Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Exploit.Java.CVE-2011-3544.jy + Weitere Viren?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 03.03.2012, 20:14   #1
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Icon17

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Hallo Trojaner-Board User!


Und zwar ich eine ein großes Problem!

Vor 2 Tagen ungefähr war ich auf der Seite:
www.serials.ws, hatte allerdings mein Kaspersky Internet Security 2012 Deaktiviert! (Das war weil es Hamachi i.wie beim Spielen geblockt hatte).
Aufjedenfall ist auf einmal mein explorer (Desktop) verschwunden und die Meldung:"explorer.exe funktioniert nicht mehr".
Dann hatte sich mein Win7 gefreezed und es öffnete sich ein Fenster mit folgender Meldung: Zahlen sie 50€ für ein Update, dieser Virus wird euch bekannt sein.
Aufjedenfall habe ich mit einer zufälligen Tastenkombination es geschafft dieses Fenster zu umgehen, sozusagen zu "minimieren".
Ich hatte noch einige Ordner geöffnet und hatte somit zugriff auf meine desktop dateien undco.
Nun habe ich mein Kaspersky geöffnet und habe meinen Rechner gescannt, virus gefunden und gelöscht!
Aber das war noch nicht alles, ich habe die Registry (shell)-Winlogon gecheckt nur explorer.exe vorhanden.
Dann habe ich mich ein wenig Informiert. Spybot-Search&Destroy installiert laufen lassen und es hatte noch einen Trojaner gefunden, und gelöscht.

Und heute habe ich meine zeit in Teamspeak3 verbracht und plötzlich hang sich mein pc auf, hatte kein Zugriff mehr auf mein Internet das hatte sich dauernt neu Connected. Was war dann klar? Ich bin noch infected!
Kaspersky Scan gemacht und nun kamen 3 solcher Meldungen:

Exploit.Java.CVE-2011-3544.jy einmal in:
Temp wo genau weiß ich nicht mehr! -> 4bb9e887-782cca65//Effect.class
Temp wo genau weiß ich nicht mehr! -> 4bb9e887-782cca65//Inc.class
Temp wo genau weiß ich nicht mehr! -> 4bb9e887-782cca65//Matrix.class

und nebenbei ich bekomme dauernt solche "Skriptfehler"
Zeile: 1
Zeichen: 7
Fehler: ungültiges zeichen
Code: 0
URL: hxxp://adserver.71i.de/global_js/ICQ/M_18-24_FB2_ICQ_Client_DE.js?mpt\n=$RANDOM7$$RANDOM4$&mpvc=$HTMLCLICKURL$

Ja - Nein Habe bis jetzt immer wieder auf nein gedrückt!

Ich brauche unbedingt eure Hilfe!
Ich würde mich sehr freuen wenn sie mit ihrem Wissen meine probleme beheben könnten!
Es währe "schön" wenn ihr noch weitere Viren finden würdet!
Denn wenn nicht weiteres währe dann liegt es wohl an meinem Rechner -.-


OTL LOG:
(Ich weiß nicht wie ich einen Anhang mache!)

hxxp://pastebin.com/952469Pm

GMER log:

hxxp://pastebin.com/hCMG87mS

Malewarebytes logs folgen!



Rechner Details:
AMD Phenom(tm) 9500 Quead-Core Processor 2,20GHz
4,50GB Ram
Win7 Ultimate 64Bit
AMD Radeon HD 6850
Wlan

Weitere Informationen nötig?


edit:

OSAM log:
hxxp://pastebin.com/6RM1RA8v

Push.. :S könnte sich bitte jemand das hier mal ansehen?
ich habe nämlich auch mit meinem Bankdaten hier gearbeitet.. :/

Push... :S

Alt 05.03.2012, 15:59   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:
ATTFilter
 hier steht das Log
         
__________________

__________________

Alt 05.03.2012, 17:29   #3
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.04.02

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Manuel :: UNKNOWN [Administrator]

Schutz: Deaktiviert

04.03.2012 13:40:38
mbam-log-2012-03-04 (13-40-38).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 492744
Laufzeit: 1 Stunde(n), 46 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKCU\Software\--((Mutex))-- (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.


Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden).

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Manuel\AppData\Local\Temp\dclogs\2012-03-01-5.dc (Stolen.Data) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\--((Mutex))--.dat (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
Habe diese Funde gelöscht!


ESET logs folgen!
__________________

Alt 05.03.2012, 19:06   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.03.2012, 19:17   #5
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Hallo, ich danke dir schoneinmal für deine Hilfe!

Also nein es gibt keine anderen "logs" nur protection logs, da ich die IP protection geblockt habe.
Es hat mir die Teamspeak3 Ip geblockt deshalb.

Log 1 habe ich oben gepostet!

Log 2:
2012/03/03 19:45:33 +0100 UNKNOWN Manuel MESSAGE IP Protection stopped
2012/03/03 19:53:52 +0100 UNKNOWN Manuel MESSAGE Executing scheduled update: Daily
2012/03/03 19:53:52 +0100 UNKNOWN Manuel ERROR Scheduled update failed: Config missing or corrupt, please reinstall failed with error code 2

Log3:
2012/03/04 16:10:13 +0100 UNKNOWN Manuel MESSAGE Executing scheduled update: Daily
2012/03/04 16:10:14 +0100 UNKNOWN Manuel MESSAGE Database already up-to-date

Log4:
2012/03/05 04:01:29 +0100 UNKNOWN Manuel MESSAGE Executing scheduled update: Daily
2012/03/05 04:01:49 +0100 UNKNOWN Manuel MESSAGE Scheduled update executed successfully: database updated from version v2012.03.04.02 to version v2012.03.05.01


Eset Scanner scannt schon seit 02:10 Std!
hoffe es nimmt bald ein ende


Alt 05.03.2012, 19:34   #6
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



ESET LOG:

Code:
ATTFilter
 C:\Program Files (x86)\GamersFirst\War Rock\system\WarRock.exe	a variant of Win32/Packed.Themida application
C:\Users\Manuel\AppData\Local\Mozilla\Firefox\Profiles\34nask8m.default\Cache\2\91\9CD4Fd01	HTML/ScrInject.B.Gen virus
C:\Users\Manuel\AppData\Roaming\Uniblue\RegistryBooster\_temp\registrybooster.exe	Win32/RegistryBooster application
C:\Users\Manuel\Downloads\SoftonicDownloader_fuer_driverscanner.exe	a variant of Win32/SoftonicDownloader.C application
C:\Users\Manuel\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe	Win32/SoftonicDownloader.C application
C:\Users\Manuel\Downloads\SoftonicDownloader_fuer_morphvox.exe	a variant of Win32/SoftonicDownloader.C application
E:\Unlocker1.9.1-x64.exe	Win32/Adware.ADON application
         
Habe das Eset noch offen! nichts entfernt.
Wie sehen meine weiteren Schritte aus?
Ich sehe das hier ist ein Trojaner, mit dem etwas zusammen hängen könnte, stimmts?

C:\Users\Manuel\AppData\Local\Mozilla\Firefox\Profiles\34nask8m.default\Cache\2\91\9CD4Fd01 HTML/ScrInject.B.Gen virus

Alt 05.03.2012, 19:53   #7
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Zitat:
C:\Users\Manuel\AppData\Roaming\Uniblue\RegistryBooster\_temp\registrybooster.exe
Finger weg von Registry-Cleanern!!

Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich.
Wir lesen oft genug von Hilfesuchenden, dass deren System nach der Nutzung von Registry Cleanern nicht mehr startet.
  • Wie soll der Cleaner zu 100% wissen ob der Eintrag benötigt wird oder nicht ?
  • Es ist vollkommen egal ob ein paar verwaiste Registry Einträge am System sind oder nicht.
  • Auch die dauernd angepriesene Beschleunigung des Systems ist nur bedingt wahr. Du würdest es nicht merken.

Ein sogenanntes False Positive von einem Cleaner kann auch dein System unbootbar machen.
Zerstörst Du die Registry, zerstörst Du Windows.

Zitat:
C:\Users\Manuel\Downloads\SoftonicDownloader_fuer_driverscanner.exe
Finger weg von Softonic!!

Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.03.2012, 19:59   #8
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Ich deeinstalliere Dieses Programm sofort!
Danke!

Und was soll ich nun mit diesem Trojaner anstellen?!

Alt 05.03.2012, 20:03   #9
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Nach der Deinstallation:

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
Code:
ATTFilter
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 05.03.2012, 20:37   #10
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Meine frage lautet noch nebenbei.. Ich habe diesen Trojaner nicht gelöscht!
Was passiert nun mit diesem? soll ich einfach abwarten und auf neue Anweisungen von ihnen warten?

OTL LOG:

[Code] ========== Files Created - No Company Name ==========

[2012.03.05 17:17:36 | 148,478,077 | ---- | C] () -- C:\Users\Manuel\Desktop\Aoe game.rar
[2012.03.05 14:12:29 | 000,017,121 | ---- | C] () -- C:\Users\Manuel\Desktop\screen.JPG
[2012.03.05 01:53:58 | 1152,225,384 | ---- | C] () -- C:\Users\Manuel\Desktop\Cyrap musik.rar
[2012.03.05 01:28:17 | 000,341,612 | ---- | C] () -- C:\Users\Manuel\Desktop\scanning.JPG
[2012.03.05 01:25:43 | 000,002,126 | ---- | C] () -- C:\Users\Public\Desktop\MorphVOX Junior.lnk
[2012.03.04 22:37:35 | 000,000,408 | ---- | C] () -- C:\Users\Manuel\Desktop\playlist.asx
[2012.03.04 22:36:29 | 000,000,241 | ---- | C] () -- C:\Users\Manuel\Desktop\listen.pls
[2012.03.04 22:31:43 | 000,000,260 | ---- | C] () -- C:\Users\Manuel\Desktop\Dubstep radio.asx
[2012.03.04 14:21:59 | 000,001,046 | ---- | C] () -- C:\Users\Manuel\Desktop\VirtualDJ Home FREE.lnk
[2012.03.04 13:42:11 | 000,027,726 | ---- | C] () -- C:\Users\Manuel\Desktop\explot.JPG
[2012.03.04 13:38:46 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.03.03 19:13:00 | 000,302,592 | ---- | C] () -- C:\Users\Manuel\Desktop\zkry329u.exe
[2012.03.03 13:31:17 | 000,001,398 | ---- | C] () -- C:\Users\Manuel\Desktop\Free YouTube to MP3 Converter.lnk
[2012.03.03 04:54:19 | 000,000,929 | ---- | C] () -- C:\Users\Public\Desktop\Tunngle beta.lnk
[2012.03.03 03:23:28 | 066,764,644 | ---- | C] () -- C:\Users\Manuel\Desktop\GENETIKK - Puls (_Voodoozirkus_ OUT NOW!)(720p_VP8-Vorbis).webm
[2012.03.03 01:58:16 | 000,019,405 | ---- | C] () -- C:\Users\Manuel\Desktop\Unbenannt.JPG
[2012.03.02 23:01:48 | 000,049,935 | ---- | C] () -- C:\Users\Manuel\Desktop\HB.JPG
[2012.03.02 22:40:36 | 004,218,210 | ---- | C] () -- C:\Users\Manuel\Desktop\Frauenarzt Die Nutte(240p_H.264-AAC).mp4
[2012.03.02 22:40:35 | 006,952,632 | ---- | C] () -- C:\Users\Manuel\Desktop\!!! FRAUENARZT - LASS DiCH GEHN (SPREiZ DEiNE BEiNE) LYRiCS !!!.avi(240p_H.264-AAC).mp4
[2012.03.02 19:02:25 | 000,001,112 | ---- | C] () -- C:\Users\Manuel\Desktop\Siggi Blitz Vorschule 2.lnk
[2012.03.02 18:16:45 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
[2012.03.02 17:12:18 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.03.02 17:12:17 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.03.02 02:35:21 | 000,000,454 | ---- | C] () -- C:\Users\Manuel\Desktop\Hardbase.asx
[2012.03.02 02:34:41 | 000,000,454 | ---- | C] () -- C:\Users\Manuel\Desktop\CoreTime.asx
[2012.03.02 02:33:58 | 000,000,462 | R--- | C] () -- C:\Users\Manuel\Desktop\Housetime.asx
[2012.03.02 02:32:51 | 000,001,258 | ---- | C] () -- C:\Users\Manuel\Desktop\Spybot - Search & Destroy.lnk
[2012.03.02 02:20:35 | 000,001,139 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2012.03.02 02:20:32 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2012.03.02 02:20:32 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012.03.02 02:20:32 | 000,077,312 | ---- | C] () -- C:\Windows\SysWow64\ztvunace26.dll
[2012.03.02 02:20:32 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012.03.01 22:27:52 | 000,000,926 | ---- | C] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2012.03.01 22:23:42 | 000,163,845 | ---- | C] () -- C:\Users\Manuel\Desktop\The_Matrix_Revolutions,_2003,_Keanu_Reeves,_Laurence_Fishburne,_Carrie-Anne_Moss,_Monica_Bellucci.jpg
[2012.03.01 20:18:30 | 1286,430,720 | ---- | C] () -- C:\Users\Manuel\Desktop\WXP_SP2_x64.09.09.iso
[2012.03.01 19:29:08 | 000,000,470 | R--- | C] () -- C:\Users\Manuel\Desktop\technobase!.asx
[2012.03.01 13:39:29 | 000,000,615 | ---- | C] () -- C:\Windows\eReg.dat
[2012.03.01 13:37:18 | 000,001,926 | ---- | C] () -- C:\Users\Manuel\Desktop\Command & Conquer(TM) Generäle.lnk
[2012.03.01 01:13:46 | 000,002,601 | ---- | C] () -- C:\Users\Public\Documents\Global.sw2
[2012.02.29 20:18:41 | 000,001,107 | ---- | C] () -- C:\Users\Manuel\Desktop\Adobe Photoshop CS5 (64 Bit).lnk
[2012.02.29 20:17:30 | 000,001,207 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012.02.29 20:14:16 | 000,001,169 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012.02.29 20:13:34 | 000,001,262 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012.02.29 20:10:26 | 000,001,353 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012.02.29 20:10:17 | 000,001,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012.02.29 04:37:46 | 000,022,580 | ---- | C] () -- C:\Users\Manuel\Desktop\Publication1.ppp
[2012.02.29 04:02:47 | 000,002,473 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif PagePlus X6.lnk
[2012.02.29 04:02:47 | 000,002,120 | ---- | C] () -- C:\Users\Public\Desktop\Serif PagePlus X6.lnk
[2012.02.28 17:10:03 | 035,063,120 | ---- | C] () -- C:\Users\Manuel\wfwfawa.wav
[2012.02.27 03:15:19 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
[2012.02.27 02:11:23 | 000,000,600 | ---- | C] () -- C:\Users\Manuel\AppData\Roaming\winscp.rnd
[2012.02.27 02:11:22 | 000,001,849 | ---- | C] () -- C:\Users\Manuel\Desktop\WinSCP.lnk
[2012.02.26 21:19:24 | 000,032,768 | ---- | C] () -- C:\Windows\SysNative\UUDECODE.EXE
[2012.02.26 21:19:24 | 000,024,576 | ---- | C] () -- C:\Windows\SysNative\UUENCODE.EXE
[2012.02.26 21:19:24 | 000,003,431 | ---- | C] () -- C:\Windows\SysNative\UUDECODE.C
[2012.02.26 21:19:24 | 000,002,507 | ---- | C] () -- C:\Windows\SysNative\UUENCODE.C
[2012.02.26 15:42:33 | 000,001,949 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.02.26 15:42:33 | 000,001,899 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012.02.26 11:43:38 | 028,909,070 | ---- | C] () -- C:\Users\Manuel\Desktop\aGlotze_v10 vlc1.11.rar
[2012.02.24 22:42:23 | 000,000,060 | ---- | C] () -- C:\Users\Manuel\update.bat
[2012.02.24 02:26:59 | 000,002,098 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2012.02.24 02:26:59 | 000,002,086 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2012.02.23 23:41:47 | 000,001,857 | ---- | C] () -- C:\Users\Manuel\Desktop\UseNeXT.lnk
[2012.02.23 05:22:16 | 000,002,012 | -H-- | C] () -- C:\Users\Manuel\Documents\Default.rdp
[2012.02.23 05:02:10 | 000,000,600 | ---- | C] () -- C:\Users\Manuel\AppData\Local\PUTTY.RND
[2012.02.23 00:37:24 | 000,105,781 | ---- | C] () -- C:\Users\Manuel\Documents\dwadwdadwa.jpg
[2012.02.22 22:00:45 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\OpenVPN GUI.lnk
[2012.02.22 21:54:56 | 000,000,241 | ---- | C] () -- C:\Users\Manuel\openvpn-connect.json
[2012.02.22 00:32:19 | 000,001,950 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.02.21 23:41:34 | 000,028,036 | ---- | C] () -- C:\Users\Manuel\Documents\Unbenannt.JPG
[2012.02.21 21:31:24 | 000,000,999 | ---- | C] () -- C:\Users\Manuel\Desktop\DUC 3.0.lnk
[2012.02.21 21:26:59 | 006,864,080 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_21_26_57.wav
[2012.02.21 21:13:02 | 001,336,400 | ---- | C] () -- C:\Users\Manuel\fwafwa.wav
[2012.02.21 21:09:15 | 033,239,120 | ---- | C] () -- C:\Users\Manuel\dwadwa.wav
[2012.02.21 21:01:35 | 052,097,360 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_21_1_33.wav
[2012.02.21 16:26:33 | 076,942,160 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_16_26_31.wav
[2012.02.21 16:19:02 | 014,480,720 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_16_18_59.wav
[2012.02.21 01:46:02 | 000,002,544 | ---- | C] () -- C:\Windows\diagwrn.xml
[2012.02.21 01:46:02 | 000,001,890 | ---- | C] () -- C:\Windows\diagerr.xml
[2012.02.18 22:03:26 | 002,486,480 | ---- | C] () -- C:\Users\Manuel\pain multiaccount MELDEN.wav
[2012.02.14 22:45:29 | 000,014,051 | ---- | C] () -- C:\Windows\SysNative\RaCoInst.dat
[2012.02.14 14:17:22 | 000,001,065 | ---- | C] () -- C:\Users\Manuel\Desktop\Firstload.lnk
[2012.02.13 02:23:38 | 000,000,919 | ---- | C] () -- C:\Users\Manuel\Desktop\IDA Pro Free.lnk
[2012.02.12 20:17:06 | 000,007,600 | ---- | C] () -- C:\Users\Manuel\AppData\Local\Resmon.ResmonCfg
[2012.02.11 21:08:11 | 000,001,298 | ---- | C] () -- C:\Users\Public\Desktop\ArchiCrypt Shredder 5.lnk
[2012.02.11 21:08:05 | 000,236,608 | ---- | C] () -- C:\Windows\SysWow64\Shredder.dll
[2012.02.11 20:45:18 | 000,001,019 | ---- | C] () -- C:\Users\Manuel\Desktop\Proxifier.lnk
[2012.02.11 20:45:17 | 000,055,024 | ---- | C] () -- C:\Windows\SysNative\PrxerNsp.dll
[2012.02.11 20:45:17 | 000,054,000 | ---- | C] () -- C:\Windows\SysWow64\PrxerNsp.dll
[2012.02.11 20:32:14 | 000,001,740 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
[2012.02.11 20:32:14 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\Wireshark.lnk
[2012.02.10 03:40:25 | 000,031,744 | ---- | C] () -- C:\Users\Manuel\Desktop\ChangeMAC-2010.exe
[2012.02.10 03:05:59 | 000,000,459 | ---- | C] () -- C:\Users\Manuel\Desktop\Cain.lnk
[2012.02.09 00:50:40 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012.02.08 22:01:51 | 001,588,762 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.02.08 16:19:14 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX Music Maker MX Premium Download-Version.lnk
[2012.02.08 16:08:06 | 000,000,345 | ---- | C] () -- C:\Windows\BeatBox.INI
[2012.02.07 10:09:42 | 000,001,177 | ---- | C] () -- C:\Users\Manuel\Desktop\technomaker.exe.lnk
[2012.02.07 10:08:05 | 000,000,133 | ---- | C] () -- C:\Windows\technomaker.INI
[2012.02.07 10:06:46 | 000,014,182 | ---- | C] () -- C:\Windows\SysWow64\DLLAV32.lib
[2012.02.07 10:03:52 | 000,001,208 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2012.02.06 23:56:20 | 000,002,037 | ---- | C] () -- C:\Users\Manuel\Desktop\JDownloader.lnk
[2012.02.06 23:56:16 | 000,002,001 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.02.06 23:56:16 | 000,001,945 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.02.06 23:56:16 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.02.06 20:28:09 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.01.31 20:28:44 | 000,282,864 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.01.31 20:28:41 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.01.28 17:25:01 | 000,017,408 | ---- | C] () -- C:\Users\Manuel\AppData\Local\WebpageIcons.db
[2012.01.28 16:43:40 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.12.06 03:35:10 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011.12.06 03:35:10 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011.09.19 08:07:46 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2011.09.19 08:07:32 | 000,058,368 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.21 19:56:22 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2010.06.25 18:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll

========== LOP Check ==========

[2012.02.11 21:08:08 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ACShredder5
[2012.02.26 15:42:41 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Canneverbe Limited
[2012.03.02 01:41:54 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DAEMON Tools Lite
[2012.02.29 23:09:11 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DarknessII
[2012.02.13 02:23:53 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Datarescue
[2012.03.03 13:31:38 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoft
[2012.03.03 13:31:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.24 11:30:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\FileZilla
[2012.03.01 04:47:50 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Firstload
[2012.03.05 20:09:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ICQ
[2012.01.28 17:56:25 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Leadertech
[2012.02.16 02:53:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\LolClient
[2012.02.13 01:52:16 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\MAGIX
[2012.03.02 01:53:40 | 000,000,000 | RHSD | M] -- C:\Users\Manuel\AppData\Roaming\MicroUpdate
[2012.02.21 15:25:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Origin
[2012.02.21 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Proxifier
[2012.03.05 01:58:59 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Screaming Bee
[2012.02.29 04:04:01 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Serif
[2012.03.02 02:20:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Simply Super Software
[2012.03.02 02:22:12 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Spamihilator
[2012.02.01 22:12:57 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TeamViewer
[2012.02.24 02:27:06 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Thunderbird
[2012.02.12 21:20:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TrueCrypt
[2012.03.03 18:05:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TS3Client
[2012.03.03 04:56:13 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Tunngle
[2012.03.05 20:00:58 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Uniblue
[2012.03.05 20:09:45 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\UseNeXT
[2009.07.14 06:08:49 | 000,017,010 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.02.11 21:08:08 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ACShredder5
[2012.03.04 20:13:39 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Adobe
[2012.03.03 13:55:24 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Apple Computer
[2012.01.31 15:39:49 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ATI
[2012.02.26 15:42:41 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Canneverbe Limited
[2012.03.02 01:41:54 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DAEMON Tools Lite
[2012.02.29 23:09:11 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DarknessII
[2012.02.13 02:23:53 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Datarescue
[2012.03.03 13:31:38 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoft
[2012.03.03 13:31:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.24 11:30:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\FileZilla
[2012.03.01 04:47:50 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Firstload
[2012.03.05 20:09:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ICQ
[2012.01.28 16:12:51 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Identities
[2012.01.28 17:56:25 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Leadertech
[2012.02.16 02:53:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\LolClient
[2012.01.28 17:20:49 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Macromedia
[2012.02.13 01:52:16 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\MAGIX
[2012.03.03 19:37:28 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Malwarebytes
[2009.07.14 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Media Center Programs
[2012.02.23 22:36:18 | 000,000,000 | --SD | M] -- C:\Users\Manuel\AppData\Roaming\Microsoft
[2012.03.02 01:53:40 | 000,000,000 | RHSD | M] -- C:\Users\Manuel\AppData\Roaming\MicroUpdate
[2012.01.28 16:56:59 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Mozilla
[2012.02.21 15:25:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Origin
[2012.02.21 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Proxifier
[2012.03.05 01:58:59 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Screaming Bee
[2012.02.12 00:07:22 | 000,000,000 | RH-D | M] -- C:\Users\Manuel\AppData\Roaming\SecuROM
[2012.02.29 04:04:01 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Serif
[2012.03.02 02:20:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Simply Super Software
[2012.03.05 20:09:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Skype
[2012.03.02 02:22:12 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Spamihilator
[2012.02.01 22:12:57 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TeamViewer
[2012.02.24 02:27:06 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Thunderbird
[2012.02.12 21:20:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TrueCrypt
[2012.03.03 18:05:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TS3Client
[2012.03.03 04:56:13 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Tunngle
[2012.03.05 20:00:58 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Uniblue
[2012.03.05 20:09:45 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\UseNeXT
[2012.02.06 01:59:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\vlc
[2012.03.05 13:00:43 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Winamp
[2012.01.28 17:06:05 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >
[2012.01.28 17:56:22 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Manuel\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2012.03.05 03:55:40 | 007,253,200 | ---- | M] (Uniblue Systems Ltd ) -- C:\Users\Manuel\AppData\Roaming\Uniblue\RegistryBooster\_temp\registrybooster.exe

< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< MD5 for: USER32.DLL >
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll

< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe

< MD5 for: WININIT.EXE >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

< MD5 for: WINLOGON.EXE >
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WS2IFSL.SYS >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2012.03.02 17:12:18 | 000,353,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dxtmsft.dll
[2012.03.02 17:12:18 | 000,223,232 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dxtrans.dll
[2009.07.14 02:15:36 | 000,226,816 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\LocationApi.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 436 bytes -> C:\Users\Manuel\Desktop\Publication1.ppp:SummaryInformation

< End of report >
[\Code]

Alt 07.03.2012, 04:50   #11
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Pfeil

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Hallo, danke es hat Funktioniert logs sind hier unten .
Ist es normal das nach diesem Vorgang, das Hochfahren länger dauert?
Als ich mich in mein benutzerkonto eingeloggt habe, musste ich erstmal eine Minute warten bis alles gebootet war.
Ich hoffe das war nur eine "ausnahme".
Und es ist ratsam nach diesen Trojanern die Passwörter zu changen oder?!

Code:
ATTFilter
 All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-129560445-3818396582-2292848211-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\DefaultNetworkProfile| /E : value set successfully!
HKU\S-1-5-21-129560445-3818396582-2292848211-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKU\S-1-5-21-129560445-3818396582-2292848211-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-129560445-3818396582-2292848211-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Unable to set value : HKEY_USERS\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E!
Registry key HKEY_USERS\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}\ not found.
Registry value HKEY_USERS\S-1-5-21-129560445-3818396582-2292848211-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_USERS\S-1-5-21-129560445-3818396582-2292848211-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer deleted successfully.
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe moved successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLowDiskSpaceChecks deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\system32\MSDCSC\dlxcc.exe deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File move failed. F:\autorun.inf scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c54e3a53-6523-11e1-8d7c-bc53493c3cbb}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c54e3a53-6523-11e1-8d7c-bc53493c3cbb}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c54e3a53-6523-11e1-8d7c-bc53493c3cbb}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c54e3a53-6523-11e1-8d7c-bc53493c3cbb}\ not found.
File M:\pushinst.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d34618aa-49c6-11e1-8510-001d92e9f7cd}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d34618aa-49c6-11e1-8510-001d92e9f7cd}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d34618aa-49c6-11e1-8510-001d92e9f7cd}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d34618aa-49c6-11e1-8510-001d92e9f7cd}\ not found.
File K:\start.exe /checksection not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f53a6a2f-49c0-11e1-9b3e-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f53a6a2f-49c0-11e1-9b3e-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f53a6a2f-49c0-11e1-9b3e-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f53a6a2f-49c0-11e1-9b3e-806e6f6e6963}\ not found.
File move failed. F:\Launch.exe scheduled to be moved on reboot.
ADS C:\Users\Manuel\Desktop\Publication1.ppp:SummaryInformation deleted successfully.
========== FILES ==========
C:\Windows\system32\MSDCSC folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Manuel
->Temp folder emptied: 8521675 bytes
->Temporary Internet Files folder emptied: 2320744 bytes
->Java cache emptied: 1638733 bytes
->FireFox cache emptied: 740752567 bytes
->Flash cache emptied: 2730 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 55296 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 24297576 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes
RecycleBin emptied: 1392726014 bytes
 
Total Files Cleaned = 2.070,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.35.0 log created on 03072012_043102

Files\Folders moved on Reboot...
File move failed. F:\autorun.inf scheduled to be moved on reboot.
File move failed. F:\Launch.exe scheduled to be moved on reboot.
C:\Users\Manuel\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...
         
Achja eine nebenfrage, wieso wurde Spybot search and Destroy entfernt?
hier auf diesen Board wurde wiese Programm empfohlen.. das verwirrt mich leicht.
Aber wenn das programm nicht nötig ist dann kann mir das ja nur Recht sein, schon eine Anwendung weniger.

Alt 07.03.2012, 16:24   #12
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



ComboFix durchrattern lassen!
Maus und tastertur nicht angerührt

Combofix Logfile:
Code:
ATTFilter
ComboFix 12-03-07.03 - Manuel 07.03.2012  16:07:49.1.4 - x64
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.49.1031.18.4606.3248 [GMT 1:00]
ausgeführt von:: c:\users\Manuel\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Manuel\AppData\Local\assembly\tmp
c:\users\Manuel\AppData\Roaming\InstallDir
c:\users\Manuel\AppData\Roaming\Microsoft\Windows\lARkr8tK0VXpuGMp8L.dat
c:\users\Manuel\AppData\Roaming\Microsoft\Windows\lARkr8tK0VXpuGMp8L.xtr
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-02-07 bis 2012-03-07  ))))))))))))))))))))))))))))))
.
.
2012-03-07 15:17 . 2012-03-07 15:17	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-03-07 05:30 . 2012-03-07 05:31	--------	d-----w-	c:\program files (x86)\Wireshark
2012-03-07 05:27 . 2012-03-07 05:27	--------	d-----w-	c:\program files (x86)\Common Files\Java
2012-03-07 05:27 . 2012-03-07 05:27	--------	d-----w-	c:\program files (x86)\Java
2012-03-07 05:05 . 2012-03-07 05:05	--------	d-----w-	c:\users\Manuel\AppData\Local\Secunia PSI
2012-03-07 05:05 . 2012-03-07 05:05	--------	d-----w-	c:\program files (x86)\Secunia
2012-03-07 04:57 . 2012-03-07 04:57	--------	d-----w-	c:\users\Manuel\AppData\Roaming\SUPERAntiSpyware.com
2012-03-07 04:57 . 2012-03-07 04:59	--------	d-----w-	c:\program files\SUPERAntiSpyware
2012-03-07 04:57 . 2012-03-07 04:57	--------	d-----w-	c:\programdata\SUPERAntiSpyware.com
2012-03-07 03:31 . 2012-03-07 03:31	--------	d-----w-	C:\_OTL
2012-03-06 20:07 . 2012-03-06 20:07	--------	d-----w-	c:\program files (x86)\Screaming Bee
2012-03-06 14:34 . 2012-03-07 03:47	--------	d-----r-	C:\Javascript
2012-03-04 14:19 . 2012-03-04 14:19	--------	d-----w-	c:\users\Manuel\AppData\Local\Vitalwerks
2012-03-04 14:10 . 2012-03-04 14:10	--------	d-----w-	c:\program files (x86)\No-IP
2012-03-04 13:21 . 2012-03-04 13:21	--------	d-----w-	c:\program files (x86)\VirtualDJ
2012-03-04 12:38 . 2012-03-04 12:38	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-04 12:38 . 2011-12-10 14:24	23152	----a-w-	c:\windows\system32\drivers\mbam.sys
2012-03-04 02:02 . 2012-03-04 02:02	--------	d-sh--w-	c:\windows\SysWow64\%APPDATA%
2012-03-03 18:37 . 2012-03-03 18:37	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Malwarebytes
2012-03-03 18:37 . 2012-03-03 18:37	--------	d-----w-	c:\programdata\Malwarebytes
2012-03-03 11:21 . 2012-03-03 11:21	--------	d-----w-	c:\windows\SysWow64\wbem\en-US
2012-03-03 11:20 . 2012-03-03 11:20	--------	d-----w-	c:\windows\system32\wbem\en-US
2012-03-03 03:54 . 2012-03-03 03:56	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Tunngle
2012-03-03 03:54 . 2012-03-03 03:54	--------	d-----w-	c:\programdata\Tunngle
2012-03-03 03:54 . 2009-09-16 06:02	31232	----a-w-	c:\windows\system32\drivers\tap0901t.sys
2012-03-03 03:54 . 2012-03-03 03:56	--------	d-----w-	c:\program files (x86)\Tunngle
2012-03-03 02:52 . 2012-03-03 02:52	--------	d-----w-	c:\program files (x86)\Common Files\Skype
2012-03-02 17:45 . 2010-09-14 06:45	367104	----a-w-	c:\windows\system32\wcncsvc.dll
2012-03-02 17:45 . 2010-09-14 06:07	276992	----a-w-	c:\windows\SysWow64\wcncsvc.dll
2012-03-02 17:16 . 2012-03-02 17:16	--------	d-----w-	c:\program files (x86)\Winamp Detect
2012-03-02 17:15 . 2012-03-02 17:15	--------	d-----w-	c:\program files (x86)\Common Files\PX Storage Engine
2012-03-02 17:15 . 2012-03-06 17:37	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Winamp
2012-03-02 17:15 . 2012-03-02 17:16	--------	d-----w-	c:\program files (x86)\Winamp
2012-03-02 17:14 . 2012-03-02 17:15	--------	d-----w-	c:\program files\Virtual Audio Cable
2012-03-02 17:14 . 2012-03-02 17:14	66728	----a-w-	c:\windows\system32\drivers\vrtaucbl.sys
2012-03-02 17:09 . 2009-09-10 06:28	311808	----a-w-	c:\windows\system32\msv1_0.dll
2012-03-02 17:09 . 2009-09-10 05:52	257024	----a-w-	c:\windows\SysWow64\msv1_0.dll
2012-03-02 16:30 . 2009-10-10 03:17	14336	----a-w-	c:\windows\system32\drivers\sffp_sd.sys
2012-03-02 16:30 . 2012-03-02 16:30	--------	d-----w-	c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2012-03-02 16:18 . 2010-02-23 08:16	294912	----a-w-	c:\windows\system32\browserchoice.exe
2012-03-02 15:48 . 2012-03-04 02:22	--------	d-----w-	c:\program files (x86)\Microsoft Silverlight
2012-03-02 15:10 . 2010-03-04 04:40	184832	----a-w-	c:\windows\system32\drivers\usbvideo.sys
2012-03-02 15:10 . 2010-03-04 04:32	243712	----a-w-	c:\windows\system32\drivers\ks.sys
2012-03-02 15:08 . 2009-09-03 07:36	1975296	----a-w-	c:\windows\system32\CertEnroll.dll
2012-03-02 15:08 . 2009-09-03 07:04	1320960	----a-w-	c:\windows\SysWow64\CertEnroll.dll
2012-03-02 15:06 . 2012-01-14 04:02	3143168	----a-w-	c:\windows\system32\win32k.sys
2012-03-02 15:05 . 2010-07-29 06:30	82944	----a-w-	c:\windows\SysWow64\iccvid.dll
2012-03-02 15:04 . 2011-11-05 05:17	2048	----a-w-	c:\windows\system32\tzres.dll
2012-03-02 14:53 . 2011-12-16 08:42	634368	----a-w-	c:\windows\system32\msvcrt.dll
2012-03-02 14:53 . 2011-12-16 07:59	690688	----a-w-	c:\windows\SysWow64\msvcrt.dll
2012-03-02 14:51 . 2011-06-23 05:29	5507968	----a-w-	c:\windows\system32\ntoskrnl.exe
2012-03-02 14:51 . 2011-06-23 04:38	3957120	----a-w-	c:\windows\SysWow64\ntkrnlpa.exe
2012-03-02 14:51 . 2011-06-23 04:38	3902336	----a-w-	c:\windows\SysWow64\ntoskrnl.exe
2012-03-02 14:47 . 2011-11-19 15:07	77312	----a-w-	c:\windows\system32\packager.dll
2012-03-02 14:47 . 2011-11-19 14:06	67072	----a-w-	c:\windows\SysWow64\packager.dll
2012-03-02 14:45 . 2009-12-29 08:03	220672	----a-w-	c:\windows\system32\wintrust.dll
2012-03-02 14:45 . 2009-12-29 06:55	172032	----a-w-	c:\windows\SysWow64\wintrust.dll
2012-03-02 14:45 . 2010-01-09 07:19	139264	----a-w-	c:\windows\system32\cabview.dll
2012-03-02 14:45 . 2010-01-09 06:52	132608	----a-w-	c:\windows\SysWow64\cabview.dll
2012-03-02 14:32 . 2012-02-08 07:13	8643640	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{5DDF34F3-52EA-4A34-9495-2FF642A099B0}\mpengine.dll
2012-03-02 03:13 . 2009-06-18 11:55	18816	------w-	c:\windows\SysWow64\SAVRKBootTasks.sys
2012-03-02 01:32 . 2012-03-07 03:31	--------	d-----w-	c:\program files (x86)\Spybot - Search & Destroy
2012-03-02 01:32 . 2012-03-03 04:39	--------	d-----w-	c:\programdata\Spybot - Search & Destroy
2012-03-02 01:21 . 2012-03-02 01:22	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Spamihilator
2012-03-02 01:20 . 2006-06-19 12:01	69632	----a-w-	c:\windows\SysWow64\ztvcabinet.dll
2012-03-02 01:20 . 2006-05-25 14:52	162304	----a-w-	c:\windows\SysWow64\ztvunrar36.dll
2012-03-02 01:20 . 2005-08-26 00:50	77312	----a-w-	c:\windows\SysWow64\ztvunace26.dll
2012-03-02 01:20 . 2003-02-02 19:06	153088	----a-w-	c:\windows\SysWow64\UNRAR3.dll
2012-03-02 01:20 . 2002-03-06 00:00	75264	----a-w-	c:\windows\SysWow64\unacev2.dll
2012-03-02 01:20 . 2012-03-02 11:24	--------	d-----w-	c:\program files (x86)\Trojan Remover
2012-03-02 01:20 . 2012-03-02 01:20	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Simply Super Software
2012-03-02 01:20 . 2012-03-02 01:20	--------	d-----w-	c:\programdata\Simply Super Software
2012-03-01 23:32 . 2012-03-02 00:53	--------	d-sh--r-	c:\users\Manuel\AppData\Roaming\MicroUpdate
2012-03-01 21:29 . 2012-03-01 21:29	--------	d-----w-	c:\program files (x86)\LogMeIn Hamachi
2012-03-01 21:28 . 2012-03-06 14:06	--------	d-----w-	c:\users\Manuel\AppData\Local\LogMeIn Hamachi
2012-03-01 16:11 . 2012-03-01 16:11	--------	d-----w-	c:\users\Manuel\AppData\Local\Downloaded Installations
2012-03-01 00:06 . 2012-03-01 00:06	--------	d-----w-	c:\program files (x86)\Midway Home Entertainment
2012-02-29 20:39 . 2012-02-29 22:09	--------	d-----w-	c:\users\Manuel\AppData\Roaming\DarknessII
2012-02-29 20:11 . 2012-03-04 19:09	--------	d-----w-	c:\programdata\regid.1986-12.com.adobe
2012-02-29 19:14 . 2012-02-29 19:18	--------	d-----w-	c:\program files\Common Files\Adobe
2012-02-29 19:12 . 2012-02-29 19:12	--------	d-----w-	c:\program files (x86)\Adobe Media Player
2012-02-29 19:09 . 2012-03-07 05:38	--------	d-----w-	c:\program files (x86)\Common Files\Adobe AIR
2012-02-29 03:04 . 2012-02-29 03:04	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Serif
2012-02-29 02:59 . 2012-02-29 02:59	--------	d-----w-	c:\program files (x86)\Serif
2012-02-27 02:30 . 2012-03-01 20:05	--------	d-----w-	c:\users\Manuel\VirtualBox VMs
2012-02-27 02:16 . 2012-03-06 23:01	--------	d-----w-	c:\users\Manuel\.VirtualBox
2012-02-27 02:15 . 2011-12-19 12:45	224048	----a-w-	c:\windows\system32\drivers\VBoxDrv.sys
2012-02-27 02:14 . 2011-12-19 12:45	130864	----a-w-	c:\windows\system32\drivers\VBoxUSBMon.sys
2012-02-27 02:14 . 2012-02-27 02:14	--------	d-----w-	c:\program files\Oracle
2012-02-27 01:11 . 2012-02-27 01:11	--------	d-----w-	c:\program files (x86)\WinSCP
2012-02-26 20:19 . 2001-08-12 13:38	--------	d-----w-	c:\windows\system32\software.lc
2012-02-26 20:19 . 2001-07-13 10:59	32768	----a-w-	c:\windows\system32\UUDECODE.EXE
2012-02-26 20:19 . 1998-12-08 15:28	24576	----a-w-	c:\windows\system32\UUENCODE.EXE
2012-02-26 14:42 . 2012-02-26 14:42	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Canneverbe Limited
2012-02-26 14:42 . 2012-02-26 14:42	--------	d-----w-	c:\programdata\Canneverbe Limited
2012-02-26 14:42 . 2012-02-26 14:42	--------	d-----w-	c:\program files (x86)\CDBurnerXP
2012-02-24 21:42 . 2012-02-24 21:42	60	----a-w-	c:\users\Manuel\update.bat
2012-02-24 20:38 . 2012-02-25 00:49	--------	d-----w-	c:\program files (x86)\Valve
2012-02-24 08:38 . 2012-02-24 08:38	--------	d-----w-	c:\programdata\ATI
2012-02-24 08:21 . 2012-02-24 08:21	--------	d-----w-	C:\AMD
2012-02-24 08:16 . 2012-02-24 08:16	--------	d-----w-	c:\programdata\EA Core
2012-02-24 08:16 . 2012-02-24 10:04	--------	d-----w-	c:\programdata\EA Logs
2012-02-24 08:15 . 2012-02-24 08:15	--------	d--h--w-	c:\program files (x86)\Common Files\EAInstaller
2012-02-24 08:13 . 2012-02-24 08:13	--------	d-----w-	c:\programdata\NVIDIA
2012-02-24 06:51 . 2012-03-02 01:11	--------	d-----w-	c:\program files (x86)\Battlelog Web Plugins
2012-02-24 01:27 . 2012-02-24 01:27	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Thunderbird
2012-02-24 01:27 . 2012-02-24 01:27	--------	d-----w-	c:\users\Manuel\AppData\Local\Thunderbird
2012-02-24 01:26 . 2012-02-24 01:26	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2012-02-23 22:41 . 2012-03-07 15:04	--------	d-----w-	c:\users\Manuel\AppData\Roaming\UseNeXT
2012-02-23 22:41 . 2012-02-23 22:41	--------	d-----w-	c:\program files (x86)\UseNeXT
2012-02-23 15:40 . 2012-02-23 15:40	--------	d-----w-	c:\programdata\Blizzard Entertainment
2012-02-23 04:42 . 2012-02-23 04:42	--------	d-----w-	c:\users\Manuel\AppData\Local\Apps
2012-02-23 04:42 . 2012-02-29 20:53	--------	d-----w-	c:\users\Manuel\AppData\Local\Deployment
2012-02-23 02:28 . 2012-02-24 10:30	--------	d-----w-	c:\users\Manuel\AppData\Roaming\FileZilla
2012-02-23 02:27 . 2012-02-23 02:28	--------	d-----w-	c:\program files (x86)\FileZilla FTP Client
2012-02-22 22:05 . 2012-02-22 22:05	--------	d-----w-	c:\program files (x86)\Intelore
2012-02-22 21:00 . 2012-02-22 21:00	--------	d-----w-	c:\program files (x86)\OpenVPN
2012-02-22 02:32 . 2012-02-22 03:12	--------	d-----w-	c:\program files (x86)\Common Files\Blizzard Entertainment
2012-02-21 23:32 . 2012-02-21 23:32	254528	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-21 23:32 . 2012-03-02 01:10	--------	d-----w-	c:\program files (x86)\DAEMON Tools Toolbar
2012-02-21 23:32 . 2012-02-21 23:33	--------	d-----w-	c:\program files (x86)\DAEMON Tools Lite
2012-02-21 20:25 . 2012-03-04 17:48	--------	d-----w-	c:\programdata\boost_interprocess
2012-02-21 20:10 . 2012-03-05 00:58	--------	d-----w-	c:\users\Manuel\AppData\Roaming\Screaming Bee
2012-02-21 20:10 . 2012-02-21 20:11	--------	d-----w-	c:\programdata\Screaming Bee
2012-02-21 20:08 . 2012-02-21 20:08	--------	d-----w-	c:\users\Manuel\AppData\Local\Windows Live
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-07 05:39 . 2012-01-28 16:12	414368	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-07 05:27 . 2012-01-31 17:43	472808	----a-w-	c:\windows\SysWow64\deployJava1.dll
2012-02-28 15:39 . 2012-01-31 19:32	282864	----a-w-	c:\windows\SysWow64\PnkBstrB.xtr
2012-02-28 15:39 . 2012-01-31 19:28	282864	----a-w-	c:\windows\SysWow64\PnkBstrB.exe
2012-02-28 15:38 . 2012-01-31 19:28	280904	----a-w-	c:\windows\SysWow64\PnkBstrB.ex0
2012-02-24 09:52 . 2012-01-31 19:28	76888	----a-w-	c:\windows\SysWow64\PnkBstrA.exe
2012-01-29 04:10 . 2012-01-28 15:29	279656	------w-	c:\windows\system32\MpSigStub.exe
2012-01-28 16:56 . 2012-01-28 16:56	53248	----a-r-	c:\users\Manuel\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-01-18 05:44 . 2012-01-18 05:44	540960	----a-w-	c:\windows\SysWow64\LVUI2RC.dll
2012-01-18 05:44 . 2012-01-18 05:44	545056	----a-w-	c:\windows\SysWow64\LVUI2.dll
2012-01-18 05:44 . 2012-01-18 05:44	561440	----a-w-	c:\windows\system32\LVUIRC64.dll
2012-01-18 05:44 . 2012-01-18 05:44	4865568	----a-w-	c:\windows\system32\drivers\lvuvc64.sys
2012-01-18 05:44 . 2012-01-18 05:44	769312	----a-w-	c:\windows\system32\LVUI64.dll
2012-01-18 05:44 . 2012-01-18 05:44	351136	----a-w-	c:\windows\system32\drivers\lvrs64.sys
2012-01-18 05:44 . 2012-01-18 05:44	307488	----a-w-	c:\windows\SysWow64\lvcodec2.dll
2012-01-18 05:44 . 2012-01-18 05:44	263456	----a-w-	c:\windows\system32\lvco13311044.dll
2012-01-18 05:44 . 2012-01-18 05:44	176416	----a-w-	c:\windows\system32\lvcod64.dll
2012-01-18 05:44 . 2012-01-18 05:44	25632	----a-w-	c:\windows\system32\drivers\lvbflt64.sys
2012-01-18 05:44 . 2012-01-18 05:44	336408	----a-w-	c:\windows\SysWow64\DevManagerCore.dll
2012-01-18 05:44 . 2012-01-18 05:44	336408	----a-w-	c:\windows\system32\DevManagerCore.dll
2012-01-18 05:44 . 2012-01-18 05:44	10920984	----a-w-	c:\windows\SysWow64\LogiDPP.dll
2012-01-18 05:44 . 2012-01-18 05:44	10920984	----a-w-	c:\windows\system32\LogiDPP.dll
2012-01-18 05:44 . 2012-01-18 05:44	104472	----a-w-	c:\windows\SysWow64\LogiDPPApp.exe
2012-01-18 05:44 . 2012-01-18 05:44	104472	----a-w-	c:\windows\system32\LogiDPPApp.exe
2011-12-19 12:45 . 2011-12-19 12:45	146736	----a-w-	c:\windows\system32\drivers\VBoxNetAdp.sys
2011-12-19 12:43 . 2011-12-19 12:43	320816	----a-w-	c:\windows\system32\VBoxNetFltNobj.dll
2011-12-19 12:43 . 2011-12-19 12:43	165680	----a-w-	c:\windows\system32\drivers\VBoxNetFlt.sys
2011-12-15 17:29 . 2011-12-15 17:29	31232	----a-w-	c:\windows\system32\drivers\tap0901.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-01-20 5487488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-05 343168]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-7-29 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-15 158856]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\84B.tmp [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-02-14 736104]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
S0 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-12-05 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424]
S2 ArchiCrypt Sichere Loeschzonen;ArchiCrypt Shredder - Sichere Löschzonen Hilfsservice;c:\program files (x86)\ArchiCrypt\ArchiCrypt Shredder 5\ArchiCryptInjector64.exe [2010-05-04 312032]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-07-29 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-07-29 399416]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-01-19 3027840]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 CompFilter64;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbflt64.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech HD Webcam C510(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [x]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - SASDIFSV
*Deregistered* - ArchiCryptInjector
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-14 10806816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = 
mStart Page = 
mLocal Page = 
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube Download - c:\users\Manuel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Manuel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
LSP: %SystemRoot%\system32\PrxerDrv.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Manuel\AppData\Roaming\Mozilla\Firefox\Profiles\34nask8m.default\
FF - prefs.js: browser.startup.homepage - www.google.de
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108298
FF - user.js: extensions.BabylonToolbar_i.babExt - 
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 14823d1c00000000000000ffd3fc8b8d
FF - user.js: extensions.BabylonToolbar_i.hardId - 14823d1c00000000000000ffd3fc8b8d
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15400
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.170:51
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Half-Life Dedicated Server Update Tool - c:\server\UNWISE.EXE
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\84B.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
   57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}"=hex:51,66,7a,6c,4c,1d,38,12,da,39,34,
   5d,e1,a9,97,05,de,be,2c,e9,c9,ff,c2,38
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E33CF602-D945-461A-83F0-819F76A199F8}"=hex:51,66,7a,6c,4c,1d,38,12,6c,f5,2f,
   e7,77,97,74,03,fc,e6,c2,df,73,ff,dd,ec
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:7b,8a,a4,41,66,fa,cc,01
.
[HKEY_USERS\S-1-5-21-129560445-3818396582-2292848211-1001\Software\SecuROM\License information*]
"datasecu"=hex:61,3b,44,e9,3b,02,14,c3,02,f9,33,8d,06,9f,a0,44,04,ac,ea,91,f1,
   91,26,2f,95,50,95,34,ea,71,02,0e,a1,2c,52,4e,75,b3,cf,48,fa,25,3c,81,64,d1,\
"rkeysecu"=hex:f4,2d,bc,4e,07,00,56,80,ae,94,46,f3,cf,01,cc,35
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-03-07  16:20:49
ComboFix-quarantined-files.txt  2012-03-07 15:20
.
Vor Suchlauf: 11 Verzeichnis(se), 24.830.599.168 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 24.446.562.304 Bytes frei
.
- - End Of File - - 888849A5728AB6FC01524D307880250D
         
--- --- ---

Alt 05.03.2012, 20:37   #13
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



========== Files Created - No Company Name ==========

[2012.03.05 17:17:36 | 148,478,077 | ---- | C] () -- C:\Users\Manuel\Desktop\Aoe game.rar
[2012.03.05 14:12:29 | 000,017,121 | ---- | C] () -- C:\Users\Manuel\Desktop\screen.JPG
[2012.03.05 01:53:58 | 1152,225,384 | ---- | C] () -- C:\Users\Manuel\Desktop\Cyrap musik.rar
[2012.03.05 01:28:17 | 000,341,612 | ---- | C] () -- C:\Users\Manuel\Desktop\scanning.JPG
[2012.03.05 01:25:43 | 000,002,126 | ---- | C] () -- C:\Users\Public\Desktop\MorphVOX Junior.lnk
[2012.03.04 22:37:35 | 000,000,408 | ---- | C] () -- C:\Users\Manuel\Desktop\playlist.asx
[2012.03.04 22:36:29 | 000,000,241 | ---- | C] () -- C:\Users\Manuel\Desktop\listen.pls
[2012.03.04 22:31:43 | 000,000,260 | ---- | C] () -- C:\Users\Manuel\Desktop\Dubstep radio.asx
[2012.03.04 14:21:59 | 000,001,046 | ---- | C] () -- C:\Users\Manuel\Desktop\VirtualDJ Home FREE.lnk
[2012.03.04 13:42:11 | 000,027,726 | ---- | C] () -- C:\Users\Manuel\Desktop\explot.JPG
[2012.03.04 13:38:46 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.03.03 19:13:00 | 000,302,592 | ---- | C] () -- C:\Users\Manuel\Desktop\zkry329u.exe
[2012.03.03 13:31:17 | 000,001,398 | ---- | C] () -- C:\Users\Manuel\Desktop\Free YouTube to MP3 Converter.lnk
[2012.03.03 04:54:19 | 000,000,929 | ---- | C] () -- C:\Users\Public\Desktop\Tunngle beta.lnk
[2012.03.03 03:23:28 | 066,764,644 | ---- | C] () -- C:\Users\Manuel\Desktop\GENETIKK - Puls (_Voodoozirkus_ OUT NOW!)(720p_VP8-Vorbis).webm
[2012.03.03 01:58:16 | 000,019,405 | ---- | C] () -- C:\Users\Manuel\Desktop\Unbenannt.JPG
[2012.03.02 23:01:48 | 000,049,935 | ---- | C] () -- C:\Users\Manuel\Desktop\HB.JPG
[2012.03.02 22:40:36 | 004,218,210 | ---- | C] () -- C:\Users\Manuel\Desktop\Frauenarzt Die Nutte(240p_H.264-AAC).mp4
[2012.03.02 22:40:35 | 006,952,632 | ---- | C] () -- C:\Users\Manuel\Desktop\!!! FRAUENARZT - LASS DiCH GEHN (SPREiZ DEiNE BEiNE) LYRiCS !!!.avi(240p_H.264-AAC).mp4
[2012.03.02 19:02:25 | 000,001,112 | ---- | C] () -- C:\Users\Manuel\Desktop\Siggi Blitz Vorschule 2.lnk
[2012.03.02 18:16:45 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
[2012.03.02 17:12:18 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.03.02 17:12:17 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.03.02 02:35:21 | 000,000,454 | ---- | C] () -- C:\Users\Manuel\Desktop\Hardbase.asx
[2012.03.02 02:34:41 | 000,000,454 | ---- | C] () -- C:\Users\Manuel\Desktop\CoreTime.asx
[2012.03.02 02:33:58 | 000,000,462 | R--- | C] () -- C:\Users\Manuel\Desktop\Housetime.asx
[2012.03.02 02:32:51 | 000,001,258 | ---- | C] () -- C:\Users\Manuel\Desktop\Spybot - Search & Destroy.lnk
[2012.03.02 02:20:35 | 000,001,139 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2012.03.02 02:20:32 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2012.03.02 02:20:32 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012.03.02 02:20:32 | 000,077,312 | ---- | C] () -- C:\Windows\SysWow64\ztvunace26.dll
[2012.03.02 02:20:32 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012.03.01 22:27:52 | 000,000,926 | ---- | C] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2012.03.01 22:23:42 | 000,163,845 | ---- | C] () -- C:\Users\Manuel\Desktop\The_Matrix_Revolutions,_2003,_Keanu_Reeves,_Laurence_Fishburne,_Carrie-Anne_Moss,_Monica_Bellucci.jpg
[2012.03.01 20:18:30 | 1286,430,720 | ---- | C] () -- C:\Users\Manuel\Desktop\WXP_SP2_x64.09.09.iso
[2012.03.01 19:29:08 | 000,000,470 | R--- | C] () -- C:\Users\Manuel\Desktop\technobase!.asx
[2012.03.01 13:39:29 | 000,000,615 | ---- | C] () -- C:\Windows\eReg.dat
[2012.03.01 13:37:18 | 000,001,926 | ---- | C] () -- C:\Users\Manuel\Desktop\Command & Conquer(TM) Generäle.lnk
[2012.03.01 01:13:46 | 000,002,601 | ---- | C] () -- C:\Users\Public\Documents\Global.sw2
[2012.02.29 20:18:41 | 000,001,107 | ---- | C] () -- C:\Users\Manuel\Desktop\Adobe Photoshop CS5 (64 Bit).lnk
[2012.02.29 20:17:30 | 000,001,207 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012.02.29 20:14:16 | 000,001,169 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012.02.29 20:13:34 | 000,001,262 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012.02.29 20:10:26 | 000,001,353 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012.02.29 20:10:17 | 000,001,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012.02.29 04:37:46 | 000,022,580 | ---- | C] () -- C:\Users\Manuel\Desktop\Publication1.ppp
[2012.02.29 04:02:47 | 000,002,473 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif PagePlus X6.lnk
[2012.02.29 04:02:47 | 000,002,120 | ---- | C] () -- C:\Users\Public\Desktop\Serif PagePlus X6.lnk
[2012.02.28 17:10:03 | 035,063,120 | ---- | C] () -- C:\Users\Manuel\wfwfawa.wav
[2012.02.27 03:15:19 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
[2012.02.27 02:11:23 | 000,000,600 | ---- | C] () -- C:\Users\Manuel\AppData\Roaming\winscp.rnd
[2012.02.27 02:11:22 | 000,001,849 | ---- | C] () -- C:\Users\Manuel\Desktop\WinSCP.lnk
[2012.02.26 21:19:24 | 000,032,768 | ---- | C] () -- C:\Windows\SysNative\UUDECODE.EXE
[2012.02.26 21:19:24 | 000,024,576 | ---- | C] () -- C:\Windows\SysNative\UUENCODE.EXE
[2012.02.26 21:19:24 | 000,003,431 | ---- | C] () -- C:\Windows\SysNative\UUDECODE.C
[2012.02.26 21:19:24 | 000,002,507 | ---- | C] () -- C:\Windows\SysNative\UUENCODE.C
[2012.02.26 15:42:33 | 000,001,949 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.02.26 15:42:33 | 000,001,899 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012.02.26 11:43:38 | 028,909,070 | ---- | C] () -- C:\Users\Manuel\Desktop\aGlotze_v10 vlc1.11.rar
[2012.02.24 22:42:23 | 000,000,060 | ---- | C] () -- C:\Users\Manuel\update.bat
[2012.02.24 02:26:59 | 000,002,098 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2012.02.24 02:26:59 | 000,002,086 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2012.02.23 23:41:47 | 000,001,857 | ---- | C] () -- C:\Users\Manuel\Desktop\UseNeXT.lnk
[2012.02.23 05:22:16 | 000,002,012 | -H-- | C] () -- C:\Users\Manuel\Documents\Default.rdp
[2012.02.23 05:02:10 | 000,000,600 | ---- | C] () -- C:\Users\Manuel\AppData\Local\PUTTY.RND
[2012.02.23 00:37:24 | 000,105,781 | ---- | C] () -- C:\Users\Manuel\Documents\dwadwdadwa.jpg
[2012.02.22 22:00:45 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\OpenVPN GUI.lnk
[2012.02.22 21:54:56 | 000,000,241 | ---- | C] () -- C:\Users\Manuel\openvpn-connect.json
[2012.02.22 00:32:19 | 000,001,950 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.02.21 23:41:34 | 000,028,036 | ---- | C] () -- C:\Users\Manuel\Documents\Unbenannt.JPG
[2012.02.21 21:31:24 | 000,000,999 | ---- | C] () -- C:\Users\Manuel\Desktop\DUC 3.0.lnk
[2012.02.21 21:26:59 | 006,864,080 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_21_26_57.wav
[2012.02.21 21:13:02 | 001,336,400 | ---- | C] () -- C:\Users\Manuel\fwafwa.wav
[2012.02.21 21:09:15 | 033,239,120 | ---- | C] () -- C:\Users\Manuel\dwadwa.wav
[2012.02.21 21:01:35 | 052,097,360 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_21_1_33.wav
[2012.02.21 16:26:33 | 076,942,160 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_16_26_31.wav
[2012.02.21 16:19:02 | 014,480,720 | ---- | C] () -- C:\Users\Manuel\ts3_recording_12_02_21_16_18_59.wav
[2012.02.21 01:46:02 | 000,002,544 | ---- | C] () -- C:\Windows\diagwrn.xml
[2012.02.21 01:46:02 | 000,001,890 | ---- | C] () -- C:\Windows\diagerr.xml
[2012.02.18 22:03:26 | 002,486,480 | ---- | C] () -- C:\Users\Manuel\pain multiaccount MELDEN.wav
[2012.02.14 22:45:29 | 000,014,051 | ---- | C] () -- C:\Windows\SysNative\RaCoInst.dat
[2012.02.14 14:17:22 | 000,001,065 | ---- | C] () -- C:\Users\Manuel\Desktop\Firstload.lnk
[2012.02.13 02:23:38 | 000,000,919 | ---- | C] () -- C:\Users\Manuel\Desktop\IDA Pro Free.lnk
[2012.02.12 20:17:06 | 000,007,600 | ---- | C] () -- C:\Users\Manuel\AppData\Local\Resmon.ResmonCfg
[2012.02.11 21:08:11 | 000,001,298 | ---- | C] () -- C:\Users\Public\Desktop\ArchiCrypt Shredder 5.lnk
[2012.02.11 21:08:05 | 000,236,608 | ---- | C] () -- C:\Windows\SysWow64\Shredder.dll
[2012.02.11 20:45:18 | 000,001,019 | ---- | C] () -- C:\Users\Manuel\Desktop\Proxifier.lnk
[2012.02.11 20:45:17 | 000,055,024 | ---- | C] () -- C:\Windows\SysNative\PrxerNsp.dll
[2012.02.11 20:45:17 | 000,054,000 | ---- | C] () -- C:\Windows\SysWow64\PrxerNsp.dll
[2012.02.11 20:32:14 | 000,001,740 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
[2012.02.11 20:32:14 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\Wireshark.lnk
[2012.02.10 03:40:25 | 000,031,744 | ---- | C] () -- C:\Users\Manuel\Desktop\ChangeMAC-2010.exe
[2012.02.10 03:05:59 | 000,000,459 | ---- | C] () -- C:\Users\Manuel\Desktop\Cain.lnk
[2012.02.09 00:50:40 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012.02.08 22:01:51 | 001,588,762 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.02.08 16:19:14 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX Music Maker MX Premium Download-Version.lnk
[2012.02.08 16:08:06 | 000,000,345 | ---- | C] () -- C:\Windows\BeatBox.INI
[2012.02.07 10:09:42 | 000,001,177 | ---- | C] () -- C:\Users\Manuel\Desktop\technomaker.exe.lnk
[2012.02.07 10:08:05 | 000,000,133 | ---- | C] () -- C:\Windows\technomaker.INI
[2012.02.07 10:06:46 | 000,014,182 | ---- | C] () -- C:\Windows\SysWow64\DLLAV32.lib
[2012.02.07 10:03:52 | 000,001,208 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2012.02.06 23:56:20 | 000,002,037 | ---- | C] () -- C:\Users\Manuel\Desktop\JDownloader.lnk
[2012.02.06 23:56:16 | 000,002,001 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.02.06 23:56:16 | 000,001,945 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.02.06 23:56:16 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.02.06 20:28:09 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.01.31 20:28:44 | 000,282,864 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.01.31 20:28:41 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.01.28 17:25:01 | 000,017,408 | ---- | C] () -- C:\Users\Manuel\AppData\Local\WebpageIcons.db
[2012.01.28 16:43:40 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.12.06 03:35:10 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011.12.06 03:35:10 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011.09.19 08:07:46 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2011.09.19 08:07:32 | 000,058,368 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.21 19:56:22 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2010.06.25 18:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll

========== LOP Check ==========

[2012.02.11 21:08:08 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ACShredder5
[2012.02.26 15:42:41 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Canneverbe Limited
[2012.03.02 01:41:54 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DAEMON Tools Lite
[2012.02.29 23:09:11 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DarknessII
[2012.02.13 02:23:53 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Datarescue
[2012.03.03 13:31:38 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoft
[2012.03.03 13:31:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.24 11:30:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\FileZilla
[2012.03.01 04:47:50 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Firstload
[2012.03.05 20:09:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ICQ
[2012.01.28 17:56:25 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Leadertech
[2012.02.16 02:53:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\LolClient
[2012.02.13 01:52:16 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\MAGIX
[2012.03.02 01:53:40 | 000,000,000 | RHSD | M] -- C:\Users\Manuel\AppData\Roaming\MicroUpdate
[2012.02.21 15:25:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Origin
[2012.02.21 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Proxifier
[2012.03.05 01:58:59 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Screaming Bee
[2012.02.29 04:04:01 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Serif
[2012.03.02 02:20:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Simply Super Software
[2012.03.02 02:22:12 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Spamihilator
[2012.02.01 22:12:57 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TeamViewer
[2012.02.24 02:27:06 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Thunderbird
[2012.02.12 21:20:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TrueCrypt
[2012.03.03 18:05:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TS3Client
[2012.03.03 04:56:13 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Tunngle
[2012.03.05 20:00:58 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Uniblue
[2012.03.05 20:09:45 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\UseNeXT
[2009.07.14 06:08:49 | 000,017,010 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.02.11 21:08:08 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ACShredder5
[2012.03.04 20:13:39 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Adobe
[2012.03.03 13:55:24 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Apple Computer
[2012.01.31 15:39:49 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ATI
[2012.02.26 15:42:41 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Canneverbe Limited
[2012.03.02 01:41:54 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DAEMON Tools Lite
[2012.02.29 23:09:11 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DarknessII
[2012.02.13 02:23:53 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Datarescue
[2012.03.03 13:31:38 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoft
[2012.03.03 13:31:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.24 11:30:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\FileZilla
[2012.03.01 04:47:50 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Firstload
[2012.03.05 20:09:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\ICQ
[2012.01.28 16:12:51 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Identities
[2012.01.28 17:56:25 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Leadertech
[2012.02.16 02:53:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\LolClient
[2012.01.28 17:20:49 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Macromedia
[2012.02.13 01:52:16 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\MAGIX
[2012.03.03 19:37:28 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Malwarebytes
[2009.07.14 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Media Center Programs
[2012.02.23 22:36:18 | 000,000,000 | --SD | M] -- C:\Users\Manuel\AppData\Roaming\Microsoft
[2012.03.02 01:53:40 | 000,000,000 | RHSD | M] -- C:\Users\Manuel\AppData\Roaming\MicroUpdate
[2012.01.28 16:56:59 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Mozilla
[2012.02.21 15:25:07 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Origin
[2012.02.21 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Proxifier
[2012.03.05 01:58:59 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Screaming Bee
[2012.02.12 00:07:22 | 000,000,000 | RH-D | M] -- C:\Users\Manuel\AppData\Roaming\SecuROM
[2012.02.29 04:04:01 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Serif
[2012.03.02 02:20:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Simply Super Software
[2012.03.05 20:09:23 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Skype
[2012.03.02 02:22:12 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Spamihilator
[2012.02.01 22:12:57 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TeamViewer
[2012.02.24 02:27:06 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Thunderbird
[2012.02.12 21:20:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TrueCrypt
[2012.03.03 18:05:37 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\TS3Client
[2012.03.03 04:56:13 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Tunngle
[2012.03.05 20:00:58 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Uniblue
[2012.03.05 20:09:45 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\UseNeXT
[2012.02.06 01:59:31 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\vlc
[2012.03.05 13:00:43 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\Winamp
[2012.01.28 17:06:05 | 000,000,000 | ---D | M] -- C:\Users\Manuel\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >
[2012.01.28 17:56:22 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Manuel\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2012.03.05 03:55:40 | 007,253,200 | ---- | M] (Uniblue Systems Ltd ) -- C:\Users\Manuel\AppData\Roaming\Uniblue\RegistryBooster\_temp\registrybooster.exe

< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0033117673c16921\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_38e464dbe521cc7f\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< MD5 for: USER32.DLL >
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll

< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe

< MD5 for: WININIT.EXE >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

< MD5 for: WINLOGON.EXE >
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WS2IFSL.SYS >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2012.03.02 17:12:18 | 000,353,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dxtmsft.dll
[2012.03.02 17:12:18 | 000,223,232 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dxtrans.dll
[2009.07.14 02:15:36 | 000,226,816 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\LocationApi.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 436 bytes -> C:\Users\Manuel\Desktop\Publication1.ppp:SummaryInformation

< End of report >

Alt 05.03.2012, 20:38   #14
xan1m0rphx
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Oh da ist wohl etwas schief gelaufen.. :S
Entschuldige!

Alt 06.03.2012, 11:30   #15
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Standard

Exploit.Java.CVE-2011-3544.jy + Weitere Viren?



Pack das Log gezippt in den Anhang wenn es zu groß/unübersichtlich ist
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Exploit.Java.CVE-2011-3544.jy + Weitere Viren?
beim spielen, dateien, desktop, explorer, explorer.exe, fehler, folge, funktioniert nicht mehr, geblockt, gelöscht, infected, internet, kaspersky, neu, ordner, problem, probleme, registry, rojaner gefunden, security, seite, spiele, spielen, teamspeak, trojaner gefunden, trojaner-board, ungültiges, update, viren, viren?, virus




Ähnliche Themen: Exploit.Java.CVE-2011-3544.jy + Weitere Viren?


  1. Java/Exploit.CVE-2011-3544.BR trojan
    Log-Analyse und Auswertung - 28.11.2012 (14)
  2. AVSCAN hat mehrere Java-Viren JAVA/Agent.M* und Exploits EXP/CVE-2011-3544 gefunden
    Log-Analyse und Auswertung - 15.10.2012 (24)
  3. AviraExploitsfunde:EXP/2011-3544.CZ.2; EXP/Java.Ternub.a.6; EXP/Java.Ternub.a.28 &Fund APPL/HideWindows.31232 in C:\Programme\MioNet\cmd.exe
    Plagegeister aller Art und deren Bekämpfung - 07.10.2012 (33)
  4. Laptop befallen von: Exploit.Java.cve-2011-3544.ji, Was tun?
    Plagegeister aller Art und deren Bekämpfung - 09.08.2012 (12)
  5. 14 Funde bei AntiVir nach erscheinen des JAVA Logos (EXP/2008-5353.AR,EXP/CVE-2011-3544.CF)
    Log-Analyse und Auswertung - 03.08.2012 (25)
  6. Desinfec't 2012/Kaspersky findet Exploit.Java.CVE-2011-3544.** und Exploit.Java.CVE-2012-0507.**
    Plagegeister aller Art und deren Bekämpfung - 22.06.2012 (21)
  7. Desinfec't 2012/Kaspersky findet Exploit.Java.CVE-2011-3544.** und Exploit.Java.CVE-2012-0507.**
    Mülltonne - 11.06.2012 (0)
  8. Panda Cloud AntiVirus PRo findet zwei Exploit CVE-2011-3544 Trojaner
    Log-Analyse und Auswertung - 17.05.2012 (20)
  9. Java-Script Virus: Exploit: Java/CVE-2011-3544.gen!E
    Plagegeister aller Art und deren Bekämpfung - 04.05.2012 (13)
  10. EXP/CVE-2011-3544.BY, EXP/JAVA.Ternub.Gen Wie bekomm ich die Viren weg/ Hab ich die noch?
    Plagegeister aller Art und deren Bekämpfung - 08.04.2012 (4)
  11. 3 Viren: EXP/2011-3544.CZ und EXP/JAVA.Loader.Gen und EXP/CVE-2012-0507
    Plagegeister aller Art und deren Bekämpfung - 06.04.2012 (2)
  12. Trojaner Exploit.Java.CVE-2011-3544.jh & Virus P2P-Worm.Win23.Palevo.nzl
    Plagegeister aller Art und deren Bekämpfung - 04.04.2012 (5)
  13. Avira meldet EXP/2011-3544.BW.1 und JAVA/Dldr.OpenS.H
    Plagegeister aller Art und deren Bekämpfung - 27.03.2012 (5)
  14. Java:CVE-2011-3544-AX und viele versteckte Objekte entdeckt, Rechner bockt
    Log-Analyse und Auswertung - 21.03.2012 (51)
  15. 2 Viren gefunden (Exploit) - EXP/CVE-2011-3544.E und EXP/CVE-2011-3544.J
    Plagegeister aller Art und deren Bekämpfung - 20.02.2012 (30)
  16. exploit.java.cve-2011-3544 irreparabel
    Plagegeister aller Art und deren Bekämpfung - 07.02.2012 (23)
  17. Windows Security Center 2012, Java/CVE-2011-3544.D und weitere Malware?
    Log-Analyse und Auswertung - 08.12.2011 (5)

Zum Thema Exploit.Java.CVE-2011-3544.jy + Weitere Viren? - Hallo Trojaner-Board User! Und zwar ich eine ein großes Problem! Vor 2 Tagen ungefähr war ich auf der Seite: www.serials.ws, hatte allerdings mein Kaspersky Internet Security 2012 Deaktiviert! (Das war - Exploit.Java.CVE-2011-3544.jy + Weitere Viren?...
Archiv
Du betrachtest: Exploit.Java.CVE-2011-3544.jy + Weitere Viren? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.