|
Plagegeister aller Art und deren Bekämpfung: GVU Trojaner - Laptop gesperrtWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.08.2012, 18:39 | #1 |
| GVU Trojaner - Laptop gesperrt hallo, habe eben den GVU trojaner eingefangen. leider will mein laptop ihn nicht mehr freilassen... was kann ich tun? denn auch im abgesicherten modus (mit und ohne netzwerk) kommt die sperrseite.... |
14.08.2012, 19:02 | #2 |
/// Malware-holic | GVU Trojaner - Laptop gesperrt hi
__________________starte neu, drücke f8 wähle abgesicherter modus mit netzwerk, melde dich in deinem konto an. Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
14.08.2012, 20:54 | #3 |
| GVU Trojaner - Laptop gesperrt danke für die schnelle antwort! das problem ist, auch im abgesicherten modus kommt die gvu seite, sodass ich nicht auf den desktop zugreifen kann...
__________________so, habe nun mit otlpenet eine cd erstellt und damit einen scan laufen lassen. allerdings ohne den oben von dir angegebenen inhalt in die textbox zu kopieren. soll ich noch einen scan damit durchführen? hier die otl.txt: Code:
ATTFilter OTL logfile created on: 8/15/2012 7:20:52 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 296.62 Gb Total Space | 138.99 Gb Free Space | 46.86% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand] -- -- (SPTISRV) SRV - File not found [On_Demand] -- -- (MSCSPTISRV) SRV - File not found [Auto] -- -- (0268391304585483mcinstcleanup) SRV - [2012/01/20 07:42:40 | 000,329,168 | ---- | M] () [Auto] -- C:\Program Files\Verbindungsassistent\WTGService.exe -- (WTGService) SRV - [2011/08/03 16:43:45 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/04/20 04:50:46 | 000,792,976 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent) SRV - [2011/03/09 08:30:08 | 000,092,592 | ---- | M] (TomTom) [Disabled] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2009/09/08 12:09:14 | 000,083,312 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper) SRV - [2009/04/01 18:15:30 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR) SRV - [2008/03/03 08:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr) SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/08/14 15:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service) SRV - [2007/05/31 04:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007/05/31 04:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (VMnetAdapter) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand] -- -- (IpInIp) DRV - File not found [Kernel | On_Demand] -- -- (igfx) DRV - File not found [Kernel | On_Demand] -- -- (catchme) DRV - File not found [File_System | System] -- -- (AFSRedirector) DRV - File not found [File_System | On_Demand] -- -- (AFSLibrary) DRV - [2012/07/10 15:07:43 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2012/01/20 07:39:33 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake) DRV - [2012/01/20 07:39:33 | 000,100,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewsercd.sys -- (ewsercd) DRV - [2011/08/03 16:27:28 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva) DRV - [2011/07/29 07:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv) DRV - [2011/07/29 07:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv) DRV - [2009/04/11 01:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan) DRV - [2009/04/11 00:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB) DRV - [2008/12/13 06:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2008/02/22 20:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2008/02/11 20:49:44 | 007,626,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2008/02/05 20:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2008/01/20 22:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV - [2008/01/20 22:23:21 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\loop.sys -- (msloop) DRV - [2007/12/16 21:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP) DRV - [2007/12/14 00:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2007/12/13 12:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall) DRV - [2007/09/18 23:29:09 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R) DRV - [2007/06/05 20:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony) DRV - [2007/05/26 04:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2004/02/04 02:19:32 | 000,024,177 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2004/02/04 02:19:16 | 000,057,372 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes] IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.club-vaio.com/vbc IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/07 18:09:46 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/28 11:06:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/05/28 11:06:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions [2010/07/05 16:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010/07/29 11:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com [2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\uploadr@flickr.com [2012/08/13 06:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions [2010/07/07 17:45:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011/10/29 15:52:00 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011/02/11 17:16:51 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906} [2012/07/28 01:39:41 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2012/08/08 18:16:15 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\FoxdieGraphite@tanjihay.com [2012/03/20 11:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions File not found (No name found) -- () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\CSSEDITOR@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\EYEDROPPER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FS@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FULLSCREEN@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\GFD@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-CS@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-DE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-EN-US@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ES-ES@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FI@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FR@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HU@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-IT@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-JA@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-KO@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-NL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-PL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SR@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SV-SE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-CN@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-TW@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\MATHML@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SNIPPETS@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SVG-EDIT@GOOGLEGROUPS.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TABLELAYOUT@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TEMPLATESMANAGER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\THUMBNAILER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TIPOFTHEDAY@BLUEGRIFFON.COM.XPI [2012/08/07 18:09:46 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011/10/03 00:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010/07/12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012/07/02 06:29:39 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/07/02 06:29:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/07/02 06:29:39 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012/07/02 06:29:39 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/02 06:29:39 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/02 06:29:39 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012/08/08 14:46:11 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google BAE\BAE.dll (Your Company Name) O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found. O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKU\Jonas_ON_C\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Jonas_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Free YouTube Download - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKU\Jonas_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKU\Jonas_ON_C Winlogon: Shell - (C:\Users\Jonas\AppData\Roaming\msconfig.dat) - C:\Users\Jonas\AppData\Roaming\msconfig.dat () O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img30.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img30.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/08/14 12:14:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012/08/13 08:30:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/13 08:08:43 | 000,038,224 | ---- | C] (CANON INC.) -- C:\Windows\System32\IJRMF.exe [2012/08/12 15:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2012/08/12 15:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo [2012/08/08 14:52:55 | 000,000,000 | ---D | C] -- C:\Windows\temp [2012/08/08 14:49:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2012/08/08 14:49:15 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\temp [2012/08/08 14:31:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012/08/08 14:31:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012/08/08 14:31:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2012/08/08 14:31:27 | 000,000,000 | ---D | C] -- C:\Qoobox [2012/08/08 14:31:10 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2012/08/07 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ztgcrqxmyuqrqqg [2012/08/03 17:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Snappy Fax Version 5 [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\IrfanView [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2012/07/28 19:09:10 | 002,369,456 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.CommandBars.v13.4.2.ocx [2012/07/28 19:09:10 | 000,077,504 | ---- | C] (Michael Thummerer Software Design) -- C:\Windows\System32\mtScrollContainer.ocx [2012/07/21 07:27:35 | 000,000,000 | ---D | C] -- C:\DIE_TUSCHS [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/08/15 05:29:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/08/15 05:29:24 | 000,000,045 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini [2012/08/14 13:25:47 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2012/08/14 13:25:19 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012/08/14 12:45:08 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/08/14 12:14:46 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012/08/14 12:14:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012/08/14 12:13:32 | 000,629,436 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012/08/14 12:13:32 | 000,596,690 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/08/14 12:13:32 | 000,126,890 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012/08/14 12:13:32 | 000,104,506 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/08/13 11:59:43 | 000,042,496 | ---- | M] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/08/13 11:23:38 | 000,000,746 | -H-- | M] () -- C:\Windows\EPMBatch.ept [2012/08/13 08:30:21 | 000,001,219 | ---- | M] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk [2012/08/13 08:30:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/12 16:02:45 | 000,166,763 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001 [2012/08/12 15:39:04 | 000,001,765 | ---- | M] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk [2012/08/12 15:39:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2012/08/11 03:35:56 | 003,846,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012/08/08 17:26:23 | 000,000,600 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd [2012/08/08 14:46:11 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2012/07/31 18:06:36 | 000,001,687 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk [2012/07/31 18:06:36 | 000,000,807 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView.lnk [2012/07/28 01:32:30 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012/07/28 01:32:30 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/08/14 13:16:31 | 000,000,045 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini [2012/08/14 12:14:46 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012/08/13 08:30:21 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe [2012/08/13 08:30:21 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll [2012/08/13 08:30:21 | 000,001,219 | ---- | C] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk [2012/08/13 08:30:20 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe [2012/08/13 08:30:20 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys [2012/08/13 08:30:20 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys [2012/08/12 15:39:04 | 000,001,765 | ---- | C] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk [2012/08/08 14:31:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012/08/08 14:31:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012/08/08 14:31:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012/08/08 14:31:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012/08/08 14:31:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012/07/31 18:06:36 | 000,001,687 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk [2012/07/31 18:06:36 | 000,000,807 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView.lnk [2012/06/29 11:15:27 | 000,000,600 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd [2012/06/13 11:33:54 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI [2012/05/15 09:33:02 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2012/02/11 20:01:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat [2012/02/11 15:23:07 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2012/02/11 15:23:00 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012/02/11 15:22:49 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2012/02/09 16:15:58 | 000,006,854 | RHS- | C] () -- C:\Windows\innova3.ini [2012/01/31 14:37:33 | 000,000,196 | ---- | C] () -- C:\Windows\System32\ftdiun2k.ini [2012/01/15 08:31:23 | 000,099,328 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.dat [2011/08/23 07:34:38 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI [2011/08/23 07:34:36 | 000,000,772 | ---- | C] () -- C:\Windows\ODBCINST.INI [2011/08/10 01:18:00 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{72A5C72A-484F-44E4-A570-0EB5D6ED0F18} [2011/08/10 01:07:04 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{80EA586A-7A9E-4E80-A54B-C062188EA15D} [2011/06/30 06:38:21 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll [2011/06/30 06:38:20 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/06/30 06:38:14 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2011/04/13 11:40:47 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2011/04/13 11:40:06 | 000,006,360 | ---- | C] () -- C:\Windows\mgxoschk.ini [2011/02/11 17:15:33 | 000,015,873 | ---- | C] () -- C:\Windows\System32\Inetde.dll [2010/12/17 04:01:47 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI [2010/12/02 07:51:55 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe [2010/11/10 10:45:30 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010/11/06 05:17:15 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2010/09/30 04:20:58 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010/09/30 04:20:58 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010/08/18 16:24:04 | 000,002,738 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp DirectShow Decoder.dat [2010/08/18 16:14:48 | 000,229,752 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe [2010/08/18 16:14:48 | 000,015,341 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat [2010/07/17 11:12:48 | 000,330,240 | ---- | C] () -- C:\Windows\PICSUninstall.exe [2010/07/13 08:19:52 | 000,042,496 | ---- | C] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/07/08 08:07:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010/07/08 08:07:32 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010/07/05 17:19:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2010/07/05 13:08:29 | 000,001,356 | ---- | C] () -- C:\Users\Jonas\AppData\Local\d3d9caps.dat [2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.dat [2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001 [2010/07/05 12:49:09 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI [2008/08/05 02:07:20 | 000,065,216 | ---- | C] () -- C:\Windows\System32\PDFreDirectMonNT.dll [2008/02/04 20:09:01 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1295.dll [2008/01/21 03:15:58 | 000,629,436 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008/01/21 03:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008/01/21 03:15:58 | 000,126,890 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008/01/21 03:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2007/09/11 19:57:44 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll [2007/09/11 19:54:26 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll [2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 08:47:37 | 003,846,408 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 06:33:01 | 000,596,690 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 06:33:01 | 000,104,506 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat ========== LOP Check ========== [2010/11/11 10:24:11 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\.purple [2012/07/30 18:11:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\AllDup [2011/11/26 18:52:17 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Audacity [2011/04/15 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Azureus [2011/07/13 05:46:46 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Blender Foundation [2011/03/16 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\BOM [2010/07/15 16:07:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Canon [2011/05/05 05:22:48 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2010/07/17 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Crossword Compiler Deutsch 8 [2012/07/26 04:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite [2010/12/02 19:26:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DataCast [2010/08/18 16:24:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\dBpoweramp [2012/06/25 16:16:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Disruptive Innovations SARL [2012/08/09 06:35:58 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Dropbox [2012/03/19 02:34:06 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoft [2011/04/04 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers [2010/11/18 08:12:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Flickr [2010/11/26 05:58:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Free Sound Recorder [2011/01/19 05:14:41 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\GetRightToGo [2010/07/15 13:45:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Gutscheinmieze [2011/09/29 16:22:59 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\HandBrake [2011/10/19 18:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ImgBurn [2012/02/09 16:15:54 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\innoplus [2010/09/25 17:23:24 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\InterVideo [2012/07/31 18:06:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\IrfanView [2012/04/04 06:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\kompozer.net [2010/09/29 14:23:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Leadertech [2011/04/28 04:53:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\MAGIX [2010/09/29 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OOo-dev [2010/07/28 07:22:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OpenOffice.org [2010/08/17 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PDF reDirect [2010/07/15 17:17:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoFiltre [2010/12/09 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoScape [2010/07/17 11:13:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\pics [2012/07/21 08:00:40 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\RipIt4Me [2010/07/05 16:00:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Thunderbird [2010/07/29 11:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TomTom [2011/04/30 11:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TP [2011/10/24 15:28:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\uTorrent [2012/01/21 02:58:52 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Verbindungsassistent [2011/06/30 06:42:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Video DVD Maker FREE [2011/03/09 12:33:05 | 000,000,000 | ---D | M] -- C:\ProgramData\AllDup [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2010/07/15 15:38:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ [2010/07/17 09:35:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJEGV [2010/07/15 16:07:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan [2012/06/29 11:56:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco [2012/07/10 15:21:26 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2011/02/12 13:20:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Eltima Software [2012/04/14 17:40:47 | 000,000,000 | ---D | M] -- C:\ProgramData\F4D55F3E00016D2B000B49DB570F1C8B [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2010/09/11 17:45:30 | 000,000,000 | ---D | M] -- C:\ProgramData\ifolor [2012/02/09 16:15:57 | 000,000,000 | ---D | M] -- C:\ProgramData\innoplus [2012/01/29 08:32:35 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX [2010/07/15 15:10:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Phase6 [2010/07/17 11:13:34 | 000,000,000 | ---D | M] -- C:\ProgramData\pics [2011/08/27 10:18:04 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe [2010/07/05 12:39:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2010/12/17 04:10:35 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP [2006/11/02 09:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2010/07/29 12:02:08 | 000,000,000 | ---D | M] -- C:\ProgramData\TomTom [2010/07/05 12:44:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2011/03/27 16:05:14 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch [2012/08/07 12:56:37 | 000,000,000 | ---D | M] -- C:\ProgramData\ztgcrqxmyuqrqqg [2010/07/05 12:30:27 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3} [2011/03/18 18:25:39 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2012/08/14 13:25:47 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > hier die otl.txt: Code:
ATTFilter OTL logfile created on: 8/15/2012 7:20:52 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 296.62 Gb Total Space | 138.99 Gb Free Space | 46.86% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand] -- -- (SPTISRV) SRV - File not found [On_Demand] -- -- (MSCSPTISRV) SRV - File not found [Auto] -- -- (0268391304585483mcinstcleanup) SRV - [2012/01/20 07:42:40 | 000,329,168 | ---- | M] () [Auto] -- C:\Program Files\Verbindungsassistent\WTGService.exe -- (WTGService) SRV - [2011/08/03 16:43:45 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/04/20 04:50:46 | 000,792,976 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent) SRV - [2011/03/09 08:30:08 | 000,092,592 | ---- | M] (TomTom) [Disabled] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2009/09/08 12:09:14 | 000,083,312 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper) SRV - [2009/04/01 18:15:30 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR) SRV - [2008/03/03 08:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr) SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/08/14 15:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service) SRV - [2007/05/31 04:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007/05/31 04:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (VMnetAdapter) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand] -- -- (IpInIp) DRV - File not found [Kernel | On_Demand] -- -- (igfx) DRV - File not found [Kernel | On_Demand] -- -- (catchme) DRV - File not found [File_System | System] -- -- (AFSRedirector) DRV - File not found [File_System | On_Demand] -- -- (AFSLibrary) DRV - [2012/07/10 15:07:43 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2012/01/20 07:39:33 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake) DRV - [2012/01/20 07:39:33 | 000,100,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewsercd.sys -- (ewsercd) DRV - [2011/08/03 16:27:28 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva) DRV - [2011/07/29 07:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv) DRV - [2011/07/29 07:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv) DRV - [2009/04/11 01:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan) DRV - [2009/04/11 00:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB) DRV - [2008/12/13 06:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2008/02/22 20:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2008/02/11 20:49:44 | 007,626,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2008/02/05 20:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2008/01/20 22:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV - [2008/01/20 22:23:21 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\loop.sys -- (msloop) DRV - [2007/12/16 21:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP) DRV - [2007/12/14 00:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2007/12/13 12:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall) DRV - [2007/09/18 23:29:09 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R) DRV - [2007/06/05 20:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony) DRV - [2007/05/26 04:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2004/02/04 02:19:32 | 000,024,177 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2004/02/04 02:19:16 | 000,057,372 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes] IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.club-vaio.com/vbc IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/07 18:09:46 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/28 11:06:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/05/28 11:06:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions [2010/07/05 16:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010/07/29 11:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com [2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\uploadr@flickr.com [2012/08/13 06:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions [2010/07/07 17:45:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011/10/29 15:52:00 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011/02/11 17:16:51 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906} [2012/07/28 01:39:41 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2012/08/08 18:16:15 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\FoxdieGraphite@tanjihay.com [2012/03/20 11:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions File not found (No name found) -- () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\CSSEDITOR@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\EYEDROPPER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FS@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FULLSCREEN@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\GFD@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-CS@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-DE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-EN-US@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ES-ES@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FI@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FR@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HU@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-IT@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-JA@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-KO@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-NL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-PL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SR@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SV-SE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-CN@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-TW@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\MATHML@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SNIPPETS@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SVG-EDIT@GOOGLEGROUPS.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TABLELAYOUT@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TEMPLATESMANAGER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\THUMBNAILER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TIPOFTHEDAY@BLUEGRIFFON.COM.XPI [2012/08/07 18:09:46 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011/10/03 00:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010/07/12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012/07/02 06:29:39 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/07/02 06:29:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/07/02 06:29:39 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012/07/02 06:29:39 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/02 06:29:39 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/02 06:29:39 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012/08/08 14:46:11 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google BAE\BAE.dll (Your Company Name) O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found. O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKU\Jonas_ON_C\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Jonas_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Free YouTube Download - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKU\Jonas_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKU\Jonas_ON_C Winlogon: Shell - (C:\Users\Jonas\AppData\Roaming\msconfig.dat) - C:\Users\Jonas\AppData\Roaming\msconfig.dat () O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img30.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img30.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/08/14 12:14:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012/08/13 08:30:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/13 08:08:43 | 000,038,224 | ---- | C] (CANON INC.) -- C:\Windows\System32\IJRMF.exe [2012/08/12 15:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2012/08/12 15:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo [2012/08/08 14:52:55 | 000,000,000 | ---D | C] -- C:\Windows\temp [2012/08/08 14:49:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2012/08/08 14:49:15 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\temp [2012/08/08 14:31:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012/08/08 14:31:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012/08/08 14:31:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2012/08/08 14:31:27 | 000,000,000 | ---D | C] -- C:\Qoobox [2012/08/08 14:31:10 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2012/08/07 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ztgcrqxmyuqrqqg [2012/08/03 17:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Snappy Fax Version 5 [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\IrfanView [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [2012/07/28 19:09:10 | 002,369,456 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.CommandBars.v13.4.2.ocx [2012/07/28 19:09:10 | 000,077,504 | ---- | C] (Michael Thummerer Software Design) -- C:\Windows\System32\mtScrollContainer.ocx [2012/07/21 07:27:35 | 000,000,000 | ---D | C] -- C:\DIE_TUSCHS [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/08/15 05:29:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/08/15 05:29:24 | 000,000,045 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini [2012/08/14 13:25:47 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2012/08/14 13:25:19 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012/08/14 12:45:08 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/08/14 12:14:46 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012/08/14 12:14:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012/08/14 12:13:32 | 000,629,436 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012/08/14 12:13:32 | 000,596,690 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/08/14 12:13:32 | 000,126,890 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012/08/14 12:13:32 | 000,104,506 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/08/13 11:59:43 | 000,042,496 | ---- | M] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/08/13 11:23:38 | 000,000,746 | -H-- | M] () -- C:\Windows\EPMBatch.ept [2012/08/13 08:30:21 | 000,001,219 | ---- | M] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk [2012/08/13 08:30:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/12 16:02:45 | 000,166,763 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001 [2012/08/12 15:39:04 | 000,001,765 | ---- | M] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk [2012/08/12 15:39:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2012/08/11 03:35:56 | 003,846,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012/08/08 17:26:23 | 000,000,600 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd [2012/08/08 14:46:11 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2012/07/31 18:06:36 | 000,001,687 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk [2012/07/31 18:06:36 | 000,000,807 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView.lnk [2012/07/28 01:32:30 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012/07/28 01:32:30 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/08/14 13:16:31 | 000,000,045 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini [2012/08/14 12:14:46 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012/08/13 08:30:21 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe [2012/08/13 08:30:21 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll [2012/08/13 08:30:21 | 000,001,219 | ---- | C] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk [2012/08/13 08:30:20 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe [2012/08/13 08:30:20 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys [2012/08/13 08:30:20 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys [2012/08/12 15:39:04 | 000,001,765 | ---- | C] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk [2012/08/08 14:31:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012/08/08 14:31:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012/08/08 14:31:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012/08/08 14:31:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012/08/08 14:31:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012/07/31 18:06:36 | 000,001,687 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk [2012/07/31 18:06:36 | 000,000,807 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView.lnk [2012/06/29 11:15:27 | 000,000,600 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd [2012/06/13 11:33:54 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI [2012/05/15 09:33:02 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2012/02/11 20:01:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat [2012/02/11 15:23:07 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2012/02/11 15:23:00 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012/02/11 15:22:49 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2012/02/09 16:15:58 | 000,006,854 | RHS- | C] () -- C:\Windows\innova3.ini [2012/01/31 14:37:33 | 000,000,196 | ---- | C] () -- C:\Windows\System32\ftdiun2k.ini [2012/01/15 08:31:23 | 000,099,328 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.dat [2011/08/23 07:34:38 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI [2011/08/23 07:34:36 | 000,000,772 | ---- | C] () -- C:\Windows\ODBCINST.INI [2011/08/10 01:18:00 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{72A5C72A-484F-44E4-A570-0EB5D6ED0F18} [2011/08/10 01:07:04 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{80EA586A-7A9E-4E80-A54B-C062188EA15D} [2011/06/30 06:38:21 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll [2011/06/30 06:38:20 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/06/30 06:38:14 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2011/04/13 11:40:47 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2011/04/13 11:40:06 | 000,006,360 | ---- | C] () -- C:\Windows\mgxoschk.ini [2011/02/11 17:15:33 | 000,015,873 | ---- | C] () -- C:\Windows\System32\Inetde.dll [2010/12/17 04:01:47 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI [2010/12/02 07:51:55 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe [2010/11/10 10:45:30 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010/11/06 05:17:15 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2010/09/30 04:20:58 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010/09/30 04:20:58 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010/08/18 16:24:04 | 000,002,738 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp DirectShow Decoder.dat [2010/08/18 16:14:48 | 000,229,752 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe [2010/08/18 16:14:48 | 000,015,341 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat [2010/07/17 11:12:48 | 000,330,240 | ---- | C] () -- C:\Windows\PICSUninstall.exe [2010/07/13 08:19:52 | 000,042,496 | ---- | C] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/07/08 08:07:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010/07/08 08:07:32 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010/07/05 17:19:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2010/07/05 13:08:29 | 000,001,356 | ---- | C] () -- C:\Users\Jonas\AppData\Local\d3d9caps.dat [2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.dat [2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001 [2010/07/05 12:49:09 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI [2008/08/05 02:07:20 | 000,065,216 | ---- | C] () -- C:\Windows\System32\PDFreDirectMonNT.dll [2008/02/04 20:09:01 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1295.dll [2008/01/21 03:15:58 | 000,629,436 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008/01/21 03:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008/01/21 03:15:58 | 000,126,890 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008/01/21 03:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2007/09/11 19:57:44 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll [2007/09/11 19:54:26 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll [2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 08:47:37 | 003,846,408 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 06:33:01 | 000,596,690 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 06:33:01 | 000,104,506 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat ========== LOP Check ========== [2010/11/11 10:24:11 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\.purple [2012/07/30 18:11:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\AllDup [2011/11/26 18:52:17 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Audacity [2011/04/15 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Azureus [2011/07/13 05:46:46 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Blender Foundation [2011/03/16 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\BOM [2010/07/15 16:07:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Canon [2011/05/05 05:22:48 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2010/07/17 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Crossword Compiler Deutsch 8 [2012/07/26 04:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite [2010/12/02 19:26:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DataCast [2010/08/18 16:24:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\dBpoweramp [2012/06/25 16:16:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Disruptive Innovations SARL [2012/08/09 06:35:58 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Dropbox [2012/03/19 02:34:06 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoft [2011/04/04 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers [2010/11/18 08:12:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Flickr [2010/11/26 05:58:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Free Sound Recorder [2011/01/19 05:14:41 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\GetRightToGo [2010/07/15 13:45:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Gutscheinmieze [2011/09/29 16:22:59 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\HandBrake [2011/10/19 18:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ImgBurn [2012/02/09 16:15:54 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\innoplus [2010/09/25 17:23:24 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\InterVideo [2012/07/31 18:06:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\IrfanView [2012/04/04 06:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\kompozer.net [2010/09/29 14:23:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Leadertech [2011/04/28 04:53:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\MAGIX [2010/09/29 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OOo-dev [2010/07/28 07:22:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OpenOffice.org [2010/08/17 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PDF reDirect [2010/07/15 17:17:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoFiltre [2010/12/09 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoScape [2010/07/17 11:13:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\pics [2012/07/21 08:00:40 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\RipIt4Me [2010/07/05 16:00:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Thunderbird [2010/07/29 11:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TomTom [2011/04/30 11:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TP [2011/10/24 15:28:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\uTorrent [2012/01/21 02:58:52 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Verbindungsassistent [2011/06/30 06:42:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Video DVD Maker FREE [2011/03/09 12:33:05 | 000,000,000 | ---D | M] -- C:\ProgramData\AllDup [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2010/07/15 15:38:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ [2010/07/17 09:35:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJEGV [2010/07/15 16:07:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan [2012/06/29 11:56:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco [2012/07/10 15:21:26 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2011/02/12 13:20:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Eltima Software [2012/04/14 17:40:47 | 000,000,000 | ---D | M] -- C:\ProgramData\F4D55F3E00016D2B000B49DB570F1C8B [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2010/09/11 17:45:30 | 000,000,000 | ---D | M] -- C:\ProgramData\ifolor [2012/02/09 16:15:57 | 000,000,000 | ---D | M] -- C:\ProgramData\innoplus [2012/01/29 08:32:35 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX [2010/07/15 15:10:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Phase6 [2010/07/17 11:13:34 | 000,000,000 | ---D | M] -- C:\ProgramData\pics [2011/08/27 10:18:04 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe [2010/07/05 12:39:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2010/12/17 04:10:35 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP [2006/11/02 09:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2010/07/29 12:02:08 | 000,000,000 | ---D | M] -- C:\ProgramData\TomTom [2010/07/05 12:44:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2011/03/27 16:05:14 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch [2012/08/07 12:56:37 | 000,000,000 | ---D | M] -- C:\ProgramData\ztgcrqxmyuqrqqg [2010/07/05 12:30:27 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3} [2011/03/18 18:25:39 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2012/08/14 13:25:47 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
17.08.2012, 18:20 | #4 |
| GVU Trojaner - Laptop gesperrt Keine Idee? |
17.08.2012, 18:36 | #5 | |
/// Malware-holic | GVU Trojaner - Laptop gesperrt sorry Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!Downloade dir bitte Combofix von einem dieser Downloadspiegel Link 1 Link 2 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
18.08.2012, 14:50 | #6 |
| GVU Trojaner - Laptop gesperrt Danke für die Antwort! Ich kann leider combofix nicht herunterladen und ausführen, da ich keinen Zugriff auf den Desktop habe. Direkt nach dem anmelden kommt ja immer die sperrseite. (auch im abgesicherten Modus) gibt's dafür ne Lösung? |
20.08.2012, 17:09 | #7 |
/// Malware-holic | GVU Trojaner - Laptop gesperrt mach mal folgendes bitte: Mit einem sauberen 2. Rechner eine OTLPE-CD erstellen und den infizierten Rechner dann von dieser CD booten: Falls Du kein Brennprogramm installiert hast, lade dir bitte ISOBurner herunter. Das Programm wird Dir erlauben, OTLPE auf eine CD zu brennen und sie bootfähig zu machen. Du brauchst das Tool nur zu installieren, der Rest läuft automatisch => Wie brenne ich eine ISO Datei auf CD/DVD. Lade OTLPENet.exe von OldTimer herunter und speichere sie auf Deinem Desktop. Anmerkung: Die Datei ist ca. 120 MB groß und es wird bei langsamer Internet-Verbindung ein wenig dauern, bis Du sie runtergeladen hast.
Bebilderte Anleitung: OTLpe-Scan
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
21.08.2012, 11:21 | #8 |
| GVU Trojaner - Laptop gesperrt habe alles wie beschrieben durchgeführt, oder jedenfalls versucht: otlpe bleibt nach einiger zeit immer stehen und gibt folgende fehlermeldung: "out of memory". in der statusleiste unten steht zu diesem zeitpunkt immer "manual file scan - getting folder structure". und in der textbox ist der oberste eintrag dann "%SYSTEMDRIVE%\*." habe mal einen ss angehängt.. |
22.08.2012, 17:37 | #9 |
/// Malware-holic | GVU Trojaner - Laptop gesperrt dann versuchs ohne mein script, das sollte dann gehen
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
30.08.2012, 22:29 | #10 |
| GVU Trojaner - Laptop gesperrt ohne hat's geklappt. hier die datei: Code:
ATTFilter OTL logfile created on: 8/28/2012 2:04:01 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 296.62 Gb Total Space | 136.00 Gb Free Space | 45.85% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand] -- -- (SPTISRV) SRV - File not found [On_Demand] -- -- (MSCSPTISRV) SRV - File not found [Auto] -- -- (0268391304585483mcinstcleanup) SRV - [2012/01/20 07:42:40 | 000,329,168 | ---- | M] () [Auto] -- C:\Program Files\Verbindungsassistent\WTGService.exe -- (WTGService) SRV - [2011/08/03 16:43:45 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/04/20 04:50:46 | 000,792,976 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent) SRV - [2011/03/09 08:30:08 | 000,092,592 | ---- | M] (TomTom) [Disabled] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2009/09/08 12:09:14 | 000,083,312 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper) SRV - [2009/04/01 18:15:30 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR) SRV - [2008/03/03 08:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr) SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/08/14 15:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service) SRV - [2007/05/31 04:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007/05/31 04:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (VMnetAdapter) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand] -- -- (IpInIp) DRV - File not found [Kernel | On_Demand] -- -- (igfx) DRV - File not found [Kernel | On_Demand] -- -- (catchme) DRV - File not found [File_System | System] -- -- (AFSRedirector) DRV - File not found [File_System | On_Demand] -- -- (AFSLibrary) DRV - [2012/07/10 15:07:43 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2012/01/20 07:39:33 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake) DRV - [2012/01/20 07:39:33 | 000,100,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewsercd.sys -- (ewsercd) DRV - [2011/08/03 16:27:28 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva) DRV - [2011/07/29 07:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv) DRV - [2011/07/29 07:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv) DRV - [2009/04/11 01:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan) DRV - [2009/04/11 00:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB) DRV - [2008/12/13 06:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2008/02/22 20:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2008/02/11 20:49:44 | 007,626,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2008/02/05 20:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2008/01/20 22:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV - [2008/01/20 22:23:21 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\loop.sys -- (msloop) DRV - [2007/12/16 21:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP) DRV - [2007/12/14 00:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2007/12/13 12:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall) DRV - [2007/09/18 23:29:09 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R) DRV - [2007/06/05 20:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony) DRV - [2007/05/26 04:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2004/02/04 02:19:32 | 000,024,177 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2004/02/04 02:19:16 | 000,057,372 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes] IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.club-vaio.com/vbc IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/07 18:09:46 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/28 11:06:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/05/28 11:06:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions [2010/07/05 16:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010/07/29 11:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com [2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\uploadr@flickr.com [2012/08/13 06:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions [2010/07/07 17:45:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011/10/29 15:52:00 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011/02/11 17:16:51 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906} [2012/07/28 01:39:41 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2012/08/08 18:16:15 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\FoxdieGraphite@tanjihay.com [2012/03/20 11:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions File not found (No name found) -- () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\CSSEDITOR@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\EYEDROPPER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FS@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FULLSCREEN@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\GFD@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-CS@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-DE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-EN-US@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ES-ES@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FI@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FR@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HU@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-IT@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-JA@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-KO@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-NL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-PL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SL@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SR@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SV-SE@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-CN@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-TW@BLUEGRIFFON.ORG.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\MATHML@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SNIPPETS@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SVG-EDIT@GOOGLEGROUPS.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TABLELAYOUT@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TEMPLATESMANAGER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\THUMBNAILER@BLUEGRIFFON.COM.XPI () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TIPOFTHEDAY@BLUEGRIFFON.COM.XPI [2012/08/07 18:09:46 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011/10/03 00:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010/07/12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012/07/02 06:29:39 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/07/02 06:29:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/07/02 06:29:39 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012/07/02 06:29:39 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012/07/02 06:29:39 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012/07/02 06:29:39 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012/08/08 14:46:11 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google BAE\BAE.dll (Your Company Name) O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found. O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKU\Jonas_ON_C\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Jonas_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Free YouTube Download - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKU\Jonas_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKU\Jonas_ON_C Winlogon: Shell - (C:\Users\Jonas\AppData\Roaming\msconfig.dat) - C:\Users\Jonas\AppData\Roaming\msconfig.dat () O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img30.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img30.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/08/15 19:34:07 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012/08/14 12:14:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012/08/13 08:30:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/13 08:08:43 | 000,038,224 | ---- | C] (CANON INC.) -- C:\Windows\System32\IJRMF.exe [2012/08/12 15:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2012/08/12 15:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo [2012/08/08 14:52:55 | 000,000,000 | ---D | C] -- C:\Windows\temp [2012/08/08 14:49:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2012/08/08 14:49:15 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\temp [2012/08/08 14:31:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012/08/08 14:31:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012/08/08 14:31:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2012/08/08 14:31:27 | 000,000,000 | ---D | C] -- C:\Qoobox [2012/08/08 14:31:10 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2012/08/07 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ztgcrqxmyuqrqqg [2012/08/03 17:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Snappy Fax Version 5 [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\IrfanView [2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/08/21 04:49:51 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/08/21 04:49:42 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012/08/21 04:49:42 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012/08/21 04:49:33 | 3219,578,880 | -HS- | M] () -- C:\hiberfil.sys [2012/08/21 03:50:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/08/21 03:50:12 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2012/08/21 03:50:06 | 000,000,045 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini [2012/08/14 12:45:08 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/08/14 12:14:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012/08/14 12:13:32 | 000,629,436 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012/08/14 12:13:32 | 000,596,690 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/08/14 12:13:32 | 000,126,890 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012/08/14 12:13:32 | 000,104,506 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/08/13 11:59:43 | 000,042,496 | ---- | M] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/08/13 11:23:38 | 000,000,746 | -H-- | M] () -- C:\Windows\EPMBatch.ept [2012/08/13 08:30:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/12 16:02:45 | 000,166,763 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001 [2012/08/12 15:39:04 | 000,001,765 | ---- | M] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk [2012/08/12 15:39:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo [2012/08/11 03:35:56 | 003,846,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012/08/08 17:26:23 | 000,000,600 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd [2012/08/08 14:46:11 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2012/07/31 18:06:36 | 000,001,687 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk [2012/07/31 18:06:36 | 000,000,807 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView.lnk [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/08/21 04:49:33 | 3219,578,880 | -HS- | C] () -- C:\hiberfil.sys [2012/08/14 13:16:31 | 000,000,045 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini [2012/08/13 08:30:21 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe [2012/08/13 08:30:21 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll [2012/08/13 08:30:20 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe [2012/08/13 08:30:20 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys [2012/08/13 08:30:20 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys [2012/08/12 15:39:04 | 000,001,765 | ---- | C] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk [2012/08/08 14:31:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012/08/08 14:31:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012/08/08 14:31:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012/08/08 14:31:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012/08/08 14:31:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012/07/31 18:06:36 | 000,001,687 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk [2012/07/31 18:06:36 | 000,000,807 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView.lnk [2012/06/29 11:15:27 | 000,000,600 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd [2012/06/13 11:33:54 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI [2012/05/15 09:33:02 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2012/02/11 20:01:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat [2012/02/11 15:23:07 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2012/02/11 15:23:00 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012/02/11 15:22:49 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2012/02/09 16:15:58 | 000,006,854 | RHS- | C] () -- C:\Windows\innova3.ini [2012/01/31 14:37:33 | 000,000,196 | ---- | C] () -- C:\Windows\System32\ftdiun2k.ini [2012/01/15 08:31:23 | 000,099,328 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.dat [2011/08/23 07:34:38 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI [2011/08/23 07:34:36 | 000,000,772 | ---- | C] () -- C:\Windows\ODBCINST.INI [2011/08/10 01:18:00 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{72A5C72A-484F-44E4-A570-0EB5D6ED0F18} [2011/08/10 01:07:04 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{80EA586A-7A9E-4E80-A54B-C062188EA15D} [2011/06/30 06:38:21 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll [2011/06/30 06:38:20 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/06/30 06:38:14 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2011/04/13 11:40:47 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2011/04/13 11:40:06 | 000,006,360 | ---- | C] () -- C:\Windows\mgxoschk.ini [2011/02/11 17:15:33 | 000,015,873 | ---- | C] () -- C:\Windows\System32\Inetde.dll [2010/12/17 04:01:47 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI [2010/12/02 07:51:55 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe [2010/11/10 10:45:30 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010/11/06 05:17:15 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2010/09/30 04:20:58 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010/09/30 04:20:58 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010/08/18 16:24:04 | 000,002,738 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp DirectShow Decoder.dat [2010/08/18 16:14:48 | 000,229,752 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe [2010/08/18 16:14:48 | 000,015,341 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat [2010/07/17 11:12:48 | 000,330,240 | ---- | C] () -- C:\Windows\PICSUninstall.exe [2010/07/13 08:19:52 | 000,042,496 | ---- | C] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/07/08 08:07:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010/07/08 08:07:32 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010/07/05 17:19:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2010/07/05 13:08:29 | 000,001,356 | ---- | C] () -- C:\Users\Jonas\AppData\Local\d3d9caps.dat [2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.dat [2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001 [2010/07/05 12:49:09 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI [2008/08/05 02:07:20 | 000,065,216 | ---- | C] () -- C:\Windows\System32\PDFreDirectMonNT.dll [2008/02/04 20:09:01 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1295.dll [2008/01/21 03:15:58 | 000,629,436 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008/01/21 03:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008/01/21 03:15:58 | 000,126,890 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008/01/21 03:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2007/09/11 19:57:44 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll [2007/09/11 19:54:26 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll [2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 08:47:37 | 003,846,408 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 06:33:01 | 000,596,690 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 06:33:01 | 000,104,506 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat ========== LOP Check ========== [2010/11/11 10:24:11 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\.purple [2012/07/30 18:11:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\AllDup [2011/11/26 18:52:17 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Audacity [2011/04/15 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Azureus [2011/07/13 05:46:46 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Blender Foundation [2011/03/16 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\BOM [2010/07/15 16:07:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Canon [2011/05/05 05:22:48 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2010/07/17 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Crossword Compiler Deutsch 8 [2012/07/26 04:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite [2010/12/02 19:26:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DataCast [2010/08/18 16:24:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\dBpoweramp [2012/06/25 16:16:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Disruptive Innovations SARL [2012/08/09 06:35:58 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Dropbox [2012/03/19 02:34:06 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoft [2011/04/04 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers [2010/11/18 08:12:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Flickr [2010/11/26 05:58:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Free Sound Recorder [2011/01/19 05:14:41 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\GetRightToGo [2010/07/15 13:45:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Gutscheinmieze [2011/09/29 16:22:59 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\HandBrake [2011/10/19 18:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ImgBurn [2012/02/09 16:15:54 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\innoplus [2010/09/25 17:23:24 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\InterVideo [2012/07/31 18:06:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\IrfanView [2012/04/04 06:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\kompozer.net [2010/09/29 14:23:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Leadertech [2011/04/28 04:53:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\MAGIX [2010/09/29 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OOo-dev [2010/07/28 07:22:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OpenOffice.org [2010/08/17 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PDF reDirect [2010/07/15 17:17:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoFiltre [2010/12/09 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoScape [2010/07/17 11:13:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\pics [2012/07/21 08:00:40 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\RipIt4Me [2010/07/05 16:00:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Thunderbird [2010/07/29 11:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TomTom [2011/04/30 11:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TP [2011/10/24 15:28:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\uTorrent [2012/01/21 02:58:52 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Verbindungsassistent [2011/06/30 06:42:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Video DVD Maker FREE [2011/03/09 12:33:05 | 000,000,000 | ---D | M] -- C:\ProgramData\AllDup [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2010/07/15 15:38:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ [2010/07/17 09:35:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJEGV [2010/07/15 16:07:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan [2012/06/29 11:56:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco [2012/07/10 15:21:26 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2011/02/12 13:20:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Eltima Software [2012/04/14 17:40:47 | 000,000,000 | ---D | M] -- C:\ProgramData\F4D55F3E00016D2B000B49DB570F1C8B [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2010/09/11 17:45:30 | 000,000,000 | ---D | M] -- C:\ProgramData\ifolor [2012/02/09 16:15:57 | 000,000,000 | ---D | M] -- C:\ProgramData\innoplus [2012/01/29 08:32:35 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX [2010/07/15 15:10:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Phase6 [2010/07/17 11:13:34 | 000,000,000 | ---D | M] -- C:\ProgramData\pics [2011/08/27 10:18:04 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe [2010/07/05 12:39:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony [2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2010/12/17 04:10:35 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP [2006/11/02 09:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2010/07/29 12:02:08 | 000,000,000 | ---D | M] -- C:\ProgramData\TomTom [2010/07/05 12:44:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall [2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2011/03/27 16:05:14 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch [2012/08/07 12:56:37 | 000,000,000 | ---D | M] -- C:\ProgramData\ztgcrqxmyuqrqqg [2010/07/05 12:30:27 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3} [2011/03/18 18:25:39 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2012/08/21 03:50:12 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
04.09.2012, 20:55 | #11 |
/// Malware-holic | GVU Trojaner - Laptop gesperrt auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort rein: Code:
ATTFilter :OTL O20 - HKU\Jonas_ON_C Winlogon: Shell - (C:\Users\Jonas\AppData\Roaming\msconfig.dat) - C:\Users\Jonas\AppData\Roaming\msconfig.dat () :Files :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] dieses speicherst du auf nem usb stick als fix.txt nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist. • Klicke nun bitte auf den Fix Button. es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick. wenn dies nicht funktioniert, bitte den fix manuell eintragen. dann klicke erneut den fix buton. pc startet evtl. neu. wenn ja, nimm die cd aus dem laufwerk, windows sollte nun normal starten und die otl.txt öffnen, log posten bitte.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
11.09.2012, 10:05 | #12 |
| GVU Trojaner - Laptop gesperrt hallo, habe den fix durchgeführt. wurde danach auch nach dem neustart gefragt. dieser wurde allerdings nicht automatisch durchgeführt. wollte dann manuell neustarten, dabei ist otlpenet eingefroren... also per netzschalter das "runterfahren" erzwungen. wieder eingeschaltet, cd raus genommen und vista startet wieder. so weit, so gut. allerdings gibt's keine aktuelle otl.txt. es ist nur die alte vom scan da, beim fix wurde anscheinend keine erstellt. vllt durch das einfrieren? weitere schritte? von vista aus nochmal nen scan laufen lassen oder was sollte ich nun machen? |
11.09.2012, 10:07 | #13 | |
/// Malware-holic | GVU Trojaner - Laptop gesperrt hi Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!Downloade dir bitte Combofix von einem dieser Downloadspiegel Link 1 Link 2 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
11.09.2012, 10:52 | #14 |
| GVU Trojaner - Laptop gesperrt hier die combofix.txt: Code:
ATTFilter ComboFix 12-09-11.01 - Jonas 11.09.2012 11:18:48.2.2 - x86 ausgeführt von:: c:\users\Jonas\Desktop\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Jonas\AppData\Roaming\msconfig.ini . . ((((((((((((((((((((((( Dateien erstellt von 2012-08-11 bis 2012-09-11 )))))))))))))))))))))))))))))) . . 2012-09-11 18:41 . 2011-07-13 02:55 2237440 ----a-r- C:\OTLPE.exe 2012-09-11 18:41 . 2012-09-11 18:41 -------- d-----w- C:\_OTL 2012-09-11 09:24 . 2012-09-11 09:24 -------- d-----w- c:\users\Jonas\AppData\Local\temp 2012-09-11 09:24 . 2012-09-11 09:24 -------- d-----w- c:\users\Public\AppData\Local\temp 2012-09-11 09:24 . 2012-09-11 09:24 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-08-14 16:17 . 2012-06-29 08:44 6891424 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C24814AE-3D83-4522-BEE5-A9EA6D4B25FB}\mpengine.dll 2012-08-13 12:30 . 2012-05-17 15:36 2468520 ----a-w- c:\windows\system32\BootMan.exe 2012-08-13 12:30 . 2011-07-29 11:54 19840 ----a-w- c:\windows\system32\EuEpmGdi.dll 2012-08-13 12:30 . 2011-07-29 11:54 86408 ----a-w- c:\windows\system32\setupempdrv03.exe 2012-08-13 12:30 . 2011-07-29 11:54 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys 2012-08-13 12:30 . 2011-07-29 11:54 14216 ----a-w- c:\windows\system32\epmntdrv.sys 2012-08-13 12:08 . 2009-02-26 17:32 38224 ------w- c:\windows\system32\IJRMF.exe 2012-08-12 20:25 . 2012-08-12 20:25 -------- d-----w- c:\users\Jonas\licman 2012-08-12 20:25 . 2012-08-12 20:25 -------- d-----w- c:\users\Jonas\EREnt 2012-08-12 19:39 . 2012-08-12 19:45 -------- d-----w- c:\program files\CrystalDiskInfo . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-28 05:32 . 2012-04-10 20:48 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-28 05:32 . 2011-05-16 10:21 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-10 19:07 . 2010-09-29 18:29 477240 ----a-w- c:\windows\system32\drivers\sptd.sys 2012-06-13 13:40 . 2012-07-11 12:22 2047488 ----a-w- c:\windows\system32\win32k.sys 2012-08-07 22:09 . 2012-01-20 08:35 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Jonas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Jonas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Jonas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKLM\~\startupfolder\C:^Users^Jonas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk] path=c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk backup=c:\windows\pss\Dropbox.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Jonas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OOo-dev 3.3.lnk] path=c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OOo-dev 3.3.lnk backup=c:\windows\pss\OOo-dev 3.3.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] 2008-02-23 00:38 122880 ----a-w- c:\program files\Apoint\Apoint.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2012-05-30 18:06 59280 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter] 2009-03-24 02:00 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu] 2009-03-18 01:40 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] 2012-04-17 15:19 3671872 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility] 2009-05-19 15:11 136544 ----a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe] 2007-11-21 11:38 311296 ----a-w- c:\program files\Sony\ISB Utility\ISBMgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2012-06-07 17:33 421776 ----a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2008-02-12 00:47 8497696 ----a-w- c:\windows\System32\nvcpl.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2008-02-12 00:47 81920 ----a-w- c:\windows\System32\nvmctray.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc] 2008-02-12 00:50 86016 ----a-w- c:\windows\System32\nvsvc.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2012-04-18 18:56 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2008-01-23 00:11 4718592 ----a-w- c:\windows\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel] 2008-01-23 00:11 1826816 ----a-w- c:\windows\SkyTel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2011-06-09 12:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe] 2011-03-09 12:30 247728 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2010-07-12 16:32 74752 ----a-w- c:\program files\Winamp\winampa.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center] 2007-05-31 08:21 648072 ----a-w- c:\windows\WindowsMobile\wmdc.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 . R2 0268391304585483mcinstcleanup;0268391304585483mcinstcleanup; [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - ECACHE . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . Inhalt des "geplante Tasks" Ordners . 2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-06 10:25] . 2012-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-06 10:25] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.club-vaio.com/vbc uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~1\MIC279~1\Office14\ONBttnIE.dll/105 IE: Free YouTube Download - c:\users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to MP3 Converter - c:\users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MIC279~1\Office14\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2206084&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.google.de FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2206084&q= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . MSConfigStartUp-AVP - c:\program files\Kaspersky Lab\Kaspersky Security Suite CBE\avp.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2012-09-11 11:24 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2775964904-2318342985-3309343633-1003\Software\SecuROM\License information*] "datasecu"=hex:9a,85,31,37,9c,f8,a3,45,14,57,07,2c,b0,78,e0,0b,09,4c,6f,b6,c5, 29,a5,08,76,da,7e,48,a1,8f,ca,4f,11,55,83,a3,0a,b7,e6,cc,a6,38,4a,94,d1,9e,\ "rkeysecu"=hex:b9,04,84,cf,bc,f7,f3,e8,79,e5,f6,b7,c2,2b,06,23 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2012-09-11 11:26:41 ComboFix-quarantined-files.txt 2012-09-11 09:26 ComboFix2.txt 2012-08-08 18:49 . Vor Suchlauf: 22 Verzeichnis(se), 146.151.825.408 Bytes frei Nach Suchlauf: 23 Verzeichnis(se), 146.185.735.168 Bytes frei . - - End Of File - - B09D4B89B0E19381E99B3710B31B4261 |
11.09.2012, 11:04 | #15 |
/// Malware-holic | GVU Trojaner - Laptop gesperrt hi malwarebytes: Downloade Dir bitte Malwarebytes
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
Themen zu GVU Trojaner - Laptop gesperrt |
abgesicherte, abgesicherten, abgesicherten modus, gesperrt, gvu trojander, gvu trojaner, laptop, laptop gesperrt, modus, netzwerk, nicht mehr, troja, trojaner |