|
Log-Analyse und Auswertung: BKA UKASH TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.08.2011, 17:01 | #1 |
| BKA UKASH Trojaner Hallo.. bräuchte Mal eure Hilfe bei der entfernung des BKA Trojaners. Vielen Dank schonmal für eure Mühe! |
10.08.2011, 17:23 | #2 |
| BKA UKASH Trojaner Hm..kann meine Lofile nicht posten weil die angeblich zu lang ist! Als Archiv wird sie mir dann als zu groß angegeben!
__________________Was soll ich tun? |
10.08.2011, 18:07 | #3 |
| BKA UKASH Trojaner So hier jetzt meine Logfiles:OTL Logfile:
__________________Code:
ATTFilter OTL logfile created on: 8/10/2011 9:32:04 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE 64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 90.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86) Drive C: | 100.00 Mb Total Space | 75.52 Mb Free Space | 75.52% Space Free | Partition Type: NTFS Drive D: | 286.27 Gb Total Space | 139.09 Gb Free Space | 48.59% Space Free | Partition Type: NTFS Drive E: | 7.45 Gb Total Space | 7.45 Gb Free Space | 99.98% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2009/09/16 06:23:32 | 000,696,848 | ---- | M] (McAfee, Inc.) [On_Demand] -- D:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS) SRV:64bit: - [2009/09/16 05:15:32 | 000,155,456 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield) SRV:64bit: - [2009/08/05 15:30:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto] -- D:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc) SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009/07/03 21:47:12 | 000,240,160 | ---- | M] (Acer) [Auto] -- D:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service) SRV:64bit: - [2009/03/27 22:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto] -- D:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio) SRV - [2011/08/02 14:03:38 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand] -- D:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/08/01 15:56:29 | 003,542,616 | ---- | M] () [Auto] -- D:\Program Files (x86)\Common Files\Akamai\netsession_win_2da1ebd.dll -- (Akamai) SRV - [2011/07/21 07:41:17 | 000,269,480 | ---- | M] (Avira GmbH) [Auto] -- D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011/06/24 11:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) [Auto] -- D:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater) SRV - [2011/05/21 02:01:00 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto] -- D:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2011/05/14 05:26:42 | 000,136,360 | ---- | M] (Avira GmbH) [Auto] -- D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011/02/16 09:49:08 | 000,101,048 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service) SRV - [2010/12/30 15:30:16 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- D:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010/09/08 15:46:00 | 003,852,792 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand] -- D:\Windows\SysWow64\GameMon.des -- (npggsvc) SRV - [2010/09/06 13:56:38 | 000,247,096 | ---- | M] () [Auto] -- D:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2010/03/18 08:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/01/29 18:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto] -- D:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC) SRV - [2010/01/15 08:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand] -- D:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2009/10/27 06:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -- (MpfService) SRV - [2009/10/02 08:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files (x86)\McAfee\MSK\MskSrver.exe -- (MSK80Service) SRV - [2009/09/17 09:29:04 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc) SRV - [2009/09/16 04:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand] -- D:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -- (McSysmon) SRV - [2009/08/20 20:25:50 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto] -- D:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc) SRV - [2009/08/07 05:18:54 | 000,311,592 | ---- | M] () [Auto] -- D:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService) SRV - [2009/07/08 06:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy) SRV - [2009/07/07 14:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto] -- D:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc) SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009/06/04 22:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto] -- D:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R) SRV - [2009/06/04 09:04:50 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto] -- D:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/07/21 07:41:21 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System] -- D:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2011/07/21 07:41:21 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto] -- D:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2011/05/10 05:41:27 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/04/02 16:43:51 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- D:\Windows\System32\drivers\sptd.sys -- (sptd) DRV:64bit: - [2009/10/05 11:34:00 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\athrx.sys -- (athr) DRV:64bit: - [2009/09/16 05:22:40 | 000,308,296 | ---- | M] (McAfee, Inc.) [Kernel | System] -- D:\Windows\System32\drivers\mfehidk.sys -- (mfehidk) DRV:64bit: - [2009/09/16 05:22:40 | 000,102,472 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk) DRV:64bit: - [2009/09/16 05:22:40 | 000,049,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk) DRV:64bit: - [2009/09/16 05:15:38 | 000,040,904 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\mferkdk.sys -- (mferkdk) DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\serscan.sys -- (StillCam) DRV:64bit: - [2009/06/20 07:35:00 | 000,317,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM) DRV:64bit: - [2009/06/19 22:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- D:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 16:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 16:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\BCMWL664.SYS -- (BCM43XX) DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/04 20:46:50 | 000,216,064 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:64bit: - [2009/06/02 23:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System] -- D:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk) DRV:64bit: - [2009/06/02 23:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System] -- D:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter) DRV:64bit: - [2009/06/02 23:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System] -- D:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ) DRV:64bit: - [2009/04/09 17:23:02 | 000,176,144 | ---- | M] (McAfee, Inc.) [Kernel | System] -- D:\Windows\System32\drivers\Mpfp.sys -- (MPFP) DRV:64bit: - [2009/04/06 21:31:08 | 001,208,320 | ---- | M] (LSI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\agrsm64.sys -- (AgereSoftModem) DRV:64bit: - [2007/02/15 20:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ElbyCDFL.sys -- (ElbyCDFL) DRV - [2009/12/19 14:27:33 | 000,012,400 | ---- | M] (Macrovision Europe Ltd) [Kernel | Auto] -- D:\Windows\SysWOW64\drivers\SECDRV.SYS -- (SecDrv) DRV - [2007/02/15 20:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- D:\Windows\SysWOW64\drivers\ElbyCDFL.sys -- (ElbyCDFL) DRV - [2005/01/03 11:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand] -- D:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7736&r=27361109g816l03g8z1m5t5861a537 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7736&r=27361109g816l03g8z1m5t5861a537 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Gast_ON_D\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7736&r=27361109g816l03g8z1m5t5861a537 IE - HKU\Gast_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ IE - HKU\Gast_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\Gast_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\Gast_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BA D8 56 7C E7 4A CB 01 [binary data] IE - HKU\Gast_ON_D\..\URLSearchHook: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Reg Error: Key error. File not found IE - HKU\Gast_ON_D\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) IE - HKU\Gast_ON_D\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found IE - HKU\Gast_ON_D\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found IE - HKU\Gast_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Halo_ON_D\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7736&r=27361109g816l03g8z1m5t5861a537 IE - HKU\Halo_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7736&r=27361109g816l03g8z1m5t5861a537 IE - HKU\Halo_ON_D\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) IE - HKU\Halo_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Shaki_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/webhp?sourceid=navclient&hl=de&ie=UTF-8 IE - HKU\Shaki_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\Shaki_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\Shaki_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BA D8 56 7C E7 4A CB 01 [binary data] IE - HKU\Shaki_ON_D\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\Shaki_ON_D\..\URLSearchHook: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Reg Error: Key error. File not found IE - HKU\Shaki_ON_D\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) IE - HKU\Shaki_ON_D\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found IE - HKU\Shaki_ON_D\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - Reg Error: Key error. File not found IE - HKU\Shaki_ON_D\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found IE - HKU\Shaki_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer: D:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: D:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: D:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/02 06:22:25 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/02/25 10:57:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/02/25 10:57:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/06/07 13:55:57 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/02 06:22:25 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}: C:\Program Files (x86)\PriceGong\2.1.0\FF [2011/02/18 13:14:29 | 000,000,000 | ---D | M] [2011/08/02 19:29:36 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Shaki\AppData\Roaming\Mozilla\Extensions O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - D:\Program Files (x86)\McAfee\MSK\mskapbho64.dll () O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.) O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) O2:64bit: - BHO: (DownloadHelper Class) - {FF2573AE-E1ED-40e1-83BA-F544CB2EE135} - D:\Program Files\Common Files\Download Helper\DownloadHelperx64.dll (IE Download Helper) O2 - BHO: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - D:\Program Files (x86)\Dealio Toolbar\IE\4.5\dealioToolbarIE.dll (Spigot, Inc.) O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (PriceGongBHO Class) - {1631550F-191D-4826-B069-D9439253D926} - D:\Program Files (x86)\PriceGong\2.1.0\PriceGongIE.dll (PriceGong) O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - D:\Program Files (x86)\McAfee\MSK\mskapbho.dll () O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.) O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - D:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - D:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) O2 - BHO: (DownloadHelper Class) - {FF2573AE-E1ED-40e1-83BA-F544CB2EE135} - D:\Program Files (x86)\Common Files\Download Helper\DownloadHelper.dll (IE Download Helper) O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - D:\Program Files (x86)\Dealio Toolbar\IE\4.5\dealioToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - D:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:64bit: - HKU\Gast_ON_D\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - D:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKU\Gast_ON_D\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3:64bit: - HKU\Halo_ON_D\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - D:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKU\Halo_ON_D\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3:64bit: - HKU\Shaki_ON_D\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - D:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKU\Shaki_ON_D\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKU\Shaki_ON_D\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O4:64bit: - HKLM..\Run: [Acer ePower Management] D:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated) O4:64bit: - HKLM..\Run: [IAAnotif] D:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [mwlDaemon] D:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.) O4:64bit: - HKLM..\Run: [PLFSetI] D:\Windows\PLFSetI.exe () O4:64bit: - HKLM..\Run: [RtHDVCpl] D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ArcadeDeluxeAgent] D:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.) O4 - HKLM..\Run: [avgnt] D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BackupManagerTray] D:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.) O4 - HKLM..\Run: [CloneCDTray] D:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.) O4 - HKLM..\Run: [DivXUpdate] D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [EgisTecLiveUpdate] D:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.) O4 - HKLM..\Run: [LManager] D:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [mcagent_exe] D:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKLM..\Run: [NortonOnlineBackupReminder] D:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation) O4 - HKLM..\Run: [PDFPrint] D:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [PlayMovie] D:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.) O4 - HKLM..\Run: [SweetIM] D:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) O4 - HKU\Gast_ON_D..\Run: [EA Core] File not found O4 - HKU\Gast_ON_D..\Run: [ICQ] D:\Program Files (x86)\ICQ7.0\ICQ.exe (ICQ, LLC.) O4 - HKU\Gast_ON_D..\Run: [Speech Recognition] D:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) O4 - HKU\Gast_ON_D..\Run: [uTorrent] D:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) O4 - HKU\LocalService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\Shaki_ON_D..\Run: [{BCF0BE45-AC1B-7E9D-006F-843F1A828A6F}] D:\Users\Shaki\AppData\Roaming\Cyumod\raixy.exe (Copyright (C) 2010-2011 Marvell Semiconductor) O4 - HKU\Shaki_ON_D..\Run: [avupdate] D:\Users\Shaki\AppData\Roaming\jashla.exe () O4 - HKU\Shaki_ON_D..\Run: [ICQ] D:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.) O4 - HKU\Shaki_ON_D..\Run: [Speech Recognition] D:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) O4 - HKU\Shaki_ON_D..\Run: [Steam] D:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) O4 - HKU\Shaki_ON_D..\Run: [uTorrent] D:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) O4 - HKU\UpdatusUser_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\Gast_ON_D..\RunOnce: [FlashPlayerUpdate] File not found O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found O4 - HKU\UpdatusUser_ON_D..\RunOnce: [mctadmin] File not found O4 - HKU\UpdatusUser_ON_D..\RunOnce: [ScrSav] D:\Program Files (x86)\Acer\Screensaver\run_Acer.exe () O4 - Startup: D:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk () O4 - Startup: D:\Users\Shaki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk () O4 - Startup: D:\Users\Shaki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Dogz2.LNK () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: Free YouTube Download - D:\Users\Shaki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - D:\Users\Shaki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8:64bit: - Extra context menu item: Google Sidewiki... - D:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.) O8 - Extra context menu item: Free YouTube Download - D:\Users\Shaki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - D:\Users\Shaki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Google Sidewiki... - D:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.) O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ipp - No CLSID value found O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - D:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{a4b51cd6-3e98-11df-89d5-00262d575721}\Shell - "" = AutoRun O33 - MountPoints2\{a4b51cd6-3e98-11df-89d5-00262d575721}\Shell\AutoRun\command - "" = E:\autorun.exe O33 - MountPoints2\{d6ca2d8d-b6cb-11de-ba4e-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{d6ca2d8d-b6cb-11de-ba4e-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011/08/07 16:53:00 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Roaming\Origin [2011/08/07 16:52:37 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Local\Origin [2011/08/07 16:50:54 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin [2011/08/07 16:50:46 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Origin Games [2011/08/07 16:50:46 | 000,000,000 | ---D | C] -- D:\ProgramData\Origin [2011/08/07 16:49:57 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Origin [2011/08/02 19:01:29 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming\Yahoo! [2011/08/02 19:01:28 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming\Adobe [2011/08/02 19:01:26 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming\Google [2011/08/02 19:01:21 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local\Google [2011/08/02 19:00:20 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local\EgisTec [2011/08/02 18:59:56 | 000,000,000 | R--D | C] -- D:\Users\Halo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011/08/02 18:59:56 | 000,000,000 | R--D | C] -- D:\Users\Halo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011/08/02 18:59:55 | 000,000,000 | -H-D | C] -- D:\Users\Halo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned [2011/08/02 18:59:46 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming\Identities [2011/08/02 18:59:38 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local\VirtualStore [2011/08/02 18:58:54 | 000,000,000 | -HSD | C] -- D:\Users\Halo\AppData\Local\Verlauf [2011/08/02 18:58:54 | 000,000,000 | -HSD | C] -- D:\Users\Halo\AppData\Local\Temporary Internet Files [2011/08/02 18:58:54 | 000,000,000 | -HSD | C] -- D:\Users\Halo\AppData\Local\Anwendungsdaten [2011/08/02 18:58:54 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\LocalLow [2011/08/02 18:58:53 | 000,000,000 | --SD | C] -- D:\Users\Halo\AppData\Roaming\Microsoft [2011/08/02 18:58:53 | 000,000,000 | R--D | C] -- D:\Users\Halo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011/08/02 18:58:53 | 000,000,000 | R--D | C] -- D:\Users\Halo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011/08/02 18:58:53 | 000,000,000 | -HSD | C] -- D:\Users\Halo\Documents\Eigene Videos [2011/08/02 18:58:53 | 000,000,000 | -HSD | C] -- D:\Users\Halo\Documents\Eigene Musik [2011/08/02 18:58:53 | 000,000,000 | -HSD | C] -- D:\Users\Halo\Documents\Eigene Bilder [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local\Temp [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local\Microsoft Help [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local\Microsoft [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming\Media Center Programs [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Roaming\Macromedia [2011/08/02 18:58:53 | 000,000,000 | ---D | C] -- D:\Users\Halo\AppData\Local [2011/08/02 18:54:14 | 013,917,848 | ---- | C] (PortableApps.com) -- D:\Users\Shaki\Desktop\FirefoxPortable_4.0.1_German.paf.exe [2011/08/02 17:57:12 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Roaming\Nofu [2011/08/02 17:57:12 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Roaming\Cyumod [2011/08/02 16:48:32 | 000,093,696 | ---- | C] (BreakPoint Software) -- D:\Windows\SysWow64\0.07512266418370261.exe [2011/08/02 15:46:11 | 000,065,536 | RHS- | C] (Nmiwduiac Zfuflnyzzad) -- D:\Windows\SysWow64\wshelper7.dll [2011/07/31 16:39:22 | 000,000,000 | ---D | C] -- D:\Users\Shaki\Desktop\nähe [2011/07/31 16:38:21 | 000,000,000 | ---D | C] -- D:\Windows\System32\SPReview [2011/07/31 16:36:49 | 000,000,000 | ---D | C] -- D:\Windows\System32\EventProviders [2011/07/29 13:40:21 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam [2011/07/29 13:20:39 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Steam [2011/07/29 13:20:37 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [2011/07/29 13:20:36 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Steam [2011/07/26 18:49:46 | 000,000,000 | ---D | C] -- D:\Users\Shaki\Desktop\lol [2011/07/26 15:59:17 | 000,000,000 | ---D | C] -- D:\Users\Shaki\Documents\Story File [2011/07/26 15:24:22 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioConverter Studio [2011/07/26 15:11:59 | 000,286,720 | ---- | C] (Indigo Rose Corporation) -- D:\Windows\iun506.exe [2011/07/26 15:11:59 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3 File Editor [2011/07/26 15:11:58 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Mp3 File Editor [2011/07/26 15:01:09 | 000,000,000 | ---D | C] -- D:\Users\Shaki\Documents\Smith Micro [2011/07/26 15:01:09 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Roaming\Smith Micro [2011/07/26 14:59:49 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manga Studio EX Demo 4.0 [2011/07/26 14:59:21 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Smith Micro [2011/07/25 18:43:01 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\DESIGNER [2011/07/25 18:42:46 | 000,000,000 | ---D | C] -- D:\Windows\PCHEALTH [2011/07/25 18:41:36 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft Office [2011/07/20 08:03:53 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Application Updater [2011/07/20 08:03:52 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\Spigot [2011/07/20 08:03:52 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Dealio Toolbar [2011/07/19 13:25:30 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\NVIDIA Corporation [2011/07/19 13:24:36 | 000,000,000 | ---D | C] -- D:\ProgramData\NVIDIA Corporation [2011/07/19 13:18:43 | 000,067,176 | ---- | C] (Khronos Group) -- D:\Windows\System32\OpenCL.dll [2011/07/19 13:18:43 | 000,057,960 | ---- | C] (Khronos Group) -- D:\Windows\SysWow64\OpenCL.dll [2011/07/19 13:18:15 | 000,000,000 | ---D | C] -- D:\Program Files\NVIDIA Corporation [2011/07/19 13:17:31 | 000,000,000 | ---D | C] -- D:\NVIDIA [2011/07/18 21:19:08 | 000,000,000 | ---D | C] -- D:\Users\Shaki\Desktop\Convert your life [2011/07/18 20:47:55 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy MP3 Cutter [2011/07/18 20:47:54 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Easy MP3 Cutter [2011/07/18 20:22:19 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [2011/07/18 20:22:08 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\DVDVideoSoft [2011/07/18 20:17:55 | 000,000,000 | ---D | C] -- D:\Users\Shaki\AppData\Roaming\DVDVideoSoft [2011/07/18 20:17:31 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Common Files\DVDVideoSoft [2011/07/18 16:26:29 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- D:\Windows\System32\fms.dll [2011/07/18 16:25:57 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- D:\Windows\SysWow64\fms.dll [2009/08/22 04:44:20 | 000,036,136 | ---- | C] (Oberon Media) -- D:\ProgramData\FullRemove.exe [2 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ] [1 D:\Windows\*.tmp files -> D:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/08/10 14:21:11 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat [2011/08/10 14:21:08 | 000,053,550 | ---- | M] () -- D:\Windows\System32\Config.MPF [2011/08/10 14:21:08 | 000,008,212 | ---- | M] () -- D:\Windows\mfebcdata [2011/08/10 14:19:42 | 000,000,308 | -HS- | M] () -- D:\Windows\tasks\ebikmqqh.job [2011/08/10 14:19:27 | 3217,231,872 | -HS- | M] () -- D:\hiberfil.sys [2011/08/10 10:59:14 | 000,001,106 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/08/10 10:59:08 | 000,000,286 | -H-- | M] () -- D:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job [2011/08/10 10:59:05 | 000,000,286 | -H-- | M] () -- D:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job [2011/08/10 10:59:02 | 000,000,246 | -H-- | M] () -- D:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011/08/08 15:50:22 | 000,017,376 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/08/08 15:50:22 | 000,017,376 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/08/08 14:29:00 | 000,001,110 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/08/08 14:27:04 | 000,163,328 | ---- | M] () -- D:\Users\Shaki\AppData\Roaming\jashla.exe [2011/08/08 06:02:07 | 000,104,713 | ---- | M] () -- D:\Users\Shaki\Desktop\B_L01_1433.jpg [2011/08/07 16:50:54 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin [2011/08/04 09:11:41 | 000,659,004 | ---- | M] () -- D:\Windows\System32\perfh007.dat [2011/08/04 09:11:41 | 000,620,150 | ---- | M] () -- D:\Windows\System32\perfh009.dat [2011/08/04 09:11:41 | 000,132,542 | ---- | M] () -- D:\Windows\System32\perfc007.dat [2011/08/04 09:11:41 | 000,108,332 | ---- | M] () -- D:\Windows\System32\perfc009.dat [2011/08/03 08:10:50 | 000,684,586 | ---- | M] () -- D:\Users\Shaki\Desktop\anger_fl.jpg [2011/08/02 19:26:22 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [2011/08/02 19:00:40 | 000,001,437 | ---- | M] () -- D:\Users\Halo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/08/02 18:54:53 | 013,917,848 | ---- | M] (PortableApps.com) -- D:\Users\Shaki\Desktop\FirefoxPortable_4.0.1_German.paf.exe [2011/08/02 17:57:20 | 000,000,058 | ---- | M] () -- D:\Users\Shaki\AppData\Roaming\you.bmp [2011/08/02 16:48:34 | 000,093,696 | ---- | M] (BreakPoint Software) -- D:\Windows\SysWow64\0.07512266418370261.exe [2011/08/02 15:46:11 | 000,065,536 | RHS- | M] (Nmiwduiac Zfuflnyzzad) -- D:\Windows\SysWow64\wshelper7.dll [2011/08/01 01:21:52 | 000,356,720 | ---- | M] () -- D:\Windows\System32\FNTCACHE.DAT [2011/07/31 19:08:13 | 000,000,320 | ---- | M] () -- D:\Windows\tasks\McQcTask.job [2011/07/31 19:08:13 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3 File Editor [2011/07/31 17:26:41 | 000,001,441 | ---- | M] () -- D:\Users\Shaki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/07/30 19:54:18 | 000,025,352 | ---- | M] () -- D:\Users\Shaki\Desktop\V_for_Vendetta_Stencil_2_by_beraka.jpg [2011/07/30 11:51:50 | 000,067,506 | ---- | M] () -- D:\Users\Shaki\Desktop\feuer schablone.jpg [2011/07/30 07:59:00 | 000,046,821 | ---- | M] () -- D:\Users\Shaki\Desktop\gfs_80714_2_7.jpg [2011/07/30 06:43:37 | 000,012,288 | ---- | M] () -- D:\Users\Shaki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/07/29 13:20:47 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [2011/07/26 15:26:46 | 049,080,364 | ---- | M] () -- D:\Users\Shaki\Desktop\Gin'iro No Kami No Agito - Chouwa Oto With Reflection.wav [2011/07/26 15:24:26 | 000,000,892 | ---- | M] () -- D:\Users\Shaki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AudioConverter Studio.lnk [2011/07/26 15:24:26 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioConverter Studio [2011/07/26 15:12:52 | 000,286,720 | ---- | M] (Indigo Rose Corporation) -- D:\Windows\iun506.exe [2011/07/26 14:59:49 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manga Studio EX Demo 4.0 [2011/07/25 18:44:14 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [2011/07/25 18:11:28 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [2011/07/23 23:33:22 | 000,029,038 | ---- | M] () -- D:\Users\Shaki\Desktop\time.odt [2011/07/21 07:41:21 | 000,123,784 | ---- | M] (Avira GmbH) -- D:\Windows\System32\drivers\avipbb.sys [2011/07/21 07:41:21 | 000,088,288 | ---- | M] (Avira GmbH) -- D:\Windows\System32\drivers\avgntflt.sys [2011/07/18 21:23:53 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [2011/07/18 21:18:43 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2011/07/18 20:47:56 | 000,001,016 | ---- | M] () -- D:\Users\Shaki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Easy MP3 Cutter.lnk [2011/07/18 20:47:56 | 000,001,016 | ---- | M] () -- D:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Easy MP3 Cutter.lnk [2011/07/18 20:47:56 | 000,000,992 | ---- | M] () -- D:\Users\Gast\Desktop\Easy MP3 Cutter.lnk [2011/07/18 20:47:56 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy MP3 Cutter [2011/07/18 20:39:16 | 000,000,503 | ---- | M] () -- D:\Windows\powermp3cutterjoiner.ini [2 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ] [1 D:\Windows\*.tmp files -> D:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/08/10 14:21:08 | 000,008,212 | ---- | C] () -- D:\Windows\mfebcdata [2011/08/08 14:27:04 | 000,163,328 | ---- | C] () -- D:\Users\Shaki\AppData\Roaming\jashla.exe [2011/08/08 06:02:46 | 000,104,713 | ---- | C] () -- D:\Users\Shaki\Desktop\B_L01_1433.jpg [2011/08/03 09:26:42 | 000,046,821 | ---- | C] () -- D:\Users\Shaki\Desktop\gfs_80714_2_7.jpg [2011/08/03 09:26:23 | 000,025,352 | ---- | C] () -- D:\Users\Shaki\Desktop\V_for_Vendetta_Stencil_2_by_beraka.jpg [2011/08/03 09:25:18 | 000,067,506 | ---- | C] () -- D:\Users\Shaki\Desktop\feuer schablone.jpg [2011/08/03 08:11:06 | 000,684,586 | ---- | C] () -- D:\Users\Shaki\Desktop\anger_fl.jpg [2011/08/02 19:00:40 | 000,001,437 | ---- | C] () -- D:\Users\Halo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/08/02 19:00:04 | 000,001,409 | ---- | C] () -- D:\Users\Halo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2011/08/02 18:59:57 | 000,001,443 | ---- | C] () -- D:\Users\Halo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011/08/02 18:58:53 | 000,000,290 | ---- | C] () -- D:\Users\Halo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2011/08/02 18:58:53 | 000,000,272 | ---- | C] () -- D:\Users\Halo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2011/08/02 17:57:20 | 000,000,058 | ---- | C] () -- D:\Users\Shaki\AppData\Roaming\you.bmp [2011/08/02 15:46:46 | 000,000,286 | -H-- | C] () -- D:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job [2011/08/02 15:46:42 | 000,000,286 | -H-- | C] () -- D:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job [2011/08/02 15:46:39 | 000,000,246 | -H-- | C] () -- D:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011/08/02 15:46:36 | 000,000,308 | -HS- | C] () -- D:\Windows\tasks\ebikmqqh.job [2011/07/31 17:26:31 | 000,001,447 | ---- | C] () -- D:\Users\Shaki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011/07/26 15:26:44 | 049,080,364 | ---- | C] () -- D:\Users\Shaki\Desktop\Gin'iro No Kami No Agito - Chouwa Oto With Reflection.wav [2011/07/26 15:24:26 | 000,000,892 | ---- | C] () -- D:\Users\Shaki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AudioConverter Studio.lnk [2011/07/23 23:33:22 | 000,029,038 | ---- | C] () -- D:\Users\Shaki\Desktop\time.odt [2011/07/19 13:18:38 | 000,007,384 | ---- | C] () -- D:\Windows\System32\nvinfo.pb [2011/07/18 20:47:56 | 000,001,016 | ---- | C] () -- D:\Users\Shaki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Easy MP3 Cutter.lnk [2011/07/18 20:47:56 | 000,001,016 | ---- | C] () -- D:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Easy MP3 Cutter.lnk [2011/07/18 20:47:56 | 000,000,992 | ---- | C] () -- D:\Users\Gast\Desktop\Easy MP3 Cutter.lnk [2011/07/18 16:27:47 | 000,347,904 | ---- | C] () -- D:\Windows\System32\systemsf.ebd [2011/07/18 16:27:22 | 000,281,600 | ---- | C] () -- D:\Windows\System32\DShowRdpFilter.dll [2011/07/18 16:27:17 | 000,252,928 | ---- | C] () -- D:\Windows\SysWow64\DShowRdpFilter.dll [2011/07/18 16:25:26 | 000,010,429 | ---- | C] () -- D:\Windows\System32\ScavengeSpace.xml [2011/07/18 16:25:07 | 000,105,559 | ---- | C] () -- D:\Windows\SysWow64\RacRules.xml [2011/07/18 16:25:07 | 000,105,559 | ---- | C] () -- D:\Windows\System32\RacRules.xml [2011/07/18 16:24:36 | 000,001,041 | ---- | C] () -- D:\Windows\SysWow64\tcpbidi.xml [2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- D:\Windows\SysWow64\xlive.dll.cat [2010/12/30 15:24:38 | 000,000,209 | ---- | C] () -- D:\Windows\ODBCINST.INI [2010/12/13 17:58:18 | 000,066,872 | ---- | C] () -- D:\Windows\SysWow64\PnkBstrA.exe [2010/12/13 17:58:11 | 000,103,736 | ---- | C] () -- D:\Windows\SysWow64\PnkBstrB.exe [2010/10/17 09:37:21 | 000,000,056 | -H-- | C] () -- D:\ProgramData\ezsidmv.dat [2010/10/13 16:13:17 | 000,161,188 | ---- | C] () -- D:\Windows\Expstudio Audio Editor FREE Uninstaller.exe [2010/08/16 06:29:30 | 001,514,120 | ---- | C] () -- D:\Windows\SysWow64\PerfStringBackup.INI [2010/08/02 06:11:59 | 000,230,452 | ---- | C] () -- D:\Windows\hpoins46.dat [2010/05/15 13:19:25 | 000,290,816 | ---- | C] () -- D:\Windows\SysWow64\decdll.dll [2010/01/29 17:21:20 | 000,000,532 | ---- | C] () -- D:\Windows\hpomdl46.dat [2010/01/15 13:33:26 | 000,000,000 | ---- | C] () -- D:\Windows\nsreg.dat [2010/01/15 13:18:48 | 000,012,288 | ---- | C] () -- D:\Users\Shaki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/12/25 18:16:37 | 000,000,041 | -HS- | C] () -- D:\ProgramData\.zreglib [2009/11/30 12:18:19 | 000,000,403 | ---- | C] () -- D:\Windows\ODBC.INI [2009/11/28 05:49:22 | 000,056,320 | ---- | C] () -- D:\Windows\SysWow64\iyvu9_32.dll [2009/11/28 05:46:57 | 000,000,889 | ---- | C] () -- D:\Windows\disney.ini [2009/11/28 05:46:53 | 000,000,205 | ---- | C] () -- D:\Windows\disneysy.ini [2009/11/20 16:10:33 | 000,000,425 | ---- | C] () -- D:\Windows\BRWMARK.INI [2009/11/20 16:10:33 | 000,000,027 | ---- | C] () -- D:\Windows\BRPP2KA.INI [2009/11/20 11:33:33 | 000,000,794 | ---- | C] () -- D:\Users\Shaki\AppData\Roaming\wklnhst.dat [2009/10/12 06:42:37 | 000,001,666 | ---- | C] () -- D:\Windows\WPatchProgress.ini [2009/10/11 21:31:16 | 000,000,033 | ---- | C] () -- D:\Windows\LaunApp.ini [2009/10/11 21:16:31 | 000,200,704 | ---- | C] () -- D:\Windows\PLFSetI.exe [2009/10/11 21:16:31 | 000,106,496 | ---- | C] () -- D:\Windows\FixUVC.exe [2009/10/11 21:16:31 | 000,000,074 | ---- | C] () -- D:\Windows\PidList.ini [2009/08/22 02:01:23 | 000,872,448 | ---- | C] () -- D:\Windows\iconv.dll [2009/08/22 02:01:23 | 000,743,424 | ---- | C] () -- D:\Windows\libxml2.dll [2009/08/22 02:01:21 | 000,000,193 | ---- | C] () -- D:\Windows\Prelaunch.ini [2009/08/22 02:01:21 | 000,000,168 | ---- | C] () -- D:\Windows\WisLangCode.ini [2009/08/22 02:01:21 | 000,000,147 | ---- | C] () -- D:\Windows\WisPriority.ini [2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- D:\Windows\bootstat.dat [2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- D:\Windows\SysWow64\NOISE.DAT [2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- D:\Windows\SysWow64\dssec.dat [2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- D:\Windows\mib.bin [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- D:\Windows\SysWow64\ir32_32.dll [2009/07/13 17:59:36 | 000,982,196 | ---- | C] () -- D:\Windows\SysWow64\igkrng500.bin [2009/07/13 17:59:36 | 000,139,824 | ---- | C] () -- D:\Windows\SysWow64\igfcg500.bin [2009/07/13 17:59:36 | 000,097,448 | ---- | C] () -- D:\Windows\SysWow64\igfcg500m.bin [2009/07/13 17:59:35 | 000,417,344 | ---- | C] () -- D:\Windows\SysWow64\igcompkrng500.bin [2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- D:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- D:\Windows\SysWow64\mlang.dat [2007/11/14 13:42:27 | 000,237,568 | ---- | C] () -- D:\Windows\SysWow64\lame_enc.dll [2007/11/09 07:01:59 | 000,000,164 | ---- | C] () -- D:\Windows\SysWow64\psyswin32.dll [2006/12/30 12:48:38 | 000,000,503 | ---- | C] () -- D:\Windows\powermp3cutterjoiner.ini ========== LOP Check ========== [2009/08/22 01:41:17 | 000,000,000 | ---D | M] -- D:\ProgramData\Acer [2009/11/20 11:12:24 | 000,000,000 | -HSD | M] -- D:\ProgramData\Anwendungsdaten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Application Data [2009/11/21 12:59:16 | 000,000,000 | ---D | M] -- D:\ProgramData\Arcade Lab [2010/08/16 10:02:15 | 000,000,000 | ---D | M] -- D:\ProgramData\Artweaver [2009/11/21 07:38:35 | 000,000,000 | ---D | M] -- D:\ProgramData\AWEM [2009/08/22 04:56:16 | 000,000,000 | ---D | M] -- D:\ProgramData\BackupManager [2010/12/12 04:07:26 | 000,000,000 | ---D | M] -- D:\ProgramData\Codemasters [2010/04/02 16:43:01 | 000,000,000 | ---D | M] -- D:\ProgramData\DAEMON Tools Lite [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Desktop [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Documents [2009/11/20 11:12:24 | 000,000,000 | -HSD | M] -- D:\ProgramData\Dokumente [2010/12/20 20:43:42 | 000,000,000 | ---D | M] -- D:\ProgramData\Driver Whiz [2010/07/26 10:11:01 | 000,000,000 | ---D | M] -- D:\ProgramData\EA Logs [2009/10/11 21:15:45 | 000,000,000 | ---D | M] -- D:\ProgramData\EgisTec [2011/08/07 16:49:59 | 000,000,000 | ---D | M] -- D:\ProgramData\Electronic Arts [2009/08/22 06:30:37 | 000,000,000 | ---D | M] -- D:\ProgramData\eSobi [2009/11/25 13:24:05 | 000,000,000 | ---D | M] -- D:\ProgramData\FarmFrenzy2 [2009/11/20 11:12:24 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favoriten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favorites [2009/11/25 14:46:51 | 000,000,000 | ---D | M] -- D:\ProgramData\Friends Games [2011/02/02 09:53:06 | 000,000,000 | ---D | M] -- D:\ProgramData\ICQ [2010/03/09 16:04:59 | 000,000,000 | ---D | M] -- D:\ProgramData\Intenium [2010/09/18 10:46:21 | 000,000,000 | ---D | M] -- D:\ProgramData\Nexon [2009/12/19 15:49:43 | 000,000,000 | ---D | M] -- D:\ProgramData\NFS Underground [2009/10/11 21:20:41 | 000,000,000 | ---D | M] -- D:\ProgramData\OEM [2011/08/07 16:53:00 | 000,000,000 | ---D | M] -- D:\ProgramData\Origin [2009/12/12 04:54:46 | 000,000,000 | ---D | M] -- D:\ProgramData\Partner [2010/12/20 21:01:10 | 000,000,000 | ---D | M] -- D:\ProgramData\PC Drivers HeadQuarters [2009/11/25 12:23:14 | 000,000,000 | ---D | M] -- D:\ProgramData\PlayFirst [2010/10/19 09:43:35 | 000,000,000 | ---D | M] -- D:\ProgramData\regid.1986-12.com.adobe [2009/11/20 18:31:59 | 000,000,000 | ---D | M] -- D:\ProgramData\Sandlot Games [2010/05/22 16:39:04 | 000,000,000 | ---D | M] -- D:\ProgramData\SimCity Societies [2010/08/07 07:58:00 | 000,000,000 | ---D | M] -- D:\ProgramData\Solidshield [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Start Menu [2009/11/20 11:12:24 | 000,000,000 | -HSD | M] -- D:\ProgramData\Startmenü [2011/02/18 13:10:02 | 000,000,000 | ---D | M] -- D:\ProgramData\SweetIM [2010/02/28 16:19:48 | 000,000,000 | ---D | M] -- D:\ProgramData\SYSTEMAX Software Development [2011/06/14 10:29:03 | 000,000,000 | ---D | M] -- D:\ProgramData\Temp [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Templates [2010/12/20 20:44:03 | 000,000,000 | ---D | M] -- D:\ProgramData\UAB [2010/05/06 06:07:55 | 000,000,000 | ---D | M] -- D:\ProgramData\Ubisoft [2010/08/16 06:37:50 | 000,000,000 | ---D | M] -- D:\ProgramData\Virtualized Applications [2009/11/20 11:12:24 | 000,000,000 | -HSD | M] -- D:\ProgramData\Vorlagen [2011/08/10 14:19:42 | 000,000,308 | -HS- | M] () -- D:\Windows\Tasks\ebikmqqh.job [2011/06/14 19:20:07 | 000,000,342 | ---- | M] () -- D:\Windows\Tasks\McDefragTask.job [2011/07/31 19:08:13 | 000,000,320 | ---- | M] () -- D:\Windows\Tasks\McQcTask.job [2010/10/30 05:02:08 | 000,032,640 | ---- | M] () -- D:\Windows\Tasks\SCHEDLGU.TXT [2011/08/10 10:59:08 | 000,000,286 | -H-- | M] () -- D:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job [2011/08/10 10:59:02 | 000,000,246 | -H-- | M] () -- D:\Windows\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011/08/10 10:59:05 | 000,000,286 | -H-- | M] () -- D:\Windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 24 bytes -> D:\Windows:B2DBC5CEA306D089 @Alternate Data Stream - 163 bytes -> D:\ProgramData\Temp:F84B8DB5 @Alternate Data Stream - 153 bytes -> D:\ProgramData\Temp:4D066AD2 @Alternate Data Stream - 146 bytes -> D:\ProgramData\Temp:AB689DEA @Alternate Data Stream - 133 bytes -> D:\ProgramData\Temp:93DE1838 @Alternate Data Stream - 130 bytes -> D:\ProgramData\Temp:E1F04E8D @Alternate Data Stream - 129 bytes -> D:\ProgramData\Temp:1D32EC29 @Alternate Data Stream - 128 bytes -> D:\ProgramData\Temp:ABE89FFE @Alternate Data Stream - 125 bytes -> D:\ProgramData\Temp:E3C56885 @Alternate Data Stream - 121 bytes -> D:\ProgramData\Temp:0B9176C0 @Alternate Data Stream - 118 bytes -> D:\ProgramData\Temp:4CF61E54 < End of report > Geändert von Halo (10.08.2011 um 18:40 Uhr) |
10.08.2011, 18:44 | #4 |
| BKA UKASH Trojaner und Extras:OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 8/10/2011 9:32:04 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE 64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 90.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86) Drive C: | 100.00 Mb Total Space | 75.52 Mb Free Space | 75.52% Space Free | Partition Type: NTFS Drive D: | 286.27 Gb Total Space | 139.09 Gb Free Space | 48.59% Space Free | Partition Type: NTFS Drive E: | 7.45 Gb Total Space | 7.45 Gb Free Space | 99.98% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- D:\Windows\System32\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- D:\Windows\SysWow64\control.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0AFFEA39-60AF-4C4F-BB47-4A1F7CB12129}" = HP Deskjet F4500 All-in-One Driver Software 14.0 Rel. 6 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{48C0866E-57EB-444C-8371-8E4321066BC3}" = Network64 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{9125DC5B-1320-49B4-83C8-0B8FF4868DC3}" = IE Download Helper "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{96F70DF8-160F-4F9C-9B9E-2A9B439B4EB9}" = Broadcom Gigabit NetLink Controller "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 275.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 275.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 275.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.2.23.3 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer "{de2f2d9c-53e2-40ee-8209-74da63cb060f}" = Python 3.0.1 (64-bit) "{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD1}" = Paint.NET v3.5.5 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "CutePDF Writer Installation" = CutePDF Writer 2.8 "Expstudio Audio Editor FREE" = Expstudio Audio Editor FREE "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "LSI Soft Modem" = LSI HDA Modem "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0AFFEA39-60AF-4C4F-BB47-4A1F7CB12129}" = HP Deskjet F4500 All-in-One Driver Software 14.0 Rel. 6 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{48C0866E-57EB-444C-8371-8E4321066BC3}" = Network64 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{9125DC5B-1320-49B4-83C8-0B8FF4868DC3}" = IE Download Helper "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{96F70DF8-160F-4F9C-9B9E-2A9B439B4EB9}" = Broadcom Gigabit NetLink Controller "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 275.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 275.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 275.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.2.23.3 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer "{de2f2d9c-53e2-40ee-8209-74da63cb060f}" = Python 3.0.1 (64-bit) "{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD1}" = Paint.NET v3.5.5 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "CutePDF Writer Installation" = CutePDF Writer 2.8 "Expstudio Audio Editor FREE" = Expstudio Audio Editor FREE "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "LSI Soft Modem" = LSI HDA Modem "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver < End of report > |
10.08.2011, 21:22 | #5 |
| BKA UKASH Trojaner Hallo..habe jetzt im Abgesicherten Modus, über Ccleaner, im Autostart die Datei jaschla.exe und raixy.exe deaktiviert und gelöscht. Habe dadurch wieder vollen Zugriff auf mein System bekommen. Der Eintrag raixy schreibt sich allerdings nach einem Neustart wieder in die Registrie ein. Also weiss ich nicht ob der Trojaner tatsächlich entfernt ist oder ob die Datei raixy wichtig ist!(Systemzugriff besteht weiterhin) Über eine Antwort würde ich mich freuen. Danke |
Themen zu BKA UKASH Trojaner |
bka ukash, entfernung, schonmal, troja, trojane, trojaner, ukash, ukash trojaner |