|
Plagegeister aller Art und deren Bekämpfung: Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 EuroWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.03.2012, 22:03 | #1 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro Hallo zusammen Wie schon andere vor mir beschrieben haben, ich habe mir etwas eingefangen, wodurch nach einer Weile im internet stehts ein schwarzer Bildschirm erscheint, der mit der deutschen Flagge umrahmt ist. Ich werde aufgefordert aufgrund eienr Virenverseuchung 50 Euro für ein Sicherheitsupdate zu bezahlen und dies per UKash zu tun. Wenn ich den Rechner wieder neu starte, kommt nach einer bestimmten Zeit wieder die gleiche Meldung. Momentan bin ich mit dem internet normal verbunden. Danke schonmal im Voraus |
23.03.2012, 16:28 | #2 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro hi
__________________neustart, f8 drücken abgesicherter modus mit netzwerk wählen, im betroffenen konto anmelden, internet verbindung herstellen. Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
24.03.2012, 12:43 | #3 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro OTL Logfile:
__________________Code:
ATTFilter OTL logfile created on: 24.03.2012 12:18:28 - Run 1 OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\***\My Documents\Downloads Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000807 | Country: Switzerland | Language: DES | Date Format: dd.MM.yyyy 2.99 Gb Total Physical Memory | 2.62 Gb Available Physical Memory | 87.54% Memory free 5.83 Gb Paging File | 5.63 Gb Available in Paging File | 96.55% Paging File free Paging file location(s): D:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.31 Gb Total Space | 3.30 Gb Free Space | 11.25% Space Free | Partition Type: NTFS Drive D: | 45.22 Gb Total Space | 7.38 Gb Free Space | 16.32% Space Free | Partition Type: NTFS Unable to calculate disk information. Computer Name: HSG04712-N | User Name: *** | NOT logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.03.24 11:45:37 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\***\My Documents\Downloads\OTL.exe PRC - [2009.03.06 11:28:26 | 001,443,144 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe PRC - [2006.02.08 11:28:12 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe ========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV - [2010.05.07 17:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) [Auto | Unknown] -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv) SRV - [2010.03.18 15:11:17 | 003,391,488 | ---- | M] (IBM Corp) [Auto | Unknown] -- C:\Program Files\IBM\Lotus\Notes\nsd.exe -- (Lotus Notes Diagnostics) SRV - [2010.02.17 22:07:32 | 001,568,768 | ---- | M] (BrainWare Consulting & Development) [Auto | Unknown] -- C:\WINDOWS\Columbus.exe -- (bwColumbus) SRV - [2009.09.29 10:30:00 | 000,058,760 | ---- | M] (IBM Corp) [Auto | Unknown] -- C:\Program Files\IBM\Lotus\Notes\ntmulti.exe -- (Multi-user Cleanup Service) SRV - [2009.03.09 08:51:47 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Unknown] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009.03.06 11:28:30 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr) SRV - [2009.03.06 11:28:30 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr) SRV - [2009.03.06 11:28:26 | 002,440,120 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus) SRV - [2009.03.06 11:28:26 | 001,795,400 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService) SRV - [2009.03.06 11:28:26 | 000,320,840 | ---- | M] (Symantec Corporation) [On_Demand | Unknown] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC) SRV - [2008.07.22 19:06:29 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand | Unknown] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate) SRV - [2008.07.18 06:58:46 | 002,549,248 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Auto | Unknown] -- C:\WINDOWS\system32\hasplms.exe -- (hasplms) SRV - [2008.02.22 11:40:20 | 000,475,136 | ---- | M] (Dell Inc.) [Auto | Unknown] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC) SRV - [2007.09.28 15:05:16 | 000,128,360 | ---- | M] (TOSHIBA CORPORATION) [Auto | Unknown] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service) SRV - [2007.05.10 09:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) [Auto | Unknown] -- C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe -- (STacSV) SRV - [2007.02.21 10:19:40 | 000,294,912 | ---- | M] (Intel(R) Corporation) [Auto | Unknown] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel(R) SRV - [2005.01.21 14:07:16 | 000,081,920 | ---- | M] (TerraNovum) [Auto | Unknown] -- C:\WINDOWS\system32\PMService.exe -- (EPA_GPO_PMService) Energy Star(TM) SRV - [2004.08.27 09:34:52 | 001,445,912 | ---- | M] (Cisco Systems, Inc.) [Auto | Unknown] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2004.08.04 02:56:48 | 000,089,088 | ---- | M] (Microsoft Corporation) [Unknown (-1) | Unknown] -- C:\WINDOWS\system32\wbem\wmiaprpl.dll -- (WmiApRpl) SRV - [2004.02.17 15:50:28 | 000,287,888 | ---- | M] (Funk Software, Inc.) [Auto | Unknown] -- C:\Program Files\Columbus\Proxy Host\Ph32Svc.exe -- (ProxyHostService) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Unknown] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Unknown] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDCOMP) DRV - File not found [Kernel | System | Unknown] -- -- (PCIDump) DRV - File not found [Kernel | System | Unknown] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Unknown] -- -- (i2omgmt) DRV - File not found [Kernel | System | Unknown] -- -- (Changer) DRV - [2012.01.23 13:07:07 | 000,167,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\WpsHelper.sys -- (WpsHelper) DRV - [2012.01.23 13:05:40 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120124.035\NAVEX15.SYS -- (NAVEX15) DRV - [2012.01.23 13:05:40 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120124.035\NAVENG.SYS -- (NAVENG) DRV - [2011.11.15 05:04:12 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) DRV - [2011.11.15 05:04:12 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2010.11.10 03:49:50 | 004,323,040 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech HD Webcam C310(UVC) DRV - [2010.11.10 03:48:12 | 000,283,744 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS) DRV - [2010.05.07 17:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon) DRV - [2009.05.13 07:20:37 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent) DRV - [2009.04.30 21:55:58 | 002,687,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI) DRV - [2009.03.06 11:28:34 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys -- (WPS) DRV - [2009.03.06 11:28:32 | 000,319,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL) DRV - [2009.03.06 11:28:32 | 000,279,600 | ---- | M] (Symantec Corporation) [File_System | System | Unknown] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP) DRV - [2009.03.06 11:28:32 | 000,043,824 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX) DRV - [2009.03.06 11:28:28 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Unknown] -- C:\WINDOWS\system32\drivers\SysPlant.sys -- (SysPlant) DRV - [2009.03.06 11:28:28 | 000,049,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\Teefer2.sys -- (Teefer2) DRV - [2009.03.06 11:28:22 | 000,191,536 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI) DRV - [2009.03.06 11:28:22 | 000,027,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV) DRV - [2009.03.06 11:28:20 | 000,420,400 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv) DRV - [2009.03.06 11:28:18 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon) DRV - [2008.03.18 15:45:34 | 000,350,720 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\aksfridge.sys -- (aksfridge) DRV - [2008.02.18 14:49:46 | 000,100,992 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2008.02.15 14:01:06 | 000,131,712 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (tosrfbd) DRV - [2008.02.12 11:14:50 | 000,586,240 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (hardlock) DRV - [2008.01.31 14:55:06 | 000,074,240 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\Tosrfhid.sys -- (Tosrfhid) DRV - [2007.11.29 08:45:44 | 000,036,608 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (tosrfbnp) DRV - [2007.10.18 13:25:00 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb) DRV - [2007.10.02 10:43:22 | 000,064,128 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom) DRV - [2007.09.11 14:40:30 | 000,238,976 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp) DRV - [2007.09.11 14:40:30 | 000,046,336 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\akshhl.sys -- (akshhl) DRV - [2007.09.11 14:40:30 | 000,014,976 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb) DRV - [2007.09.04 10:50:00 | 000,031,744 | ---- | M] (CSR, plc) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\csrbcxp.sys -- (CSRBC) DRV - [2007.06.25 17:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2007.05.10 09:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2007.03.26 09:19:00 | 000,062,208 | ---- | M] (O2Micro) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\oz776.sys -- (guardian2) DRV - [2007.02.25 05:05:24 | 002,203,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel(R) DRV - [2007.02.21 10:16:12 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans) DRV - [2007.02.16 14:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2006.11.02 17:47:36 | 000,989,696 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV) DRV - [2006.11.02 17:47:00 | 000,209,152 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL) DRV - [2006.11.02 17:46:56 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2006.10.10 18:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte) DRV - [2005.08.12 15:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\APPDRV.SYS -- (APPDRV) DRV - [2005.01.07 04:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds) DRV - [2004.08.27 09:30:38 | 000,269,387 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2004.08.04 02:56:48 | 000,089,088 | ---- | M] (Microsoft Corporation) [Unknown (-1) | Unknown (-1) | Unknown] -- C:\WINDOWS\system32\wbem\wmiaprpl.dll -- (WmiApRpl) DRV - [2004.02.17 15:51:50 | 000,061,008 | ---- | M] () [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\phw2ksys.sys -- (ProxyHostDriver) DRV - [2004.02.17 15:51:48 | 000,011,472 | ---- | M] (Funk Software, Inc.) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\phmmini.sys -- (ProxyHostMirrorDisplay) DRV - [2004.02.02 11:29:00 | 000,139,604 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE) DRV - [2003.08.28 20:40:26 | 000,189,792 | ---- | M] (Zone Labs Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant) DRV - [2003.05.01 12:26:34 | 000,005,220 | R--- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA) DRV - [2002.07.17 07:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Unknown] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32) DRV - [2000.07.24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\BRPAR.SYS -- (BrPar) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {1FDB14C0-10CF-446A-94E9-7053AEF0B536} IE - HKLM\..\SearchScopes\{1FDB14C0-10CF-446A-94E9-7053AEF0B536}: "URL" = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Universität St.Gallen | HSG Startseite IE - HKCU\..\SearchScopes,DefaultScope = {085AD17E-5D9A-4C95-8A8A-E54AFFD0F88C} IE - HKCU\..\SearchScopes\{085AD17E-5D9A-4C95-8A8A-E54AFFD0F88C}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKCU\..\SearchScopes\{8FB4398C-9165-4575-B080-FCB87AAC683F}: "URL" = Google IE - HKCU\..\SearchScopes\{ADD387A9-0A33-4466-A7A2-3E15DA891918}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.unisg.ch/" FF - prefs.js..extensions.enabledItems: {C598822D-6E25-4ADB-9137-D52C050F315C}:2.6 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@fronter.com/FronterOES: C:\Program Files\Fronter\Fronter OES\npfronter_oes2.dll ( ) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.10.835: File not found FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1136: File not found FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.847: File not found FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.03.17 15:03:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.30 09:20:46 | 000,000,000 | ---D | M] [2008.07.01 15:31:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\***\Application Data\mozilla\Extensions [2011.09.26 21:57:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\***\Application Data\mozilla\Firefox\Profiles\0a7tqgwu.default\extensions [2010.06.24 13:16:23 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\***\Application Data\mozilla\Firefox\Profiles\0a7tqgwu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011.09.26 21:57:39 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Documents and Settings\***\Application Data\mozilla\Firefox\Profiles\0a7tqgwu.default\extensions\DeviceDetection@logitech.com [2011.11.09 05:47:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions () (No name found) -- C:\DOCUMENTS AND SETTINGS\***\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0A7TQGWU.DEFAULT\EXTENSIONS\{C598822D-6E25-4ADB-9137-D52C050F315C}.XPI [2010.08.19 07:52:42 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2012.03.17 15:03:55 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.08.19 07:52:40 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.02.15 21:41:18 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.02.15 21:41:18 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.02.15 21:41:18 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.02.15 21:41:18 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.02.15 21:41:18 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.02.15 21:41:18 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.04.30 07:05:24 | 000,168,952 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 093qpeuqpmz6ebfa.com #[Trojan.TrustedZone] O1 - Hosts: 127.0.0.1 0bucksforpornmovie.com #[Malicious.Links.Codec] O1 - Hosts: 127.0.0.1 0ki.ru #[TROJ_SMALL.KYZ] O1 - Hosts: 127.0.0.1 0nlyzoo.com #[Malicious.Links] O1 - Hosts: 127.0.0.1 1.hao929.cn #[IFrame.Exploit] O1 - Hosts: 127.0.0.1 12345dns.net #[Malicious.Links.Codec] O1 - Hosts: 127.0.0.1 16643.kit.carpediem.fr #[HJTH.Carpediem Dialer] O1 - Hosts: 127.0.0.1 16755.dialer.lincassa.com #[HJTH.Carpediem Dialer] O1 - Hosts: 127.0.0.1 18girl-av.com #[Javascript.Exploit] O1 - Hosts: 127.0.0.1 1amanda.info #[Spamdexing] O1 - Hosts: 127.0.0.1 1pharma.net #[Spamdexing] O1 - Hosts: 127.0.0.1 1-se.com #[CWS.Aboutblank][W32.Tuoba.Trojan] O1 - Hosts: 127.0.0.1 1speed.info #[Malicious.Links] O1 - Hosts: 127.0.0.1 1stmovieclub.net #[Malicious.Links.Codec] O1 - Hosts: 127.0.0.1 2117966.net #[IFrame.Exploit][server down?] O1 - Hosts: 127.0.0.1 22pics.com #[Malicious.Links.Codec] O1 - Hosts: 127.0.0.1 235-video-clip.info #[Spamdexing] O1 - Hosts: 127.0.0.1 266-video-the-tube.info #[Malicious.Links.Codec] O1 - Hosts: 127.0.0.1 2k-sex.com #[Porn-Dialer.Win32.Madial.a] O1 - Hosts: 127.0.0.1 2z0o.net #[Trojan.Popper] O1 - Hosts: 127.0.0.1 3xpicsmovies.com #[Malicious.Links] O1 - Hosts: 127.0.0.1 404traff.com #[Spamdexing] O1 - Hosts: 127.0.0.1 40ch.com #[Spamdexing.Codec] O1 - Hosts: 127.0.0.1 41m.com #[HJTH.XXXToolbar Variant][Trojan.Clicker.BL] O1 - Hosts: 3057 more lines... O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (NCH EN Toolbar) - {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files\NCH_EN\prxtbNCH_.dll (Conduit Ltd.) O2 - BHO: (CmjBrowserHelperObject Object) - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll (Mindjet) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (NCH EN Toolbar) - {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files\NCH_EN\prxtbNCH_.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (NCH EN Toolbar) - {37483B40-C254-4A72-BDA4-22EE90182C1E} - C:\Program Files\NCH_EN\prxtbNCH_.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) O4 - HKLM..\Run: [EPA_EZ_GPO_Tool] C:\WINDOWS\system32\EZ_GPO_Tool.exe (Environmental Protection Agency) O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [HP LaserJet P2030 Install] "C:\Program Files\HP\HP LaserJet P2030 Series\Setup.exe" AFTERREBOOT=YES File not found O4 - HKLM..\Run: [HPUsageTracking] c:\Program Files\HP\HP UT\bin\hppusg.exe () O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation) O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation) O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.) O4 - HKLM..\Run: [ProxyHostTrayIcon] C:\Program Files\Columbus\Proxy Host\phtray.exe (Funk Software, Inc.) O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.) O4 - HKLM..\Run: [StartColumbus] C:\WINDOWS\Columbus.exe (BrainWare Consulting & Development) O4 - HKLM..\Run: [Symantec AntiVirus überprüfen] C:\WINDOWS\system32\SAVchecker.exe (Universität St. Gallen) O4 - HKCU..\Run: [bürofit mit UniSport] \\cl-stud-data\unisg-apps$\standard\bürofit\ergosport.exe Autostart File not found O4 - HKCU..\Run: [ClearRumborakLastFile] C:\gs\Rumborak\RedMon_LastFiler.exe (University of St. Gallen) O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Vid HD\Vid.exe (Logitech Inc.) O4 - HKCU..\Run: [SkypePM] C:\Documents and Settings\***\Local Settings\Application Data\Skype\SkypePM.exe (Microsoft Corporation) O4 - HKCU..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Notes\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090922-1655\preload.exe () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{6DC47739-3BB0-4494-A43D-193BF54070AE}\Icon3E5562ED7.ico () O4 - Startup: C:\Documents and Settings\***\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\***\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoOnlinePrintsWizard = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPublishingWizard = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 1 = \\DC-Antares\Netlogon\callHSGPrinters.vbs O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonType = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 1 O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) O15 - HKLM\..Trusted Domains: unisg.ch ([]* in Local intranet) O15 - HKLM\..Trusted Ranges: Range1 ([*] in Local intranet) O15 - HKCU\..Trusted Domains: unisg.ch ([]* in Local intranet) O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet) O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://studmaillz.unisg.ch/iNotes6W.cab (iNotes6 Class) O16 - DPF: {6CEDB6B5-4859-4E3A-BCA2-FB8E565B8AD9} Reg Error: Value error. (Reg Error: Value error.) O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} C:\WINDOWS\system32\dwa85W.cab (IBM Lotus iNotes 8.5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37825.2838541667 (Reg Error: Key error.) O16 - DPF: {A4E84B61-1174-4309-87F0-E795A64158CC} Reg Error: Value error. (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} Reg Error: Value error. (Reg Error: Value error.) O16 - DPF: LearningSpace5 Chat Reg Error: Value error. (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O16 - DPF: Sametime BroadCast Client ST25PF1 hxxp://gemma.unisg.ch/sametime/stbroadcastclient/STBroadcastClient.cab (Reg Error: Key error.) O16 - DPF: Sametime Meeting Room Client ST25PF1 Reg Error: Value error. (Reg Error: Key error.) O16 - DPF: Sametime MRC 651 Reg Error: Value error. (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Unisg.ch O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7702EBD5-EAA3-463C-8B49-835206208D1D}: Domain = unisg.ch O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84FEA397-B897-4C4F-9983-CE4FF20AFDD0}: DhcpNameServer = 192.168.2.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 0 O32 - AutoRun File - [2008.04.30 10:19:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{25de3ae6-0a25-11de-b656-001e37f651eb}\Shell - "" = AutoRun O33 - MountPoints2\{25de3ae6-0a25-11de-b656-001e37f651eb}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{25de3ae6-0a25-11de-b656-001e37f651eb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{424bd4d2-e913-11e0-bd9d-001c234afae0}\Shell\AutoRun\command - "" = F:\urDrive.exe O33 - MountPoints2\{5399f2ee-4e44-11dd-b4e8-001e37f651eb}\Shell - "" = AutoRun O33 - MountPoints2\{5399f2ee-4e44-11dd-b4e8-001e37f651eb}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5399f2ee-4e44-11dd-b4e8-001e37f651eb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{5399f2f0-4e44-11dd-b4e8-001e37f651eb}\Shell - "" = AutoRun O33 - MountPoints2\{5399f2f0-4e44-11dd-b4e8-001e37f651eb}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{5399f2f0-4e44-11dd-b4e8-001e37f651eb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{6618e008-8eff-11dd-b57e-001e37f651eb}\Shell - "" = AutoRun O33 - MountPoints2\{6618e008-8eff-11dd-b57e-001e37f651eb}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{6618e008-8eff-11dd-b57e-001e37f651eb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{8c4d5bf8-fb64-11de-b880-001c234afae0}\Shell\AutoRun\command - "" = F:\setup.exe O33 - MountPoints2\{d1e9a278-ae68-11de-b7bf-001e37f651eb}\Shell - "" = AutoRun O33 - MountPoints2\{d1e9a278-ae68-11de-b7bf-001e37f651eb}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{d1e9a278-ae68-11de-b7bf-001e37f651eb}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL SanDisk-Games.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML) ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1 ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 10.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7 ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789) ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366) ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {f5de1b93-9d38-416b-b09e-aa85a8e84309} - Q818529 ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{2E18FDF6-1C8E-4813-A7D9-22DEAF1F0349} - RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found CREATERESTOREPOINT Error creating restore point. ========== Files/Folders - Created Within 30 Days ========== [2012.03.19 20:24:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Desktop\Wohnungsanzeigen Frankfurt [2012.03.19 13:36:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\My Documents\sTEUERERKLÄRUNG SCHWEIZ [2012.03.12 07:30:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\WLANProfiles [2012.03.07 15:51:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Desktop\Paper new final [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.03.24 12:12:11 | 000,435,476 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012.03.24 12:12:11 | 000,069,362 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012.03.24 12:07:43 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.03.24 12:05:00 | 000,000,394 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{04717CE6-353B-49D3-9235-3B4F523B0AAC}.job [2012.03.24 11:59:07 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk [2012.03.24 11:50:14 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Desktop anzeigen.scf [2012.03.24 11:30:24 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.03.23 12:54:04 | 000,002,741 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Skype.lnk [2012.03.23 11:59:45 | 000,001,919 | ---- | M] () -- C:\Documents and Settings\***\My Documents\2560x1024_20100108 Büro.dsv [2012.03.23 11:46:43 | 000,153,543 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Ausbildungsvetrag-AFF2010.pdf [2012.03.23 11:19:59 | 000,005,691 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Tauglichkeitsattest.pdf [2012.03.23 11:19:44 | 000,024,938 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Bewerberfragebogen.pdf [2012.03.23 08:15:00 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\SAVChecker.job [2012.03.22 21:19:27 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\***\defogger_reenable [2012.03.19 21:22:09 | 000,000,207 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Arbeitslosen SG.url [2012.03.16 16:50:49 | 000,057,652 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Regression EvRigor-GoalFulfillment.spv [2012.03.12 15:01:41 | 000,001,508 | ---- | M] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator (2).lnk [2012.03.12 09:02:10 | 000,034,460 | ---- | M] () -- C:\Documents and Settings\***\Desktop\KTI_Projektabschluss_Merkblatt_d[1].pdf [2012.03.07 14:56:34 | 000,023,201 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Relationship Earlyinvest GoalFulfillment.spv [2012.02.27 13:24:32 | 000,000,404 | ---- | M] () -- C:\Documents and Settings\***\.JavaPowUpload.properties [2012.02.24 08:21:52 | 000,001,047 | ---- | M] () -- C:\Documents and Settings\***\Start Menu\Programs\Startup\Dropbox.lnk [2012.02.24 08:21:52 | 000,001,047 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Dropbox.lnk [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.03.23 11:19:59 | 000,005,691 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Tauglichkeitsattest.pdf [2012.03.23 11:19:44 | 000,024,938 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Bewerberfragebogen.pdf [2012.03.23 11:19:24 | 000,153,543 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Ausbildungsvetrag-AFF2010.pdf [2012.03.22 21:19:27 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\***\defogger_reenable [2012.03.19 21:21:53 | 000,000,207 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Arbeitslosen SG.url [2012.03.16 16:48:27 | 000,057,652 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Regression EvRigor-GoalFulfillment.spv [2012.03.12 15:01:41 | 000,001,508 | ---- | C] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator (2).lnk [2012.03.12 09:02:10 | 000,034,460 | ---- | C] () -- C:\Documents and Settings\***\Desktop\KTI_Projektabschluss_Merkblatt_d[1].pdf [2012.03.07 14:56:33 | 000,023,201 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Relationship Earlyinvest GoalFulfillment.spv [2011.10.07 16:38:17 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\hpsfs.dll [2010.11.26 15:06:50 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010.11.10 03:45:32 | 000,102,744 | ---- | C] () -- C:\WINDOWS\System32\LogiDPPApp.exe [2010.11.10 03:45:30 | 010,871,128 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll [2010.11.10 03:45:20 | 000,316,248 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll [2010.05.07 17:46:36 | 000,014,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll [2010.05.07 17:43:30 | 000,025,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys ========== LOP Check ========== [2008.11.24 10:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ElsterFormular [2010.06.22 08:52:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lotus [2008.06.02 18:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mindjet [2011.04.04 12:01:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound [2009.03.09 09:05:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel [2010.02.04 08:47:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SPSS [2010.09.27 23:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tmp [2011.09.01 07:58:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Xerox [2010.11.23 13:50:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Amazon [2010.05.06 08:13:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Columbus [2008.07.01 09:56:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Design Science [2009.11.18 11:18:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Desktopicon [2012.03.24 12:00:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Dropbox [2012.03.23 11:47:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\EndNote [2008.07.01 09:56:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\ICAClient [2008.11.07 14:59:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Lingo4u [2011.04.04 12:36:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\NCH Swift Sound [2012.03.12 09:01:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\PriceGong [2011.04.04 12:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Recordpad [2008.12.03 22:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\think-cell [2008.07.01 09:56:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\UniSG [2011.09.01 07:59:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\Xerox [2012.03.23 08:15:00 | 000,000,272 | ---- | M] () -- C:\WINDOWS\Tasks\SAVChecker.job [2012.03.24 12:05:00 | 000,000,394 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{04717CE6-353B-49D3-9235-3B4F523B0AAC}.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.10.11 03:00:42 | 000,000,000 | ---D | M] -- C:\$hsgusf [2009.04.02 15:17:02 | 000,000,000 | ---D | M] -- C:\adaptec [2009.06.03 13:44:09 | 000,000,000 | ---D | M] -- C:\Aixperanto [2012.01.02 22:41:14 | 000,000,000 | ---D | M] -- C:\BlueByte [2012.03.22 21:20:34 | 000,000,000 | -HSD | M] -- C:\Config.Msi [2008.04.30 11:50:56 | 000,000,000 | ---D | M] -- C:\dell [2011.11.09 06:40:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings [2010.01.06 07:59:29 | 000,000,000 | -HSD | M] -- C:\found.000 [2008.06.02 17:33:09 | 000,000,000 | ---D | M] -- C:\gs [2011.10.07 16:50:27 | 000,000,000 | ---D | M] -- C:\hp_LJ_P2030_Full_Solution [2008.04.30 11:56:34 | 000,000,000 | ---D | M] -- C:\Intel [2010.04.02 14:36:50 | 000,000,000 | ---D | M] -- C:\MadTV [2008.06.02 17:09:35 | 000,000,000 | RH-D | M] -- C:\MSOCache [2011.04.04 08:08:06 | 000,000,000 | ---D | M] -- C:\My Music [2011.10.21 02:06:07 | 000,000,000 | R--D | M] -- C:\Program Files [2011.12.06 00:56:55 | 000,000,000 | ---D | M] -- C:\Programme [2009.07.27 19:44:59 | 000,000,000 | ---D | M] -- C:\PROPL21 [2011.11.13 02:28:45 | 000,000,000 | -HSD | M] -- C:\RECYCLER [2009.02.20 09:48:57 | 000,000,000 | ---D | M] -- C:\SmartDraw 2009 [2011.02.01 10:04:55 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012.03.24 11:58:46 | 000,000,000 | ---D | M] -- C:\WINDOWS < %PROGRAMFILES%\*.exe > [2004.02.20 11:31:02 | 000,069,632 | ---- | M] () -- C:\Program Files\uninstgs.exe Invalid Environment Variable: LOCALAPPDATA < %systemroot%\*. /mp /s > < MD5 for: AGP440.SYS > [2006.02.08 11:47:14 | 016,682,779 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys < MD5 for: ATAPI.SYS > [2006.02.08 11:47:14 | 016,682,779 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2004.08.03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys [2006.02.08 11:47:14 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys [2004.08.03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys < MD5 for: EVENTLOG.DLL > [2004.08.04 02:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: EXPLORER.EXE > [2006.02.08 11:28:12 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=45757077A47C68A603A79B03A1A836AB -- C:\WINDOWS\explorer.exe < MD5 for: NETLOGON.DLL > [2004.08.04 02:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2004.08.04 02:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll < MD5 for: USER32.DLL > [2007.03.08 16:36:28 | 000,577,536 | ---- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 -- C:\WINDOWS\system32\user32.dll < MD5 for: USERINIT.EXE > [2004.08.04 02:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2004.08.04 02:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2002.08.29 15:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2008.04.30 12:08:54 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2008.04.30 12:08:54 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2008.04.30 12:08:54 | 000,921,600 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\system32\*.dll /lockedfiles > [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %USERPROFILE%\*.* > [2012.02.27 13:24:32 | 000,000,404 | ---- | M] () -- C:\Documents and Settings\***\.JavaPowUpload.properties [2012.03.22 21:19:27 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\***\defogger_reenable [2008.07.01 09:56:34 | 000,008,223 | ---- | M] () -- C:\Documents and Settings\***\gsview32.ini [2012.03.24 12:21:15 | 015,204,352 | -H-- | M] () -- C:\Documents and Settings\***\NTUSER.DAT [2012.03.24 12:21:22 | 001,294,336 | -H-- | M] () -- C:\Documents and Settings\***\NTUSER.DAT.LOG [2012.03.24 12:06:22 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\***\ntuser.ini [2011.06.07 06:59:40 | 000,006,064 | RHS- | M] () -- C:\Documents and Settings\***\ntuser.pol [2008.12.08 14:02:38 | 000,010,231 | ---- | M] () -- C:\Documents and Settings\***\StefanSchrettle_Stefan_elster_2048.pfx < %USERPROFILE%\Local Settings\Temp\*.exe > [2012.03.22 20:21:54 | 000,076,960 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\***\Local Settings\Temp\0.3059515409632334.exe [2012.03.22 20:21:52 | 000,076,960 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\***\Local Settings\Temp\0.7784838969206154.exe [2012.03.22 20:21:53 | 000,076,960 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\***\Local Settings\Temp\0.9354084406440376.exe [2008.04.03 13:12:06 | 000,110,592 | R--- | M] (Huawei Technologies Co., Ltd.) -- C:\Documents and Settings\***\Local Settings\Temp\DataCard_Setup.exe [2012.03.22 20:21:54 | 000,031,232 | ---- | M] () -- C:\Documents and Settings\***\Local Settings\Temp\mor.exe [2008.04.02 19:08:54 | 000,007,168 | R--- | M] () -- C:\Documents and Settings\***\Local Settings\Temp\ResetDevice.exe [2012.03.08 08:59:28 | 024,247,944 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\***\Local Settings\Temp\SkypeSetup.exe [35 C:\Documents and Settings\***\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\***\Local Settings\Temp\*.tmp -> ] < %USERPROFILE%\Local Settings\Temp\*.dll > [2009.03.06 11:28:34 | 000,049,480 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\***\Local Settings\Temp\FwsVpn.dll [2009.03.06 11:28:34 | 000,107,848 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\***\Local Settings\Temp\SymVPN.dll [2009.03.06 11:28:34 | 000,357,704 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\***\Local Settings\Temp\sysfer.dll [35 C:\Documents and Settings\***\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\***\Local Settings\Temp\*.tmp -> ] < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Kmode: %SystemRoot%\system32\win32k.sys [2010.05.02 06:56:34 | 001,850,880 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 < > < End of report > OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 24.03.2012 12:18:29 - Run 1 OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\***\My Documents\Downloads Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000807 | Country: Switzerland | Language: DES | Date Format: dd.MM.yyyy 2.99 Gb Total Physical Memory | 2.62 Gb Available Physical Memory | 87.54% Memory free 5.83 Gb Paging File | 5.63 Gb Available in Paging File | 96.55% Paging File free Paging file location(s): D:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.31 Gb Total Space | 3.30 Gb Free Space | 11.25% Space Free | Partition Type: NTFS Drive D: | 45.22 Gb Total Space | 7.38 Gb Free Space | 16.32% Space Free | Partition Type: NTFS Unable to calculate disk information. Computer Name: HSG04712-N | User Name: *** | NOT logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "3389:TCP" = 3389:TCP:*:enabled:Remotedesktop "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1505:TCP" = 1505:TCP:*:Enabled:Proxy Host (TCP) "1505:UDP" = 1505:TCP:*:Enabled:Proxy Host (UDP) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "3389:TCP" = 3389:TCP:*:enabled:Remotedesktop "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1505:TCP" = 1505:TCP:*:Enabled:Proxy Host (TCP) "1505:UDP" = 1505:TCP:*:Enabled:Proxy Host (UDP) ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\columbus.exe" = %windir%\columbus.exe:*:enabled:Columbus Client -- (BrainWare Consulting & Development) "%windir%\system32\dpmw32.exe" = %windir%\system32\dpmw32.exe:*:enabled:dpmw32 "%ProgramFiles%\VERITAS NetBackup Professional\System\NBPClientSvcush.exe" = %ProgramFiles%\VERITAS NetBackup Professional\System\NBPClientSvcush.exe:*:enabled:Veritas Netbackup (NBPClientSvcush.exe) "%ProgramFiles%\VERITAS NetBackup Professional\NBPClientush.exe" = %ProgramFiles%\VERITAS NetBackup Professional\NBPClientush.exe:*:enabled:Veritas Netbackup (NBPClientush.exe) "C:\WINDOWS\COLUMBUS.EXE" = C:\WINDOWS\COLUMBUS.EXE:*:Enabled:Columbus User and Service part -- (BrainWare Consulting & Development) "C:\Program Files\Columbus\Proxy Host\Phost.exe" = C:\Program Files\Columbus\Proxy Host\Phost.exe:*:Enabled:Proxy Host Control Panel -- (Funk Software, Inc.) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\columbus.exe" = %windir%\columbus.exe:*:enabled:Columbus Client -- (BrainWare Consulting & Development) "%windir%\system32\dpmw32.exe" = %windir%\system32\dpmw32.exe:*:enabled:dpmw32 "%ProgramFiles%\VERITAS NetBackup Professional\System\NBPClientSvcush.exe" = %ProgramFiles%\VERITAS NetBackup Professional\System\NBPClientSvcush.exe:*:enabled:Veritas Netbackup (NBPClientSvcush.exe) "%ProgramFiles%\VERITAS NetBackup Professional\NBPClientush.exe" = %ProgramFiles%\VERITAS NetBackup Professional\NBPClientush.exe:*:enabled:Veritas Netbackup (NBPClientush.exe) "C:\WINDOWS\COLUMBUS.EXE" = C:\WINDOWS\COLUMBUS.EXE:*:Enabled:Columbus User and Service part -- (BrainWare Consulting & Development) "C:\Program Files\Columbus\Proxy Host\Phost.exe" = C:\Program Files\Columbus\Proxy Host\Phost.exe:*:Enabled:Proxy Host Control Panel -- (Funk Software, Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0111FE56-5724-45C0-81D3-9DEEBF56870B}" = IBM Lotus Quickr Connectors "{01450CBD-A03E-4641-84FC-1CFC8FA541D2}" = think-cell "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video "{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime "{09298F26-A95C-31E2-9D95-2C60F586F075}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data "{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView "{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1F0291A3-B6F8-4077-A455-06ECA5BF6B7B}" = think-cell "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe "{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer "{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 21 "{316C9EC9-1D9C-4D28-BE9D-8DFBC4C7E612}" = Unisg Ads Kernel "{32FEA42D-3A59-49D9-8A2F-A3E2D8E663DF}" = SPSS SmartViewer 15.0 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{358A9F00-3B82-4CFB-A5D4-832C16C603AC}" = Thomson ONE Analytics for Office "{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5 "{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}" = Symantec Endpoint Protection "{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA "{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = Mobile Connect "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{4412F224-3849-4461-A3E9-DEEF8D252790}" = Visual Studio C++ 10.0 Runtime "{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{535C72E9-CA0D-46FF-B7E5-B102113420EA}" = think-cell "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy "{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI "{650D2589-137C-434C-8712-C2123942640C}" = VBA (2627.01) "{65D9DA69-4C22-46CA-B762-A338CAC94599}" = Amos 18 "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler "{677245E9-8B44-4B90-B7D0-468165284B34}" = Lotus Notes 7.0.2 de "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7 "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6DC47739-3BB0-4494-A43D-193BF54070AE}" = Cisco Systems VPN Client 4.6.00.0049 "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders "{804DE1A3-45D2-4AAC-8526-E9ADE47D84DF}" = Mindjet MindManager Pro 6 "{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio "{8500A84B-5310-4E68-B457-2437AA2746B7}" = PASW Smartreader 18 "{87F7773C-EC9C-461A-AA7B-4AF8EF54DF49}" = EndNote X1 "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8B519E5C-409B-4332-9A64-CCF1836A3424}" = Proxy Host "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12 "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{F4DB5C3F-51A3-4862-A3AC-41A142441E27}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0407-0000-0000000FF1CE}_PRJPRO_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0407-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0407-0000-0000000FF1CE}_PRJPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0407-0000-0000000FF1CE}_PRJPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0407-0000-0000000FF1CE}_VISPRO_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0407-0000-0000000FF1CE}_VISPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0407-0000-0000000FF1CE}_VISPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0407-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{58FC5E37-DD28-4D4A-A549-125744C6763C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0410-0000-0000000FF1CE}_PRJPRO_{58FC5E37-DD28-4D4A-A549-125744C6763C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0410-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0410-0000-0000000FF1CE}_PRJPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0410-0000-0000000FF1CE}_PRJPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0410-0000-0000000FF1CE}_VISPRO_{58FC5E37-DD28-4D4A-A549-125744C6763C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0410-0000-0000000FF1CE}_VISPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-001F-0410-0000-0000000FF1CE}_VISPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-001F-0410-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007 "{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007 "{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-0054-0407-0000-0000000FF1CE}" = Microsoft Office Visio MUI (German) 2007 "{90120000-0054-0407-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{888B9AC7-8F5C-456B-A27A-157A6C310E52}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-006E-0407-0000-0000000FF1CE}_PRJPRO_{888B9AC7-8F5C-456B-A27A-157A6C310E52}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-006E-0407-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-006E-0407-0000-0000000FF1CE}_PRJPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-006E-0407-0000-0000000FF1CE}_PRJPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-006E-0407-0000-0000000FF1CE}_VISPRO_{888B9AC7-8F5C-456B-A27A-157A6C310E52}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-006E-0407-0000-0000000FF1CE}_VISPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-006E-0407-0000-0000000FF1CE}_VISPRO_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-006E-0407-0000-0000000FF1CE}_VISPRO_{FAE3F81C-08DB-4703-B120-E75A0504F0CE}" = "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90120000-00B4-0407-0000-0000000FF1CE}" = Microsoft Office Project MUI (German) 2007 "{90120000-00B4-0407-0000-0000000FF1CE}_PRJPRO_{BDF1CC81-808F-4284-89A1-5FBBEE801886}" = "{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{DCBECE36-8F23-4B33-925E-A1C6183C0DBD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{E90C8CB5-8873-47DB-A0F9-7F06D3279DB8}" = "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz "{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig "{95468B00-C081-4B27-AC96-0A2A31359E60}" = Adobe Flash Player 10 ActiveX "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver "{A2AC3780-DD4E-4958-84B5-0E4CE2F6C8B5}" = PASW Statistics 18.0.1 Patch "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio "{A82D052A-0806-42DF-80CD-1730A1AC0ED3}" = MrvlUsgTracking "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AB6B977F-7767-4B7C-9465-4D2EAC2182C9}" = Fronter OES "{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch "{AC76BA86-7AD7-1031-7B44-A81200000003}" = Adobe Reader 8.1.2 - Deutsch "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2 "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C25215FC-5900-48B0-B93C-8D3379027312}" = PASW Statistics 18 "{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU "{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU "{C336A3DB-FA32-42BE-97D0-FFD42D807FD6}" = Oz776 SCR Driver V1.1.4.2 "{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba "{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch "{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software "{D8CB35E1-A6A2-4EA6-8260-3C16B3CF7893}" = AXIS Media Control Embedded "{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore "{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2 "{EE287DB0-8E86-4942-A344-EB0E8E3CB75F}" = Lotus Notes 8.5.1 de "{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi "{F872A4F8-4EC5-4668-A908-7C7275B0BE49}" = hppusgP2030 "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook "Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8.1.2 Professional "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Aladdin DiagnostiX 1.10" = Aladdin DiagnostiX 1.10 "Aladdin Monitor 1.4" = Aladdin Monitor 1.4 "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 "AXIS Media Control Embedded" = AXIS Media Control Embedded "Brother HL-1430" = Brother HL-1430 "CDex" = CDex extraction audio "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem "conduitEngine" = Conduit Engine "Digital Editions" = Adobe Digital Editions "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "DSMT6" = MathType 6 "ENTERPRISE" = Microsoft Office Enterprise 2007 "FormatFactory" = FormatFactory 2.15 "FreePDF_XP" = FreePDF XP (Remove only) "GPL Ghostscript 8.62" = GPL Ghostscript 8.62 "GPL Ghostscript Fonts" = GPL Ghostscript Fonts "HASP License Manager" = HASP License Manager "HDMI" = Intel(R) Graphics Media Accelerator Driver "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "IE7-MUI" = Windows Internet Explorer 7 Multilingual User Interface (MUI) "InstallShield_{358A9F00-3B82-4CFB-A5D4-832C16C603AC}" = Thomson ONE Banker for Office "InstallShield_{C336A3DB-FA32-42BE-97D0-FFD42D807FD6}" = Oz776 SCR Driver V1.1.4.2 "IrfanView" = IrfanView (remove only) "ISI ResearchSoft - Export Helper" = ISI ResearchSoft - Export Helper "LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation) "Logitech Vid" = Logitech Vid HD "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Modul FV" = Modul F/V "Mozilla Firefox 11.0 (x86 de)" = Mozilla Firefox 11.0 (x86 de) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MWSnap 3" = MWSnap 3 "MyTomTom" = MyTomTom 3.1.0.530 "NCH_EN Toolbar" = NCH EN Toolbar "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PRJPRO" = Microsoft Office Project Professional 2007 "ProInst" = Intel(R) PROSet/Wireless Software "Siedler3Deinstall" = Siedler3 "softonic-de3 Toolbar" = softonic-de3 Toolbar "TUGZip_is1" = TUGZip 3.5 "VISPRO" = Microsoft Office Visio Professional 2007 "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinZip" = WinZip "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 "XY Chart Labeler 7.0" = XY Chart Labeler 7.0 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "LingoPad_is1" = LingoPad 2.5.1 (Build 325) ========== Last 10 Event Log Errors ========== Error: Unable to start EventLog service! < End of report > |
24.03.2012, 19:03 | #4 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro hi ersetze *** im script durch nutzernamen. dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
ATTFilter :OTL O4 - HKCU..\Run: [SkypePM] C:\Documents and Settings\***\Local Settings\Application Data\Skype\SkypePM.exe (Microsoft Corporation) :Files C:\Documents and Settings\***\Local Settings\Application Data\Skype :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! Drücke bitte die + E Taste.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
25.03.2012, 11:06 | #5 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro Hallo und vielen Dank soweit. Da ich beim ersten Mal den Usernamen nur einmal ersetzt habe und einmal übersehen hatte, dass nochmals *** im Skript steht, habe ich das vorgeschlagene Vorgehen mit dem Fix Button zweimal durchgeführt, deshalb im Folgenden die zwei daraus resultierenden Textdokumente: All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SkypePM deleted successfully. File C:\Documents and Settings\***\Local Settings\Application Data\Skype\SkypePM.exe not found. ========== COMMANDS ========== [EMPTYFLASH] User: 02602522 User: Administrator User: All Users User: Columbusx User: Default User User: hsg-item99 User: HSG-Spezial User: LocalService User: mgrdhe User: ** User: NetworkService User: *** ->Flash cache emptied: 13649 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: 02602522 User: Administrator User: All Users User: Columbusx User: Default User ->Temp folder emptied: 0 bytes Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. ->Temporary Internet Files folder emptied: 44843026 bytes User: hsg-item99 User: HSG-Spezial User: LocalService User: mgrdhe User: ** User: NetworkService User: *** ->Temp folder emptied: 233476539 bytes ->Temporary Internet Files folder emptied: 248120650 bytes ->Java cache emptied: 23662194 bytes ->FireFox cache emptied: 187837649 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Windows Temp folder emptied: 157619652 bytes RecycleBin emptied: 105219796 bytes Total Files Cleaned = 954.00 mb OTL by OldTimer - Version 3.2.39.2 log created on 03252012_110646 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Nach dem zweiten Durchlauf wurde folgendes Textdokument ausgegeben: All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SkypePM not found. C:\Documents and Settings\***\Local Settings\Application Data\Skype\SkypePM.exe moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: 02602522 User: Administrator User: All Users User: Columbusx User: Default User User: hsg-item99 User: HSG-Spezial User: LocalService User: mgrdhe User: ** User: NetworkService User: *** ->Flash cache emptied: 456 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: 02602522 User: Administrator User: All Users User: Columbusx User: Default User ->Temp folder emptied: 0 bytes Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. ->Temporary Internet Files folder emptied: 44843026 bytes User: hsg-item99 User: HSG-Spezial User: LocalService User: mgrdhe User: ** User: NetworkService User: *** ->Temp folder emptied: 16662 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 18579617 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key. Windows Temp folder emptied: 16702 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 61.00 mb OTL by OldTimer - Version 3.2.39.2 log created on 03252012_113410 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Hallo markusg Der Upload hat soweit gut funktioniert. Geändert von Stehle (25.03.2012 um 11:24 Uhr) |
25.03.2012, 15:02 | #6 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro danke für den upload Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde! Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
__________________ --> Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro |
26.03.2012, 16:28 | #7 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro Hallo Markus Ich hab das Problem, dass ich meinen Virenschutz aufgrund mangelnder Administratorenrechte nicht vollständig ausschalten kann (was für ComboFix ja gefordert wird). Ich nutze Symantec Endpoint Protection, das aus den drei Komponenten "Viren- und AntispywareSchutz", "Proaktiver Bedrohungsschutz" und "Netzwerkbedrohungsschutz" besteht. Lediglich die letzte Komponente kann ich deaktivieren. Deshalb die Frage, ComboFix trotzdem ausführen, oder gibt es eine Alternative? Rein zr Info, momentan zeigen sich übrigens keine Symptome des Virus mehr. |
26.03.2012, 18:14 | #8 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro wieso bist du kein administrator?
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
26.03.2012, 18:25 | #9 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro Der PC wurde mir vom IT-Support eingerichtet, auf den ich momentan aber nicht zurückgreiden kann. Generell bin ich Administrator, aber das Virenprogramm scheint irgendwie nochmal gesondert gesichert zu sein. Wenn ich per Rechtsklink auf das Symantec-Symbol gehe, dann ist "deaktivieren" grau hinterlegt und lässt sich nicht betätigen. Genaueres kann ich Dir leider aufgrund mangelnder Kenntnis nicht sagen. |
26.03.2012, 18:26 | #10 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro hmm, hast du überhaupt mit eurem suport gesprochen ob ne bereinigung erwünscht ist, firmen haben da ja häufig regeln und da wird dann nicht bereinigt.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
26.03.2012, 18:29 | #11 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro naja begeistert waren sie nicht, aber da ich momentan nicht vor-Ort bin, konnten Sie mir auch nicht weiterhelfen |
26.03.2012, 18:30 | #12 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro dann machs ohne deaktivierung von mcafee
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
26.03.2012, 18:37 | #13 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro Naja, begeistert waren die nicht unbedingt, aber da ich momentan nicht vor-Ort bin, konnten Sie mit auch nicht weiterhelfen. Zumidnest haben Sie mir freie Hand gelassen. Hallo, habe nun ComboFix drüberlaufen lassen: Combofix Logfile: Code:
ATTFilter ComboFix 12-03-22.01 - ** 26.03.2012 20:11:30.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.41.1033.18.3062.2170 [GMT 2:00] ausgeführt von:: c:\documents and settings\***\Desktop\ComboFix.exe AV: Symantec Endpoint Protection *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\**\Application Data\PriceGong c:\documents and settings\**\Application Data\PriceGong\Data\mru.xml c:\documents and settings\**\WINDOWS c:\documents and settings\***\Application Data\Desktopicon c:\documents and settings\***\Application Data\Desktopicon\eBayShortcuts.exe c:\documents and settings\***\Application Data\PriceGong c:\documents and settings\***\Application Data\PriceGong\Data\1.xml c:\documents and settings\***\Application Data\PriceGong\Data\a.xml c:\documents and settings\***\Application Data\PriceGong\Data\b.xml c:\documents and settings\***\Application Data\PriceGong\Data\c.xml c:\documents and settings\***\Application Data\PriceGong\Data\d.xml c:\documents and settings\***\Application Data\PriceGong\Data\e.xml c:\documents and settings\***\Application Data\PriceGong\Data\f.xml c:\documents and settings\***\Application Data\PriceGong\Data\g.xml c:\documents and settings\***\Application Data\PriceGong\Data\h.xml c:\documents and settings\***\Application Data\PriceGong\Data\i.xml c:\documents and settings\***\Application Data\PriceGong\Data\J.xml c:\documents and settings\***\Application Data\PriceGong\Data\k.xml c:\documents and settings\***\Application Data\PriceGong\Data\l.xml c:\documents and settings\***\Application Data\PriceGong\Data\m.xml c:\documents and settings\***\Application Data\PriceGong\Data\mru.xml c:\documents and settings\***\Application Data\PriceGong\Data\n.xml c:\documents and settings\***\Application Data\PriceGong\Data\o.xml c:\documents and settings\***\Application Data\PriceGong\Data\p.xml c:\documents and settings\***\Application Data\PriceGong\Data\q.xml c:\documents and settings\***\Application Data\PriceGong\Data\r.xml c:\documents and settings\***\Application Data\PriceGong\Data\s.xml c:\documents and settings\***\Application Data\PriceGong\Data\t.xml c:\documents and settings\***\Application Data\PriceGong\Data\u.xml c:\documents and settings\***\Application Data\PriceGong\Data\v.xml c:\documents and settings\***\Application Data\PriceGong\Data\w.xml c:\documents and settings\***\Application Data\PriceGong\Data\x.xml c:\documents and settings\***\Application Data\PriceGong\Data\y.xml c:\documents and settings\***\Application Data\PriceGong\Data\z.xml c:\documents and settings\***\WINDOWS c:\windows\IsUn0407.exe c:\windows\system32\prsgrc.dll c:\windows\unin0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2012-02-26 bis 2012-03-26 )))))))))))))))))))))))))))))) . . 2012-03-25 09:06 . 2012-03-25 10:12 -------- d-----w- C:\_OTL 2012-03-22 20:23 . 2012-03-22 20:23 -------- d-----w- c:\documents and settings\**\Local Settings\Application Data\TomTom 2012-03-17 14:03 . 2012-03-17 14:03 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-17 14:03 . 2012-03-17 14:03 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-03-12 06:30 . 2012-03-12 06:30 -------- d--h--w- c:\windows\system32\WLANProfiles . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-23 12:07 . 2009-03-06 10:28 167936 ----a-w- c:\windows\system32\drivers\WpsHelper.sys 2004-02-20 10:31 . 2008-06-02 16:32 69632 -c----w- c:\program files\uninstgs.exe 2012-03-17 14:03 . 2011-04-30 08:42 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2006-02-08 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\netman.dll . [-] 2006-02-08 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe . [-] 2006-02-08 10:32 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\system32\es.dll . [-] 2006-02-08 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\linkinfo.dll . [-] 2006-02-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll . [-] 2006-02-08 . 45757077A47C68A603A79B03A1A836AB . 1032192 . . [6.00.2900.2649] . . c:\windows\explorer.exe . [-] 2006-02-08 . A2F755E237FA2CDD748A80BFBE6657F3 . 1285632 . . [5.1.2600.2726] . . c:\windows\system32\ole32.dll . [-] 2005-05-27 22:14 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\system32\drivers\aec.sys . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-11-13 3913000] "{37483b40-c254-4a72-bda4-22ee90182c1e}"= "c:\program files\NCH_EN\prxtbNCH_.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}] . [HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-11-13 19:58 3913000 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37483b40-c254-4a72-bda4-22ee90182c1e}] 2011-01-17 14:54 175912 ----a-w- c:\program files\NCH_EN\prxtbNCH_.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}] 2010-11-13 19:58 3913000 ----a-w- c:\program files\softonic-de3\tbsoft.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-11-13 3913000] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-11-13 3913000] "{37483b40-c254-4a72-bda4-22ee90182c1e}"= "c:\program files\NCH_EN\prxtbNCH_.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{37483B40-C254-4A72-BDA4-22EE90182C1E}"= "c:\program files\NCH_EN\prxtbNCH_.dll" [2011-01-17 175912] "{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-11-13 3913000] . [HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}] . [HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "bürofit mit UniSport"="\\cl-stud-data\unisg-apps$\standard\bürofit\ergosport.exe Autostart" [X] "ClearRumborakLastFile"="c:\gs\rumborak\RedMon_LastFiler.exe" [2004-09-07 28672] "Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2010-10-29 5915480] "MyTomTomSA.exe"="c:\program files\MyTomTom 3\MyTomTomSA.exe" [2011-11-14 435672] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504] "ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008] "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752] "StartColumbus"="columbus.exe" [2010-02-17 1568768] "EPA_EZ_GPO_Tool"="c:\windows\system32\EZ_GPO_Tool.exe" [2005-01-21 69632] "Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152] "ProxyHostTrayIcon"="c:\program files\Columbus\Proxy Host\phtray.exe" [2004-02-17 230544] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "Symantec AntiVirus überprüfen"="c:\windows\system32\SAVChecker.exe" [2008-06-29 33792] "FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2008-07-22 357376] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat\Acrotray.exe" [2008-01-11 623992] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-03-06 115560] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-07 165208] "HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2008-05-07 36864] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nlsf"="move" [X] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544] . c:\documents and settings\***\Start Menu\Programs\Startup\ Dropbox.lnk - c:\documents and settings\**\Application Data\Dropbox\bin\Dropbox.exe [N/A] . c:\documents and settings\**\Start Menu\Programs\Startup\ HASP License Manager.lnk - c:\program files\Aladdin\HASP LM\nhsrvw32.exe [2009-1-9 1011712] Logitech . Produktregistrierung.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-2-22 2938184] VPN Client.lnk - c:\windows\Installer\{6DC47739-3BB0-4494-A43D-193BF54070AE}\Icon3E5562ED7.ico [2011-5-19 6144] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "LogonType"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoOnlinePrintsWizard"= 1 (0x1) "NoPublishingWizard"= 1 (0x1) "NoWelcomeScreen"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au] "NoAutoUpdate"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\columbus.exe"= "%windir%\\system32\\dpmw32.exe"= "%ProgramFiles%\\VERITAS NetBackup Professional\\System\\NBPClientSvcush.exe"= "%ProgramFiles%\\VERITAS NetBackup Professional\\NBPClientush.exe"= "c:\\WINDOWS\\COLUMBUS.EXE"= "c:\\Program Files\\Columbus\\Proxy Host\\Phost.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:Remotedesktop "1505:TCP"= 1505:TCP:Proxy Host (TCP) "1505:UDP"= 1505:TCP:Proxy Host (UDP) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowOutboundPacketTooBig"= 1 (0x1) "AllowOutboundDestinationUnreachable"= 1 (0x1) "AllowOutboundSourceQuench"= 1 (0x1) "AllowRedirect"= 1 (0x1) "AllowInboundEchoRequest"= 1 (0x1) "AllowInboundRouterRequest"= 1 (0x1) "AllowOutboundTimeExceeded"= 1 (0x1) "AllowOutboundParameterProblem"= 1 (0x1) "AllowInboundTimestampRequest"= 1 (0x1) "AllowInboundMaskRequest"= 1 (0x1) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings] "Enabled"= 1 (0x1) . R2 bwColumbus;BrainWare Columbus;c:\windows\Columbus.exe [01.01.1980 02:00 1568768] R2 EPA_GPO_PMService;Energy Star(TM) EZ GPO Power Management Configuration Tool;c:\windows\system32\PMService.exe [02.06.2008 18:38 81920] R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?] R2 Lotus Notes Diagnostics;Lotus Notes-Diagnose;c:\program files\IBM\Lotus\Notes\nsd.exe [22.06.2010 10:05 3391488] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [15.11.2011 06:04 106104] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [06.03.2009 12:28 23888] . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - APPMGMT *NewlyCreated* - IDRIVERT *NewlyCreated* - RASMAN . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . Inhalt des "geplante Tasks" Ordners . 2012-03-26 c:\windows\Tasks\SAVChecker.job - c:\windows\system32\SAVchecker.exe [2008-07-03 23:00] . 2012-03-26 c:\windows\Tasks\User_Feed_Synchronization-{04717CE6-353B-49D3-9235-3B4F523B0AAC}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 16:36] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2801948 uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch uInternet Settings,ProxyOverride = <local> IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: An vorhandenes PDF anfügen - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Auswahl in Adobe PDF konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Auswahl in vorhandene PDF-Datei konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Verknüpfungsziel in Adobe PDF konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} TCP: DhcpNameServer = 192.168.2.1 DPF: LearningSpace5 Chat DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: Sametime BroadCast Client ST25PF1 - hxxp://gemma.unisg.ch/sametime/stbroadcastclient/STBroadcastClient.cab DPF: Sametime Meeting Room Client ST25PF1 DPF: Sametime MRC 651 DPF: {6CEDB6B5-4859-4E3A-BCA2-FB8E565B8AD9} DPF: {A4E84B61-1174-4309-87F0-E795A64158CC} FF - ProfilePath - c:\documents and settings\**\Application Data\Mozilla\Firefox\Profiles\qelgptoq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - NCH EN Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2801948&SearchSource=13 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) HKLM-Run-HP LaserJet P2030 Install - c:\program files\HP\HP LaserJet P2030 Series\Setup.exe SafeBoot-Symantec Antvirus AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-InstallShield_{358A9F00-3B82-4CFB-A5D4-832C16C603AC} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe AddRemove-KB923789 - c:\windows\system32\MacroMed\Flash\genuinst.exe AddRemove-Siedler3Deinstall - c:\windows\IsUn0407.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-03-26 20:16 Windows 5.1.2600 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . HKLM\Software\Microsoft\Windows\CurrentVersion\Run HP LaserJet P2030 Install = "c:\program files\HP\HP LaserJet P2030 Series\Setup.exe" AFTERREBOOT=YES??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\ . Zeit der Fertigstellung: 2012-03-26 20:18:17 ComboFix-quarantined-files.txt 2012-03-26 18:18 . Vor Suchlauf: 3'874'152'448 bytes free Nach Suchlauf: 3'886'338'048 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /bootlogo /noguiboot . - - End Of File - - 8A1D2471EA4D94EAF14D9A181AFC8485 |
27.03.2012, 14:43 | #14 |
/// Malware-holic | Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro malwarebytes: Downloade Dir bitte Malwarebytes
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
27.03.2012, 20:57 | #15 |
| Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro Hallo, habe nun Malwarebytes drüberlaufen lassen mit folgendem Resultat: Malwarebytes Anti-Malware (Test) 1.60.1.1000 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: v2012.03.27.04 Windows XP Service Pack 2 x86 NTFS Internet Explorer 7.0.5730.13 *** :: HSG04712-N [Administrator] Schutz: Aktiviert 27.03.2012 18:43:26 mbam-log-2012-03-27 (18-43-26).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 451510 Laufzeit: 2 Stunde(n), 26 Minute(n), 7 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|StartMenuLogoff (PUM.Hijack.StartMenu) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Qoobox\Quarantine\C\Documents and Settings\***\Application Data\Desktopicon\eBayShortcuts.exe.vir (Adware.ADON) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\WINDOWS\Cache\300354_Office_2007_Base_MUI_01_0\Client\WindowsSystem\userinfo.exe (Malware.Packer.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\WINDOWS\Cache\300354_Office_2007_Config_MUI_01_0\Client\WindowsSystem\userinfo.exe (Malware.Packer.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\_OTL\MovedFiles\03252012_113410\C_Documents and Settings\***\Local Settings\Application Data\Skype\SkypePM.exe (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
Themen zu Trojaner, Schwarzer Bildschirm inkl. Deutschlandflagge, 50 Euro |
andere, bestimmte, bestimmten, bezahlen, bildschirm, deutsche, deutschen, eingefangen, erscheint, euro, gefangen, gen, interne, internet, neu, rechner, schonmal, schwarzer, schwarzer bildschirm, sicherheitsupdate, starte, tan, troja, trojaner, verseuchung |