![]() |
|
Log-Analyse und Auswertung: Malwarebytes - FundWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 | |
![]() | ![]() Malwarebytes - Fund Nachdem Avira mehrmals aufgehängt und der Defender sich ständig ausgeschaltet hat, hab ich Malwarebytes laufen lassen und folgendes kam dabei raus: Zitat:
Die Probleme mit meinem Laptop häufen sich mittlerweile, Windows-Mail merkt sich kein Passwort, PDF-Dateien sind nicht mehr lesbar, der angebliche Standardsuchanbieter auf IE wurde beschädigt, obwohl das eigentlich Google ist und tadellos funktioniert. Der Scanner meint, ein Softwareproblem zu orten, obwohl bei der Diagnose alles einwandfrei läuft. Sehr mysteriös für mich. Ich flehe um Hilfe, bin panisch. ![]() |
![]() | #2 | ||
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Malwarebytes - Fund Hallo und Herzlich Willkommen!
__________________![]() Bevor wir unsere Zusammenarbeit beginnen, [Bitte Vollständig lesen]: Zitat:
Für Vista und Win7: Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen! 1. Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
2. Um festzustellen, ob veraltete oder schädliche Software unter Programme installiert sind, ich würde gerne noch all deine installierten Programme sehen:
Zitat:
kira
__________________ |
![]() | #3 | ||
![]() | ![]() Malwarebytes - Fund Oh, so schnell hab ich gar nicht mit einer Antwort gerechnet, dafür hab ich schon vorgearbeitet:
__________________OTL: Zitat:
Code:
ATTFilter OTL Extras logfile created on: 31.05.2012 16:35:21 - Run 1 OTL by OldTimer - Version 3.2.44.0 Folder = C:\Users\HOPSI\Müll Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 1,87 Gb Total Physical Memory | 1,06 Gb Available Physical Memory | 56,59% Memory free 3,99 Gb Paging File | 2,68 Gb Available in Paging File | 67,10% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 223,74 Gb Total Space | 164,43 Gb Free Space | 73,49% Space Free | Partition Type: NTFS Drive D: | 7,59 Gb Total Space | 0,75 Gb Free Space | 9,88% Space Free | Partition Type: NTFS Drive E: | 1,55 Gb Total Space | 1,32 Gb Free Space | 84,77% Space Free | Partition Type: NTFS Computer Name: CHRISTKIND-PC | User Name: HOPSI | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Users\HOPSI\Downloads\Diverses\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Users\HOPSI\Downloads\Diverses\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{34DA11C1-BD18-43F8-A35A-D6B49681F819}" = rport=139 | protocol=6 | dir=out | app=system | "{566BFDC2-46AD-452C-AC85-B0EC6204702E}" = lport=139 | protocol=6 | dir=in | app=system | "{6B954BF8-270F-441A-81B1-0501EEBC6604}" = rport=138 | protocol=17 | dir=out | app=system | "{B049E7AC-AF9E-4734-A9C4-3744A0194E3C}" = rport=137 | protocol=17 | dir=out | app=system | "{B074E03E-D552-4ED0-8A70-1689B0CC4C8F}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe | "{B8F97EAC-98B1-4BDD-9EBC-534C781DBF15}" = lport=445 | protocol=6 | dir=in | app=system | "{C5969AE3-B109-40C1-A074-B9E1C20CE68F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{C5BD03AD-343C-443A-8A28-91C3EC49F40E}" = lport=137 | protocol=17 | dir=in | app=system | "{CA22E9AC-2C29-4C55-93C7-AC5505324EB1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{D4B2E3FA-1A01-4BBF-A32B-73DC39862F7D}" = lport=138 | protocol=17 | dir=in | app=system | "{E2413390-1B71-4FD0-8A64-B45156760F39}" = rport=445 | protocol=6 | dir=out | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{015B634C-8375-417F-AB95-640321E410ED}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe | "{0508E06E-9137-410F-8821-C4F048AFD936}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{0A4CD25B-AB04-485B-B840-B6E44EBD8D9C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{164B13A2-D200-4F2D-9E0A-822208093595}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe | "{1E89CBB2-716F-44AE-9188-2B275F93811B}" = protocol=6 | dir=in | app=c:\users\hopsi\appdata\local\temp\7zs1b2f\hpdiagnosticcoreui.exe | "{264B4626-A958-4A98-99CC-D00D469ED0D9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe | "{2AE147C5-75B1-4371-953C-8326CCE7DD82}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | "{3A20A9B4-5A83-4213-9108-9B700F4D0C08}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{4BD4061C-54B2-446F-B20E-60B7D075076A}" = dir=in | app=f:\setup\hpznui01.exe | "{62289510-7B45-4D74-987A-AB26CDFB4725}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{62BF7E73-32F3-42DD-BA6C-0D54C2444184}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{6E48489E-C3CC-4CCC-B325-AEDCC8223CA1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe | "{7D45E3A7-F3DA-4F29-B33B-B454C85E66F2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe | "{99B555AD-B278-42BA-9376-2A898D62A929}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe | "{A7EA1774-BEA4-4E99-8393-316F4C11786E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{ADB08262-E113-408A-9445-1DD47503E7EA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe | "{B245C972-8D8E-4C4B-B2F8-1E3AE7FEA1B1}" = protocol=17 | dir=in | app=c:\users\hopsi\appdata\local\temp\7zs1b2f\hpdiagnosticcoreui.exe | "{C8D75FE8-4587-47FF-8335-384620F7C19C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe | "{CCEB6426-D92F-471E-A454-2620C25A9F1B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe | "{D0645F4C-E97D-4884-86E6-7542BFC37E3A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D8BB5931-FD09-416A-919C-272BDE3C3F2F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe | "{F9AE79D3-8917-4727-8B26-43394749DE22}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe | "TCP Query User{0EFD96BD-BCC1-4038-8BA8-9392AD8A9799}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{2C5AFD57-BA15-4182-BCC5-8B4A2C5475BD}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{910CA72D-F84C-4E6D-996D-61E025518102}C:\users\hopsi\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\hopsi\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe | "TCP Query User{C39CBA12-9D67-42AC-BEA7-28BAC98F8322}C:\program files\microsoft games\age of empires ii\empires2.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\empires2.exe | "UDP Query User{1ACD41DA-844A-4BA7-8F09-2FC1504CD08F}C:\program files\microsoft games\age of empires ii\empires2.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\empires2.exe | "UDP Query User{393AD420-D47D-4A4D-A4B0-F6F5123450B3}C:\users\hopsi\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\hopsi\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe | "UDP Query User{3D1C7612-4857-484E-ABD7-2A44F6C970B2}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{4A790FB5-A793-4A96-91E2-F77154A12902}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{02C03AE0-E898-5C22-AFD4-877466FFBD98}" = CCC Help English "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.4900 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) "{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller "{07FB18CF-3F76-43AC-0F02-B2DC201D27F4}" = Catalyst Control Center Localization Thai "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{09B17771-7F41-193C-4B8B-93B07653707C}" = Catalyst Control Center Localization Czech "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{15ADCB87-FB9D-BE4B-89EB-A5439DADACEB}" = CCC Help Japanese "{160FB2C2-37D9-C291-9B79-B660241AD747}" = Catalyst Control Center Localization Dutch "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{19CA53A9-E256-6AF1-28FA-EE61A88886CA}" = Catalyst Control Center Localization Chinese Traditional "{1A239B49-FDA5-8BCF-05E9-15C69A8591F7}" = Catalyst Control Center Localization Swedish "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2012D762-5DCA-455A-B5FE-EDF79BC93E18}" = HP Photosmart C4700 All-In-One Driver Software 13.0 Rel .6 "{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery "{228FAF8F-3380-6579-E37D-8AE663A543EE}" = CCC Help Russian "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check "{2692EC5B-A136-5340-C10C-4FA987FBA569}" = Catalyst Control Center Localization Spanish "{26A24AE4-039D-4CA4-87B4-2F83216018F0}" = Java(TM) 6 Update 18 "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{279F3807-2744-5B05-1CD5-612097502559}" = CCC Help Polish "{27A94385-A7BD-17DA-3827-E54A3B203E7C}" = CCC Help Chinese Traditional "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth "{290B83AA-093A-45BF-A917-D1C4A1E8D917}" = HP Active Support Library "{2B5BC746-6594-F319-D806-BA97C1B3D8E9}" = Catalyst Control Center Localization Japanese "{2DB165DC-DDB4-403F-B985-19F3EC7D0357}" = HP ProtectTools Security Manager "{2E2499C1-D876-D3A5-5329-23719AF4EEA5}" = CCC Help French "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons "{3583F14B-42A8-C383-37B1-6186DD87BA46}" = Catalyst Control Center Localization Korean "{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module "{36262360-D6DF-EFAE-7AB2-5FE47F01BB8A}" = Catalyst Control Center Graphics Full Existing "{36720FFD-D8DC-502D-5B59-97261633B847}" = Catalyst Control Center Graphics Full New "{3912A629-0020-0005-3131-2FBA74D4DF0A}" = InterVideo WinDVD "{3A6F4A31-8CFD-46B4-8385-E1F384DB121E}" = PDF-XChange Viewer "{3B1815F1-A388-CBA9-439E-8D97D0A9C6FB}" = CCC Help Portuguese "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = ST Wiederherstellungs- & Sicherungsprogramme "{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager "{426C7CC1-5AC3-4758-A40C-6446F2CEA8C9}" = ccc-Branding "{4282CA13-4119-B9F9-A13D-F7E8C61978F9}" = CCC Help Turkish "{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3 "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{541847E5-E8C5-075B-9F2B-2FF2A3C971C1}" = Catalyst Control Center Localization Hungarian "{5B1E200F-327D-AA06-4990-8E1505DFC754}" = CCC Help Greek "{5D7347E1-AE03-478B-3BE2-F1279693F745}" = ccc-utility "{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check "{5E156316-7276-D0B6-D6CD-A356B897FAB3}" = CCC Help Hungarian "{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{6276CABC-7E19-4945-9A9C-3549D965E687}" = CCC Help Danish "{6368D4AE-BFC1-4AAD-25AD-7EBA1CDEAFF0}" = CCC Help Thai "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent "{67D3B081-1389-D544-6889-3E3BA2691171}" = CCC Help Korean "{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting "{69333A04-5134-40A5-A055-9166A7AA1EC8}" = "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BA9955E-1F40-7E11-1488-228DAEFB0FD8}" = CCC Help Italian "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{6E8C9958-A445-06B7-9180-F1C546E90B6B}" = Catalyst Control Center Localization Chinese Standard "{6EF125F8-F86B-C019-2A11-53D9C99AEE00}" = Catalyst Control Center Localization Danish "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0 "{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = Application Installer 4.00.B14 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network "{75918444-A9D8-86F4-3644-08917713894F}" = CCC Help German "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7FB12670-0F93-4E1E-B2F5-4F339199A03A}" = Microsoft SQL Server Native Client "{849A32C3-E75A-4791-9B11-E568BA3525A4}" = Microsoft SQL Server VSS Writer "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B3CDDCA-0913-D8CE-F4E1-E0F8D0200B87}" = CCC Help Norwegian "{8CC5F040-44F2-4FB7-9720-47F53F96D180}" = MSCU for Microsoft Vista "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{990BA001-D69F-9DB2-56CE-88E0399B30FB}" = ccc-core-static "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C4AED81-8040-28D3-FCE3-E87DC2B948EC}" = Catalyst Control Center Localization German "{A1A34147-C621-1D90-3C27-D90CF2E1ADFA}" = CCC Help Czech "{A55F4F9F-CCA8-4732-AA1F-0390A4A50947}" = C4700 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA2F07A9-7EB5-4185-BAA9-A02F56F1396A}" = CCC Help Dutch "{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch "{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status "{B19B5C55-573E-14F3-0047-7029B5618529}" = Catalyst Control Center Graphics Light "{B33E503B-8A82-E0EF-1ABE-06BF0489A6F9}" = CCC Help Swedish "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B7A7937C-B0B5-1040-FC2E-EB05872EF72C}" = Catalyst Control Center Localization Turkish "{B7F2B452-4461-88FF-EFD0-8E888D1A4C2D}" = CCC Help Spanish "{BBE5C83E-4DC5-494F-8A23-3AAE242E94C2}" = HP Easy Setup - Frontend "{BC281B89-4AF1-D881-ABB3-853444E7C1D5}" = Catalyst Control Center Localization Greek "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BE41F3D2-FC73-4C3E-A2C2-5D2B08A5B2D0}" = Credential Manager for HP ProtectTools "{C41A421C-59F6-8393-014A-F655460AD5F5}" = CCC Help Finnish "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C6271F2D-3D0A-439B-BD78-584E017C636E}" = Vista Default Settings "{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D02B9787-3152-A4A0-43E9-AF5E62715D4E}" = Catalyst Control Center Localization Polish "{D32067CD-7409-4792-BFA0-1469BCD8F0C8}" = HP Wireless Assistant "{D9B4D7EE-481C-4C36-86AB-A8F7417725FF}" = LightScribe 1.6.43.1 "{DB11E77A-8184-C8D3-55DF-73F937EE2F3D}" = Catalyst Control Center Localization Norwegian "{DB58F76A-5B4F-DD75-7AD5-EDA4500BC7AC}" = ATI Catalyst Install Manager "{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp "{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update "{DDDBC1AF-504A-3E17-4A74-E8C69D2C0D0E}" = Catalyst Control Center Localization Finnish "{DEDBEB69-C5E7-4904-A885-9227C8D982B0}" = HP MULTIPLE WLAN INSTALLER for VISTA "{DFE967A8-9C30-413C-B2D5-C0D576949553}" = ESU for Microsoft Vista "{E03D8FE4-70BF-26F8-DA3B-974E3A561308}" = CCC Help Chinese Standard "{E25074CB-A222-3A2D-0542-CC5BAD57ED76}" = Catalyst Control Center Localization Russian "{E25AA53F-6878-4C64-8130-EB8D678DF303}" = HP User Guides 0064 "{E36F3199-C282-47CA-BAC7-2B77D247E760}" = PS_AIO_06_C4700_SW_Min "{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}" = HP Help and Support "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 "{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack "{EC04A654-128B-5439-0198-E1178E1E6E76}" = Catalyst Control Center Core Implementation "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9 "{EF6CEC13-B014-8BD5-5E56-78E68494A167}" = Catalyst Control Center Localization Italian "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager "{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL "{F4144B54-EA3B-72F5-D464-211A1D7BAB95}" = Catalyst Control Center Localization Portuguese "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F7B5554B-5CDE-4D16-9ACF-00BFB1ACD668}" = HP BIOS Configuration for ProtectTools "{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core "{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = HP Active Support Library 32 bit components "{FAFC99FB-4361-7B69-AF2B-87A60406B60C}" = Catalyst Control Center Localization French "{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "7-Zip" = 7-Zip 9.20 "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Agere Systems Soft Modem" = Agere Systems HDA Modem "ATI Uninstaller" = ATI Uninstaller "Avira AntiVir Desktop" = Avira Free Antivirus "AVS Media Player_is1" = AVS Media Player 4.1.6.80 "AVS Update Manager_is1" = AVS Update Manager 1.0 "AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4 "AVS4YOU Video Converter 7_is1" = AVS Video Converter 8 "Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter "CCleaner" = CCleaner "Free Studio_is1" = Free Studio version 5.5.0 "GIMP-2_is1" = GIMP 2.8.0 "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Print Projects" = HP Print Projects 1.0 "HP QuickLook_is1" = HP QuickLook "HP Smart Web Printing" = HP Smart Web Printing 4.5 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "PDF Complete" = PDF Complete Special Edition "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 2.0.1 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 30.05.2012 18:13:12 | Computer Name = CHRISTKIND-PC | Source = VSS | ID = 8194 Description = Error - 30.05.2012 18:13:18 | Computer Name = CHRISTKIND-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585 Description = Error - 30.05.2012 18:28:41 | Computer Name = CHRISTKIND-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585 Description = Error - 30.05.2012 19:18:14 | Computer Name = CHRISTKIND-PC | Source = EventSystem | ID = 4621 Description = Error - 30.05.2012 19:31:55 | Computer Name = CHRISTKIND-PC | Source = MsiInstaller | ID = 11714 Description = Error - 30.05.2012 19:35:28 | Computer Name = CHRISTKIND-PC | Source = VSS | ID = 8194 Description = Error - 30.05.2012 20:04:09 | Computer Name = CHRISTKIND-PC | Source = EventSystem | ID = 4621 Description = Error - 30.05.2012 20:35:06 | Computer Name = CHRISTKIND-PC | Source = VSS | ID = 8194 Description = Error - 30.05.2012 22:24:00 | Computer Name = CHRISTKIND-PC | Source = EventSystem | ID = 4621 Description = Error - 31.05.2012 07:08:40 | Computer Name = CHRISTKIND-PC | Source = VSS | ID = 8194 Description = [ Credential Manager Events ] Error - 11.10.2009 08:27:21 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 13.10.2009 10:26:16 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 18.10.2009 13:09:41 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 11.11.2009 17:30:50 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 16.11.2009 16:55:39 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 20.11.2009 08:32:11 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 25.11.2009 16:58:01 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 28.11.2009 15:20:28 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 05.12.2009 17:18:04 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. Error - 27.12.2009 07:48:51 | Computer Name = CHRISTKIND-PC | Source = AuthWiz | ID = 100796068 Description = The submitted credentials were rejected. Benutzer: HOPSI@CHRISTKIND-PC Anmeldeinformationen: Kennwort Fehler: (0xC516020B) Anmeldung fehlgeschlagen. Überprüfen Sie, ob Benutzername und Domäne korrekt sind, und geben Sie Ihr Kennwort erneut ein. Bei Kennwörtern wird die Groß- und Kleinschreibung beachtet. Stellen Sie sicher, dass die Feststelltaste nicht aktiviert ist. [ System Events ] Error - 30.05.2012 21:56:58 | Computer Name = CHRISTKIND-PC | Source = Service Control Manager | ID = 7034 Description = Error - 31.05.2012 06:30:41 | Computer Name = CHRISTKIND-PC | Source = Service Control Manager | ID = 7000 Description = Error - 31.05.2012 06:30:41 | Computer Name = CHRISTKIND-PC | Source = Service Control Manager | ID = 7034 Description = Error - 31.05.2012 07:22:28 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = Error - 31.05.2012 07:22:28 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = Error - 31.05.2012 07:23:25 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = Error - 31.05.2012 07:37:42 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = Error - 31.05.2012 08:03:27 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = Error - 31.05.2012 08:08:54 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = Error - 31.05.2012 08:16:05 | Computer Name = CHRISTKIND-PC | Source = DCOM | ID = 10016 Description = < End of report > CCLEANER: Zitat:
|
![]() | #4 | |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Malwarebytes - Fund Systemreinigung und Prüfung: 1. Zitat:
Code:
ATTFilter :OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_AT&c=none&bd=smb&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_AT&c=none&bd=smb&pf=laptop IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={output Encoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{8b0d31e7-0331-43cc-87cd-a472317f1305}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb010YYat_ZKxdm604YYat&ptb=BF440357-C679-4203-BB69-37091495D1D2&psa=&ind=2011010713&ptnrS=ZNzfb010YYat_ZKxdm604YYat&si=&st=sb&n=77dd9699&searchfor={sea rchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2438727 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/ IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={i nputEncoding?}&oe={outputEncoding?}&rlz=1I7GGNI_deAT484 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\HOPSI\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\HOPSI\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) [2011.04.05 01:49:53 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\HOPSI\AppData\Roaming\mozilla\Firefox\Profiles\dvboq4hq.default\extensions\engine@conduit.com [2010.06.30 22:46:44 | 000,002,333 | ---- | M] () -- C:\Users\HOPSI\AppData\Roaming\Mozilla\Firefox\Profiles\dvboq4hq.default\searchplugins\askcom.xml [2010.01.13 19:16:11 | 000,000,881 | ---- | M] () -- C:\Users\HOPSI\AppData\Roaming\Mozilla\Firefox\Profiles\dvboq4hq.default\searchplugins\conduit.xml File not found (No name found) -- C:\USERS\HOPSI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DVBOQ4HQ.DEFAULT\EXTENSIONS\TOOLBAR@ASK.COM O2 - BHO: (no name) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKCU..\Run: [] File not found O32 - HKLM CDRom: AutoRun - 1 O32 - Unable to obtain root file information for disk D:\ O33 - MountPoints2\{09e4315c-b7e9-11de-a613-d02839127291}\Shell - "" = AutoRun O33 - MountPoints2\{09e4315c-b7e9-11de-a613-d02839127291}\Shell\AutoRun\command - "" = G:\AutoRun.exe [2012.05.31 15:56:24 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.05.31 15:52:02 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1457105073-1478914729-850536785-1006UA.job [2012.05.31 12:32:47 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.05.30 21:52:00 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1457105073-1478914729-850536785-1006Core.job [2012.05.30 21:47:13 | 000,001,120 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1457105073-1478914729-850536785-1006UA.job [2012.05.30 21:47:12 | 000,001,068 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1457105073-1478914729-850536785-1006Core.job @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:9E3E060F @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:92A815D8 @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:73AFBB96 @Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:E945C214 @Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:AABCC5A7 @Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:5BC73C48 @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMPFC3B090 @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:0F2BA284 @Alternate Data Stream - 470 bytes -> C:\Users\HOPSI\Documents\fb.eml:OECustomProperty @Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:5345C8F6 @Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:E690114B @Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:AE75CCC8 @Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:89C28CF6 @Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:3D186293 @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:CAF8DAC8 @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:EEB25EAE @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:8BFA0030 @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:40EE25BB @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:386B39C3 @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:28CDD861 @Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP390A6A7 @Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:C76CFF82 @Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:23834E1E @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:E6C6EB3B @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C48A983C @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A0921B2C @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A02025CE @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:79875988 @Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:EF5B3572 @Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:C7F08EA3 @Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3969ACF7 @Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0EC7A545 @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:CAC06C34 @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:834DD57E @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:53DF4438 @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:526B3022 @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1C201DEB @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:EE39C93C @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:E7B4296D @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:E14FA16F @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMPC0B1070 @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C36B1175 @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:B64F7263 @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:943E8182 @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:61AF2B29 @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:5D10C56A @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:3B454A5C @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0BBF232A @Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:F84B8DB5 @Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:9FD757A9 @Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:6017A808 @Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:491270B8 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:FC70A22A @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E9FAC3AB @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:B54E4B5A @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:A5241382 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:89CF6F9C @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:609CAC7C @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:2DF54B62 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:123A86B5 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:91DEEE71 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:88A44CC1 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:864881BF @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:700B9342 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:5FA4CB99 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:3651A580 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:041C0562 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:E80802C7 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:AA0017FD @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A819A132 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:65AB2A58 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:59465B40 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:55E1514E @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:2BFCDF84 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:26A148EB @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:1C6CB897 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:14A1BBE3 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:FED25C29 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:BF6A2C54 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:B8EB1B99 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A5584049 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:8BE7A048 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:8924043A @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:737160C1 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:551BED5F @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:1181620C @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FDDD8917 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:EAF954B6 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:EA10407C @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:E2CB42C9 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:896E1EFF @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7881FECE @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:6FD3C973 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:4A448DB2 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:43E95997 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:2AE74FF9 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:19474103 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:FAB64002 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B3196E8D @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A7DA2BCD @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:9E76E7F3 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:9A7BF72D @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:80F63EC3 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:7A0EFE63 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:7A032A04 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:512E1728 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:488F7244 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:F8F070C2 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:EC855C73 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP46ECFD5 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C928F3BE @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:AFB24B00 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:AED33A42 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:A88BE334 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:9DF07E8F @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:98982C88 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:80EA2EA3 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:7972CF54 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6247E766 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:51E1A4D8 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:42A3BDD7 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:3AD6342E @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:1B389835 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:101708D3 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:0DFE2AE1 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:F3EFA8A8 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:EDC744FB @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:C10635F6 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:A6D89509 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:A6D6E537 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9EE6560D @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:90865A6D @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8944C195 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:870649A4 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:71004506 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:61B54B15 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:4FA837B4 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:405D842B @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:3B812EE0 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:315B4A13 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:2E3F04BC @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:25249477 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:FC8FFA4E @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C7973317 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C0893153 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:BB71BBA2 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:7E082023 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:74B9EA7F @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:6BFA43EB @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:6425A235 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:55F44B88 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:4C528C86 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:3E200C29 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1B7E2022 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:0E684AC9 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMPE875C30 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP5E0200E @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:C8AC644A @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:895A78C5 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:7ADB695A @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:627153F1 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5520ED93 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4F7FE589 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:38B32B54 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:1D6B18F1 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMPE47A3DA @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP8D58038 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP31BE97C @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP2C57161 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:CD9109D4 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:C5E2BAEE @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:B60D5127 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:85C3B823 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:7CEDF9F3 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:697DDE2B @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5CE91C67 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C6EBC69 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:52C24010 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:4DCAC4BC @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3539CD43 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:260575F1 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:2495D97A @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:1CDEDE11 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:072F1F69 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:0696EC8E @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:008586AE @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C22674B6 @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:BE40C8A2 @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:9B721CFF @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:842B0AED @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:69AF9D20 @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:61F0C8FB @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:5080697C @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:EC0A74A1 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMPD04902E @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMPC21D414 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:A2FF62A6 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:A0CB43B2 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:9D03192E @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:9BAC4211 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:98DFF516 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:71612023 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:71112705 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:598E0FFA @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:48FEA089 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:3815BC84 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0E636D62 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:EA1919C7 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMPE6EED8B @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:B845F669 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:B0456F0C @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9E9A3410 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:99B20AD0 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:996104FC @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:961B84C5 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6F0B6A5A @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:4E243396 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:370E4EFB @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:2871B698 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:FC2D0F32 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CA8D6B60 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:BD9F7E4E @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:AAA06E15 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:93D985FC @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:918B7566 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:689AB7E9 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:5EF1AD34 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:4673E9EA @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:17C48B08 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:16A4620C @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:F5B51004 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E7B49FBF @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E3B5F2D1 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP055FC10 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:B1786630 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:7B52659E @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:53B8C5D2 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4A906D4A @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:206470A5 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:1392F09D @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E895790F @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E3CEEC4C @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E2CFA9CD @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:B8384DB6 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:A58B27C9 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9ACB70D7 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:8E5EA40F @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:7547DA5B @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:6BD304B9 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:63B38619 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:3DB6F365 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:237E4B91 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:0E22C5DB @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:0AC32449 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:CF61CE5A @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:AECF4772 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:5FFC2819 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3D6B89CE @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3D36932D @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:2B1EA607 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:2AF322BF @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:275AA066 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:054F0F17 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:C30487EE @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:BD27B7FC @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:B2735F9E @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:B1381B34 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:70E897B5 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:6C5EC3CD @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:3E06C78F @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:3C282BEA @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:397D67BA @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:3086B95F @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:0F0A5896 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BE6B5FC3 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:B904C348 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:8BA6C9F8 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:7CA7BED1 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:55818279 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:4DDE401B @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:B1FBA7E1 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A60D0FA6 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:94B46CA2 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:9491C9C7 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:90D89144 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:22313216 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:1ECED34B @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:1B927722 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:FAFEC4B9 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:EF0C5444 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMPE9F4320 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:BF6C81B2 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:9A6EBBF2 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:7C412B92 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:774A0E14 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:0D278FB5 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:07241935 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:067F588D @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:8B4B9596 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7FCB9D0D @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:6FE17A89 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:5B6F7F60 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:5197985B @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:29F0CA7D @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:24FECE50 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:F42B5B0E @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:E91ADC66 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:E732B44B @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:E411AA0D @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:CEF2A14E @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:4FE30352 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:43982D5E @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:39C7B7C6 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMPF0BC727 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP507B5A8 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C8E82994 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:409A775B @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:3C5ABDC7 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:12D2EB9C @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:E51234A9 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:7A0FEE87 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:5E9B629B @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:3FD496E1 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:331B76C7 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:2E49FF93 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:109734F6 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:0ED4AC2F @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP0668210 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BDCD8531 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:A3251D01 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:50636E35 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:43301D1D @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:090FB735 @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:97C4F81F @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:9398DBB4 @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:78E0DF72 @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:561B1D2B @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:523B97A0 @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:08D8BB20 @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:4FE42FFC @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:4573A78F @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:FC4EA67C @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:848CC150 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:80B291A7 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3E988A0F @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:2BC498A4 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:124B94C0 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP92485C9 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:BA05E0C4 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:6E86D926 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5D351BC6 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:57B2B96C @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:569CEE83 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:40D8F125 @Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:95198126 @Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:5A437AC3 @Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:53DF59D1 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP48500F8 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:CB0EB1DE @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C0A9D0E7 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:B2CD146E @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:7776B809 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:6444B424 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:177313FB @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:ED810E46 @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:E32966C0 @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:C07A6A6B @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:55BB2521 @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:225CD7D5 @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:F14D1F80 @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:8E7F155B @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82529191 @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:27D1368B :Files C:\Users\HOPSI\AppData\Roaming\pdfforge C:\Windows\System32\pdfcmon.dll ipconfig /flushdns /c :Commands [purity] [emptytemp]
2. Java aktualisieren- über Systemsteuerung-> Nach Update suchen... oder: Downloade nun die Offline-Version von Java für 32 Bit Version 6 Update 32 von Oracle und installiere sie. Achte darauf, eventuell angebotene Toolbars nicht mitzuinstallieren, also während der Installation den Haken bei der Toolbar entfernen. 3. Tipps (unabhängig davon ob man den Internet Explorer benutzt oder nicht!): -> Tipps zu Internet Explorer -> Standard Suchmaschine des Explorers ändern -> Wie kann ich den Cache im Internet Explorer leeren? 4. reinige dein System mit CCleaner:
5.
6. Auch auf USB-Sticks, selbstgebrannten Datenträgern, externen Festplatten und anderen Datenträgern können Viren transportiert werden. Man muss daher durch regelmäßige Prüfungen auf Schäden, die durch Malware ("Worm.Win32.Autorun") verursacht worden sein können, überwacht werden. Hierfür sind ser gut geegnet und empfohlen, die auf dem Speichermedium gesicherten Daten, mit Hilfe des kostenlosen Online Scanners zu prüfen. Schließe jetzt alle externe Datenträgeran (USB Sticks etc) Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.►Anleitung 7. -> Führe dann einen Komplett-Systemcheck mit Eset Online Scanner (NOD32)Kostenlose Online Scanner durch Achtung!: >>Du sollst nicht die Antivirus-Sicherheitssoftware installieren, sondern dein System nur online scannen<< 8. erneut einen Scan mit OTL:
► berichte erneut über den Zustand des Computers. Ob noch Probleme auftreten, wenn ja, welche?
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
![]() | #5 | |
![]() | ![]() Malwarebytes - Fund Also Schritt für Schritt: zu 1. +) Änderungen hab ich keine vorgenommen +) Fixen mit OTL erledigt, hier das Ergebnis: Zitat:
|
![]() | #6 |
![]() | ![]() Malwarebytes - Fund zu 2. +) Java Version 6 Update 32 installiert Nun öffnet sich bei jedem Öffnen des IE oder auch nur eines neuen Tabs ein Fenster der Benutzerkonntensteuerung, die meine Zustimmung zum Fortsetzen fordert. ![]() zu 3. +) Beim Öffnen des IE erscheint nach wie vor folgendes Fenster: |
![]() |
Themen zu Malwarebytes - Fund |
administrator, anti-malware, autostart, avira, dateien, dateisystem, defender, explorer, folge, gelöscht, google, heuristiks/extra, heuristiks/shuriken, laptop, malwarebytes, nicht mehr, passwort, probleme, pup.funwebproducts, quarantäne, scan, service pack 2, software, softwareproblem, speicher, version, vista |