|
Log-Analyse und Auswertung: vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.12.2011, 00:31 | #1 |
| vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. Hallo, ich habe vor ca4 Tagen eine datei installiert und habe seither perfomanceprobleme. (rechner reagiert lagsamer als zuvor und verschiede spiele stützen aus unerfindlichen gründen ab. meist ohne Fehlermeldung) ich habe win7 ultimate und verwende Avira (Avira findet nach einem vollständigem scan jedoch nichts.) ich habe mich an die Anleitung gehalten und mit defogger meine vituellen CDlaufwerke deaktiviert und nicht wieder aktiviert. nach 14 stunden musste ich meinen rechner abschalten aber gema war noch nicht ganz fertig. gema war gerade beim ordner: C:\Windows\winsxs als ich den rechner abschalten musste. ich habe das log vorher noch gespeichert. gema meinte zudem das VC5SecS.exe vllt ein rootkick sein könnte. Laut googlesuche gehört diese datei zu VitualCD, einem laufwerkemulationsprogramm das ich verwende. mfg DPK hier das OTL log: OTL logfile created on: 03.12.2011 16:54:15 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\wind_of_pain\Desktop Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 3,25 Gb Total Physical Memory | 2,14 Gb Available Physical Memory | 65,90% Memory free 6,50 Gb Paging File | 5,41 Gb Available in Paging File | 83,33% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 35,13 Gb Total Space | 4,55 Gb Free Space | 12,96% Space Free | Partition Type: NTFS Drive D: | 461,04 Gb Total Space | 48,05 Gb Free Space | 10,42% Space Free | Partition Type: NTFS Drive E: | 100,00 Gb Total Space | 3,90 Gb Free Space | 3,90% Space Free | Partition Type: NTFS Drive F: | 7,77 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: PAINKEEPER | User Name: wind_of_pain | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\wind_of_pain\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited) PRC - C:\Windows\System32\atieclxx.exe (AMD) PRC - C:\Windows\System32\atiesrxx.exe (AMD) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Programme\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH) ========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation) SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (VC5SecS) -- C:\Program Files\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH) ========== Driver Services (SafeList) ========== DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.) DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation) DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) -- C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.) DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.) DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.) DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.) DRV - (Mkd2kfNt) -- C:\Windows\System32\drivers\Mkd2kfNT.sys () DRV - (Mkd2Nadr) -- C:\Windows\System32\drivers\Mkd2Nadr.sys () DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys () DRV - (vbev5mp) -- C:\Windows\System32\drivers\VBEV5MP.sys (H+H Software GmbH) DRV - (tandpl) -- C:\Windows\System32\drivers\tandpl.sys () DRV - (enodpl) -- C:\Windows\System32\drivers\enodpl.sys () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = my.daemon-search.com [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 78 7D 97 60 6F CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6 FF - prefs.js..extensions.enabledItems: firegestures@xuldev.org:1.6.3 FF - prefs.js..extensions.enabledItems: trackmenot@mrl.nyu.edu:0.6.723 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.2 FF - prefs.js..extensions.enabledItems: btpersonas@brandthunder.com:1.1.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.10 07:37:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.16 22:05:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.08.21 16:40:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions [2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011.11.29 11:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions [2011.11.18 00:15:18 | 000,000,000 | ---D | M] ("Personas Interactive Theme Engine") -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions\btpersonas@brandthunder.com [2011.02.27 01:22:06 | 000,002,071 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\absearch-search.xml [2010.03.18 19:11:59 | 000,000,873 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\conduit.xml [2011.02.18 22:01:35 | 000,002,059 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\daemon-search.xml [2010.01.07 08:26:56 | 000,000,526 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\yahoo.xml [2011.11.10 16:11:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions () (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI () (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI [2011.11.10 07:37:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011.11.10 07:37:12 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.11.10 07:37:12 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.11.10 07:37:12 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.11.10 07:37:12 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.11.10 07:37:12 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.11.10 07:37:12 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.08.24 23:00:13 | 000,000,950 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 193.178.171.175 www.wienerlinien.at O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4E33D05-3FC0-499D-AF69-F6B5EE3D5DD1}: DhcpNameServer = 10.0.0.1 O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell - "" = AutoRun O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell\AutoRun\command - "" = G:\SETUP.EXE O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {47B3BDBB-F2AE-4B55-95C8-921C25DB3B76} - .NET Framework ActiveX: {49C187D7-91E1-459E-9759-2925384BD397} - .NET Framework ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5A604D2C-E968-429B-8327-62B5CE52126D} - .NET Framework ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {9793EDE2-499E-4A14-8220-523691D8F91B} - .NET Framework ActiveX: {A59B76D1-5E3B-4893-BB7F-AF69B2570A73} - .NET Framework ActiveX: {BFA2E378-31D9-4595-AFA9-CA19E610DC0F} - .NET Framework ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CE4BC71D-A88B-4943-BB3D-AF9C0E7D4387} - .NET Framework ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {FE600E50-2C69-46D5-ACAA-2B617006245C} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SetPointII.lnk - C:\Programme\Logitech\SetPoint II\SetPointII.exe - (Logitech Inc.) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip - - File not found MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DAEMON Tools Lite.lnk - C:\Programme\DAEMON Tools Lite\DTLite.exe - (DT Soft Ltd) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk - C:\Programme\Common Files\Logishrd\eReg\SetPoint\eReg.exe - (Leader Technologies/Logitech) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Mozilla Thunderbird.lnk - C:\Programme\Mozilla Thunderbird\thunderbird.exe - (Mozilla Messaging) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Skype.lnk - - File not found MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: avgnt - hkey= - key= - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig - StartUpReg: Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: VC5Player - hkey= - key= - C:\Programme\HHVcdV5Sys\VC5Play.exe (H+H Software GmbH) MsConfig - StartUpReg: WinampAgent - hkey= - key= - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.) MsConfig - State: "startup" - 1 CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.12.03 16:23:50 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe [2011.11.30 15:09:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\Neuer Ordner [2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue [2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue [2011.11.29 19:42:59 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\backups [2011.11.29 19:23:12 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\Uniblue [2011.11.29 19:22:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} [2011.11.29 19:15:17 | 000,939,368 | ---- | C] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx [2011.11.29 19:14:27 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\PackageAware [2011.11.12 01:37:28 | 002,339,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.11.05 13:30:47 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent [2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\uTorrent [2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\uTorrent [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.12.03 16:50:19 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job [2011.12.03 16:49:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.12.03 16:49:14 | 2616,500,224 | -HS- | M] () -- C:\hiberfil.sys [2011.12.03 16:47:40 | 000,000,020 | ---- | M] () -- C:\Users\wind_of_pain\defogger_reenable [2011.12.03 16:47:03 | 000,050,477 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe [2011.12.03 16:23:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe [2011.11.30 14:25:30 | 000,001,979 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank [2011.11.19 07:39:05 | 000,694,232 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2011.11.19 07:39:05 | 000,693,256 | ---- | M] () -- C:\Windows\System32\perfh00A.dat [2011.11.19 07:39:05 | 000,690,994 | ---- | M] () -- C:\Windows\System32\perfh013.dat [2011.11.19 07:39:05 | 000,689,528 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2011.11.19 07:39:05 | 000,688,910 | ---- | M] () -- C:\Windows\System32\perfh010.dat [2011.11.19 07:39:05 | 000,679,144 | ---- | M] () -- C:\Windows\System32\prfh0816.dat [2011.11.19 07:39:05 | 000,675,760 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2011.11.19 07:39:05 | 000,663,606 | ---- | M] () -- C:\Windows\System32\prfh0416.dat [2011.11.19 07:39:05 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.11.19 07:39:05 | 000,631,982 | ---- | M] () -- C:\Windows\System32\perfh00E.dat [2011.11.19 07:39:05 | 000,622,946 | ---- | M] () -- C:\Windows\System32\perfh005.dat [2011.11.19 07:39:05 | 000,617,370 | ---- | M] () -- C:\Windows\System32\perfh01D.dat [2011.11.19 07:39:05 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.11.19 07:39:05 | 000,610,004 | ---- | M] () -- C:\Windows\System32\perfh01F.dat [2011.11.19 07:39:05 | 000,551,572 | ---- | M] () -- C:\Windows\System32\perfh008.dat [2011.11.19 07:39:05 | 000,461,974 | ---- | M] () -- C:\Windows\System32\perfh006.dat [2011.11.19 07:39:05 | 000,448,388 | ---- | M] () -- C:\Windows\System32\perfh014.dat [2011.11.19 07:39:05 | 000,434,288 | ---- | M] () -- C:\Windows\System32\perfh001.dat [2011.11.19 07:39:05 | 000,433,190 | ---- | M] () -- C:\Windows\System32\perfh00B.dat [2011.11.19 07:39:05 | 000,399,538 | ---- | M] () -- C:\Windows\System32\perfh012.dat [2011.11.19 07:39:05 | 000,388,320 | ---- | M] () -- C:\Windows\System32\perfh011.dat [2011.11.19 07:39:05 | 000,377,672 | ---- | M] () -- C:\Windows\System32\prfh0404.dat [2011.11.19 07:39:05 | 000,361,570 | ---- | M] () -- C:\Windows\System32\prfh0804.dat [2011.11.19 07:39:05 | 000,353,324 | ---- | M] () -- C:\Windows\System32\perfh00D.dat [2011.11.19 07:39:05 | 000,148,112 | ---- | M] () -- C:\Windows\System32\perfc00E.dat [2011.11.19 07:39:05 | 000,136,864 | ---- | M] () -- C:\Windows\System32\perfc00A.dat [2011.11.19 07:39:05 | 000,134,642 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2011.11.19 07:39:05 | 000,133,554 | ---- | M] () -- C:\Windows\System32\prfc0816.dat [2011.11.19 07:39:05 | 000,132,742 | ---- | M] () -- C:\Windows\System32\perfc013.dat [2011.11.19 07:39:05 | 000,132,318 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2011.11.19 07:39:05 | 000,129,942 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2011.11.19 07:39:05 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.11.19 07:39:05 | 000,127,896 | ---- | M] () -- C:\Windows\System32\prfc0416.dat [2011.11.19 07:39:05 | 000,126,946 | ---- | M] () -- C:\Windows\System32\perfc010.dat [2011.11.19 07:39:05 | 000,123,542 | ---- | M] () -- C:\Windows\System32\perfc01D.dat [2011.11.19 07:39:05 | 000,121,590 | ---- | M] () -- C:\Windows\System32\perfc005.dat [2011.11.19 07:39:05 | 000,121,328 | ---- | M] () -- C:\Windows\System32\perfc01F.dat [2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc011.dat [2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.11.19 07:39:05 | 000,104,478 | ---- | M] () -- C:\Windows\System32\perfc012.dat [2011.11.19 07:39:05 | 000,104,050 | ---- | M] () -- C:\Windows\System32\prfc0804.dat [2011.11.19 07:39:05 | 000,099,136 | ---- | M] () -- C:\Windows\System32\prfc0404.dat [2011.11.19 07:39:05 | 000,089,238 | ---- | M] () -- C:\Windows\System32\perfc008.dat [2011.11.19 07:39:05 | 000,081,950 | ---- | M] () -- C:\Windows\System32\perfc00B.dat [2011.11.19 07:39:05 | 000,079,606 | ---- | M] () -- C:\Windows\System32\perfc006.dat [2011.11.19 07:39:05 | 000,078,786 | ---- | M] () -- C:\Windows\System32\perfc001.dat [2011.11.19 07:39:05 | 000,076,898 | ---- | M] () -- C:\Windows\System32\perfc014.dat [2011.11.19 07:39:05 | 000,068,896 | ---- | M] () -- C:\Windows\System32\perfc00D.dat [2011.11.18 08:54:56 | 004,157,452 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3 [2011.11.17 07:43:32 | 002,712,973 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3 [2011.11.12 09:23:29 | 000,289,720 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.11.07 09:26:14 | 000,939,368 | ---- | M] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx [2011.11.06 12:32:25 | 001,169,064 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3 [2011.11.06 10:06:12 | 001,743,820 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3 [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.12.03 16:47:26 | 000,000,020 | ---- | C] () -- C:\Users\wind_of_pain\defogger_reenable [2011.12.03 16:47:02 | 000,050,477 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe [2011.11.30 11:06:42 | 000,001,979 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank [2011.11.29 19:23:13 | 000,000,346 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job [2011.11.18 08:48:00 | 004,157,452 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3 [2011.11.17 07:39:32 | 002,712,973 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3 [2011.11.06 12:30:48 | 001,169,064 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3 [2011.11.06 10:04:47 | 001,743,820 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3 [2011.10.20 06:42:23 | 000,007,621 | ---- | C] () -- C:\Users\wind_of_pain\AppData\Local\Resmon.ResmonCfg [2011.09.14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll [2011.08.26 15:34:14 | 000,239,869 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2011.05.10 20:10:14 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat [2011.03.31 18:03:33 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini [2011.02.18 22:38:36 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib [2010.02.23 02:17:04 | 000,767,328 | ---- | C] () -- C:\Windows\System32\kdfinj.dll [2010.02.23 02:12:44 | 000,131,072 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2kfNT.sys [2010.02.23 02:12:44 | 000,079,104 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2Nadr.sys [2010.02.19 14:36:01 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll [2010.02.14 18:11:19 | 000,007,552 | ---- | C] () -- C:\Windows\System32\drivers\enodpl.sys [2010.02.14 18:11:19 | 000,004,736 | ---- | C] () -- C:\Windows\System32\drivers\tandpl.sys [2010.01.17 03:09:12 | 000,388,320 | ---- | C] () -- C:\Windows\System32\perfh011.dat [2010.01.17 03:09:12 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat [2010.01.17 03:09:12 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc011.dat [2010.01.17 03:09:12 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat [2010.01.17 03:02:11 | 000,551,572 | ---- | C] () -- C:\Windows\System32\perfh008.dat [2010.01.17 03:02:11 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat [2010.01.17 03:02:11 | 000,089,238 | ---- | C] () -- C:\Windows\System32\perfc008.dat [2010.01.17 03:02:11 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat [2010.01.17 02:58:33 | 000,610,004 | ---- | C] () -- C:\Windows\System32\perfh01F.dat [2010.01.17 02:58:33 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat [2010.01.17 02:58:33 | 000,121,328 | ---- | C] () -- C:\Windows\System32\perfc01F.dat [2010.01.17 02:58:33 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat [2010.01.17 02:55:17 | 000,631,982 | ---- | C] () -- C:\Windows\System32\perfh00E.dat [2010.01.17 02:55:17 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat [2010.01.17 02:55:17 | 000,148,112 | ---- | C] () -- C:\Windows\System32\perfc00E.dat [2010.01.17 02:55:17 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat [2010.01.17 02:51:58 | 000,679,144 | ---- | C] () -- C:\Windows\System32\prfh0816.dat [2010.01.17 02:51:58 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat [2010.01.17 02:51:58 | 000,133,554 | ---- | C] () -- C:\Windows\System32\prfc0816.dat [2010.01.17 02:51:58 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat [2010.01.17 02:48:49 | 000,690,994 | ---- | C] () -- C:\Windows\System32\perfh013.dat [2010.01.17 02:48:49 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat [2010.01.17 02:48:49 | 000,132,742 | ---- | C] () -- C:\Windows\System32\perfc013.dat [2010.01.17 02:48:49 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat [2010.01.17 02:45:11 | 000,461,974 | ---- | C] () -- C:\Windows\System32\perfh006.dat [2010.01.17 02:45:11 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat [2010.01.17 02:45:11 | 000,079,606 | ---- | C] () -- C:\Windows\System32\perfc006.dat [2010.01.17 02:45:11 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat [2010.01.17 02:40:31 | 000,617,370 | ---- | C] () -- C:\Windows\System32\perfh01D.dat [2010.01.17 02:40:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat [2010.01.17 02:40:31 | 000,123,542 | ---- | C] () -- C:\Windows\System32\perfc01D.dat [2010.01.17 02:40:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat [2010.01.13 22:23:59 | 000,693,256 | ---- | C] () -- C:\Windows\System32\perfh00A.dat [2010.01.13 22:23:59 | 000,689,528 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2010.01.13 22:23:59 | 000,675,760 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2010.01.13 22:23:59 | 000,663,606 | ---- | C] () -- C:\Windows\System32\prfh0416.dat [2010.01.13 22:23:59 | 000,434,288 | ---- | C] () -- C:\Windows\System32\perfh001.dat [2010.01.13 22:23:59 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat [2010.01.13 22:23:59 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2010.01.13 22:23:59 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2010.01.13 22:23:59 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat [2010.01.13 22:23:59 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat [2010.01.13 22:23:59 | 000,136,864 | ---- | C] () -- C:\Windows\System32\perfc00A.dat [2010.01.13 22:23:59 | 000,134,642 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2010.01.13 22:23:59 | 000,132,318 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2010.01.13 22:23:59 | 000,127,896 | ---- | C] () -- C:\Windows\System32\prfc0416.dat [2010.01.13 22:23:59 | 000,078,786 | ---- | C] () -- C:\Windows\System32\perfc001.dat [2010.01.13 22:23:59 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat [2010.01.13 22:23:59 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat [2010.01.13 22:23:59 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2010.01.13 22:23:59 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2010.01.13 22:23:59 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat [2010.01.12 22:41:22 | 000,353,324 | ---- | C] () -- C:\Windows\System32\perfh00D.dat [2010.01.12 22:41:22 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat [2010.01.12 22:41:22 | 000,068,896 | ---- | C] () -- C:\Windows\System32\perfc00D.dat [2010.01.12 22:41:22 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat [2010.01.12 22:33:42 | 000,688,910 | ---- | C] () -- C:\Windows\System32\perfh010.dat [2010.01.12 22:33:42 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat [2010.01.12 22:33:42 | 000,126,946 | ---- | C] () -- C:\Windows\System32\perfc010.dat [2010.01.12 22:33:42 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat [2010.01.12 22:28:09 | 000,377,672 | ---- | C] () -- C:\Windows\System32\prfh0404.dat [2010.01.12 22:28:09 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat [2010.01.12 22:28:09 | 000,099,136 | ---- | C] () -- C:\Windows\System32\prfc0404.dat [2010.01.12 22:28:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat [2010.01.12 22:24:53 | 000,399,538 | ---- | C] () -- C:\Windows\System32\perfh012.dat [2010.01.12 22:24:53 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat [2010.01.12 22:24:53 | 000,104,478 | ---- | C] () -- C:\Windows\System32\perfc012.dat [2010.01.12 22:24:53 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat [2010.01.12 22:21:08 | 000,694,232 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2010.01.12 22:21:08 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2010.01.12 22:21:08 | 000,129,942 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2010.01.12 22:21:08 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2010.01.12 22:17:10 | 000,622,946 | ---- | C] () -- C:\Windows\System32\perfh005.dat [2010.01.12 22:17:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat [2010.01.12 22:17:10 | 000,121,590 | ---- | C] () -- C:\Windows\System32\perfc005.dat [2010.01.12 22:17:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat [2010.01.12 22:12:15 | 000,433,190 | ---- | C] () -- C:\Windows\System32\perfh00B.dat [2010.01.12 22:12:15 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat [2010.01.12 22:12:15 | 000,081,950 | ---- | C] () -- C:\Windows\System32\perfc00B.dat [2010.01.12 22:12:15 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat [2010.01.12 22:09:09 | 000,361,570 | ---- | C] () -- C:\Windows\System32\prfh0804.dat [2010.01.12 22:09:09 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat [2010.01.12 22:09:09 | 000,104,050 | ---- | C] () -- C:\Windows\System32\prfc0804.dat [2010.01.12 22:09:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat [2010.01.12 21:58:54 | 000,448,388 | ---- | C] () -- C:\Windows\System32\perfh014.dat [2010.01.12 21:58:54 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat [2010.01.12 21:58:54 | 000,076,898 | ---- | C] () -- C:\Windows\System32\perfc014.dat [2010.01.12 21:58:54 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat [2009.12.08 12:14:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2009.11.29 12:25:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2009.11.27 13:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2009.07.14 09:47:43 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009.07.14 09:47:43 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 000,289,720 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 01:55:09 | 000,587,776 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll [2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2004.08.13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys [1997.11.17 17:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2009.11.27 13:51:21 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2011.09.21 21:55:09 | 000,000,000 | ---D | M] -- C:\5301b5d6b61d5e9fd4431d67 [2011.07.06 14:14:32 | 000,000,000 | ---D | M] -- C:\ATI [2009.11.27 13:36:56 | 000,000,000 | -HSD | M] -- C:\Boot [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2010.06.09 23:40:05 | 000,000,000 | ---D | M] -- C:\FrozenSynapse [2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs [2011.11.29 19:47:31 | 000,000,000 | R--D | M] -- C:\Program Files [2011.12.03 16:49:13 | 000,000,000 | -H-D | M] -- C:\ProgramData [2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Programme [2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Recovery [2011.12.03 16:58:07 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2009.11.27 13:51:09 | 000,000,000 | R--D | M] -- C:\Users [2011.10.24 18:26:18 | 000,000,000 | ---D | M] -- C:\Windows < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.manifest /3 > < MD5 for: AFD.SYS > [2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\System32\drivers\afd.sys [2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_d81220b5bf827af7\afd.sys [2010.11.20 09:40:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=1151FD4FB0216CFED887BFDE29EBD516 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b\afd.sys [2011.04.25 03:18:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=9EBBBA55060F786F0FCAA3893BFA2806 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_d9f97e05bca8003a\afd.sys [2011.04.25 03:27:23 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C114AB7A1550D42EA1700FFD4179CF5A -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys [2011.04.25 04:24:09 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C427F91A748CD342A2B3F9278D9FD6A5 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_da774a9ad5cea29e\afd.sys [2009.07.14 00:12:38 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=DDC040FDB01EF1712A6B13E52AFB104C -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys < MD5 for: EXPLORER.EXE > [2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe [2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe [2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe [2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe [2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe [2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe [2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe [2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe < MD5 for: REGEDIT.EXE > [2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe [2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe < MD5 for: USERINIT.EXE > [2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe [2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-03 14:43:03 < End of report > |
05.12.2011, 14:24 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.Zitat:
__________________ |
05.12.2011, 15:10 | #3 |
| vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. verzeihung. kein spezieller grund. ich scheine es einfach vergessen zu haben
__________________folgende Datei wurde installiert hxxp://www.filehippo.com/download_hijackthis/ sinn: log an einen freund schicken, der mir aber doch nicht helfen konnte. Davor hat mich nur instesesiert, warum gewisse Programme sporadisch abstützen, danach wurde es häufiger. Vor diesem Zeitpunkt wurden von mir keine bewussten änderungen des systems durchgeführt (nur das automatische windowsupdate und avira) und das problem bestand in der jetzigen Form zu diesem Zeitpunkt auch nicht. |
05.12.2011, 15:46 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
06.12.2011, 19:20 | #5 |
| vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. hier die logs von Malwarebytes und ESET: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Datenbank Version: 8316 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 05.12.2011 20:11:44 mbam-log-2011-12-05 (20-11-44).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Durchsuchte Objekte: 641918 Laufzeit: 2 Stunde(n), 19 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) --------------------------------------------- ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=e9608af7ce6f3d41bb3fa53a0add7e54 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-05 11:38:08 # local_time=2011-12-06 12:38:08 (+0100, Mitteleuropäische Zeit) # country="Austria" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1797 16775165 100 94 193691 59657866 100044 0 # compatibility_mode=5893 16776573 100 94 27392 74748636 0 0 # compatibility_mode=8192 67108863 100 0 3661 3661 0 0 # scanned=506078 # found=27 # cleaned=0 # scan_time=10843 C:\$Recycle.Bin\S-1-5-21-3012151111-3320611238-1688054739-1001\$R9I841H.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\$Recycle.Bin\S-1-5-21-3012151111-3320611238-1688054739-1001\$RCMD0QA.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia945C.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\mia99D9.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Users\wind_of_pain\AppData\Local\Temp\miaA78E.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I ${Memory} Win32/RegistryBooster application 00000000000000000000000000000000 I |
06.12.2011, 19:28 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.Zitat:
Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich. Wir lesen oft genug von Hilfesuchenden, dass deren System nach der Nutzung von Registry Cleanern nicht mehr startet.
Ein sogenanntes False Positive von einem Cleaner kann auch dein System unbootbar machen. Zerstörst Du die Registry, zerstörst Du Windows.
__________________ --> vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. |
06.12.2011, 23:12 | #7 |
| vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. aha ... danke für deine Mühe. Gibt es etwas das ich gegen die von diesem Programm verursachten Änderungen tun kann, oder muss ich mein System neu aufsetzen? |
07.12.2011, 12:22 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. Mach bitte ein neues OTL-Log. Poste es in CODE-Tags! CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. |
adobe, antivir, autorun, avira, c:\windows\system32\rundll32.exe, defender, explorer, fehlermeldung, firefox, format, host.exe, installation, langs, log, logfile, microsoft, mozilla thunderbird, object, ordner, plug-in, programme, required, rundll, scan, sched.exe, secure, software, taskhost.exe, usb, virus, webcheck, windows, winlogon.exe, wmp |