|
Log-Analyse und Auswertung: GVU-Trojaner mit WebcamWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.08.2012, 15:14 | #1 |
| GVU-Trojaner mit Webcam Hallo, ich bin neu hier da ich mir vor zwei Tagen einen GVU-Trojaner (mit Webcam) eingefangen habe/hatte. Daraufhin habe ich mir die Kaspersky Rescue Disk 10 heruntergeladen, mir mit dieser wieder Zugang zum System verschafft und auch einen Virenscan durchgeführt bei dem mehrere betroffene Files entdeckt und gelöscht wurden. Diese kann ich euch hier leider nicht mehr angeben. Der PC läuft seither wieder normal. Ich wollte mich aber trotzdem nochmal versichern und nachfragen ob euerer Meinung nach noch weitere Schritte von Nöten sind. Hierzu findet ihr im folgenden die Log-Files. OTL.txt:OTL Logfile: Code:
ATTFilter OTL logfile created on: 08.08.2012 12:56:50 - Run 1 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\ToSa\Desktop Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1013,42 Mb Total Physical Memory | 342,21 Mb Available Physical Memory | 33,77% Memory free 1,99 Gb Paging File | 1,09 Gb Available in Paging File | 54,63% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 116,44 Gb Total Space | 18,27 Gb Free Space | 15,69% Space Free | Partition Type: NTFS Drive D: | 116,05 Gb Total Space | 109,63 Gb Free Space | 94,47% Space Free | Partition Type: NTFS Drive F: | 267,04 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: TOSA-TOSH | User Name: ToSa | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.08.08 12:54:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\ToSa\Desktop\OTL.exe PRC - [2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\ToSa\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.07.01 11:59:04 | 001,295,224 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe PRC - [2010.07.01 11:59:02 | 000,051,576 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe PRC - [2010.04.19 14:40:02 | 000,136,136 | ---- | M] (Toshiba Europe GmbH) -- C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe PRC - [2010.04.13 17:24:58 | 000,694,816 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe PRC - [2010.03.25 13:09:24 | 000,742,712 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe PRC - [2010.03.09 02:23:22 | 001,086,760 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe PRC - [2010.03.03 12:17:48 | 000,030,040 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe PRC - [2010.02.24 01:54:48 | 002,454,840 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe PRC - [2010.02.22 13:23:50 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe PRC - [2010.02.11 02:40:24 | 001,050,072 | ---- | M] (Toshiba Europe GmbH) -- C:\Program Files\Toshiba TEMPRO\TemproTray.exe PRC - [2010.02.05 17:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe PRC - [2010.02.05 17:40:44 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe PRC - [2010.01.28 16:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe PRC - [2010.01.15 14:08:38 | 000,935,208 | ---- | M] (Nero AG) -- c:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe PRC - [2009.12.25 15:21:16 | 000,034,160 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\Utilities\KeNotify.exe PRC - [2009.11.05 22:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe PRC - [2009.11.05 22:04:12 | 000,480,608 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe PRC - [2009.08.13 12:31:24 | 000,521,528 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe PRC - [2009.07.28 20:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe PRC - [2009.07.28 14:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe PRC - [2009.06.30 10:23:54 | 000,762,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\vVX1000.exe PRC - [2009.03.10 18:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe ========== Modules (No Company Name) ========== MOD - [2012.07.01 15:48:02 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll MOD - [2012.06.21 22:09:39 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll MOD - [2012.06.21 22:06:37 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll MOD - [2012.06.21 22:06:02 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll MOD - [2012.06.21 22:05:46 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll MOD - [2012.05.30 20:06:48 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.05.30 20:06:30 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2012.05.12 18:15:49 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll MOD - [2012.05.12 05:51:59 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll MOD - [2012.05.12 05:48:47 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll MOD - [2012.05.12 05:48:21 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll MOD - [2012.05.12 05:47:59 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll MOD - [2012.05.12 05:47:55 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll MOD - [2012.05.12 05:47:27 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll MOD - [2012.01.03 10:45:08 | 000,016,832 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll MOD - [2011.06.09 10:52:03 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll MOD - [2010.11.13 02:02:22 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll MOD - [2010.11.13 02:02:21 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2010.03.03 14:14:58 | 000,016,184 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF11.dll MOD - [2010.03.03 14:14:56 | 000,016,184 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF10.dll MOD - [2010.03.03 14:14:32 | 008,783,160 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll MOD - [2010.02.05 17:40:28 | 000,079,192 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll MOD - [2009.11.03 13:26:26 | 000,058,680 | ---- | M] () -- C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll MOD - [2009.07.14 10:47:11 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2009.06.22 14:38:40 | 000,015,160 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll MOD - [2009.03.12 20:08:04 | 000,049,152 | ---- | M] () -- C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll MOD - [2006.10.07 11:57:04 | 000,053,248 | ---- | M] () -- C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll ========== Win32 Services (SafeList) ========== SRV - [2012.08.02 17:09:42 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2010.07.01 11:59:02 | 000,051,576 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo) SRV - [2010.02.11 02:40:12 | 000,124,368 | ---- | M] (Toshiba Europe GmbH) [On_Demand | Stopped] -- C:\Program Files\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService) SRV - [2010.02.05 17:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service) SRV - [2010.01.28 16:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService) SRV - [2010.01.15 14:08:38 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- c:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2009.11.05 22:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv) SRV - [2009.07.28 14:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.03.10 18:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\cmnsusbser.sys -- (cmnsusbser) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.03.12 11:23:14 | 000,189,984 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV - [2009.11.06 12:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009.07.30 21:02:34 | 000,036,208 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter) DRV - [2009.07.30 16:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst) DRV - [2009.07.14 16:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ) DRV - [2009.06.30 10:24:04 | 001,961,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VX1000.sys -- (VX1000) DRV - [2009.06.22 17:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {5308E876-2F31-469D-9161-67BE894E3ED9} IE - HKLM\..\SearchScopes\{5308E876-2F31-469D-9161-67BE894E3ED9}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.avg.com/?cid={8BB0D223-A978-4BA7-9F34-9DADFCF1F7A9}&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&lang=de&ds=hk011&pr=sa&d=2012-07-15 15:47:41&v=11.1.0.12&sap=hp IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKCU\..\SearchScopes\{21F23D3E-D738-4718-8BAD-ABC7868C87B3}: "URL" = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms} IE - HKCU\..\SearchScopes\{5A0AE168-9790-4650-A159-95AADB107CD4}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKCU\..\SearchScopes\{5B6F482F-6429-4FA9-82C7-EC32F9CDDF72}: "URL" = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2 IE - HKCU\..\SearchScopes\{6BC0351F-04A8-449C-AD7F-6999E6F9993E}: "URL" = hxxp://search.softonic.com/MON00015/tb_v1?q={searchTerms}&SearchSource=4&cc= IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={8BB0D223-A978-4BA7-9F34-9DADFCF1F7A9}&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&lang=de&ds=hk011&pr=sa&d=2012-07-15 15:47:41&v=11.1.0.12&sap=dsp&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "hxxp://isearch.avg.com?cid=%7B51b341e3-9e13-487f-a302-67dae3628962%7D&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&ds=hk011&v=11.1.0.12&lang=de&pr=sa&d=2012-07-15%2015%3A47%3A41&sap=hp" FF - prefs.js..keyword.URL: "hxxp://isearch.avg.com/search?cid=%7B51b341e3-9e13-487f-a302-67dae3628962%7D&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&ds=hk011&v=11.1.0.12&lang=de&pr=sa&d=2012-07-15%2015%3A47%3A41&sap=ku&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.08.02 17:09:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.10.18 22:52:25 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.08.02 17:09:43 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.10.18 22:52:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ToSa\AppData\Roaming\mozilla\Extensions [2012.05.07 14:11:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ToSa\AppData\Roaming\mozilla\Firefox\Profiles\sx3smlxf.default\extensions [2012.04.21 08:09:54 | 000,002,060 | ---- | M] () -- C:\Users\ToSa\AppData\Roaming\Mozilla\Firefox\Profiles\sx3smlxf.default\searchplugins\softonic.xml [2012.08.08 12:36:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012.08.08 12:36:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012.08.02 17:09:43 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.07.02 13:28:24 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.07.15 15:47:36 | 000,003,750 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml [2012.07.02 13:28:24 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.07.02 13:28:24 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.07.02 13:28:24 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.02 13:28:24 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.02 13:28:24 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.) O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION) O4 - HKLM..\Run: [NBAgent] c:\Program Files\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe (Nero AG) O4 - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA) O4 - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH) O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH) O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.) O4 - HKLM..\Run: [VX1000] C:\Windows\vVX1000.exe (Microsoft Corporation) O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10u_Plugin.exe (Adobe Systems, Inc.) O4 - Startup: C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\ToSa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O4 - Startup: C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B4348AAB-A3E3-4AEB-A657-F65565E79928}: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EEA39B3E-6E82-4734-B4BD-C36E00AEB70F}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\autorun.exe O33 - MountPoints2\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\DPFMate.exe O33 - MountPoints2\E\Shell - "" = AutoRun O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.08.08 12:53:57 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\ToSa\Desktop\OTL.exe [2012.08.08 00:18:16 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0 [2012.08.06 19:35:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab [2012.07.22 11:44:52 | 000,000,000 | ---D | C] -- C:\Users\ToSa\Documents\Klarmobil [2012.07.15 18:57:07 | 000,000,000 | ---D | C] -- C:\Users\ToSa\.pdfsam [2012.07.15 17:08:53 | 000,000,000 | ---D | C] -- C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF Split And Merge [2012.07.15 17:08:51 | 000,000,000 | ---D | C] -- C:\Program Files\pdfsam [2012.07.11 11:42:50 | 000,000,000 | ---D | C] -- C:\Users\ToSa\Documents\Schwangerschaft [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.08.08 12:55:31 | 000,302,592 | ---- | M] () -- C:\Users\ToSa\Desktop\ett98cf7.exe [2012.08.08 12:54:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\ToSa\Desktop\OTL.exe [2012.08.08 12:47:49 | 000,000,000 | ---- | M] () -- C:\Users\ToSa\defogger_reenable [2012.08.08 12:44:55 | 000,050,477 | ---- | M] () -- C:\Users\ToSa\Desktop\Defogger.exe [2012.08.08 12:33:37 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.08.08 12:33:36 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.08.08 12:24:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.08.08 12:23:52 | 796,987,392 | -HS- | M] () -- C:\hiberfil.sys [2012.08.07 12:38:25 | 004,503,728 | ---- | M] () -- C:\ProgramData\rat_0ybba.pad [2012.08.07 12:24:49 | 000,659,236 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.08.07 12:24:49 | 000,620,382 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.08.07 12:24:49 | 000,132,774 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.08.07 12:24:49 | 000,108,564 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.08.06 12:01:20 | 000,001,884 | ---- | M] () -- C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk [2012.08.05 17:12:44 | 000,017,979 | ---- | M] () -- C:\Users\ToSa\Desktop\Urlaub Union Lido.ods [2012.08.05 14:54:32 | 000,011,286 | ---- | M] () -- C:\Users\ToSa\Desktop\Arbeitszeiten Nebenjob.ods [2012.07.23 22:39:02 | 000,097,159 | ---- | M] () -- C:\Users\ToSa\Desktop\sterne aufm bus.odp [2012.07.15 21:42:06 | 000,430,880 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.08.08 12:55:28 | 000,302,592 | ---- | C] () -- C:\Users\ToSa\Desktop\ett98cf7.exe [2012.08.08 12:47:49 | 000,000,000 | ---- | C] () -- C:\Users\ToSa\defogger_reenable [2012.08.08 12:44:50 | 000,050,477 | ---- | C] () -- C:\Users\ToSa\Desktop\Defogger.exe [2012.08.06 12:01:20 | 004,503,728 | ---- | C] () -- C:\ProgramData\rat_0ybba.pad [2012.08.06 12:01:20 | 000,001,884 | ---- | C] () -- C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk [2012.08.03 18:17:02 | 000,017,979 | ---- | C] () -- C:\Users\ToSa\Desktop\Urlaub Union Lido.ods [2012.07.25 04:52:24 | 000,011,286 | ---- | C] () -- C:\Users\ToSa\Desktop\Arbeitszeiten Nebenjob.ods [2012.07.23 18:48:07 | 000,097,159 | ---- | C] () -- C:\Users\ToSa\Desktop\sterne aufm bus.odp [2011.09.22 19:24:59 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011.06.08 15:44:47 | 000,287,024 | ---- | C] () -- C:\Users\ToSa\SoftonicDownloader_fuer_openoffice.exe [2010.10.23 10:03:25 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [2010.10.23 09:39:04 | 000,045,056 | ---- | C] () -- C:\Windows\System32\HWS_Ctrl.dll [2010.10.23 09:35:52 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2010.10.23 09:29:52 | 000,000,712 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat [2010.10.23 09:29:52 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat ========== LOP Check ========== [2012.03.08 13:15:18 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Amazon [2011.04.13 21:30:43 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Desktop [2012.08.08 12:25:40 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Dropbox [2011.04.21 17:13:55 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Free Download Manager [2011.11.22 23:08:03 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\IrfanView [2011.06.09 15:35:43 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\OpenOffice.org [2011.11.22 23:01:21 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\SoftGrid Client [2011.01.19 13:58:49 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Software4u [2011.10.18 22:52:49 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Thunderbird [2011.01.15 19:50:33 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Toshiba [2011.01.09 19:35:22 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\TP [2011.01.27 17:04:53 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\WinBatch [2011.10.24 13:07:52 | 000,000,000 | ---D | M] -- C:\Users\ToSa\AppData\Roaming\Zoner [2012.05.21 05:10:00 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Extra.txt:OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 08.08.2012 12:56:50 - Run 1 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\ToSa\Desktop Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1013,42 Mb Total Physical Memory | 342,21 Mb Available Physical Memory | 33,77% Memory free 1,99 Gb Paging File | 1,09 Gb Available in Paging File | 54,63% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 116,44 Gb Total Space | 18,27 Gb Free Space | 15,69% Space Free | Partition Type: NTFS Drive D: | 116,05 Gb Total Space | 109,63 Gb Free Space | 94,47% Space Free | Partition Type: NTFS Drive F: | 267,04 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: TOSA-TOSH | User Name: ToSa | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1CEEA259-80E2-42C4-BCE2-81F3558E25EC}" = lport=2869 | protocol=6 | dir=in | app=system | "{A89385BC-25CB-435C-BF31-D4D401C437AE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1744246E-E9E6-46C5-B118-53D0574F9420}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{4193F2F4-190B-4104-9219-CD861C497241}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{4BEC7B33-D38A-431C-9A4A-50DB5F87A3DC}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{756ECD61-F655-4F12-8848-CE300654C267}" = protocol=6 | dir=in | app=c:\users\tosa\appdata\roaming\dropbox\bin\dropbox.exe | "{B2683950-375B-436B-9A9F-B7B8A76B32D7}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{BDC43941-6C1D-41A0-9EEA-EF66E214BDDB}" = protocol=17 | dir=in | app=c:\users\tosa\appdata\roaming\dropbox\bin\dropbox.exe | "{BE610D0F-4F66-42E5-84CE-5CD16CF1EFAE}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D167EE86-A8E3-4382-BF12-339137305BEB}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{E00C9C53-87BE-47F6-9267-9ECF8F9756A3}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{E062FA26-B54C-46E9-8485-5A299E38773F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{EFA1DBAB-9874-4028-A4EB-DF5D190D3890}" = dir=in | app=c:\program files\itunes\itunes.exe | "{F4A3950B-CFF8-45B8-AFAC-108D59919DE8}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "TCP Query User{95561177-623E-44D8-98E3-EC611D50D917}C:\users\tosa\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\tosa\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{06F81A9F-0A03-4A28-B755-D4F840225C13}C:\users\tosa\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\tosa\appdata\roaming\dropbox\bin\dropbox.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{0420F95C-11FF-4E02-B967-6CC22B188F9F}" = Nero BackItUp "{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33 "{2B000B80-A3FA-4B92-A5FF-D9AD402B6701}" = Toshiba TEMPRO "{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie "{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed "{397516AE-7DFE-4F90-84E0-BD616D559434}" = Nero BurnRights "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password "{51E2F9B3-A972-4F58-B4EF-4D9676D9F5D1}" = Nero RescueAgent "{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{607BE7BF-7C28-4ADB-A4A0-385962B901C3}" = TOSHIBA ConfigFree "{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility "{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6C3CF7AC-5AB0-42D9-93C0-68166A57AFB6}" = Nero Express "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder "{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart "{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help "{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support "{8f65bed9-aef7-4643-b437-1cbf6392e37e}" = Nero 9 Essentials "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station "{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.0 - Deutsch "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center "{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator "{B894522E-C079-4DC8-A305-30BA6E2F4459}" = TOSHIBA ReelTime "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C7A4F26F-F9B0-41B2-8659-99181108CDE3}" = TOSHIBA Media Controller "{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade "{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help "{CCF62642-ECB1-4D2B-80C0-3FD3286AEAED}" = TOSHIBA Sync Utility "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert "{E08CC458-41FB-4BB5-9B08-2C83DB55A5B9}" = Nero BackItUp and Burn "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help "{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter "{F6BDD7C5-89ED-4569-9318-469AA9732572}" = Nero BurnRights Help "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool "{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "AudibleManager" = AudibleManager "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisorkennwort "InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup "InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility "InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder "InstallShield_{B894522E-C079-4DC8-A305-30BA6E2F4459}" = TOSHIBA ReelTime "InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert "InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de) "Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 2.0.1 "WinLiveSuite_Wave3" = Windows Live Essentials "ZonerPhotoStudio13_EN_is1" = Zoner Photo Studio 13 FREE ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "pdfsam" = pdfsam ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 11.07.2012 09:15:37 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 3027 Error - 11.07.2012 09:15:38 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 11.07.2012 09:15:38 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 4041 Error - 11.07.2012 09:15:38 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 4041 Error - 11.07.2012 09:15:39 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 11.07.2012 09:15:39 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 5039 Error - 11.07.2012 09:15:39 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 5039 Error - 16.07.2012 05:19:28 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 16.07.2012 05:19:28 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1077 Error - 16.07.2012 05:19:28 | Computer Name = ToSa-TOSH | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1077 [ System Events ] Error - 06.08.2012 11:37:22 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Netzwerklistendienst" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error - 06.08.2012 11:37:23 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Server" wurde mit folgendem Fehler beendet: %%13 Error - 06.08.2012 11:39:30 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 06.08.2012 12:41:05 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 06.08.2012 13:06:20 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 06.08.2012 13:33:01 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 07.08.2012 06:39:34 | Computer Name = ToSa-TOSH | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?07.?08.?2012 um 12:38:42 unerwartet heruntergefahren. Error - 07.08.2012 06:39:46 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 07.08.2012 15:47:41 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 07.08.2012 15:53:58 | Computer Name = ToSa-TOSH | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147467243. < End of report > Gmer.txt:GMER Logfile: Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-08-08 15:45:05 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.PB2O Running: ett98cf7.exe; Driver: C:\Users\ToSa\AppData\Local\Temp\kgldapow.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 81C8E3C9 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81CC7D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} PAGE spsys.sys!?SPRevision@@3PADA + 4F90 A5B9A000 98 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...] PAGE spsys.sys!?SPRevision@@3PADA + 4FF3 A5B9A063 191 Bytes [A5, 8B, 45, 08, F0, 0F, BA, ...] PAGE spsys.sys!?SPRevision@@3PADA + 50B3 A5B9A123 629 Bytes [55, B9, A5, FE, 05, 34, 55, ...] PAGE spsys.sys!?SPRevision@@3PADA + 5329 A5B9A399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...] PAGE spsys.sys!?SPRevision@@3PADA + 538F A5B9A3FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...] PAGE ... ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation) Device \Driver\ACPI_HAL \Device\00000046 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS@StateIndex 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4E00F40-E8C0-477B-8806-D40A0BB5A0E7} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E00F40-E8C0-477B-8806-D40A0BB5A0E7} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E00F40-E8C0-477B-8806-D40A0BB5A0E7}@Path \Microsoft\Windows Defender\MP Scheduled Scan Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E00F40-E8C0-477B-8806-D40A0BB5A0E7}@Hash 0xE7 0xCF 0x86 0x38 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E00F40-E8C0-477B-8806-D40A0BB5A0E7}@Triggers 0x15 0x00 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E00F40-E8C0-477B-8806-D40A0BB5A0E7}@DynamicInfo 0x03 0x00 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan@Id {C4E00F40-E8C0-477B-8806-D40A0BB5A0E7} ---- EOF - GMER 1.0.15 ---- defogger.txt: defogger_disable by jpshortstuff (23.02.10.1) Log created at 12:47 on 08/08/2012 (ToSa) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Wäre super wenn Ihr mir bei meinem Problem unter die Arme greifen könntet. Vielen Dank schon einmal im Voraus. Grüße Throsten |
08.08.2012, 15:59 | #2 |
/// Helfer-Team | GVU-Trojaner mit WebcamFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\cmnsusbser.sys -- (cmnsusbser) IE - HKLM\..\SearchScopes,DefaultScope = {5308E876-2F31-469D-9161-67BE894E3ED9} IE - HKLM\..\SearchScopes\{5308E876-2F31-469D-9161-67BE894E3ED9}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com/?cid={8BB0D223-A978-4BA7-9F34-9DADFCF1F7A9}&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&lang=de&ds=hk011&pr=sa&d=2012-07-15 15:47:41&v=11.1.0.12&sap=hp IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKCU\..\SearchScopes\{21F23D3E-D738-4718-8BAD-ABC7868C87B3}: "URL" = http://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms} IE - HKCU\..\SearchScopes\{5A0AE168-9790-4650-A159-95AADB107CD4}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKCU\..\SearchScopes\{5B6F482F-6429-4FA9-82C7-EC32F9CDDF72}: "URL" = http://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2 IE - HKCU\..\SearchScopes\{6BC0351F-04A8-449C-AD7F-6999E6F9993E}: "URL" = http://search.softonic.com/MON00015/tb_v1?q={searchTerms}&SearchSource=4&cc= IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8BB0D223-A978-4BA7-9F34-9DADFCF1F7A9}&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&lang=de&ds=hk011&pr=sa&d=2012-07-15 15:47:41&v=11.1.0.12&sap=dsp&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://isearch.avg.com?cid=%7B51b341e3-9e13-487f-a302-67dae3628962%7D&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&ds=hk011&v=11.1.0.12&lang=de&pr=sa&d=2012-07-15%2015%3A47%3A41&sap=hp" FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B51b341e3-9e13-487f-a302-67dae3628962%7D&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&ds=hk011&v=11.1.0.12&lang=de&pr=sa&d=2012-07-15%2015%3A47%3A41&sap=ku&q=" FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\autorun.exe O33 - MountPoints2\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\Shell - "" = AutoRun O33 - MountPoints2\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\Shell\AutoRun\command - "" = E:\DPFMate.exe O33 - MountPoints2\E\Shell - "" = AutoRun O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [2012.08.08 12:55:31 | 000,302,592 | ---- | M] () -- C:\Users\ToSa\Desktop\ett98cf7.exe [2012.08.07 12:38:25 | 004,503,728 | ---- | M] () -- C:\ProgramData\rat_0ybba.pad [2012.08.06 12:01:20 | 000,001,884 | ---- | M] () -- C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk [2012.04.21 08:09:54 | 000,002,060 | ---- | M] () -- C:\Users\ToSa\AppData\Roaming\Mozilla\Firefox\Profiles\sx3smlxf.default\searchplugins\softonic.xml [2011.06.08 15:44:47 | 000,287,024 | ---- | C] () -- C:\Users\ToSa\SoftonicDownloader_fuer_openoffice.exe :Files ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
09.08.2012, 10:05 | #3 |
| GVU-Trojaner mit Webcam Hallo,
__________________vielen Dank für die schnelle Antwort bzw. Hilfe. Ich habe OTL den Fix ausführen lassen, folgender Log wurde erstellt: All processes killed ========== OTL ========== Service hwdatacard stopped successfully! Service hwdatacard deleted successfully! File system32\DRIVERS\ewusbmdm.sys not found. Service cmnsusbser stopped successfully! Service cmnsusbser deleted successfully! File system32\DRIVERS\cmnsusbser.sys not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5308E876-2F31-469D-9161-67BE894E3ED9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5308E876-2F31-469D-9161-67BE894E3ED9}\ not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{21F23D3E-D738-4718-8BAD-ABC7868C87B3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21F23D3E-D738-4718-8BAD-ABC7868C87B3}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5A0AE168-9790-4650-A159-95AADB107CD4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5A0AE168-9790-4650-A159-95AADB107CD4}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5B6F482F-6429-4FA9-82C7-EC32F9CDDF72}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B6F482F-6429-4FA9-82C7-EC32F9CDDF72}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6BC0351F-04A8-449C-AD7F-6999E6F9993E}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6BC0351F-04A8-449C-AD7F-6999E6F9993E}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "AVG Secure Search" removed from browser.search.defaultenginename Prefs.js: "Google" removed from browser.search.selectedEngine Prefs.js: "hxxp://isearch.avg.com?cid=%7B51b341e3-9e13-487f-a302-67dae3628962%7D&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&ds=hk011&v=11.1.0.12&lang=de&pr=sa&d=2012-07-15%2015%3A47%3A41&sap=hp" removed from browser.startup.homepage Prefs.js: "hxxp://isearch.avg.com/search?cid=%7B51b341e3-9e13-487f-a302-67dae3628962%7D&mid=6ba9a8ca512542638d5e30e04e96b36f-72c19b577b08692757de264850fd90e1a85a1e71&ds=hk011&v=11.1.0.12&lang=de&pr=sa&d=2012-07-15%2015%3A47%3A41&sap=ku&q=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLinkedConnections deleted successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a8bc2ca-77d4-11e1-9b26-88ae1df44cb6}\ not found. File E:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2a8bc2e7-77d4-11e1-9b26-88ae1df44cb6}\ not found. File E:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f1484b8-6c33-11e0-97bd-88ae1df44cb6}\ not found. File E:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7352d6c2-77ee-11e1-9afb-88ae1df44cb6}\ not found. File E:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cdb7dc2-2e13-11e1-b071-88ae1df44cb6}\ not found. File E:\DPFMate.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found. File E:\AutoRun.exe not found. C:\Windows\System32\TBD4405.tmp deleted successfully. C:\Users\ToSa\Desktop\ett98cf7.exe moved successfully. C:\ProgramData\rat_0ybba.pad moved successfully. C:\Users\ToSa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk moved successfully. C:\Users\ToSa\AppData\Roaming\Mozilla\Firefox\Profiles\sx3smlxf.default\searchplugins\softonic.xml moved successfully. C:\Users\ToSa\SoftonicDownloader_fuer_openoffice.exe moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\ToSa\Desktop\cmd.bat deleted successfully. C:\Users\ToSa\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: ToSa ->Temp folder emptied: 896424296 bytes ->Temporary Internet Files folder emptied: 566852580 bytes ->Java cache emptied: 941577 bytes ->FireFox cache emptied: 377109382 bytes ->Flash cache emptied: 112586 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 191942586 bytes RecycleBin emptied: 1335257 bytes Total Files Cleaned = 1.941,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public User: ToSa ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.56.0 log created on 08092012_104829 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... Gibt es weitere Schritte die ich ausführen sollte? Gruß Thorsten |
09.08.2012, 10:06 | #4 |
/// Helfer-Team | GVU-Trojaner mit Webcam Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
09.08.2012, 21:44 | #5 |
| GVU-Trojaner mit Webcam Hallo, der Rechner läuft soweit gut würd ich sagen. Vor dem Fix mit OTL hatte ich nach dem Hochfahren noch eine Fehlermeldung das ein Modul (C:\Users\ToSa\AppData\Local\Temp\abby0_tar.exe) nicht gefunden werden kann. Diese ist mittlerweile aber auch verschwunden. Also insofern alles TipTop. Die Log-Files der beiden durchgeführten Aktionen findest Du anbei. Vielen Dank nochmal für die Unterstützung Malwarebytes: Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.09.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 ToSa :: TOSA-TOSH [Administrator] Schutz: Aktiviert 09.08.2012 16:39:43 mbam-log-2012-08-09 (16-39-43).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 308952 Laufzeit: 1 Stunde(n), 27 Minute(n), 54 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\ToSa\Downloads\SoftonicDownloader_fuer_microsoft-office-compatibility-pack.exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\_OTL\MovedFiles\08092012_104829\C_Users\ToSa\SoftonicDownloader_fuer_openoffice.exe (PUP.OfferBundler.ST) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleaner: # AdwCleaner v1.800 - Logfile created 08/09/2012 at 18:15:48 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Starter Service Pack 1 (32 bits) # User : ToSa - TOSA-TOSH # Running from : C:\Users\ToSa\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** File Found : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml ***** [Registry] ***** Key Found : HKCU\Software\IGearSettings Key Found : HKLM\SOFTWARE\Software ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=15&cc= -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\ToSa\AppData\Roaming\Mozilla\Firefox\Profiles\sx3smlxf.default\prefs.js Found : user_pref("extensions.Softonic.admin", false); Found : user_pref("extensions.Softonic.aflt", "orgnl"); Found : user_pref("extensions.Softonic.autoRvrt", "false"); Found : user_pref("extensions.Softonic.dfltLng", ""); Found : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)"); Found : user_pref("extensions.Softonic.dspOld", ""); Found : user_pref("extensions.Softonic.excTlbr", false); Found : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=13&cc[...] Found : user_pref("extensions.Softonic.hpOld", "hxxp://www.startfenster.com"); Found : user_pref("extensions.Softonic.id", "42f7a98d00000000000000264df321e2"); Found : user_pref("extensions.Softonic.instlDay", "15484"); Found : user_pref("extensions.Softonic.instlRef", "MON00001"); Found : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=[...] Found : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=1[...] Found : user_pref("extensions.Softonic.prdct", "Softonic"); Found : user_pref("extensions.Softonic.prtnrId", "softonic"); Found : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search set[...] Found : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Found : user_pref("extensions.Softonic.tlbrId", "base"); Found : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource[...] Found : user_pref("extensions.Softonic.vrsn", "1.5.21.0"); Found : user_pref("extensions.Softonic.vrsni", "1.5.21.0"); Found : user_pref("extensions.Softonic_i.dfltSrch", true); Found : user_pref("extensions.Softonic_i.dnsErr", true); Found : user_pref("extensions.Softonic_i.hmpg", true); Found : user_pref("extensions.Softonic_i.hmpgUrl", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=1[...] Found : user_pref("extensions.Softonic_i.newTab", false); Found : user_pref("extensions.Softonic_i.smplGrp", "none"); Found : user_pref("extensions.Softonic_i.vrsnTs", "1.5.21.04:50:53"); ************************* AdwCleaner[R1].txt - [3715 octets] - [09/08/2012 18:15:48] ########## EOF - C:\AdwCleaner[R1].txt - [3843 octets] ########## Grüße Thorsten |
10.08.2012, 12:27 | #6 |
/// Helfer-Team | GVU-Trojaner mit Webcam Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ --> GVU-Trojaner mit Webcam |
21.08.2012, 15:10 | #7 |
| GVU-Trojaner mit Webcam Hallo, war im Urlaub deshalb kommt meine Antwort etwas verspätete, sorry! Hab die beiden Aktionen ausgeführt. Die Log-Datei des AdwCleaners folgt anbei. Beim Scan mit Emisoft wurde nichts gefunden und es wurde auch keine Log-Datei geschrieben. AdwCleaner: # AdwCleaner v1.800 - Logfile created 08/18/2012 at 20:00:17 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Starter Service Pack 1 (32 bits) # User : ToSa - TOSA-TOSH # Running from : C:\Users\ToSa\Desktop\AntiVirus-Software\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml ***** [Registry] ***** Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKLM\SOFTWARE\Software ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=15&cc= --> hxxp://www.google.com -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\ToSa\AppData\Roaming\Mozilla\Firefox\Profiles\sx3smlxf.default\prefs.js C:\Users\ToSa\AppData\Roaming\Mozilla\Firefox\Profiles\sx3smlxf.default\user.js ... Deleted ! Deleted : user_pref("extensions.Softonic.admin", false); Deleted : user_pref("extensions.Softonic.aflt", "orgnl"); Deleted : user_pref("extensions.Softonic.autoRvrt", "false"); Deleted : user_pref("extensions.Softonic.dfltLng", ""); Deleted : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)"); Deleted : user_pref("extensions.Softonic.dspOld", ""); Deleted : user_pref("extensions.Softonic.excTlbr", false); Deleted : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=13&cc[...] Deleted : user_pref("extensions.Softonic.hpOld", "hxxp://www.startfenster.com"); Deleted : user_pref("extensions.Softonic.id", "42f7a98d00000000000000264df321e2"); Deleted : user_pref("extensions.Softonic.instlDay", "15484"); Deleted : user_pref("extensions.Softonic.instlRef", "MON00001"); Deleted : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=[...] Deleted : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=1[...] Deleted : user_pref("extensions.Softonic.prdct", "Softonic"); Deleted : user_pref("extensions.Softonic.prtnrId", "softonic"); Deleted : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search set[...] Deleted : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Deleted : user_pref("extensions.Softonic.tlbrId", "base"); Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource[...] Deleted : user_pref("extensions.Softonic.vrsn", "1.5.21.0"); Deleted : user_pref("extensions.Softonic.vrsni", "1.5.21.0"); Deleted : user_pref("extensions.Softonic_i.dfltSrch", true); Deleted : user_pref("extensions.Softonic_i.dnsErr", true); Deleted : user_pref("extensions.Softonic_i.hmpg", true); Deleted : user_pref("extensions.Softonic_i.hmpgUrl", "hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=1[...] Deleted : user_pref("extensions.Softonic_i.newTab", false); Deleted : user_pref("extensions.Softonic_i.smplGrp", "none"); Deleted : user_pref("extensions.Softonic_i.vrsnTs", "1.5.21.04:50:53"); ************************* AdwCleaner[R1].txt - [3844 octets] - [09/08/2012 18:15:48] AdwCleaner[S1].txt - [3781 octets] - [18/08/2012 20:00:17] ########## EOF - C:\AdwCleaner[S1].txt - [3909 octets] ########## Danke und Gruß Thorsten |
21.08.2012, 15:21 | #8 |
/// Helfer-Team | GVU-Trojaner mit Webcam Emsisoft Log? |
23.08.2012, 23:15 | #9 |
| GVU-Trojaner mit Webcam Hallo, musst ein bisschen suchen, hab die Log-Datei dann aber noch gefunden Anbei der Emisoft-Log: Emsisoft Anti-Malware - Version 6.6 Letztes Update: 23.08.2012 17:30:17 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 23.08.2012 17:34:40 Gescannt 572676 Gefunden 0 Scan Ende: 23.08.2012 21:15:09 Scan Zeit: 3:40:29 Gruß Thorsten |
24.08.2012, 00:04 | #10 |
/// Helfer-Team | GVU-Trojaner mit Webcam Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
24.08.2012, 14:32 | #11 |
| GVU-Trojaner mit Webcam Hi, haben den Scann nun durchgeführt. Der Log folgt: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=972132effcf82649967181e06ff2ea5c # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-24 09:59:05 # local_time=2012-08-24 11:59:05 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=4096 16777215 100 0 1221362 1221362 0 0 # compatibility_mode=5893 16776573 100 94 33842 97400257 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=130299 # found=1 # cleaned=1 # scan_time=33278 C:\Users\ToSa\Downloads\WinZip165International.exe a variant of Win32/OpenInstall application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Grüße Thorsten |
24.08.2012, 14:54 | #12 |
/// Helfer-Team | GVU-Trojaner mit Webcam Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck |
28.08.2012, 22:49 | #13 |
| GVU-Trojaner mit Webcam Hallo, Java hab ich runtergeladen und dementsprechend eingestellt. Der PluginCheck ergab folgendes: PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 14.0.1 ist aktuell Flash 10,3,181,34 ist veraltet! Aktualisieren Sie bitte auf die neueste Version! Java (1,7,0,6) ist aktuell. Adobe Reader 9,5,1,283 ist veraltet! Aktualisieren Sie bitte auf die neueste Version: 10,1,3 Grüße Thorsten |
29.08.2012, 01:53 | #14 |
/// Helfer-Team | GVU-Trojaner mit Webcam Rest aktualisieren Sehr gut! damit bist Du sauber und entlassen! adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
03.09.2012, 13:37 | #15 |
| GVU-Trojaner mit Webcam Hallo, vielen Dank für Eure tolle Unterstützung! Ich hoffe ich muss eure Hilfe nicht so schnell wieder in Anspruch nehmen. Nochmals vielen Dank! Grüße Thorsten |
Themen zu GVU-Trojaner mit Webcam |
autorun, avg secure search, bonjour, cftmon.lnk, defender, firefox, flash player, free download, go_0molg.pad, gvu trojaner, gvu trojaner 2.07, gvu trojaner entfernen, gvu trojaner mit webcam, gvu-trojaner mit webcam, index, install.exe, installation, locker, plug-in, problem, realtek, registry, reveton.c, scan, secure search, security, software, svchost.exe, system, usb 2.0, webcam gvu trojaner, webcamfenster, windows |