![]() |
|
Plagegeister aller Art und deren Bekämpfung: Yahoo Mail Acc verschickt Spam Mails an persönliche KontakteWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Yahoo Mail Acc verschickt Spam Mails an persönliche Kontakte Liebe Community, wie bereits im Titel erwähnt wurde, verschickt mein Yahoo Mail Acc. seit zwei Tagen an einige Leute aus meiner Kontaktliste Spam Mails. Ich wurde darauf aufmerksam, weil mich Bekannte darauf angesprochen haben. Wenn ich über den Browser auf yahoo zugreife sehe ich jedoch keine ausgegangenen Mails im Ordner "Gedendet" , auch mein Outlook zeigt mir keine Mails im Ausgang an, welche ich nicht selbst verschickt hatte. Mein Passwort auf yahoo habe ich bereits geändert: es bestand zuvor aus 8 Stellen, aber lediglich aus Kleinbuchstaben und Ziffern, habe dies nun in 8 Stellen, Klein- und Großbuchstaben , sowie Ziffern umgeändert. Anbei nun - hoffentlich alle wichtigen - logs (bin ein totaler newbie in diesem bereich...): [malware, eset, OTL, extras] - habe jene scans durchgeführt, die ich bei der Suche nach dem Thema in diversen threads fand: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.07.31.01 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 9.0.8112.16421 Thomas :: THOMAS-PC [Administrator] Schutz: Aktiviert 31.07.2012 03:27:35 mbam-log-2012-07-31 (03-27-35).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 369391 Laufzeit: 52 Minute(n), 56 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 11 HKCR\AppID\{D2083641-E57F-4eab-BB85-0582424F4A29} (Adware.HotBar.CP) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\ClickPotatoLiteAX.info (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\ClickPotatoLiteAX.info.1 (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\ClickPotatoLiteAX.UserProfiles (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\ClickPotatoLiteAX.UserProfiles.1 (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\MenuButtonIE.ButtonIE (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\MenuButtonIE.ButtonIE.1 (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\AppID\MenuButtonIE.DLL (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\clickpotatolitesa (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\ClickPotatoLite (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 1 HKLM\SOFTWARE\Mozilla\Firefox\extensions|ClickPotatoLite@ClickPotatoLite.com (Adware.ClickPotato) -> Daten: C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\firefox\extensions -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 9 C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\ClickPotatoLiteSA (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0 (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\firefox (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\firefox\extensions (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\firefox\extensions\plugins (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 20 C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSACB.exe (Adware.HotBar.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAHook.dll (Adware.HotBar.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\firefox\extensions\plugins\npclntax_ClickPotatoLiteSA.dll (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\Mozilla Firefox\plugins\npclntax_ClickPotatoLiteSA.dll (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FKMSU1KU\DivX_Installer[1].exe (Rootkit.Dropper) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Temp\274436984.Uninstall\Uninstall.exe (Affiliate.Downloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\AppData\Local\Temp\ICReinstall\MusicConverterSetup.exe (Affiliate.Downloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Thomas\Downloads\simx.exe (PUP.Adware.RKN) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\L\00000008.@ (Trojan.BitMiner) -> Löschen bei Neustart. C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA.dat (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAAbout.mht (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAau.dat (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAEULA.mht (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA_kyf_update.dat (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\copyright.txt (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\ClickPotatoLite\bin\10.0.728.0\firefox\extensions\install.rdf (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\About Us.lnk (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Customer Support.lnk (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Uninstall Instructions.lnk (Adware.ClickPotato) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter OTL logfile created on: 31.07.2012 10:50:47 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Thomas\Downloads 64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 3,19 Gb Total Physical Memory | 1,96 Gb Available Physical Memory | 61,57% Memory free 6,57 Gb Paging File | 5,09 Gb Available in Paging File | 77,47% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 116,46 Gb Total Space | 20,81 Gb Free Space | 17,87% Space Free | Partition Type: NTFS Drive D: | 112,52 Gb Total Space | 12,15 Gb Free Space | 10,80% Space Free | Partition Type: NTFS Drive E: | 3,90 Gb Total Space | 2,92 Gb Free Space | 75,00% Space Free | Partition Type: FAT32 Computer Name: THOMAS-PC | User Name: Thomas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.07.31 10:50:19 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Thomas\Downloads\OTL.exe PRC - [2012.07.28 01:58:31 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe PRC - [2012.07.18 10:12:02 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe PRC - [2009.12.18 00:32:30 | 000,497,856 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe PRC - [2009.07.20 04:00:00 | 000,077,824 | ---- | M] () -- C:\Programme\SetPoint\x86\SetPoint32.exe PRC - [2007.09.17 11:28:26 | 001,732,608 | ---- | M] (Belkin) -- C:\Program Files (x86)\Belkin\F5D8053\Belkinwcui.exe ========== Modules (No Company Name) ========== MOD - [2012.07.28 01:58:30 | 009,465,032 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll MOD - [2012.07.18 10:12:02 | 002,003,424 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe MOD - [2009.07.20 04:00:00 | 000,077,824 | ---- | M] () -- C:\Programme\SetPoint\x86\SetPoint32.exe MOD - [2009.04.11 08:28:22 | 000,223,232 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll MOD - [2007.10.26 10:51:08 | 000,200,704 | ---- | M] () -- C:\Program Files (x86)\Belkin\F5D8053\BelkinwcuiDLL.dll MOD - [2007.03.30 00:00:44 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\Belkin\F5D8053\BelkinHWStatus.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010.11.26 04:54:12 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2008.01.21 04:50:23 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2012.07.28 01:58:31 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.07.18 10:12:02 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.12.18 00:32:30 | 000,497,856 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent) SRV - [2009.07.20 12:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2009.03.30 06:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012.02.29 15:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011.05.12 14:03:12 | 000,006,144 | ---- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\9C32.tmp -- (MEMSWEEP2) DRV:64bit: - [2010.11.26 06:20:20 | 008,120,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag) DRV:64bit: - [2010.11.26 06:20:20 | 008,120,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2010.11.26 04:16:46 | 000,289,792 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010.11.17 14:04:18 | 000,111,120 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdLH6.sys -- (AtiHDAudioService) DRV:64bit: - [2010.06.09 22:41:13 | 000,123,840 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\AnyDVD.sys -- (AnyDVD) DRV:64bit: - [2010.06.02 18:54:09 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\atksgt.sys -- (atksgt) DRV:64bit: - [2010.06.02 18:54:09 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\lirsgt.sys -- (lirsgt) DRV:64bit: - [2010.01.01 19:20:28 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV:64bit: - [2009.12.18 00:18:51 | 000,024,248 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\vpnva64.sys -- (vpnva) DRV:64bit: - [2009.10.08 16:35:06 | 000,871,408 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\Drivers\sptd.sys -- (sptd) DRV:64bit: - [2009.10.01 02:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb) DRV:64bit: - [2009.09.30 16:32:44 | 000,120,336 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2009.06.17 18:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys -- (LMouFilt) DRV:64bit: - [2009.06.17 18:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys -- (LHidFilt) DRV:64bit: - [2009.06.17 18:53:34 | 000,030,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys -- (L8042Kbd) DRV:64bit: - [2008.08.06 10:26:08 | 000,174,592 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169) DRV:64bit: - [2007.08.16 00:50:06 | 000,688,640 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\netr28ux.sys -- (netr28ux) DRV - [2011.05.12 14:05:32 | 000,018,816 | ---- | M] (Sophos Group) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\SAVRKBootTasks.sys -- (SAVRKBootTasks) DRV - [2010.06.09 22:41:13 | 000,123,840 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.telekom.at/suche IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.telekom.at IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = hxxp://www.daemon-search.com/search/web?q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.126 FF - prefs.js..extensions.enabledItems: ClickPotatoLite@ClickPotatoLite.com:10.0.0.0 FF - prefs.js..extensions.enabledItems: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files (x86)\DNA\plugins\npbtdna.dll (BitTorrent, Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.08.16 12:47:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.18 10:12:02 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.07.31 09:55:55 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.18 10:12:02 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.07.31 09:55:55 | 000,000,000 | ---D | M] [2009.03.10 22:44:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Thomas\AppData\Roaming\mozilla\Extensions [2012.07.01 10:11:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Thomas\AppData\Roaming\mozilla\Firefox\Profiles\kv5mvy10.default\extensions [2011.04.07 18:27:33 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Thomas\AppData\Roaming\mozilla\Firefox\Profiles\kv5mvy10.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2009.10.08 16:38:48 | 000,002,399 | ---- | M] () -- C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\kv5mvy10.default\searchplugins\daemon-search.xml [2012.03.16 07:54:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012.02.04 15:51:15 | 000,255,318 | ---- | M] () (No name found) -- C:\USERS\THOMAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KV5MVY10.DEFAULT\EXTENSIONS\SQLITEMANAGER@MRINALKANT.BLOGSPOT.COM.XPI [2012.07.18 10:12:02 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npbittorrent.dll [2012.07.03 09:16:42 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.08.17 14:18:16 | 000,002,191 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012.07.03 09:16:42 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.07.03 09:16:42 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.07.03 09:16:42 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.03 09:16:42 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.03 09:16:42 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - Startup: C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Thomas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Thomas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: blank ([]about in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 195.34.133.21 212.186.211.21 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2BFA1DB5-B8DD-4C41-AA3D-E8AE2A04E54A}: DhcpNameServer = 195.34.133.21 212.186.211.21 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DDB42094-DAF4-47F5-BB11-B418F260F870}: DhcpNameServer = 10.0.0.138 O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{27536e6f-b418-11de-a011-001966981b2a}\Shell - "" = AutoRun O33 - MountPoints2\{27536e6f-b418-11de-a011-001966981b2a}\Shell\AutoRun\command - "" = G:\SETUP.EXE O33 - MountPoints2\{27536e6f-b418-11de-a011-001966981b2a}\Shell\configure\command - "" = G:\SETUP.EXE O33 - MountPoints2\{27536e6f-b418-11de-a011-001966981b2a}\Shell\install\command - "" = G:\SETUP.EXE O33 - MountPoints2\{54420fe9-16b3-11e0-a9a6-001966981b2a}\Shell - "" = AutoRun O33 - MountPoints2\{54420fe9-16b3-11e0-a9a6-001966981b2a}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{54421012-16b3-11e0-a9a6-001966981b2a}\Shell - "" = AutoRun O33 - MountPoints2\{54421012-16b3-11e0-a9a6-001966981b2a}\Shell\AutoRun\command - "" = I:\AutoRun.exe O33 - MountPoints2\{c80ea12d-a86b-11de-9b1b-001966981b2a}\Shell\AutoRun\command - "" = WDSetup.exe O33 - MountPoints2\{dc97b760-17a1-11e0-a030-df148b89f510}\Shell - "" = AutoRun O33 - MountPoints2\{dc97b760-17a1-11e0-a030-df148b89f510}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{f68c54d7-179c-11e0-a2d4-001966981b2a}\Shell - "" = AutoRun O33 - MountPoints2\{f68c54d7-179c-11e0-a2d4-001966981b2a}\Shell\AutoRun\command - "" = H:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012.07.31 03:26:25 | 000,000,000 | ---D | C] -- C:\Users\Thomas\AppData\Roaming\Malwarebytes [2012.07.31 03:26:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.07.31 03:26:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.07.31 03:26:15 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012.07.31 03:26:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2012.07.31 03:18:30 | 000,018,816 | ---- | C] (Sophos Group) -- C:\Windows\SysWow64\SAVRKBootTasks.sys [2012.07.30 22:27:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos [2012.07.30 22:27:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos [2012.07.12 03:07:03 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.07.03 09:16:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012.07.03 09:16:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2012.07.02 12:11:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2012.07.02 12:10:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle [2012.07.01 11:09:10 | 000,000,000 | ---D | C] -- C:\Users\Thomas\AppData\Local\Macromedia [2012.07.01 11:07:27 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed [2012.07.01 11:07:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dropbox [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.07.31 10:46:42 | 001,474,792 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012.07.31 10:46:42 | 000,643,898 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012.07.31 10:46:42 | 000,600,532 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012.07.31 10:46:42 | 000,131,214 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012.07.31 10:46:42 | 000,108,414 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012.07.31 10:39:45 | 000,003,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012.07.31 10:39:45 | 000,003,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012.07.31 10:39:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.07.31 10:38:03 | 000,000,020 | ---- | M] () -- C:\Users\Thomas\defogger_reenable [2012.07.31 09:58:02 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.07.31 03:26:16 | 000,000,961 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.07.30 17:41:50 | 000,000,500 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Thomas.job [2012.07.29 21:59:38 | 000,097,964 | ---- | M] () -- C:\Users\Thomas\Desktop\mplayerc64.exe.1.2.908.0.dmp [2012.07.24 15:19:37 | 000,002,655 | ---- | M] () -- C:\Users\Thomas\Desktop\Microsoft Office Word 2007.lnk [2012.07.22 18:01:00 | 002,806,797 | ---- | M] () -- C:\Users\Thomas\Desktop\IMG_0554.MOV [2012.07.12 03:25:21 | 000,375,264 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012.07.02 12:08:19 | 000,001,930 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.07.31 10:38:03 | 000,000,020 | ---- | C] () -- C:\Users\Thomas\defogger_reenable [2012.07.31 03:26:16 | 000,000,961 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.07.29 21:59:38 | 000,097,964 | ---- | C] () -- C:\Users\Thomas\Desktop\mplayerc64.exe.1.2.908.0.dmp [2012.07.24 18:15:52 | 000,016,896 | ---- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\80000000.@ [2012.07.24 18:15:52 | 000,002,048 | ---- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\00000004.@ [2012.07.24 18:15:52 | 000,001,632 | ---- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\000000cb.@ [2012.07.24 18:15:52 | 000,000,804 | ---- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\L\00000004.@ [2012.07.24 18:15:40 | 000,092,672 | ---- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\80000032.@ [2012.07.24 18:15:40 | 000,080,896 | ---- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\80000064.@ [2012.07.22 18:01:00 | 002,806,797 | ---- | C] () -- C:\Users\Thomas\Desktop\IMG_0554.MOV [2012.07.01 11:07:32 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.02.14 07:06:08 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\@ [2011.07.09 11:51:02 | 000,000,680 | ---- | C] () -- C:\Users\Thomas\AppData\Local\d3d9caps.dat [2010.09.17 21:17:00 | 000,002,888 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2010.07.06 14:59:08 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib [2010.01.22 11:47:20 | 000,000,036 | ---- | C] () -- C:\Users\Thomas\AppData\Local\housecall.guid.cache [2009.07.17 16:07:26 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2009.06.08 13:49:54 | 000,000,760 | ---- | C] () -- C:\Users\Thomas\AppData\Roaming\setup_ldm.iss [2009.04.15 16:39:42 | 000,000,466 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2009.03.11 09:40:45 | 000,031,232 | ---- | C] () -- C:\Users\Thomas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.03.10 20:03:05 | 000,000,732 | ---- | C] () -- C:\Users\Thomas\AppData\Local\d3d9caps64.dat ========== LOP Check ========== [2012.07.29 22:59:01 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\BitTorrent [2009.11.10 18:26:06 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\DAEMON Tools Lite [2009.10.08 16:23:19 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\DAEMON Tools Pro [2012.07.31 10:40:17 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\Dropbox [2011.07.30 15:52:54 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\DVDVideoSoft [2009.03.18 23:31:05 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\FOG Downloader [2011.02.01 14:57:15 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\mquadr.at [2009.06.07 13:24:03 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\Octoshape [2010.01.22 12:31:18 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\ScanSoft [2010.03.26 21:37:24 | 000,000,000 | ---D | M] -- C:\Users\Thomas\AppData\Roaming\TS3Client [2012.07.31 10:38:30 | 000,032,510 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Code:
ATTFilter 2012/07/31 03:26:32 +0200 THOMAS-PC Thomas MESSAGE Starting protection 2012/07/31 03:26:35 +0200 THOMAS-PC Thomas MESSAGE Protection started successfully 2012/07/31 03:26:38 +0200 THOMAS-PC Thomas MESSAGE Starting IP protection 2012/07/31 03:26:38 +0200 THOMAS-PC Thomas ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753 2012/07/31 03:26:44 +0200 THOMAS-PC Thomas MESSAGE Starting database refresh 2012/07/31 03:26:47 +0200 THOMAS-PC Thomas MESSAGE Database refreshed successfully 2012/07/31 03:26:55 +0200 THOMAS-PC Thomas MESSAGE Starting IP protection 2012/07/31 03:26:55 +0200 THOMAS-PC Thomas ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753 2012/07/31 09:54:49 +0200 THOMAS-PC Thomas DETECTION C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\00000008.@ Trojan.Dropper.BCMiner QUARANTINE 2012/07/31 09:57:40 +0200 THOMAS-PC Thomas MESSAGE Starting protection 2012/07/31 09:57:47 +0200 THOMAS-PC Thomas MESSAGE Protection started successfully 2012/07/31 09:57:50 +0200 THOMAS-PC Thomas MESSAGE Starting IP protection 2012/07/31 09:57:50 +0200 THOMAS-PC Thomas ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753 2012/07/31 10:04:16 +0200 THOMAS-PC Thomas DETECTION C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\00000008.@ Trojan.Dropper.BCMiner QUARANTINE 2012/07/31 10:04:57 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:05:40 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:05:42 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:41:44 +0200 THOMAS-PC Thomas MESSAGE Starting protection 2012/07/31 10:41:46 +0200 THOMAS-PC Thomas MESSAGE Protection started successfully 2012/07/31 10:41:49 +0200 THOMAS-PC Thomas MESSAGE Starting IP protection 2012/07/31 10:41:49 +0200 THOMAS-PC Thomas ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753 2012/07/31 10:46:01 +0200 THOMAS-PC Thomas DETECTION C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\00000008.@ Trojan.Dropper.BCMiner QUARANTINE 2012/07/31 10:46:13 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:46:47 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:46:53 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:49:04 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY 2012/07/31 10:49:09 +0200 THOMAS-PC Thomas DETECTION c:\windows\installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\u\00000008.@ Trojan.Dropper.BCMiner DENY Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=4f6c148d3f53a74eadc2c306981d1a81 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-31 10:40:25 # local_time=2012-07-31 12:40:25 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=5892 16776574 66 56 638988 181250304 0 0 # compatibility_mode=8192 67108863 100 0 137 137 0 0 # scanned=188681 # found=8 # cleaned=0 # scan_time=4921 C:\Users\Thomas\AppData\Local\Temp\is1438683437\MyBabylonTB.exe Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\1dd6a40c-77f46603 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\1eff1eb1-5a31cecf probably a variant of Win32/Agent.DYXWUMY trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\72137c32-35da4d89 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\000000cb.@ Win64/Conedex.B trojan (unable to clean) 00000000000000000000000000000000 I C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\80000000.@ Win64/Sirefef.AP trojan (unable to clean) 00000000000000000000000000000000 I C:\Windows\Installer\{25b515c4-4dab-6d62-66ba-6939a77c6a3c}\U\80000032.@ a variant of Win32/Sirefef.FD trojan (unable to clean) 00000000000000000000000000000000 I ${Memory} a variant of Win32/Sirefef.EZ trojan 00000000000000000000000000000000 I hoffe da lässt sich noch was retten ... danke schonmal im voraus! beste grüße tom |
Themen zu Yahoo Mail Acc verschickt Spam Mails an persönliche Kontakte |
00000008.@, administrator, adobe, adobe flash player, adware.hotbar.gen, affiliate.downloader, autorun, bho, browser, explorer, failed, firefox, flash player, format, helper, icreinstall, install.exe, intranet, logfile, löschen, malware, mozilla, mp3, plug-in, programme, pup.adware.rkn, realtek, registry, rootkit.dropper, security, senden, software, spam, vista, win32/agent.dyxwumy, win32/sirefef.ez, win32/sirefef.fd, yahoo mail |