|
Plagegeister aller Art und deren Bekämpfung: Bitte helft mir, meinen BKA-Trojaner zu beseitigen!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
16.08.2011, 20:39 | #16 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Wenn der Scan beendet ist, was mit Done! gemeldet wird, klicke Enter, um das Eingabe-Fenster zu schließen. Poste mir den Inhalt von MBRCheck_<datum>.txt vom Desktop hier in den Thread.
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
16.08.2011, 21:11 | #17 | ||
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Ich kann lesen und das habe ich auch schon gelesen. Aber bei mir erstellt er diese Textdatei, ohne dass ein Done! kommt.
__________________Folgendes steht da: Zitat:
Zitat:
also muss das ja die txt-dtei sein, die ich posten sollte. |
16.08.2011, 21:25 | #18 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! MBR mit MBRCheck ersetzen
__________________Wenn gemeldet wird: "Found non-standard or infected MBR": Achtung: Die folgenden Angaben gelten ausschließlich für diesen Computer! Nicht auf anderen Systemen benutzen! Bei Enter your choice eingeben => 2 (für restore the MBR of a physical disk with a standard boot code) und Enter drücken. Bei Enter the physical disc number to fix eingeben: 0 und Enter drücken. Bei Available MBR codes: / Please select the MBR code to write to disc: eingeben: 5 (für Windows 7) und Enter drücken. Bei Do you want to fix the MBR code? eingeben: YES und Enter drücken. Nun sollte mit Successfully wrote new MBR code! gemeldet werden, dass der MBR erfolgreich neu geschrieben wurde. Auf dem Desktop erscheint ein Logfile MBRCheck_<datum>.txt - bitte den Inhalt hier in den Thread posten. Nun den Computer neu starten und berichten, ob die Probleme noch vorhanden sind.[/QUOTE]
__________________ |
16.08.2011, 22:02 | #19 | |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Also beim Avira Scan hab ich jetzt, weil es so in der Anleitung stand, mit Rootkitsuche gemacht. Hoffe das ist nicht schlimm Zitat:
|
16.08.2011, 22:17 | #20 | |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Hier der MBRCheck Zitat:
|
17.08.2011, 05:22 | #21 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! ➊ Öffne CCleaner
➋ Alte Log-Datei löschen und das Tool nochmal ausführen Kontrolle mit MBR -t, ob Master Boot Record in Ordnung ist (MBR-Rootkit) Mit dem folgenden Tool prüfen wir, ob sich etwas Schädliches im Master Boot Record eingenistet hat.
➌ erneut einen Scan mit OTL:
__________________ --> Bitte helft mir, meinen BKA-Trojaner zu beseitigen! |
17.08.2011, 12:36 | #22 | |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen!Zitat:
Code:
ATTFilter OTL logfile created on: 17.08.2011 13:29:27 - Run 7 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Admin\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,71 Gb Available Physical Memory | 57,10% Memory free 6,18 Gb Paging File | 4,85 Gb Available in Paging File | 78,37% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 222,88 Gb Total Space | 157,03 Gb Free Space | 70,45% Space Free | Partition Type: NTFS Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.08.09 20:28:54 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe PRC - [2011.08.01 10:28:16 | 000,124,480 | ---- | M] (ICQ, LLC.) -- C:\Programme\ICQ7.5\ICQ.exe PRC - [2011.07.05 20:01:32 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2011.06.16 06:32:36 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2011.06.10 19:09:50 | 000,748,336 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe PRC - [2011.06.01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.03.28 16:15:17 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2011.03.28 16:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2011.03.28 16:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2008.05.22 17:33:54 | 000,688,128 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\SamSung\Easy Display Manager\dmhkcore.exe PRC - [2008.04.25 21:31:34 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\SamSung\EasySpeedUpManager\EasySpeedUpManager.exe PRC - [2008.04.17 20:50:00 | 006,111,232 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2008.04.17 15:26:46 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\SamSung\EBM\EasyBatteryMgr3.exe PRC - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2008.01.21 04:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2008.01.21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe PRC - [2007.07.05 07:41:42 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\SamSung\Samsung Magic Doctor\MagicDoctorKbdHk.exe PRC - [2007.04.03 18:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Programme\Canon\MyPrinter\BJMYPRT.EXE ========== Modules (SafeList) ========== MOD - [2011.08.09 20:28:54 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe MOD - [2010.08.31 17:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - [2011.07.05 20:01:32 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.06.01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6) SRV - [2011.03.28 16:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008.05.13 08:47:20 | 000,077,480 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus) SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) ========== Driver Services (SafeList) ========== DRV - [2011.07.05 20:01:32 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011.07.05 20:01:32 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.06.18 19:33:20 | 000,165,376 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2011.06.18 19:33:10 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2010.06.17 15:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2008.06.09 16:23:00 | 007,522,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2008.04.05 23:56:26 | 000,242,560 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vmc302.sys -- (VMC302) DRV - [2007.09.14 00:17:58 | 000,755,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2006.11.14 09:11:54 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KMDFMEMIO.sys -- (KMDFMEMIO) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://de-de.facebook.com/" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.07.04 20:37:20 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.04 20:37:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions [2011.08.09 15:08:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\2cazqile.default\extensions [2011.08.13 23:44:01 | 000,000,000 | ---D | M] (Collusion) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\2cazqile.default\extensions\jid1-F9UJ2thwoAm5gQ@jetpack [2011.07.09 12:15:31 | 000,005,212 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2cazqile.default\searchplugins\ecosia.xml [2011.08.13 21:29:59 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions File not found (No name found) -- () (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CAZQILE.DEFAULT\EXTENSIONS\{D04B0B40-3DAB-4F0B-97A6-04EC3EDDBFB0}.XPI () (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CAZQILE.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI [2011.06.10 07:34:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2011.06.16 06:32:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml O1 HOSTS File: ([2011.08.13 21:01:57 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [Power2GoExpress] File not found O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.08.16 00:51:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files [2011.08.15 22:11:47 | 124,539,416 | ---- | C] (Kaspersky Lab) -- C:\Users\Admin\Desktop\pure9.1.0.124de.exe [2011.08.14 13:39:22 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011.08.14 13:38:34 | 003,447,576 | ---- | C] (Piriform Ltd) -- C:\Users\Admin\Desktop\ccsetup309.exe [2011.08.13 21:29:58 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2011.08.13 21:01:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2011.08.13 17:52:18 | 000,000,000 | ---D | C] -- C:\_OTL [2011.08.13 16:03:25 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2011.08.13 16:01:35 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe [2011.08.13 15:01:11 | 000,100,864 | ---- | C] (GMER) -- C:\aglorpod.sys [2011.08.13 12:36:22 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe [2011.08.12 09:42:50 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{338FF2CA-3989-44E5-BF69-7E14A276D5BE} [2011.08.12 09:42:36 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{1BAEED21-5972-480A-94CE-6A8A62D7931B} [2011.08.12 09:16:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{511A0DD0-D1E8-44F8-A9DA-7AA6A9740D82} [2011.08.11 20:24:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2011.08.11 20:20:51 | 019,075,976 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup_4.2.0.187.exe [2011.08.11 19:22:43 | 001,081,480 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2011.08.11 19:22:03 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011.08.11 19:06:03 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2011.08.11 19:02:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SamSung [2011.08.11 19:02:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer [2011.08.11 18:58:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011.08.11 18:58:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atheros WLAN Client [2011.08.11 16:51:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.08.11 16:47:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{3D030450-9D94-45EB-8361-913E16DD713C} [2011.08.11 16:46:31 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{BCB02616-5F94-4466-840D-D38F461A866E} [2011.08.11 16:33:10 | 001,404,720 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe [2011.08.10 13:45:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{B7021062-028F-4C93-9DE1-57C1B9825AE8} [2011.08.10 13:43:39 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{6663092A-5C4E-46FB-8A4D-D67248609360} [2011.08.09 21:22:59 | 009,466,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Program Files\mbam-setup-1.51.1.1800.exe [2011.08.09 18:00:56 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes [2011.08.09 17:59:55 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011.08.09 17:59:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.08.09 17:59:37 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.08.09 17:59:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011.08.09 17:28:42 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch [2011.08.09 13:43:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\BaFög [2011.08.09 11:57:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{674DFE49-F584-4EF6-B17C-9C8BA7624020} [2011.08.09 11:57:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{7878D6C1-150C-4EAE-9B96-AAB755BFC765} [2011.08.08 16:00:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A3E22906-1A54-4411-9B26-CDB7921A5418} [2011.08.08 15:59:56 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{C2E8339B-55B4-467F-B3A8-5FCCCCB8095C} [2011.08.07 23:44:59 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{3ADAE302-1C44-4D76-91A3-BE9B1D22380F} [2011.08.07 23:44:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{B61B1800-7037-447A-AC1F-ED3D870F730E} [2011.08.06 16:42:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{C3705ED2-D531-4179-AFB0-FC317CFC8E91} [2011.08.05 11:49:46 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{1D8B70B1-2766-44FA-9577-AB161998536F} [2011.08.05 11:49:28 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{2BC1701D-E2B1-40E0-8E89-1B9C2F090BD2} [2011.08.04 10:26:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{F97D3A39-F6E8-463B-BBA5-C1571B776E03} [2011.08.04 10:26:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{8EE4828D-641E-42E2-B3EA-344405A1CDB2} [2011.08.04 00:31:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{14DBF0F1-FD34-45B7-A7C9-7762BCC738B0} [2011.08.03 16:50:52 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\2011_08_03 [2011.08.03 16:45:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Canon [2011.08.03 16:44:13 | 000,000,000 | ---D | C] -- C:\ProgramData\CanonBJ [2011.08.03 16:42:56 | 000,216,064 | ---- | C] (CANON INC.) -- C:\Windows\System32\CNMLM8S.DLL [2011.08.03 16:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Canon [2011.08.03 11:21:45 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{98616688-5746-46E2-96D5-3709E60B4703} [2011.08.03 11:21:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{0CB8A063-7C8B-4223-8722-EBBD2C4E802E} [2011.08.03 11:21:36 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{5EDE80A4-4D84-474E-824E-2A8964E5C013} [2011.08.02 21:35:50 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{F07CD4EB-65A8-4BBA-B481-D7F625632802} [2011.08.02 21:35:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{5DFB23BD-67FF-4D88-B448-2D811D95327F} [2011.08.02 09:55:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\Meine empfangenen Dateien [2011.08.02 09:35:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{B3EFD0B3-F8A5-4A63-9284-FE196D2E8E91} [2011.08.02 09:35:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A2F75EDF-27B3-4307-81FD-7F36B366A816} [2011.08.02 01:08:13 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\prince [2011.08.01 01:38:48 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{2130C5B3-0AAC-4FC6-8C59-7BCA0B26D3F9} [2011.08.01 01:32:08 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{E04867DC-9E03-440E-B78E-56E984C3FD74} [2011.07.29 15:09:54 | 002,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.07.29 15:09:51 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll [2011.07.29 15:09:51 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2011.07.27 20:41:48 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2011.07.26 10:28:12 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{21F991C7-1540-44DB-BD67-8E4896DFD49E} [2011.07.25 17:51:02 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{30CAD578-2435-459C-A7CC-3F5021053DE7} [2011.07.25 17:50:47 | 000,000,000 | ---D | C] -- C:\Users\Admin\Tracing [2011.07.25 17:19:03 | 000,000,000 | ---D | C] -- C:\Windows\de [2011.07.25 17:17:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition [2011.07.25 17:15:39 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2011.07.25 17:15:24 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live [2011.07.25 17:13:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2011.07.25 17:13:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2011.07.25 17:12:00 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Windows Live [2011.07.25 17:11:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live [2006.11.24 23:14:44 | 000,139,264 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK_wiz.dll [2006.11.24 23:14:44 | 000,126,976 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK.dll ========== Files - Modified Within 30 Days ========== [2011.08.17 13:20:25 | 000,027,839 | ---- | M] () -- C:\ProgramData\nvModes.001 [2011.08.17 13:19:57 | 000,027,839 | ---- | M] () -- C:\ProgramData\nvModes.dat [2011.08.17 13:18:29 | 000,000,374 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2011.08.17 13:18:15 | 000,003,712 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.08.17 13:18:14 | 000,003,712 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.08.17 13:18:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.08.17 13:17:35 | 3215,552,512 | -HS- | M] () -- C:\hiberfil.sys [2011.08.17 13:14:35 | 000,037,584 | ---- | M] () -- C:\Users\Admin\Desktop\cc_20110817_131424.reg [2011.08.16 23:51:24 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2011.08.16 20:21:58 | 000,080,384 | ---- | M] () -- C:\Users\Admin\Desktop\MBRCheck.exe [2011.08.15 22:14:45 | 124,539,416 | ---- | M] (Kaspersky Lab) -- C:\Users\Admin\Desktop\pure9.1.0.124de.exe [2011.08.14 14:09:22 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.08.14 14:09:22 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.08.14 14:09:22 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.08.14 14:09:22 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.08.14 13:39:23 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.08.14 13:38:36 | 003,447,576 | ---- | M] (Piriform Ltd) -- C:\Users\Admin\Desktop\ccsetup309.exe [2011.08.14 11:40:08 | 000,089,088 | ---- | M] () -- C:\Windows\System32\mbr.exe [2011.08.14 11:40:08 | 000,089,088 | ---- | M] () -- C:\Users\Admin\Desktop\mbr.exe [2011.08.13 23:06:16 | 000,014,120 | ---- | M] () -- C:\Users\Admin\Documents\bookmarks-2011-08-13.json [2011.08.13 21:26:55 | 000,000,040 | ---- | M] () -- C:\Users\Public\Documents\_rgpl [2011.08.13 21:01:57 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts [2011.08.13 16:01:36 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe [2011.08.13 15:01:11 | 000,100,864 | ---- | M] (GMER) -- C:\aglorpod.sys [2011.08.13 14:45:17 | 000,302,592 | ---- | M] () -- C:\Users\Admin\Desktop\6xnt2mxq.exe [2011.08.12 02:48:29 | 000,000,846 | ---- | M] () -- C:\Users\Admin\Desktop\firefox - Verknüpfung.lnk [2011.08.11 20:25:47 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat [2011.08.11 20:21:12 | 019,075,976 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup_4.2.0.187.exe [2011.08.11 19:23:10 | 001,081,480 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2011.08.11 18:52:48 | 000,000,104 | ---- | M] () -- C:\Users\Admin\Desktop\Computer - Verknüpfung.lnk [2011.08.11 16:51:38 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.08.11 16:33:10 | 001,404,720 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe [2011.08.09 20:28:54 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe [2011.08.09 20:28:06 | 009,466,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Program Files\mbam-setup-1.51.1.1800.exe [2011.08.09 17:52:01 | 000,252,888 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.07.30 20:13:15 | 000,020,480 | ---- | M] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== Files Created - No Company Name ========== [2011.08.17 13:14:32 | 000,037,584 | ---- | C] () -- C:\Users\Admin\Desktop\cc_20110817_131424.reg [2011.08.16 20:22:05 | 000,080,384 | ---- | C] () -- C:\Users\Admin\Desktop\MBRCheck.exe [2011.08.14 13:39:23 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.08.14 11:41:12 | 000,089,088 | ---- | C] () -- C:\Windows\System32\mbr.exe [2011.08.14 11:40:22 | 000,089,088 | ---- | C] () -- C:\Users\Admin\Desktop\mbr.exe [2011.08.14 10:19:42 | 3215,552,512 | -HS- | C] () -- C:\hiberfil.sys [2011.08.13 23:06:16 | 000,014,120 | ---- | C] () -- C:\Users\Admin\Documents\bookmarks-2011-08-13.json [2011.08.13 21:26:55 | 000,000,040 | ---- | C] () -- C:\Users\Public\Documents\_rgpl [2011.08.13 14:45:25 | 000,302,592 | ---- | C] () -- C:\Users\Admin\Desktop\6xnt2mxq.exe [2011.08.12 02:48:29 | 000,000,846 | ---- | C] () -- C:\Users\Admin\Desktop\firefox - Verknüpfung.lnk [2011.08.11 20:25:47 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011.08.11 20:24:16 | 000,002,379 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk [2011.08.11 18:52:48 | 000,000,104 | ---- | C] () -- C:\Users\Admin\Desktop\Computer - Verknüpfung.lnk [2011.08.11 16:51:38 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.08.09 17:22:59 | 000,504,657 | ---- | C] () -- C:\Users\Admin\Desktop\unhide.exe [2011.07.04 20:37:23 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2011.06.18 19:33:20 | 000,165,376 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2011.06.18 19:33:10 | 000,018,048 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2011.06.12 23:40:48 | 000,023,580 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\UserTile.png [2011.06.10 18:03:18 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011.06.10 07:35:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2011.06.10 07:35:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2011.06.09 21:15:21 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2011.06.09 20:43:28 | 000,020,480 | ---- | C] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.06.09 19:13:49 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011.06.09 18:44:14 | 000,000,684 | ---- | C] () -- C:\Windows\HotFixList.ini [2011.06.09 18:40:46 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2011.06.09 18:39:06 | 000,027,839 | ---- | C] () -- C:\ProgramData\nvModes.001 [2011.06.09 18:39:05 | 000,027,839 | ---- | C] () -- C:\ProgramData\nvModes.dat [2011.06.09 18:25:49 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini [2011.06.09 18:25:49 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini [2011.06.09 18:16:42 | 000,040,960 | ---- | C] () -- C:\Windows\System32\IhDEV.exe [2011.06.09 18:16:42 | 000,024,576 | ---- | C] () -- C:\Windows\System32\IhINF.exe [2011.06.09 18:05:05 | 000,000,680 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat [2008.01.21 09:15:58 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.01.21 09:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.01.21 09:15:58 | 000,126,454 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.01.21 09:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2007.02.26 16:49:12 | 006,139,774 | ---- | C] () -- C:\Windows\System32\imagine digital freedom.dat [2007.02.16 01:51:02 | 000,274,432 | ---- | C] () -- C:\Windows\System32\NDADLL.dll [2006.11.30 02:00:30 | 000,045,056 | ---- | C] () -- C:\Windows\System32\MAWebControl.exe [2006.11.30 02:00:28 | 000,307,200 | ---- | C] () -- C:\Windows\System32\LDBGenWizView.dll [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 14:47:37 | 000,252,888 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 12:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006.10.09 19:01:28 | 000,061,440 | ---- | C] () -- C:\Windows\System32\AVSAudioWideStereoDMO.dll ========== LOP Check ========== [2011.08.03 16:45:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Canon [2011.08.16 21:03:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ICQ [2011.06.12 23:40:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PeerNetworking [2011.08.17 13:15:33 | 000,032,572 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 17.08.2011 13:29:27 - Run 7 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Admin\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,71 Gb Available Physical Memory | 57,10% Memory free 6,18 Gb Paging File | 4,85 Gb Available in Paging File | 78,37% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 222,88 Gb Total Space | 157,03 Gb Free Space | 70,45% Space Free | Partition Type: NTFS Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = htmlfile] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-679186329-3352478774-2945693008-1000] "EnableNotifications" = 0 "EnableNotificationsRef" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0ADBA36C-E641-4E0B-91E4-F52954F52A2B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{13251F6D-25E0-4221-9637-A62C4D4D30BD}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{15146B19-FF7C-4855-B6A5-F90DF6178022}" = rport=137 | protocol=17 | dir=out | app=system | "{1556D602-93B9-4300-9751-14F06D0CE541}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{2A26A99E-F55F-4B15-9582-4EA040562D0D}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{3BFD8104-3A86-4E03-B26F-002F23B03C55}" = rport=445 | protocol=6 | dir=out | app=system | "{3EA02309-F11D-43D6-B8A2-9FD85A3D0379}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{418FEDB7-73DA-4219-94CC-929D2A794FB1}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{4E35DF6D-A8A9-4EF8-9069-5B3F33732498}" = rport=138 | protocol=17 | dir=out | app=system | "{616BE416-E9D8-41D4-99AC-5B435FA21864}" = lport=137 | protocol=17 | dir=in | app=system | "{68F19B96-B633-4690-B3D4-58A1AD7A55B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6A0A9154-99C3-41EE-808F-4950353357CF}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{80BDE7CD-9EAC-4CC7-AF1D-CEA1687DDDAB}" = rport=139 | protocol=6 | dir=out | app=system | "{82B1649E-4EC5-4FDD-92AA-51586073F31E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8FF5DC36-0D3D-4C5D-923D-94345E33431D}" = lport=445 | protocol=6 | dir=in | app=system | "{96B24376-A280-4CF0-B713-7D33B7B00D0D}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{A858AEEC-1AF3-4567-80C7-F74D8E781589}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{B9E2BBE0-5FA5-46FD-A9D0-D063A19F6FA2}" = lport=138 | protocol=17 | dir=in | app=system | "{BAC83331-82BE-4637-A7EB-2FE71F8E45B5}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{C3B2B21E-8511-48BA-9950-8824CE9B6137}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C9BAD1CC-2E9A-42AB-894A-946EC7BE733F}" = rport=2869 | protocol=6 | dir=out | app=system | "{CF281BBD-7CBA-463A-BF8F-48A1E6B189E0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{D86575B9-5514-45B5-B955-9CC47207AE48}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{DE7966DE-3C54-4E2B-8A8F-5E0826D16F2C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E3209084-DED2-44B0-B131-517FED2C2BB4}" = lport=2869 | protocol=6 | dir=in | app=system | "{EE17490A-453A-486B-B5C7-0465038C5149}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{F9B9108C-5B4F-4DEF-B0E0-C64DE3D2D4DC}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{F9F82218-D3F2-4985-959E-0E1D83D6A671}" = lport=139 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0C4058D6-466F-4DF1-8563-1B73AEE2D085}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{0C437E0D-541C-4A3E-9877-3CB2E2264674}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{0CC42F0B-CC1E-4F19-9CB2-2EE06B02D19B}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{1BEE355E-14A5-4746-BF13-EA3B60C96C5C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{2108BD04-B816-4659-888A-A05815F9B6D7}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version6\teamviewer_service.exe | "{241813D0-BD8C-4D2E-B14E-573B85D04586}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version6\teamviewer.exe | "{242D6C48-4222-4C19-9664-76D0D433963F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{2AAED9A4-B04B-4EAE-83F7-0C647FF5A478}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{2B51C36C-4B96-4F79-ADBB-F2AF837D739C}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{317F13BB-C9FF-48A7-8247-4C91F90CC3EE}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version6\teamviewer_service.exe | "{371F089A-29CE-4E27-91B0-CEFB40B05906}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{42B3BFF8-CFC3-4C1E-9D81-5CF0C4E10189}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{452F5643-B50A-4ABE-A191-84E6726320D6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{50EAF023-5BCC-44EC-852D-874FEBECA39F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{515DAF4F-EA65-497A-A014-48D276D03453}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{55A87A74-1A9A-4D92-9EFB-F8AF3E176A5C}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{577E609D-0042-441B-9138-18B56DF9A621}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{5D54B558-6AB3-4876-BF74-FCFFCFAECE96}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{675F1147-6BCD-43FC-95F3-5983294485F1}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{6BA6EBB8-462F-40EA-88C1-7CB1D1A90937}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{7C6BDC9A-7F9C-4A1B-9E2B-0137A77E2188}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{833CB862-9911-4101-B067-16A1BA9BE03F}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{9D8FE41A-DCE3-4D9E-A33C-9E2F049ED668}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{ACCED9F2-1245-4269-AB9E-3674FFD9510B}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{AD7F6F1F-5F9F-46E7-953C-F1E77037A50D}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{AEE2E7C9-17AB-46EA-915F-DFDE265E690F}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version6\teamviewer.exe | "{B0C7792B-9FEC-42DE-B083-52B028054523}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B2ED03F3-4D9B-4E3C-A5FB-D554337F389F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B3A0AE9B-1CF5-4653-B159-6BC9BB0E3279}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{B426F91E-BB9F-40C5-808F-CAA63E1AF467}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B99F807B-FE70-4F9D-ABFC-C2DFA8447397}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{BDA0A150-C483-4122-ADD0-BCCC88C1B4BA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{BECF143A-F351-4F69-B285-16B7370859C6}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{BEF99939-DA35-4AF6-A55C-12A938A6ED13}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{C6FFC124-EE7F-4C96-BFD3-39702B72F407}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe | "{E08B9F28-9A1B-4176-AF59-F366E0E6B6B5}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FDD100B9-ED24-45FB-A6A0-4F38A60195D5}" = dir=in | app=c:\program files\skype\phone\skype.exe | "TCP Query User{6B966A52-A656-44C7-9657-4F933945FC93}C:\program files\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "TCP Query User{A51E600C-B375-49E0-91BB-0ACB096B7221}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe | "UDP Query User{69901D32-F6D1-4CC7-8085-8AF950869624}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe | "UDP Query User{873C3911-A7F4-4B1F-8E0B-7F3230495136}C:\program files\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1 "{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung "{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2 "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{58D68DF0-4E8B-4E9E-B425-670F9E37C1A8}" = TES Construction Set "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera "{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5 "{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90110407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AC76BA86-7AD7-1031-7B44-A81000000003}" = Adobe Reader 8.1.0 - Deutsch "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CanonMyPrinter" = Canon My Printer "CCleaner" = CCleaner "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "ESET Online Scanner" = ESET Online Scanner v3 "InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.1.1800 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 5.0 (x86 de)" = Mozilla Firefox 5.0 (x86 de) "MP Navigator EX 1.0" = Canon MP Navigator EX 1.0 "NVIDIA Drivers" = NVIDIA Drivers "SynTPDeinstKey" = Synaptics Pointing Device Driver "TeamViewer 6" = TeamViewer 6 "VLC media player" = VLC media player 1.1.10 "WinLiveSuite" = Windows Live Essentials "YDKJG3" = YOU DON'T KNOW JACK® 3 - Abwärts! ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 15.08.2011 18:40:46 | Computer Name = Admin-PC | Source = Windows Search Service | ID = 3013 Description = Error - 15.08.2011 18:40:46 | Computer Name = Admin-PC | Source = Windows Search Service | ID = 3013 Description = Error - 15.08.2011 19:48:01 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 04:30:38 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 04:44:47 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 11:56:38 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 13:28:45 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 17:13:45 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 07:04:22 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 07:19:24 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = [ Media Center Events ] Error - 12.06.2011 02:10:16 | Computer Name = Admin-PC | Source = Media Center Guide | ID = 0 Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed; Win32 GetLastError returned 0D Prozess: DefaultDomain Objektname: Media Center Guide [ System Events ] Error - 09.06.2011 15:28:20 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 09.06.2011 15:28:36 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 09.06.2011 15:32:47 | Computer Name = Admin-PC | Source = DCOM | ID = 10010 Description = Error - 09.06.2011 15:58:06 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 09.06.2011 15:59:23 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 10.06.2011 00:54:44 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 10.06.2011 00:56:02 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 10.06.2011 11:56:25 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 10.06.2011 11:56:52 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 10.06.2011 12:32:36 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > fertig hoffentlich kannst du damit etwas anfangen |
17.08.2011, 13:48 | #23 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! gehe zu diesem Link und folge der Anleitung um den MBR zu reparieren:-> http://www.wintotal.de/tipparchiv/?id=1695 verwende Die Option /FixMbr !
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
17.08.2011, 16:30 | #24 |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Dieses Programm Bootrec.exe, muss ich das erst runterladen oder wie? Wenn ich die DVD einlege, erscheint kein "Computerreparationsoptionen" sondern nur Kompatibilität online prüfen -> Jetzt installieren -> und darunter Wissenswertes vor der Windows-Installation Datein und Einstellungen von einem anderen Computer übertragen Geändert von me pure (17.08.2011 um 16:39 Uhr) |
17.08.2011, 16:59 | #25 |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Ok hab mich durchgefuchst und hab es hinbekommen. Nach der Eingabe hab ich den Computer neu gestartet, wie als Option auszuwählen war. Jetzt kommt bestimmt nochmal ein OTL-Scan zur Überprüfung, oder? Ist der PC jetzt sauber? |
17.08.2011, 17:50 | #26 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! 1. versuche jetzt Kaspersky erneut ausführen..:-> http://www.trojaner-board.de/102477-...tml#post693235 wenn gelingt es nicht: 2. Kontrolle mit MBR -t, ob Master Boot Record in Ordnung ist (MBR-Rootkit) Mit dem folgenden Tool prüfen wir, ob sich etwas Schädliches im Master Boot Record eingenistet hat.
3. erneut einen Scan mit OTL:
► berichte erneut über den Zustand des Computers. Ob noch Probleme auftreten, wenn ja, welche?
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
17.08.2011, 18:24 | #27 | |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Yeah, der tdsskiller hat funktioniert!!!bin erstmal erleichtert. Zitat:
und hier die OTL-logs OTL Logfile: Code:
ATTFilter OTL logfile created on: 17.08.2011 19:20:31 - Run 8 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Admin\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,71% Memory free 6,21 Gb Paging File | 5,13 Gb Available in Paging File | 82,63% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 222,88 Gb Total Space | 156,46 Gb Free Space | 70,20% Space Free | Partition Type: NTFS Drive D: | 2,89 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.08.17 14:44:35 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2011.08.09 20:28:54 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe PRC - [2011.08.01 10:28:16 | 000,124,480 | ---- | M] (ICQ, LLC.) -- C:\Programme\ICQ7.5\ICQ.exe PRC - [2011.07.05 20:01:32 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2011.06.01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.03.28 16:15:17 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2011.03.28 16:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2011.03.28 16:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.05.22 17:33:54 | 000,688,128 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\SamSung\Easy Display Manager\dmhkcore.exe PRC - [2008.04.25 21:31:34 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\SamSung\EasySpeedUpManager\EasySpeedUpManager.exe PRC - [2008.04.17 20:50:00 | 006,111,232 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2008.04.17 15:26:46 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\SamSung\EBM\EasyBatteryMgr3.exe PRC - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2008.01.21 04:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe PRC - [2008.01.21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe PRC - [2007.07.05 07:41:42 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\SamSung\Samsung Magic Doctor\MagicDoctorKbdHk.exe PRC - [2007.04.03 18:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Programme\Canon\MyPrinter\BJMYPRT.EXE ========== Modules (SafeList) ========== MOD - [2011.08.09 20:28:54 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe MOD - [2010.08.31 17:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - [2011.07.05 20:01:32 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.06.01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6) SRV - [2011.03.28 16:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008.05.13 08:47:20 | 000,077,480 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus) SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) ========== Driver Services (SafeList) ========== DRV - [2011.07.05 20:01:32 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011.07.05 20:01:32 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.06.18 19:33:20 | 000,165,376 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2011.06.18 19:33:10 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2010.06.17 15:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2008.06.09 16:23:00 | 007,522,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2008.04.05 23:56:26 | 000,242,560 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vmc302.sys -- (VMC302) DRV - [2007.09.14 00:17:58 | 000,755,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2006.11.14 09:11:54 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KMDFMEMIO.sys -- (KMDFMEMIO) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://de-de.facebook.com/" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.08.17 14:44:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.04 20:37:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions [2011.08.09 15:08:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\2cazqile.default\extensions [2011.08.13 23:44:01 | 000,000,000 | ---D | M] (Collusion) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\2cazqile.default\extensions\jid1-F9UJ2thwoAm5gQ@jetpack [2011.07.09 12:15:31 | 000,005,212 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2cazqile.default\searchplugins\ecosia.xml [2011.08.13 21:29:59 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions File not found (No name found) -- () (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CAZQILE.DEFAULT\EXTENSIONS\{D04B0B40-3DAB-4F0B-97A6-04EC3EDDBFB0}.XPI () (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2CAZQILE.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI [2011.06.10 07:34:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2011.08.17 14:44:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml O1 HOSTS File: ([2011.08.13 21:01:57 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [Power2GoExpress] File not found O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008.01.19 22:00:00 | 000,000,043 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{cec9f574-92b6-11e0-ba72-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{cec9f574-92b6-11e0-ba72-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE -- [2008.01.19 22:00:00 | 000,111,672 | R--- | M] (Microsoft Corporation) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.08.17 17:35:22 | 000,000,000 | ---D | C] -- C:\$WINDOWS.~BT [2011.08.16 00:51:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files [2011.08.15 22:11:47 | 124,539,416 | ---- | C] (Kaspersky Lab) -- C:\Users\Admin\Desktop\pure9.1.0.124de.exe [2011.08.14 13:39:22 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011.08.14 13:38:34 | 003,447,576 | ---- | C] (Piriform Ltd) -- C:\Users\Admin\Desktop\ccsetup309.exe [2011.08.13 21:29:58 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2011.08.13 21:01:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2011.08.13 17:52:18 | 000,000,000 | ---D | C] -- C:\_OTL [2011.08.13 16:03:25 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2011.08.13 16:01:35 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe [2011.08.13 15:01:11 | 000,100,864 | ---- | C] (GMER) -- C:\aglorpod.sys [2011.08.13 12:36:22 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe [2011.08.12 09:42:50 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{338FF2CA-3989-44E5-BF69-7E14A276D5BE} [2011.08.12 09:42:36 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{1BAEED21-5972-480A-94CE-6A8A62D7931B} [2011.08.12 09:16:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{511A0DD0-D1E8-44F8-A9DA-7AA6A9740D82} [2011.08.11 20:24:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2011.08.11 20:20:51 | 019,075,976 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup_4.2.0.187.exe [2011.08.11 19:22:43 | 001,081,480 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2011.08.11 19:22:03 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011.08.11 19:06:03 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2011.08.11 19:02:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SamSung [2011.08.11 19:02:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer [2011.08.11 18:58:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011.08.11 18:58:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atheros WLAN Client [2011.08.11 16:51:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.08.11 16:47:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{3D030450-9D94-45EB-8361-913E16DD713C} [2011.08.11 16:46:31 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{BCB02616-5F94-4466-840D-D38F461A866E} [2011.08.11 16:33:10 | 001,404,720 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe [2011.08.10 13:45:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{B7021062-028F-4C93-9DE1-57C1B9825AE8} [2011.08.10 13:43:39 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{6663092A-5C4E-46FB-8A4D-D67248609360} [2011.08.09 21:22:59 | 009,466,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Program Files\mbam-setup-1.51.1.1800.exe [2011.08.09 18:00:56 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes [2011.08.09 17:59:55 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011.08.09 17:59:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.08.09 17:59:37 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.08.09 17:59:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011.08.09 17:28:42 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch [2011.08.09 13:43:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\BaFög [2011.08.09 11:57:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{674DFE49-F584-4EF6-B17C-9C8BA7624020} [2011.08.09 11:57:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{7878D6C1-150C-4EAE-9B96-AAB755BFC765} [2011.08.08 16:00:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A3E22906-1A54-4411-9B26-CDB7921A5418} [2011.08.08 15:59:56 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{C2E8339B-55B4-467F-B3A8-5FCCCCB8095C} [2011.08.07 23:44:59 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{3ADAE302-1C44-4D76-91A3-BE9B1D22380F} [2011.08.07 23:44:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{B61B1800-7037-447A-AC1F-ED3D870F730E} [2011.08.06 16:42:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{C3705ED2-D531-4179-AFB0-FC317CFC8E91} [2011.08.05 11:49:46 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{1D8B70B1-2766-44FA-9577-AB161998536F} [2011.08.05 11:49:28 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{2BC1701D-E2B1-40E0-8E89-1B9C2F090BD2} [2011.08.04 10:26:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{F97D3A39-F6E8-463B-BBA5-C1571B776E03} [2011.08.04 10:26:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{8EE4828D-641E-42E2-B3EA-344405A1CDB2} [2011.08.04 00:31:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{14DBF0F1-FD34-45B7-A7C9-7762BCC738B0} [2011.08.03 16:50:52 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\2011_08_03 [2011.08.03 16:45:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Canon [2011.08.03 16:44:13 | 000,000,000 | ---D | C] -- C:\ProgramData\CanonBJ [2011.08.03 16:42:56 | 000,216,064 | ---- | C] (CANON INC.) -- C:\Windows\System32\CNMLM8S.DLL [2011.08.03 16:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Canon [2011.08.03 11:21:45 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{98616688-5746-46E2-96D5-3709E60B4703} [2011.08.03 11:21:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{0CB8A063-7C8B-4223-8722-EBBD2C4E802E} [2011.08.03 11:21:36 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{5EDE80A4-4D84-474E-824E-2A8964E5C013} [2011.08.02 21:35:50 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{F07CD4EB-65A8-4BBA-B481-D7F625632802} [2011.08.02 21:35:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{5DFB23BD-67FF-4D88-B448-2D811D95327F} [2011.08.02 09:55:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\Meine empfangenen Dateien [2011.08.02 09:35:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{B3EFD0B3-F8A5-4A63-9284-FE196D2E8E91} [2011.08.02 09:35:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A2F75EDF-27B3-4307-81FD-7F36B366A816} [2011.08.02 01:08:13 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\prince [2011.08.01 01:38:48 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{2130C5B3-0AAC-4FC6-8C59-7BCA0B26D3F9} [2011.08.01 01:32:08 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{E04867DC-9E03-440E-B78E-56E984C3FD74} [2011.07.29 15:09:54 | 002,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.07.29 15:09:51 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll [2011.07.29 15:09:51 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2011.07.27 20:41:48 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2011.07.26 10:28:12 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{21F991C7-1540-44DB-BD67-8E4896DFD49E} [2011.07.25 17:51:02 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{30CAD578-2435-459C-A7CC-3F5021053DE7} [2011.07.25 17:50:47 | 000,000,000 | ---D | C] -- C:\Users\Admin\Tracing [2011.07.25 17:19:03 | 000,000,000 | ---D | C] -- C:\Windows\de [2011.07.25 17:17:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition [2011.07.25 17:15:39 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2011.07.25 17:15:24 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live [2011.07.25 17:13:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2011.07.25 17:13:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2011.07.25 17:12:00 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Windows Live [2011.07.25 17:11:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live [2006.11.24 23:14:44 | 000,139,264 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK_wiz.dll [2006.11.24 23:14:44 | 000,126,976 | ---- | C] ( ) -- C:\Windows\System32\MACSSDK.dll ========== Files - Modified Within 30 Days ========== [2011.08.17 19:21:30 | 000,027,839 | ---- | M] () -- C:\ProgramData\nvModes.001 [2011.08.17 17:54:13 | 000,000,374 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2011.08.17 17:53:55 | 000,027,839 | ---- | M] () -- C:\ProgramData\nvModes.dat [2011.08.17 17:53:43 | 000,003,712 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.08.17 17:53:43 | 000,003,712 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.08.17 17:53:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.08.17 17:53:32 | 3215,572,992 | -HS- | M] () -- C:\hiberfil.sys [2011.08.17 17:39:47 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml [2011.08.17 17:39:47 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml [2011.08.17 17:34:39 | 000,000,204 | ---- | M] () -- C:\Users\Admin\Desktop\CD-Laufwerk - Verknüpfung.lnk [2011.08.17 13:14:35 | 000,037,584 | ---- | M] () -- C:\Users\Admin\Desktop\cc_20110817_131424.reg [2011.08.16 23:51:24 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2011.08.16 20:21:58 | 000,080,384 | ---- | M] () -- C:\Users\Admin\Desktop\MBRCheck.exe [2011.08.15 22:14:45 | 124,539,416 | ---- | M] (Kaspersky Lab) -- C:\Users\Admin\Desktop\pure9.1.0.124de.exe [2011.08.14 14:09:22 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.08.14 14:09:22 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.08.14 14:09:22 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.08.14 14:09:22 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.08.14 13:39:23 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.08.14 13:38:36 | 003,447,576 | ---- | M] (Piriform Ltd) -- C:\Users\Admin\Desktop\ccsetup309.exe [2011.08.14 11:40:08 | 000,089,088 | ---- | M] () -- C:\Windows\System32\mbr.exe [2011.08.14 11:40:08 | 000,089,088 | ---- | M] () -- C:\Users\Admin\Desktop\mbr.exe [2011.08.13 23:06:16 | 000,014,120 | ---- | M] () -- C:\Users\Admin\Documents\bookmarks-2011-08-13.json [2011.08.13 21:26:55 | 000,000,040 | ---- | M] () -- C:\Users\Public\Documents\_rgpl [2011.08.13 21:01:57 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts [2011.08.13 16:01:36 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe [2011.08.13 15:01:11 | 000,100,864 | ---- | M] (GMER) -- C:\aglorpod.sys [2011.08.13 14:45:17 | 000,302,592 | ---- | M] () -- C:\Users\Admin\Desktop\6xnt2mxq.exe [2011.08.12 02:48:29 | 000,000,846 | ---- | M] () -- C:\Users\Admin\Desktop\firefox - Verknüpfung.lnk [2011.08.11 20:25:47 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat [2011.08.11 20:21:12 | 019,075,976 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup_4.2.0.187.exe [2011.08.11 19:23:10 | 001,081,480 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2011.08.11 18:52:48 | 000,000,104 | ---- | M] () -- C:\Users\Admin\Desktop\Computer - Verknüpfung.lnk [2011.08.11 16:51:38 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.08.11 16:33:10 | 001,404,720 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe [2011.08.09 20:28:54 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe [2011.08.09 20:28:06 | 009,466,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Program Files\mbam-setup-1.51.1.1800.exe [2011.08.09 17:52:01 | 000,252,888 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.07.30 20:13:15 | 000,020,480 | ---- | M] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== Files Created - No Company Name ========== [2011.08.17 17:34:39 | 000,000,204 | ---- | C] () -- C:\Users\Admin\Desktop\CD-Laufwerk - Verknüpfung.lnk [2011.08.17 13:14:32 | 000,037,584 | ---- | C] () -- C:\Users\Admin\Desktop\cc_20110817_131424.reg [2011.08.16 20:22:05 | 000,080,384 | ---- | C] () -- C:\Users\Admin\Desktop\MBRCheck.exe [2011.08.14 13:39:23 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2011.08.14 11:41:12 | 000,089,088 | ---- | C] () -- C:\Windows\System32\mbr.exe [2011.08.14 11:40:22 | 000,089,088 | ---- | C] () -- C:\Users\Admin\Desktop\mbr.exe [2011.08.14 10:19:42 | 3215,572,992 | -HS- | C] () -- C:\hiberfil.sys [2011.08.13 23:06:16 | 000,014,120 | ---- | C] () -- C:\Users\Admin\Documents\bookmarks-2011-08-13.json [2011.08.13 21:26:55 | 000,000,040 | ---- | C] () -- C:\Users\Public\Documents\_rgpl [2011.08.13 14:45:25 | 000,302,592 | ---- | C] () -- C:\Users\Admin\Desktop\6xnt2mxq.exe [2011.08.12 02:48:29 | 000,000,846 | ---- | C] () -- C:\Users\Admin\Desktop\firefox - Verknüpfung.lnk [2011.08.11 20:25:47 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011.08.11 20:24:16 | 000,002,379 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk [2011.08.11 18:52:48 | 000,000,104 | ---- | C] () -- C:\Users\Admin\Desktop\Computer - Verknüpfung.lnk [2011.08.11 16:51:38 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.08.09 17:22:59 | 000,504,657 | ---- | C] () -- C:\Users\Admin\Desktop\unhide.exe [2011.07.04 20:37:23 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2011.06.18 19:33:20 | 000,165,376 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2011.06.18 19:33:10 | 000,018,048 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2011.06.12 23:40:48 | 000,023,580 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\UserTile.png [2011.06.10 18:03:18 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011.06.10 07:35:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2011.06.10 07:35:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2011.06.09 21:15:21 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2011.06.09 20:43:28 | 000,020,480 | ---- | C] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.06.09 19:13:49 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011.06.09 18:44:14 | 000,000,684 | ---- | C] () -- C:\Windows\HotFixList.ini [2011.06.09 18:40:46 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2011.06.09 18:39:06 | 000,027,839 | ---- | C] () -- C:\ProgramData\nvModes.001 [2011.06.09 18:39:05 | 000,027,839 | ---- | C] () -- C:\ProgramData\nvModes.dat [2011.06.09 18:25:49 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini [2011.06.09 18:25:49 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini [2011.06.09 18:16:42 | 000,040,960 | ---- | C] () -- C:\Windows\System32\IhDEV.exe [2011.06.09 18:16:42 | 000,024,576 | ---- | C] () -- C:\Windows\System32\IhINF.exe [2011.06.09 18:05:05 | 000,000,680 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat [2008.01.21 09:15:58 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.01.21 09:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.01.21 09:15:58 | 000,126,454 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.01.21 09:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2007.02.26 16:49:12 | 006,139,774 | ---- | C] () -- C:\Windows\System32\imagine digital freedom.dat [2007.02.16 01:51:02 | 000,274,432 | ---- | C] () -- C:\Windows\System32\NDADLL.dll [2006.11.30 02:00:30 | 000,045,056 | ---- | C] () -- C:\Windows\System32\MAWebControl.exe [2006.11.30 02:00:28 | 000,307,200 | ---- | C] () -- C:\Windows\System32\LDBGenWizView.dll [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 14:47:37 | 000,252,888 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 12:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006.10.09 19:01:28 | 000,061,440 | ---- | C] () -- C:\Windows\System32\AVSAudioWideStereoDMO.dll ========== LOP Check ========== [2011.08.03 16:45:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Canon [2011.08.17 18:48:55 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ICQ [2011.06.12 23:40:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PeerNetworking [2011.08.17 17:47:32 | 000,032,572 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 17.08.2011 19:20:31 - Run 8 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Admin\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 66,71% Memory free 6,21 Gb Paging File | 5,13 Gb Available in Paging File | 82,63% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 222,88 Gb Total Space | 156,46 Gb Free Space | 70,20% Space Free | Partition Type: NTFS Drive D: | 2,89 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = htmlfile] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-679186329-3352478774-2945693008-1000] "EnableNotifications" = 0 "EnableNotificationsRef" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0ADBA36C-E641-4E0B-91E4-F52954F52A2B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{13251F6D-25E0-4221-9637-A62C4D4D30BD}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{15146B19-FF7C-4855-B6A5-F90DF6178022}" = rport=137 | protocol=17 | dir=out | app=system | "{1556D602-93B9-4300-9751-14F06D0CE541}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{2A26A99E-F55F-4B15-9582-4EA040562D0D}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{3BFD8104-3A86-4E03-B26F-002F23B03C55}" = rport=445 | protocol=6 | dir=out | app=system | "{3EA02309-F11D-43D6-B8A2-9FD85A3D0379}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{418FEDB7-73DA-4219-94CC-929D2A794FB1}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{4E35DF6D-A8A9-4EF8-9069-5B3F33732498}" = rport=138 | protocol=17 | dir=out | app=system | "{616BE416-E9D8-41D4-99AC-5B435FA21864}" = lport=137 | protocol=17 | dir=in | app=system | "{68F19B96-B633-4690-B3D4-58A1AD7A55B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6A0A9154-99C3-41EE-808F-4950353357CF}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{80BDE7CD-9EAC-4CC7-AF1D-CEA1687DDDAB}" = rport=139 | protocol=6 | dir=out | app=system | "{82B1649E-4EC5-4FDD-92AA-51586073F31E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8FF5DC36-0D3D-4C5D-923D-94345E33431D}" = lport=445 | protocol=6 | dir=in | app=system | "{96B24376-A280-4CF0-B713-7D33B7B00D0D}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{A858AEEC-1AF3-4567-80C7-F74D8E781589}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{B9E2BBE0-5FA5-46FD-A9D0-D063A19F6FA2}" = lport=138 | protocol=17 | dir=in | app=system | "{BAC83331-82BE-4637-A7EB-2FE71F8E45B5}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{C3B2B21E-8511-48BA-9950-8824CE9B6137}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C9BAD1CC-2E9A-42AB-894A-946EC7BE733F}" = rport=2869 | protocol=6 | dir=out | app=system | "{CF281BBD-7CBA-463A-BF8F-48A1E6B189E0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{D86575B9-5514-45B5-B955-9CC47207AE48}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{DE7966DE-3C54-4E2B-8A8F-5E0826D16F2C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E3209084-DED2-44B0-B131-517FED2C2BB4}" = lport=2869 | protocol=6 | dir=in | app=system | "{EE17490A-453A-486B-B5C7-0465038C5149}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{F9B9108C-5B4F-4DEF-B0E0-C64DE3D2D4DC}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{F9F82218-D3F2-4985-959E-0E1D83D6A671}" = lport=139 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0C4058D6-466F-4DF1-8563-1B73AEE2D085}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{0C437E0D-541C-4A3E-9877-3CB2E2264674}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{0CC42F0B-CC1E-4F19-9CB2-2EE06B02D19B}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{1BEE355E-14A5-4746-BF13-EA3B60C96C5C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{2108BD04-B816-4659-888A-A05815F9B6D7}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version6\teamviewer_service.exe | "{241813D0-BD8C-4D2E-B14E-573B85D04586}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version6\teamviewer.exe | "{242D6C48-4222-4C19-9664-76D0D433963F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{2AAED9A4-B04B-4EAE-83F7-0C647FF5A478}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{2B51C36C-4B96-4F79-ADBB-F2AF837D739C}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{317F13BB-C9FF-48A7-8247-4C91F90CC3EE}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version6\teamviewer_service.exe | "{371F089A-29CE-4E27-91B0-CEFB40B05906}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{42B3BFF8-CFC3-4C1E-9D81-5CF0C4E10189}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{452F5643-B50A-4ABE-A191-84E6726320D6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{50EAF023-5BCC-44EC-852D-874FEBECA39F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{515DAF4F-EA65-497A-A014-48D276D03453}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{55A87A74-1A9A-4D92-9EFB-F8AF3E176A5C}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{577E609D-0042-441B-9138-18B56DF9A621}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{5D54B558-6AB3-4876-BF74-FCFFCFAECE96}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{675F1147-6BCD-43FC-95F3-5983294485F1}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | "{6BA6EBB8-462F-40EA-88C1-7CB1D1A90937}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{7C6BDC9A-7F9C-4A1B-9E2B-0137A77E2188}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{833CB862-9911-4101-B067-16A1BA9BE03F}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{9D8FE41A-DCE3-4D9E-A33C-9E2F049ED668}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{ACCED9F2-1245-4269-AB9E-3674FFD9510B}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{AD7F6F1F-5F9F-46E7-953C-F1E77037A50D}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{AEE2E7C9-17AB-46EA-915F-DFDE265E690F}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version6\teamviewer.exe | "{B0C7792B-9FEC-42DE-B083-52B028054523}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B2ED03F3-4D9B-4E3C-A5FB-D554337F389F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B3A0AE9B-1CF5-4653-B159-6BC9BB0E3279}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{B426F91E-BB9F-40C5-808F-CAA63E1AF467}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B99F807B-FE70-4F9D-ABFC-C2DFA8447397}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{BDA0A150-C483-4122-ADD0-BCCC88C1B4BA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{BECF143A-F351-4F69-B285-16B7370859C6}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{BEF99939-DA35-4AF6-A55C-12A938A6ED13}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "{C6FFC124-EE7F-4C96-BFD3-39702B72F407}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe | "{E08B9F28-9A1B-4176-AF59-F366E0E6B6B5}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FDD100B9-ED24-45FB-A6A0-4F38A60195D5}" = dir=in | app=c:\program files\skype\phone\skype.exe | "TCP Query User{6B966A52-A656-44C7-9657-4F933945FC93}C:\program files\icq7.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | "TCP Query User{A51E600C-B375-49E0-91BB-0ACB096B7221}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe | "UDP Query User{69901D32-F6D1-4CC7-8085-8AF950869624}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe | "UDP Query User{873C3911-A7F4-4B1F-8E0B-7F3230495136}C:\program files\icq7.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1 "{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung "{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2 "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{58D68DF0-4E8B-4E9E-B425-670F9E37C1A8}" = TES Construction Set "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera "{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5 "{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90110407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AC76BA86-7AD7-1031-7B44-A81000000003}" = Adobe Reader 8.1.0 - Deutsch "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CanonMyPrinter" = Canon My Printer "CCleaner" = CCleaner "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "ESET Online Scanner" = ESET Online Scanner v3 "InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.1.1800 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 6.0 (x86 de)" = Mozilla Firefox 6.0 (x86 de) "MP Navigator EX 1.0" = Canon MP Navigator EX 1.0 "NVIDIA Drivers" = NVIDIA Drivers "SynTPDeinstKey" = Synaptics Pointing Device Driver "TeamViewer 6" = TeamViewer 6 "VLC media player" = VLC media player 1.1.10 "WinLiveSuite" = Windows Live Essentials "YDKJG3" = YOU DON'T KNOW JACK® 3 - Abwärts! ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 16.08.2011 04:30:38 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 04:44:47 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 11:56:38 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 13:28:45 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 16.08.2011 17:13:45 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 07:04:22 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 07:19:24 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 09:22:42 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 11:21:56 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = Error - 17.08.2011 11:55:19 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10 Description = [ Media Center Events ] Error - 12.06.2011 02:10:16 | Computer Name = Admin-PC | Source = Media Center Guide | ID = 0 Description = Ereignisinformationen: ERROR: SqmApiWrapper.SqmFlushSession failed; Win32 GetLastError returned 0D Prozess: DefaultDomain Objektname: Media Center Guide [ System Events ] Error - 09.06.2011 15:28:20 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 09.06.2011 15:28:36 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 09.06.2011 15:32:47 | Computer Name = Admin-PC | Source = DCOM | ID = 10010 Description = Error - 09.06.2011 15:58:06 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 09.06.2011 15:59:23 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 10.06.2011 00:54:44 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 10.06.2011 00:56:02 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 10.06.2011 11:56:25 | Computer Name = Admin-PC | Source = HTTP | ID = 15016 Description = Error - 10.06.2011 11:56:52 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = Error - 10.06.2011 12:32:36 | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > Also, was lässt sich nun dazu sagen? |
17.08.2011, 18:37 | #28 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! 1. Adobe Reader aktualisieren : - Bei Installation aufpassen/mitlesen!: Wenn irgendeine Software, Toolbar etc angeboten wird, bitte abwählen! - (z.B "McAfee Security Scan Plus") Adobe Reader Oder: Adobe starten-> gehe auf "Hilfe"-> "Nach Update suchen..." 2. Fixen mit OTL
Code:
ATTFilter :OTL O4 - HKCU..\Run: [Power2GoExpress] File not found O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present :Commands [purity] [emptytemp]
3. reinige dein System mit Ccleaner:
4.
5. - "Link:-> ESET Online Scanner >>Du sollst nicht die Antivirus-Sicherheitssoftware installieren, sondern dein System nur online scannen<< Auch auf USB-Sticks, selbstgebrannten Datenträgern, externen Festplatten und anderen Datenträgern können Viren transportiert werden. Man muss daher durch regelmäßige Prüfungen auf Schäden, die durch Malware ("Worm.Win32.Autorun") verursacht worden sein können, überwacht werden. Hierfür sind ser gut geegnet und empfohlen, die auf dem Speichermedium gesicherten Daten, mit Hilfe des kostenlosen Online Scanners zu prüfen. Schließe jetzt alle externe Datenträgeran (USB Sticks etc) Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.►Anleitung -> Führe dann einen Komplett-Systemcheck mit Eset/Nod32 durch - folgendes bitte anhaken > "Remove found threads" und "Scan archives" - die Scanergebnis als *.txt Dateien speichern) - meistens "C:\Programme\Eset\EsetOnlineScanner\log.txt" Vor dem Scan Einstellungen im Internet Explorer: - "Extras→ Internetoptionen→ Sicherheit": - alles auf Standardstufe stellen - Active X erlauben - um den Scan zu starten: wenn du danach gefragt wirst (den Text in der Informationsleiste ) - ActiveX-Steuerelement installieren lassen ► Wie ist den aktuellen Zustand des Rechners? Auffälligkeiten, Probleme?
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
17.08.2011, 18:39 | #29 |
| Bitte helft mir, meinen BKA-Trojaner zu beseitigen! Also ich muss sagen, dass sich mein Avira nicht mehr wegen dem tdss-virus gemeldet hat. Den Trojaner hab ich eigentlich gar nicht weiter gemerkt, außer, dass mein PC langsamer war. Ich hab ihn in der ZWischenzeit aber auch nicht mehr so intensiv genutzt. Ich werds die kommenden Tage mal beobachten, was so passiert. Soweit scheint erstmal alles in Ordnung. Sowe |
17.08.2011, 18:53 | #30 |
/// Helfer-Team | Bitte helft mir, meinen BKA-Trojaner zu beseitigen! sind wir noch nicht fertig:-> http://www.trojaner-board.de/102477-bitte-helft-mir-meinen-bka-trojaner-zu-beseitigen.html#post694293 und Endreinigung werden wir auch noch durchführen, Tools etc die wir verwendet haben entfernen
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
Themen zu Bitte helft mir, meinen BKA-Trojaner zu beseitigen! |
abgesichterten, ahnung, andere, anderen, anleitung, beseitigen, durchführen, durchgeführt, erstell, erstellt, gefunde, gefundene, gefundenen, gmer, helft, hochfahren, hoffe, konnte, leitung, malwarebytes, modus, otl.txt, system, threads, viren, windows |