral.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\SysWOW64\sfc.dll (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (ePowerSvc) -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) SRV - (Greg_Service) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated) SRV - (RS_Service) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated) SRV - (Updater Service) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe (Acer) SRV - (NTISchedulerSvc) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.) SRV - (NTIBackupSvc) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.) SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation) SRV - (BcmSqlStartupSvc) -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) SRV - (PSI_SVC_2) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) SRV - (IviRegMgr) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) ========== Driver Services (SafeList) ========== DRV:64bit: - (USBCCID) -- C:\Windows\SysNative\DRIVERS\RtsUCcid.sys File not found DRV:64bit: - (RtsUIR) -- C:\Windows\SysNative\DRIVERS\Rts516xIR.sys File not found DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (NETw5s64) Intel(R) -- C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (netw5v64) Intel(R) -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.) DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5635z&r=27360710b406l0433z145i54k1u30q IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5635z&r=27360710b406l0433z145i54k1u30q IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5635z&r=27360710b406l0433z145i54k1u30q IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5635z&r=27360710b406l0433z145i54k1u30q IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5635z&r=27360710b406l0433z145i54k1u30q IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5635z&r=27360710b406l0433z145i54k1u30q IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.10 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.07.24 00:34:18 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.07.24 00:34:18 | 000,000,000 | ---D | M] [2010.07.24 00:17:06 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\mozilla\Extensions [2010.07.24 01:02:25 | 000,000,000 | ---D | M] -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\t6h65slh.default\extensions [2010.07.24 01:02:23 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\t6h65slh.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} [2010.07.24 01:02:23 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\t6h65slh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.07.24 00:16:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.07.14 00:04:04 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.07.14 00:04:04 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.07.14 00:04:04 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.07.14 00:04:04 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.07.14 00:04:04 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated) O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe () O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.07.24 01:45:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Designer [2010.07.24 01:45:00 | 000,000,000 | ---D | C] -- C:\Windows\Msagent [2010.07.24 00:58:35 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Malwarebytes [2010.07.24 00:58:28 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.07.24 00:58:26 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.07.24 00:58:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.07.24 00:58:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.07.24 00:44:16 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Avira [2010.07.24 00:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip [2010.07.24 00:35:57 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Apple Computer [2010.07.24 00:35:57 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\Apple Computer [2010.07.24 00:35:43 | 000,126,312 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\GEARAspi64.dll [2010.07.24 00:35:43 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysWow64\GEARAspi.dll [2010.07.24 00:35:43 | 000,034,152 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys [2010.07.24 00:35:43 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2010.07.24 00:35:23 | 000,000,000 | ---D | C] -- C:\Programme\iPod [2010.07.24 00:35:22 | 000,000,000 | ---D | C] -- C:\Programme\iTunes [2010.07.24 00:35:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2010.07.24 00:35:22 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2010.07.24 00:34:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2010.07.24 00:34:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2010.07.24 00:33:56 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\Apple [2010.07.24 00:33:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2010.07.24 00:33:48 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Apple [2010.07.24 00:33:41 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour [2010.07.24 00:33:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour [2010.07.24 00:33:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2010.07.24 00:33:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple [2010.07.24 00:26:07 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\DivX [2010.07.24 00:25:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2010.07.24 00:25:52 | 000,000,000 | ---D | C] -- C:\Programme\DivX [2010.07.24 00:25:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared [2010.07.24 00:23:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX [2010.07.24 00:23:32 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX [2010.07.24 00:18:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner [2010.07.24 00:16:57 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Mozilla [2010.07.24 00:16:57 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\Mozilla [2010.07.24 00:16:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2010.07.24 00:15:32 | 000,116,568 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys [2010.07.24 00:15:32 | 000,081,072 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys [2010.07.24 00:15:32 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\SysWow64\drivers\avgntdd.sys [2010.07.24 00:15:32 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\SysWow64\drivers\avgntmgr.sys [2010.07.24 00:15:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2010.07.24 00:15:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2010.07.24 00:00:47 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Adobe [2010.07.24 00:00:44 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2010.07.24 00:00:44 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll [2010.07.24 00:00:44 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll [2010.07.24 00:00:44 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2010.07.24 00:00:44 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Google [2010.07.24 00:00:44 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\Google [2010.07.23 23:59:37 | 000,000,000 | ---D | C] -- C:\ProgramData\McQcModifier-5c47-a7b0 [2010.07.23 23:58:36 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Macromedia [2010.07.23 23:58:12 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Searches [2010.07.23 23:58:04 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Identities [2010.07.23 23:57:57 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Contacts [2010.07.23 23:57:51 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\VirtualStore [2010.07.23 23:56:26 | 000,000,000 | ---D | C] -- C:\Programme\Acer Accessory Store [2010.07.23 23:56:20 | 000,000,000 | --SD | C] -- C:\Users\Sebastian\AppData\Roaming\Microsoft [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Videos [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Saved Games [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Pictures [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Music [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Links [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Favorites [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Downloads [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Documents [2010.07.23 23:56:20 | 000,000,000 | R--D | C] -- C:\Users\Sebastian\Desktop [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Vorlagen [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\AppData\Local\Verlauf [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\AppData\Local\Temporary Internet Files [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Startmenü [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\SendTo [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Recent [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Netzwerkumgebung [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Lokale Einstellungen [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Documents\Eigene Videos [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Documents\Eigene Musik [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Eigene Dateien [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Documents\Eigene Bilder [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Druckumgebung [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Cookies [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\AppData\Local\Anwendungsdaten [2010.07.23 23:56:20 | 000,000,000 | -HSD | C] -- C:\Users\Sebastian\Anwendungsdaten [2010.07.23 23:56:20 | 000,000,000 | -H-D | C] -- C:\Users\Sebastian\AppData [2010.07.23 23:56:20 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\Temp [2010.07.23 23:56:20 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Local\Microsoft [2010.07.23 23:56:20 | 000,000,000 | ---D | C] -- C:\Users\Sebastian\AppData\Roaming\Media Center Programs [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Recovery [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Programme [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Programme\Gemeinsame Dateien [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2010.07.23 23:56:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten ========== Files - Modified Within 30 Days ========== [2010.07.24 04:53:36 | 000,052,953 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2010.07.24 04:53:36 | 000,052,953 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2010.07.24 01:51:40 | 000,786,432 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT [2010.07.24 01:46:49 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI [2010.07.24 01:46:33 | 000,000,531 | ---- | M] () -- C:\Windows\win.ini [2010.07.24 01:46:09 | 000,002,007 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2010.07.24 00:58:30 | 000,001,017 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.07.24 00:53:03 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.07.24 00:53:03 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.07.24 00:50:43 | 001,619,442 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.07.24 00:50:43 | 000,700,836 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.07.24 00:50:43 | 000,653,898 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.07.24 00:50:43 | 000,149,920 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.07.24 00:50:43 | 000,121,090 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.07.24 00:45:36 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.07.24 00:45:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.07.24 00:45:27 | 000,409,880 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.07.24 00:45:10 | 3143,311,360 | -HS- | M] () -- C:\hiberfil.sys [2010.07.24 00:44:34 | 001,217,544 | -H-- | M] () -- C:\Users\Sebastian\AppData\Local\IconCache.db [2010.07.24 00:35:49 | 000,002,429 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2010.07.24 00:34:53 | 000,107,288 | ---- | M] () -- C:\Users\Sebastian\AppData\Local\GDIPFONTCACHEV1.DAT [2010.07.24 00:34:11 | 000,001,849 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.07.24 00:26:21 | 000,001,615 | ---- | M] () -- C:\Users\Sebastian\Desktop\DivX Movies.lnk [2010.07.24 00:26:05 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk [2010.07.24 00:25:49 | 000,001,160 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk [2010.07.24 00:18:21 | 000,001,015 | ---- | M] () -- C:\Users\Sebastian\Desktop\CCleaner.lnk [2010.07.24 00:16:59 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat [2010.07.24 00:16:55 | 000,001,947 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.07.24 00:15:37 | 000,002,074 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2010.07.24 00:10:28 | 000,524,288 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.07.24 00:10:28 | 000,524,288 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2010.07.24 00:10:28 | 000,065,536 | -HS- | M] () -- C:\Users\Sebastian\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2010.07.23 23:56:20 | 000,000,020 | -HS- | M] () -- C:\Users\Sebastian\ntuser.ini ========== Files Created - No Company Name ========== [2010.07.24 01:46:49 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2010.07.24 01:46:09 | 000,002,007 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2010.07.24 00:58:30 | 000,001,017 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.07.24 00:35:49 | 000,002,429 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2010.07.24 00:34:11 | 000,001,849 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2010.07.24 00:26:21 | 000,001,615 | ---- | C] () -- C:\Users\Sebastian\Desktop\DivX Movies.lnk [2010.07.24 00:26:05 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk [2010.07.24 00:25:49 | 000,001,160 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk [2010.07.24 00:18:21 | 000,001,015 | ---- | C] () -- C:\Users\Sebastian\Desktop\CCleaner.lnk [2010.07.24 00:16:59 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2010.07.24 00:16:55 | 000,001,947 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.07.24 00:15:37 | 000,002,074 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2010.07.23 23:56:20 | 000,786,432 | -HS- | C] () -- C:\Users\Sebastian\NTUSER.DAT [2010.07.23 23:56:20 | 000,524,288 | -HS- | C] () -- C:\Users\Sebastian\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.07.23 23:56:20 | 000,524,288 | -HS- | C] () -- C:\Users\Sebastian\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2010.07.23 23:56:20 | 000,262,144 | -HS- | C] () -- C:\Users\Sebastian\ntuser.dat.LOG1 [2010.07.23 23:56:20 | 000,065,536 | -HS- | C] () -- C:\Users\Sebastian\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2010.07.23 23:56:20 | 000,000,020 | -HS- | C] () -- C:\Users\Sebastian\ntuser.ini [2010.07.23 23:56:20 | 000,000,000 | -HS- | C] () -- C:\Users\Sebastian\ntuser.dat.LOG2 [2009.07.16 00:17:29 | 001,500,444 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2009.07.16 00:08:01 | 000,632,056 | ---- | C] () -- C:\Windows\Image.dll [2009.07.16 00:08:01 | 000,000,378 | ---- | C] () -- C:\Windows\PidList.ini [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll < End of report > MBAM Zitat:
(der am Anfang genannte Fund ist inzwischen natürlich in Quarantänte) Zitat:
Was mache ich jetzt am besten? |
26.07.2010, 16:10 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Fund auf neuem LabtopZitat:
__________________ |
27.07.2010, 02:11 | #3 | ||
| Fund auf neuem Labtop Hi, danke schon einmal für deine Antwort!
__________________Einzig folgender Eintrag macht beim Ausführen vom CCleaner Probleme. Der Fehler lässt sich nicht beheben, taucht immer wieder neu auf: Ungenutzte Dateiendung {80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} HKCR\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} Was hat das denn zu bedeuten und wie "fixe" ich das? EDIT: Übrigens hat AntiVir bei der Installation den Windows Defender ausgeschaltet. Ist das ok so oder sollte ich besser beide am laufen haben? Ansonsten haben MBAM und Avira gerade nichts mehr gefunden, bzw Avira ein "verstecktes Objekt": Zitat:
Zitat:
|
27.07.2010, 13:06 | #4 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ | Fund auf neuem LabtopZitat:
Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
29.07.2010, 00:13 | #5 |
| Fund auf neuem Labtop Ok, danke, dann weiss ich jetzt Bescheid. Thread kann zu - merci! |
Themen zu Fund auf neuem Labtop |
0 bytes, 0x00000001, 64-bit, 7-zip, adblock, adobe, anfang, antivir, autorun, avgntflt.sys, avira, c:\windows\system32\rundll32.exe, chdrt64.sys, chip.de, desktop, easybox, error, excel, explorer, fehler, firefox.exe, flash player, format, google, home, home premium, iastor.sys, install.exe, internet, launch, local\temp, location, logfile, media center, microsoft office 2003, microsoft office word, mozilla, msiexec.exe, msiinstaller, nicht gefunden, notepad.exe, nt.dll, office 2007, oldtimer, otl.exe, programdata, rarsfx0, realtek, registry, richtlinie, rundll, saver, sched.exe, searchplugins, security, server, shell32.dll, shortcut, software, start menu, syswow64, temp, usb, usb 2.0, versteckte objekte, verweise, virus gefunden, webcheck, windows |