![]() |
|
Log-Analyse und Auswertung: Trojan- BNK.Win32.Keylogger.genWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() ![]() | ![]() Trojan- BNK.Win32.Keylogger.gen Hallo Leute! Ich hab einen Keylogger auf dem Pc, der veranlasst, dass ich weder auf das Internet noch auf vorhandere Programme zum Virenscan zugreifen kann. Habe OTL durchgeführt. Die Extras befinden sich im Anhang, das OTL file ist zu groß um es im Anhang zu posten also gleich hier:OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.06.2011 23:47:44 - Run 1 OTL by OldTimer - Version 3.2.24.1 Folder = F:\Dokumente und Einstellungen\m\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 511,48 Mb Total Physical Memory | 66,48 Mb Available Physical Memory | 13,00% Memory free 1,22 Gb Paging File | 0,42 Gb Available in Paging File | 34,50% Paging File free Paging file location(s): F:\pagefile.sys 768 1536 [binary data] %SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Programme Drive C: | 3,76 Gb Total Space | 3,66 Gb Free Space | 97,39% Space Free | Partition Type: FAT32 Drive D: | 89,23 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Drive F: | 41,93 Gb Total Space | 3,09 Gb Free Space | 7,38% Space Free | Partition Type: NTFS Drive G: | 111,81 Gb Total Space | 71,38 Gb Free Space | 63,84% Space Free | Partition Type: NTFS Computer Name: MELINA | User Name: m | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - F:\Dokumente und Einstellungen\m\Desktop\OTL.exe (OldTimer Tools) PRC - F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\xbv.exe () PRC - F:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - F:\Programme\Spybot - Search & Destroy 2\SDScan.exe (Safer-Networking Ltd.) PRC - F:\Programme\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) PRC - F:\Programme\Spybot - Search & Destroy 2\SDMonSvc.exe (Safer-Networking Ltd.) PRC - F:\Programme\Spybot - Search & Destroy 2\SDFWSvc.exe (Safer-Networking Ltd.) PRC - F:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - F:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - F:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - F:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) PRC - F:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) PRC - F:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.) PRC - F:\Programme\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.) PRC - F:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) PRC - F:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - F:\Programme\Philips\GoGear ARIA Device Manager\GoGear_Aria_DeviceManager.exe (Philips) PRC - F:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - F:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - F:\Programme\OpenOffice.org 3\program\swriter.exe () PRC - F:\Programme\CDBurnerXP\NMSAccessU.exe () PRC - F:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - F:\Programme\Winamp\winampa.exe () PRC - F:\Programme\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd) PRC - F:\Programme\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.) PRC - F:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) PRC - F:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw)) ========== Modules (SafeList) ========== MOD - F:\Dokumente und Einstellungen\m\Desktop\OTL.exe (OldTimer Tools) MOD - F:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (AppMgmt) -- File not found SRV - (SDWSCService) -- F:\Programme\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) SRV - (SDUpdateService) -- F:\Programme\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) SRV - (SDMonitorService) -- F:\Programme\Spybot - Search & Destroy 2\SDMonSvc.exe (Safer-Networking Ltd.) SRV - (SDFirewallService) -- F:\Programme\Spybot - Search & Destroy 2\SDFWSvc.exe (Safer-Networking Ltd.) SRV - (SDScannerService) -- F:\Programme\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) SRV - (AntiVirSchedulerService) -- F:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (AntiVirService) -- F:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (TabletServicePen) -- F:\Programme\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.) SRV - (ACDaemon) -- F:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) SRV - (NMSAccessU) -- F:\Programme\CDBurnerXP\NMSAccessU.exe () SRV - (CTDevice_Srv) -- F:\Programme\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd) ========== Driver Services (SafeList) ========== DRV - (avipbb) -- F:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- F:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- F:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avgio) -- F:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (wacomvhid) -- F:\WINDOWS\system32\drivers\wacomvhid.sys (Wacom Technology) DRV - (epmntdrv) -- F:\WINDOWS\system32\epmntdrv.sys () DRV - (EuGdiDrv) -- F:\WINDOWS\system32\EuGdiDrv.sys () DRV - (gameenum) -- F:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation) DRV - (wacommousefilter) -- F:\WINDOWS\system32\drivers\wacommousefilter.sys (Wacom Technology) DRV - (ati2mtag) -- F:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.) DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- F:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.) DRV - (MVDCODEC) -- F:\WINDOWS\system32\drivers\atinmdxx.sys (ATI Technologies Inc.) DRV - (atinrvxx) -- F:\WINDOWS\system32\drivers\atinrvxx.sys (ATI Technologies Inc.) DRV - (ATIXSAudio) -- F:\WINDOWS\system32\drivers\atinxsxx.sys (ATI Technologies Inc.) DRV - (ativraxx) -- F:\WINDOWS\system32\drivers\atinraxx.sys (ATI Technologies Inc.) DRV - (TTDec) -- F:\WINDOWS\system32\drivers\atinttxx.sys (ATI Technologies Inc.) DRV - (ATITUNEP) -- F:\WINDOWS\system32\drivers\atintuxx.sys (ATI Technologies Inc.) DRV - (SISNIC) -- F:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation) DRV - (cmpci) C-Media PCI Audio Driver (WDM) -- F:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc) DRV - (ms_mpu401) -- F:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - File not found IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - F:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.google.de" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2 FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.3.3.2 FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.3.3.2 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: F:\Programme\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox [2009.12.29 00:19:37 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: F:\Programme\Mozilla Firefox\components [2011.06.22 11:24:31 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: F:\Programme\Mozilla Firefox\plugins [2011.05.01 21:42:37 | 000,000,000 | ---D | M] [2008.12.13 22:20:19 | 000,000,000 | ---D | M] (No name found) -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Extensions [2011.06.23 16:20:10 | 000,000,000 | ---D | M] (No name found) -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\extensions [2011.06.23 16:20:04 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010.12.11 16:29:36 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011.06.23 16:20:10 | 000,000,000 | ---D | M] (softonic-de3 Community Toolbar) -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} [2011.04.21 13:16:49 | 000,000,000 | ---D | M] (Conduit Engine) -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\extensions\engine@conduit.com [2011.03.21 19:50:13 | 000,002,395 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\searchplugins\askcom.xml [2010.12.11 20:09:30 | 000,000,873 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Mozilla\Firefox\Profiles\7zigpuz7.default\searchplugins\conduit.xml [2011.06.22 11:24:31 | 000,000,000 | ---D | M] (No name found) -- F:\Programme\Mozilla Firefox\extensions [2010.12.08 20:23:38 | 000,000,000 | ---D | M] (Java Console) -- F:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011.02.20 19:27:50 | 000,000,000 | ---D | M] (Java Console) -- F:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011.04.20 13:10:08 | 000,000,000 | ---D | M] (Java Console) -- F:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} File not found (No name found) -- [2011.02.20 19:26:58 | 000,000,000 | ---D | M] (Java Quick Starter) -- F:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2011.06.04 18:36:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- F:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2011.06.16 06:32:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- F:\Programme\Mozilla Firefox\components\browsercomps.dll [2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- F:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll [2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- F:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- F:\Programme\Mozilla Firefox\searchplugins\bing.xml [2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- F:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- F:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- F:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- F:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2002.08.29 14:00:00 | 000,000,820 | ---- | M]) - F:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - F:\Programme\ArcSoft\Media Converter for Philips\Internet Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Programme\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Programme\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - F:\Programme\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - F:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Programme\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - F:\Programme\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - F:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - F:\Programme\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - F:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.) O4 - HKLM..\Run: [ArcSoft Connection Service] F:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) O4 - HKLM..\Run: [ATICCC] F:\Programme\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.) O4 - HKLM..\Run: [avgnt] F:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BluetoothAuthenticationAgent] F:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation) O4 - HKLM..\Run: [C-Media Mixer] F:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw)) O4 - HKLM..\Run: [SDTray] F:\Programme\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKLM..\Run: [SoundMan] F:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] F:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [THGuard] F:\Programme\TrojanHunter 5.3\THGuard.exe (Mischel Internet Security) O4 - HKLM..\Run: [TrojanScanner] F:\Programme\Trojan Remover\Trjscan.exe (Simply Super Software) O4 - HKLM..\Run: [WinampAgent] F:\Programme\Winamp\winampa.exe () O4 - HKCU..\Run: [888193952] F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\xbv.exe () O4 - HKCU..\Run: [CTFMON.EXE] File not found O4 - Startup: F:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Philips GoGear ARIA Device Manager.lnk = F:\Programme\Philips\GoGear ARIA Device Manager\GoGear_Aria_DeviceManager.exe (Philips) O4 - Startup: F:\Dokumente und Einstellungen\m\Startmenü\Programme\Autostart\OpenOffice.org 3.0.lnk = F:\Programme\OpenOffice.org 3\program\quickstart.exe () O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube to MP3 Converter - F:\Dokumente und Einstellungen\m\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\Programme\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: DirectAnimation Java Classes file://F:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://F:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - F:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - F:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\SDWinLogon: DllName - SDWinLogon.dll - File not found O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{0a3d0bd3-27e8-11e0-82c7-0007952a25f3}\Shell\AutoRun\command - "" = C:\Menu.exe O33 - MountPoints2\{20e67640-3116-11df-8238-0007952a25f3}\Shell\AutoRun\command - "" = C:\nhx.exe O33 - MountPoints2\{20e67640-3116-11df-8238-0007952a25f3}\Shell\open\Command - "" = C:\nhx.exe O33 - MountPoints2\{43606ed0-8142-11df-824e-0007952a25f3}\Shell\AutoRun\command - "" = C:\12gn6id2.exe O33 - MountPoints2\{43606ed0-8142-11df-824e-0007952a25f3}\Shell\open\Command - "" = C:\12gn6id2.exe O33 - MountPoints2\{804991b2-f1a8-11df-8265-0007952a25f3}\Shell - "" = AutoRun O33 - MountPoints2\{804991b2-f1a8-11df-8265-0007952a25f3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{804991b2-f1a8-11df-8265-0007952a25f3}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O33 - MountPoints2\{b08f46f0-deae-11de-8210-0007952a25f3}\Shell - "" = AutoRun O33 - MountPoints2\{b08f46f0-deae-11de-8210-0007952a25f3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{b08f46f0-deae-11de-8210-0007952a25f3}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O33 - MountPoints2\{d028b230-c49c-11df-825e-0007952a25f3}\Shell\AutoRun\command - "" = C:\pccompanion\Startme.exe O33 - MountPoints2\{d028b230-c49c-11df-825e-0007952a25f3}\Shell\menu1\command - "" = C:\pccompanion\Startme.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O35 - HKCU\..exefile [open] -- "F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\xbv.exe" -a "%1" %* () O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKCU\...exe [@ = exefile] -- "F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\xbv.exe" -a "%1" %* () ========== Files/Folders - Created Within 30 Days ========== [2011.06.24 23:45:38 | 000,579,072 | ---- | C] (OldTimer Tools) -- F:\Dokumente und Einstellungen\m\Desktop\OTL.exe [2011.06.24 23:10:32 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Spybot - Search & Destroy 2 [2011.06.24 23:10:30 | 000,015,224 | ---- | C] (Safer Networking Limited) -- F:\WINDOWS\System32\sdnclean.exe [2011.06.24 23:09:48 | 000,770,384 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\msvcr100.dll [2011.06.24 23:09:48 | 000,421,200 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\msvcp100.dll [2011.06.24 23:09:47 | 000,000,000 | ---D | C] -- F:\Programme\Spybot - Search & Destroy 2 [2011.06.24 23:08:38 | 069,608,432 | ---- | C] (Safer-Networking Ltd. ) -- F:\Dokumente und Einstellungen\m\Desktop\spybotsd-2.0.3-beta1.exe [2011.06.24 23:07:46 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\TrojanHunter [2011.06.24 20:32:59 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Startmenü\Programme\TrojanHunter [2011.06.24 20:32:57 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrojanHunter [2011.06.24 20:32:36 | 000,000,000 | ---D | C] -- F:\Programme\TrojanHunter 5.3 [2011.06.24 20:31:40 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\m\Eigene Dateien\Simply Super Software [2011.06.24 20:31:30 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Trojan Remover [2011.06.24 20:31:25 | 000,069,632 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\ztvcabinet.dll [2011.06.24 20:31:20 | 000,000,000 | ---D | C] -- F:\Programme\Trojan Remover [2011.06.24 20:31:20 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Simply Super Software [2011.06.24 20:31:20 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Simply Super Software [2011.06.24 14:13:29 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Tools [2011.06.24 00:41:30 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\m\Desktop\Hausarbeit [2011.06.16 10:12:32 | 000,105,472 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\mup.sys [2011.06.16 10:12:27 | 000,852,480 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\vgx.dll [2011.06.11 15:29:05 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\m\Desktop\sina [2011.06.05 22:50:55 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\m\Desktop\Paris SIna [2011.06.04 18:05:03 | 000,000,000 | ---D | C] -- F:\Programme\MSXML 4.0 [2011.06.04 17:52:46 | 000,273,024 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\bthport.sys [2011.06.04 17:52:13 | 000,953,856 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\mfc40u.dll [2011.06.04 17:52:00 | 000,617,472 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\comctl32.dll [2011.06.04 17:51:26 | 000,471,552 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\aclayers.dll [2011.06.04 17:49:26 | 000,203,136 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\rmcast.sys [2011.06.04 17:49:20 | 000,040,960 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\ndproxy.sys [2011.06.04 17:49:16 | 000,119,808 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\t2embed.dll [2011.06.04 17:49:16 | 000,081,920 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\fontsub.dll [2011.06.04 17:45:10 | 001,172,480 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\msxml3.dll [2011.06.04 17:44:03 | 000,331,776 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\msadce.dll [2011.06.04 17:44:00 | 000,293,376 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\browserchoice.exe [2011.06.04 17:43:21 | 000,456,320 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\mrxsmb.sys [2011.06.04 17:42:33 | 003,558,912 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\moviemk.exe [2011.06.04 17:40:08 | 000,337,408 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\netapi32.dll [2011.06.04 17:38:22 | 002,151,424 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2011.06.04 17:38:21 | 002,029,568 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\ntkrpamp.exe [2011.06.04 17:38:20 | 002,195,072 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\ntoskrnl.exe [2011.06.04 17:38:17 | 002,071,680 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2011.06.04 17:37:50 | 000,045,568 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\wab.exe [2011.06.04 17:34:17 | 000,590,848 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\rpcrt4.dll [2011.06.04 17:29:40 | 000,744,448 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\helpsvc.exe [2011.06.04 17:25:35 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\WTablet [2011.06.04 13:01:06 | 000,000,000 | ---D | C] -- F:\WINDOWS\System32\PreInstall [2011.06.04 13:01:03 | 000,000,000 | -H-D | C] -- F:\WINDOWS\$hf_mig$ [2011.06.04 12:05:12 | 000,000,000 | ---D | C] -- F:\WINDOWS\System32\SoftwareDistribution [2011.06.03 11:19:19 | 000,000,000 | ---D | C] -- F:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Google Earth [2008.10.27 11:38:54 | 000,095,056 | ---- | C] (Microsoft Corporation) -- F:\Programme\DSETUP.dll [2008.10.27 11:37:34 | 001,692,496 | ---- | C] (Microsoft Corporation) -- F:\Programme\dsetup32.dll [2008.10.27 11:36:58 | 000,526,160 | ---- | C] (Microsoft Corporation) -- F:\Programme\DXSETUP.exe [4 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ] [1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.06.24 23:45:57 | 000,579,072 | ---- | M] (OldTimer Tools) -- F:\Dokumente und Einstellungen\m\Desktop\OTL.exe [2011.06.24 23:34:25 | 000,012,186 | -HS- | M] () -- F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\po2gwq3167i7o726m4rpp [2011.06.24 23:34:25 | 000,012,186 | -HS- | M] () -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\po2gwq3167i7o726m4rpp [2011.06.24 23:18:01 | 000,001,078 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011.06.24 23:10:31 | 000,001,800 | ---- | M] () -- F:\Dokumente und Einstellungen\All Users\Desktop\Spybot-S&D Start Center.lnk [2011.06.24 22:18:04 | 000,001,074 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011.06.24 20:48:36 | 069,608,432 | ---- | M] (Safer-Networking Ltd. ) -- F:\Dokumente und Einstellungen\m\Desktop\spybotsd-2.0.3-beta1.exe [2011.06.24 20:33:00 | 000,059,392 | R--- | M] () -- F:\WINDOWS\System32\streamhlp.dll [2011.06.24 20:33:00 | 000,000,672 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Desktop\TrojanHunter.lnk [2011.06.24 20:31:31 | 000,000,786 | ---- | M] () -- F:\Dokumente und Einstellungen\All Users\Desktop\Trojan Remover.lnk [2011.06.24 16:32:30 | 000,002,048 | --S- | M] () -- F:\WINDOWS\bootstat.dat [2011.06.24 14:08:12 | 000,512,992 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Desktop\sdasetup_revwire207.exe [2011.06.24 13:52:05 | 000,348,160 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\xbv.exe [2011.06.23 17:15:00 | 000,000,276 | ---- | M] () -- F:\WINDOWS\tasks\AppleSoftwareUpdate.job [2011.06.22 11:24:37 | 000,000,696 | ---- | M] () -- F:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk [2011.06.17 11:42:00 | 000,001,374 | ---- | M] () -- F:\WINDOWS\imsins.BAK [2011.06.16 02:06:16 | 000,057,248 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Eigene Dateien\handout referat.odg [2011.06.11 16:00:27 | 000,015,826 | ---- | M] () -- F:\Dokumente und Einstellungen\m\.recently-used.xbel [2011.06.11 15:08:11 | 000,002,422 | ---- | M] () -- F:\WINDOWS\System32\wpa.dbl [2011.06.06 10:30:02 | 000,432,356 | ---- | M] () -- F:\WINDOWS\System32\perfh009.dat [2011.06.06 10:30:01 | 000,448,470 | ---- | M] () -- F:\WINDOWS\System32\perfh007.dat [2011.06.06 10:30:01 | 000,079,910 | ---- | M] () -- F:\WINDOWS\System32\perfc007.dat [2011.06.06 10:30:01 | 000,067,312 | ---- | M] () -- F:\WINDOWS\System32\perfc009.dat [2011.06.05 14:06:05 | 000,112,584 | ---- | M] () -- F:\WINDOWS\System32\FNTCACHE.DAT [2011.06.03 13:34:47 | 000,030,583 | ---- | M] () -- F:\Dokumente und Einstellungen\m\Desktop\tucan.jpg [4 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ] [1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.06.24 23:10:32 | 000,001,806 | ---- | C] () -- F:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Spybot-S&D Start Center.lnk [2011.06.24 23:10:31 | 000,001,800 | ---- | C] () -- F:\Dokumente und Einstellungen\All Users\Desktop\Spybot-S&D Start Center.lnk [2011.06.24 20:33:00 | 000,000,672 | ---- | C] () -- F:\Dokumente und Einstellungen\m\Desktop\TrojanHunter.lnk [2011.06.24 20:32:37 | 000,059,392 | R--- | C] () -- F:\WINDOWS\System32\streamhlp.dll [2011.06.24 20:31:31 | 000,000,786 | ---- | C] () -- F:\Dokumente und Einstellungen\All Users\Desktop\Trojan Remover.lnk [2011.06.24 20:31:25 | 000,162,304 | ---- | C] () -- F:\WINDOWS\System32\ztvunrar36.dll [2011.06.24 20:31:25 | 000,153,088 | ---- | C] () -- F:\WINDOWS\System32\UNRAR3.dll [2011.06.24 20:31:25 | 000,077,312 | ---- | C] () -- F:\WINDOWS\System32\ztvunace26.dll [2011.06.24 20:31:25 | 000,075,264 | ---- | C] () -- F:\WINDOWS\System32\unacev2.dll [2011.06.24 14:13:09 | 000,512,992 | ---- | C] () -- F:\Dokumente und Einstellungen\m\Desktop\sdasetup_revwire207.exe [2011.06.24 13:52:11 | 000,012,186 | -HS- | C] () -- F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\po2gwq3167i7o726m4rpp [2011.06.24 13:52:11 | 000,012,186 | -HS- | C] () -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\po2gwq3167i7o726m4rpp [2011.06.24 13:52:05 | 000,348,160 | ---- | C] () -- F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\xbv.exe [2011.06.16 02:06:15 | 000,057,248 | ---- | C] () -- F:\Dokumente und Einstellungen\m\Eigene Dateien\handout referat.odg [2011.06.11 16:00:27 | 000,015,826 | ---- | C] () -- F:\Dokumente und Einstellungen\m\.recently-used.xbel [2011.06.03 13:34:45 | 000,030,583 | ---- | C] () -- F:\Dokumente und Einstellungen\m\Desktop\tucan.jpg [2011.03.21 22:26:10 | 000,150,893 | ---- | C] () -- F:\WINDOWS\hpoins51.dat [2011.03.21 22:26:10 | 000,000,572 | ---- | C] () -- F:\WINDOWS\hpomdl51.dat [2011.03.21 20:52:39 | 000,150,867 | ---- | C] () -- F:\WINDOWS\hpoins51.dat.temp [2011.03.21 20:52:39 | 000,000,572 | ---- | C] () -- F:\WINDOWS\hpomdl51.dat.temp [2011.02.13 20:40:41 | 000,000,016 | ---- | C] () -- F:\WINDOWS\System32\crt.dat [2011.02.13 20:40:38 | 000,295,814 | ---- | C] () -- F:\WINDOWS\System32\shimg.dll [2010.12.08 16:38:09 | 000,000,056 | -H-- | C] () -- F:\WINDOWS\System32\ezsidmv.dat [2010.12.01 21:26:15 | 000,000,101 | ---- | C] () -- F:\WINDOWS\CMMIXER.INI [2010.05.26 15:22:06 | 000,000,552 | ---- | C] () -- F:\WINDOWS\System32\d3d8caps.dat [2010.01.09 23:22:12 | 000,000,664 | ---- | C] () -- F:\WINDOWS\System32\d3d9caps.dat [2009.10.13 16:20:12 | 000,000,024 | ---- | C] () -- F:\WINDOWS\Medi8or.ini [2009.10.02 18:12:27 | 000,000,524 | ---- | C] () -- F:\WINDOWS\eReg.dat [2009.01.11 18:59:36 | 000,000,025 | ---- | C] () -- F:\WINDOWS\mixerdef.ini [2009.01.11 17:41:24 | 000,038,999 | R--- | C] () -- F:\WINDOWS\cmijack.dat [2009.01.11 17:41:22 | 000,022,122 | R--- | C] () -- F:\WINDOWS\cmaudio.dat [2009.01.11 15:07:33 | 000,156,672 | ---- | C] () -- F:\WINDOWS\System32\RTLCPAPI.dll [2009.01.11 15:07:33 | 000,040,960 | ---- | C] () -- F:\WINDOWS\System32\ChCfg.exe [2009.01.10 16:48:26 | 000,020,333 | ---- | C] () -- F:\WINDOWS\cmaudio.ini [2009.01.09 22:06:15 | 000,520,192 | ---- | C] () -- F:\WINDOWS\System32\ati2sgag.exe [2008.12.18 22:05:54 | 000,000,017 | ---- | C] () -- F:\WINDOWS\Missing.ini [2008.12.18 22:00:52 | 000,025,600 | ---- | C] () -- F:\Dokumente und Einstellungen\m\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.12.13 23:42:33 | 000,472,064 | ---- | C] () -- F:\WINDOWS\System32\NTFSFormat.dll [2008.12.13 23:42:33 | 000,139,776 | ---- | C] () -- F:\WINDOWS\System32\NTFSCopy.dll [2008.12.13 23:42:33 | 000,093,184 | ---- | C] () -- F:\WINDOWS\System32\Partition.dll [2008.12.13 23:42:33 | 000,086,528 | ---- | C] () -- F:\WINDOWS\System32\NTFSLib.dll [2008.12.13 23:42:33 | 000,086,016 | ---- | C] () -- F:\WINDOWS\System32\ResizeNTFS.dll [2008.12.13 23:42:33 | 000,024,576 | ---- | C] () -- F:\WINDOWS\System32\NTFSFileSystemAnalyser.dll [2008.12.13 23:42:33 | 000,021,504 | ---- | C] () -- F:\WINDOWS\System32\Fixup.dll [2008.12.13 23:42:33 | 000,017,920 | ---- | C] () -- F:\WINDOWS\System32\SectorCopy.dll [2008.12.13 23:42:32 | 000,225,280 | ---- | C] () -- F:\WINDOWS\System32\BootMan.exe [2008.12.13 23:42:32 | 000,180,736 | ---- | C] () -- F:\WINDOWS\System32\DeviceManager.dll [2008.12.13 23:42:32 | 000,086,408 | ---- | C] () -- F:\WINDOWS\System32\setupempdrv03.exe [2008.12.13 23:42:32 | 000,068,096 | ---- | C] () -- F:\WINDOWS\System32\Device.dll [2008.12.13 23:42:32 | 000,065,536 | ---- | C] () -- F:\WINDOWS\System32\FatCopy.dll [2008.12.13 23:42:32 | 000,061,952 | ---- | C] () -- F:\WINDOWS\System32\FatResizeMove.dll [2008.12.13 23:42:32 | 000,045,568 | ---- | C] () -- F:\WINDOWS\System32\FileSystemCheck.dll [2008.12.13 23:42:32 | 000,031,744 | ---- | C] () -- F:\WINDOWS\System32\FatLib.dll [2008.12.13 23:42:32 | 000,025,088 | ---- | C] () -- F:\WINDOWS\System32\FATFileSystemAnalyser.dll [2008.12.13 23:42:32 | 000,022,016 | ---- | C] () -- F:\WINDOWS\System32\FatFormat.dll [2008.12.13 23:42:32 | 000,014,848 | ---- | C] () -- F:\WINDOWS\System32\FileSystemAnalyser.dll [2008.12.13 23:42:32 | 000,014,848 | ---- | C] () -- F:\WINDOWS\System32\EuEpmGdi.dll [2008.12.13 23:42:32 | 000,010,752 | ---- | C] () -- F:\WINDOWS\System32\DeviceAdapter.dll [2008.12.13 23:42:32 | 000,008,704 | ---- | C] () -- F:\WINDOWS\System32\epmntdrv.sys [2008.12.13 23:42:32 | 000,006,656 | ---- | C] () -- F:\WINDOWS\System32\CallbackOperator.dll [2008.12.13 23:42:32 | 000,003,072 | ---- | C] () -- F:\WINDOWS\System32\EuGdiDrv.sys [2008.12.13 22:20:22 | 000,000,000 | ---- | C] () -- F:\WINDOWS\nsreg.dat [2008.12.12 23:34:53 | 000,004,161 | ---- | C] () -- F:\WINDOWS\ODBCINST.INI [2008.12.12 23:33:41 | 000,002,048 | --S- | C] () -- F:\WINDOWS\bootstat.dat [2008.12.12 23:33:31 | 000,112,584 | ---- | C] () -- F:\WINDOWS\System32\FNTCACHE.DAT [2008.12.12 23:28:23 | 000,021,740 | ---- | C] () -- F:\WINDOWS\System32\emptyregdb.dat [2008.10.29 14:28:36 | 000,015,312 | ---- | C] () -- F:\WINDOWS\System32\RaCoInst.dat [2008.10.27 11:38:20 | 013,265,184 | ---- | C] () -- F:\Programme\dxnt.cab [2008.10.27 11:38:20 | 004,163,646 | ---- | C] () -- F:\Programme\Apr2006_MDX1_x86_Archive.cab [2008.10.27 11:38:20 | 001,907,944 | ---- | C] () -- F:\Programme\Nov2008_d3dx9_40_x64.cab [2008.10.27 11:38:20 | 001,803,074 | ---- | C] () -- F:\Programme\Nov2007_d3dx9_36_x64.cab [2008.10.27 11:38:18 | 001,801,176 | ---- | C] () -- F:\Programme\AUG2007_d3dx9_35_x64.cab [2008.10.27 11:38:18 | 001,795,100 | ---- | C] () -- F:\Programme\Aug2008_d3dx9_39_x64.cab [2008.10.27 11:38:18 | 001,793,624 | ---- | C] () -- F:\Programme\JUN2008_d3dx9_38_x64.cab [2008.10.27 11:38:18 | 001,770,878 | ---- | C] () -- F:\Programme\Mar2008_d3dx9_37_x64.cab [2008.10.27 11:38:18 | 001,710,376 | ---- | C] () -- F:\Programme\Nov2007_d3dx9_36_x86.cab [2008.10.27 11:38:18 | 001,709,168 | ---- | C] () -- F:\Programme\AUG2007_d3dx9_35_x86.cab [2008.10.27 11:38:18 | 001,608,374 | ---- | C] () -- F:\Programme\APR2007_d3dx9_33_x64.cab [2008.10.27 11:38:16 | 001,608,790 | ---- | C] () -- F:\Programme\JUN2007_d3dx9_34_x64.cab [2008.10.27 11:38:16 | 001,608,302 | ---- | C] () -- F:\Programme\JUN2007_d3dx9_34_x86.cab [2008.10.27 11:38:16 | 001,607,055 | ---- | C] () -- F:\Programme\APR2007_d3dx9_33_x86.cab [2008.10.27 11:38:16 | 001,575,392 | ---- | C] () -- F:\Programme\DEC2006_d3dx9_32_x86.cab [2008.10.27 11:38:16 | 001,572,170 | ---- | C] () -- F:\Programme\DEC2006_d3dx9_32_x64.cab [2008.10.27 11:38:14 | 001,551,228 | ---- | C] () -- F:\Programme\Nov2008_d3dx9_40_x86.cab [2008.10.27 11:38:14 | 001,465,688 | ---- | C] () -- F:\Programme\Aug2008_d3dx9_39_x86.cab [2008.10.27 11:38:14 | 001,464,894 | ---- | C] () -- F:\Programme\JUN2008_d3dx9_38_x86.cab [2008.10.27 11:38:14 | 001,413,918 | ---- | C] () -- F:\Programme\OCT2006_d3dx9_31_x64.cab [2008.10.27 11:38:14 | 001,363,812 | ---- | C] () -- F:\Programme\Feb2006_d3dx9_29_x64.cab [2008.10.27 11:38:14 | 001,358,992 | ---- | C] () -- F:\Programme\Dec2005_d3dx9_28_x64.cab [2008.10.27 11:38:12 | 001,444,298 | ---- | C] () -- F:\Programme\Mar2008_d3dx9_37_x86.cab [2008.10.27 11:38:12 | 001,398,846 | ---- | C] () -- F:\Programme\Apr2006_d3dx9_30_x64.cab [2008.10.27 11:38:12 | 001,351,558 | ---- | C] () -- F:\Programme\Aug2005_d3dx9_27_x64.cab [2008.10.27 11:38:10 | 001,348,370 | ---- | C] () -- F:\Programme\Apr2005_d3dx9_25_x64.cab [2008.10.27 11:38:10 | 001,337,018 | ---- | C] () -- F:\Programme\Jun2005_d3dx9_26_x64.cab [2008.10.27 11:38:10 | 001,248,515 | ---- | C] () -- F:\Programme\Feb2005_d3dx9_24_x64.cab [2008.10.27 11:38:10 | 001,156,507 | ---- | C] () -- F:\Programme\BDANT.cab [2008.10.27 11:38:10 | 001,128,233 | ---- | C] () -- F:\Programme\OCT2006_d3dx9_31_x86.cab [2008.10.27 11:38:10 | 001,116,237 | ---- | C] () -- F:\Programme\Apr2006_d3dx9_30_x86.cab [2008.10.27 11:38:10 | 001,080,472 | ---- | C] () -- F:\Programme\Dec2005_d3dx9_28_x86.cab [2008.10.27 11:38:08 | 001,085,736 | ---- | C] () -- F:\Programme\Feb2006_d3dx9_29_x86.cab [2008.10.27 11:38:08 | 001,079,978 | ---- | C] () -- F:\Programme\Apr2005_d3dx9_25_x86.cab [2008.10.27 11:38:08 | 001,078,660 | ---- | C] () -- F:\Programme\Aug2005_d3dx9_27_x86.cab [2008.10.27 11:38:08 | 001,065,941 | ---- | C] () -- F:\Programme\Jun2005_d3dx9_26_x86.cab [2008.10.27 11:38:08 | 001,014,241 | ---- | C] () -- F:\Programme\Feb2005_d3dx9_24_x86.cab [2008.10.27 11:38:08 | 000,995,154 | ---- | C] () -- F:\Programme\Nov2008_d3dx10_40_x64.cab [2008.10.27 11:38:08 | 000,122,810 | ---- | C] () -- F:\Programme\Nov2008_XACT_x64.cab [2008.10.27 11:38:08 | 000,097,833 | ---- | C] () -- F:\Programme\APR2007_xinput_x64.cab [2008.10.27 11:38:08 | 000,094,750 | ---- | C] () -- F:\Programme\Mar2008_XACT_x86.cab [2008.10.27 11:38:04 | 000,976,164 | ---- | C] () -- F:\Programme\BDAXP.cab [2008.10.27 11:38:04 | 000,966,445 | ---- | C] () -- F:\Programme\Nov2008_d3dx10_40_x86.cab [2008.10.27 11:38:04 | 000,917,446 | ---- | C] () -- F:\Programme\Apr2006_MDX1_x86.cab [2008.10.27 11:38:04 | 000,868,844 | ---- | C] () -- F:\Programme\JUN2008_d3dx10_38_x64.cab [2008.10.27 11:38:04 | 000,868,628 | ---- | C] () -- F:\Programme\Aug2008_d3dx10_39_x64.cab [2008.10.27 11:38:04 | 000,865,616 | ---- | C] () -- F:\Programme\Nov2007_d3dx10_36_x64.cab [2008.10.27 11:38:04 | 000,853,302 | ---- | C] () -- F:\Programme\AUG2007_d3dx10_35_x64.cab [2008.10.27 11:38:04 | 000,850,935 | ---- | C] () -- F:\Programme\JUN2008_d3dx10_38_x86.cab [2008.10.27 11:38:04 | 000,096,053 | ---- | C] () -- F:\Programme\dxupdate.cab [2008.10.27 11:38:04 | 000,094,144 | ---- | C] () -- F:\Programme\JUN2008_XACT_x86.cab [2008.10.27 11:38:04 | 000,055,538 | ---- | C] () -- F:\Programme\Nov2008_X3DAudio_x64.cab [2008.10.27 11:38:04 | 000,045,464 | ---- | C] () -- F:\Programme\dxdllreg_x86.cab [2008.10.27 11:38:02 | 000,850,183 | ---- | C] () -- F:\Programme\Aug2008_d3dx10_39_x86.cab [2008.10.27 11:38:02 | 000,845,900 | ---- | C] () -- F:\Programme\Mar2008_d3dx10_37_x64.cab [2008.10.27 11:38:02 | 000,819,276 | ---- | C] () -- F:\Programme\Mar2008_d3dx10_37_x86.cab [2008.10.27 11:38:02 | 000,094,028 | ---- | C] () -- F:\Programme\Aug2008_XACT_x86.cab [2008.10.27 11:38:02 | 000,093,700 | ---- | C] () -- F:\Programme\Nov2008_XACT_x86.cab [2008.10.27 11:38:02 | 000,088,158 | ---- | C] () -- F:\Programme\AUG2006_xinput_x64.cab [2008.10.27 11:38:02 | 000,088,117 | ---- | C] () -- F:\Programme\Apr2006_xinput_x64.cab [2008.10.27 11:38:02 | 000,087,053 | ---- | C] () -- F:\Programme\Oct2005_xinput_x64.cab [2008.10.27 11:38:02 | 000,056,170 | ---- | C] () -- F:\Programme\JUN2008_X3DAudio_x64.cab [2008.10.27 11:38:02 | 000,056,074 | ---- | C] () -- F:\Programme\Mar2008_X3DAudio_x64.cab [2008.10.27 11:38:02 | 000,054,318 | ---- | C] () -- F:\Programme\APR2007_xinput_x86.cab [2008.10.27 11:38:02 | 000,047,160 | ---- | C] () -- F:\Programme\NOV2007_X3DAudio_x64.cab [2008.10.27 11:38:02 | 000,047,074 | ---- | C] () -- F:\Programme\AUG2006_xinput_x86.cab [2008.10.27 11:38:02 | 000,046,375 | ---- | C] () -- F:\Programme\Oct2005_xinput_x86.cab [2008.10.27 11:38:02 | 000,022,921 | ---- | C] () -- F:\Programme\JUN2008_X3DAudio_x86.cab [2008.10.27 11:38:02 | 000,022,867 | ---- | C] () -- F:\Programme\Nov2008_X3DAudio_x86.cab [2008.10.27 11:38:02 | 000,019,512 | ---- | C] () -- F:\Programme\NOV2007_X3DAudio_x86.cab [2008.10.27 11:38:00 | 000,804,900 | ---- | C] () -- F:\Programme\Nov2007_d3dx10_36_x86.cab [2008.10.27 11:38:00 | 000,797,883 | ---- | C] () -- F:\Programme\AUG2007_d3dx10_35_x86.cab [2008.10.27 11:38:00 | 000,700,060 | ---- | C] () -- F:\Programme\JUN2007_d3dx10_34_x64.cab [2008.10.27 11:38:00 | 000,699,628 | ---- | C] () -- F:\Programme\APR2007_d3dx10_33_x64.cab [2008.10.27 11:38:00 | 000,047,026 | ---- | C] () -- F:\Programme\Apr2006_xinput_x86.cab [2008.10.27 11:38:00 | 000,022,883 | ---- | C] () -- F:\Programme\Mar2008_X3DAudio_x86.cab [2008.10.27 11:37:58 | 000,699,488 | ---- | C] () -- F:\Programme\JUN2007_d3dx10_34_x86.cab [2008.10.27 11:37:58 | 000,696,881 | ---- | C] () -- F:\Programme\APR2007_d3dx10_33_x86.cab [2008.10.27 11:37:58 | 000,272,384 | ---- | C] () -- F:\Programme\Aug2008_XAudio_x64.cab [2008.10.27 11:37:58 | 000,270,858 | ---- | C] () -- F:\Programme\Aug2008_XAudio_x86.cab [2008.10.27 11:37:58 | 000,270,644 | ---- | C] () -- F:\Programme\JUN2008_XAudio_x64.cab [2008.10.27 11:37:54 | 000,274,976 | ---- | C] () -- F:\Programme\Nov2008_XAudio_x64.cab [2008.10.27 11:37:54 | 000,273,627 | ---- | C] () -- F:\Programme\Nov2008_XAudio_x86.cab [2008.10.27 11:37:52 | 000,270,040 | ---- | C] () -- F:\Programme\JUN2008_XAudio_x86.cab [2008.10.27 11:37:52 | 000,252,210 | ---- | C] () -- F:\Programme\Mar2008_XAudio_x64.cab [2008.10.27 11:37:52 | 000,227,266 | ---- | C] () -- F:\Programme\Mar2008_XAudio_x86.cab [2008.10.27 11:37:52 | 000,199,112 | ---- | C] () -- F:\Programme\AUG2007_XACT_x64.cab [2008.10.27 11:37:50 | 000,213,823 | ---- | C] () -- F:\Programme\DEC2006_d3dx10_00_x64.cab [2008.10.27 11:37:50 | 000,198,138 | ---- | C] () -- F:\Programme\JUN2007_XACT_x64.cab [2008.10.27 11:37:50 | 000,193,491 | ---- | C] () -- F:\Programme\DEC2006_XACT_x64.cab [2008.10.27 11:37:48 | 000,197,778 | ---- | C] () -- F:\Programme\NOV2007_XACT_x64.cab [2008.10.27 11:37:48 | 000,196,782 | ---- | C] () -- F:\Programme\APR2007_XACT_x64.cab [2008.10.27 11:37:48 | 000,195,691 | ---- | C] () -- F:\Programme\FEB2007_XACT_x64.cab [2008.10.27 11:37:48 | 000,192,736 | ---- | C] () -- F:\Programme\DEC2006_d3dx10_00_x86.cab [2008.10.27 11:37:48 | 000,183,919 | ---- | C] () -- F:\Programme\AUG2006_XACT_x64.cab [2008.10.27 11:37:48 | 000,183,377 | ---- | C] () -- F:\Programme\OCT2006_XACT_x64.cab [2008.10.27 11:37:46 | 000,181,801 | ---- | C] () -- F:\Programme\JUN2006_XACT_x64.cab [2008.10.27 11:37:46 | 000,180,149 | ---- | C] () -- F:\Programme\Apr2006_XACT_x64.cab [2008.10.27 11:37:46 | 000,179,375 | ---- | C] () -- F:\Programme\Feb2006_XACT_x64.cab [2008.10.27 11:37:46 | 000,154,028 | ---- | C] () -- F:\Programme\AUG2007_XACT_x86.cab [2008.10.27 11:37:44 | 000,153,925 | ---- | C] () -- F:\Programme\JUN2007_XACT_x86.cab [2008.10.27 11:37:44 | 000,152,241 | ---- | C] () -- F:\Programme\APR2007_XACT_x86.cab [2008.10.27 11:37:42 | 000,149,280 | ---- | C] () -- F:\Programme\NOV2007_XACT_x86.cab [2008.10.27 11:37:42 | 000,148,999 | ---- | C] () -- F:\Programme\FEB2007_XACT_x86.cab [2008.10.27 11:37:42 | 000,146,615 | ---- | C] () -- F:\Programme\DEC2006_XACT_x86.cab [2008.10.27 11:37:42 | 000,139,033 | ---- | C] () -- F:\Programme\OCT2006_XACT_x86.cab [2008.10.27 11:37:42 | 000,138,251 | ---- | C] () -- F:\Programme\AUG2006_XACT_x86.cab [2008.10.27 11:37:40 | 000,134,687 | ---- | C] () -- F:\Programme\JUN2006_XACT_x86.cab [2008.10.27 11:37:40 | 000,133,425 | ---- | C] () -- F:\Programme\Feb2006_XACT_x86.cab [2008.10.27 11:37:40 | 000,123,352 | ---- | C] () -- F:\Programme\Mar2008_XACT_x64.cab [2008.10.27 11:37:40 | 000,122,840 | ---- | C] () -- F:\Programme\Aug2008_XACT_x64.cab [2008.10.27 11:37:40 | 000,122,070 | ---- | C] () -- F:\Programme\JUN2008_XACT_x64.cab [2008.10.27 11:37:38 | 000,134,119 | ---- | C] () -- F:\Programme\Apr2006_XACT_x86.cab [2008.03.31 23:25:46 | 000,831,488 | ---- | C] () -- F:\WINDOWS\System32\divx_xx0a.dll [2008.03.21 22:30:08 | 003,596,288 | ---- | C] () -- F:\WINDOWS\System32\qt-dx331.dll [2008.03.21 22:28:20 | 000,012,288 | ---- | C] () -- F:\WINDOWS\System32\DivXWMPExtType.dll [2006.04.28 22:05:14 | 000,127,614 | ---- | C] () -- F:\WINDOWS\System32\atiicdxx.dat [2004.08.02 15:20:40 | 000,004,569 | ---- | C] () -- F:\WINDOWS\System32\secupd.dat [2002.08.29 14:00:00 | 000,673,088 | ---- | C] () -- F:\WINDOWS\System32\mlang.dat [2002.08.29 14:00:00 | 000,448,470 | ---- | C] () -- F:\WINDOWS\System32\perfh007.dat [2002.08.29 14:00:00 | 000,432,356 | ---- | C] () -- F:\WINDOWS\System32\perfh009.dat [2002.08.29 14:00:00 | 000,272,128 | ---- | C] () -- F:\WINDOWS\System32\perfi009.dat [2002.08.29 14:00:00 | 000,269,480 | ---- | C] () -- F:\WINDOWS\System32\perfi007.dat [2002.08.29 14:00:00 | 000,218,003 | ---- | C] () -- F:\WINDOWS\System32\dssec.dat [2002.08.29 14:00:00 | 000,079,910 | ---- | C] () -- F:\WINDOWS\System32\perfc007.dat [2002.08.29 14:00:00 | 000,067,312 | ---- | C] () -- F:\WINDOWS\System32\perfc009.dat [2002.08.29 14:00:00 | 000,046,258 | ---- | C] () -- F:\WINDOWS\System32\mib.bin [2002.08.29 14:00:00 | 000,034,478 | ---- | C] () -- F:\WINDOWS\System32\perfd007.dat [2002.08.29 14:00:00 | 000,028,626 | ---- | C] () -- F:\WINDOWS\System32\perfd009.dat [2002.08.29 14:00:00 | 000,001,804 | ---- | C] () -- F:\WINDOWS\System32\dcache.bin [2002.08.29 14:00:00 | 000,000,741 | ---- | C] () -- F:\WINDOWS\System32\noise.dat [2001.09.04 11:12:28 | 013,107,200 | ---- | C] () -- F:\WINDOWS\System32\oembios.bin [2001.09.04 11:10:20 | 000,004,518 | ---- | C] () -- F:\WINDOWS\System32\oembios.dat ========== LOP Check ========== [2010.01.03 19:09:21 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Napster [2011.06.24 20:31:20 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Simply Super Software [2011.06.24 20:32:57 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrojanHunter [2009.02.25 23:12:15 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Canneverbe_Limited [2010.12.10 02:52:01 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\CocoonSoftware [2011.04.18 23:44:01 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\DVDVideoSoft [2010.12.11 16:29:34 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\DVDVideoSoftIEHelpers [2011.04.18 23:33:36 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\GetRightToGo [2011.06.11 16:00:27 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\gtk-2.0 [2008.12.13 21:48:12 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\IrfanView [2009.11.01 21:20:31 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\MatchWare [2009.08.17 18:27:39 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\OpenOffice.org [2011.03.21 22:09:02 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\PriceGong [2011.06.24 20:31:20 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Simply Super Software [2010.12.08 16:20:36 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\Sony [2011.06.24 23:07:46 | 000,000,000 | ---D | M] -- F:\Dokumente und Einstellungen\m\Anwendungsdaten\TrojanHunter ========== Purity Check ========== < End of report > Geändert von Mommratz (24.06.2011 um 23:08 Uhr) |
Themen zu Trojan- BNK.Win32.Keylogger.gen |
0x00000001, anti, anti vir, befindet, cdburnerxp, conduit, führte, inter, interne, internet, keylogger, leute, logfile, plug-in, programme, safer networking, scan, sched.exe, searchplugins, super, tablet, troja, virenscan, vollständige, zugreife, zugreifen |