|
Log-Analyse und Auswertung: Internet seit kurzem sehr langsam (komische Ip's bei netstat)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.10.2011, 21:47 | #1 | |
| Internet seit kurzem sehr langsam (komische Ip's bei netstat) allo, seit einiger Zeit ist auf einem meiner Rechner das Internet sehr langsam und auch sonst kommt mir einiges komisch vor z.B. als ich heute Webseiten aufrufen wollte kam immer der Fehler 400 auch bei google.de. Nach 2 Neustarts ging dann wieder alles. Bei netstat –o stehen auch soviele Adressen ich weiß nicht ob das normal ist. Ich verwende Windows Vista. Habe mal AVG durchlaufen lassen dies Programm hat in der USB-Fernwartung von der Fritzbox etwas gefunden und gelöscht. Bevor das gelöscht wurde Stand bei netstat: Zitat:
Hijack sag übrigens folgendes: HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 22:23:17, on 05.10.2011 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16681) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\rundll32.exe C:\Windows\RtHDVCpl.exe C:\Programme\G DATA AntiVirenKit 2007 Trial\AVKTray\AVKTray.exe C:\Windows\System32\rundll32.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Windows\system32\conime.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe C:\Windows\system32\cmd.exe C:\Users\Eltern_2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JNKULNO9\HiJackThis204[1].exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AVKTray] "C:\Programme\G DATA AntiVirenKit 2007 Trial\AVKTray\AVKTray.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE" O4 - HKLM\..\Run: [recinfo694] c:\RecInfo\RecInfo.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [AVMUSBFernanschluss] "C:\Users\Eltern_2\AppData\Local\Apps\2.0\JO57157X.5XX\99C19JG1.CMK\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\AVMAutoStart.exe" O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe O23 - Service: AVKProxy - G DATA Software AG - C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe O23 - Service: AVK Service (AVKService) - G DATA Software AG - C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKService.exe O23 - Service: AVK Wächter (AVKWCtl) - G DATA Software AG - C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKWCtl.exe O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: ProtexisLicensing - Unknown owner - c:\Windows\system32\PSIService.exe O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- End of file - 5853 bytes Vielleicht könnt ihr mir ja etwas weiter helfen. Habe dazu noch nichts passendes gefunden. |
05.10.2011, 22:20 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet seit kurzem sehr langsam (komische Ip's bei netstat) Bitte beachten => http://www.trojaner-board.de/95173-b...es-posten.html und http://www.trojaner-board.de/69886-a...-beachten.html
__________________
__________________ |
06.10.2011, 09:31 | #3 |
| Internet seit kurzem sehr langsam (komische Ip's bei netstat) oh tut mir leid.
__________________Hoffe nun mach ich alles richtig: Defogger hat mir keine Fehlermeldung angezeigt. Und OTL.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 06.10.2011 09:30:00 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Eltern_2\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16681) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 60,12% Memory free 4,21 Gb Paging File | 3,43 Gb Available in Paging File | 81,43% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 216,41 Gb Total Space | 129,99 Gb Free Space | 60,07% Space Free | Partition Type: NTFS Drive D: | 107,22 Gb Total Space | 103,20 Gb Free Space | 96,25% Space Free | Partition Type: NTFS Drive E: | 144,12 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive M: | 1,89 Gb Total Space | 1,88 Gb Free Space | 99,95% Space Free | Partition Type: FAT32 Computer Name: ELTERN-PC | User Name: Admin-Eltern | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.10.05 23:39:24 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Eltern_2\Desktop\OTL.exe PRC - [2011.09.23 06:31:50 | 002,404,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe PRC - [2011.09.21 19:53:12 | 000,973,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe PRC - [2011.09.13 06:32:40 | 001,227,616 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe PRC - [2011.09.08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\PROGRA~1\AVG\AVG2012\avgrsx.exe PRC - [2011.08.15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe PRC - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe PRC - [2007.11.16 20:50:37 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2007.07.06 11:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2007.05.03 09:04:00 | 000,649,040 | ---- | M] (G DATA Software AG) -- C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe PRC - [2007.04.02 13:49:06 | 001,042,256 | ---- | M] (G DATA Software AG) -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVKTray\AVKTray.exe PRC - [2007.04.02 13:20:22 | 000,407,376 | ---- | M] (G DATA Software AG) -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKService.exe PRC - [2007.04.02 12:09:00 | 001,103,696 | ---- | M] (G DATA Software AG) -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKWCtl.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe PRC - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe ========== Modules (No Company Name) ========== MOD - [2010.03.15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll MOD - [2006.11.02 17:30:43 | 000,385,024 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Deployment.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Deployment.resources.dll MOD - [2006.11.02 17:30:38 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2006.11.02 15:08:54 | 000,015,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\c1e49c5e89ac8bd75d701e7d9f59c1bd\dfsvc.ni.exe MOD - [2006.11.02 14:57:35 | 001,724,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c1bba45a4ec4bf42d3e0b6acdeece8e0\System.Deployment.ni.dll MOD - [2006.11.02 14:57:34 | 013,148,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\35a9f19f21aac42b979be321f1bb5fd4\System.Windows.Forms.ni.dll MOD - [2006.11.02 14:56:59 | 001,617,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\70c145ed25af403aa899ffcb633350b1\System.Drawing.ni.dll MOD - [2006.11.02 14:55:23 | 008,151,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\fcc712bc5da45a672e7f1ad176dbd5a5\System.ni.dll MOD - [2006.11.02 14:55:10 | 011,628,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7fe79782947b85d961fd55cb5e02a129\mscorlib.ni.dll MOD - [2004.12.20 20:52:54 | 000,065,536 | ---- | M] () -- C:\Program Files\Astonsoft\DeepBurner Pro\DeepBurnerShellEx.dll ========== Win32 Services (SafeList) ========== SRV - [2011.09.12 06:23:46 | 005,265,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [On_Demand | Stopped] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent) SRV - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd) SRV - [2007.10.23 00:43:12 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2007.05.03 09:04:00 | 000,649,040 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe -- (AVKProxy) SRV - [2007.04.02 13:20:22 | 000,407,376 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKService.exe -- (AVKService) SRV - [2007.04.02 12:09:00 | 001,103,696 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKWCtl.exe -- (AVKWCtl) SRV - [2006.12.14 17:00:00 | 000,544,768 | ---- | M] (Magix AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- (UPnPService) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing) SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - [2011.09.13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2011.08.08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2011.07.11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2011.07.11 01:14:02 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) DRV - [2011.07.11 01:14:02 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim) DRV - [2011.07.11 01:14:00 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2011.07.11 01:13:58 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) DRV - [2011.07.11 01:13:46 | 000,229,840 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2010.10.09 17:52:05 | 000,101,248 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avmaura.sys -- (avmaura) DRV - [2009.03.15 18:40:36 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2007.10.23 02:44:59 | 000,039,120 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\GDTdiIcpt.sys -- (GDTdiInterceptor) DRV - [2007.10.23 02:44:56 | 000,047,312 | ---- | M] (G DATA Software AG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MiniIcpt.sys -- (GDMnIcpt) DRV - [2007.10.23 02:44:55 | 000,032,464 | ---- | M] (G DATA Software AG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HookCentre.sys -- (HookCentre) DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvrd32.sys -- (nvrd32) DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor32.sys -- (nvstor32) DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\jraid.sys -- (JRAID) DRV - [2007.06.01 17:46:00 | 007,479,008 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2007.03.26 15:26:00 | 000,052,224 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\ViPrt.sys -- (ViPrt) DRV - [2007.03.26 15:26:00 | 000,016,896 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\ViBus.sys -- (ViBus) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.daemon-search.com/startpage IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.daemon-search.com/startpage" FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.0.7.0088 FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011.10.05 21:57:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.01 17:47:18 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.10.05 21:47:23 | 000,000,000 | ---D | M] [2011.07.27 13:39:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eltern\AppData\Roaming\mozilla\Extensions [2007.11.08 20:22:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eltern\AppData\Roaming\mozilla\Firefox\Profiles\6cqsjpr2.default\extensions [2009.03.15 18:43:25 | 000,000,523 | ---- | M] () -- C:\Users\Eltern\AppData\Roaming\Mozilla\Firefox\Profiles\6cqsjpr2.default\searchplugins\daemon-search.xml [2011.10.05 21:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2011.10.05 21:47:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2009.03.15 18:43:32 | 000,000,000 | ---D | M] (DAEMON Tools Toolbar) -- C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT [2011.10.05 21:46:50 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010.03.16 20:28:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.03.16 20:28:04 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2010.03.16 20:28:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2010.03.16 20:28:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2010.03.16 20:28:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2011.10.05 21:27:37 | 000,000,759 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [AVKTray] C:\Programme\G DATA AntiVirenKit 2007 Trial\AVKTray\AVKTray.exe (G DATA Software AG) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation) O4 - HKLM..\Run: [QuickFinder Scheduler] c:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation) O4 - HKLM..\Run: [recinfo694] c:\RecInfo\RecInfo.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [AVMUSBFernanschluss] C:\Users\Eltern\AppData\Local\Apps\2.0\ZJD78PP4.AO5\3XC5BK4D.OPJ\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\AVMAutoStart.exe (AVM Berlin) O4 - HKCU..\Run: [MBPlayer] C:\Program Files\MB application\MBPlayer.exe (MusicBrigade) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.6.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AAC86B9-8DC8-43ED-B6BF-0711A666A746}: DhcpNameServer = 192.168.6.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper1.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper1.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2006.10.27 14:29:14 | 000,000,106 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{20202a8f-1180-11de-95cc-0019dbf9b4fe}\Shell - "" = AutoRun O33 - MountPoints2\{20202a8f-1180-11de-95cc-0019dbf9b4fe}\Shell\AutoRun\command - "" = L:\autorun.exe de O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.10.05 22:54:55 | 000,000,000 | -H-D | C] -- C:\$AVG [2011.10.05 21:58:50 | 000,000,000 | ---D | C] -- C:\Users\Eltern\AppData\Roaming\AVG2012 [2011.10.05 21:57:45 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2011.10.05 21:57:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012 [2011.10.05 21:56:08 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012 [2011.10.05 21:56:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG [2011.10.05 21:54:37 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2011.10.05 21:53:48 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2011.10.05 21:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2011.09.13 06:30:10 | 000,032,592 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys ========== Files - Modified Within 30 Days ========== [2011.10.06 09:26:55 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.10.06 09:26:54 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.10.06 09:26:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.10.06 09:26:34 | 2145,902,592 | -HS- | M] () -- C:\hiberfil.sys [2011.10.05 23:48:17 | 000,656,262 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.10.05 23:48:17 | 000,609,944 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.10.05 23:48:17 | 000,121,228 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.10.05 23:48:17 | 000,103,726 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.10.05 23:41:42 | 000,000,176 | ---- | M] () -- C:\Users\Eltern\defogger_reenable [2011.10.05 21:59:55 | 105,854,055 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011.10.05 21:57:28 | 000,000,899 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011.10.05 21:32:21 | 000,304,704 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.10.05 21:28:24 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2011.10.05 21:22:02 | 000,005,632 | ---- | M] () -- C:\Users\Eltern\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.10.05 21:15:42 | 2421,307,391 | ---- | M] () -- C:\Videoband 2011_10_05_20_39_43.avi [2011.10.05 20:23:26 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{CEFF007C-5C08-47B0-93AB-594193834339}.job [2011.09.13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys ========== Files Created - No Company Name ========== [2011.10.05 23:41:27 | 000,000,176 | ---- | C] () -- C:\Users\Eltern\defogger_reenable [2011.10.05 21:59:55 | 105,854,055 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011.10.05 21:57:28 | 000,000,899 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011.10.05 21:28:24 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2011.10.05 21:17:42 | 2421,307,391 | ---- | C] () -- C:\Videoband 2011_10_05_20_39_43.avi [2011.10.05 21:15:47 | 000,005,632 | ---- | C] () -- C:\Users\Eltern\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.10.22 20:17:22 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS [2010.07.22 12:10:16 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2007.11.08 20:22:12 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2007.10.23 02:50:12 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2007.10.23 02:50:11 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini [2007.10.23 02:44:59 | 000,039,120 | ---- | C] () -- C:\Windows\System32\drivers\GDTdiIcpt.sys [2007.10.23 02:40:27 | 000,069,632 | ---- | C] () -- C:\Windows\System32\vuins32.dll [2006.11.02 20:40:12 | 000,174,656 | ---- | C] () -- C:\Windows\System32\PSIService.exe [2006.11.02 17:33:31 | 000,656,262 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2006.11.02 17:33:31 | 000,121,228 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 14:47:37 | 000,304,704 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:33:01 | 000,609,944 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 12:33:01 | 000,103,726 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006.11.02 09:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2006.11.02 09:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2006.08.11 09:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll [2005.02.03 02:50:28 | 000,004,224 | ---- | C] () -- C:\Windows\System32\StarOpen.sys ========== LOP Check ========== [2011.10.05 21:58:50 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\AVG2012 [2010.10.09 17:55:07 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\Canon [2009.03.15 18:44:20 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DAEMON Tools [2009.03.15 18:44:39 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DAEMON Tools Lite [2009.03.15 18:44:20 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DAEMON Tools Pro [2009.10.28 21:58:10 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DeepBurner Pro [2008.03.20 12:44:11 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\ImgBurn [2008.10.22 17:34:33 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\Leadertech [2010.07.22 12:07:25 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\MAGIX [2011.10.05 23:51:33 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2011.10.05 20:23:26 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{CEFF007C-5C08-47B0-93AB-594193834339}.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.10.05 22:54:55 | 000,000,000 | -H-D | M] -- C:\$AVG [2007.11.08 08:09:41 | 000,000,000 | ---D | M] -- C:\$fsctmp [2007.11.08 20:46:47 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2007.10.23 02:43:45 | 000,000,000 | ---D | M] -- C:\Big Fish Games [2007.10.22 18:11:18 | 000,000,000 | -HSD | M] -- C:\Boot [2006.11.02 15:02:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2007.11.07 21:48:07 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2007.10.23 02:41:41 | 000,000,000 | R--D | M] -- C:\DRIVER [2007.11.07 21:55:56 | 000,000,000 | ---D | M] -- C:\FirstSteps [2007.10.23 02:45:07 | 000,000,000 | ---D | M] -- C:\GDATA [2010.05.11 18:12:06 | 000,000,000 | ---D | M] -- C:\IrfanView [2007.10.23 02:52:49 | 000,000,000 | ---D | M] -- C:\Magix-Media-Suite [2007.10.23 02:41:41 | 000,000,000 | R--D | M] -- C:\MANUAL [2007.11.09 16:33:16 | 000,000,000 | RH-D | M] -- C:\MSOCache [2007.10.23 02:54:35 | 000,000,000 | ---D | M] -- C:\nero [2007.10.23 02:56:03 | 000,000,000 | ---D | M] -- C:\OfficeX3 [2011.10.05 21:54:37 | 000,000,000 | R--D | M] -- C:\Program Files [2011.10.05 21:57:45 | 000,000,000 | -H-D | M] -- C:\ProgramData [2007.10.23 02:44:18 | 000,000,000 | ---D | M] -- C:\Programme [2007.10.23 02:56:04 | 000,000,000 | ---D | M] -- C:\RecInfo [2011.10.06 09:33:08 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2010.10.22 20:16:11 | 000,000,000 | ---D | M] -- C:\TempEI4 [2007.10.23 14:10:07 | 000,000,000 | ---D | M] -- C:\TMP [2007.11.08 20:46:11 | 000,000,000 | R--D | M] -- C:\Users [2011.10.06 09:36:19 | 000,000,000 | ---D | M] -- C:\Windows [2007.10.23 00:33:05 | 000,000,000 | ---D | M] -- C:\x86 < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.manifest /3 > < MD5 for: EXPLORER.EXE > [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe [2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe [2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe [2007.11.16 20:50:37 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\explorer.exe [2007.11.16 20:50:37 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe [2007.11.16 20:50:36 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe [2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe [2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe < MD5 for: REGEDIT.EXE > [2006.11.02 11:45:35 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=F13123E76FDA33E55F11E0EB832E832A -- C:\Windows\regedit.exe [2006.11.02 11:45:35 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=F13123E76FDA33E55F11E0EB832E832A -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6000.16386_none_f1f7f368deed95c3\regedit.exe < MD5 for: USERINIT.EXE > [2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\System32\userinit.exe [2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe < MD5 for: WININIT.EXE > [2007.10.23 01:14:36 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=39D959CD9F3BC44F78DB3C6588AAC3FE -- C:\Windows\System32\wininit.exe [2007.10.23 01:14:36 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=39D959CD9F3BC44F78DB3C6588AAC3FE -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.20593_none_2f37c4ba208e02ab\wininit.exe [2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe < MD5 for: WINLOGON.EXE > [2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2007.10.23 01:14:36 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=A3FEA6ED9FD3CF07219A632E4A716226 -- C:\Windows\System32\winlogon.exe [2007.10.23 01:14:36 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=A3FEA6ED9FD3CF07219A632E4A716226 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.20593_none_6e080d01f12ed7fe\winlogon.exe < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-07-20 15:53:58 ========== Alternate Data Streams ========== @Alternate Data Stream - 537278 bytes -> C:\Videoband 2011_10_05_20_39_43.avi:TOC.WMV < End of report > Die Extra.txt OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 06.10.2011 09:30:00 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Eltern_2\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16681) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 60,12% Memory free 4,21 Gb Paging File | 3,43 Gb Available in Paging File | 81,43% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 216,41 Gb Total Space | 129,99 Gb Free Space | 60,07% Space Free | Partition Type: NTFS Drive D: | 107,22 Gb Total Space | 103,20 Gb Free Space | 96,25% Space Free | Partition Type: NTFS Drive E: | 144,12 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive M: | 1,89 Gb Total Space | 1,88 Gb Free Space | 99,95% Space Free | Partition Type: FAT32 Computer Name: ELTERN-PC | User Name: Admin-Eltern | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07ABB4BC-18A3-4A1A-9404-7DC24EFCE1D1}" = lport=138 | protocol=17 | dir=in | app=system | "{08240853-D043-482E-8EC1-7F9855C0C953}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{2D5CC778-EEDC-4100-8644-77318E948A79}" = rport=445 | protocol=6 | dir=out | app=system | "{52308EB7-9AF8-48A6-9F91-1BC2F0543624}" = lport=139 | protocol=6 | dir=in | app=system | "{6059875F-A6FE-4CB3-BB88-9E3C745E1811}" = rport=137 | protocol=17 | dir=out | app=system | "{72551129-2748-4359-B886-0F6F3652A87B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{7C17BE22-F4FA-43E5-BBAF-49FFBA228B50}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7D546227-012A-4B9D-B011-15D4D15D91FC}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{7DB04099-6A25-4532-90F0-40E7EC86BF78}" = rport=139 | protocol=6 | dir=out | app=system | "{926D58FD-50A2-4185-B322-D3F82FABCACA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BC696B03-9FB4-4962-BAC3-C1FAAE92FD91}" = lport=137 | protocol=17 | dir=in | app=system | "{BE1D59B7-7F65-4F3A-B7CD-2A67B808707E}" = lport=445 | protocol=6 | dir=in | app=system | "{D90E3495-374B-4304-B8A6-C63EF21C2700}" = rport=138 | protocol=17 | dir=out | app=system | "{F4AEC372-58BA-4DC3-8AF6-3DA9E6D100F9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0896583C-E4F6-416C-9C3F-5430F24D4CE8}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{090A0E94-0E4D-43BA-8FEA-F09FEB7EEAD5}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe | "{1CF3936F-A03F-40FF-A1F1-AF15F89B9992}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{23377FC1-9F61-4BBE-80A6-A6DCCAAB049B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe | "{5018DCAF-BBED-484E-A0CB-3C61B1477936}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe | "{6AE177BB-DF0C-44F9-A772-3AD40360ED85}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{76B868A7-E27B-4EF5-BF9C-DB05C97EC715}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{8D0E5E72-E95F-41AE-9BA9-4F3AEAE22D75}" = protocol=17 | dir=in | app=c:\users\eltern\appdata\local\apps\2.0\zjd78pp4.ao5\3xc5bk4d.opj\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "{9745B194-C63D-4A42-A91C-A4F8EC547BBB}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe | "{97AB14A0-9301-46FF-8040-73C898526979}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe | "{A5E7D772-AFF7-4BA7-8F6B-53DB2CED4D58}" = protocol=6 | dir=in | app=c:\users\eltern\appdata\local\apps\2.0\zjd78pp4.ao5\3xc5bk4d.opj\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "{A917F295-2211-4E92-A8EA-8CC0F8604CD2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{B200DDB0-830B-4C0C-A666-7D47F6EF0A28}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{C55AB439-7AF3-48E8-BC4D-368BD3E38381}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D383D906-C622-4D0B-8FBE-0399E60BBE89}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe | "{D4420C3F-85E2-4A77-9CEC-BC9CBFADB1DC}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe | "{D444BE6C-1D1B-417D-9264-B62EBCE7217D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DEEF850E-A129-4BFC-818A-EA8EF97A079E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{E7DDBAB4-D190-4A54-90EE-F8B902230CAE}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe | "{F608ECF8-7B22-45EC-BC2C-F98ACC08624B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{FE5771C2-DE2A-41DE-9F04-0F8AEBEBCC62}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "TCP Query User{19BDA44D-30B8-40D8-B6E8-C724189867F6}D:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe" = protocol=6 | dir=in | app=d:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe | "TCP Query User{56FF793B-5AC4-4764-B67D-9DF1AC91FD6F}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe" = protocol=6 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | "TCP Query User{ACDBDCA4-8CF6-480C-90E3-6B2ED617BAE6}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe" = protocol=6 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "UDP Query User{5C6EAAD9-1929-42FA-9412-207661B1F5CE}D:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe" = protocol=17 | dir=in | app=d:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe | "UDP Query User{DC30D536-BAE4-46CA-AB0F-9F9A863AF3B9}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe" = protocol=17 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "UDP Query User{ED48EAD5-2F0A-4AA3-A924-D954982FCD29}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe" = protocol=17 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3 "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP270_series" = Canon MP270 series MP Drivers "{1AD22277-7A1E-71EC-B27D-EB7A22BED143}" = DeepBurner Pro v1.9.0.228 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2315B23D-3E21-4920-837D-AE6460934ECB}" = FIFA 09 "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D0FEAB4-5D81-4461-A9CA-766B530FC6EA}" = G DATA AntiVirenKit "{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3 "{56839333-0802-40D6-9A50-EBB9EB2BF541}" = AVG 2012 "{6DA0B8BE-3735-4287-AF4D-B8DE088D0AA7}" = AVG 2012 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{81CD6232-10F5-4832-B3DA-1B88B1571031}" = Nero 7 Essentials "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}" = FirstSteps Diagnostics "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{AC76BA86-7AD7-1031-7B44-A81000000003}" = Adobe Reader 8.1.0 - Deutsch "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{EDA12670-56B5-4459-BA21-D010F0E3EBA1}" = Emergency 4 Deluxe "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "AVG" = AVG 2012 "AVMFBox" = AVM FRITZ!Box Dokumentation "AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss "Big Fish Games Center" = Big Fish Games Center (remove only) "Big Fish Games Sudoku" = Big Fish Games Sudoku (remove only) "Cradle of Rome" = Cradle of Rome (remove only) "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition 2.0.0.1 (D) "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ImgBurn" = ImgBurn "Luxor Amun Rising" = Luxor Amun Rising (remove only) "MAGIX Foto Manager 2007 D" = MAGIX Foto Manager 2007 4.2.0.79 (D) "MAGIX Media Suite D" = MAGIX Media Suite 1.12.0.89 (D) "MAGIX Music Manager 2007 D" = MAGIX Music Manager 2007 8.2.0.144 (D) "MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D) "MAGIX Ringtone Maker SE D" = MAGIX Ringtone Maker SE 3.1.0.4 (D) "Mahjong Towers Eternity EU" = Mahjong Towers Eternity EU (remove only) "Mozilla Firefox (3.6.2pre)" = Mozilla Firefox (3.6.2pre) "Mystery Case Files - Prime Suspects" = Mystery Case Files - Prime Suspects (remove only) "NVIDIA Drivers" = NVIDIA Drivers "Poker Superstars II" = Poker Superstars II (remove only) "Virtual Villagers" = Virtual Villagers (remove only) "VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter "WinRAR archiver" = WinRAR ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "f018cf21c0452c64" = AVM FRITZ!Box USB-Fernanschluss ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > |
06.10.2011, 13:30 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet seit kurzem sehr langsam (komische Ip's bei netstat)Zitat:
Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
06.10.2011, 15:31 | #5 |
| Internet seit kurzem sehr langsam (komische Ip's bei netstat) Danke für die Hilfe. Aber da auf dem PC nicht viele Daten waren, er allerdings zum Online-Banking genutzt wird wollt ich lieber sicher gehen und habe Neuinstalliert denke das war die schnellste und sicherst Methode. Trotzdem nochmals Danke, werd beim nächstenmal dann wieder kommen hoffentlich nicht zu früh |
06.10.2011, 15:33 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet seit kurzem sehr langsam (komische Ip's bei netstat)Zitat:
__________________ --> Internet seit kurzem sehr langsam (komische Ip's bei netstat) |
06.10.2011, 15:41 | #7 | |
| Internet seit kurzem sehr langsam (komische Ip's bei netstat)Zitat:
Aber viele Infos hab ich dazu nicht gefunden einige Schreiben das man da keine AntiViren Programme benötige andere meinen wiederrum schon. Hatte bissher viele Probleme mit Windows selbst mit PCs die am Internet angeschlossen sind aber nicht Surfen. |
06.10.2011, 15:56 | #8 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet seit kurzem sehr langsam (komische Ip's bei netstat)Zitat:
Natürlich ist Ubuntu eine sichere Distro. Aber jedes Betriebssystem ist nur so sicher wie der Anwender es eingerichtet hat. Nur muss man an Ubuntu als Laie nichts mehr weiter verändern, weil es ab Werk aus sicher eingerichtet ist.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Internet seit kurzem sehr langsam (komische Ip's bei netstat) |
adresse, adressen, aufrufe, aufrufen, avg, einiger, fehler, fritzbox, gefunde, heute, inter, interne, internet, internet sehr langsam, komisch, komische, kurzem, langsam, netstat, neustarts, plug-in, programm, rechner, sehr langsam, stand, stehe, webseite, webseiten, windows |