Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windowssystem gesperrt - Virus

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 10.01.2012, 09:37   #16
kira
/// Helfer-Team
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



zu Punkt 7. :
unter Systemsteuerung existiert "eMule" nicht mehr..wir machen das schon
alle andere Schritte bitte erledigen, dann sehen wir weiter
__________________

Warnung!:
Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
Anhang nicht öffnen, in unserem Forum erst nachfragen!

Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
Bitte diese Warnung weitergeben, wo Du nur kannst!

Alt 10.01.2012, 17:44   #17
puma165
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



9. OTL.exe

Code:
ATTFilter
All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0\ deleted successfully.
C:\Program Files\Picasa2\npPicasa2.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0\ deleted successfully.
C:\Program Files\Picasa2\npPicasa3.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
File C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll not found.
C:\Program Files\QuickTime\plugins\npqtplugin.dll moved successfully.
C:\Program Files\QuickTime\plugins\npqtplugin2.dll moved successfully.
C:\Program Files\QuickTime\plugins\npqtplugin3.dll moved successfully.
C:\Program Files\QuickTime\plugins\npqtplugin4.dll moved successfully.
C:\Program Files\QuickTime\plugins\npqtplugin5.dll moved successfully.
C:\Program Files\QuickTime\plugins\npqtplugin6.dll moved successfully.
File C:\Program Files\Google\Google Updater\2.4.1908.5032\npCIDetect14.dll not found.
File C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87FF76F0-BCA9-40DC-B1E5-254062EEE8F4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87FF76F0-BCA9-40DC-B1E5-254062EEE8F4}\ deleted successfully.
C:\Programme\Reify Software\Turnabout\turnabout.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
C:\Programme\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
File C:\Programme\ICQ6Toolbar\ICQToolBar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B99F805C-F0B1-48EA-8C8B-753BFCBED912} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B99F805C-F0B1-48EA-8C8B-753BFCBED912}\ deleted successfully.
File C:\Programme\Reify Software\Turnabout\turnabout.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
File C:\Programme\ICQ6Toolbar\ICQToolBar.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B99F805C-F0B1-48EA-8C8B-753BFCBED912} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B99F805C-F0B1-48EA-8C8B-753BFCBED912}\ not found.
File C:\Programme\Reify Software\Turnabout\turnabout.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\toolbar_eula_launcher not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Windows &Live Favorites\ deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
D:\AUTORUN.INF moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0255f92b-796d-11df-8600-001583122a35}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0255f92b-796d-11df-8600-001583122a35}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0255f92b-796d-11df-8600-001583122a35}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0255f92b-796d-11df-8600-001583122a35}\ not found.
File F:\Startme.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79750547-bcbc-11df-b95a-001583122a35}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79750547-bcbc-11df-b95a-001583122a35}\ not found.
File G:\setupSNK.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f5ff8de1-996f-11df-ae43-001583122a35}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ff8de1-996f-11df-ae43-001583122a35}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Autostart.exe not found.
C:\Windows\Tasks\Google Software Updater.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Users\Fabi\AppData\Local\rebur_navps.dat moved successfully.
C:\Users\Fabi\AppData\Local\rebur_nav.dat moved successfully.
C:\Users\Fabi\AppData\Local\rebur.dat moved successfully.
C:\Users\Fabi\AppData\Local\wgqzcsc.bat moved successfully.
C:\Users\Fabi\AppData\Local\dqgvrfuc.bat moved successfully.
C:\Users\Fabi\AppData\Local\amylxk_navps.dat moved successfully.
C:\Users\Fabi\AppData\Local\cfvro.bat moved successfully.
ADS C:\ProgramData\TEMP:8643C5BE deleted successfully.
ADS C:\ProgramData\TEMP:551E1CB4 deleted successfully.
ADS C:\ProgramData\TEMP:2FF4577A deleted successfully.
ADS C:\ProgramData\TEMP:08993BCD deleted successfully.
ADS C:\ProgramData\TEMP:77846FFE deleted successfully.
ADS C:\ProgramData\TEMP:A08FFD4D deleted successfully.
ADS C:\ProgramData\TEMP:41C283B2 deleted successfully.
ADS C:\ProgramData\TEMP:E6683E95 deleted successfully.
ADS C:\ProgramData\TEMP:CBEB737E deleted successfully.
ADS C:\ProgramData\TEMP:002640E3 deleted successfully.
ADS C:\ProgramData\TEMP:F791B5EF deleted successfully.
ADS C:\ProgramData\TEMP:FD444D31 deleted successfully.
ADS C:\ProgramData\TEMP:273A8657 deleted successfully.
ADS C:\ProgramData\TEMP:38317199 deleted successfully.
ADS C:\ProgramData\TEMP:51A22C60 deleted successfully.
ADS C:\ProgramData\TEMP:A23D24E7 deleted successfully.
ADS C:\ProgramData\TEMP:74B502CB deleted successfully.
ADS C:\ProgramData\TEMP:7079A696 deleted successfully.
ADS C:\ProgramData\TEMP:F62CAE78 deleted successfully.
ADS C:\ProgramData\TEMP:E1F04E8D deleted successfully.
ADS C:\ProgramData\TEMP:AD171C9E deleted successfully.
ADS C:\ProgramData\TEMP:895798AD deleted successfully.
ADS C:\ProgramData\TEMP:4C509008 deleted successfully.
ADS C:\ProgramData\TEMP:26946BE8 deleted successfully.
ADS C:\ProgramData\TEMP:F50F1555 deleted successfully.
ADS C:\ProgramData\TEMP:EB603FE4 deleted successfully.
ADS C:\ProgramData\TEMP:CBCE0A92 deleted successfully.
ADS C:\ProgramData\TEMP:79F970BE deleted successfully.
ADS C:\ProgramData\TEMP:87FA5E8A deleted successfully.
ADS C:\ProgramData\TEMP:30C46519 deleted successfully.
ADS C:\ProgramData\TEMP:1941675B deleted successfully.
ADS C:\ProgramData\TEMP:128A6DC9 deleted successfully.
ADS C:\ProgramData\TEMP:4F58D818 deleted successfully.
ADS C:\ProgramData\TEMP:25005EFA deleted successfully.
ADS C:\ProgramData\TEMP:0EE601C7 deleted successfully.
ADS C:\ProgramData\TEMP:F86CC73E deleted successfully.
ADS C:\ProgramData\TEMP:DCDE7C60 deleted successfully.
ADS C:\ProgramData\TEMP:76986D86 deleted successfully.
ADS C:\ProgramData\TEMP:FD6B3FC3 deleted successfully.
ADS C:\ProgramData\TEMP:E54FA796 deleted successfully.
ADS C:\ProgramData\TEMP:8FBE0E9C deleted successfully.
ADS C:\ProgramData\TEMP:226A6E31 deleted successfully.
ADS C:\ProgramData\TEMP:BDB40AA4 deleted successfully.
ADS C:\ProgramData\TEMP:B54102AD deleted successfully.
ADS C:\ProgramData\TEMP:95B7F1EC deleted successfully.
ADS C:\ProgramData\TEMP:7091055F deleted successfully.
ADS C:\ProgramData\TEMP:666FB4AA deleted successfully.
ADS C:\ProgramData\TEMP:5711EF65 deleted successfully.
ADS C:\ProgramData\TEMP:00C31200 deleted successfully.
ADS C:\ProgramData\TEMP:D66B5EAE deleted successfully.
ADS C:\ProgramData\TEMP:6DD87D86 deleted successfully.
ADS C:\ProgramData\TEMP:3A925163 deleted successfully.
ADS C:\ProgramData\TEMP:3612C9BE deleted successfully.
ADS C:\ProgramData\TEMP:05816AFA deleted successfully.
ADS C:\ProgramData\TEMP:A696643D deleted successfully.
ADS C:\ProgramData\TEMP:93DE1838 deleted successfully.
ADS C:\ProgramData\TEMP:42228396 deleted successfully.
ADS C:\ProgramData\TEMP:1C9565AC deleted successfully.
ADS C:\ProgramData\TEMP:158CC5FF deleted successfully.
ADS C:\ProgramData\TEMP:A94968B5 deleted successfully.
ADS C:\ProgramData\TEMP:A4AD016E deleted successfully.
ADS C:\ProgramData\TEMP:81ED9272 deleted successfully.
ADS C:\ProgramData\TEMP:75F5C19E deleted successfully.
ADS C:\ProgramData\TEMP:43AA121F deleted successfully.
ADS C:\ProgramData\TEMP:052A05A1 deleted successfully.
ADS C:\ProgramData\TEMP:E6B9E5A3 deleted successfully.
ADS C:\ProgramData\TEMP:E36F5B57 deleted successfully.
ADS C:\ProgramData\TEMP:5C270C64 deleted successfully.
ADS C:\ProgramData\TEMP:20B17557 deleted successfully.
ADS C:\ProgramData\TEMP:0B61DB9F deleted successfully.
ADS C:\ProgramData\TEMP:0651F96C deleted successfully.
ADS C:\ProgramData\TEMP:F264BECE deleted successfully.
ADS C:\ProgramData\TEMP:E5AFE07D deleted successfully.
ADS C:\ProgramData\TEMP:D26DD363 deleted successfully.
ADS C:\ProgramData\TEMP:BB8F0982 deleted successfully.
ADS C:\ProgramData\TEMP:B723C5EF deleted successfully.
ADS C:\ProgramData\TEMP:776E54F2 deleted successfully.
ADS C:\ProgramData\TEMP:710F4DBF deleted successfully.
ADS C:\ProgramData\TEMP:5466F106 deleted successfully.
ADS C:\ProgramData\TEMP:3780BCC3 deleted successfully.
ADS C:\ProgramData\TEMP:EA2FBCA1 deleted successfully.
ADS C:\ProgramData\TEMP:CDFF58FE deleted successfully.
ADS C:\ProgramData\TEMP:9FE30AB2 deleted successfully.
ADS C:\ProgramData\TEMP:36B6EC9F deleted successfully.
ADS C:\ProgramData\TEMP:33553E61 deleted successfully.
ADS C:\ProgramData\TEMP:162E02F7 deleted successfully.
ADS C:\ProgramData\TEMP:DAFD38AE deleted successfully.
ADS C:\ProgramData\TEMP:700CD00E deleted successfully.
ADS C:\ProgramData\TEMP:6C491D31 deleted successfully.
ADS C:\ProgramData\TEMP:1AF93AF4 deleted successfully.
ADS C:\ProgramData\TEMP:F02F4882 deleted successfully.
ADS C:\ProgramData\TEMP:AD79E1D8 deleted successfully.
ADS C:\ProgramData\TEMP:9B52F176 deleted successfully.
ADS C:\ProgramData\TEMP:4E903DEB deleted successfully.
ADS C:\ProgramData\TEMP:3B00070D deleted successfully.
ADS C:\ProgramData\TEMP:38849DE5 deleted successfully.
ADS C:\ProgramData\TEMP:34FC1C45 deleted successfully.
ADS C:\ProgramData\TEMP:2B4E9D93 deleted successfully.
ADS C:\ProgramData\TEMP:D8A7F3FF deleted successfully.
ADS C:\ProgramData\TEMP:D61069DE deleted successfully.
ADS C:\ProgramData\TEMP:AA004D25 deleted successfully.
ADS C:\ProgramData\TEMP:7DFDF9DF deleted successfully.
ADS C:\ProgramData\TEMP:426796C0 deleted successfully.
ADS C:\ProgramData\TEMP:3447AB86 deleted successfully.
ADS C:\ProgramData\TEMP:3214A283 deleted successfully.
ADS C:\ProgramData\TEMP:B14B4A95 deleted successfully.
ADS C:\ProgramData\TEMP:93C494CA deleted successfully.
ADS C:\ProgramData\TEMP:588B60C7 deleted successfully.
ADS C:\ProgramData\TEMP:558C8E0A deleted successfully.
ADS C:\ProgramData\TEMP:91973ED2 deleted successfully.
ADS C:\ProgramData\TEMP:5C07C19F deleted successfully.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\TEMP:949483BD deleted successfully.
ADS C:\ProgramData\TEMP:6641B59F deleted successfully.
ADS C:\ProgramData\TEMP:FA5F15C4 deleted successfully.
ADS C:\ProgramData\TEMP:A42A9F39 deleted successfully.
ADS C:\ProgramData\TEMP:9A7901A9 deleted successfully.
ADS C:\ProgramData\TEMP:943D6A82 deleted successfully.
ADS C:\ProgramData\TEMP:07536DA3 deleted successfully.
ADS C:\ProgramData\TEMP:E71141D2 deleted successfully.
ADS C:\ProgramData\TEMP:4D7FCCD3 deleted successfully.
ADS C:\ProgramData\TEMP:21745EE1 deleted successfully.
ADS C:\ProgramData\TEMP:ADE16379 deleted successfully.
ADS C:\ProgramData\TEMP:997E6AF4 deleted successfully.
ADS C:\ProgramData\TEMP:61E5F0F7 deleted successfully.
ADS C:\ProgramData\TEMP:48F0FFF8 deleted successfully.
ADS C:\ProgramData\TEMP:375E3FC4 deleted successfully.
ADS C:\ProgramData\TEMP:27AD48A5 deleted successfully.
ADS C:\ProgramData\TEMP:77F07255 deleted successfully.
ADS C:\ProgramData\TEMP:4F636E25 deleted successfully.
ADS C:\ProgramData\TEMP:30376ACC deleted successfully.
ADS C:\ProgramData\TEMP:54BAC9A7 deleted successfully.
ADS C:\ProgramData\TEMP:2B8FEE50 deleted successfully.
ADS C:\ProgramData\TEMP:5EBA4934 deleted successfully.
ADS C:\ProgramData\TEMP:492679C1 deleted successfully.
ADS C:\ProgramData\TEMP:1CB8D545 deleted successfully.
ADS C:\ProgramData\TEMP:E1982A23 deleted successfully.
ADS C:\ProgramData\TEMP:6F1F1DBC deleted successfully.
ADS C:\ProgramData\TEMP:41099CE9 deleted successfully.
ADS C:\ProgramData\TEMP:345E21F6 deleted successfully.
ADS C:\ProgramData\TEMP:1CB3187E deleted successfully.
ADS C:\ProgramData\TEMP:1B1330FD deleted successfully.
ADS C:\ProgramData\TEMP:F951183D deleted successfully.
ADS C:\ProgramData\TEMP:CE7C61DF deleted successfully.
ADS C:\ProgramData\TEMP:A69F57F3 deleted successfully.
ADS C:\ProgramData\TEMP:3064D21D deleted successfully.
ADS C:\ProgramData\TEMP:CF5C4195 deleted successfully.
ADS C:\ProgramData\TEMP:D690C7F7 deleted successfully.
ADS C:\ProgramData\TEMP:BB48E5A3 deleted successfully.
ADS C:\ProgramData\TEMP:9335E3B6 deleted successfully.
ADS C:\ProgramData\TEMP:6A18D1F5 deleted successfully.
ADS C:\ProgramData\TEMP:F5BB3657 deleted successfully.
ADS C:\ProgramData\TEMP:ABE89FFE deleted successfully.
ADS C:\ProgramData\TEMP:9AB338B9 deleted successfully.
ADS C:\ProgramData\TEMP:9A221D63 deleted successfully.
ADS C:\ProgramData\TEMP:765C6A14 deleted successfully.
ADS C:\ProgramData\TEMP:37CE0F2E deleted successfully.
ADS C:\ProgramData\TEMP:126591AF deleted successfully.
ADS C:\ProgramData\TEMP:0207B271 deleted successfully.
ADS C:\ProgramData\TEMP:B6FA1F20 deleted successfully.
ADS C:\ProgramData\TEMP:87E0E06D deleted successfully.
ADS C:\ProgramData\TEMP:7FC64998 deleted successfully.
ADS C:\ProgramData\TEMP:DF2EA4BB deleted successfully.
ADS C:\ProgramData\TEMP:615435BE deleted successfully.
ADS C:\ProgramData\TEMP:567AC0A6 deleted successfully.
ADS C:\ProgramData\TEMP:12A8EFF7 deleted successfully.
ADS C:\ProgramData\TEMP:919B0931 deleted successfully.
ADS C:\ProgramData\TEMP:6A97C459 deleted successfully.
========== REGISTRY ==========
Registry key Invalid\\"TCP Query User{0F5DA350-6BA4-4B87-AB29-DC7802FDB098}C:\program files\emule\emule.exe" \ not found.
Registry key Invalid\\"TCP Query User{A0B0E0E5-04EC-44CD-A7C6-846D7810BB31}C:\program files\emule\emule.exe" \ not found.
Registry key Invalid\\"UDP Query User{AC0ED212-C3CF-4A96-9402-1ED730BAF584}C:\program files\emule\emule.exe" \ not found.
Registry key Invalid\\"UDP Query User{FE6EE0E9-D6C8-4AA6-9A17-1C52C54A7F9A}C:\program files\emule\emule.exe" \ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\cfvro not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Fabi
->Temp folder emptied: 43316497 bytes
->Temporary Internet Files folder emptied: 4401742 bytes
->Java cache emptied: 3965190 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 2875511 bytes
 
User: Gast
->Temp folder emptied: 79772 bytes
->Temporary Internet Files folder emptied: 209733 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 123650 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 52,00 mb
 
Error: Unable to interpret <         und füge es hier ein: > in the current context!
 
OTL by OldTimer - Version 3.2.31.0 log created on 01102012_173136

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
         
__________________


Alt 10.01.2012, 19:49   #18
puma165
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



10.:

Code:
ATTFilter
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/10/2012 at 07:31 PM

Application Version : 5.0.1142

Core Rules Database Version : 8118
Trace Rules Database Version: 5930

Scan type       : Complete Scan
Total Scan Time : 01:40:02

Operating System Information
Windows Vista Home Premium 32-bit (Build 6.00.6000)
UAC On - Limited User (Administrator User)

Memory items scanned      : 702
Memory threats detected   : 0
Registry items scanned    : 37495
Registry threats detected : 5
File items scanned        : 42918
File threats detected     : 2

Registry Cleaner Trial
	HKCR\Install.Install
	HKCR\Install.Install\CLSID
	HKCR\Install.Install\CurVer
	HKCR\Install.Install.1
	HKCR\Install.Install.1\CLSID

Adware.Tracking Cookie
	C:\USERS\FABI\AppData\Roaming\Microsoft\Windows\Cookies\Low\fabi@doubleclick[2].txt [ Cookie:fabi@doubleclick.net/ ]

Trojan.Agent/Gen-Autoit
	C:\PROGRAM FILES\SONY ERICSSON\SONY ERICSSON PC SUITE\PC SUITE LOG.EXE
         
__________________

Alt 11.01.2012, 21:11   #19
puma165
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



OTL.Txt

Code:
ATTFilter
OTL logfile created on: 11.01.2012 20:52:27 - Run 2
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Fabi\Desktop
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,87 Gb Total Physical Memory | 0,84 Gb Available Physical Memory | 44,71% Memory free
3,92 Gb Paging File | 2,51 Gb Available in Paging File | 63,96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 129,47 Gb Total Space | 35,52 Gb Free Space | 27,44% Space Free | Partition Type: NTFS
Drive D: | 19,57 Gb Total Space | 14,28 Gb Free Space | 72,99% Space Free | Partition Type: FAT32
 
Computer Name: FABI-PC | User Name: Fabi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.07 22:54:47 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Fabi\Desktop\OTL.exe
PRC - [2011.12.09 01:44:22 | 004,616,064 | ---- | M] (SUPERAntiSpyware.com) -- C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2011.12.04 00:48:48 | 000,247,968 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe
PRC - [2011.11.12 13:14:54 | 000,307,376 | ---- | M] (Google Inc.) -- C:\Programme\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2011.08.12 00:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Programme\SUPERAntiSpyware\SASCore.exe
PRC - [2011.06.15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2011.04.27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010.11.21 10:49:24 | 000,247,608 | ---- | M] () -- C:\Programme\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.04.05 20:55:01 | 000,116,104 | ---- | M] () -- C:\Programme\Canon\IJPLM\ijplmsvc.exe
PRC - [2010.02.23 07:39:16 | 000,638,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2009.09.10 16:29:33 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmplayer.exe
PRC - [2008.10.29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.03.30 12:58:18 | 000,185,632 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Common Files\Real\Update_OB\realsched.exe
PRC - [2008.01.10 15:24:56 | 001,232,896 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2007.12.27 15:39:30 | 000,166,520 | ---- | M] () -- C:\Programme\IVT Corporation\BlueSoleil\BTNtService.exe
PRC - [2007.12.27 15:39:20 | 000,051,816 | ---- | M] () -- C:\Programme\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
PRC - [2007.08.14 11:23:00 | 000,776,192 | ---- | M] (Google) -- C:\Programme\Google\Google Desktop Search\GoogleDesktopIndex.exe
PRC - [2007.04.16 14:24:10 | 000,192,512 | ---- | M] (Wistron) -- C:\Programme\Launch Manager\HotkeyApp.exe
PRC - [2007.02.15 19:52:16 | 000,118,784 | ---- | M] (Synaptics, Inc.) -- C:\Programme\Synaptics\SynTP\SynMedion.exe
PRC - [2007.02.15 16:07:16 | 004,390,912 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2006.12.26 10:23:34 | 000,180,224 | ---- | M] (Wistron Corp.) -- C:\Programme\Launch Manager\OSD.exe
PRC - [2006.11.17 19:45:26 | 000,118,784 | ---- | M] (Wistron Corp.) -- C:\Programme\Launch Manager\WisLMSvc.exe
PRC - [2006.11.09 13:37:52 | 000,086,016 | ---- | M] () -- C:\Programme\Launch Manager\WButton.exe
PRC - [2006.11.02 13:36:04 | 000,895,488 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2006.11.02 13:36:04 | 000,201,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2006.11.02 10:44:59 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2005.07.25 12:36:40 | 000,032,768 | ---- | M] () -- C:\Programme\Launch Manager\LaunchAp.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.01.11 14:15:35 | 000,063,488 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
MOD - [2012.01.11 14:15:35 | 000,052,736 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
MOD - [2012.01.10 17:48:37 | 000,117,760 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
MOD - [2012.01.10 17:48:37 | 000,052,224 | ---- | M] () -- C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
MOD - [2010.06.03 12:46:00 | 000,067,872 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2006.11.09 13:37:52 | 000,086,016 | ---- | M] () -- C:\Programme\Launch Manager\WButton.exe
MOD - [2005.07.25 12:36:40 | 000,032,768 | ---- | M] () -- C:\Programme\Launch Manager\LaunchAp.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.08.12 00:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011.04.27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.11.21 10:49:24 | 000,247,608 | ---- | M] () [Auto | Running] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.04.05 20:55:01 | 000,116,104 | ---- | M] () [Auto | Running] -- C:\Programme\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2007.12.27 15:39:30 | 000,166,520 | ---- | M] () [Auto | Running] -- C:\Programme\IVT Corporation\BlueSoleil\BTNtService.exe -- (BlueSoleil Hid Service)
SRV - [2007.12.27 15:39:20 | 000,051,816 | ---- | M] () [Auto | Running] -- C:\Programme\IVT Corporation\BlueSoleil\StartSkysolSvc.exe -- (Start BT in service)
SRV - [2007.08.14 11:23:00 | 000,069,120 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe -- (GoogleDesktopManager)
SRV - [2007.08.13 04:59:24 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006.11.17 19:45:26 | 000,118,784 | ---- | M] (Wistron Corp.) [On_Demand | Running] -- C:\Program Files\Launch Manager\WisLMSvc.exe -- (WisLMSvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2012.01.11 14:28:25 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C7F55EC7-1B0D-4A3A-A79B-66503B788B80}\MpKsl9f236b41.sys -- (MpKsl9f236b41)
DRV - [2011.07.22 17:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011.04.18 12:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2010.03.19 14:40:55 | 000,097,792 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV05.sys -- (ACEDRV05)
DRV - [2009.05.25 13:35:00 | 000,116,904 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029unic.sys -- (s1029unic) Sony Ericsson Device 1029 USB Ethernet Emulation (WDM)
DRV - [2009.05.25 13:34:56 | 000,122,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029mdm.sys -- (s1029mdm)
DRV - [2009.05.25 13:34:56 | 000,090,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029bus.sys -- (s1029bus) Sony Ericsson Device 1029 driver (WDM)
DRV - [2009.05.25 13:34:56 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029mdfl.sys -- (s1029mdfl)
DRV - [2009.05.25 13:34:54 | 000,115,880 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029mgmt.sys -- (s1029mgmt) Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM)
DRV - [2009.05.25 13:34:54 | 000,111,912 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029obex.sys -- (s1029obex)
DRV - [2009.05.25 13:34:54 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s1029nd5.sys -- (s1029nd5) Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS)
DRV - [2007.06.25 10:43:38 | 000,098,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117obex.sys -- (s117obex)
DRV - [2007.06.25 10:43:36 | 000,108,456 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117mdm.sys -- (s117mdm)
DRV - [2007.06.25 10:43:36 | 000,100,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117mgmt.sys -- (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM)
DRV - [2007.06.25 10:43:36 | 000,098,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117unic.sys -- (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM)
DRV - [2007.06.25 10:43:36 | 000,022,952 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117nd5.sys -- (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS)
DRV - [2007.06.25 10:43:26 | 000,014,888 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117mdfl.sys -- (s117mdfl)
DRV - [2007.06.25 10:43:22 | 000,082,984 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s117bus.sys -- (s117bus) Sony Ericsson Device 117 driver (WDM)
DRV - [2007.06.24 21:56:54 | 000,038,920 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007.06.24 21:56:40 | 000,027,656 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007.06.24 21:56:34 | 000,034,312 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007.03.05 20:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btnetdrv.sys -- (BT)
DRV - [2007.03.05 20:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007.03.05 20:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007.03.05 20:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VCommMgr.sys -- (VcommMgr)
DRV - [2007.03.05 20:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VComm.sys -- (VComm)
DRV - [2007.02.07 17:35:10 | 001,729,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2007.01.13 09:40:00 | 004,452,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007.01.08 18:34:04 | 000,449,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athrusb.sys -- (athrusb)
DRV - [2006.11.15 16:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006.11.15 11:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.11.15 09:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006.11.02 08:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.02 08:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2006.09.15 07:44:18 | 000,011,520 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2003.04.28 10:27:06 | 000,009,867 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\HOTKEY.sys -- (Hotkey)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2910: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Fabi\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
 
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1908.5032\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa2.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Move Media Player 7 (Enabled) = C:\Users\Fabi\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Fabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google-Suche = C:\Users\Fabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Google Mail = C:\Users\Fabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,736 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1             localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programme\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe (Wistron Corp.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSConfig] C:\Windows\System32\msconfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Öffnen mit WordPerfect - C:\Programme\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra 'Tools' menuitem : &Turnabout Options... - {1C1CB5F8-D5A3-4FD9-876C-ECD2BDA32716} - C:\Program Files\Reify Software\Turnabout\turnabout.dll File not found
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldde-de.cab (MSN Photo Upload Tool)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} hxxp://static.pe.schuelervz.net/photouploader/ImageUploader5.cab?nocache=1227798386 (Image Uploader Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v911/Navigram.cab (Navigram Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldde-de.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} https://secure.gopetslive.com/dev/gopets.cab (GoPets Control)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} https://secure.gopetslive.com/dev/GoPetsWeb.cab (GoPetsWeb Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{252131F5-C094-4AC0-9132-D2C62238476B}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\data {038664DA-5BA5-47FC-88D9-15ADE940ED55} - C:\Program Files\Reify Software\Turnabout\turnabout.dll File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Programme\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Fabi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Fabi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programme\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.10 21:13:04 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.01.10 19:55:52 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.01.10 17:48:05 | 000,000,000 | ---D | C] -- C:\Users\Fabi\AppData\Roaming\SUPERAntiSpyware.com
[2012.01.10 17:46:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.01.10 17:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012.01.10 17:46:31 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.01.10 17:31:36 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.01.09 18:08:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012.01.09 18:07:44 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.01.09 17:53:42 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.01.09 17:53:42 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.01.09 17:53:42 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.01.07 23:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.01.07 23:25:04 | 003,562,624 | ---- | C] (Piriform Ltd) -- C:\Users\Fabi\Desktop\ccsetup314.exe
[2012.01.07 22:54:36 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Fabi\Desktop\OTL.exe
[2012.01.07 19:05:30 | 000,000,000 | ---D | C] -- C:\Users\Fabi\AppData\Roaming\Malwarebytes
[2012.01.07 19:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.07 19:04:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.01.07 19:03:12 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.01.07 19:03:11 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.01.07 00:49:47 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2007.08.14 11:09:25 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll
[32 C:\Users\Fabi\Documents\*.tmp files -> C:\Users\Fabi\Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.11 21:00:14 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{68F20928-A1BD-45E6-889F-3AF40BD81F0B}.job
[2012.01.11 20:13:15 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.11 20:13:15 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.11 20:08:23 | 000,012,978 | ---- | M] () -- C:\Users\Fabi\AppData\Roaming\nvModes.dat
[2012.01.11 20:08:23 | 000,012,978 | ---- | M] () -- C:\Users\Fabi\AppData\Roaming\nvModes.001
[2012.01.11 20:08:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.11 14:12:41 | 2011,873,280 | -HS- | M] () -- C:\hiberfil.sys
[2012.01.10 19:53:49 | 000,651,350 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.10 19:53:49 | 000,618,470 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.10 19:53:49 | 000,121,114 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.10 19:53:49 | 000,107,614 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.10 19:36:09 | 000,000,974 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012.01.10 17:46:47 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.01.09 18:12:22 | 000,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012.01.09 17:39:01 | 000,000,680 | ---- | M] () -- C:\Users\Fabi\AppData\Local\d3d9caps.dat
[2012.01.07 23:27:26 | 000,000,808 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.01.07 23:25:26 | 003,562,624 | ---- | M] (Piriform Ltd) -- C:\Users\Fabi\Desktop\ccsetup314.exe
[2012.01.07 22:54:47 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Fabi\Desktop\OTL.exe
[2012.01.07 19:05:09 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.01.07 11:42:29 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.01.07 00:50:23 | 000,029,152 | ---- | M] () -- C:\Users\Fabi\Desktop\Desktop.zip
[2012.01.06 23:39:10 | 000,000,000 | ---- | M] () -- C:\Users\Fabi\defogger_reenable
[2012.01.03 17:57:39 | 000,002,637 | ---- | M] () -- C:\Users\Fabi\Desktop\Microsoft Office Word 2003.lnk
[2011.12.23 15:01:12 | 000,000,556 | ---- | M] () -- C:\Windows\tasks\Norton Security Scan for Fabi.job
[2011.12.14 22:08:29 | 000,017,408 | -H-- | M] () -- C:\Users\Fabi\Desktop\photothumb.db
[32 C:\Users\Fabi\Documents\*.tmp files -> C:\Users\Fabi\Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.10 17:46:47 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.01.10 17:36:05 | 000,000,974 | ---- | C] () -- C:\Windows\tasks\Google Software Updater.job
[2012.01.09 18:09:31 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012.01.09 18:09:31 | 000,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012.01.09 17:41:29 | 2011,873,280 | -HS- | C] () -- C:\hiberfil.sys
[2012.01.07 23:27:25 | 000,000,808 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.01.07 19:05:09 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.01.07 00:50:23 | 000,029,152 | ---- | C] () -- C:\Users\Fabi\Desktop\Desktop.zip
[2012.01.06 23:39:10 | 000,000,000 | ---- | C] () -- C:\Users\Fabi\defogger_reenable
[2009.06.23 14:02:26 | 000,004,096 | -H-- | C] () -- C:\Users\Fabi\AppData\Local\keyfile3.drm
[2009.01.25 15:02:29 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.03.21 21:11:46 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2008.02.02 18:11:10 | 000,164,352 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2007.12.17 18:59:37 | 000,641,021 | ---- | C] () -- C:\Windows\unins000.exe
[2007.12.17 18:59:37 | 000,006,817 | ---- | C] () -- C:\Windows\unins000.dat
[2007.11.26 19:47:42 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll
[2007.11.18 11:28:05 | 000,000,680 | ---- | C] () -- C:\Users\Fabi\AppData\Local\d3d9caps.dat
[2007.11.04 20:45:52 | 000,076,800 | ---- | C] () -- C:\Users\Fabi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.11.04 10:55:19 | 000,012,978 | ---- | C] () -- C:\Users\Fabi\AppData\Roaming\nvModes.001
[2007.11.04 10:48:24 | 000,012,978 | ---- | C] () -- C:\Users\Fabi\AppData\Roaming\nvModes.dat
[2007.11.04 10:17:00 | 000,000,092 | ---- | C] () -- C:\Users\Fabi\AppData\Local\fusioncache.dat
[2007.08.14 11:09:25 | 001,729,152 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
[2007.08.13 06:07:52 | 000,009,867 | ---- | C] () -- C:\Windows\System32\drivers\HOTKEY.sys
[2007.08.13 05:23:33 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.08.13 05:23:18 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2006.12.11 05:06:31 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006.11.02 16:33:31 | 000,651,350 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 16:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 16:33:31 | 000,121,114 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 16:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,367,248 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,618,470 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,107,614 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.11.02 08:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2006.11.02 08:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2003.02.20 17:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
 
========== LOP Check ==========
 
[2009.01.11 13:13:47 | 000,000,000 | -HSD | M] -- C:\Users\Fabi\AppData\Roaming\.#
[2011.06.24 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\1morebee
[2010.02.15 20:44:14 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Alawar
[2008.06.01 17:57:38 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Alterlab
[2008.11.02 16:03:09 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Amaranth Games
[2010.08.26 03:25:59 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Amazon
[2008.03.04 17:59:47 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Aquapark
[2007.11.19 15:33:02 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Balloon Express
[2008.10.17 14:42:36 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\BeachPartyCraze
[2009.07.31 11:19:09 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\BlamGames
[2010.06.07 18:13:06 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Boomzap
[2010.02.13 00:51:22 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Camel101
[2010.12.21 21:19:02 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Canon
[2009.12.26 00:23:57 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\CasualForge
[2008.03.07 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\eGames
[2010.02.12 15:57:57 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\EleFun Games
[2010.02.21 00:51:03 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Fuzzy Games
[2009.03.28 18:27:25 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\GameInvest
[2008.11.23 17:33:24 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Gamelab
[2008.03.02 13:00:52 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Home Sweet Home
[2010.01.24 13:48:42 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\HSA
[2011.08.31 14:43:17 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\ICQ
[2007.11.07 14:11:42 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\ICQ Toolbar
[2008.10.22 14:52:52 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\ITTNord
[2009.01.18 17:07:56 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\iWin
[2008.03.07 16:14:52 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Jane s Hotel
[2008.11.23 17:01:48 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Ludia
[2008.03.18 16:29:38 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Magic Seeds
[2008.05.25 10:52:03 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Meridian93
[2010.06.11 17:04:21 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Merscom
[2007.12.01 15:28:01 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\MysteryStudio
[2010.10.02 23:47:27 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\oberon
[2009.11.18 16:39:25 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Oberon Games
[2010.07.27 14:08:06 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\panoramik
[2008.10.28 14:41:40 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\PetShowCraze
[2012.01.07 11:21:19 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\PhotoScape
[2009.04.24 14:31:10 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\PlayFirst
[2008.10.22 15:11:25 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Pogo Games
[2007.12.15 11:45:32 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Sandlot Games
[2010.01.18 18:56:38 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Shape games
[2008.05.22 13:21:18 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Sony
[2011.01.23 16:30:25 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\StarOffice8
[2008.01.20 17:19:54 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Super-Cow
[2007.11.04 17:19:25 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\T-Online
[2008.03.12 15:06:45 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Total Eclipse
[2008.02.02 19:59:28 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\URSE Games
[2009.03.21 19:40:14 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Valusoft
[2008.03.02 20:19:35 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\ViquaSoft
[2010.01.23 13:04:13 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\Windows Live Writer
[2009.05.23 21:47:06 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\World-LooM
[2009.12.06 22:54:33 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\YoudaGames
[2009.03.22 18:31:32 | 000,000,000 | ---D | M] -- C:\Users\Fabi\AppData\Roaming\ZEMNOTT
[2007.11.09 17:50:29 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job
[2012.01.10 22:48:06 | 000,032,578 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.01.11 21:00:14 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{68F20928-A1BD-45E6-889F-3AF40BD81F0B}.job
 
========== Purity Check ==========
 
 

< End of report >
         

Extras.Txt

Code:
ATTFilter
OTL Extras logfile created on: 11.01.2012 20:52:27 - Run 2
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Fabi\Desktop
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,87 Gb Total Physical Memory | 0,84 Gb Available Physical Memory | 44,71% Memory free
3,92 Gb Paging File | 2,51 Gb Available in Paging File | 63,96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 129,47 Gb Total Space | 35,52 Gb Free Space | 27,44% Space Free | Partition Type: NTFS
Drive D: | 19,57 Gb Total Space | 14,28 Gb Free Space | 72,99% Space Free | Partition Type: FAT32
 
Computer Name: FABI-PC | User Name: Fabi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{103EA1D4-0ADC-4D6A-AE71-F780D24C8211}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{241EFEEF-2626-4DB4-BDD4-6C84E6245E43}" = rport=137 | protocol=17 | dir=out | app=system | 
"{2AD8E65E-9162-41F8-ACC7-85256DCF6FA5}" = rport=445 | protocol=6 | dir=out | app=system | 
"{41DCBC0B-FAB0-4D3F-9262-E25E42FF76B2}" = rport=139 | protocol=6 | dir=out | app=system | 
"{6D99D5CA-347A-46B2-B232-0DD32BAB9E46}" = lport=137 | protocol=17 | dir=in | app=system | 
"{720B02EA-7EA1-411E-8488-31F74685EBF6}" = rport=138 | protocol=17 | dir=out | app=system | 
"{96D87760-C082-47A2-9DEC-15FD8D3116E1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{9C23306C-B58B-449C-8306-FDDF9787AC9F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{BD19027C-ED86-43B0-97FF-8BBFD96424FE}" = lport=138 | protocol=17 | dir=in | app=system | 
"{C5361ABF-E576-49B4-9FB4-DEC2F9F6E01D}" = lport=445 | protocol=6 | dir=in | app=system | 
"{C63B2376-F8C7-4576-BBD8-52194EF8F98A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{CC288217-C172-4B5B-858C-6F69A69CD314}" = lport=139 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02507FC3-EFA0-4F75-9837-7BAB45418993}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager 1.0\mediamanager.exe | 
"{0B8C9772-FA04-4342-B352-44D282AFA019}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{2EA40D41-60C9-48AD-B0AD-5051FD721890}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{2F8807CD-24F5-4961-ABC7-604C86D093A4}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{3FF914E6-22C8-4EF2-93EF-944EF970E414}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{4A0DD295-7B7F-4D53-A00F-5999377A9FCC}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{5953A6A8-B3BB-4B03-B956-8701585F25B8}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{5E8BD244-ECA1-4A9B-AA31-2B6C76DB58A6}" = protocol=6 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe | 
"{79B78259-DDF0-4E58-962E-8E2458FF2AAB}" = protocol=17 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe | 
"{88A8B0A1-A5EA-4F31-8DFB-84CA88F02483}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{89130995-3636-4CFE-9DF4-0329DE3FD835}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{97F4653B-654F-4DA1-9960-DD6ADA8A92F7}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager 1.0\mediamanager.exe | 
"{99AF53E8-2BE6-45A5-BD09-1EF5436F83B6}" = protocol=6 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe | 
"{9A00A4CF-7BB9-44C0-A0EF-8526ED2790DC}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{9EEB8D6F-E176-46D6-9D3D-6BEAFF23849B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{A12AF980-DD0A-4BCC-88F8-A5D465A9BBE4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{A97FA3B3-AC7E-4F96-8DD4-589F5F9CE7FC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | 
"{C7EE2E93-549F-4AD6-989F-1F2620649066}" = protocol=17 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe | 
"{CD9BAC6D-C10B-4B08-A500-A4C7CC1B2E1B}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{D2087E66-72FA-4CE0-8FEA-DE5804E1F8CF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{DD182D98-B60A-48B2-83AE-2FA09616B324}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe | 
"{E3437246-A9DE-40DC-BE65-9269908F600F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{EFA5DEAE-AA06-46CF-B626-D02C1BA66B1F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{F3B83C52-211A-4B89-84AF-3C69D4DFD2C2}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{FBE49167-0DFC-43E3-897C-E6CA25805112}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"TCP Query User{30318520-7D42-4370-AD0C-8F832769BB10}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"TCP Query User{5769D8A6-7375-426E-BEE9-27E23E2DD375}C:\games\game alarm\gamealarm.exe" = protocol=6 | dir=in | app=c:\games\game alarm\gamealarm.exe | 
"TCP Query User{734879EE-B333-4AB4-B6BD-0888DB54F424}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"TCP Query User{912A8113-8FFE-49C1-AFDA-7F729B4B301C}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe | 
"TCP Query User{B387C826-9648-4A8B-9846-AF37EAB66DE5}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"TCP Query User{DF02504F-039C-456A-84D9-60B6E88C0103}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"UDP Query User{050722B0-DBC7-4C05-9960-A26F4B496AC6}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe | 
"UDP Query User{26CA0FF8-C0BF-453B-BFAA-EB247888BD1B}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"UDP Query User{3383AA64-D440-4797-A777-94B16A64EFBE}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"UDP Query User{783A0946-184F-4B91-A589-D483B3B7B8A1}C:\games\game alarm\gamealarm.exe" = protocol=17 | dir=in | app=c:\games\game alarm\gamealarm.exe | 
"UDP Query User{DCC7D2ED-D2EB-4936-BE21-73980E5FBFE5}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"UDP Query User{F005A03D-5323-4803-A1EE-E72EE40C904E}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00D0200F-3B4D-4A2F-869E-533ED835A943}" = Hervorhebe-Funktion (Windows Live Toolbar)
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{0AC49543-9CE2-4434-AD42-5AA6E2967FA5}" = Windows Live Toolbar
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series" = Canon MP280 series MP Drivers
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1EDFA38A-2FEB-4E62-82C9-DA415C0EEF33}" = IEEE 802.11g Wireless LAN driver
"{218761F6-CBF6-4973-B910-A33E6563A1EA}" = Windows Live Toolbar-Erweiterung (Windows Live Toolbar)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 30
"{2B091530-69AA-442E-AB09-39ED06B58220}" = Windows Live Messenger
"{2DD6C198-FA9A-40B4-8DE5-CE5206E3EB34}" = Smart Menus (Windows Live Toolbar)
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 3.010.00
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Suyin Live Camera
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{45FCADDB-0B29-457E-83A1-D245C62A716C}" = OLYMPUS Master 2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client DE-DE Language Pack
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5C72622B-643D-4296-B57D-5D53D0C68509}" = Sony Ericsson Media Manager 1.0
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = Die Sims 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites für Windows Live Toolbar
"{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}" = Windows Live installer
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}" = Turbo Fiesta
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115369807}" = Sunshine Acres
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11564540}" = Gourmania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11565287}" = Frogs In Love
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115655273}" = Daycare Nightmare Mini Monsters
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116433950}" = Jewelix
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116507277}" = Miracles
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116510433}" = Orchard
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116511547}" = TonkyPonky
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116514193}" = Fix-it-up Kate`s Adventure
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116554407}" = DQ Tycoon
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116558297}" = Jennys Fish Shop
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116563147}" = Cooking Academy 2 World Cuisine
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116648913}" = Costume Chaos
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116726920}" = Fab Fashion
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11684033}" = Success Story
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116921517}" = Plan it Green
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117044280}" = Mystic Emporium
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117156680}" = Sprill
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117213877}" = TikiBar
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117247390}" = Lovely Kitchen
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117379630}" = Youda Sushi Chef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11738453}" = Burger Shop 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117388953}" = Hotel Mogul
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117576307}" = Mr Jones Graveyard Shift
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117601840}" = Farm Frenzy 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117604257}" = Joe’s Garden
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117701833}" = Cake Mania Main Street
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117762797}" = Kelly Green Garden Queen
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117795997}" = Kitchen Brigade
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118074470}" = Built It - Miami Beach Resort
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118266520}" = Fiona Finch And Finest Flowers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118268417}" = Cake Shop 2
"{82F2B38B-1426-443D-874C-AC25675E7BEB}" = Windows Live Mail
"{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{87E01B1B-92A0-416F-9F8E-9BE921A05F9F}" = StarOffice 8
"{8F85CC2C-4B26-4CF6-B835-DC59BCEDD287}" = Bluesoleil2.7.0.13 VoIP Release 071227
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{A1C659AF-C761-47A8-BAFD-5FD2BE1ED419}" = Wildlife Park 2
"{A1D08B90-AE1A-4885-AC29-731496FD397E}" = Windows Live Fotogalerie
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA047D7C-5E7C-4878-B75C-77589151B563}" = SUYIN webcam
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.7 - Deutsch
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AF303019-87A0-426B-A16F-62690AFF7797}" = Schüler-CD Dorn Bader Physik SEK I
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B3282FB8-874B-4054-8356-9EB391A826F9}" = OLYMPUS muvee theaterPack
"{B398C579-6578-4A6A-AE55-310D7C1A80B6}" = phase6
"{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}" = Windows Live Writer
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.4.0
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe  1.4.124.1
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 1.60.00
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Canon MP280 series Benutzerregistrierung" = Canon MP280 series Benutzerregistrierung
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CCleaner" = CCleaner
"cfvro" = Favorit
"Die Sims 2 (TM)" = Die Sims 2 (TM) Screen Saver
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"ICQToolbar" = ICQ Toolbar
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"MTS2_ColourOptions_is1" = Colour Options 2.0 (beta) for The Sims 2 (and Sims 2 University
"NSS" = Norton Security Scan
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"RealPlayer 6.0" = RealPlayer
"Sandlot Games Client Services 1.2.2_is1" = Sandlot Games Client Services 1.2.2
"Sandlot Games Client Services_is1" = Sandlot Games Client Services
"Ski Alpin 2006_0001" = Ski Alpin 2006
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Tierpension" = Meine Tierpension
"turnabout" = Turnabout IE Plugin
"Windows Live Toolbar" = Windows Live Toolbar
"YTdetect" = Yahoo! Detect
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"gamealarm-DEFAULT" = Game Alarm
"Move Media Player" = Move Media Player
"sc11-DE_SEVENONE_MAIN" = Big Pizza Ski Challenge 11
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12.07.2010 09:10:31 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:10:32 | Computer Name = Fabi-PC | Source = WerSvc | ID = 5007
Description = 
 
Error - 12.07.2010 09:11:00 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:11:40 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:12:13 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:12:21 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:14:31 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:16:37 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 12.07.2010 09:17:32 | Computer Name = Fabi-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 1.5.13.0, Zeitstempel
 0x458d61a6, fehlerhaftes Modul NMIndexStoreSvr.exe, Version 1.5.13.0, Zeitstempel
 0x458d61a6, Ausnahmecode 0xc0000005, Fehleroffset 0x0006991e,  Prozess-ID 0xd34, 
Anwendungsstartzeit 01cb21c3d85009b2.
 
Error - 12.07.2010 09:43:52 | Computer Name = Fabi-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
[ System Events ]
Error - 10.01.2012 12:34:05 | Computer Name = Fabi-PC | Source = Microsoft Antimalware | ID = 3002
Description = Fehler in %%860-Echtzeitschutzfunktion.     Funktion: %%835     Fehlercode: 
0x80004005     Fehlerbeschreibung: Unbekannter Fehler      Ursache: %%842
 
Error - 10.01.2012 14:35:19 | Computer Name = Fabi-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 3, Funktion 0.   Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 10.01.2012 14:35:19 | Computer Name = Fabi-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 2, Funktion 0.   Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 10.01.2012 14:36:25 | Computer Name = Fabi-PC | Source = Microsoft Antimalware | ID = 3002
Description = Fehler in %%860-Echtzeitschutzfunktion.     Funktion: %%835     Fehlercode: 
0x80004005     Fehlerbeschreibung: Unbekannter Fehler      Ursache: %%842
 
Error - 10.01.2012 14:37:20 | Computer Name = Fabi-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 10.01.2012 14:37:20 | Computer Name = Fabi-PC | Source = Service Control Manager | ID = 7026
Description = 
 
Error - 10.01.2012 17:47:15 | Computer Name = Fabi-PC | Source = DCOM | ID = 10010
Description = 
 
Error - 11.01.2012 09:12:25 | Computer Name = Fabi-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 3, Funktion 0.   Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 11.01.2012 09:12:25 | Computer Name = Fabi-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 2, Funktion 0.   Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 11.01.2012 09:13:39 | Computer Name = Fabi-PC | Source = Microsoft Antimalware | ID = 3002
Description = Fehler in %%860-Echtzeitschutzfunktion.     Funktion: %%835     Fehlercode: 
0x80004005     Fehlerbeschreibung: Unbekannter Fehler      Ursache: %%842
 
 
< End of report >
         

Alt 11.01.2012, 21:47   #20
puma165
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



alles bis auf schritt 1. und 7. erledigt


Alt 11.01.2012, 21:52   #21
kira
/// Helfer-Team
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



1.
zu Posting #13./Punkt 1.:
Du sollst unter Systemsteuerung-> Software/Programme nicht nach "Adware" suchen, sondern nach:
Zitat:
Favorit
also deinstalliere bitte wie ich es beschrieben hatte

außerdem:
Zitat:
► Berichte mir kurz über alle Umsetzungsschritte, die Du aus diesem Posting (#13) erledigt hast!
2.
erneut einen Scan mit OTL:
  • Doppelklick auf die OTL.exe
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Oben findest Du ein Kästchen mit Ausgabe.
    Wähle bitte Standard-Ausgabe
  • Unter Extra-Registrierung wähle bitte Benutze SafeList.
  • Mache Häckchen bei LOP- und Purity-Prüfung.
  • Klicke nun auf Scan links oben.
  • Wenn der Scan beendet wurde werden zwei Logfiles erstellt.
    Du findest die Logfiles auf Deinem Desktop => OTL.txt und Extras.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.
__________________
--> Windowssystem gesperrt - Virus

Alt 13.01.2012, 14:22   #22
puma165
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



1. : habe ich jetzt entfernt
2. : Java aktualisiert
3. : die alten Java-Versionen gelöscht
4. : Adobe Reader aktualisiert
5. : Spyware entfernt
6. : Norton Security gelöscht
7. : emule nicht gefunden??
8. : System mit CCleaner gereinigt
9. : mit OTL gefixt
10.: mit SUPERAntiSpyware gefixt
11.: USB-Sticks angeschlossen und 12.: mit Eset Online Scanner gescant (hat seehr lange gedauert)
13.: unnötige Programme aus dem Autostart genommen
14.: mit OTL gescannt

es hat alles geklappt (außer schritt 7)

Alt 14.01.2012, 06:49   #23
kira
/// Helfer-Team
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



1.
Programme deinstallieren/entfernen, die wir verwendet haben und nicht brauchst, bis auf:
Code:
ATTFilter
CCleaner
         
- Zeitweise laufen lassen:-> Anleitung

2.
Tool-Bereinigung mit OTL

Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
  • Bitte lade Dir (falls noch nicht vorhanden) OTL von OldTimer herunter.
  • Speichere es auf Deinem Desktop.
  • Doppelklick auf OTL.exe um das Programm auszuführen.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Klicke auf den Button "Bereinigung"
  • OTL fragt eventuell nach einem Neustart.
    Sollte es dies tun, so lasse dies bitte zu.
Anmerkung: Nach dem Neustart werden OTL und andere Helferprogramme, die Du im Laufe der Bereinigung heruntergeladen hast, nicht mehr vorhanden sein. Sie wurden entfernt. Es ist daher Ok, wenn diese Programme nicht mehr vorhanden sind. Sollten noch welche übrig geblieben sein, lösche sie manuell.

3.
Wenn alles gut verlaufen und dein System läuft stabil,mache folgendes:
Alle Systemwiederherstellungspunkte löschen, auch den Letzten

4.
Ich würde Dir vorsichtshalber raten, dein Passwort zu ändern
z.B. Login-, Mail- oder Website-Passwörter
Tipps:
Die sichere Passwort-Wahl - (sollte man eigentlich regelmäßigen Abständen ca. alle 3-5 Monate ändern)
auch noch hier unter: Sicheres Kennwort (Password)

5.
Zitat:
► für Windows Vista
das Service Pack 1
und dann noch
das Service Pack 2
bitte aufspielen!:-> - Microsoft Update hält Ihren Computer auf dem neuesten Stand!
Internet Explorer ebenfalls (Version 9 ist aktuell)
Software wie Betriebssysteme, Browser und E-Mail Clients werden laufend weiterentwickelt. Gleichzeitig arbeiten jedoch auch Hacker daran, ständig neue Sicherheitslücken zu finden und auszunutzen. Was heute noch keine Schlupflücke für Viren und Würmer ist, kann morgen bereits zur Gefahr werden, wenn der entsprechende Schädling programmiert wurde. Das führt dazu, dass es relativ häufig zu Meldungen über neue Sicherheitsanfälligkeiten kommt, auch wenn diese noch nicht durch Hacker entdeckt wurden. Denn selbstverständlich suchen auch Sicherheitsspezialisten nach potenziellen Angriffsmöglichkeiten. Updates der Softwareentwickler sorgen dafür, dass der User immer die aktuellste und sicherste Version des Betriebssystems und der installierten Software nutzen kann.

Lesestoff Nr.1:
  • Wie erstelle ich ein eingeschränktes Benutzerkonto?
  • Software immer auf dem neuesten Stand halten!:
    ALLE auf dem System installierten Programme und Treiber, sollten regelmäßig upgedatet werden um Sicherheitslücken zu vermeiden und um das reibungslose Arbeitsabläufe zu erreichen!
  • Ein sicherer Browser als IE z.B. *Ein Wechsel des Standardbrowsers zu...von SETI@home* - Firefox - FirefoxWiki/Einstellungen - Erweiterungen für Firefox - Standardbrowser
  • Sichere eMail Clients z.B. Thunderbird-->Erweiterungen für Mozilla Thunderbird
    - Unbekannten E-Mail-Anhang NICHT öffnen!
  • Sichere Paswort - Die sichere Passwort-Wahl - (sollte man eigentlich regelmäßigen Abständen ca. alle 3-5 Monate ändern)
    auch noch hier unter: Sicheres Kennwort (Password)
    Die fünf häufigsten Passwort-Fehler[/b[
  • "Never accept software from strangers" - Installiere grundsätzlich immer nur Programme, die Du auch wirklich benötigst und von denen Du überzeugt bist, dass sie seriös sind.
    Du hast die Wahl!, welche zusätzlichen Komponenten noch installiert werden sollen? -> Bei der Installation immer mitlesen, Sponsoren und Partnerprogramme, Toolbars oder eventuell noch andere extra angebotene Programme möglichst abwählen!
    Sponsor-Programm, Toolbars möglist abwählen (so wird oft Art von Adware/Spyware mitinstalliert)
  • NICHT irgendwelche Programme aus dem Netz laden, wenn nicht zu 100% fest steht, dass es sich dabei um saubere Software handelt. Nette Versprechen der Hersteller garantieren noch lange keine einwandfreie Funktionsweise, also vorher blättere die Seiten bei GOOGLE, da kannst Du Dir wertvolle Informationen holen!!!
  • Programme und Treiber:
    Nur vom Hersteller!
  • Onlinebanking:
    Gib deine Passwörter niemals preis!
    Seriöse Bankinstitute, E- Mail- Provider oder Online- Shops versenden grundsätzlich keine E- Mails, in denen Kunden aufgefordert werden, vertrauliche Daten wie Passwörter, Verfügernummer, PINs oder TANs preiszugeben. Bei dieser Art von E- Mails handelt es sich immer um Betrugsversuche, weshalb entsprechende Anfragen nicht beantwortet werden sollten. Sobald der Verdacht auf Betrug entsteht, melde deinen Verdacht der jeweiligen Bank- Hotline.
  • Comnputer, anderen (Gästen/Freunden) zur Nutzung überlassen überlassen - Nutze nur vertrauenswürdige Computer!
    Vergewissere dich, dass nur Personen deines Vertrauens deinen Computer nutzen oder verwalten und wickel niemals Bankgeschäfte über nicht vertrauenswürdige Computer - beispielsweise aus einem Internetcafé während des Urlaubs - ab
  • Vorsicht bei der Nutzung fremder Computer und anschliessbare Externe Speichermedien wie Festplatte, USB Sticks, Speicherkarten usw![/color] - IT-Betrüger machen keinen Urlaub!/bsi-fuer-buerger.de - auch zeitweise anschließen und scannen lassen (sehe unter `kostenlose Online-Viren-Scanner`)
  • Webseiten ohne Gültiges Impressum nicht besuchen
  • Lizenzkosten sparen? - Vorsicht bei Dateien/Programmen aus nicht vertrauenswürdigen Quellen! - "full Keygen, Crack, Serial, Warez, keygenerators" etc.
    Sind immer verseucht mit diverse Malware/Schadprogramme/Code, es gibt keine seite wo Viren frei ist. (Man sollte nicht absitlich der Teufel holen) Eine weitere höchst unsichere Quelle ist das File-Sharing der sog. (Musik-)Tauschbörsen.
    ► Ausserdem machst Du dich damit strafbar!
  • Nur eine Firewall sowie ein Antiviren Programm verwenden, welche sich immer auf dem aktuellsten Stand befinden sollten!
    Das Installieren von `zuviel` Software beeinträchtigt die Systemleistung und Sicherheit, verlangsamt den Start-Vorgang enorm und belastet den Arbeitsspeicher (weil laufen ja die Programme nebeneinander gleichzeitig, die viel Performance fressen, aber wenig Qualität bringen). Im Laufe der Zeit wird der rechner durch zu viel unnötigen Ballast immer langsamer, und unsicherer. Um so mehr Programme installiert sind, um so häufiger treten Probleme auf, die dann unter Umständen nur schwer lösen können. Dazu kommt noch, das einige Programme große Sicherheitsrisiken mit sich bringen
  • Virenscanner
  • BSI für Bürger
  • SETI@home - [Sicherheit] Sicherheitskonzept
  • Entwicklung schädlicher Websites/viruslist.com
  • Brennpunkt: Bilder und Töne
    Gefährliche Bilder, schräge Töne/BSI

** Der gesunde Menschenverstand, Windows und Internet-Software sicher konfigurieren ist der beste Weg zur Sicherheit im Webverkehr ist !!
Zitat:
Da der Bestand der Datenbank wird täglich ergänzt und erweitert bzw werden mit der aktuellen Virendefinition die Informationen über den betroffenen Virus aufgenommen, empfehle ich dir mindestens einmal pro Woche (später genügt es sicherlich einmal im Monat) dein System Online Scannen lassen (immer mit einen anderen Scanner), um eine zweite Meinung einzuholen - Die auf dem Speichermedium gesicherten Daten sollten auch mit einbezogen werden!
(benutzen meist ActiveX und/oder Java): Kostenlose Online Scanner -
Lesestoff Nr.2:
► Kann sich auf Dauer eine Menge Datenmüll ansammeln, sich Fehlermeldungen häufen, der PC ist wahrscheinlich nicht mehr so schnell, wie früher:wünsch Dir alles Gute

Wenn Du uns unterstützen möchtest→ Spendekonto

gruß
kira
__________________

Warnung!:
Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
Anhang nicht öffnen, in unserem Forum erst nachfragen!

Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
Bitte diese Warnung weitergeben, wo Du nur kannst!

Alt 18.01.2012, 15:37   #24
puma165
 
Windowssystem gesperrt - Virus - Standard

Windowssystem gesperrt - Virus



ok vieeeeelen vieeeelen Dank für alles!
werde mir das alles nochmal in Ruhe durchlesen und habe die letzten Schritte noch gemacht. Es sind keine Probleme mehr aufgetreten und das wird jetzt hoffentlich auch so bleiben!

Viiieeeelllleeeennn Daaaannnkkk!

Antwort

Themen zu Windowssystem gesperrt - Virus
32bit, abend, abgesicherte, abgesicherten, abgesicherten modus, bezahlung, euro, freischalten, freue, gesperrt, gmer, konnte, könntet, laptop, loszuwerden, mehrfach, meldung, modus, neustart, nichts, scan, schonmal, sicherheitsgründen, virus, windowssystem gesperrt, windowssystem gesperrt virus bezahlen entfernen, würde




Ähnliche Themen: Windowssystem gesperrt - Virus


  1. Windowssystem gesperrt, Malwarebytes ausgeführt
    Log-Analyse und Auswertung - 25.03.2012 (28)
  2. Windowssystem gesperrt - Zahlungsaufforderung!
    Log-Analyse und Auswertung - 23.03.2012 (15)
  3. Windowssystem gesperrt 50 Euro Zahlung
    Log-Analyse und Auswertung - 23.03.2012 (17)
  4. Ihr Windowssystem wurde gesperrt
    Log-Analyse und Auswertung - 18.03.2012 (1)
  5. Windowssystem gesperrt! Aus Sicherheitsgründen ...
    Plagegeister aller Art und deren Bekämpfung - 17.03.2012 (11)
  6. Aus Sicherheitsgründen Windowssystem gesperrt
    Plagegeister aller Art und deren Bekämpfung - 14.02.2012 (1)
  7. Windowssystem zum Schutz gesperrt
    Plagegeister aller Art und deren Bekämpfung - 08.02.2012 (19)
  8. Aus Sicherheitsgründen wurde ihr Windowssystem gesperrt - 50 € Virus
    Log-Analyse und Auswertung - 11.01.2012 (9)
  9. Windowssystem gesperrt (wie bei And946)
    Log-Analyse und Auswertung - 11.01.2012 (16)
  10. Aus Sicherheitsgründen wurde ihr Windowssystem gesperrt und Zahlungsaufforderung
    Plagegeister aller Art und deren Bekämpfung - 06.01.2012 (7)
  11. Windowssystem gesperrt - 50 Euro zahlen
    Plagegeister aller Art und deren Bekämpfung - 05.01.2012 (23)
  12. Aus Sicherheitsgründen wurde ihr Windowssystem gesperrt
    Plagegeister aller Art und deren Bekämpfung - 30.12.2011 (21)
  13. Windowssystem wurde gesperrt!
    Log-Analyse und Auswertung - 30.12.2011 (32)
  14. Windowssystem gesperrt
    Log-Analyse und Auswertung - 29.12.2011 (9)
  15. Aus Sicherheitsgründen wird ihr Windowssystem gesperrt
    Log-Analyse und Auswertung - 19.12.2011 (1)
  16. windowssystem gesperrt
    Log-Analyse und Auswertung - 16.12.2011 (10)
  17. Windowssystem gesperrt 50euro gefordert
    Log-Analyse und Auswertung - 06.12.2011 (3)

Zum Thema Windowssystem gesperrt - Virus - zu Punkt 7. : unter Systemsteuerung existiert "eMule" nicht mehr..wir machen das schon alle andere Schritte bitte erledigen, dann sehen wir weiter - Windowssystem gesperrt - Virus...
Archiv
Du betrachtest: Windowssystem gesperrt - Virus auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.