|
Log-Analyse und Auswertung: Immer wieder Trojan.Banker in \AppData\RoamingWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
23.07.2012, 20:03 | #1 |
| Immer wieder Trojan.Banker in \AppData\Roaming Hallo liebe Community, mein AntiVirus (AVG Free) findet seit Kurzem immer wieder Trojaner und zwar immer in C:\Users\***\AppData\Roaming\ . Die Trojaner werden erfolgreich in Quarantäne verschoben, aber es tauchen immer wieder neue auf. Ich bin ein absoluter Leihe auf dem Gebiet und hoffe Ihr könnt mir weiterhelfen. Das ist das Logfile von Malwarebytes Anti-Malware (Quick Scan): Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.07.22.06 Windows Vista x86 NTFS Internet Explorer 7.0.6000.17037 *** :: ***-PC [Administrator] Schutz: Aktiviert 22.07.2012 14:44:36 mbam-log-2012-07-22 (14-44-36).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 427971 Laufzeit: 2 Stunde(n), 4 Minute(n), 57 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 3 HKCR\CLSID\{20C28584-8F10-4D92-987C-0A1008E2435A} (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20C28584-8F10-4D92-987C-0A1008E2435A} (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{20C28584-8F10-4D92-987C-0A1008E2435A} (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\***\AppData\Roaming\BAcroIEHelpe155.dll (Trojan.Banker) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Und hier das von OTL: OTL logfile created on: 22.07.2012 21:16:31 - Run 2 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\***\Downloads Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.17037) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,99 Gb Total Physical Memory | 0,98 Gb Available Physical Memory | 49,33% Memory free 4,19 Gb Paging File | 2,88 Gb Available in Paging File | 68,75% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 92,21 Gb Total Space | 29,48 Gb Free Space | 31,98% Space Free | Partition Type: NTFS Drive D: | 45,12 Gb Total Space | 21,65 Gb Free Space | 47,98% Space Free | Partition Type: NTFS Unable to calculate disk information. Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.07.22 20:26:54 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\***\Downloads\OTL.exe PRC - [2012.07.09 12:51:33 | 000,935,008 | ---- | M] () -- C:\Programme\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe PRC - [2012.07.09 12:51:29 | 001,107,552 | ---- | M] () -- C:\Programme\AVG Secure Search\vprot.exe PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.07.03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.04.04 07:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.01.28 12:47:08 | 002,077,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG9\avgtray.exe PRC - [2012.01.16 23:45:34 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\Update\realsched.exe PRC - [2011.06.17 19:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.207\SSScheduler.exe PRC - [2010.11.25 15:04:08 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG9\avgcsrvx.exe PRC - [2010.09.24 11:25:45 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG9\avgnsx.exe PRC - [2010.09.07 18:47:18 | 000,202,048 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperService.exe PRC - [2010.09.07 18:47:08 | 000,664,896 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe PRC - [2010.07.15 19:57:51 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG9\avgrsx.exe PRC - [2010.07.15 19:57:47 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG9\avgwdsvc.exe PRC - [2010.07.15 19:57:41 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programme\AVG\AVG9\avgchsvx.exe PRC - [2009.12.02 17:36:16 | 000,172,544 | ---- | M] (Panasonic Corporation) -- C:\Programme\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe PRC - [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.01.29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Programme\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe PRC - [2008.01.28 03:09:07 | 002,641,920 | ---- | M] (pdfforge hxxp://www.pdfforge.org/) -- C:\Programme\PDFCreator\PDFCreator.exe PRC - [2008.01.10 01:40:22 | 001,232,896 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2007.10.26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) -- C:\Users\***\Desktop\vpn\cvpnd.exe PRC - [2007.09.26 11:53:56 | 000,554,352 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe PRC - [2007.06.26 20:27:46 | 000,312,320 | ---- | M] (shbox.de) -- C:\Programme\FreePDF_XP\fpassist.exe PRC - [2007.03.14 00:00:00 | 004,399,104 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe PRC - [2006.11.22 18:31:26 | 000,630,784 | ---- | M] (Motorola Inc.) -- C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe PRC - [2006.11.02 11:45:59 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe PRC - [2006.11.02 11:44:59 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2006.10.27 01:47:42 | 000,031,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe ========== Modules (No Company Name) ========== MOD - [2012.07.20 21:36:15 | 000,133,632 | ---- | M] () -- C:\Users\***~1\AppData\Local\Google\Chrome\USERDA~1\Default\EXTENS~2\DHKPLH~1\1.7_0\BABYLO~1.DLL MOD - [2012.07.09 12:51:33 | 000,132,704 | ---- | M] () -- C:\Programme\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll MOD - [2012.07.09 12:51:29 | 001,107,552 | ---- | M] () -- C:\Programme\AVG Secure Search\vprot.exe MOD - [2012.06.27 18:38:52 | 000,531,968 | ---- | M] () -- C:\Users\***\AppData\Roaming\BabylonToolbar\CR\BUSolution.dll MOD - [2011.10.09 16:02:35 | 000,689,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlServ#\96da3dc0cfd812f4f284902dbf93c699\System.Data.SqlServerCe.ni.dll MOD - [2010.09.07 18:47:08 | 000,664,896 | ---- | M] () -- C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe MOD - [2009.10.16 23:37:13 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e6001d416f7c468334934a2c6a41c631\System.Configuration.ni.dll MOD - [2009.10.16 19:39:29 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\7208ffa39630e9b923331f9df0947a12\System.Xml.ni.dll MOD - [2009.10.16 19:37:46 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1941d7639299344ae28fb6b23da65247\System.Windows.Forms.ni.dll MOD - [2009.10.16 19:36:59 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6312464f64727a2a50d5ce3fd73ad1bb\System.Drawing.ni.dll MOD - [2009.10.16 19:35:22 | 006,616,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\813556b5a2722045b0ea14467fd00227\System.Data.ni.dll MOD - [2009.10.16 19:30:55 | 007,868,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\52e1ea3c7491e05cda766d7b3ce3d559\System.ni.dll MOD - [2009.10.16 19:29:12 | 011,486,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\17f572b09facdc5fda9431558eb7a26e\mscorlib.ni.dll MOD - [2008.07.27 20:00:26 | 002,933,248 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll MOD - [2008.07.27 20:00:17 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2007.11.28 20:59:42 | 003,702,784 | ---- | M] () -- C:\Programme\PDFCreator\GS8.61\gs8.61\Bin\gsdll32.dll MOD - [2006.11.22 18:31:30 | 000,065,536 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56ita.dll MOD - [2006.11.22 18:31:30 | 000,065,536 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56esp.dll MOD - [2006.11.22 18:31:30 | 000,065,536 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56brz.dll MOD - [2006.11.22 18:31:30 | 000,053,248 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56kor.dll MOD - [2006.11.22 18:31:28 | 000,065,536 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56ger.dll MOD - [2006.11.22 18:31:28 | 000,065,536 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56fra.dll MOD - [2006.11.22 18:31:28 | 000,065,536 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56dnk.dll MOD - [2006.11.22 18:31:28 | 000,057,344 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56jpn.dll MOD - [2006.11.22 18:31:28 | 000,053,248 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56cht.dll MOD - [2006.11.22 18:31:28 | 000,053,248 | ---- | M] () -- C:\Programme\Motorola\SMSERIAL\sm56chs.dll MOD - [2005.03.30 23:23:08 | 000,124,416 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll MOD - [2003.07.11 04:09:28 | 000,048,192 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\Web Folders\1031\NSEXTINT.DLL ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (LiveUpdate Notice Ex) SRV - File not found [Auto | Stopped] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (CLTNetCnService) SRV - [2012.07.20 21:22:05 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.09 12:51:33 | 000,935,008 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -- (vToolbarUpdater11.2.0) SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.06.07 12:09:53 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.03 08:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.04.04 07:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.11.10 15:17:31 | 000,167,264 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\AVG\AVG9\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service) SRV - [2011.06.17 19:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService) SRV - [2010.09.07 18:47:18 | 000,202,048 | ---- | M] () [Auto | Running] -- C:\Programme\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper) SRV - [2010.07.15 19:57:47 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Programme\AVG\AVG9\avgwdsvc.exe -- (avg9wd) SRV - [2008.01.29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service) SRV - [2007.10.26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Users\***\Desktop\vpn\cvpnd.exe -- (CVPND) SRV - [2007.09.26 11:53:56 | 002,999,664 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate) SRV - [2007.09.26 11:53:56 | 000,554,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatisches LiveUpdate - Scheduler) SRV - [2007.08.01 15:36:58 | 000,290,816 | ---- | M] (T-Systems Enterprise Services GmbH) [On_Demand | Stopped] -- C:\Programme\T-Online\DSL-Manager\DslMgrSvc.exe -- (TDslMgrService) SRV - [2007.07.04 13:12:03 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2006.11.02 14:36:04 | 000,895,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2006.11.02 11:46:13 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2006.11.02 11:46:12 | 000,167,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) SRV - [2006.10.27 01:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service) SRV - [2006.10.26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006.10.26 15:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2011.09.12 19:01:45 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (AvgMfx86) DRV - [2011.05.05 19:11:42 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (AvgTdiX) DRV - [2010.07.15 19:57:42 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (AvgLdx86) DRV - [2010.06.18 16:09:48 | 000,023,936 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem) DRV - [2010.06.18 15:41:34 | 000,019,968 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgp.sys -- (motccgp) DRV - [2010.04.01 15:31:50 | 000,023,424 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Motousbnet.sys -- (Motousbnet) DRV - [2010.01.25 20:56:44 | 000,009,472 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motusbdevice.sys -- (motusbdevice) DRV - [2009.01.29 18:18:00 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl) DRV - [2009.01.29 18:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService) DRV - [2007.11.02 16:51:30 | 000,006,400 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService) DRV - [2007.10.26 14:27:00 | 000,306,300 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2007.08.01 15:49:00 | 000,016,448 | ---- | M] (T-Systems Enterprise Services GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\dslmnlwf.sys -- (DslMNLwf) DRV - [2007.02.25 06:14:00 | 002,216,448 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R) DRV - [2007.01.31 13:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE) DRV - [2007.01.18 16:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA) DRV - [2007.01.15 23:28:20 | 000,070,144 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2006.11.22 18:35:00 | 000,982,272 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2006.11.02 10:55:05 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb) DRV - [2006.11.02 09:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel(R) DRV - [2006.07.14 14:55:34 | 000,105,088 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvatabus.sys -- (nvatabus) DRV - [2005.08.30 18:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm) DRV - [2005.08.30 18:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl) DRV - [2005.08.30 18:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?affID=110819&tt=190712_n_mont_2912_8&babsrc=HP_ss&mntrId=dcd19e93000000000000001b77728b46 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=110819&tt=190712_n_mont_2912_8&babsrc=SP_ss&mntrId=dcd19e93000000000000001b77728b46 IE - HKCU\..\SearchScopes\{31CF9EBE-5755-4a1d-AC25-2834D952D9B4}: "URL" = hxxp://search.pdfcreator-toolbar.org/search?p=Q&ts=ne&w={searchTerms}&csrc=search-field IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPB_de IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={69C485A0-DEE6-44C7-B82C-4D59351964E6}&mid=8282d1591555d70385a51acd52f0603f-a77818d523489fd002351b8c0a29c0946d1fcd56&lang=de&ds=AVG&pr=fr&d=2011-12-18 11:11:40&v=10.0.0.7&sap=dsp&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.order.1: "Search the web (Babylon)" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.update: false FF - prefs.js..browser.startup.homepage: "hxxp://search.babylon.com/?affID=110819&tt=190712_n_mont_2912_8&babsrc=HP_ss&mntrId=dcd19e93000000000000001b77728b46" FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872 FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001 FF - prefs.js..keyword.URL: "hxxp://search.babylon.com/?affID=110819&tt=190712_n_mont_2912_8&babsrc=KW_ss&mntrId=dcd19e93000000000000001b77728b46&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011.09.12 19:03:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.12\ [2012.07.09 12:51:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.01.16 23:46:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.07 12:09:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.07.20 22:06:48 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Users\***\AppData\Roaming\13008 [2012.06.20 22:20:20 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}: C:\Users\***\AppData\Roaming\13001.027 [2012.07.18 20:20:44 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.07 12:09:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.07.20 22:06:48 | 000,000,000 | ---D | M] [2008.07.06 18:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2012.07.21 23:56:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\86hc9w61.default\extensions [2010.04.27 19:03:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\86hc9w61.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012.07.20 21:32:42 | 000,000,000 | ---D | M] (DealPly) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\86hc9w61.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2012.07.20 21:31:42 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\86hc9w61.default\extensions\plugin@yontoo.com [2011.08.18 20:58:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.06.01 08:46:39 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012.07.18 20:20:44 | 000,000,000 | ---D | M] (Java Link Helper) -- C:\USERS\***\APPDATA\ROAMING\13001.027 [2012.06.20 22:20:20 | 000,000,000 | ---D | M] (Java Link Helper) -- C:\USERS\***\APPDATA\ROAMING\13008 [2012.06.07 12:09:55 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.06.07 12:09:48 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.07.09 12:51:28 | 000,003,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml [2012.07.20 21:32:09 | 000,002,363 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2012.06.07 12:09:48 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.06.07 12:09:48 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.06.07 12:09:48 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.06.07 12:09:48 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.06.07 12:09:48 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - homepage: hxxp://search.babylon.com/?affID=110819&tt=190712_n_mont_2912_8&babsrc=HP_ss&mntrId=dcd19e93000000000000001b77728b46 CHR - default_search_provider: Search the web (Babylon) (Enabled) CHR - default_search_provider: search_url = hxxp://search.babylon.com/?q={searchTerms}&affID=110819&tt=190712_n_mont_2912_8&babsrc=SP_ss&mntrId=dcd19e93000000000000001b77728b46 CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://search.babylon.com/?affID=110819&tt=190712_n_mont_2912_8&babsrc=HP_ss&mntrId=dcd19e93000000000000001b77728b46 CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\gcswf32.dll CHR - plugin: Shockwave Flash (Disabled) = C:\Users\***\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: Babylon Toolbar = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.7_0\ CHR - Extension: DealPly = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.0.7.2_0\ CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\ CHR - Extension: Skype Click to Call = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\ CHR - Extension: Yontoo = C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\ O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Programme\BabylonToolbar\BabylonToolbar\1.5.29.1\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programme\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programme\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Programme\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.) O2 - BHO: (PDFCreator Toolbar Helper) - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll File not found O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll File not found O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programme\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Programme\BabylonToolbar\BabylonToolbar\1.5.29.1\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (PDFCreator Toolbar) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll File not found O4 - HKLM..\Run: [AVG9_TRAY] C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [HF_G_Jul] C:\Program Files\AVG Secure Search\HF_G_Jul.exe () O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation) O4 - HKLM..\Run: [TkBellExe] c:\program files\Update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe () O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation) O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} hxxp://static.ak.studivz.net/photouploader/ImageUploader4.cab (Image Uploader Control) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7442A3D2-65DC-4B48-A448-4D704C0229F6}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programme\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Programme\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll () O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img19.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img19.jpg O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{0f863e6c-ec99-11de-860c-00030d6ef376}\Shell\AutoRun\command - "" = G:\Menu.exe O33 - MountPoints2\{673d3687-ed50-11de-bd71-00030d6ef376}\Shell\AutoRun\command - "" = F:\Menu.exe O33 - MountPoints2\{6fdbd4d9-5339-11de-9a06-00030d6ef376}\Shell\AutoRun\command - "" = ysep1.exe O33 - MountPoints2\{6fdbd4d9-5339-11de-9a06-00030d6ef376}\Shell\open\Command - "" = ysep1.exe O33 - MountPoints2\{aac31f78-9ab7-11de-8f19-00030d6ef376}\Shell - "" = AutoRun O33 - MountPoints2\{aac31f78-9ab7-11de-8f19-00030d6ef376}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O33 - MountPoints2\{efecf9ba-1755-11e1-b168-00030d6ef376}\Shell - "" = AutoRun O33 - MountPoints2\{efecf9ba-1755-11e1-b168-00030d6ef376}\Shell\AutoRun\command - "" = F:\setup.exe -a O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012.07.22 14:41:45 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2012.07.22 14:40:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.07.22 14:40:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.07.22 14:40:41 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.07.22 14:40:41 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.07.20 22:06:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2012.07.20 21:32:52 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\BabylonToolbar [2012.07.20 21:32:35 | 000,000,000 | ---D | C] -- C:\Program Files\BabylonToolbar [2012.07.20 21:31:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Creator [2012.07.20 21:31:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly [2012.07.20 21:31:40 | 000,000,000 | ---D | C] -- C:\Program Files\Yontoo [2012.07.20 21:31:38 | 000,000,000 | ---D | C] -- C:\Program_Zusatz [2012.07.20 21:31:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2012.07.20 21:31:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon [2012.07.20 21:31:26 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Babylon [2012.07.20 21:31:24 | 000,000,000 | ---D | C] -- C:\Program Files\DealPly [2012.07.20 21:16:55 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.07.18 20:20:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.027 [2012.07.17 22:31:22 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.026 [2012.07.15 23:24:04 | 000,000,000 | ---D | C] -- C:\61c81ed55522a94c4949 [2012.07.15 21:28:41 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.025 [2012.07.10 14:39:35 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.021 [2012.07.09 12:41:10 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.020 [2012.07.08 14:59:08 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.019 [2012.07.07 16:39:23 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.018 [2012.07.07 12:48:41 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.017 [2012.07.04 21:57:30 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.015 [2012.07.01 15:52:13 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.013 [2012.07.01 10:44:24 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Macromedia [2012.07.01 10:07:55 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\13001.012 [2012.01.16 23:46:47 | 000,016,896 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\wmdmhelper.dll [2012.01.16 23:46:43 | 000,139,264 | ---- | C] (Inner Media, Inc.) -- C:\Program Files\dunzip32.dll [2012.01.16 23:46:43 | 000,034,304 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rjprog.dll [2012.01.16 23:46:42 | 000,361,984 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rjdlg.dll [2012.01.16 23:46:40 | 000,641,536 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rjbres.dll [2012.01.16 23:46:40 | 000,045,056 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\ierjplug.dll [2012.01.16 23:46:39 | 000,009,728 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\fixrjb.exe [2012.01.16 23:46:37 | 001,115,376 | ---- | C] (Gracenote) -- C:\Program Files\cddbmusicid.dll [2012.01.16 23:46:36 | 000,943,344 | ---- | C] (Gracenote) -- C:\Program Files\cddblink.dll [2012.01.16 23:46:32 | 002,041,072 | ---- | C] (Gracenote, Inc.) -- C:\Program Files\cddbcontrol.dll [2012.01.16 23:46:32 | 000,074,240 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\tsasdk.dll [2012.01.16 23:46:32 | 000,045,056 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\mmcdda32.dll [2012.01.16 23:46:32 | 000,023,552 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\tnetdtct.dll [2012.01.16 23:46:31 | 000,048,640 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\tpasdk.dll [2012.01.16 23:46:29 | 000,067,584 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rpwa3260.dll [2012.01.16 23:46:27 | 000,045,728 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rpshellsearch.dll [2012.01.16 23:46:17 | 000,375,416 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\realconverter.exe [2012.01.16 23:46:17 | 000,349,304 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\convert.exe [2012.01.16 23:46:15 | 000,390,384 | ---- | C] (MainConcept GmbH) -- C:\Program Files\mc_enc_mp4v.dll [2012.01.16 23:46:12 | 000,381,040 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\realtrimmer.exe [2012.01.16 23:46:12 | 000,129,648 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\realshare.exe [2012.01.16 23:46:08 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dbghelp.dll [2012.01.16 23:46:07 | 000,072,192 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rjwmapln.dll [2012.01.16 23:46:04 | 000,046,592 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rpau3260.dll [2012.01.16 23:45:44 | 000,029,824 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rndevicedbbuilder.exe [2012.01.16 23:45:43 | 000,088,064 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\hxaudiodevicehook.dll [2012.01.16 23:45:42 | 000,116,888 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rdsf3260.dll [2012.01.16 23:45:42 | 000,086,528 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rpplugprot.dll [2012.01.16 23:45:42 | 000,064,656 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rpshell.dll [2012.01.16 23:45:38 | 000,018,072 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\rphelperapp.exe [2012.01.16 23:45:38 | 000,010,240 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\realjbox.exe [2012.01.16 23:45:37 | 000,499,312 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\realplay.exe [2012.01.16 23:45:35 | 000,439,464 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\recordingmanager.exe [10 C:\Users\***\Desktop\*.tmp files -> C:\Users\***\Desktop\*.tmp -> ] [1 C:\Users\***\AppData\Roaming\*.tmp files -> C:\Users\***\AppData\Roaming\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.07.22 21:20:20 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E003C6A6-7B0E-4229-84A0-146E9AD56B69}.job [2012.07.22 21:16:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.07.22 20:52:19 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012.07.22 20:52:19 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012.07.22 20:33:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.07.22 20:25:24 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable [2012.07.22 19:52:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.07.22 16:56:26 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.07.22 16:56:00 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys [2012.07.22 14:40:44 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.07.22 13:46:28 | 101,968,570 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm [2012.07.21 22:47:53 | 005,330,588 | ---- | M] () -- C:\Users\***\Desktop\1.rar [2012.07.21 22:43:03 | 000,047,811 | ---- | M] () -- C:\Users\***\Desktop\pddr.zip [2012.07.20 22:06:49 | 000,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012.07.20 21:32:36 | 000,000,318 | ---- | M] () -- C:\user.js [2012.07.18 22:35:51 | 000,000,034 | ---- | M] () -- C:\Users\***\AppData\Roaming\blckdom.res [2012.07.16 21:30:32 | 000,000,037 | ---- | M] () -- C:\Users\***\AppData\Roaming\urhtps.dat [2012.07.15 20:47:49 | 000,001,977 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012.07.09 21:27:33 | 000,000,454 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for ***.job [2012.07.07 22:13:45 | 000,470,478 | ---- | M] () -- C:\Users\***\Desktop\FLT_2DEZB829094_0.pdf [2012.07.04 21:06:43 | 000,641,344 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.07.04 21:06:43 | 000,610,142 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.07.04 21:06:43 | 000,116,706 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.07.04 21:06:43 | 000,103,924 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [10 C:\Users\***\Desktop\*.tmp files -> C:\Users\***\Desktop\*.tmp -> ] [1 C:\Users\***\AppData\Roaming\*.tmp files -> C:\Users\***\AppData\Roaming\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.07.22 20:25:24 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable [2012.07.22 14:40:44 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.07.20 22:06:49 | 000,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012.07.20 22:06:48 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2012.07.20 21:32:35 | 000,000,318 | ---- | C] () -- C:\user.js [2012.07.20 21:31:53 | 000,086,016 | ---- | C] () -- C:\Windows\System32\custmon32i.dll [2012.07.15 23:21:32 | 000,047,811 | ---- | C] () -- C:\Users\***\Desktop\pddr.zip [2012.07.09 21:07:06 | 000,000,037 | ---- | C] () -- C:\Users\***\AppData\Roaming\urhtps.dat [2012.07.07 22:13:45 | 000,470,478 | ---- | C] () -- C:\Users\***\Desktop\FLT_2DEZB829094_0.pdf [2012.06.11 21:53:33 | 000,000,034 | ---- | C] () -- C:\Users\***\AppData\Roaming\blckdom.res [2012.06.03 15:52:14 | 000,000,448 | ---- | C] () -- C:\ProgramData\pjetsiyyyiqnsvj [2012.01.16 23:46:39 | 000,002,851 | ---- | C] () -- C:\Program Files\cdroms.cfg [2012.01.16 23:46:29 | 000,119,808 | ---- | C] () -- C:\Program Files\waiting.avi [2012.01.16 23:46:29 | 000,027,278 | ---- | C] () -- C:\Program Files\frw.bmp [2012.01.16 23:46:29 | 000,016,296 | ---- | C] () -- C:\Program Files\realtfon.fon [2012.01.16 23:46:28 | 000,057,762 | ---- | C] () -- C:\Program Files\howto.chm [2012.01.16 23:46:28 | 000,040,154 | ---- | C] () -- C:\Program Files\realplay.chm [2012.01.16 23:46:17 | 000,800,292 | ---- | C] () -- C:\Program Files\converter.vs [2012.01.16 23:46:12 | 000,045,405 | ---- | C] () -- C:\Program Files\sharemedia.vs [2012.01.16 23:46:10 | 000,001,209 | ---- | C] () -- C:\Program Files\flvplay.swf [2012.01.16 23:46:04 | 000,028,013 | ---- | C] () -- C:\Program Files\RealNetworks License.html [2012.01.16 23:46:04 | 000,028,013 | ---- | C] () -- C:\Program Files\playrlic.html [2012.01.16 23:45:53 | 000,055,043 | ---- | C] () -- C:\Program Files\presets.rnx [2012.01.16 23:45:52 | 000,000,480 | ---- | C] () -- C:\Program Files\keys.dat [2012.01.16 23:45:50 | 000,061,495 | ---- | C] () -- C:\Program Files\ssimages.vs [2012.01.16 23:45:49 | 000,943,150 | ---- | C] () -- C:\Program Files\normal.vs [2012.01.16 23:45:41 | 000,001,030 | ---- | C] () -- C:\Program Files\autoplaylist.dat [2012.01.16 23:45:41 | 000,000,050 | ---- | C] () -- C:\Program Files\strs23.dat [2012.01.16 23:45:41 | 000,000,013 | ---- | C] () -- C:\Program Files\strs26.dat [2012.01.16 23:45:37 | 000,017,846 | ---- | C] () -- C:\Program Files\videotest.rm [2012.01.16 23:45:37 | 000,000,221 | ---- | C] () -- C:\Program Files\subscription.rnx [2012.01.16 23:45:37 | 000,000,177 | ---- | C] () -- C:\Program Files\freeoffers.rnx [2011.10.09 16:03:44 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2011.10.09 16:03:44 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat [2011.10.09 16:03:44 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat [2011.10.09 16:03:44 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2011.10.09 16:03:44 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat [2011.10.09 16:03:44 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat [2011.10.09 16:03:44 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2011.10.09 16:03:44 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat [2011.10.09 16:03:44 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat [2011.10.09 16:03:44 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat [2011.10.09 16:03:44 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat [2011.10.09 16:03:44 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat [2011.10.09 16:03:44 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat [2011.10.09 16:03:44 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat [2011.10.09 16:03:44 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat [2011.10.09 16:03:44 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat [2011.10.09 16:03:44 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat [2011.10.09 16:03:44 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat [2011.10.09 16:03:44 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2010.01.04 19:53:32 | 001,456,640 | ---- | C] () -- C:\Program Files\Common Files\Falk Navi-Manager.msi [2009.12.22 20:28:44 | 000,008,398 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate [2009.12.21 02:02:03 | 000,000,680 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2009.12.01 01:44:10 | 000,000,000 | ---- | C] () -- C:\Users\***\AppData\Local\prvlcl.dat [2009.02.05 15:52:16 | 000,001,074 | RH-- | C] () -- C:\Users\***\XrxWm.ini [2009.02.05 15:52:16 | 000,000,522 | RH-- | C] () -- C:\Users\***\xw45cpdy.dyc [2008.12.11 18:35:59 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2008.03.23 23:54:04 | 000,004,096 | -H-- | C] () -- C:\Users\***\AppData\Local\keyfile3.drm [2007.09.08 13:55:22 | 000,000,100 | ---- | C] () -- C:\Users\***\AppData\Local\fusioncache.dat [2007.09.01 16:58:58 | 000,000,236 | ---- | C] () -- C:\Users\***\AppData\Roaming\wklnhst.dat [2007.08.31 19:35:05 | 000,026,624 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== LOP Check ========== [2012.07.01 10:08:03 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.012 [2012.07.01 15:52:13 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.013 [2012.07.04 21:57:35 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.015 [2012.07.07 12:48:51 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.017 [2012.07.07 16:39:32 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.018 [2012.07.08 15:39:20 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.019 [2012.07.09 12:41:18 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.020 [2012.07.10 14:39:36 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.021 [2012.07.15 21:28:41 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.025 [2012.07.17 22:31:38 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.026 [2012.07.18 20:20:44 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13001.027 [2012.06.11 21:53:43 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13003 [2012.06.12 20:37:59 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13004 [2012.06.20 22:20:20 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\13008 [2008.09.20 17:33:55 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\aAvgApi [2012.07.20 21:31:26 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Babylon [2012.07.20 21:32:53 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\BabylonToolbar [2012.06.11 21:53:13 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\kock [2009.11.01 00:18:46 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\lyx16 [2009.05.01 12:28:29 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\MuPAD [2009.12.21 08:25:47 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Stata10 [2007.09.08 13:21:41 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\T-Online [2007.09.01 23:26:29 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Template [2012.06.11 23:02:28 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\UAs [2009.10.31 23:54:02 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\xm1 [2012.06.11 21:53:34 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\xmldm [2012.07.22 16:54:57 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2012.07.22 21:20:20 | 000,000,432 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{E003C6A6-7B0E-4229-84A0-146E9AD56B69}.job ========== Purity Check ========== < End of report > Tausend Dank schon Mal! |
27.07.2012, 13:03 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Immer wieder Trojan.Banker in \AppData\RoamingCode:
ATTFilter C:\Users\***\AppData\Roaming\BAcroIEHelpe155.dll (Trojan.Banker)
__________________ |
28.07.2012, 08:20 | #3 |
| Immer wieder Trojan.Banker in \AppData\Roaming Letzte Zeit (seit etwa zwei Wochen) mache ich kein Online Banking mehr von diesem Laptop aus, früher schon. Danke für die Rückmeldung!
__________________ |
28.07.2012, 22:21 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Immer wieder Trojan.Banker in \AppData\Roaming Willst du auch weiterhin unter Windows mit diesem Rechner sicher OnlineBanking machen?
__________________ Logfiles bitte immer in CODE-Tags posten |
19.08.2012, 13:58 | #5 |
| Immer wieder Trojan.Banker in \AppData\Roaming Sorry für die späte Antwort, war im Urlaub. Ja, ich würde gerne mit diesem Rechner irgendwann mal wieder sicher Online Banking machen. Wird's noch möglich sein??? VG |
20.08.2012, 20:32 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Immer wieder Trojan.Banker in \AppData\Roaming Wenn unter Windows solltest du das System neu aufsetzen - andere "sichere" Möglichkeit gibt es nicht, mit einem derartig bereinigten System wären noch zuviele Risiken da - willst du die eingehen?
__________________ --> Immer wieder Trojan.Banker in \AppData\Roaming |
20.08.2012, 20:46 | #7 |
| Immer wieder Trojan.Banker in \AppData\Roaming Eine andere Wahl habe ich ja anscheinend nicht |
21.08.2012, 12:34 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Immer wieder Trojan.Banker in \AppData\Roaming Wie gesagt, man kann bereinigen wenn du das Risiko eingehen willst und dann wieder OnlineBanking mit dieser Kiste machen willst unter Windows
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Immer wieder Trojan.Banker in \AppData\Roaming |
antivirus, avg secure search, avg security toolbar, babylon toolbar, babylontoolbar, bho, browser, cid, dealply, desktop, downloader, error, excel, firefox, flash player, format, google, helper, heuristiks/extra, heuristiks/shuriken, home, logfile, mozilla, plug-in, realtek, registry, scan, search the web, searchscopes, secure search, security, senden, software, symantec, tarma, trojan.agent, trojan.banker, trojaner, vista, vtoolbarupdater, yontoo |