|
Plagegeister aller Art und deren Bekämpfung: Bundestrojaner sperrt Win7Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.06.2012, 09:35 | #1 |
| Bundestrojaner sperrt Win7 Hallo, also ich habe mir einen Bundestrojaner eingefangen der beim Hochfahren von Win7 den Rechner sperrt. Kann mir jemand helfen das Ding wieder los zu werden? Die OTL Disk hätte ich nach lesen der anderen Beiträge schon mal erstellt. Aber was jetz? Einfach den Scan laufen lassen und die Log posten? Vielen Dank schon mal. |
25.06.2012, 10:56 | #2 |
| Bundestrojaner sperrt Win7 Hi,
__________________ja (und beten das nichts verschlüsselt wurde ;o)... chris
__________________ |
25.06.2012, 11:25 | #3 |
| Bundestrojaner sperrt Win7 Hi,
__________________Also beten tue ich jetzt schon seit einigen Stunden ;-) Unten also jetzt der die Log Datei. Ich hoffe das passt so. OTL Logfile: Code:
ATTFilter OTL logfile created on: 6/25/2012 5:15:54 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows 7 Professional (Version = 6.1.7600) - Type = System Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 125.00 Gb Total Space | 84.65 Gb Free Space | 67.72% Space Free | Partition Type: NTFS Drive F: | 107.88 Gb Total Space | 14.16 Gb Free Space | 13.13% Space Free | Partition Type: NTFS Drive X: | 3.73 Gb Total Space | 2.83 Gb Free Space | 75.94% Space Free | Partition Type: FAT Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [Auto] -- -- (z525bus) SRV - File not found [Auto] -- -- (yats32) SRV - File not found [Auto] -- -- (WmXlCore) SRV - File not found [Auto] -- -- (WimFltr) SRV - File not found [Auto] -- -- (wcontrol) SRV - File not found [Auto] -- -- (vzupsvc) SRV - File not found [Auto] -- -- (USBVCD) SRV - File not found [Auto] -- -- (usbbus) SRV - File not found [Auto] -- -- (tvichw32) SRV - File not found [Auto] -- -- (TUWinStylerThemeSvc) SRV - File not found [Auto] -- -- (transbaseservice) SRV - File not found [Auto] -- -- (TPM) SRV - File not found [Auto] -- -- (tosrfec) SRV - File not found [Auto] -- -- (tbiosdrv) SRV - File not found [Auto] -- -- (symmpi) SRV - File not found [Auto] -- -- (swupdtmr) SRV - File not found [Auto] -- -- (steamdvr) SRV - File not found [Auto] -- -- (spcstb) SRV - File not found [Auto] -- -- (SNPSTD3) SRV - File not found [Auto] -- -- (Slpsvdr) SRV - File not found [Auto] -- -- (SiRemFil) SRV - File not found [Auto] -- -- (sgeclient) SRV - File not found [Auto] -- -- (ser2pl) SRV - File not found [Auto] -- -- (sbhooksvc) SRV - File not found [Auto] -- -- (rkhdrv31) SRV - File not found [Auto] -- -- (RecAgent) SRV - File not found [Auto] -- -- (radiosvr) SRV - File not found [Auto] -- -- (pshost) SRV - File not found [Auto] -- -- (pelmouse) SRV - File not found [Auto] -- -- (pdlncbas) SRV - File not found [Auto] -- -- (ovepstatusengine) SRV - File not found [Auto] -- -- (NWSIPX32) SRV - File not found [Auto] -- -- (nv4) SRV - File not found [Auto] -- -- (ntservice1) SRV - File not found [Auto] -- -- (nsm1mdm) SRV - File not found [Auto] -- -- (npfmntor) SRV - File not found [Auto] -- -- (nmsaccess) SRV - File not found [Auto] -- -- (nalntservice) SRV - File not found [Auto] -- -- (mxssvr) SRV - File not found [Auto] -- -- (mr7910) SRV - File not found [Auto] -- -- (lyncusbserv) SRV - File not found [Auto] -- -- (lvckap) SRV - File not found [Auto] -- -- (ltmodem5) SRV - File not found [Auto] -- -- (konfig) SRV - File not found [Auto] -- -- (issvc) SRV - File not found [Auto] -- -- (issm) SRV - File not found [Auto] -- -- (ipinip) SRV - File not found [Auto] -- -- (ipahelper.exe) SRV - File not found [Auto] -- -- (ICAM3NT5) SRV - File not found [Auto] -- -- (iap) SRV - File not found [Auto] -- -- (i2omgmt) SRV - File not found [Auto] -- -- (hpn) SRV - File not found [Auto] -- -- (eSettingsService) SRV - File not found [Auto] -- -- (enxpsvr) SRV - File not found [Auto] -- -- (enxpsvc) SRV - File not found [Auto] -- -- (digirefresh) SRV - File not found [Auto] -- -- (digictrl) SRV - File not found [Auto] -- -- (dbustrcm) SRV - File not found [Auto] -- -- (cqmghost) SRV - File not found [Auto] -- -- (com0com) SRV - File not found [Auto] -- -- (clisvc) SRV - File not found [Auto] -- -- (Cam5603D) SRV - File not found [Auto] -- -- (cachemanxp) SRV - File not found [Auto] -- -- (btnhnd) SRV - File not found [Auto] -- -- (bcoreusb) SRV - File not found [Auto] -- -- (BCMTPM) SRV - File not found [Auto] -- -- (basfipm) SRV - File not found [Auto] -- -- (avidsdmservice) SRV - File not found [Auto] -- -- (aliadwdm) SRV - File not found [Auto] -- -- (AffinegyService) SRV - File not found [Auto] -- -- (aexnsclient) SRV - File not found [Auto] -- -- (adpu160m) SRV - File not found [Auto] -- -- (AcronisOSSReinstallSvc) SRV - [2012/05/21 19:24:57 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service) SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework) SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp) SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield) SRV - [2011/09/29 10:44:32 | 002,498,560 | ---- | M] () [Auto] -- C:\Program Files\McAfee\EEGo\EegoService.exe -- (McAfee EEGo) SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent) SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire) SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr) SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager) SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc) SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim) SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService) SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService) SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service) SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage) SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService) SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec) SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr) SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (mfeavfk01) DRV - File not found [Kernel | On_Demand] -- -- (FirehkMP) DRV - File not found [Kernel | On_Demand] -- -- (Firehk) DRV - [2011/11/01 05:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2011/11/01 05:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2011/11/01 05:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011/11/01 05:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp) DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk) DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet) DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk) DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk) DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk) DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk) DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek) DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK) DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk) DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn) DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog) DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp) DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter) DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm) DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ) DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm) DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM) DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM) DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl) DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM) DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad) DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr) DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis) DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum) DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd) DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R) DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps) DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard) DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler) DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt) DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R) DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv) DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr) DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus) DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc) DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It) DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap) DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID) DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID) DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV) DRV - [2007/01/24 10:27:54 | 000,039,704 | ---- | M] (Belcarra Technologies) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rcblan.sys -- (RemoteControl-USBLAN) DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom) DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://mywikis.tycoelectronics.com/cm/wiki/?id=10294 IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy IE - HKU\EG005689_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://mywikis.tycoelectronics.com/cm/wiki/?id=10294 IE - HKU\EG005689_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy IE - HKU\EG011222_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\EG011222_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://myte.tycoelectronics.com/portal/server.pt?PageID=0&parentname=Login&parentid=1&CommunityID=256&space=CommunityPage&control=SetCommunity&cached=false&in_hi_userid=104876 IE - HKU\EG011222_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\EG011222_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy IE - HKU\SMSAccess_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M] [2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll Hosts file not found O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\EG011222_ON_C\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O3 - HKU\EG011222_ON_C\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation) O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) O4 - HKLM..\Run: [dcmsvc] C:\Program Files\dcmsvc\dcmsvc.exe () O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation) O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.) O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.) O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.) O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation) O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.) O4 - HKLM..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe () O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals) O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC) O4 - HKU\EG011222_ON_C..\Run: [] File not found O4 - HKU\EG011222_ON_C..\Run: [7Rxb5FismTZydeX] File not found O4 - HKU\EG011222_ON_C..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) O4 - HKU\EG011222_ON_C..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe () O4 - HKU\EG011222_ON_C..\Run: [X1FileMonitor.exe] C:\Program Files\X1\X1FileMonitor.exe () O4 - HKU\LocalService_ON_C..\Run: [Sidebar] File not found O4 - HKU\NetworkService_ON_C..\Run: [Sidebar] File not found O4 - HKU\SMSAccess_ON_C..\Run: [Sidebar] File not found O4 - HKU\EG005689_ON_C..\RunOnce: [SetupRevertTELogo] C:\Apps\TECApps\SetupRevertTELogo.exe () O4 - HKU\EG011222_ON_C..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe (Adobe Systems Incorporated) O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\SMSAccess_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPhoneExplorer.lnk () O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Office Keyboard.exe () O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warner Bros.lnk () O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\X1 System Tray.lnk () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Administrator_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\EG005689_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\EG005689_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\EG011222_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\SMSAccess_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation) O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000040 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000042 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000044 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000045 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000046 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000047 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000048 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000049 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000050 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000051 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000052 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000053 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000054 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000055 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000056 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000057 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000058 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000059 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000060 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000061 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000062 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000063 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000064 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000065 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000066 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000067 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000068 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000069 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000070 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000071 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000072 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000073 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000074 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000075 - File not found O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.14 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf) O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH) O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKU\EG011222_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\ecojink: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll - File not found O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{1dab4fdb-6116-11e0-839c-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{1dab4fdb-6116-11e0-839c-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/06/25 04:47:38 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\NPE [2012/06/24 20:26:57 | 000,000,000 | ---D | C] -- C:\NPE [2012/06/24 20:26:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2012/06/24 19:06:19 | 000,000,000 | ---D | C] -- C:\NBRT [2012/06/22 13:11:24 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0 [2012/06/22 09:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\egvixvcletcqitf [2012/06/21 20:03:26 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\Mozilla [2012/06/21 09:06:42 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1F484A5F-3B4F-4B28-BEDF-E27115B582F5} [2012/06/21 09:06:20 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{40128DC9-A673-4F4C-8993-82A501B5C9B4} [2012/06/20 05:15:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{89FBBE95-9710-4104-9ED3-B337ACFE728A} [2012/06/20 05:15:30 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{0B6D5AC8-7D22-4FF4-900B-F7898B4A3976} [2012/06/20 02:24:00 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B94F1FFE-CFB8-4DA4-890B-9C97863D79FF} [2012/06/20 02:19:03 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{D829BDE5-7A5F-4874-8835-D1398A74577B} [2012/06/20 02:15:08 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{81659A2B-17B2-4F6F-AA2A-3E02A62BD734} [2012/06/19 04:26:11 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B6C49E82-062F-496A-8ECC-5E5C606CACCE} [2012/06/19 04:25:54 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{39CF9DA7-9F42-44FB-920C-E117251DEB5B} [2012/06/19 02:54:39 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\.salesforce.com [2012/06/19 02:54:37 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\salesforce.com [2012/06/19 02:54:37 | 000,000,000 | ---D | C] -- C:\ProgramData\salesforce.com [2012/06/19 02:52:24 | 000,000,000 | ---D | C] -- C:\Program Files\salesforce.com [2012/06/18 05:12:43 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{72C8C4AE-44DC-4533-ACE5-D06A04A2379C} [2012/06/17 06:42:52 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1D2A4A4E-B3D2-4AA9-9F87-C92511618ADC} [2012/06/14 04:54:30 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{43F24588-D02C-4408-A6A5-0061ECDE2FF5} [2012/06/14 04:20:48 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{041B35CC-6060-4C69-B7AA-6EC9C05854FD} [2012/06/13 08:31:55 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{9458F21D-65AB-43BB-BC37-A91E4F54704C} [2012/06/13 08:31:35 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{3F0F1BF6-A91B-4498-8373-0F9C7A548612} [2012/06/13 08:07:55 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{10EA408A-F370-4D9D-B534-EE878AE683DB} [2012/06/11 15:07:48 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{468BB37E-322C-4546-8DB5-CADF6FE816E8} [2012/06/10 13:48:45 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{5781FDF2-A01C-4504-870B-A570E9CC24CB} [2012/06/07 17:04:06 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{4193B25C-65F4-4451-B1C3-A220E23DEF27} [2012/06/05 14:42:27 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{BD37A6E8-51C3-4B7F-8F51-CBEAE17D439F} [2012/06/05 14:42:06 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{8250949A-A41A-49E6-BC2A-27589F896F6B} [2012/06/03 09:21:33 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{157D3603-8789-452C-81AE-295C1176437E} [2012/06/03 09:21:10 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{7A901744-F987-46E4-9864-F644E5E55C65} [2012/06/02 14:50:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{AE5993DB-7119-4200-BEBD-5ACA400074F9} [2012/06/01 05:15:21 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B729E639-C1AE-4261-915A-2933B3FD62DA} [2012/06/01 04:50:44 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{02628924-0716-41F2-94ED-D12EA2B0C627} [2012/05/30 03:41:56 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{DEA7767A-0FD8-4056-9A81-4DE6A151096F} [2012/05/30 03:41:42 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B0478902-55DB-499B-B4DB-91E865B52374} [2012/05/29 16:13:09 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{344BF6F8-DD81-48DE-B707-F97D6739A941} [2012/05/29 02:30:58 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{C1839AB4-0F1D-4673-9F34-33D8C929F41B} [2012/05/29 02:27:35 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{28645085-0D13-4ACB-BFD6-B968E004D3CD} [2012/05/28 18:49:22 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{C50E0260-1456-4DB3-8725-AA147D68F1F1} [2012/05/28 18:11:54 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{62026264-D041-4062-9BAA-B5CA7EFA13A0} [2012/05/28 17:53:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{755B7984-437E-43E7-9AA3-D7718774A4CE} [2012/05/28 17:06:32 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{F8627BBB-A9C5-44DC-9B01-B0481E84C516} [2012/05/28 17:03:09 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1DB5DBC7-D1DA-41F4-A35A-24458644E564} [2012/05/28 14:13:37 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{A110C5EC-813F-4B66-A94B-E338D5C42F4B} [2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe [2007/08/13 11:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\EG011222\AppData\Local\CDRip.dll [2007/01/18 15:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\EG011222\AppData\Local\No23 Recorder.exe [2006/12/11 13:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\EG011222\AppData\Local\basscd.dll [2006/12/11 13:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\EG011222\AppData\Local\bass.dll [1 C:\Users\EG011222\AppData\Roaming\*.tmp files -> C:\Users\EG011222\AppData\Roaming\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/06/25 10:09:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/06/25 10:09:30 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/06/25 10:09:30 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/06/25 10:08:59 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini [2012/06/25 10:08:18 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/06/25 10:06:18 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys [2012/06/25 09:48:35 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012/06/25 09:48:35 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012/06/25 09:48:35 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/06/25 09:48:35 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/06/25 09:45:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job [2012/06/25 06:44:13 | 000,000,298 | ---- | M] () -- C:\ProgramData\SMRResults300.dat [2012/06/25 04:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012/06/24 10:45:08 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_trash_log.cmd [2012/06/24 07:53:50 | 000,003,600 | ---- | M] () -- C:\bootsqm.dat [2012/06/24 06:14:19 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/06/24 00:45:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job [2012/06/22 09:44:25 | 000,000,052 | ---- | M] () -- C:\ProgramData\kwztyvvcmhovudt [2012/06/22 09:44:19 | 000,061,440 | ---- | M] () -- C:\ProgramData\tddanntg.exe [2012/06/22 09:44:19 | 000,061,440 | ---- | M] () -- C:\ProgramData\ohpfgkae.exe [2012/06/21 09:25:58 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2012/06/20 07:33:35 | 000,061,666 | ---- | M] () -- C:\Users\EG011222\Desktop\TGV Buchungsbestätigung.pdf [2012/06/20 07:26:14 | 000,106,366 | ---- | M] () -- C:\Users\EG011222\Desktop\LE_MANS_GARE-CHARLES_DE_GAULLE_2_TGV_20-06-12.pdf [2012/06/20 02:22:13 | 000,002,486 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk [2012/06/19 02:41:58 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI [2012/06/19 02:41:47 | 000,023,745 | ---- | M] () -- C:\Users\EG011222\AppData\Roaming\Microsoft Excel.ADR [2012/06/17 06:50:56 | 000,021,504 | ---- | M] () -- C:\Windows\jestertb.dll [1 C:\Users\EG011222\AppData\Roaming\*.tmp files -> C:\Users\EG011222\AppData\Roaming\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/06/25 06:44:13 | 000,000,298 | ---- | C] () -- C:\ProgramData\SMRResults300.dat [2012/06/24 07:53:50 | 000,003,600 | ---- | C] () -- C:\bootsqm.dat [2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\tddanntg.exe [2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\ohpfgkae.exe [2012/06/22 09:44:20 | 000,000,052 | ---- | C] () -- C:\ProgramData\kwztyvvcmhovudt [2012/06/20 07:33:34 | 000,061,666 | ---- | C] () -- C:\Users\EG011222\Desktop\TGV Buchungsbestätigung.pdf [2012/06/20 07:26:14 | 000,106,366 | ---- | C] () -- C:\Users\EG011222\Desktop\LE_MANS_GARE-CHARLES_DE_GAULLE_2_TGV_20-06-12.pdf [2012/06/17 06:50:56 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll [2012/04/09 04:47:24 | 000,001,497 | ---- | C] () -- C:\Users\EG011222\AppData\Local\RecConfig.xml [2012/03/15 05:30:20 | 000,005,624 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\BAcroIEHelpe087.dll [2012/03/14 05:38:45 | 000,005,624 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\BAcroIEHelpe086.dll [2012/03/13 09:02:59 | 000,003,584 | ---- | C] () -- C:\Users\EG011222\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/12/18 08:31:25 | 000,007,667 | ---- | C] () -- C:\Users\EG011222\AppData\Local\Resmon.ResmonCfg [2011/11/07 18:38:45 | 000,000,008 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\pij8405e9rx3klvv.dat [2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp [2011/09/05 09:32:47 | 000,023,745 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\Microsoft Excel.ADR [2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll [2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe [2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp [2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat [2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat [2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini [2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin [2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll [2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll [2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll [2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll [2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll [2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini [2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI [2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini [2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll [2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin [2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll [2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin [2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin [2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll [2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll [2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll [2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll [2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini [2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4 [2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll [2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll [2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll [2007/08/13 11:46:00 | 000,155,136 | ---- | C] () -- C:\Users\EG011222\AppData\Local\lame_enc.dll [2006/10/25 19:06:48 | 000,064,000 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbisenc.dll [2006/10/25 19:06:48 | 000,019,456 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbisfile.dll [2006/10/25 19:06:46 | 000,143,872 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbis.dll [2006/10/25 19:06:36 | 000,015,872 | ---- | C] () -- C:\Users\EG011222\AppData\Local\ogg.dll [2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll [2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll [2005/08/23 16:34:06 | 000,029,184 | ---- | C] () -- C:\Users\EG011222\AppData\Local\no23xwrapper.dll [2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI ========== LOP Check ========== [2011/04/07 09:37:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ICAClient [2011/04/08 04:54:30 | 000,000,000 | ---D | M] -- C:\Users\EG005689\AppData\Roaming\ICAClient [2011/04/15 06:15:03 | 000,000,000 | ---D | M] -- C:\Users\EG005689\AppData\Roaming\Vodafone [2012/06/20 09:38:19 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\.oit [2012/06/19 02:54:39 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\.salesforce.com [2011/12/22 16:29:23 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\1&1 Mail & Media GmbH [2012/01/20 09:11:39 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Aventail [2012/04/09 06:52:49 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1 [2012/04/20 15:34:22 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\DVDVideoSoft [2011/12/23 16:59:09 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\DVDVideoSoftIEHelpers [2011/06/07 09:25:44 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Foxit [2011/06/07 09:25:45 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Foxit Software [2011/04/08 05:41:08 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\ICAClient [2012/05/24 12:24:37 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\inkscape [2012/05/02 12:03:23 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Itsth [2012/03/05 03:32:05 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\kock [2011/04/29 05:03:34 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Leadertech [2012/05/28 14:31:53 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\MyPhoneExplorer [2012/02/06 06:15:40 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia [2011/05/31 19:05:49 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia Ovi Suite [2012/02/06 06:17:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia Suite [2011/05/31 19:05:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\PC Suite [2012/03/11 11:31:48 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\RavensburgerTipToi [2012/06/19 02:54:37 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\salesforce.com [2011/04/28 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\SAP [2012/03/13 16:17:14 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\UAs [2011/04/08 06:05:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Vodafone [2011/04/28 15:50:10 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Vodafone Mobile Connect [2012/03/13 16:17:57 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\xmldm [2012/05/22 13:49:52 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\XnView [2011/12/23 16:54:22 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Youtube Downloader HD [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications [2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail [2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom [2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2012/06/22 09:44:24 | 000,000,000 | ---D | M] -- C:\ProgramData\egvixvcletcqitf [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia [2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount [2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache [2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite [2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi [2012/06/19 02:54:37 | 000,000,000 | ---D | M] -- C:\ProgramData\salesforce.com [2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2012/05/02 12:51:41 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP [2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall [2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb [2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone [2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2012/05/17 14:50:32 | 000,000,000 | ---D | M] -- C:\ProgramData\Windows [2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip [2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater [2012/05/07 04:12:47 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9FF7C773 < End of report > [/CODE] |
25.06.2012, 12:47 | #4 |
| Bundestrojaner sperrt Win7 Hi, Script auf USB-Stick kopieren, von OTL-Disk booten, rüberkopieren und wie folgt verfahren: By teh way: Du hast die Enterpriseedition (McAfee) im Einsatz, ist das ein Firmenrechner (auch die Cloudlösung spricht dafür)... Dann muß sich eigentlich der Sysadmin darum kümmern... Fix für OTL:
Code:
ATTFilter :OTL O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe () O4 - HKU\EG011222_ON_C..\Run: [] File not found O4 - HKU\EG011222_ON_C..\Run: [7Rxb5FismTZydeX] File not found O4 - HKU\EG011222_ON_C..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe () O20 - Winlogon\Notify\ecojink: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll - File not found [2012/06/25 04:47:38 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\NPE [2012/06/22 09:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\egvixvcletcqitf [2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\tddanntg.exe [2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\ohpfgkae.exe [2012/06/22 09:44:20 | 000,000,052 | ---- | C] () -- C:\ProgramData\kwztyvvcmhovudt [2012/06/17 06:50:56 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll [2012/06/22 09:44:24 | 000,000,000 | ---D | M] -- C:\ProgramData\egvixvcletcqitf @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9FF7C773 :Commands [emptytemp] [resethosts] [createrestorepoint] [Reboot]
Der Rechner sollte jetzt wieder booten... Malwarebytes Antimalware (MAM) Anleitung&Download hier: http://www.trojaner-board.de/51187-m...i-malware.html Falls der Download nicht klappt, bitte hierüber eine generische Version runterladen: http://filepony.de/download-chameleon/ Danach bitte update der Signaturdateien (Reiter "Aktualisierungen" -> Suche nach Aktualisierungen") Fullscan und alles bereinigen lassen! Log posten. chris
__________________ Don't bring me down Vor dem posten beachten! Spenden (Wer spenden will, kann sich gerne melden ) |
25.06.2012, 13:27 | #5 |
| Bundestrojaner sperrt Win7 Hi, also erst mal vielen Dank für die Hilfe. Ich kann zumindest mal wieder hochfahren. Das mit dem Firmenrechner ist nicht ganz richtig. Das ist ein ehemaliger Rechner meiner Firma. Den hab ich so wie er jetzt ist gekauft. Das es da eine Cloudlösung gibt ist mir noch nicht einmal bekannt ;-) Ist das nur allgemein oder soll ich auch das LOG von Malwarebytes posten? greggy |
25.06.2012, 16:52 | #6 |
| Bundestrojaner sperrt Win7 Hi, bitte beide Logs posten... (OTL, MAM)... chris
__________________ --> Bundestrojaner sperrt Win7 |
Themen zu Bundestrojaner sperrt Win7 |
andere, anderen, beiträge, bundes, bundestrojaner, bundestrojaner eingefangen, einfach, eingefangen, erstell, gefangen, gen, hochfahren, laufe, laufen, log, poste, posten, rechner, scan, sperrt, win, win7 |