| ![]() PWS-Spyeye!conf bei jedem Neustart Hallo Trojanerboard, mein Virenschutzprogramm (McAfee von Web.de) meldet kurz nach jedem Neustart des Computers (Windows 7), dass ein Trojaner entfernt wurde. Es handelt sich um PWS-Spyeye!conf. McAfee gibt an, man müsse den MBR reparieren. Ich habe dies versucht mit Hilfe der Recovery DVD, "Computer reparieren" und dann in die Konsole bootrec /fixmbr eingegeben. Das Problem besteht aber weiter. Ich habe die logfiles von OTL.EXE attached. Allerdings wurde immer nur OTL.TXT erstellt, wenn ich die vom Board definierten Befehle kopiert habe. Das EXTRA.TXT kommt daher aus einem früheren OTL Lauf ohne die benutzerdefinierte Befehle. GMER ist 2x abgestürzt bevor ein logfile geschrieben wurde. Gibt es eine Möglichkeit dieses Problem zu reparieren? Schon mal vielen Dank für Eure Hilfe! Gruß TURM2012 |
Hallo und Herzlich Willkommen!
Zitat:
Für Vista und Win7: Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen! 1. Lade Dir Malwarebytes Anti-Malware von→ malwarebytes.org
2. TDSSKiller von Kaspersky
3. erneut einen Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
4. Um festzustellen, ob veraltete oder schädliche Software unter Programme installiert sind, ich würde gerne noch all deine installierten Programme sehen: Lade dir das Tool CCleaner herunter → Download installieren (Software-Lizenzvereinbarung lesen, falls angeboten wird "Füge CCleaner Yahoo! Toolbar hinzu" abwählen)→ starten→ Sprache → Deutsch auswählen dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..." wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein Zitat:
** Möglichst nicht ins internet gehen, kein Online-Banking, File-sharing, Chatprogramme usw grußkira
Hallo kira,
__________________ich habe die verschiedenen Scans durchgeführt. Hier kommen die logfiles: 1. Malwarebytes Code:
Malwarebytes Anti-Malware (Test) www.malwarebytes.org

Datenbank Version: v2012.01.27.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Admin :: MEDION [Administrator]

Schutz: Aktiviert

27.01.2012 20:47:53
mbam-log-2012-01-27 (20-47-53).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 897155
Laufzeit: 13 Stunde(n), 29 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{B5BABB46-811A-F7EA-2FCC-DEE4E54A850E} (Trojan.ZbotR.Gen) -> Daten: C:\Users\Admin\AppData\Roaming\Icace\yzda.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|aighfrshdgf.exe (Trojan.SpyEyes) -> Daten: C:\aighfrshdgf\aighfrshdgf.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\aighfrshdgf (Trojan.SpyEyes) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
2. TDSS
3.OTL.EXE
Error - 16.05.2011 15:14:35 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 21:14:23 - Fehler beim Herstellen der Internetverbindung. 21:14:23 - Serververbindung konnte nicht hergestellt werden..

[ System Events ]
Error - 27.01.2012 15:34:47 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description =
Error - 27.01.2012 15:34:47 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description =
Error - 27.01.2012 15:34:48 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description =
Error - 27.01.2012 15:34:48 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description =
Error - 27.01.2012 19:24:14 | Computer Name = Medion | Source = iaStor | ID = 262153 Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error - 28.01.2012 13:57:43 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description = Error - 28.01.2012 13:57:43 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description = Error - 28.01.2012 13:57:43 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description = Error - 28.01.2012 13:57:43 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description = Error - 28.01.2012 15:32:32 | Computer Name = Medion | Source = iaStor | ID = 262153 Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. < End of report > |
| ![]() PWS-Spyeye!conf bei jedem Neustart 4. install Code:
ATTFilter 7-Zip 9.21beta 11.05.2011 ACD/Labs Software in C:\Program Files\ACDFREE12\ ACD/Labs 05.02.2010 v12.00, FREE Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 16.10.2011 6,00MB Adobe Flash Player 11 Plugin Adobe Systems Incorporated 19.11.2011 6,00MB Adobe Reader X (10.1.2) - Deutsch Adobe Systems Incorporated 10.01.2012 167,5MB 10.1.2 Adobe Shockwave Player 11 Adobe Systems, Inc. 06.11.2009 11 Aldi Foto Service 4.6 ORWO Net 26.11.2010 4.6 Aldi Nord Fotoservice 2.7 26.11.2010 ALDI Nord Online Druck Service 4.6 ORWO Net 26.11.2010 4.6 Apple Application Support Apple Inc. 07.01.2012 61,1MB 2.1.6 Apple Mobile Device Support Apple Inc. 07.01.2012 24,1MB Apple Software Update Apple Inc. 01.07.2011 2,25MB Audiograbber 1.83 SE Audiograbber Deutschland 03.01.2010 1.83 SE Bonjour Apple Inc. 22.10.2011 0,91MB CCleaner Piriform 27.01.2012 3.15 Chess Tutor Step 1 Cor van Wijgerden 22.12.2010 Chess Tutor Step 2 Demo Cor van Wijgerden 12.07.2010 Cinergy T Stick MKII V9.06.3.01 19.02.2010 Compatibility Pack for the 2007 Office system Microsoft Corporation 12.12.2011 92,9MB 12.0.6514.5001 Corel Home Office 5.0.56 Corel Corporation 06.11.2009 Corel Painter Essentials 4 Corel Corporation 06.11.2009 CorelDRAW Essentials 4 Corel Corporation 06.11.2009 CorelDRAW Essentials 4 - Windows Shell Extension Corel Corporation 06.11.2009 2,93MB CyberLink MediaShow CyberLink Corp. 09.06.2009 315MB 4.1.2325 CyberLink PhotoNow CyberLink Corp. 09.06.2009 21,8MB 1.1.5615 CyberLink PowerDirector CyberLink Corp. 09.06.2009 422MB 7.0.2625 CyberLink PowerDVD 8 CyberLink Corp. 09.06.2009 99,1MB 8.0.2606a CyberLink PowerProducer CyberLink Corp. 09.06.2009 311MB CyberLink YouCam CyberLink Corp. 09.06.2009 73,6MB 2.0.2521 Dropbox Dropbox, Inc. 29.12.2011 1.2.49 e-Wörterbücher 06.11.2009 Finger-sensing Pad Driver FSP 06.11.2009 Foxlink Webcam Sonix 09.06.2009 5.8.51000.202_WHQL FreePDF (Remove only) 11.05.2011 Fritz 5.32 10.07.2010 G DATA Logox4 Speechengine G DATA Software AG 16.03.2010 Google Earth Google 10.07.2011 85,3MB Google Updater Google Inc. 06.11.2009 2.4.1487.6512 GPL Ghostscript 9.00 11.05.2011 Intel® Matrix Storage Manager Intel Corporation 06.11.2009 iTunes Apple Inc. 07.01.2012 169,6MB Java(TM) 6 Update 29 Sun Microsystems, Inc. 09.06.2009 97,0MB 6.0.290 Lernwerkstatt 7 Medienwerkstatt Mühlacker Verlagsgesellschaft mbH 16.03.2010 764MB 7.00.0000 Malwarebytes Anti-Malware Version Malwarebytes Corporation 26.01.2012 18,6MB McAfee Internet Security Suite McAfee, Inc. 28.12.2011 11.0.649 McAfee Security Scan Plus McAfee, Inc. 08.03.2011 8,30MB Microsoft .NET Framework 4 Client Profile Microsoft Corporation 26.06.2010 38,8MB 4.0.30319 Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 26.06.2010 2,94MB 4.0.30319 Microsoft Office File Validation Add-In Microsoft Corporation 16.09.2011 7,94MB 14.0.5130.5003 Microsoft Office PowerPoint Viewer 2007 (German) Microsoft Corporation 12.12.2011 158,0MB 12.0.6425.1000 Microsoft Office Professional Plus 2010 Microsoft Corporation 28.11.2011 14.0.6029.1000 Microsoft Silverlight Microsoft Corporation 16.10.2011 209MB 4.0.60831.0 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 09.06.2009 1,74MB 3.1.0000 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 10.09.2009 0,25MB 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 17.06.2011 0,29MB 8.0.61001 Microsoft Works Microsoft Corporation 17.12.2010 878MB 9.7.0621 Mozilla Firefox 9.0.1 (x86 de) Mozilla 23.12.2011 42,6MB 9.0.1 MSXML 4.0 SP2 (KB927978) Microsoft Corporation 09.06.2009 34,00KB 4.20.9841.0 MSXML 4.0 SP2 (KB954430) Microsoft Corporation 09.06.2009 1,28MB 4.20.9870.0 MSXML 4.0 SP2 (KB973688) Microsoft Corporation 27.11.2009 1,33MB 4.20.9876.0 Nero 8 Essentials Nero AG 09.06.2009 1.938MB 8.3.124 NVIDIA Drivers NVIDIA Corporation 06.11.2009 1.3 PC Connectivity Solution Nokia 03.07.2010 9,22MB ProtectDisc Driver, Version 11 ProtectDisc Software GmbH 16.03.2010 QuickTime Apple Inc. 29.10.2011 73,3MB Radio.fx Tobit.Software 26.02.2010 Realtek 8136 8168 8169 Ethernet Driver Realtek 17.06.2009 1.00.0005 Realtek High Definition Audio Driver Realtek Semiconductor Corp. 06.11.2009 Realtek USB 2.0 Card Reader Realtek Semiconductor Corp. 09.06.2009 6.0.6000.20111 REALTEK Wireless LAN Driver REALTEK Semiconductor Corp. 09.06.2009 1.01.0092 RedMon - Redirection Port Monitor 11.05.2011 SAMSUNG Mobile Composite Device Software 03.07.2010 Samsung Mobile Modem Device Software 03.07.2010 SAMSUNG Mobile Modem Driver Set 03.07.2010 SAMSUNG Mobile Modem V2 Software 03.07.2010 Samsung Mobile phone USB driver Drive Software 03.07.2010 SAMSUNG Mobile USB Modem 1.0 Software 03.07.2010 SAMSUNG Mobile USB Modem Software 03.07.2010 Samsung New PC Studio Samsung Electronics Co., Ltd. 03.07.2010 223MB 1.00.0000 SAMSUNG USB Mobile Device Software 03.07.2010 SamsungConnectivityCableDriver Samsung 03.07.2010 0,62MB ScanSpyware ScanSpyware.Net 14.01.2012 7,22MB Security Task Manager 1.8d Neuber Software 22.01.2012 1.8d Skype Click to Call Skype Technologies S.A. 20.10.2011 12,6MB 5.6.8442 Skype™ 5.5 Skype Technologies S.A. 20.10.2011 17,0MB 5.5.124 STANLY Track DFS Deutsche Flugsicherung GmbH 10.01.2012 Synaptics Pointing Device Driver Synaptics Incorporated 03.07.2011 TerraTec Home Cinema 19.02.2010 6.11.5 Windows Live Anmelde-Assistent Microsoft Corporation 09.06.2009 1,93MB 5.000.818.6 Windows Live Essentials Microsoft Corporation 07.04.2011 14.0.8117.0416 Windows Live Sync Microsoft Corporation 07.04.2011 2,79MB 14.0.8117.416 Windows Live-Uploadtool Microsoft Corporation 09.06.2009 0,22MB 14.0.8014.1029 Windows Mobile-Gerätecenter Microsoft Corporation 10.08.2010 27,5MB 6.1.6965.0 Windows-Treiberpaket - MobileTop (sshpmdm) Modem (01/26/2008 MobileTop 03.07.2010 01/26/2008 Windows-Treiberpaket - Nokia pccsmcfd (10/12/2007 Nokia 03.07.2010 10/12/2007 WISO Konto Online 2010 Buhl Data Service GmbH 28.08.2010 Schon mal vielen Dank!!! /// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() PWS-Spyeye!conf bei jedem Neustart 1. Absichtlich installiert?: Zitat:
deinstalliere: Verwende stabiler und sichere Programme als solche,die potentielle Risiken mit sich bringen! Zitat:
ATTFilter :OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://web.de/ FF - prefs.js..browser.startup.homepage: "http://web.de/" FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) [2011.12.24 11:57:47 | 000,000,933 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\11-suche.xml [2011.12.24 11:57:47 | 000,002,419 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\englische-ergebnisse.xml [2011.12.24 11:57:47 | 000,010,525 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\gmx-suche.xml [2011.12.24 11:57:47 | 000,002,457 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\lastminute.xml [2011.12.24 11:57:47 | 000,005,508 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\webde-suche.xml [2011.10.17 16:49:04 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.10.17 16:49:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml [2012.01.28 19:45:11 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.01.28 19:42:10 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2012.01.28 18:55:51 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job :Commands [purity] [emptytemp]
4. reinige dein System mit CCleaner:
6. Auch auf USB-Sticks, selbstgebrannten Datenträgern, externen Festplatten und anderen Datenträgern können Viren transportiert werden. Man muss daher durch regelmäßige Prüfungen auf Schäden, die durch Malware ("Worm.Win32.Autorun") verursacht worden sein können, überwacht werden. Hierfür sind ser gut geegnet und empfohlen, die auf dem Speichermedium gesicherten Daten, mit Hilfe des kostenlosen Online Scanners zu prüfen. Schließe jetzt alle externe Datenträgeran (USB Sticks etc) Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.►Anleitung 7. -> Führe dann einen Komplett-Systemcheck mit Eset Online Scanner (NOD32)Kostenlose Online Scanner durch Achtung!: >>Du sollst nicht die Antivirus-Sicherheitssoftware installieren, sondern dein System nur online scannen<< 8. erneut einen Scan mit OTL:
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
| ![]() PWS-Spyeye!conf bei jedem Neustart Hallo kira, seit ich Malwarebytes und tdss laufen gelassen habe, meldet das McAfee Virenschutzprogramm nach dem Neustart keine Trojaner mehr. Zu Deinem letzten Post: *1* ---Zitat--- Absichtlich installiert?: FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\backup\thunderbirdbkplugin ---Zitatende--- Bullguard war beim Kauf als Testversion installiert, habe das Programm später deinstalliert, diese Programmteile sind wohl übriggebliegen und können gelöscht werden. *2* Scanspyware ist deinstalliert *3* OTL.EXE logfile Code:
ATTFilter All processes killed Error: Unable to interpret <Code:> in the current context! Error: Unable to interpret <---------> in the current context! ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Prefs.js: "hxxp://web.de/" removed from browser.startup.homepage Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully. C:\Program Files\Google\Update\\npGoogleUpdate3.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully. File C:\Program Files\Google\Update\\npGoogleUpdate3.dll not found. C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\11-suche.xml moved successfully. C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\englische-ergebnisse.xml moved successfully. C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\gmx-suche.xml moved successfully. C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\lastminute.xml moved successfully. C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\webde-suche.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\bing.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\Google Software Updater.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Admin ->Temp folder emptied: 233216516 bytes ->Temporary Internet Files folder emptied: 280933079 bytes ->Java cache emptied: 16436337 bytes ->FireFox cache emptied: 186839367 bytes ->Apple Safari cache emptied: 12972032 bytes ->Flash cache emptied: 3729 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Moritz ->Temp folder emptied: 31981948 bytes ->Temporary Internet Files folder emptied: 203539187 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 560029785 bytes ->Apple Safari cache emptied: 14336 bytes ->Flash cache emptied: 67475 bytes User: Public User: Theresa ->Temp folder emptied: 3956566 bytes ->Temporary Internet Files folder emptied: 3047627 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 47533774 bytes ->Flash cache emptied: 1413 bytes User: Ulrike&Ralf User: Ulrike_Ralf %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 11111374357 bytes RecycleBin emptied: 394028 bytes Total Files Cleaned = 12.104,00 mb OTL by OldTimer - Version log created on 01302012_213206 Files\Folders moved on Reboot... C:\Windows\temp\gis1479a\2.4.1487.6512\de\cires.dll.mui moved successfully. C:\Windows\temp\gis1479a\2.4.1487.6512\ci.dll moved successfully. C:\Windows\temp\gis1479a\2.4.1487.6512\cires.dll moved successfully. C:\Windows\temp\gis1479a\GoogleUpdater.exe moved successfully. C:\Windows\temp\sqlite_fqs2247beIawz9D moved successfully. C:\Windows\temp\sqlite_hJhaqbXbQOhZYE5 moved successfully. C:\Windows\temp\sqlite_tbZ1bCjXlvmUdhF moved successfully. Registry entries deleted on Reboot... Gruß TURM2012 |
| ![]() PWS-Spyeye!conf bei jedem Neustart Hallo kira, hier noch das log-file von superantispyware: Code:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 01/31/2012 at 11:58 PM Application Version : 5.0.1142 Core Rules Database Version : 8185 Trace Rules Database Version: 5997 Scan type : Complete Scan Total Scan Time : 02:36:34 Operating System Information Windows 7 Home Premium 32-bit, Service Pack 1 (Build 6.01.7601) UAC On - Limited User Memory items scanned : 765 Memory threats detected : 0 Registry items scanned : 26442 Registry threats detected : 0 File items scanned : 49852 File threats detected : 54 Adware.Tracking Cookie C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@track.adform[2].txt [ Cookie:moritz@track.adform.net/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@zanox[1].txt [ Cookie:moritz@zanox.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@fastclick[2].txt [ Cookie:moritz@fastclick.net/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@im.banner.t-online[2].txt [ Cookie:moritz@im.banner.t-online.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@casalemedia[2].txt [ Cookie:moritz@casalemedia.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@banners.181[1].txt [ Cookie:moritz@banners.181.fm/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@xiti[1].txt [ Cookie:moritz@xiti.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@postadserver.anschlusstor[1].txt [ Cookie:moritz@postadserver.anschlusstor.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\X00OFCMN.txt [ Cookie:moritz@doubleclick.net/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@ad2.adfarm1.adition[1].txt [ Cookie:moritz@ad2.adfarm1.adition.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@ads.pointroll[1].txt [ Cookie:moritz@ads.pointroll.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\moritz@traffictrack[1].txt [ Cookie:moritz@traffictrack.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@content.yieldmanager[2].txt [ Cookie:moritz@content.yieldmanager.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@secmedia[2].txt [ Cookie:moritz@secmedia.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@tracking.mindshare[1].txt [ Cookie:moritz@tracking.mindshare.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@tracking.quisma[2].txt [ Cookie:moritz@tracking.quisma.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@unitymedia[2].txt [ Cookie:moritz@unitymedia.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@zanox[2].txt [ Cookie:moritz@zanox.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@www.zanox-affiliate[2].txt [ Cookie:moritz@www.zanox-affiliate.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@beacons.hottraffic[1].txt [ Cookie:moritz@beacons.hottraffic.nl/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@ad1.adfarm1.adition[2].txt [ Cookie:moritz@ad1.adfarm1.adition.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@ad3.adfarm1.adition[2].txt [ Cookie:moritz@ad3.adfarm1.adition.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@track.effiliation[1].txt [ Cookie:moritz@track.effiliation.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@ad4.adfarm1.adition[2].txt [ Cookie:moritz@ad4.adfarm1.adition.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@atdmt[1].txt [ Cookie:moritz@atdmt.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@xiti[1].txt [ Cookie:moritz@xiti.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@www.etracker[1].txt [ Cookie:moritz@www.etracker.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\HZ7RX5D0.txt [ Cookie:moritz@doubleclick.net/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@ad2.adfarm1.adition[1].txt [ Cookie:moritz@ad2.adfarm1.adition.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@ad.yieldmanager[2].txt [ Cookie:moritz@ad.yieldmanager.com/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@ad.dyntracker[1].txt [ Cookie:moritz@ad.dyntracker.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@content.yieldmanager[1].txt [ Cookie:moritz@content.yieldmanager.com/ak/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\XN563O9J.txt [ Cookie:moritz@superrtl.122.2o7.net/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@traffictrack[1].txt [ Cookie:moritz@traffictrack.de/ ] C:\USERS\MORITZ\AppData\Roaming\Microsoft\Windows\Cookies\Low\moritz@smartadserver[1].txt [ Cookie:moritz@smartadserver.com/ ] C:\USERS\MORITZ\Cookies\moritz@track.adform[2].txt [ Cookie:moritz@track.adform.net/ ] C:\USERS\MORITZ\Cookies\moritz@zanox[1].txt [ Cookie:moritz@zanox.com/ ] C:\USERS\MORITZ\Cookies\moritz@fastclick[2].txt [ Cookie:moritz@fastclick.net/ ] C:\USERS\MORITZ\Cookies\moritz@im.banner.t-online[2].txt [ Cookie:moritz@im.banner.t-online.de/ ] C:\USERS\MORITZ\Cookies\moritz@casalemedia[2].txt [ Cookie:moritz@casalemedia.com/ ] C:\USERS\MORITZ\Cookies\moritz@banners.181[1].txt [ Cookie:moritz@banners.181.fm/ ] C:\USERS\MORITZ\Cookies\moritz@xiti[1].txt [ Cookie:moritz@xiti.com/ ] C:\USERS\MORITZ\Cookies\moritz@postadserver.anschlusstor[1].txt [ Cookie:moritz@postadserver.anschlusstor.de/ ] C:\USERS\MORITZ\Cookies\X00OFCMN.txt [ Cookie:moritz@doubleclick.net/ ] C:\USERS\MORITZ\Cookies\moritz@ad2.adfarm1.adition[1].txt [ Cookie:moritz@ad2.adfarm1.adition.com/ ] C:\USERS\MORITZ\Cookies\moritz@ads.pointroll[1].txt [ Cookie:moritz@ads.pointroll.com/ ] C:\USERS\MORITZ\Cookies\moritz@traffictrack[1].txt [ Cookie:moritz@traffictrack.de/ ] C:\USERS\THERESA\AppData\Roaming\Microsoft\Windows\Cookies\Low\PKUEDJ7Z.txt [ Cookie:theresa@fl01.ct2.comclick.com/ ] C:\USERS\THERESA\AppData\Roaming\Microsoft\Windows\Cookies\Low\BXI53NBW.txt [ Cookie:theresa@apmebf.com/ ] C:\USERS\THERESA\AppData\Roaming\Microsoft\Windows\Cookies\Low\N0QBQEK2.txt [ Cookie:theresa@atdmt.com/ ] C:\USERS\THERESA\AppData\Roaming\Microsoft\Windows\Cookies\Low\0MN4NTUU.txt [ Cookie:theresa@ad.yieldmanager.com/ ] C:\USERS\THERESA\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q91C362P.txt [ Cookie:theresa@adfarm1.adition.com/ ] C:\USERS\THERESA\AppData\Roaming\Microsoft\Windows\Cookies\Low\T91HIYE8.txt [ Cookie:theresa@2o7.net/ ] C:\USERS\MORITZ\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\MORITZ@STATCOUNTER[1].TXT [ /STATCOUNTER ] |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() PWS-Spyeye!conf bei jedem Neustart Punkte 6., 7., und 8., fehlen noch... ► berichte auch erneut über den Zustand des Computers. Ob noch Probleme auftreten, wenn ja, welche?
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
| ![]() PWS-Spyeye!conf bei jedem Neustart Hallo kira, die Trojanermeldungen sind nicht mehr aufgetaucht.ö zu 6, 7, 8: ESET online scan habe ich durchgeführt und hier noch die OTL log-files: OTL Logfile: Code:
ATTFilter OTL logfile created on: 01.02.2012 22:13:58 - Run 7 OTL by OldTimer - Version Folder = C:\Users\Admin\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,77 Gb Available Physical Memory | 58,97% Memory free 5,99 Gb Paging File | 4,24 Gb Available in Paging File | 70,79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 268,79 Gb Total Space | 133,71 Gb Free Space | 49,75% Space Free | Partition Type: NTFS Drive D: | 29,28 Gb Total Space | 14,43 Gb Free Space | 49,29% Space Free | Partition Type: FAT32 Drive F: | 963,70 Mb Total Space | 529,73 Mb Free Space | 54,97% Space Free | Partition Type: FAT Computer Name: MEDION | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Tobit Radio.fx\Server\rfx-server.exe () PRC - C:\Users\Admin\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software) PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Programme\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.) PRC - C:\Programme\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.) PRC - C:\Programme\FreePDF_XP\fpassist.exe (shbox.de) PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten) PRC - C:\Windows\Temp\gis2a775\GoogleUpdater.exe (Google) PRC - C:\Windows\System32\Rezip.exe () PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) PRC - C:\Programme\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe () PRC - C:\Windows\tsnp2uvc.exe () PRC - C:\Programme\McAfee\SiteAdvisor\McSACore.exe () PRC - C:\Programme\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) PRC - C:\Windows\System32\PSIService.exe () ========== Modules (No Company Name) ========== MOD - C:\Programme\Mozilla Firefox\mozjs.dll () MOD - C:\Programme\Tobit Radio.fx\Client\tobitclt.dll () MOD - C:\Programme\Tobit Radio.fx\Client\rfx-client$.ger () MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll () MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Windows\tsnp2uvc.exe () MOD - C:\Programme\McAfee\SiteAdvisor\sahook.dll () MOD - C:\Programme\Common Files\microsoft shared\Web Folders\1031\NSEXTINT.DLL () ========== Win32 Services (SafeList) ========== SRV - (Radio.fx) -- C:\Programme\Tobit Radio.fx\Server\rfx-server.exe () SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SRV - (mfevtp) -- C:\Programme\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe () SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe () SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com) SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation) SRV - (MSK80Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (Rezip) -- C:\Windows\System32\Rezip.exe () SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) SRV - (resetWinService) -- C:\Program Files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe () SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe () SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.) SRV - (PSI_SVC_2) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) SRV - (ProtexisLicensing) -- C:\Windows\System32\PSIService.exe () SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation) DRV - (mfehidk) -- C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.) DRV - (mfefirek) -- C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.) DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.) DRV - (mfewfpk) -- C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.) DRV - (mfeapfk) -- C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.) DRV - (mferkdet) -- C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.) DRV - (mfenlfk) -- C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.) DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.) DRV - (cfwids) -- C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.) DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (WINUSB) -- C:\Windows\system32\drivers\WinUSB.SYS (Microsoft Corporation) DRV - (rtl8192se) -- C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation ) DRV - (AF15BDA) -- C:\Windows\System32\drivers\AF15BDA.sys (ITETech ) DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys () DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek ) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation) DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI) DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation) DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH) DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\System32\drivers\snp2uvc.sys () DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia) DRV - (sscdmdm) -- C:\Windows\System32\drivers\sscdmdm.sys (MCCI Corporation) DRV - (sscdmdfl) -- C:\Windows\System32\drivers\sscdmdfl.sys (MCCI Corporation) DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\sscdbus.sys (MCCI Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.8 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll () FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll (Google) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010.03.03 18:32:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012.02.01 15:38:26 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.01 15:40:00 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.11 19:42:31 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\backup\thunderbirdbkplugin [2009.11.07 22:03:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions [2012.01.31 21:11:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\3wgcqp2z.default\extensions [2010.05.01 20:44:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\3wgcqp2z.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012.01.31 21:11:49 | 000,000,933 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\11-suche.xml [2012.01.31 21:11:49 | 000,002,419 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\englische-ergebnisse.xml [2012.01.31 21:11:49 | 000,010,525 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\gmx-suche.xml [2012.01.31 21:11:49 | 000,002,457 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\lastminute.xml [2012.01.31 21:11:48 | 000,005,508 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\3wgcqp2z.default\searchplugins\webde-suche.xml [2011.12.24 11:33:06 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2011.10.21 18:52:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2012.02.01 15:38:26 | 000,000,000 | ---D | M] (McAfee ScriptScan for Firefox) -- C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE () (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3WGCQP2Z.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI () (No name found) -- C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3WGCQP2Z.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI [2012.02.01 15:39:56 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.04.14 13:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll [2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011.10.17 16:49:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.10.17 16:49:04 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.10.17 16:49:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.17 16:49:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml O1 HOSTS File: ([2012.01.17 22:35:23 | 000,419,771 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O1 - Hosts: www.36site.com O1 - Hosts: 36site.com O1 - Hosts: 3721.com O1 - Hosts: 39-93.com O1 - Hosts: www.3bay.it O1 - Hosts: 3bay.it O1 - Hosts: www.3mates.com O1 - Hosts: 3mates.com O1 - Hosts: 3o7dbisqfd4.nedqunefr.com O1 - Hosts: 3xclipsonline.com O1 - Hosts: www.3xclipsonline.com O1 - Hosts: 3xcurves.com O1 - Hosts: www.3xcurves.com O1 - Hosts: 3xfestival.com O1 - Hosts: www.3xfestival.com O1 - Hosts: 3x-festival.com O1 - Hosts: www.3x-festival.com O1 - Hosts: www.3x-galls.com O1 - Hosts: 3x-galls.com O1 - Hosts: www.3xmiracle.com O1 - Hosts: 3xmiracle.com O1 - Hosts: www.3xmoviesblog.com O1 - Hosts: 3xmoviesblog.com O1 - Hosts: 14408 more lines... O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\McAfee\SystemCore\ScriptSn.20111226124254.dll (McAfee, Inc.) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.) O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll () O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll () O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Programme\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKLM..\Run: [MDS_Menu] C:\Program Files\HomeCinema\MediaShow4\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\HomeCinema\PowerDVD8\Language\Language.exe () O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe () O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKCU..\Run: [rfxsrvtray] C:\Program Files\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software) O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 File not found O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 File not found O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6EF1B4EB-1134-4AB9-8FBB-CEE5E3C3499A}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8B7CBA12-E6ED-4B51-BDE1-9F32F3DDD5A8}: DhcpNameServer = O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll () O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Programme\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O24 - Desktop WallPaper: O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2008.08.21 11:50:32 | 000,000,672 | RH-- | M] () - D:\autoexec.bat -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012.02.01 20:02:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee [2012.02.01 15:57:04 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.01.31 21:16:11 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\SUPERAntiSpyware.com [2012.01.31 21:15:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware [2012.01.31 21:15:21 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com [2012.01.31 21:15:21 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2012.01.31 21:14:24 | 014,332,544 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Admin\Desktop\SUPERAntiSpyware.exe [2012.01.31 19:23:24 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll [2012.01.31 19:23:21 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll [2012.01.30 21:32:06 | 000,000,000 | ---D | C] -- C:\_OTL [2012.01.28 20:49:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2012.01.28 20:49:18 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012.01.28 20:48:09 | 003,587,688 | ---- | C] (Piriform Ltd) -- C:\Users\Admin\Desktop\ccsetup315.exe [2012.01.27 20:44:23 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes [2012.01.27 20:44:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.01.27 20:44:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.01.27 20:43:58 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.01.27 20:43:58 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.01.24 16:44:58 | 002,058,032 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe [2012.01.23 20:14:21 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan [2012.01.23 20:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager [2012.01.23 20:13:55 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager [2012.01.21 21:04:56 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe [2012.01.15 21:27:47 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\ScanSpyware [2012.01.11 20:00:58 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll [2012.01.11 20:00:51 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll [2012.01.11 20:00:46 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll [2012.01.08 20:57:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012.01.08 20:56:39 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012.01.08 20:56:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2009.06.10 14:00:53 | 000,225,280 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll [2009.06.10 14:00:52 | 000,176,128 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll ========== Files - Modified Within 30 Days ========== [2012.02.01 21:43:10 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2012.02.01 18:57:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.02.01 15:42:45 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.02.01 15:42:45 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.02.01 15:42:45 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.02.01 15:42:45 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.02.01 15:42:31 | 000,010,880 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.02.01 15:42:31 | 000,010,880 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.02.01 15:34:42 | 2411,888,640 | -HS- | M] () -- C:\hiberfil.sys [2012.01.31 21:15:25 | 000,001,965 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2012.01.31 19:18:52 | 000,001,832 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk [2012.01.30 23:00:54 | 000,184,152 | ---- | M] () -- C:\Users\Admin\Documents\cc_20120130_230005.reg [2012.01.30 22:57:06 | 014,332,544 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Admin\Desktop\SUPERAntiSpyware.exe [2012.01.28 20:49:18 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012.01.28 20:46:00 | 003,587,688 | ---- | M] (Piriform Ltd) -- C:\Users\Admin\Desktop\ccsetup315.exe [2012.01.27 20:44:08 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.01.24 16:44:58 | 002,058,032 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Admin\Desktop\TDSSKiller.exe [2012.01.22 12:31:43 | 000,302,592 | ---- | M] () -- C:\Users\Admin\Desktop\094yu5ee.exe [2012.01.22 10:02:05 | 000,000,000 | ---- | M] () -- C:\Users\Admin\defogger_reenable [2012.01.22 09:58:47 | 000,050,477 | ---- | M] () -- C:\Users\Admin\Desktop\Defogger.exe [2012.01.21 21:03:24 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe [2012.01.19 12:15:52 | 003,537,752 | ---- | M] (Tobit.Software) -- C:\Windows\RXSUnins.exe [2012.01.19 12:15:52 | 003,537,752 | ---- | M] (Tobit.Software) -- C:\Windows\RXCUnins.exe [2012.01.17 22:35:23 | 000,419,771 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts [2012.01.16 10:29:31 | 001,370,274 | ---- | M] () -- C:\Users\Admin\Desktop\Unbenannt.bmp [2012.01.08 20:57:38 | 000,001,757 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk ========== Files Created - No Company Name ========== [2012.01.31 21:15:25 | 000,001,965 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk [2012.01.30 23:00:28 | 000,184,152 | ---- | C] () -- C:\Users\Admin\Documents\cc_20120130_230005.reg [2012.01.30 22:06:00 | 000,000,868 | ---- | C] () -- C:\Windows\tasks\Google Software Updater.job [2012.01.28 20:49:18 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012.01.27 20:44:08 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.01.22 12:32:10 | 000,302,592 | ---- | C] () -- C:\Users\Admin\Desktop\094yu5ee.exe [2012.01.22 10:02:05 | 000,000,000 | ---- | C] () -- C:\Users\Admin\defogger_reenable [2012.01.22 09:59:44 | 000,050,477 | ---- | C] () -- C:\Users\Admin\Desktop\Defogger.exe [2012.01.16 10:29:29 | 001,370,274 | ---- | C] () -- C:\Users\Admin\Desktop\Unbenannt.bmp [2012.01.08 20:57:38 | 000,001,757 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2011.05.12 18:24:31 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe [2011.05.12 18:24:30 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll [2010.11.27 23:57:25 | 000,001,032 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\mdbu.bin [2010.07.04 16:15:58 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll [2010.07.04 16:15:58 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys [2010.02.07 18:13:44 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2010.01.11 21:24:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2009.11.18 22:40:49 | 000,000,952 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys [2009.11.14 21:18:56 | 000,554,496 | ---- | C] () -- C:\Windows\System32\dvmsg.dll [2009.11.08 16:44:15 | 000,000,780 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\wklnhst.dat [2009.11.07 22:08:03 | 000,021,532 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat [2009.07.14 09:47:43 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009.07.14 09:47:43 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 000,472,328 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,616,008 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.06.18 03:51:33 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009.06.10 15:18:19 | 000,036,864 | ---- | C] () -- C:\Windows\System32\Hooks.dll [2009.06.10 14:00:53 | 001,799,808 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys [2009.06.10 14:00:53 | 000,233,472 | ---- | C] () -- C:\Windows\tsnp2uvc.exe [2009.06.10 14:00:53 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini [2009.06.10 14:00:52 | 000,028,544 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys [2009.06.10 13:58:06 | 000,311,296 | ---- | C] () -- C:\Windows\System32\Rezip.exe [2009.06.10 13:38:31 | 000,000,276 | ---- | C] () -- C:\Windows\System32\drivers\SamSfPa.dat [2009.06.09 09:54:18 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2007.10.25 16:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2007.06.05 12:20:32 | 000,177,704 | ---- | C] () -- C:\Windows\System32\PSIService.exe [2002.01.03 01:09:18 | 000,000,356 | ---- | C] () -- C:\Windows\System32\AF15IrTbl.bin ========== LOP Check ========== [2011.11.26 10:15:28 | 000,000,000 | -HSD | M] -- C:\Users\Admin\AppData\Roaming\.# [2010.02.06 14:03:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Advanced Chemistry Development [2011.04.08 18:52:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Apethy [2010.08.14 16:56:54 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Buhl Data Service [2010.08.29 09:06:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Buhl Data Service GmbH [2010.12.23 15:28:16 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Chess Tutor [2010.12.05 13:19:54 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Cornelsen [2010.08.14 16:57:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DataDesign [2012.01.16 20:36:38 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Dropbox [2011.04.09 18:30:43 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Icace [2010.08.14 16:56:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\LetsTrade [2010.07.04 18:37:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PC Suite [2010.03.17 20:08:29 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ProtectDisc [2010.07.04 16:15:47 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Samsung [2012.01.30 21:19:47 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ScanSpyware [2010.07.13 21:54:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ShredderChess [2010.02.01 17:11:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Template [2010.02.20 18:02:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TerraTec [2010.02.27 17:31:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Tobit [2012.01.30 17:47:50 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 01.02.2012 22:13:58 - Run 7 OTL by OldTimer - Version Folder = C:\Users\Admin\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,99 Gb Total Physical Memory | 1,77 Gb Available Physical Memory | 58,97% Memory free 5,99 Gb Paging File | 4,24 Gb Available in Paging File | 70,79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 268,79 Gb Total Space | 133,71 Gb Free Space | 49,75% Space Free | Partition Type: NTFS Drive D: | 29,28 Gb Total Space | 14,43 Gb Free Space | 49,29% Space Free | Partition Type: FAT32 Drive F: | 963,70 Mb Total Space | 529,73 Mb Free Space | 54,97% Space Free | Partition Type: FAT Computer Name: MEDION | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Home Office 5.0.56 "_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 "_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension "_{E1A63F75-1F72-4450-980D-434496FFC646}" = Corel Painter Essentials 4 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT "{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE "{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 29 "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{32626B60-151E-11D4-A8C5-0050DA353A30}" = Fritz 5.32 "{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support "{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN "{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT "{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Home Office "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Foxlink Webcam "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works "{39FE455F-9478-451B-9420-73C15143DF8E}" = Corel Home Office - IPM "{3A714E01-1F68-4DE5-BA35-CD687F7A8606}" = Lernwerkstatt 7 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{4737AD9F-13AA-4E4C-B86F-B631D557F6A7}" = e-Wörterbücher "{47948554-90C6-4AAC-8CFA-D23CE11C1031}" = Nero 8 Essentials "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5017D60D-C0A5-4CC8-8D2F-0BDA1ADF39D0}" = Corel Home Office - Templates1 "{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime "{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver "{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support "{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A6FDA71-871C-4F35-9392-A27B7E9B7A54}_is1" = Chess Tutor Step 1 "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUSR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4 "{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile-Gerätecenter "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9D3D8C60-A55F-4fed-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver "{A2047586-14F2-439B-8B6F-1DF07E727B8E}_is1" = Chess Tutor Step 2 Demo "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR "{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Deutsch "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes "{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw "{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR "{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update "{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension "{D00667F9-0EF8-4EA5-A17B-C3FD7B3B06D1}" = WISO Konto Online 2010 "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E1A63F75-1F72-4450-980D-434496FFC646}" = Corel Painter Essentials 4 "{E74EA3B1-7192-489D-9A57-0AE918FEC001}" = Corel Home Office - Launcher "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters "{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FA3215C7-7032-4D4D-B21F-C9D941749283}" = Corel Home Office 5.0.56 "3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows-Treiberpaket - Nokia pccsmcfd (10/12/2007 "7-Zip" = 7-Zip 9.21beta "ACDLabs in C__Program_Files_ACDFREE12_" = ACD/Labs Software in C:\Program Files\ACDFREE12\ "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Aldi Foto Service" = Aldi Foto Service 4.6 "Aldi Nord Fotoservice_is1" = Aldi Nord Fotoservice 2.7 "ALDI Nord Online Druck Service" = ALDI Nord Online Druck Service 4.6 "Audiograbber" = Audiograbber 1.83 SE "CCleaner" = CCleaner "Cinergy T Stick MKII" = Cinergy T Stick MKII V9.06.3.01 "E24870CB6AA1C3511635FF9020A3E9471287FBE7" = Windows-Treiberpaket - MobileTop (sshpmdm) Modem (01/26/2008 "FreePDF_XP" = FreePDF (Remove only) "Google Updater" = Google Updater "GPL Ghostscript 9.00" = GPL Ghostscript 9.00 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "InstallShield_{3A714E01-1F68-4DE5-BA35-CD687F7A8606}" = Lernwerkstatt 7 "InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow "InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "lgx4.lgx.server" = G DATA Logox4 Speechengine "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "McAfee Security Scan" = McAfee Security Scan Plus "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 10.0 (x86 de)" = Mozilla Firefox 10.0 (x86 de) "MSC" = McAfee Internet Security Suite "NVIDIA Drivers" = NVIDIA Drivers "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "ProtectDisc Driver 11" = ProtectDisc Driver, Version 11 "Redirection Port Monitor" = RedMon - Redirection Port Monitor "SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software "SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set "Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software "SAMSUNG Mobile Modem V2" = SAMSUNG Mobile Modem V2 Software "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software "Security Task Manager" = Security Task Manager 1.8d "SynTPDeinstKey" = Synaptics Pointing Device Driver "Tobit Radio.fx Server" = Radio.fx "WinLiveSuite_Wave3" = Windows Live Essentials "WISO Konto Online 2010" = WISO Konto Online 2010 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "STANLY Track" = STANLY Track ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 01.02.2012 13:54:23 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 01.02.2012 13:54:23 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 5164 Error - 01.02.2012 13:54:23 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 5164 Error - 01.02.2012 13:54:25 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 01.02.2012 13:54:25 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6272 Error - 01.02.2012 13:54:25 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6272 Error - 01.02.2012 13:54:26 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 01.02.2012 13:54:26 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 7332 Error - 01.02.2012 13:54:26 | Computer Name = Medion | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 7332 Error - 01.02.2012 14:33:31 | Computer Name = Medion | Source = SideBySide | ID = 16842827 Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe" in Zeile 2. Mehrere requestedPrivileges-Elemente sind nicht im Manifest zulässig. [ Media Center Events ] Error - 24.03.2011 10:49:16 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 15:49:11 - Fehler beim Herstellen der Internetverbindung. 15:49:11 - Serververbindung konnte nicht hergestellt werden.. Error - 25.03.2011 10:36:33 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 15:36:33 - Fehler beim Herstellen der Internetverbindung. 15:36:33 - Serververbindung konnte nicht hergestellt werden.. Error - 25.03.2011 10:36:42 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 15:36:38 - Fehler beim Herstellen der Internetverbindung. 15:36:38 - Serververbindung konnte nicht hergestellt werden.. Error - 25.03.2011 11:36:47 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 16:36:47 - Fehler beim Herstellen der Internetverbindung. 16:36:47 - Serververbindung konnte nicht hergestellt werden.. Error - 25.03.2011 11:36:53 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 16:36:52 - Fehler beim Herstellen der Internetverbindung. 16:36:52 - Serververbindung konnte nicht hergestellt werden.. Error - 27.03.2011 07:03:15 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 13:03:15 - Fehler beim Herstellen der Internetverbindung. 13:03:15 - Serververbindung konnte nicht hergestellt werden.. Error - 27.03.2011 07:03:22 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 13:03:20 - Fehler beim Herstellen der Internetverbindung. 13:03:20 - Serververbindung konnte nicht hergestellt werden.. Error - 10.05.2011 10:14:20 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 16:14:14 - Fehler beim Herstellen der Internetverbindung. 16:14:15 - Serververbindung konnte nicht hergestellt werden.. Error - 16.05.2011 15:14:18 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 21:14:18 - Fehler beim Herstellen der Internetverbindung. 21:14:18 - Serververbindung konnte nicht hergestellt werden.. Error - 16.05.2011 15:14:35 | Computer Name = Medion | Source = MCUpdate | ID = 0 Description = 21:14:23 - Fehler beim Herstellen der Internetverbindung. 21:14:23 - Serververbindung konnte nicht hergestellt werden.. [ System Events ] Error - 31.01.2012 19:15:59 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description = Error - 31.01.2012 19:15:59 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description = Error - 31.01.2012 19:15:59 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description = Error - 01.02.2012 10:36:11 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description = Error - 01.02.2012 10:36:11 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description = Error - 01.02.2012 10:36:11 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866321 Description = Error - 01.02.2012 10:36:11 | Computer Name = Medion | Source = WMPNetworkSvc | ID = 866317 Description = Error - 01.02.2012 10:48:38 | Computer Name = Medion | Source = iaStor | ID = 262153 Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error - 01.02.2012 12:38:30 | Computer Name = Medion | Source = DCOM | ID = 10010 Description = Error - 01.02.2012 16:26:27 | Computer Name = Medion | Source = volsnap | ID = 393252 Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. < End of report > Gruß TURM2012 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() PWS-Spyeye!conf bei jedem Neustart 1. Programme deinstallieren/entfernen, die wir verwendet haben und nicht brauchst, bis auf: Code:
ATTFilter CCleaner 2. Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
3. Wenn alles gut verlaufen und dein System läuft stabil,mache folgendes: Alle Systemwiederherstellungspunkte löschen, auch den Letzten 4. Ich würde Dir vorsichtshalber raten, dein Passwort zu ändern (man sollte alle 3-4 Monate machen) z.B. Login-, Mail- oder Website-Passwörter Tipps: Die sichere Passwort-Wahl - (sollte man eigentlich regelmäßigen Abständen ca. alle 3-5 Monate ändern) auch noch hier unter: Sicheres Kennwort (Password) 5. ► für Windows Updates ziehen:-> - Microsoft Update hält Ihren Computer auf dem neuesten Stand! Lesestoff Nr.1:
** Der gesunde Menschenverstand, Windows und Internet-Software sicher konfigurieren ist der beste Weg zur Sicherheit im Webverkehr ist !! Zitat:
► Kann sich auf Dauer eine Menge Datenmüll ansammeln, sich Fehlermeldungen häufen, der PC ist wahrscheinlich nicht mehr so schnell, wie früher:
![]() Wenn Du uns unterstützen möchtest→ Spendekonto gruß kira
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
| ![]() PWS-Spyeye!conf bei jedem Neustart Hallo kira, alles erledigt. Ganz herzlichen Dank für Deine professionelle Hilfe!!! :-) :-) Gruß und alles Gute, TURM2012 |
