Alt 14.08.2012, 06:28   #1
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt


ich bin kein Computer-Profie und hoffe, daß ich hier alles richtig mache.

ich habe folgendes Problem:

Plötzlich war mein Bildschirm wie eingefrohren. Es war der bekannte "BKA Hinweis" mit den dementsprechenden Zahlungsaufforderungen.
Habe dann den Rechner mit Strg und Entf und dann mit dem Taskmanager runtergefahren
Ich habe dann den Rechner neu gestartet und diesen mit Kaspersky-RescueDisc 2010 gescannt (vorher neuestes Kaspersky Update geladen).

Es wurde eine Bedrohung angezeigt und diese dann wie von Kaspersky empfohlen in die Quarantäne geschoben.
Danach habe ich den Rechner nochmal scannen lassen und Kaspersky hat dann nichts mehr gefunden.

Super dachte ich, Kaspersky Disk raus und den Rechner neu gestartet...
Windows startet kurz, ca 1 Sekunde und dann bekomm ich einen weissen Bildschirm. Sieht so aus wie eine leehre Firefoxseite.
Und nichts geht mehr, genau wie diese "BKA Seite". Kann den Rechner dann nur mit STRg und Entf über den Taskmanager ausmachen.

Nun habe ich mir über Euch die OTLPE geladen und auf eine DVD gebrannt. Programm lässt sich auch starten.

Nachdem ich den Button OTLPE gedrückt habe, habe ich meinen Windowsordner gesucht und angeklickt
"Windows 7 Ultimate (f" dann den Ordner "Windows" dann startet OTLPE auch.

Wenn ich direkt auf "Windows 7 Ultimate (f" gehe erscheint: "Target is not windows 2000 or later".

Der erste Text: "Do you wish to load the remote registry" erscheint nicht
Der Zweit und Dritte aber und habe beim dritten Text den Haken rausgenommen.

OTL startet und ich habe bei "Benutzerdefinierte Scans/Fixes" Euren Text rein kopiert von einem User mit dem gleichen Problem.



Ich hoffe ich war jetzt nicht zu voreilig. Packe jetzt den OTL Text und versuche den Euch zu mailen.

Bedanke mich jetzt schon einmal für Eure Hilfe. OTL.tex folgt weiter unten.

Gruß Ingmar

OTL Text:OTL Logfile:
OTL logfile created on: 8/13/2012 9:23:58 PM - Run 
OTLPE by OldTimer - Version     Folder = X:\Programs\OTLPE
Windows 7 Ultimate  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\Windows | %ProgramFiles% = F:\Program Files
Drive C: | 100.00 Mb Total Space | 65.65 Mb Free Space | 65.65% Space Free | Partition Type: NTFS
Drive D: | 7.46 Gb Total Space | 7.46 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive F: | 465.66 Gb Total Space | 170.49 Gb Free Space | 36.61% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - [2011/09/05 10:06:01 | 000,040,960 | ---- | M] () [Auto] -- F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2011/08/11 19:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- F:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2010/11/19 11:51:48 | 001,483,072 | ---- | M] (TuneUp Software) [Auto] -- F:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/11/19 11:49:04 | 000,029,504 | ---- | M] (TuneUp Software) [Auto] -- F:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010/09/07 12:01:10 | 000,079,872 | ---- | M] () [Auto] -- F:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010/07/20 13:15:34 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- F:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/07/20 13:15:17 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- F:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/03/19 11:13:40 | 000,145,680 | R--- | M] (4G Systems GmbH & Co. KG) [Auto] -- F:\Windows\service4g.exe -- (XS Stick Service)
SRV - [2010/03/18 05:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto] -- F:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/12/15 13:52:17 | 002,480,048 | ---- | M] (Acronis) [Auto] -- F:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009/12/10 06:25:00 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand] -- F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/11/12 00:42:50 | 000,661,072 | ---- | M] (Acronis) [Auto] -- F:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009/11/04 11:45:02 | 000,172,032 | ---- | M] (AMD) [Auto] -- F:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009/07/14 16:53:00 | 000,185,632 | ---- | M] (Ralink Technology, Corp.) [Auto] -- F:\Program Files\RALINK\Common\RaRegistry.exe -- (RalinkRegistryWriter)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/06/22 09:21:58 | 000,304,592 | ---- | M] () [Auto] -- F:\Program Files\XSManager\WTGService.exe -- (WTGService)
SRV - [2009/05/14 11:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto] -- F:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2009/02/26 08:46:40 | 000,147,456 | ---- | M] () [Auto] -- F:\Windows\System32\ANIWConnService.exe -- (ANIWConnService)
SRV - [2008/09/08 02:59:00 | 000,575,488 | ---- | M] (Nokia.) [On_Demand] -- F:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/08/29 10:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto] -- F:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2007/06/05 08:20:32 | 000,177,704 | ---- | M] () [Auto] -- F:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/01/19 06:49:26 | 000,049,152 | ---- | M] (Wireless Service) [Auto] -- F:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService)
SRV - [2007/01/10 23:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto] -- F:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
SRV - [2006/10/31 17:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) [Auto] -- F:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] --  -- (VcommMgr)
DRV - File not found [Kernel | On_Demand] --  -- (VComm)
DRV - File not found [Kernel | On_Demand] --  -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand] --  -- (BT)
DRV - [2012/03/26 19:42:10 | 000,121,080 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2011/09/15 10:08:08 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] -- F:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2011/07/22 12:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- F:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 17:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/05/06 15:47:46 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- F:\Windows\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/10/07 07:34:32 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand] -- F:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010/07/20 13:15:17 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- F:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/07/08 09:17:56 | 000,603,240 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand] -- F:\Windows\System32\drivers\RTL8192su.sys -- (RTL8192su)
DRV - [2010/06/23 05:24:56 | 000,023,040 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- F:\Windows\System32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010/01/26 22:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto] -- F:\Windows\System32\drivers\npf.sys -- (npf)
DRV - [2009/12/15 13:52:18 | 000,160,288 | ---- | M] (Acronis) [File_System | On_Demand] -- F:\Windows\System32\drivers\afcdp.sys -- (afcdp)
DRV - [2009/12/15 13:52:16 | 000,911,680 | ---- | M] (Acronis) [Kernel | Boot] -- F:\Windows\System32\drivers\tdrpm258.sys -- (tdrpman258) Acronis Try&Decide and Restore Points filter (build 258)
DRV - [2009/12/15 13:52:12 | 000,581,984 | ---- | M] (Acronis) [Kernel | Boot] -- F:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV - [2009/12/15 13:51:58 | 000,158,272 | ---- | M] (Acronis) [Kernel | Boot] -- F:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV - [2009/12/11 19:53:04 | 000,271,360 | ---- | M] () [Kernel | Auto] -- F:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/12/11 19:53:00 | 000,018,048 | ---- | M] () [Kernel | Auto] -- F:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009/11/04 12:16:46 | 005,079,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/10/26 03:54:24 | 000,025,088 | ---- | M] (HTC, Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009/09/30 10:33:56 | 000,104,976 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009/09/25 05:13:12 | 000,159,232 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2009/08/17 14:17:44 | 001,077,760 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/07/29 12:18:20 | 000,553,472 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- F:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- F:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/04/15 09:32:36 | 000,715,520 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\rt2870.sys -- (rt2870)
DRV - [2009/02/13 07:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand] -- F:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2009/01/07 18:39:36 | 000,020,744 | ---- | M] (IVT Corporation.) [Kernel | Boot] -- F:\Windows\System32\drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2008/12/07 07:44:54 | 000,030,088 | ---- | M] () [Kernel | On_Demand] -- F:\Windows\System32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2008/10/31 10:19:38 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand] -- F:\Windows\System32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2008/09/04 00:28:22 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2008/09/04 00:27:54 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2008/09/04 00:27:28 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008/08/26 05:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- F:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/07/02 09:58:48 | 000,026,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2007/07/03 10:58:20 | 000,106,792 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2007/07/03 10:57:24 | 000,011,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2007/07/03 10:54:24 | 000,080,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2006/11/30 14:55:00 | 000,113,792 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2006/11/20 12:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2006/11/10 09:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\afc.sys -- (Afc)
DRV - [2006/11/02 12:41:00 | 000,053,504 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2006/10/27 19:29:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006/10/10 14:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2006/10/05 11:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2005/08/01 11:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System] -- F:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005/07/11 13:58:00 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2005/05/17 08:48:21 | 000,050,176 | ---- | M] (Protection Technology) [Kernel | Boot] -- F:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/05/16 09:23:38 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot] -- F:\Windows\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2005/05/16 09:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot] -- F:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005/01/06 08:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- F:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2004/08/13 03:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand] -- F:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 3E DB 04 73 79 CA 01  [binary data]
IE - HKU\Ingmar_ON_F\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
IE - HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic Deutsch Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}:5.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:
FF - prefs.js..extensions.enabledItems: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c}:
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: F:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: F:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: F:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/19 00:30:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/12 10:40:36 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\firejump@firejump.net [2011/11/24 06:17:31 | 000,000,000 | ---D | M]
[2009/12/10 04:48:47 | 000,000,000 | ---D | M] (No name found) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Extensions
[2012/07/16 04:05:42 | 000,000,000 | ---D | M] (No name found) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions
[2012/05/18 14:04:31 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/07/16 04:05:42 | 000,000,000 | ---D | M] (ST Deutsch Community Toolbar) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}
[2011/12/30 07:52:36 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/12/15 08:40:47 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011/06/05 05:00:30 | 000,000,000 | ---D | M] (Conduit Engine) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\engine@conduit.com
[2011/11/24 06:17:31 | 000,000,000 | ---D | M] (FireJump) -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\firejump@firejump.net
[2011/09/05 10:06:08 | 000,002,559 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\askcom.xml
[2011/09/05 10:06:08 | 000,001,110 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\conduit.xml
[2011/12/15 07:19:47 | 000,003,915 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\sweetim.xml
[2011/09/05 10:06:08 | 000,001,872 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\{44A48CB3-B684-4A71-A2E8-4D0767F54B17}.xml
[2011/09/05 10:06:08 | 000,002,190 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\{47620369-28C0-4261-9EF5-2369DBC3C023}.xml
[2011/09/05 10:06:08 | 000,002,079 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\{4985DE69-F338-4A7D-83E2-D06AE13DA867}.xml
[2011/11/25 04:12:38 | 000,000,000 | ---D | M] (No name found) -- F:\Program Files\Mozilla Firefox\extensions
[2011/03/11 17:56:52 | 000,000,000 | ---D | M] (Skype extension) -- F:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
File not found (No name found) -- 
[2012/07/19 00:30:12 | 000,136,672 | ---- | M] (Mozilla Foundation) -- F:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 15:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- F:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/04/09 12:15:13 | 000,001,392 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/02/16 19:31:59 | 000,002,352 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/04/09 12:15:13 | 000,002,252 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/09 12:15:13 | 000,001,153 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/04/09 12:15:13 | 000,006,805 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/04/09 12:15:13 | 000,001,178 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/04/09 12:15:13 | 000,001,105 | ---- | M] () -- F:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2010/12/02 15:20:34 | 000,000,898 | ---- | M]) - F:\Windows\System32\drivers\etc\hosts
O1 - Hosts:                activate.adobe.com
O1 - Hosts:       applian.securesites.com
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - F:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\Ingmar_ON_F\..\Toolbar\WebBrowser: (Softonic Deutsch Toolbar) - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.)
O3 - HKU\Ingmar_ON_F\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] F:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] F:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ANIWZCS2Service] F:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
O4 - HKLM..\Run: [Ask and Record FLV Service] F:\Program Files\Replay Media Catcher\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] F:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [D-Link D-Link Wireless N DWA-140] F:\Program Files\D-Link\DWA-140 revB\AirNCFG.exe (D-Link Corp.)
O4 - HKLM..\Run: [EEventManager] F:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HDAudDeck] F:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [HTC Sync Loader] F:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [NBKeyScan] F:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [Ocs_SM] F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4 - HKLM..\Run: [OpwareSE4] F:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Smart File Advisor] F:\Program Files\Smart File Advisor\sfa.exe (Filefacts.net)
O4 - HKLM..\Run: [StartCCC] F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [starter4g] F:\Windows\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [TrueImageMonitor.exe] F:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [TweakUI 1.33 deutsch] F:\Windows\System32\TWEAKUI.CPL (Brummelchen@gmx.at)
O4 - HKLM..\Run: [WrtMon.exe] F:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKU\Ingmar_ON_F..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] F:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKU\Ingmar_ON_F..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKU\Ingmar_ON_F..\Run: [wnzhztlwwvwoahc] F:\ProgramData\wnzhztlw.exe ()
O4 - HKU\LocalService_ON_F..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_F..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\Ingmar_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: Free YouTube Download - F:\Users\Ingmar\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - F:\Users\Ingmar\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab (Java Plug-in 1.5.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - F:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - F:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - F:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\Shell - "" = AutoRun
O33 - MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\Shell\AutoRun\command - "" = H:\USBAutoRun.exe
O33 - MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AUTORUN.exe
O33 - MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\Shell - "" = AutoRun
O33 - MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\AUTORUN.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: Sharedaccess -  File not found
NetSvcs: SRService -  File not found
NetSvcs: UxTuneUp - F:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp -  File not found
NetSvcs: wuauserv -  File not found
NetSvcs: BITS -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
MsConfig - State: "bootini" - 0
========== Files/Folders - Created Within 30 Days ==========
[2012/08/10 16:02:12 | 000,000,000 | ---D | C] -- F:\ProgramData\jqfnlczewmpbtxp
[2012/07/28 06:51:48 | 000,000,000 | ---D | C] -- F:\Users\Ingmar\AppData\Roaming\Malwarebytes
[2012/07/28 06:51:45 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/28 06:51:44 | 000,000,000 | ---D | C] -- F:\Program Files\Malwarebytes' Anti-Malware
[2012/07/28 06:51:44 | 000,000,000 | ---D | C] -- F:\ProgramData\Malwarebytes
[2010/11/07 17:53:42 | 002,131,336 | ---- | C] (Ask.com                                                      ) -- F:\Program Files\Common Files\AskToolbarInstaller.exe
[2010/03/11 07:55:02 | 000,047,360 | ---- | C] (VSO Software) -- F:\Users\Ingmar\AppData\Roaming\pcouffin.sys
[1 F:\Windows\System32\*.tmp files -> F:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/11 11:13:09 | 000,067,584 | --S- | M] () -- F:\Windows\bootstat.dat
[2012/08/11 11:12:05 | 000,000,007 | ---- | M] () -- F:\Windows\System32\ANIWZCSUSERNAME
[2012/08/11 11:11:46 | 000,001,094 | ---- | M] () -- F:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/11 11:11:29 | 2616,594,432 | -HS- | M] () -- F:\hiberfil.sys
[2012/08/11 10:34:19 | 000,016,944 | -H-- | M] () -- F:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/11 10:34:19 | 000,016,944 | -H-- | M] () -- F:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/10 16:02:12 | 000,000,051 | ---- | M] () -- F:\ProgramData\mijgefhjgbuamsf
[2012/08/10 16:02:06 | 000,057,344 | ---- | M] () -- F:\ProgramData\wnzhztlw.exe
[2012/08/10 15:35:00 | 000,001,098 | ---- | M] () -- F:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/10 11:22:13 | 000,657,438 | ---- | M] () -- F:\Windows\System32\perfh007.dat
[2012/08/10 11:22:13 | 000,618,714 | ---- | M] () -- F:\Windows\System32\perfh009.dat
[2012/08/10 11:22:13 | 000,130,810 | ---- | M] () -- F:\Windows\System32\perfc007.dat
[2012/08/10 11:22:13 | 000,107,034 | ---- | M] () -- F:\Windows\System32\perfc009.dat
[2012/08/10 11:00:29 | 103,525,852 | ---- | M] () -- F:\Windows\System32\drivers\Avg\incavi.avm
[2012/08/09 02:17:11 | 000,000,040 | -HS- | M] () -- F:\ProgramData\.zreglib
[2012/08/09 02:14:36 | 000,000,000 | R--D | M] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/07 04:13:03 | 000,000,102 | ---- | M] () -- F:\Users\Ingmar\AppData\default.pls
[2012/07/28 11:47:15 | 000,000,000 | ---D | M] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/28 10:48:14 | 267,563,210 | ---- | M] () -- F:\Windows\MEMORY.DMP
[2012/07/19 00:30:16 | 000,002,047 | ---- | M] () -- F:\Users\Ingmar\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[1 F:\Windows\System32\*.tmp files -> F:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/10 16:02:12 | 000,057,344 | ---- | C] () -- F:\ProgramData\wnzhztlw.exe
[2012/08/10 16:02:07 | 000,000,051 | ---- | C] () -- F:\ProgramData\mijgefhjgbuamsf
[2012/08/09 02:17:11 | 000,000,040 | -HS- | C] () -- F:\ProgramData\.zreglib
[2012/08/09 02:14:36 | 000,002,122 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HD Writer.lnk
[2012/08/09 02:14:36 | 000,001,379 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
[2012/08/09 02:14:36 | 000,000,914 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
[2012/06/20 10:58:21 | 004,503,728 | ---- | C] () -- F:\ProgramData\0tbpw.pad
[2012/05/11 10:18:27 | 000,065,793 | ---- | C] () -- F:\Windows\System32\esfwad.bin
[2012/01/22 07:02:43 | 000,085,504 | ---- | C] () -- F:\Windows\System32\ff_vfw.dll
[2011/11/25 16:55:36 | 000,000,029 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\default.rss
[2011/11/25 16:55:35 | 000,000,000 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\downloads.m3u
[2011/04/29 05:49:52 | 000,045,115 | ---- | C] () -- F:\Windows\System32\ANICtl.dll
[2011/02/12 09:51:37 | 000,000,000 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\chrtmp
[2010/12/23 15:25:31 | 000,000,056 | -H-- | C] () -- F:\Windows\System32\ezsidmv.dat
[2010/12/02 15:21:12 | 000,237,568 | ---- | C] () -- F:\Windows\System32\rmc_rtspdl.dll
[2010/11/12 11:52:21 | 000,000,060 | ---- | C] () -- F:\Windows\dcmvwr.INI
[2010/11/10 13:56:16 | 000,000,000 | ---- | C] () -- F:\Windows\iPlayer.INI
[2010/11/04 09:47:40 | 000,003,284 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\ANIWZCS{B44F8B5D-A5B3-441F-9F39-49F0C4B7E99B}
[2010/11/04 09:46:47 | 000,147,456 | ---- | C] () -- F:\Windows\System32\ANIWConnService.exe
[2010/11/04 09:46:42 | 000,315,392 | ---- | C] () -- F:\Windows\System32\ANIOApi.dll
[2010/11/04 09:46:32 | 000,258,048 | ---- | C] () -- F:\Windows\System32\wlanapp.dll
[2010/11/04 09:46:32 | 000,204,800 | ---- | C] () -- F:\Windows\System32\aIPH.dll
[2010/11/04 09:46:32 | 000,049,152 | ---- | C] () -- F:\Windows\System32\JJAKEn.dll
[2010/11/04 09:46:32 | 000,049,152 | ---- | C] () -- F:\Windows\System32\AQCKGen.dll
[2010/11/04 09:46:18 | 000,724,992 | ---- | C] () -- F:\Windows\System32\ANIOWPS.dll
[2010/11/04 09:46:18 | 000,237,568 | ---- | C] () -- F:\Windows\System32\ANIWPS.exe
[2010/11/04 09:45:06 | 000,013,931 | ---- | C] () -- F:\Windows\System32\RaCoInst.dat
[2010/07/15 02:39:00 | 000,000,173 | ---- | C] () -- F:\Windows\SOFTPEG.INI
[2010/06/02 13:36:25 | 000,000,848 | -HS- | C] () -- F:\Windows\System32\KGyGaAvL.sys
[2010/03/17 08:18:02 | 000,000,071 | ---- | C] () -- F:\Windows\EPSONCD.INI
[2010/03/15 06:07:16 | 000,040,960 | ---- | C] () -- F:\Windows\System32\IPPCPUID.DLL
[2010/03/15 06:06:21 | 000,011,776 | ---- | C] () -- F:\Windows\System32\pmsbfn32.dll
[2010/03/15 06:04:09 | 000,000,416 | ---- | C] () -- F:\Windows\MAXLINK.INI
[2010/03/15 05:53:17 | 000,000,029 | ---- | C] () -- F:\Windows\DEBUGSM.INI
[2010/03/15 05:37:40 | 000,094,486 | ---- | C] () -- F:\Windows\System32\EPPICPrinterDB.dat
[2010/03/15 05:37:40 | 000,001,146 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_DU.dat
[2010/03/15 05:37:40 | 000,001,136 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_ES.dat
[2010/03/15 05:37:40 | 000,001,120 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_IT.dat
[2010/03/15 05:37:40 | 000,001,107 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_GE.dat
[2010/03/15 05:37:40 | 000,001,104 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_EN.dat
[2010/03/15 05:37:40 | 000,000,099 | ---- | C] () -- F:\Windows\System32\PICSDK.ini
[2010/03/15 05:37:39 | 000,026,154 | ---- | C] () -- F:\Windows\System32\EPPICPattern1.dat
[2010/03/15 05:37:39 | 000,024,903 | ---- | C] () -- F:\Windows\System32\EPPICPattern3.dat
[2010/03/15 05:37:39 | 000,021,390 | ---- | C] () -- F:\Windows\System32\EPPICPattern5.dat
[2010/03/15 05:37:39 | 000,020,148 | ---- | C] () -- F:\Windows\System32\EPPICPattern2.dat
[2010/03/15 05:37:39 | 000,011,811 | ---- | C] () -- F:\Windows\System32\EPPICPattern4.dat
[2010/03/15 05:37:39 | 000,004,943 | ---- | C] () -- F:\Windows\System32\EPPICPattern6.dat
[2010/03/15 05:37:39 | 000,001,139 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_PT.dat
[2010/03/15 05:37:39 | 000,001,139 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_BP.dat
[2010/03/15 05:37:39 | 000,001,129 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_FR.dat
[2010/03/15 05:37:39 | 000,001,129 | ---- | C] () -- F:\Windows\System32\EPPICPresetData_CF.dat
[2010/03/15 05:25:39 | 000,000,025 | ---- | C] () -- F:\Windows\CDER220.ini
[2010/03/13 11:08:24 | 000,000,485 | ---- | C] () -- F:\Windows\DVDFabGold.INI
[2010/03/11 07:55:56 | 000,001,189 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\vso_ts_preview.xml
[2010/03/11 07:55:02 | 000,087,608 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\inst.exe
[2010/03/11 07:55:02 | 000,007,887 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\pcouffin.cat
[2010/03/11 07:55:02 | 000,001,144 | ---- | C] () -- F:\Users\Ingmar\AppData\Roaming\pcouffin.inf
[2010/02/19 18:02:21 | 000,046,592 | ---- | C] () -- F:\Users\Ingmar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/04 16:24:53 | 000,303,104 | ---- | C] () -- F:\Windows\System32\CmiInstallResAll.dll
[2010/02/02 03:23:49 | 000,000,096 | ---- | C] () -- F:\Windows\WirelessFTP.INI
[2010/01/31 16:36:49 | 000,004,940 | ---- | C] () -- F:\ProgramData\mtbjfghn.xbe
[2010/01/31 03:15:24 | 000,000,000 | ---- | C] () -- F:\Windows\tosOBEX.INI
[2010/01/26 22:09:02 | 000,053,299 | ---- | C] () -- F:\Windows\System32\pthreadVC.dll
[2010/01/15 07:21:40 | 000,094,208 | ---- | C] () -- F:\Windows\VMix.dll
[2010/01/15 07:21:40 | 000,000,294 | ---- | C] () -- F:\Windows\cmudax3.ini
[2009/12/11 19:53:04 | 000,271,360 | ---- | C] () -- F:\Windows\System32\drivers\atksgt.sys
[2009/12/11 19:53:00 | 000,018,048 | ---- | C] () -- F:\Windows\System32\drivers\lirsgt.sys
[2009/12/11 08:50:37 | 000,000,102 | ---- | C] () -- F:\Users\Ingmar\AppData\default.pls
[2009/12/11 08:50:31 | 000,000,069 | ---- | C] () -- F:\Windows\NeroDigital.ini
[2009/12/10 16:53:09 | 000,007,618 | ---- | C] () -- F:\Users\Ingmar\AppData\Local\Resmon.ResmonCfg
[2009/12/10 08:07:24 | 000,000,000 | ---- | C] () -- F:\Windows\ativpsrm.bin
[2009/12/10 06:55:31 | 000,004,757 | ---- | C] () -- F:\Windows\Irremote.ini
[2009/12/10 04:48:42 | 000,000,000 | ---- | C] () -- F:\Windows\nsreg.dat
[2009/12/10 04:28:57 | 000,000,020 | ---- | C] () -- F:\Windows\RaUI.INI
[2009/12/10 04:28:04 | 000,315,392 | ---- | C] () -- F:\Windows\System32\AegisI5.exe
[2009/12/10 04:28:04 | 000,303,234 | ---- | C] () -- F:\Windows\System32\Install7x.dll
[2009/12/10 04:28:04 | 000,002,048 | ---- | C] () -- F:\Windows\System32\drivers\rt73.bin
[2009/12/03 03:27:28 | 000,080,416 | ---- | C] () -- F:\Windows\System32\RtNicProp32.dll
[2009/09/01 16:55:54 | 000,195,855 | ---- | C] () -- F:\Windows\System32\atiicdxx.dat
[2009/07/14 04:47:43 | 000,657,438 | ---- | C] () -- F:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- F:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,130,810 | ---- | C] () -- F:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- F:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- F:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 002,442,112 | ---- | C] () -- F:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,618,714 | ---- | C] () -- F:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- F:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,107,034 | ---- | C] () -- F:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- F:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- F:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- F:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- F:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- F:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- F:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- F:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- F:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- F:\Windows\System32\mlang.dat
[2009/02/18 13:55:20 | 000,294,912 | ---- | C] () -- F:\Windows\System32\ATIODE.exe
[2009/02/03 16:52:02 | 000,045,056 | ---- | C] () -- F:\Windows\System32\ATIODCLI.exe
[2008/12/07 07:44:54 | 000,030,088 | ---- | C] () -- F:\Windows\System32\drivers\btnetBus.sys
[2007/06/05 08:20:32 | 000,177,704 | ---- | C] () -- F:\Windows\System32\PSIService.exe
[2007/04/27 04:43:58 | 000,120,200 | ---- | C] () -- F:\Windows\System32\DLLDEV32i.dll
[2006/12/05 08:05:06 | 000,114,688 | ---- | C] () -- F:\Windows\System32\TosBtAcc.dll
[2005/07/22 16:30:20 | 000,065,536 | ---- | C] () -- F:\Windows\System32\TosCommAPI.dll
[2005/02/25 01:15:00 | 000,159,744 | ---- | C] () -- F:\Windows\System32\EPSPTDV.DLL
[2004/08/13 03:56:20 | 000,005,810 | ---- | C] () -- F:\Windows\System32\drivers\ASACPI.sys
[2000/07/22 11:49:46 | 000,431,104 | ---- | C] () -- F:\Windows\System32\VFCodec.dll
========== LOP Check ==========
[2009/12/15 13:54:31 | 000,000,000 | ---D | M] -- F:\ProgramData\Acronis
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Application Data
[2012/07/28 11:47:04 | 000,000,000 | ---D | M] -- F:\ProgramData\avg9
[2009/12/10 05:45:57 | 000,000,000 | ---D | M] -- F:\ProgramData\Azureus
[2012/02/16 19:31:55 | 000,000,000 | ---D | M] -- F:\ProgramData\Babylon
[2011/03/15 04:59:11 | 000,000,000 | -H-D | M] -- F:\ProgramData\Common Files
[2012/01/22 06:39:37 | 000,000,000 | ---D | M] -- F:\ProgramData\Cypheros
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Documents
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Dokumente
[2012/05/11 12:34:46 | 000,000,000 | ---D | M] -- F:\ProgramData\EPSON
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Favorites
[2010/02/02 02:44:33 | 000,000,000 | ---D | M] -- F:\ProgramData\Installations
[2012/08/10 19:11:37 | 000,000,000 | ---D | M] -- F:\ProgramData\jqfnlczewmpbtxp
[2011/06/24 09:29:59 | 000,000,000 | ---D | M] -- F:\ProgramData\MAGIX
[2012/06/20 11:40:52 | 000,000,000 | ---D | M] -- F:\ProgramData\MFAData
[2012/03/11 17:13:15 | 000,000,000 | ---D | M] -- F:\ProgramData\Panasonic
[2010/07/21 06:19:52 | 000,000,000 | ---D | M] -- F:\ProgramData\PC Suite
[2009/12/10 09:20:27 | 000,000,000 | ---D | M] -- F:\ProgramData\Ralink
[2009/12/10 09:19:51 | 000,000,000 | ---D | M] -- F:\ProgramData\Ralink Driver
[2010/03/15 06:03:58 | 000,000,000 | ---D | M] -- F:\ProgramData\ScanSoft
[2012/04/18 17:00:28 | 000,000,000 | ---D | M] -- F:\ProgramData\SlySoft
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Start Menu
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Startmenü
[2012/06/20 11:35:12 | 000,000,000 | ---D | M] -- F:\ProgramData\Temp
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\ProgramData\Templates
[2011/02/17 15:42:24 | 000,000,000 | ---D | M] -- F:\ProgramData\TuneUp Software
[2010/03/15 08:38:13 | 000,000,000 | ---D | M] -- F:\ProgramData\UDL
[2009/12/10 05:30:26 | 000,000,000 | ---D | M] -- F:\ProgramData\Ulead Systems
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\ProgramData\Vorlagen
[2011/02/17 15:40:39 | 000,000,000 | -HSD | M] -- F:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011/01/30 16:50:26 | 000,000,000 | ---D | M] -- F:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/03 01:49:23 | 000,032,640 | ---- | M] () -- F:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
[2010/01/15 07:23:20 | 000,000,000 | -H-D | M] -- F:\$AVG
[2010/09/08 11:24:02 | 000,000,000 | -HSD | M] -- F:\$Recycle.Bin
[2012/07/11 22:35:02 | 000,000,000 | -HSD | M] -- F:\Config.Msi
[2010/12/24 08:59:59 | 000,000,000 | ---D | M] -- F:\Die Ultimative Chart - Show - Die Beliebtesten Weihnachts Hits Aller Zeiten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- F:\Documents and Settings
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\Dokumente und Einstellungen
[2011/02/12 08:54:26 | 000,000,000 | ---D | M] -- F:\DVDFabPlatinum_Temp
[2010/02/19 17:01:09 | 000,000,000 | ---D | M] -- F:\Games
[2012/07/28 13:03:14 | 000,000,000 | ---D | M] -- F:\Kaspersky Rescue Disk 10.0
[2009/12/10 05:20:50 | 000,000,000 | RH-D | M] -- F:\MSOCache
[2011/09/18 13:51:15 | 000,000,000 | ---D | M] -- F:\Musik Michi
[2009/07/13 22:37:05 | 000,000,000 | ---D | M] -- F:\PerfLogs
[2012/07/28 11:47:03 | 000,000,000 | R--D | M] -- F:\Program Files
[2012/08/10 16:02:12 | 000,000,000 | -H-D | M] -- F:\ProgramData
[2009/12/09 07:21:48 | 000,000,000 | -HSD | M] -- F:\Programme
[2009/12/09 07:21:49 | 000,000,000 | -HSD | M] -- F:\Recovery
[2012/06/22 14:24:29 | 000,000,000 | -HSD | M] -- F:\RECYCLER
[2012/08/07 09:14:38 | 000,000,000 | ---D | M] -- F:\Ripp
[2012/07/15 17:39:39 | 000,000,000 | ---D | M] -- F:\Serien noch sehen
[2012/02/02 15:06:00 | 000,000,000 | ---D | M] -- F:\Sicherungen von FP 1TB - noch kopieren auf andere FP
[2010/10/30 13:18:42 | 000,000,000 | ---D | M] -- F:\Sounds
[2012/08/08 12:29:30 | 000,000,000 | -HSD | M] -- F:\System Volume Information
[2009/12/10 08:28:09 | 000,000,000 | ---D | M] -- F:\totalcmd
[2012/06/24 04:48:24 | 000,000,000 | ---D | M] -- F:\TV Aufnahmen Receiver
[2009/12/09 07:21:55 | 000,000,000 | R--D | M] -- F:\Users
[2012/08/09 02:13:14 | 000,000,000 | ---D | M] -- F:\Windows
< %PROGRAMFILES%\*.exe >
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
< %systemroot%\*. /mp /s >
< MD5 for: AGP440.SYS  >
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- F:\Windows\System32\drivers\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- F:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- F:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
< MD5 for: ATAPI.SYS  >
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 12-10-2009-141822\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-74253\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-93637\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal#2\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal#3\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\IDE-Kanal\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\Standard-Zweikanal-PCI-IDE-Controller#1\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Users\Ingmar\Documents\DriverGenius\Backup\Driver Backup 2-2-2010-94419\Standard-Zweikanal-PCI-IDE-Controller\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Windows\System32\drivers\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- F:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
< MD5 for: CNGAUDIT.DLL  >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- F:\Windows\System32\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- F:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: EVENTLOG.DLL  >
[2010/12/14 15:35:28 | 000,036,352 | ---- | M] (Panasonic Corporation) MD5=79FF6641458DDBDDB69A6261D46E7E71 -- F:\Program Files\Panasonic\HD Writer AE 3.0\Core\EventLog\EventLog.dll
[2010/12/14 15:35:28 | 000,036,352 | ---- | M] (Panasonic Corporation) MD5=79FF6641458DDBDDB69A6261D46E7E71 -- F:\Program Files\Panasonic\HD Writer AE 3.0\Core\Spec\AVCHD\BDCore\EventLog.dll
< MD5 for: EXPLORER.EXE  >
[2009/07/13 21:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- F:\Windows\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: IASTORV.SYS  >
[2009/07/13 21:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- F:\Windows\System32\drivers\iaStorV.sys
[2009/07/13 21:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- F:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 21:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- F:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
< MD5 for: NETLOGON.DLL  >
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- F:\Windows\System32\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- F:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVSTOR.SYS  >
[2009/07/13 21:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- F:\Windows\System32\drivers\nvstor.sys
[2009/07/13 21:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- F:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 21:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- F:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL  >
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- F:\Windows\System32\scecli.dll
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- F:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
< MD5 for: USER32.DLL  >
[2009/07/13 21:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- F:\Windows\System32\user32.dll
[2009/07/13 21:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- F:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
< MD5 for: USERINIT.EXE  >
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- F:\Windows\System32\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- F:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WINLOGON.EXE  >
[2009/10/28 02:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- F:\Windows\System32\winlogon.exe
[2009/10/28 02:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WS2IFSL.SYS  >
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- F:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- F:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 21:15:21 | 000,828,928 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- F:\Windows\system32\fontext.dll
[2010/07/27 10:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- F:\Windows\system32\shell32.dll
[1 F:\Windows\system32\*.tmp files -> F:\Windows\system32\*.tmp -> ]
Invalid Environment Variable: %USERPROFILE%\*.*
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
< End of report >
--- --- ---

Alt 14.08.2012, 06:40   #2
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Fixen mit OTLpe

  • Starte den unbootbaren Computer erneut mit der OTLPE-CD,
  • warte bis der Reatogo-X-Pe-Desktop erscheint und doppelklicke das OTLPE-Icon.

  • Kopiere folgendes Skript in das Textfeld unterhalb von Custom Scans/Fixes:
  • Sollte das mangels Internet-Verbindung nicht möglich sein,
  • kopiere den Text aus der folgenden Code-Box und speichere ihn als Fix.txt auf einen USB-Stick.
  • Schließe den USB-Stick an den Computer an und öffne Fix.txt mit dem Explorer auf dem Reatogo-Desktop.
  • Kopiere den Inhalt von Fix.txt in das Textfeld unterhalb von Custom Scans/Fixes:

SRV - [2011/09/05 10:06:01 | 000,040,960 | ---- | M] () [Auto] -- F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer) 
DRV - File not found [Kernel | On_Demand] -- -- (VcommMgr) 
DRV - File not found [Kernel | On_Demand] -- -- (VComm) 
DRV - File not found [Kernel | On_Demand] -- -- (Btcsrusb) 
DRV - File not found [Kernel | On_Demand] -- -- (BT) 
IE - HKU\Ingmar_ON_F\..\URLSearchHook: {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.) 
IE - HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local 
FF - prefs.js..browser.search.defaultengine: "Ask.com" 
FF - prefs.js..browser.search.defaultenginename: "Yahoo" 
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic Deutsch Customized Web Search" 
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=" 
FF - prefs.js..browser.search.order.1: "Ask.com" 
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-" 
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-" 
FF - prefs.js..browser.search.selectedEngine: "Yahoo" 
FF - prefs.js..browser.search.useDBForOrder: true 
FF - prefs.js..browser.startup.homepage: "http://www.google.de/" 
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=" 
File not found (No name found) -- 
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) 
O2 - BHO: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.) 
O3 - HKLM\..\Toolbar: (Softonic Deutsch Toolbar) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.) 
O3 - HKU\Ingmar_ON_F\..\Toolbar\WebBrowser: (Softonic Deutsch Toolbar) - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - F:\Program Files\Softonic_Deutsch\prxtbSof0.dll (Conduit Ltd.) 
O3 - HKU\Ingmar_ON_F\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) 
O4 - HKLM..\Run: [Ocs_SM] F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS) 
O4 - HKU\Ingmar_ON_F..\Run: [wnzhztlwwvwoahc] F:\ProgramData\wnzhztlw.exe () 
O4 - HKU\LocalService_ON_F..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (Microsoft Corporation) 
O4 - HKU\NetworkService_ON_F..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (Microsoft Corporation) 
O4 - Startup: F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk () 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 
O7 - HKU\Ingmar_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab (Java Plug-in 1.5.0_15) 
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - F:\autoexec.bat -- [ NTFS ] 
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] 
O33 - MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\Shell - "" = AutoRun 
O33 - MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\Shell\AutoRun\command - "" = H:\USBAutoRun.exe 
O33 - MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\Shell - "" = AutoRun 
O33 - MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AUTORUN.exe 
O33 - MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\Shell - "" = AutoRun 
O33 - MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\Shell\AutoRun\command - "" = E:\autorun.exe 
O33 - MountPoints2\D\Shell - "" = AutoRun 
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\AUTORUN.exe 
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 
[1 F:\Windows\System32\*.tmp files -> F:\Windows\System32\*.tmp -> ] 
[2012/08/10 16:02:06 | 000,057,344 | ---- | M] () -- F:\ProgramData\wnzhztlw.exe 

[2012/02/16 19:31:55 | 000,000,000 | ---D | M] -- F:\ProgramData\Babylon 
[2010/11/07 17:53:42 | 002,131,336 | ---- | C] (Ask.com ) -- F:\Program Files\Common Files\AskToolbarInstaller.exe 
[2012/08/11 11:11:46 | 000,001,094 | ---- | M] () -- F:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2012/08/11 11:12:05 | 000,000,007 | ---- | M] () -- F:\Windows\System32\ANIWZCSUSERNAME 
[2012/08/10 16:02:12 | 000,000,000 | ---D | C] -- F:\ProgramData\jqfnlczewmpbtxp 
[2012/08/10 16:02:12 | 000,000,051 | ---- | M] () -- F:\ProgramData\mijgefhjgbuamsf 
[2012/08/10 15:35:00 | 000,001,098 | ---- | M] () -- F:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2012/06/20 10:58:21 | 004,503,728 | ---- | C] () -- F:\ProgramData\0tbpw.pad 

ipconfig /flushdns /c

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Klick auf .
  • Kopiere den Inhalt hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\OTLpe\MovedFiles\<datum_nummer.log>
  • Teste, ob den Computer nun wieder in den normalen Windows-Modus booten kannst und berichte.


Alt 14.08.2012, 11:31   #3
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

habe alles so gemacht wie oben beschrieben. Ich konnte den Rechner jetzt voll booten.
Ich lass den Rechner jetzt einfach mal an und warte auf weitere Instruktionen.
Ich maile jetzt das Logfile

Hier das Logfile:

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SearchAnonymizer deleted successfully.
F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VcommMgr deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VComm deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Btcsrusb deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BT deleted successfully.
Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ deleted successfully.
F:\Program Files\Softonic_Deutsch\prxtbSof0.dll moved successfully.
HKU\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Yahoo" removed from browser.search.defaultenginename
Prefs.js: "Softonic Deutsch Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=" removed from browser.search.defaulturl
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "moz2-ytff-" removed from browser.search.param.yahoo-fr
Prefs.js: "moz2-ytff-" removed from browser.search.param.yahoo-fr-cjkt
Prefs.js: "Yahoo" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "hxxp://www.google.de/" removed from browser.startup.homepage
Prefs.js: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
F:\Program Files\ConduitEngine\prxConduitEngine.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ not found.
File F:\Program Files\Softonic_Deutsch\prxtbSof0.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}\ not found.
File F:\Program Files\Softonic_Deutsch\prxtbSof0.dll not found.
Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}\ not found.
File F:\Program Files\Softonic_Deutsch\prxtbSof0.dll not found.
Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE5D279F-081B-4404-994D-C6B60AAEBA6D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE5D279F-081B-4404-994D-C6B60AAEBA6D}\ deleted successfully.
File To-Page\EPSON Web-To-Page.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Ocs_SM deleted successfully.
F:\Users\Ingmar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe moved successfully.
Registry value HKEY_USERS\Ingmar_ON_F\Software\Microsoft\Windows\CurrentVersion\Run\\wnzhztlwwvwoahc deleted successfully.
F:\ProgramData\wnzhztlw.exe moved successfully.
Registry value HKEY_USERS\LocalService_ON_F\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
F:\Windows\System32\mctadmin.exe moved successfully.
Registry value HKEY_USERS\NetworkService_ON_F\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
File F:\Windows\System32\mctadmin.exe not found.
F:\Users\Ingmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLinkedConnections deleted successfully.
Registry value HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\Ingmar_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\LocalService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\NetworkService_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_USERS\systemprofile_ON_F\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
F:\autoexec.bat moved successfully.
File move failed. X:\AUTORUN.INF scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303f57f4-ebf0-11df-a0c3-1caff7117e83}\ not found.
File H:\USBAutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4526cb3c-e4b1-11de-a29b-806e6f6e6963}\ not found.
File E:\AUTORUN.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56e0a404-bb5b-11df-8bf7-001693000472}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56e0a404-bb5b-11df-8bf7-001693000472}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56e0a404-bb5b-11df-8bf7-001693000472}\ not found.
File E:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found.
File D:\AUTORUN.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.
F:\Windows\System32\ConduitEngine.tmp deleted successfully.
File F:\ProgramData\wnzhztlw.exe not found.
F:\ProgramData\Babylon folder moved successfully.
F:\Program Files\Common Files\AskToolbarInstaller.exe moved successfully.
F:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
F:\Windows\System32\ANIWZCSUSERNAME moved successfully.
F:\ProgramData\jqfnlczewmpbtxp folder moved successfully.
F:\ProgramData\mijgefhjgbuamsf moved successfully.
F:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
F:\ProgramData\0tbpw.pad moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
An internal error occurred: The system cannot find the file specified.

Please contact Microsoft Product Support Services for further help.
Additional information: Unable to open registry key for tcpip.
F:\cmd.bat deleted successfully.
F:\cmd.txt deleted successfully.
========== COMMANDS ==========


User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56504 bytes

User: Default User

User: Ingmar
->Temp folder emptied: 1627344 bytes
->Temporary Internet Files folder emptied: 61910994 bytes
->Java cache emptied: 1253300 bytes
->FireFox cache emptied: 662365457 bytes
->Google Chrome cache emptied: 29693417 bytes
->Flash cache emptied: 2893532 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 67319 bytes

Total Files Cleaned = 725.00 mb

OTLPE by OldTimer - Version log created on 08142012_210311

Alt 14.08.2012, 11:33   #4
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Sehr gut!

1. Schritt
Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktualisiere die Datenbank!
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".

2. Schritt

Downloade Dir bitte AdwCleaner auf deinen Desktop.

  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.
Mfg, t'john
Das TB unterstützen

Alt 14.08.2012, 14:42   #5
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt


mit Malwarebytes Anti-Malware den Rechner überprüft (vorher neues Update geladen).

3 Bedrohungen sind gefunden worden und anschließend gelöscht.

Danach den AdwCleaner geladen und ausgeführt.

Ich lass den Rechner jetzt so laufen und warte auf neue Instruktionen.

Es folgen die beiden .tex Dateien von Alwarebytes und AdwCleaner:

Hier Malwarebytes Anti-Malware:

Malwarebytes Anti-Malware

Datenbank Version: v2012.08.14.02

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Ingmar :: INGMAR-PC [Administrator]

14.08.2012 12:52:38
mbam-log-2012-08-14 (15-12-20).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 405887
Laufzeit: 53 Minute(n), 38 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Keine Aktion durchgeführt.
C:\_OTL\MovedFiles\08142012_210311\F_ProgramData\wnzhztlw.exe (Trojan.Ransom) -> Keine Aktion durchgeführt.
C:\Users\Ingmar\ms.exe (Trojan.Ransom) -> Keine Aktion durchgeführt.


Hier AdwCleaner:

# AdwCleaner v1.801 - Logfile created 08/14/2012 at 15:31:02
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate (32 bits)
# User : Ingmar - INGMAR-PC
# Boot Mode : Normal
# Running from : C:\Users\Ingmar\Desktop\adwcleaner.exe
# Option [Search]

***** [Services] *****

***** [Files / Folders] *****

Folder Found : C:\Users\Ingmar\AppData\Local\Babylon
Folder Found : C:\Users\Ingmar\AppData\Local\Conduit
Folder Found : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk
Folder Found : C:\Users\Ingmar\AppData\LocalLow\BabylonToolbar
Folder Found : C:\Users\Ingmar\AppData\LocalLow\Conduit
Folder Found : C:\Users\Ingmar\AppData\LocalLow\ConduitEngine
Folder Found : C:\Users\Ingmar\AppData\LocalLow\PriceGong
Folder Found : C:\Users\Ingmar\AppData\LocalLow\Softonic_Deutsch
Folder Found : C:\Users\Ingmar\AppData\Roaming\Babylon
Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\Conduit
Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\ConduitEngine
Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\CT1351351
Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}
Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
Folder Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\engine@conduit.com
Folder Found : C:\Program Files\AutocompletePro
Folder Found : C:\Program Files\BabylonToolbar
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\ConduitEngine
Folder Found : C:\Program Files\Softonic_Deutsch
File Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Askcom.xml
File Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Conduit.xml
File Found : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\SweetIm.xml
File Found : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1351351
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\AutocompletePro
Key Found : HKCU\Software\AutocompleteProBHO
Key Found : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Found : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\conduitEngine
Key Found : HKLM\SOFTWARE\conduitEngine
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro3_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_Deutsch Toolbar
Key Found : HKLM\SOFTWARE\Softonic_Deutsch

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7A732C9-B723-41BF-AF97-8C15E35697B7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF58A471-4933-4904-AA5C-54F1DC0B2EFA}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79E5FE6A-EBEE-4979-94EA-E914A52136C3}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : default
File : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\prefs.js

Found : user_pref("CT1351351.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT1351351.CTID", "CT1351351");
Found : user_pref("CT1351351.DialogsAlignMode", "LTR");
Found : user_pref("CT1351351.EMailNotifierPollDate", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedLastCount4950394486774855536", 480);
Found : user_pref("CT1351351.FeedPollDate129255010870695542", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870695548", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870695554", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870695560", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870695566", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851822", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851828", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851834", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851840", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851846", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851852", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851858", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851864", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851870", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851876", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851882", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851888", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851894", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851900", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851906", "Wed Nov 17 2010 16:32:17 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851912", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851918", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851924", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851930", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851936", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.FeedPollDate129255010870851942", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.FeedTTL129255010870695554", 5);
Found : user_pref("CT1351351.FeedTTL129255010870695560", 5);
Found : user_pref("CT1351351.FeedTTL129255010870851840", 2);
Found : user_pref("CT1351351.FeedTTL129255010870851870", 5);
Found : user_pref("CT1351351.FeedTTL129255010870851882", 30);
Found : user_pref("CT1351351.FirstTime", true);
Found : user_pref("CT1351351.FirstTimeFF3", true);
Found : user_pref("CT1351351.FixPageNotFoundErrors", true);
Found : user_pref("CT1351351.GroupingServerCheckInterval", 1440);
Found : user_pref("CT1351351.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT1351351.Initialize", true);
Found : user_pref("CT1351351.InitializeCommonPrefs", true);
Found : user_pref("CT1351351.InstalledDate", "Wed Nov 17 2010 16:32:15 GMT+0100");
Found : user_pref("CT1351351.InvalidateCache", false);
Found : user_pref("CT1351351.IsGrouping", false);
Found : user_pref("CT1351351.IsMulticommunity", false);
Found : user_pref("CT1351351.IsOpenThankYouPage", true);
Found : user_pref("CT1351351.IsOpenUninstallPage", true);
Found : user_pref("CT1351351.LanguagePackLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100");
Found : user_pref("CT1351351.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT1351351.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT1351351.LastLogin_2.4.0.4", "Wed Nov 17 2010 16:33:06 GMT+0100");
Found : user_pref("CT1351351.LatestVersion", "");
Found : user_pref("CT1351351.Locale", "de-de");
Found : user_pref("CT1351351.LoginCache", 4);
Found : user_pref("CT1351351.MCDetectTooltipHeight", "83");
Found : user_pref("CT1351351.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT1351351.MCDetectTooltipWidth", "295");
Found : user_pref("CT1351351.RadioIsPodcast", false);
Found : user_pref("CT1351351.RadioLastCheckTime", "Wed Nov 17 2010 16:32:16 GMT+0100");
Found : user_pref("CT1351351.RadioLastUpdateIPServer", "3");
Found : user_pref("CT1351351.RadioLastUpdateServer", "128929877726170000");
Found : user_pref("CT1351351.RadioMediaID", "10531746");
Found : user_pref("CT1351351.RadioMediaType", "Media Player");
Found : user_pref("CT1351351.RadioMenuSelectedID", "EBRadioMenu_CT135135110531746");
Found : user_pref("CT1351351.RadioStationName", "Antenne%20Bayern%20Top%2040");
Found : user_pref("CT1351351.RadioStationURL", "hxxp://channels.webradio.antenne.de/top-40");
Found : user_pref("CT1351351.SHRINK_TOOLBAR", 1);
Found : user_pref("CT1351351.SearchEngine", "Websuche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_T[...]
Found : user_pref("CT1351351.SearchFromAddressBarIsInit", true);
Found : user_pref("CT1351351.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT135[...]
Found : user_pref("CT1351351.SearchInNewTabEnabled", true);
Found : user_pref("CT1351351.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT1351351.SearchInNewTabLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100");
Found : user_pref("CT1351351.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT1351351.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT1351351.SettingsCheckIntervalMin", 120);
Found : user_pref("CT1351351.SettingsLastCheckTime", "Wed Nov 17 2010 16:32:10 GMT+0100");
Found : user_pref("CT1351351.SettingsLastUpdate", "1289939422");
Found : user_pref("CT1351351.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT1351351.ThirdPartyComponentsLastCheck", "Wed Nov 17 2010 16:32:10 GMT+0100");
Found : user_pref("CT1351351.ThirdPartyComponentsLastUpdate", "1255348257");
Found : user_pref("CT1351351.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Found : user_pref("CT1351351.UserID", "UN33001363855390975");
Found : user_pref("CT1351351.ValidationData_Toolbar", 2);
Found : user_pref("CT1351351.WeatherNetwork", "");
Found : user_pref("CT1351351.WeatherPollDate", "Wed Nov 17 2010 16:32:18 GMT+0100");
Found : user_pref("CT1351351.WeatherUnit", "C");
Found : user_pref("CT1351351.alertChannelId", "669");
Found : user_pref("CT1351351.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E");
Found : user_pref("CT1351351.clientLogIsEnabled", false);
Found : user_pref("CT1351351.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT1351351.myStuffEnabled", true);
Found : user_pref("CT1351351.myStuffPublihserMinWidth", 400);
Found : user_pref("CT1351351.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT1351351.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT1351351.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT1351351.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Found : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Found : user_pref("CommunityToolbar.IsEngineShown", true);
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT1351351,ConduitEngine");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT1351351");
Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Jun 05 2011 11:00:47 GMT+02[...]
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Jul 03 2011 11:58:05 GMT+0200");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jul 06 2011 17:34:35 GMT+0200");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "4bbe4652-9509-4515-b7de-abe86693c26f");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1351351");
Found : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sun Jul 03 2011 11:58:07 GMT+0200");
Found : user_pref("ConduitEngine.CTID", "ConduitEngine");
Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Jul 06 2011 11:57:55 GMT+0200");
Found : user_pref("ConduitEngine.FirstServerDate", "06/05/2011 12");
Found : user_pref("ConduitEngine.FirstTime", true);
Found : user_pref("ConduitEngine.FirstTimeFF3", true);
Found : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Found : user_pref("ConduitEngine.Initialize", true);
Found : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Found : user_pref("ConduitEngine.InstalledDate", "Sun Jun 05 2011 11:00:51 GMT+0200");
Found : user_pref("ConduitEngine.IsMulticommunity", false);
Found : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Found : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jul 06 2011 17:34:42 GMT+0200");
Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jul 06 2011 14:42:01 GMT+0200");
Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jul 06 2011 14:42:01 GMT+0200");
Found : user_pref("ConduitEngine.UserID", "UN52334012069164096");
Found : user_pref("ConduitEngine.componentAlertEnabled", false);
Found : user_pref("ConduitEngine.engineLocale", "de");
Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jul 06 2011 17:34:41 GMT+0200");
Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jul 06 2011 16:42:03 GMT+0200");
Found : user_pref("ConduitEngine.initDone", true);
Found : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Found : user_pref("ConduitEngine.usagesFlag", 1);

-\\ Google Chrome v21.0.1180.77

File : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found : "description": "AutocompletePro - Speed up your search with your personal search sugg[...]
Found : "name": "AutocompletePro plugin for chrome",


AdwCleaner[R1].txt - [19063 octets] - [14/08/2012 15:31:02]

########## EOF - C:\AdwCleaner[R1].txt - [19192 octets] ##########

Alt 14.08.2012, 15:11   #6
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Sehr gut!

  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.


Malware-Scan mit Emsisoft Anti-Malware

Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm.
Lade über Jetzt Updaten die aktuellen Signaturen herunter.
Wähle den Freeware-Modus aus.

Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers.
Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten.

Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
--> BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Alt 14.08.2012, 15:31   #7
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt


Rechner mit adwcleaner.exe gescannt und Delite ausgeführt.
Unten folgt die Textdatei welche bei Neustart sich öffnete.

Emsisoft Anti-Malware konnte ich runterladen aber nicht installieren.

Fehlermeldung: "Für den Betrieb auf Windows 7 oder Windowsserver 2008
R2 ist das Service Pack 1 erforderlich"

Was nun?
Ich habe das Programm SUPERAntiSpyware 5.5.1012. Nützt das ggf. etwas?

Hier erstmal die Textdatei nach dem Neustart:

# AdwCleaner v1.801 - Logfile created 08/14/2012 at 16:16:00
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate (32 bits)
# User : Ingmar - INGMAR-PC
# Boot Mode : Normal
# Running from : C:\Users\Ingmar\Desktop\adwcleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

Folder Deleted : C:\Users\Ingmar\AppData\Local\Babylon
Folder Deleted : C:\Users\Ingmar\AppData\Local\Conduit
Folder Deleted : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk
Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Ingmar\AppData\LocalLow\Softonic_Deutsch
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\Conduit
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\ConduitEngine
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\CT1351351
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{8dbb6d8e-e4a6-4e3b-9753-af78b226441c}
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
Folder Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\extensions\engine@conduit.com
Folder Deleted : C:\Program Files\AutocompletePro
Folder Deleted : C:\Program Files\BabylonToolbar
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\ConduitEngine
Folder Deleted : C:\Program Files\Softonic_Deutsch
File Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\searchplugins\SweetIm.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1351351
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AutocompletePro
Key Deleted : HKCU\Software\AutocompleteProBHO
Key Deleted : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\conduitEngine
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro3_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_Deutsch Toolbar
Key Deleted : HKLM\SOFTWARE\Softonic_Deutsch

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6E4C89CF-3061-4EE4-B22A-B7A8AAEA5CB3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7A732C9-B723-41BF-AF97-8C15E35697B7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF58A471-4933-4904-AA5C-54F1DC0B2EFA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79E5FE6A-EBEE-4979-94EA-E914A52136C3}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ADB41EA7-CC3A-4EB7-806B-073AD7ED8EED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : default
File : C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\prefs.js

C:\Users\Ingmar\AppData\Roaming\Mozilla\Firefox\Profiles\jihk27mr.default\user.js ... Deleted !

Deleted : user_pref("CT1351351.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT1351351.CTID", "CT1351351");
Deleted : user_pref("CT1351351.DialogsAlignMode", "LTR");
Deleted : user_pref("CT1351351.EMailNotifierPollDate", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedLastCount4950394486774855536", 480);
Deleted : user_pref("CT1351351.FeedPollDate129255010870695542", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870695548", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870695554", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870695560", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870695566", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851822", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851828", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851834", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851840", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851846", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851852", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851858", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851864", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851870", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851876", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851882", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851888", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851894", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851900", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851906", "Wed Nov 17 2010 16:32:17 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851912", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851918", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851924", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851930", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851936", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.FeedPollDate129255010870851942", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.FeedTTL129255010870695554", 5);
Deleted : user_pref("CT1351351.FeedTTL129255010870695560", 5);
Deleted : user_pref("CT1351351.FeedTTL129255010870851840", 2);
Deleted : user_pref("CT1351351.FeedTTL129255010870851870", 5);
Deleted : user_pref("CT1351351.FeedTTL129255010870851882", 30);
Deleted : user_pref("CT1351351.FirstTime", true);
Deleted : user_pref("CT1351351.FirstTimeFF3", true);
Deleted : user_pref("CT1351351.FixPageNotFoundErrors", true);
Deleted : user_pref("CT1351351.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT1351351.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT1351351.Initialize", true);
Deleted : user_pref("CT1351351.InitializeCommonPrefs", true);
Deleted : user_pref("CT1351351.InstalledDate", "Wed Nov 17 2010 16:32:15 GMT+0100");
Deleted : user_pref("CT1351351.InvalidateCache", false);
Deleted : user_pref("CT1351351.IsGrouping", false);
Deleted : user_pref("CT1351351.IsMulticommunity", false);
Deleted : user_pref("CT1351351.IsOpenThankYouPage", true);
Deleted : user_pref("CT1351351.IsOpenUninstallPage", true);
Deleted : user_pref("CT1351351.LanguagePackLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100");
Deleted : user_pref("CT1351351.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT1351351.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT1351351.LastLogin_2.4.0.4", "Wed Nov 17 2010 16:33:06 GMT+0100");
Deleted : user_pref("CT1351351.LatestVersion", "");
Deleted : user_pref("CT1351351.Locale", "de-de");
Deleted : user_pref("CT1351351.LoginCache", 4);
Deleted : user_pref("CT1351351.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT1351351.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT1351351.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT1351351.RadioIsPodcast", false);
Deleted : user_pref("CT1351351.RadioLastCheckTime", "Wed Nov 17 2010 16:32:16 GMT+0100");
Deleted : user_pref("CT1351351.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT1351351.RadioLastUpdateServer", "128929877726170000");
Deleted : user_pref("CT1351351.RadioMediaID", "10531746");
Deleted : user_pref("CT1351351.RadioMediaType", "Media Player");
Deleted : user_pref("CT1351351.RadioMenuSelectedID", "EBRadioMenu_CT135135110531746");
Deleted : user_pref("CT1351351.RadioStationName", "Antenne%20Bayern%20Top%2040");
Deleted : user_pref("CT1351351.RadioStationURL", "hxxp://channels.webradio.antenne.de/top-40");
Deleted : user_pref("CT1351351.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT1351351.SearchEngine", "Websuche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_T[...]
Deleted : user_pref("CT1351351.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT1351351.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT135[...]
Deleted : user_pref("CT1351351.SearchInNewTabEnabled", true);
Deleted : user_pref("CT1351351.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT1351351.SearchInNewTabLastCheckTime", "Wed Nov 17 2010 16:33:06 GMT+0100");
Deleted : user_pref("CT1351351.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT1351351.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT1351351.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT1351351.SettingsLastCheckTime", "Wed Nov 17 2010 16:32:10 GMT+0100");
Deleted : user_pref("CT1351351.SettingsLastUpdate", "1289939422");
Deleted : user_pref("CT1351351.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT1351351.ThirdPartyComponentsLastCheck", "Wed Nov 17 2010 16:32:10 GMT+0100");
Deleted : user_pref("CT1351351.ThirdPartyComponentsLastUpdate", "1255348257");
Deleted : user_pref("CT1351351.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT1351351.UserID", "UN33001363855390975");
Deleted : user_pref("CT1351351.ValidationData_Toolbar", 2);
Deleted : user_pref("CT1351351.WeatherNetwork", "");
Deleted : user_pref("CT1351351.WeatherPollDate", "Wed Nov 17 2010 16:32:18 GMT+0100");
Deleted : user_pref("CT1351351.WeatherUnit", "C");
Deleted : user_pref("CT1351351.alertChannelId", "669");
Deleted : user_pref("CT1351351.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E");
Deleted : user_pref("CT1351351.clientLogIsEnabled", false);
Deleted : user_pref("CT1351351.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT1351351.myStuffEnabled", true);
Deleted : user_pref("CT1351351.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT1351351.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT1351351.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT1351351.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT1351351.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT1351351,ConduitEngine");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT1351351");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Jun 05 2011 11:00:47 GMT+02[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Jul 03 2011 11:58:05 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jul 06 2011 17:34:35 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "4bbe4652-9509-4515-b7de-abe86693c26f");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT1351351");
Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sun Jul 03 2011 11:58:07 GMT+0200");
Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Jul 06 2011 11:57:55 GMT+0200");
Deleted : user_pref("ConduitEngine.FirstServerDate", "06/05/2011 12");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstalledDate", "Sun Jun 05 2011 11:00:51 GMT+0200");
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jul 06 2011 17:34:42 GMT+0200");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jul 06 2011 14:42:01 GMT+0200");
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jul 06 2011 14:42:01 GMT+0200");
Deleted : user_pref("ConduitEngine.UserID", "UN52334012069164096");
Deleted : user_pref("ConduitEngine.componentAlertEnabled", false);
Deleted : user_pref("ConduitEngine.engineLocale", "de");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jul 06 2011 17:34:41 GMT+0200");
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jul 06 2011 16:42:03 GMT+0200");
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("ConduitEngine.usagesFlag", 1);

-\\ Google Chrome v21.0.1180.77

File : C:\Users\Ingmar\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "AutocompletePro - Speed up your search with your personal search sugg[...]
Deleted : "name": "AutocompletePro plugin for chrome",


AdwCleaner[R1].txt - [19194 octets] - [14/08/2012 15:31:02]
AdwCleaner[R2].txt - [19255 octets] - [14/08/2012 16:15:47]
AdwCleaner[S1].txt - [19687 octets] - [14/08/2012 16:16:00]

########## EOF - C:\AdwCleaner[S1].txt - [19816 octets] ##########

Alt 14.08.2012, 15:39   #8
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Alle Updates, inkl SP1 einspielen!
Mfg, t'john
Das TB unterstützen

Alt 14.08.2012, 20:34   #9
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt


ich habe mehrfach versucht Windows Updates bzw. das Sp1 runterzuladen.
Leider vergebens, es liegt wohl an meiner lahmen Internetverbindung. Bei größeren
Datein bricht diese anscheinend den Download ab...

Wie sieht es aus, wenn ich eine neue Windows Version installiere, wären dann auch
alle Schädlinge vernichtet, da die Festplatte formatiert wird?
Bzw. habe ich noch eine Acronis Image von dem Rechner als dieser neu war. Wenn ich
die wieder Installiere, werden die Schädlinge dann vernichtet? Auch da wird ja die
Festplatte formatiert?

Für einen Tip wäre ich dankbar.

Gruß Ingmar

Alt 15.08.2012, 09:09   #10
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Ja, das waeren sie.

Aber wenn du dein Rechner nicht aktuell haelst wird du dieses Problem (oder ein groesseres) sofort wieder haben!
Mfg, t'john
Das TB unterstützen

Alt 15.08.2012, 09:19   #11
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt


aktuell halten, bedeutet das, das ich immer alle Windows Updates machen soll bzw. alle verfügbaren Sp`s installiere?
Welches Antivirenprogramm ist das beste? Ich hatte bislang das von AVG Free Edition, aber das scheint ja nicht so gut zu sein.

Gruß Ingmar

Alt 15.08.2012, 10:51   #12
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

aktuell halten, bedeutet das, das ich immer alle Windows Updates machen soll bzw. alle verfügbaren Sp`s installiere?
Ja, und zwar immer sofort.

Welches Antivirenprogramm ist das beste? Ich hatte bislang das von AVG Free Edition, aber das scheint ja nicht so gut zu sein.
Alle die Hilfe suchen haben einen Virenscanner.
Es nützt nichts.
Mfg, t'john
Das TB unterstützen

Alt 28.09.2012, 10:54   #13
/// Helfer-Team
BKA/GVU Trojaner  wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt - Standard

BKA/GVU Trojaner wird trotz Kaspersky-RescueDisc 2010 leider nicht entfernt

Fehlende Rückmeldung

Gibt es Probleme beim Abarbeiten obiger Anleitung?

Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen.

Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist.
Mfg, t'john
Das TB unterstützen


