|
Log-Analyse und Auswertung: Trojaner AppData Temp Windows 7Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
06.01.2012, 17:21 | #1 |
| Trojaner AppData Temp Windows 7 Hallo liebe Community. Ich kam gestern zurück an den PC und hab direkt ein paar Nachrichten von Kaspersky 2011 erhalten, bezüglich gefundenen Trojanern und gefundener Malware. Konnte einiges löschen, aber 2 Trojaner lassen sich nicht entfernen. Der PC läuft recht normal und im Taskmanager sehe ich auch nichts auffälliges. Sie finden sich in: C:/Documents and settings/Name/Appdata/Local/nun folgt eine Zahlenreihenfolge Der zweite befindet sich im selben ordner, ist allerdings eine .exe, auch wieder bestehend aus irgendeiner Zahlenreihenfolge. Ich habe ein Log mit OTL erstellt, da ich gesehen habe dass das ist hilfreich für euch ist, hier der Log:OTL Logfile: OTL EXTRAS Logfile: Code:
ATTFilter OTL logfile created on: 06.01.2012 16:58:07 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\***\Desktop Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 894,49 Mb Total Physical Memory | 228,71 Mb Available Physical Memory | 25,57% Memory free 1,87 Gb Paging File | 0,83 Gb Available in Paging File | 44,18% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 127,99 Gb Total Space | 26,89 Gb Free Space | 21,01% Space Free | Partition Type: NTFS Computer Name: PC5000 | User Name: **** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\r\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\VideoLAN\VLC\vlc.exe () PRC - C:\Windows\System32\atieclxx.exe (AMD) PRC - C:\Windows\System32\atiesrxx.exe (AMD) PRC - C:\Users\Per\AppData\Local\TVersity\Media Server\MediaServer.exe () PRC - C:\Programme\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) PRC - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe () PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - c:\Programme\Windows Defender\MpCmdRun.exe (Microsoft Corporation) ========== Modules (No Company Name) ========== MOD - C:\Programme\Mozilla Firefox\js3250.dll () MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll () MOD - C:\Users\r\AppData\Roaming\Mozilla\Firefox\Profiles\qdw1qu3d.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\imtcp_xpcom.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvorbis_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libzvbi_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libxml_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libx264_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvout_sdl_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtwolame_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libzip_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvisual_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvod_rtsp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libwingdi_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libty_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvcd_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libwaveout_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvobsub_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvideo_filter_wrapper_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libyuy2_i420_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvout_wrapper_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libyuy2_i422_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libwav_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libwall_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvoc_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvmem_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libxtag_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libyuv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libwave_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libvc1_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libxa_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libyuvp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libugly_resampler_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtaglib_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtheora_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libswscale_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libts_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsubtitle_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtransform_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsvcdsub_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtta_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtrivial_channel_mixer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libtrivial_mixer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libt140_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libqt4_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libskins2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libschroedinger_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_rtp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_raop_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libremoteosd_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librtp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsdl_image_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libspeex_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libspatializer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsap_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_transcode_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libreal_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsubsdec_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librss_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsubsusf_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_record_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_mosaic_bridge_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_standard_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libscreen_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_bridge_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libspudec_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_es_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsmf_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libscaletempo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librotate_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librawvid_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_smem_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libscene_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libquicktime_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_duplicate_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_filter_rar_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librealvideo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstats_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsimple_channel_mixer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librawdv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librawaud_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_display_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libsharpen_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libripple_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librawvideo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_gather_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_autodel_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libscale_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_filter_record_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\librv32_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_description_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libspdif_mixer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libstream_out_dummy_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmkv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmod_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpng_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmp4_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_ts_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmpgatofixed32_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libplaylist_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liboldhttp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_ps_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libportaudio_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libogg_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_h264_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpostproc_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liboldrc_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpanoramix_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_mpeg4audio_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_ogg_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_mp4_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_asf_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libps_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmosaic_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_dirac_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libosd_parser_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_vc1_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liboldtelnet_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libnuv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_mpegvideo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_avi_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmotiondetect_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_mpeg4video_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_flac_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpuzzle_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_mlp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmono_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libosdmenu_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpodcast_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmpeg_audio_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpva_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libntservice_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libnsv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libparam_eq_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libnetsync_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpsychedelic_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libpacketizer_copy_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libnsc_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libnormvol_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_wav_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmsn_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmotionblur_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libnoise_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_mpjpeg_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmux_dummy_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmpgv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblibass_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfreetype_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblive555_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgnutls_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblua_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libflac_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfluidsynth_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgoom_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblibmpeg2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi420_rgb_sse2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libkate_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi420_rgb_mmx_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libglwin32_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi420_rgb_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi420_yuy2_sse2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libhotkeys_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi422_yuy2_sse2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgradient_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libflacsys_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi420_yuy2_mmx_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblogo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfilesystem_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmarq_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi420_yuy2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi422_yuy2_mmx_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmagnify_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libheadphone_channel_mixer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi422_yuy2_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgestures_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmirror_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmediadirs_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblpcm_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmjpeg_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liblogger_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgaussianblur_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmemcpymmxext_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmemcpy3dn_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libglobalhotkeys_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libmemcpymmx_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libinvmem_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libi422_i420_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgrey_yuv_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libgrain_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libh264_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfloat32_mixer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libinvert_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfolder_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfaad_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libequalizer_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libes_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libextract_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libexport_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libfake_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liberase_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdirac_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcaca_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdvdnav_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdshow_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdtstofloat32_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdvdread_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libbda_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdvbsub_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcdda_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdeinterlace_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libavi_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdirectx_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdirect3d_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libblend_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdmo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libbandlimited_resampler_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcrop_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libball_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdummy_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdts_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcc_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcvdsub_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcroppadd_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libchorus_flanger_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libbluescreen_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcanvas_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libblendbench_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcolorthres_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libcdg_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libclone_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libconverter_fixed_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libchain_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdtstospdif_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdolby_surround_decoder_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdemuxdump_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdemux_cdg_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libdrawable_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libavcodec_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\libvlccore.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_output_shout_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaout_sdl_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libatmo_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\vlc.exe () MOD - C:\Programme\VideoLAN\VLC\libvlc.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_bd_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_http_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_mms_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libasf_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_realrtsp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liba52tofloat32_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaudiobargraph_v_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libadjust_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaout_directx_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaraw_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_imem_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaudioscrobbler_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaudio_format_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_ftp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libadpcm_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaudiobargraph_a_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_output_udp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liba52_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_output_http_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaout_file_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_smb_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaiff_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_fake_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libalphamask_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaes3_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_udp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libau_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_output_file_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_tcp_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_attachment_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\libaccess_output_dummy_plugin.dll () MOD - C:\Programme\VideoLAN\VLC\plugins\liba52tospdif_plugin.dll () ========== Win32 Services (SafeList) ========== SRV - (sppuinotify) -- File not found SRV - (sppsvc) -- File not found SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD) SRV - (TVersityMediaServer) -- C:\Users\***\AppData\Local\TVersity\Media Server\MediaServer.exe () SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (TeamViewer5) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH) SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe () SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys () DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab) DRV - (kl2) -- C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO) DRV - (KL1) -- C:\Windows\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO) DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) 2000 DDK provider) DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO) DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia) DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia) DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia) DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia) DRV - (nmwcdnsu) -- C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia) DRV - (nmwcdnsuc) -- C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia) DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.) DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab) DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation) DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (mcdbus) -- C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.) DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia) DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.) DRV - (ASPI32) -- C:\Windows\System32\drivers\ASPI32.SYS (Adaptec) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.ask.com/?l=dis&o=15788 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 61 EC E4 3E 48 ED CA 01 [binary data] IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll (DeviceVM Inc.) IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.dgap.de/" FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2 FF - prefs.js..extensions.enabledItems: 5 FF - prefs.js..extensions.enabledItems: 3 FF - prefs.js..extensions.enabledItems: 1 FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.4 FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:7.3.0.0 FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011.06.20 21:51:54 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.12.21 13:04:02 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.12.21 13:04:02 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2010.11.11 11:50:54 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011.06.20 21:51:55 | 000,000,000 | ---D | M] [2010.05.06 20:02:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Per\AppData\Roaming\mozilla\Extensions [2012.01.06 17:00:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Per\AppData\Roaming\mozilla\Firefox\Profiles\qdw1qu3d.default\extensions [2011.12.10 17:52:16 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\Per\AppData\Roaming\mozilla\Firefox\Profiles\qdw1qu3d.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2011.07.03 23:46:22 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Per\AppData\Roaming\mozilla\Firefox\Profiles\qdw1qu3d.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2010.05.30 03:05:29 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\Per\AppData\Roaming\mozilla\Firefox\Profiles\qdw1qu3d.default\extensions\firefox@tvunetworks.com [2011.10.05 20:43:46 | 000,002,400 | ---- | M] () -- C:\Users\Per\AppData\Roaming\Mozilla\Firefox\Profiles\qdw1qu3d.default\searchplugins\askcom.xml [2011.06.26 12:48:37 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2010.05.07 19:34:31 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2011.06.20 21:51:54 | 000,000,000 | ---D | M] (Firefox Synchronisation Extension) -- C:\PROGRAM FILES\NOKIA\NOKIA OVI SUITE\CONNECTORS\BOOKMARKS CONNECTOR\FIREFOXEXTENSION [2010.09.20 01:30:46 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.09.20 01:30:46 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2010.09.20 01:30:47 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2010.09.20 01:30:47 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2010.09.20 01:30:47 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Free YouTube Download - C:\Users\Per\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BE4616A-1C66-4638-A29B-439CB5911689}: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) -C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{631f6760-6e61-11e0-bb5e-001fd0d23c89}\Shell - "" = AutoRun O33 - MountPoints2\{631f6760-6e61-11e0-bb5e-001fd0d23c89}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a O33 - MountPoints2\H\Shell - "" = AutoRun O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== File not found -- C:\Users\****\Desktop\Slipknot - The subliminal verses [www.whiplashdownload.blogspot.com.rar [2012.01.06 16:56:26 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Per\Desktop\OTL.exe [2012.01.05 17:29:20 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Raekwon - Unexpected Victory (DatPiff.com) [2012.01.03 16:25:27 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab [2012.01.03 16:24:52 | 000,000,000 | ---D | C] -- C:\Users\***\SystemRequirementsLab [2011.12.25 18:52:47 | 000,000,000 | ---D | C] -- C:\Users\****r\Desktop\Kanye West My Beatiful Dark Twisted Fantasy [2011.12.25 18:46:52 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\DMX - Greatest Hits (2007) [2011.12.24 22:15:13 | 000,000,000 | ---D | C] -- C:\Users\****\Desktop\SMOKE DZA SWEETBABYKUSHEDGOD [2011.12.23 15:30:38 | 000,000,000 | ---D | C] -- C:\Users\*****r\Desktop\D.I.T.C.-Unreleased_Production_1994-2008-C4 [2011.12.23 00:50:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011.12.23 00:49:02 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2011.12.23 00:48:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2011.12.10 17:52:48 | 000,000,000 | ---D | C] -- C:\Users\****\Documents\iMacros [2011.12.08 22:51:56 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\3269981 ========== Files - Modified Within 30 Days ========== File not found -- C:\Users\******r\Desktop\Slipknot - The subliminal verses [www.whiplashdownload.blogspot.com.rar [2012.01.06 16:56:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\****\Desktop\OTL.exe [2012.01.06 16:45:17 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.01.06 16:45:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.01.06 16:45:02 | 703,455,232 | -HS- | M] () -- C:\hiberfil.sys [2012.01.06 01:44:17 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.01.05 18:16:10 | 004,733,446 | ---- | M] () -- C:\Users\***r\Desktop\Kool G Rap Feat. Nas - Fast Life (Norfside Remix).mp3 [2012.01.05 17:31:53 | 000,204,800 | ---- | M] () -- C:\Users\*****r\AppData\Local\Temp$$_temp.mdb [2012.01.05 17:31:48 | 000,000,128 | ---- | M] () -- C:\Users\****r\AppData\Local\Temp$$_temp.ldb [2012.01.04 16:27:23 | 001,352,069 | ---- | M] () -- C:\Users\****r\Desktop\IMG_0094.JPG [2012.01.04 16:24:07 | 001,138,444 | ---- | M] () -- C:\Users\***r\Desktop\IMG_0092.JPG [2012.01.04 16:24:02 | 001,353,504 | ---- | M] () -- C:\Users****r\Desktop\IMG_0093.JPG [2012.01.04 16:23:54 | 001,395,542 | ---- | M] () -- C:\Users\****r\Desktop\IMG_0091.JPG [2012.01.04 16:23:38 | 001,293,499 | ---- | M] () -- C:\Users\****r\Desktop\IMG_0090.JPG [2012.01.03 02:23:31 | 003,667,029 | ---- | M] () -- C:\Users\******\Desktop\01 Curren$y - Plot music.mp3 [2011.12.28 18:48:40 | 000,643,628 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.12.28 18:48:40 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.12.28 18:48:40 | 000,126,188 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.12.28 18:48:40 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.12.26 22:50:42 | 001,333,316 | ---- | M] () -- C:\Users\***\Desktop\IMG_0079.JPG [2011.12.26 22:34:28 | 001,385,636 | ---- | M] () -- C:\Users\*****\Desktop\IMG_0073.JPG [2011.12.26 22:34:25 | 001,358,786 | ---- | M] () -- C:\Users\*\Desktop\yesyaw.JPG [2011.12.26 22:34:06 | 001,305,182 | ---- | M] () -- C:\Users\***\Desktop\IMG_0072.JPG [2011.12.26 22:33:59 | 001,397,747 | ---- | M] () -- C:\Users\***r\Desktop\IMG_0074.JPG [2011.12.26 22:33:55 | 001,309,840 | ---- | M] () -- C:\Users\***\Desktop\IMG_0075.JPG [2011.12.25 18:31:46 | 006,954,104 | ---- | M] () -- C:\Users\****\Desktop\Runaway (Feat. Pusha T).mp3 [2011.12.23 17:45:22 | 006,293,786 | ---- | M] () -- C:\Users\****\Desktop\Corner Boy P feat. Smoke Dza, Fiend & Killa Kyleon - La La Pt. 2 (Official Video).mp3 [2011.12.23 00:50:15 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2011.12.09 17:58:26 | 000,008,414 | ---- | M] () -- C:\Users\****\Documents\13599.MDS [2011.12.09 17:58:25 | 3543,728,127 | ---- | M] () -- C:\Users\*****\Documents\13599.ISO ========== Files Created - No Company Name ========== [2012.01.05 18:15:53 | 004,733,446 | ---- | C] () -- C:\Users\**\Desktop\Kool G Rap Feat. Nas - Fast Life (Norfside Remix).mp3 [2012.01.05 17:30:57 | 000,204,800 | ---- | C] () -- C:\Users\***r\AppData\Local\Temp$$_temp.mdb [2012.01.05 17:30:57 | 000,000,128 | ---- | C] () -- C:\Users\****\AppData\Local\Temp$$_temp.ldb [2012.01.04 16:24:07 | 001,138,444 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0092.JPG [2012.01.04 16:24:03 | 001,353,504 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0093.JPG [2012.01.04 16:23:20 | 001,293,499 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0090.JPG [2012.01.04 16:23:14 | 001,395,542 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0091.JPG [2012.01.04 16:23:08 | 001,352,069 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0094.JPG [2012.01.03 02:22:54 | 003,667,029 | ---- | C] () -- C:\Users\**r\Desktop\01 Curren$y - Plot music.mp3 [2011.12.26 22:50:03 | 001,333,316 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0079.JPG [2011.12.26 22:34:06 | 001,305,182 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0072.JPG [2011.12.26 22:34:03 | 001,385,636 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0073.JPG [2011.12.26 22:34:00 | 001,397,747 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0074.JPG [2011.12.26 22:33:56 | 001,309,840 | ---- | C] () -- C:\Users\**r\Desktop\IMG_0075.JPG [2011.12.26 22:33:50 | 001,358,786 | ---- | C] () -- C:\Users\**r\Desktop\yesyaw.JPG [2011.12.25 18:30:59 | 006,954,104 | ---- | C] () -- C:\Users\**r\Desktop\Runaway (Feat. Pusha T).mp3 [2011.12.23 17:44:59 | 006,293,786 | ---- | C] () -- C:\Users\**r\Desktop\Corner Boy P feat. Smoke Dza, Fiend & Killa Kyleon - La La Pt. 2 (Official Video).mp3 [2011.12.23 00:50:14 | 000,001,753 | ---- | C] () -- C:\Users\blic\Desktop\iTunes.lnk [2011.12.09 17:58:26 | 000,008,414 | ---- | C] () -- C:\Users\**r\Documents\13599.MDS [2011.12.09 17:47:11 | 3543,728,127 | ---- | C] () -- C:\Users\**r\Documents\13599.ISO [2011.07.16 14:28:03 | 000,000,000 | ---- | C] () -- C:\Users\***AppData\Local\{12694502-A088-467C-829F-6F120745A65F} [2010.12.06 14:58:56 | 002,496,715 | ---- | C] () -- C:\Windows\System32\abgx360.exe [2010.06.26 14:24:11 | 000,037,888 | ---- | C] () -- C:\Windows\System32\AVIwrap.dll [2010.06.26 14:24:10 | 000,073,216 | ---- | C] () -- C:\Windows\System32\unrar.dll [2010.06.26 14:24:09 | 000,105,472 | ---- | C] () -- C:\Windows\System32\OggDS.dll [2010.06.26 14:24:08 | 000,092,672 | ---- | C] () -- C:\Windows\System32\vorbis.dll [2010.06.26 14:24:08 | 000,090,624 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll [2010.06.26 14:24:08 | 000,021,504 | ---- | C] () -- C:\Windows\System32\ogg.dll [2010.06.26 14:24:07 | 000,132,096 | ---- | C] () -- C:\Windows\System32\libavcodec.dll [2010.06.26 14:24:07 | 000,028,672 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll [2010.06.26 14:24:07 | 000,008,704 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll [2010.06.26 14:24:06 | 000,077,664 | ---- | C] () -- C:\Windows\System32\IR21_R.DLL [2010.06.26 14:24:06 | 000,019,968 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll [2010.06.26 14:24:04 | 000,180,736 | ---- | C] () -- C:\Windows\System32\vfcodec.dll [2010.06.26 14:24:02 | 000,202,240 | ---- | C] () -- C:\Windows\System32\XviD.dll [2010.06.26 14:24:01 | 000,039,936 | ---- | C] () -- C:\Windows\System32\mp4fil32.dll [2010.06.24 19:43:05 | 000,115,369 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat [2010.06.24 19:43:05 | 000,097,961 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat [2010.06.16 14:22:56 | 000,219,348 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2010.06.15 23:28:54 | 000,002,857 | ---- | C] () -- C:\Windows\System32\atipblag.dat [2010.06.06 19:15:35 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2010.05.11 19:02:17 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010.05.06 19:09:59 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2010.05.06 18:58:30 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2009.09.09 19:01:40 | 000,027,675 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat [2009.07.14 09:50:01 | 000,643,628 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009.07.14 09:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009.07.14 09:50:01 | 000,126,188 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009.07.14 09:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 000,431,632 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,606,992 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,103,370 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009.02.18 18:55:20 | 000,294,912 | ---- | C] () -- C:\Windows\System32\ATIODE.exe [2009.02.03 21:52:02 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe [2007.06.21 07:34:08 | 000,203,328 | R--- | C] () -- C:\Windows\GSetup.exe ========== LOP Check ========== [2011.05.18 21:34:38 | 000,000,000 | ---D | M] -- C:\Users\\AppData\Roaming\abgx360 [2010.12.04 17:33:42 | 000,000,000 | ---D | M] -- C:\Users\\AppData\Roaming\Amazon [2010.05.11 22:20:32 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\Ashampoo [2010.09.07 18:57:07 | 000,000,000 | ---D | M] -- C:\Users\\AppData\Roaming\DAEMON Tools Lite [2010.09.01 16:45:48 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\DAEMON Tools Net [2011.07.03 23:47:28 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\DVDVideoSoft [2011.07.03 23:46:21 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\DVDVideoSoftIEHelpers [2010.06.16 20:23:46 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\FreeFLVConverter [2011.11.30 17:16:48 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\ICQ [2011.10.05 17:11:49 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\ImgBurn [2011.06.20 22:39:15 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\Nokia [2011.06.20 22:39:32 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\Nokia Ovi Suite [2010.08.02 22:26:58 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\OpenOffice.org [2011.06.20 22:00:47 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\PC Suite [2011.10.23 21:04:08 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\redsn0w [2011.10.24 16:10:58 | 000,000,000 | ---D | M] -- C:\Users\r\AppData\Roaming\Software4u [2010.05.25 00:49:53 | 000,000,000 | ---D | M] -- C:\Users\Per\AppData\Roaming\TeamViewer [2011.06.10 13:52:13 | 000,000,000 | ---D | M] -- C:\Users\Per\AppData\Roaming\UseNeXT [2011.12.31 15:13:57 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT OTL Extras logfile created on: 06.01.2012 16:58:07 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\*******\Desktop Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 894,49 Mb Total Physical Memory | 228,71 Mb Available Physical Memory | 25,57% Memory free 1,87 Gb Paging File | 0,83 Gb Available in Paging File | 44,18% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 127,99 Gb Total Space | 26,89 Gb Free Space | 21,01% Space Free | Partition Type: NTFS Computer Name: PC5000 | User Name: | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [TVersity] -- "C:\Users\\AppData\Local\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17 "{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime "{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{45DF6D99-666D-41FA-8D62-0E183B6240F3}" = PC Connectivity Solution "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011 "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1 "{749A1EDD-16C2-4C63-B013-D38F0F953973}" = OviMPlatform "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{8112C6B3-91E1-4560-8AB9-876DADFA37C5}" = Ovi Desktop Sync Engine "{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2 "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{2D93D6D2-CA5B-4767-91DA-3E8F60E81664}" = "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3 - Deutsch "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{AF28141B-B865-F5C2-BA12-C0A8CDC56B75}" = ATI Catalyst Install Manager "{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes "{B8B4446F-87E1-4423-A47A-16832C24A199}" = Nokia Ovi Suite "{DCFF9230-22DC-40ED-BBCC-0F260B85734C}" = Tsunami-Filter-Pack "{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{EE5B5B24-EEFC-4C8B-BF8B-256D705BAD89}" = Nokia Ovi Suite Software Updater "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) "abgx360" = abgx360 v1.0.5 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10 "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 "Ashampoo Burning Studio 2008 Advanced_is1" = Ashampoo Burning Studio 2008 Advanced "ClipMOPS" = ClipMOPS "DivX Setup.divx.com" = DivX-Setup "DVD Flick_is1" = DVD Flick 1.3.0.7 "ENTERPRISE" = Microsoft Office Enterprise 2007 "FE5AE7DC-7B01-4263-A94C-B4526C276549_is1" = iPhone Explorer "ffdshow_is1" = ffdshow v1.1.3516 [2010-07-25] "Free FLV Converter_is1" = Free FLV Converter V 6.8.0 "Free YouTube Download 3_is1" = Free YouTube Download 3 version 3.0.4.628 "Google Chrome" = Google Chrome "ICQToolbar" = ICQ Toolbar "ImgBurn" = ImgBurn "InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011 "JDownloader" = JDownloader "MagicDisc 2.7.106" = MagicDisc 2.7.106 "Mozilla Firefox (3.6.25)" = Mozilla Firefox (3.6.25) "Nokia Ovi Suite" = Nokia Ovi Suite "RATattack" = RATattack 0.2 "TeamViewer 5" = TeamViewer 5 "TVersity Codec Pack" = TVersity Codec Pack 1.4 "TVersity Media Server" = TVersity Media Server 1.9.2 "UseNeXT_is1" = UseNeXT "VLC media player" = VLC media player 1.1.4 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 12.11.2011 14:47:29 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 8455 Error - 12.11.2011 14:47:29 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 8455 Error - 12.11.2011 14:47:30 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 12.11.2011 14:47:30 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 9469 Error - 12.11.2011 14:47:30 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 9469 Error - 12.11.2011 14:47:40 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 12.11.2011 14:47:40 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 19874 Error - 12.11.2011 14:47:40 | Computer Name = PC5000 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 19874 Error - 13.11.2011 10:17:42 | Computer Name = PC5000 | Source = Winlogon | ID = 4103 Description = Fehler bei der Windows-Lizenzaktivierung. Fehler 0x80070002. Error - 13.11.2011 11:53:48 | Computer Name = PC5000 | Source = VSS | ID = 8194 Description = [ Media Center Events ] Error - 05.06.2010 21:07:14 | Computer Name = PC5000 | Source = Microsoft-Windows-Media Center Extender | ID = 116 Description = Error - 05.06.2010 21:10:37 | Computer Name = PC5000 | Source = Microsoft-Windows-Media Center Extender | ID = 116 Description = Error - 05.02.2011 12:53:10 | Computer Name = PC5000 | Source = MCUpdate | ID = 0 Description = 17:53:03 - MCEClientUX konnte nicht abgerufen werden (Fehler: Die zugrunde liegende Verbindung wurde geschlossen: Für den geschützten SSL/TLS-Kanal konnte keine Vertrauensstellung hergestellt werden..) Error - 10.02.2011 09:59:35 | Computer Name = PC5000 | Source = Microsoft-Windows-Media Center Extender | ID = 301 Description = [ System Events ] Error - 06.01.2012 11:45:24 | Computer Name = PC5000 | Source = Disk | ID = 262151 Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error - 06.01.2012 11:45:27 | Computer Name = PC5000 | Source = Disk | ID = 262151 Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error - 06.01.2012 11:45:30 | Computer Name = PC5000 | Source = Disk | ID = 262151 Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error - 06.01.2012 11:45:33 | Computer Name = PC5000 | Source = Disk | ID = 262151 Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error - 06.01.2012 11:45:34 | Computer Name = PC5000 | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: kl2 Error - 06.01.2012 11:45:51 | Computer Name = PC5000 | Source = Disk | ID = 262151 Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error - 06.01.2012 11:45:55 | Computer Name = PC5000 | Source = Disk | ID = 262151 Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error - 06.01.2012 11:47:36 | Computer Name = PC5000 | Source = Service Control Manager | ID = 7000 Description = Der Dienst "sppsvc" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error - 06.01.2012 11:48:27 | Computer Name = PC5000 | Source = DCOM | ID = 10001 Description = Error - 06.01.2012 11:48:35 | Computer Name = PC5000 | Source = Service Control Manager | ID = 7000 Description = Der Dienst "sppsvc" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 < End of report > --- --- --- Geändert von watupgz (06.01.2012 um 17:27 Uhr) |
06.01.2012, 17:49 | #2 |
| Trojaner AppData Temp Windows 7 doppelpost
__________________Geändert von watupgz (06.01.2012 um 18:00 Uhr) |
06.01.2012, 17:55 | #3 |
| Trojaner AppData Temp Windows 7 Hoffe mir hilft jemand, schreibe meine Bachelor arbeit und brauche den PC unbedingt voll funktionsfähig. Kaspersky 2011 zeigt mir dass Malware gefunden wurde, kann sie aber nicht neutralisieren oder löschen. Passiert einfach nichts.
__________________Wäre toll wenn sich jemand die Zeit nehmen würde. Liebe Grüße |
07.01.2012, 01:13 | #4 |
| Trojaner AppData Temp Windows 7 Habe anderweitig Hilfe erhalten, Thread kann geclosed werden. |
Themen zu Trojaner AppData Temp Windows 7 |
autorun, avp.exe, bonjour, downloader, error, excel.exe, fehler, firefox, flash player, format, google, google chrome, google earth, helper, hilfreich, install.exe, jdownloader, kaspersky, langs, logfile, microsoft office word, mozilla, plug-in, realtek, registry, rundll, scan, security, senden, server, software, studio, taskhost.exe, taskmanager, tastatur, trojaner, version=1.0, webcheck, windows, wrapper, xpcom.dll, zahlenreihe |