|
Log-Analyse und Auswertung: Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wirdWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.03.2012, 16:50 | #1 |
| Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird Hallo zusammen, also ich habe das Problem das wenn ich den Rechner starte, egal in welchem Modus, bekomme ich immer einen Weißen Bildschirm mit der Aufschrift "Bitte warten Sie während die Verbindung hergestellt wird". Hab das Problem auch schon gesucht aber keine allgemein gültige Lösung gefunden. Anbei das OTL Log. Code:
ATTFilter OTL logfile created on: 3/19/2012 7:28:45 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows 7 Professional (Version = 6.1.7600) - Type = System Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 125.00 Gb Total Space | 84.50 Gb Free Space | 67.60% Space Free | Partition Type: NTFS Drive D: | 107.88 Gb Total Space | 23.44 Gb Free Space | 21.73% Space Free | Partition Type: NTFS Drive X: | 3.73 Gb Total Space | 3.33 Gb Free Space | 89.26% Space Free | Partition Type: FAT Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service) SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework) SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp) SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield) SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent) SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire) SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr) SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager) SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc) SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim) SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService) SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService) SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service) SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage) SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService) SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec) SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr) SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (mfeavfk01) DRV - File not found [Kernel | On_Demand] -- -- (FirehkMP) DRV - File not found [Kernel | On_Demand] -- -- (Firehk) DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp) DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk) DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet) DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk) DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk) DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk) DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk) DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek) DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK) DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk) DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn) DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog) DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp) DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter) DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm) DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ) DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm) DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM) DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM) DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl) DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM) DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad) DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr) DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis) DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum) DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd) DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R) DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps) DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard) DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler) DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt) DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R) DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv) DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr) DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus) DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc) DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It) DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap) DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID) DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID) DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV) DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom) DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M] [2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [7Rxb5FismTZydeX] C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation) O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation) O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.) O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.) O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.) O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation) O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.) O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals) O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.) O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf) O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O20 - HKLM Winlogon: UserInit - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O24 - Desktop WallPaper: O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/03/19 16:07:56 | 000,000,000 | ---D | C] -- C:\_OTL [2012/03/19 03:15:04 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe [2012/03/19 03:15:03 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll [2012/03/19 03:15:00 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll [2012/03/19 03:14:45 | 000,826,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll [2012/03/11 11:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\RavensburgerTipToi [2012/03/11 11:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Ravensburger tiptoi [2012/03/09 06:10:40 | 000,000,000 | ---D | C] -- C:\xmldm [2012/02/29 09:53:53 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012/02/29 09:53:01 | 000,180,488 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE [2012/02/22 15:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc [2012/02/22 15:47:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Shared [2012/02/22 15:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Corporation [2012/02/22 15:35:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe ========== Files - Modified Within 30 Days ========== [2012/03/19 11:13:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/03/19 11:13:02 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini [2012/03/19 11:09:55 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys [2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/03/19 08:45:59 | 000,000,074 | ---- | M] () -- C:\Windows\System32\settings.bin [2012/03/19 08:40:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job [2012/03/19 03:01:52 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2012/03/19 02:53:13 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job [2012/03/19 02:50:13 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012/03/19 02:50:13 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012/03/19 02:50:13 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/03/19 02:50:13 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/03/05 16:25:03 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI [2012/02/29 09:53:46 | 000,180,488 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE [2012/02/22 16:10:56 | 000,476,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012/02/22 15:47:55 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Reader for PC.lnk [2012/02/22 15:47:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc ========== Files Created - No Company Name ========== [2012/02/22 15:47:55 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Reader for PC.lnk [2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp [2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll [2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe [2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp [2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat [2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat [2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini [2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin [2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll [2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll [2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll [2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll [2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll [2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini [2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI [2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini [2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll [2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin [2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll [2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin [2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin [2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll [2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll [2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll [2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll [2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini [2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4 [2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll [2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll [2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll [2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll [2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll [2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI ========== LOP Check ========== [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications [2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail [2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom [2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia [2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount [2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache [2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite [2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi [2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall [2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb [2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip [2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater [2012/02/06 03:23:06 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
19.03.2012, 16:59 | #2 |
/// Malware-holic | Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird hi,
__________________auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort rein: Code:
ATTFilter :OTL O20 - HKLM Winlogon: Shell - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O4 - HKLM..\Run: [7Rxb5FismTZydeX] C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) :Files C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist. • Klicke nun bitte auf den Fix Button. es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick. wenn dies nicht funktioniert, bitte den fix manuell eintragen. dann klicke erneut den fix buton. pc startet evtl. neu. wenn ja, nimm die cd aus dem laufwerk, windows sollte nun normal starten und die otl.txt öffnen, log posten bitte. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! Drücke bitte die + E Taste.
__________________ |
19.03.2012, 20:35 | #3 |
| Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird Vielen danke erst mal, der Rechner bootet wieder ganz normal.
__________________Ich hoffe mal der Rest passt auch. OTL Logfile: Code:
ATTFilter OTL logfile created on: 3/19/2012 7:28:45 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows 7 Professional (Version = 6.1.7600) - Type = System Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 125.00 Gb Total Space | 84.50 Gb Free Space | 67.60% Space Free | Partition Type: NTFS Drive D: | 107.88 Gb Total Space | 23.44 Gb Free Space | 21.73% Space Free | Partition Type: NTFS Drive X: | 3.73 Gb Total Space | 3.33 Gb Free Space | 89.26% Space Free | Partition Type: FAT Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service) SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework) SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp) SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield) SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent) SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire) SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr) SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager) SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc) SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim) SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService) SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService) SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service) SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage) SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService) SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec) SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr) SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (mfeavfk01) DRV - File not found [Kernel | On_Demand] -- -- (FirehkMP) DRV - File not found [Kernel | On_Demand] -- -- (Firehk) DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp) DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk) DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet) DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk) DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk) DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk) DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk) DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek) DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK) DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk) DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn) DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog) DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp) DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter) DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm) DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ) DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm) DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM) DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM) DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl) DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM) DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad) DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr) DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis) DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum) DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd) DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R) DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps) DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard) DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler) DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt) DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R) DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv) DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr) DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus) DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc) DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It) DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap) DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID) DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID) DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV) DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom) DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M] [2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [7Rxb5FismTZydeX] C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation) O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation) O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.) O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.) O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.) O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation) O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.) O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals) O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.) O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf) O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O20 - HKLM Winlogon: UserInit - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O24 - Desktop WallPaper: O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/03/19 16:07:56 | 000,000,000 | ---D | C] -- C:\_OTL [2012/03/19 03:15:04 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe [2012/03/19 03:15:03 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll [2012/03/19 03:15:00 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll [2012/03/19 03:14:45 | 000,826,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll [2012/03/11 11:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\RavensburgerTipToi [2012/03/11 11:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Ravensburger tiptoi [2012/03/09 06:10:40 | 000,000,000 | ---D | C] -- C:\xmldm [2012/02/29 09:53:53 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012/02/29 09:53:01 | 000,180,488 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE [2012/02/22 15:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc [2012/02/22 15:47:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Shared [2012/02/22 15:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Corporation [2012/02/22 15:35:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe ========== Files - Modified Within 30 Days ========== [2012/03/19 11:13:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/03/19 11:13:02 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini [2012/03/19 11:09:55 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys [2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/03/19 08:45:59 | 000,000,074 | ---- | M] () -- C:\Windows\System32\settings.bin [2012/03/19 08:40:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job [2012/03/19 03:01:52 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2012/03/19 02:53:13 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job [2012/03/19 02:50:13 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012/03/19 02:50:13 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012/03/19 02:50:13 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/03/19 02:50:13 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/03/05 16:25:03 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI [2012/02/29 09:53:46 | 000,180,488 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE [2012/02/22 16:10:56 | 000,476,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012/02/22 15:47:55 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Reader for PC.lnk [2012/02/22 15:47:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc ========== Files Created - No Company Name ========== [2012/02/22 15:47:55 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Reader for PC.lnk [2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp [2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll [2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe [2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp [2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat [2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat [2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini [2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin [2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll [2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll [2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll [2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll [2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll [2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini [2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI [2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini [2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll [2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin [2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll [2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin [2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin [2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll [2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll [2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll [2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll [2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini [2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4 [2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll [2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll [2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll [2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll [2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll [2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI ========== LOP Check ========== [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications [2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail [2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom [2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia [2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount [2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache [2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite [2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi [2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall [2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb [2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip [2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater [2012/02/06 03:23:06 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > [/CODE] |
19.03.2012, 20:50 | #4 |
| Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird Ich habe nun auch den Upload versucht, aber leider bekomm ich den "Link zum Thema im Forum" nicht hin. Habs mit dem Thema "Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird" probiert, aber das scheint wohl nicht richtig zu sein? |
19.03.2012, 21:32 | #5 |
/// Malware-holic | Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird welches problem gibts da, link aus der adress zeile kopieren und dort einfügen. dann gehts
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
19.03.2012, 22:37 | #6 |
| Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird Sorry finde die Beschreibung nicht ganz so klar. Hatte Sie auf jeden Fall falsch verstanden. Nu is gut und das Ding ist oben. |
20.03.2012, 12:21 | #7 |
/// Malware-holic | Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird hi bis wir fertig sind, wird nur auf den für die reinigung nötigen seiten gesurft, nirgendwo anders. Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde! Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
Themen zu Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird |
adobe, agent, autorun, bho, bildschirm, bitte warten, browser, cdrom, defender, explorer, explorer.exe, firefox, format, ics, logfile, microsoft, pdf creator, plug-in, problem, registry, scan, software, system32, trojaner auf der festplatte, version=1.0, virusscan, vodafone, wallpaper, win32, winlogon, wireless |