|
Plagegeister aller Art und deren Bekämpfung: Live Security PremiumWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
04.09.2012, 15:11 | #1 |
| Live Security Premium Nachdem ich die "Bundespolizei" dank eurer Hilfe erfolgreich bekämpft habe, steht nun der nächste Ärger ins Haus, diesmal in Form von "Live Security Premium". Hier gleich mal das Malwarebytes Log Code:
ATTFilter Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.09.04.07 Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 8.0.7601.17514 Tom :: TOM-PC [Administrator] 04.09.2012 16:08:29 mbam-log-2012-09-04 (16-09-23).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 243635 Laufzeit: 42 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce|225932FD00011628005484B8F875F002 (Trojan.FakeMS) -> Daten: C:\ProgramData\225932FD00011628005484B8F875F002\225932FD00011628005484B8F875F002.exe -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\ProgramData\225932FD00011628005484B8F875F002\225932FD00011628005484B8F875F002.exe (Trojan.FakeMS) -> Keine Aktion durchgeführt. C:\Users\Tom\AppData\Local\Temp\tmp4437881a\v.exe (Trojan.FakeMS) -> Keine Aktion durchgeführt. (Ende) Hab die Funde auch schon in Quarantäne geschickt und neu gestartet. Was nun? |
04.09.2012, 22:44 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Live Security Premium Bitte erstmal routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
__________________Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ |
05.09.2012, 15:37 | #3 |
| Live Security Premium Hier der Malware Log
__________________Code:
ATTFilter Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.09.05.06 Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 8.0.7601.17514 Tom :: TOM-PC [Administrator] 05.09.2012 14:44:18 mbam-log-2012-09-05 (14-44-18).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 493055 Laufzeit: 29 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Und der zweite Log Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fe849fea4cc1f34ab93f99a65093005f # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-09-05 01:22:29 # local_time=2012-09-05 03:22:29 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 38436507 98480870 0 0 # compatibility_mode=8192 67108863 100 0 1825 1825 0 0 # scanned=7948 # found=0 # cleaned=0 # scan_time=329 ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fe849fea4cc1f34ab93f99a65093005f # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-09-05 02:29:04 # local_time=2012-09-05 04:29:04 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1792 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 38436862 98481225 0 0 # compatibility_mode=8192 67108863 100 0 2180 2180 0 0 # scanned=295523 # found=0 # cleaned=0 # scan_time=3969 |
05.09.2012, 15:41 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Live Security Premium adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
05.09.2012, 15:43 | #5 |
| Live Security Premium Ich konnte jetzt auch Windows im normales Modus starten. Gestern ging's noch nicht. Ich hab bevor ich das Forum aufgsucht hab, schon versucht mit ADW Cleaner usw das Problem in den Griff zu bekommen, kann es sein, dass das gefruchtet hat? Der adw Log Code:
ATTFilter # AdwCleaner v2.000 - Datei am 09/05/2012 um 16:43:48 erstellt # Aktualisiert am 30/08/2012 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Tom - TOM-PC # Normaler Modus : Normal # Ausgeführt unter : C:\Users\Tom\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v15.0 (de) Profilname : default Datei : C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\zappub05.default\prefs.js [OK] Die Datei ist sauber. Profilname : default Datei : C:\Users\Carina\AppData\Roaming\Mozilla\Firefox\Profiles\3igot4kv.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v [Version kann nicht ermittelt werden] Datei : C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1788 octets] - [04/09/2012 15:59:20] AdwCleaner[S1].txt - [2600 octets] - [04/09/2012 15:59:44] AdwCleaner[R2].txt - [1181 octets] - [05/09/2012 16:43:48] ########## EOF - C:\AdwCleaner[R2].txt - [1241 octets] ########## |
05.09.2012, 16:24 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Live Security Premium Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ --> Live Security Premium |
05.09.2012, 16:52 | #7 |
| Live Security Premium Also bei den Custom Scans/Fixes steht nichts. OTL Log OTL Logfile: Code:
ATTFilter OTL logfile created on: 9/5/2012 5:45:29 PM - Run 2 OTL by OldTimer - Version 3.2.60.0 Folder = C:\Users\Tom\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 7.98 Gb Total Physical Memory | 6.51 Gb Available Physical Memory | 81.58% Memory free 15.96 Gb Paging File | 14.31 Gb Available in Paging File | 89.64% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 58.53 Gb Total Space | 1.59 Gb Free Space | 2.72% Space Free | Partition Type: NTFS Drive D: | 891.00 Gb Total Space | 599.13 Gb Free Space | 67.24% Space Free | Partition Type: NTFS Drive E: | 40.51 Gb Total Space | 22.02 Gb Free Space | 54.36% Space Free | Partition Type: NTFS Computer Name: TOM-PC | User Name: Tom | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Tom\Desktop\OTL.exe (OldTimer Tools) PRC - D:\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - D:\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (Apple Inc.) PRC - C:\Windows\SysWOW64\PnkBstrA.exe () PRC - D:\Sony Reader\appHelper\ReaderAppHelper.exe (Sony Corporation) PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) PRC - D:\Kies\External\FirmwareUpdate\KiesPDLR.exe () PRC - D:\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) PRC - C:\Program Files (x86)\dcmsvc\dcmsvc.exe () PRC - D:\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) ========== Modules (No Company Name) ========== MOD - C:\Users\Tom\AppData\Local\Temp\ae201572-4813-4010-9ed2-ee29ddec066a\CliSecureRT.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\2e16482769fcdf856919e292a968f16c\IAStorUtil.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\063174e87d258ef1db040cbfbdd4cd31\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\984f8802a334d2ae862b66bf71332c10\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\d55bed00e3d36b0db5bd3994c77fe850\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\697786bb51408d41d980263d90a56d03\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\9abdaeea6a61127606bbc324d9177579\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\0189f9fb0ff0476b570aeadfc036ddd6\System.Management.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\d8c2194d25c5dad7f9dfb480857bbc76\System.Runtime.Remoting.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f91c92735c4a913143a0914c8cb531f2\System.Xaml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\3b2b9f4ec1819e4b95792d92f56d26f9\IAStorCommon.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\fd52e266873de847aea40b1d0715e0bb\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\500ffaf6258746eaf0bfc333ab534a51\System.Core.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\b54a85f8f8f5ac297357c80b95834a90\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\360d70391adff56f1d029b1a538d2431\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\97d737762adec957a2d7c80fafb4703a\mscorlib.ni.dll () MOD - D:\Sony Reader\appHelper\fsk.dll () MOD - D:\Sony Reader\appHelper\readerAppHelper.dll () MOD - D:\Sony Reader\appHelper\USBDetector.dll () MOD - D:\Sony Reader\appHelper\FskNetInterface.dll () MOD - D:\Sony Reader\appHelper\FskPower.dll () MOD - D:\Sony Reader\appHelper\FskinLocalize.dll () MOD - D:\Sony Reader\appHelper\FskTimeHardware.dll () MOD - D:\Sony Reader\appHelper\ticket.dll () MOD - D:\Sony Reader\appHelper\ebookDeviceNotifier.dll () MOD - D:\Sony Reader\appHelper\FskDocumentViewer.dll () MOD - D:\Sony Reader\appHelper\Fskin.dll () MOD - D:\Sony Reader\appHelper\FskMobileMediaDevice.dll () MOD - D:\Sony Reader\appHelper\FskMediaPlayers.dll () MOD - D:\Sony Reader\appHelper\FskSecurity.dll () MOD - D:\Sony Reader\appHelper\ebookUsb.dll () MOD - D:\Kies\External\FirmwareUpdate\KiesPDLR.exe () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll () MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll () MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll () MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll () MOD - C:\Program Files (x86)\dcmsvc\dcmsvc.exe () ========== Services (SafeList) ========== SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (AntiVirService) -- D:\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirSchedulerService) -- D:\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (Sony SCSI Helper Service) -- C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe (Sony Corporation) SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (DAUpdaterSvc) -- D:\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd) DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH) DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation) DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation) DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation) DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation) DRV:64bit: - (epmntdrv) -- C:\Windows\SysNative\epmntdrv.sys () DRV:64bit: - (EuGdiDrv) -- C:\Windows\SysNative\EuGdiDrv.sys () DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation) DRV:64bit: - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation) DRV:64bit: - (ssadmdfl) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation) DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation) DRV:64bit: - (sscdmdm) -- C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation) DRV:64bit: - (sscdbus) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation) DRV:64bit: - (sscdmdfl) -- C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.) DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink) DRV:64bit: - (mv91xx) -- C:\Windows\SysNative\drivers\mv91xx.sys (Marvell Semiconductor, Inc.) DRV:64bit: - (RTL8192su) -- C:\Windows\SysNative\drivers\RTL8192su.sys (Realtek Semiconductor Corporation ) DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:64bit: - (SynasUSB) -- C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft) DRV - (epmntdrv) -- C:\Windows\SysWOW64\epmntdrv.sys () DRV - (EuGdiDrv) -- C:\Windows\SysWOW64\EuGdiDrv.sys () DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com IE - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "" FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: D:\Sony Reader\npreaderdetectmoz.dll (Sony Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: D:\Veetle\plugins\npVeetle.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: D:\Veetle\Player\npvlc.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/07 18:16:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: D:\Firefox\components [2012/08/31 11:14:36 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: D:\Firefox\plugins [2012/08/16 17:44:39 | 000,000,000 | ---D | M] [2011/05/30 21:32:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tom\AppData\Roaming\mozilla\Extensions [2012/09/02 10:15:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tom\AppData\Roaming\mozilla\Firefox\Profiles\zappub05.default\extensions [2012/08/14 09:47:26 | 000,001,210 | ---- | M] () -- C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\zappub05.default\searchplugins\search.xml [2012/02/07 18:16:27 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 [2012/09/02 10:15:32 | 000,699,353 | ---- | M] () (No name found) -- C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZAPPUB05.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI ========== Chrome ========== CHR - default_search_provider: (Enabled) CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - Extension: Skype Click to Call = C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\ CHR - Extension: Skype Click to Call = C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8312_0\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\ O1 HOSTS File: ([2011/07/18 22:49:06 | 000,434,670 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 123fporn.info O1 - Hosts: 14957 more lines... O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found. O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found. O4:64bit: - HKLM..\Run: [MedionReminder] C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] D:\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [dcmsvc] C:\Program Files (x86)\dcmsvc\dcmsvc.exe () O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) O4 - HKLM..\Run: [Reader Application Helper] D:\Sony Reader\appHelper\ReaderAppHelper.exe (Sony Corporation) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001..\Run: [KiesHelper] D:\Kies\KiesHelper.exe (Samsung) O4 - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001..\Run: [KiesPDLR] D:\Kies\External\FirmwareUpdate\KiesPDLR.exe () O4 - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001..\Run: [KiesTrayAgent] D:\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-21-1992664349-3133250512-2622041644-1001..\Run: [Steam] D:\Steam\Steam.exe (Valve Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O8:64bit: - Extra context menu item: Google Sidewiki... - Reg Error: Value error. File not found O8 - Extra context menu item: Google Sidewiki... - Reg Error: Value error. File not found O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in ) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 10.6.2) O16 - DPF: {CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 1.7.0_06) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 1.7.0_06) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.33.55.5 212.33.32.160 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BCE7BB5D-4BFC-4465-BD17-DDE4C7AF17B2}: DhcpNameServer = 212.33.55.5 212.33.32.160 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012/09/05 14:46:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET [2012/09/05 14:46:20 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Tom\Desktop\esetsmartinstaller_enu.exe [2012/09/04 18:16:11 | 000,599,040 | ---- | C] (OldTimer Tools) -- C:\Users\Tom\Desktop\OTL.exe [2012/09/04 15:53:28 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/09/04 15:53:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/09/04 15:15:39 | 000,000,000 | ---D | C] -- C:\ProgramData\225932FD00011628005484B8F875F002 [2012/09/02 12:23:01 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Roaming\DarknessII [2012/08/27 16:27:11 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\FalloutNV [2012/08/24 18:01:52 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012/08/22 15:27:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2012/08/21 17:04:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware [2012/08/21 17:04:54 | 000,000,000 | ---D | C] -- C:\Users\Tom\Documents\Anti-Malware [2012/08/21 13:39:02 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Roaming\Malwarebytes [2012/08/21 13:38:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012/08/19 08:07:30 | 000,000,000 | ---D | C] -- C:\Users\Tom\Documents\DeadIsland [2012/08/14 08:16:26 | 000,000,000 | ---D | C] -- C:\Windows\de [2012/08/14 08:16:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2012/08/14 08:12:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive [2012/08/13 22:18:35 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{D7B242FC-952F-4749-B7FC-61BD46687AC9} [2012/08/13 22:18:25 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{68C8D199-67A3-4E3E-821F-861F419B35D5} [2012/08/13 22:18:15 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{1D70913B-6037-4462-8338-120348A468AB} [2012/08/13 22:17:46 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{7345A72B-0248-4A0D-BCA5-78B39E452584} [2012/08/13 22:14:59 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{F8989C18-1764-4FC8-9652-AAE54AC63773} [2012/08/13 22:10:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition [2012/08/13 21:54:01 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{8089A168-5353-452A-9A6D-23CB913003C6} [2012/08/13 21:53:52 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{609C7F39-CED3-47C8-BBBD-C1B44B5EFD05} [2012/08/13 21:53:22 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{BE1B60E5-E3DC-44AB-88B2-ECB186F257F0} [2012/08/13 21:53:01 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{5A640B31-6CF0-4621-9FB5-D6D1B3F023C8} [2012/08/13 21:44:23 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys [2012/08/13 21:44:20 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Roaming\DAEMON Tools Lite [2012/08/13 21:43:08 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2012/08/13 21:38:20 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Roaming\CyberLink [2012/08/13 20:39:48 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{508C848F-C2BB-4266-B021-5B22E0BB04D8} [2012/08/13 20:39:18 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{D43B3731-E7E5-493F-803B-9CFDBCEF6E3D} [2012/08/13 20:39:03 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{8D902ED0-D20F-4FE4-8A8D-0CFCDB565BA5} [2012/08/13 20:23:01 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{91E6C1A3-9752-45AE-AFDA-DBDD482019B2} [2012/08/13 20:22:33 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{A9B34539-5829-43C3-8FBD-496EA37B6088} [2012/08/13 20:22:24 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{29B8F54F-337C-4CF0-9BF6-6567297A992A} [2012/08/13 20:21:54 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{1C2127C1-51C5-4896-874F-CAD644F7939B} [2012/08/13 20:21:34 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{901E6EBB-C6BE-4D6D-9659-DA0D611E4265} [2012/08/13 18:54:40 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\{80B307AF-704C-41FF-98D2-84EA28DD9E01} [2012/08/12 19:10:47 | 000,000,000 | ---D | C] -- C:\Users\Tom\AppData\Local\DDMSettings [2011/03/24 12:37:25 | 019,786,880 | ---- | C] (Electronic Arts, Inc.) -- C:\Program Files (x86)\eadm-installer.exe ========== Files - Modified Within 30 Days ========== [2012/09/05 16:58:57 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/09/05 16:57:18 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/09/05 16:57:18 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/09/05 16:56:08 | 003,863,516 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012/09/05 16:56:08 | 001,594,396 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012/09/05 16:56:08 | 001,021,624 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012/09/05 16:56:08 | 001,020,168 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012/09/05 16:56:08 | 000,006,536 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012/09/05 16:49:59 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/09/05 16:48:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/09/05 16:48:28 | 2133,086,207 | -HS- | M] () -- C:\hiberfil.sys [2012/09/05 14:46:21 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Tom\Desktop\esetsmartinstaller_enu.exe [2012/09/04 18:16:20 | 000,050,477 | ---- | M] () -- C:\Users\Tom\Desktop\Defogger.exe [2012/09/04 18:16:11 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Users\Tom\Desktop\OTL.exe [2012/09/04 15:58:53 | 000,511,265 | ---- | M] () -- C:\Users\Tom\Desktop\adwcleaner.exe [2012/09/04 10:46:04 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2012/09/04 10:46:04 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2012/09/04 10:45:40 | 000,282,864 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2012/08/24 14:40:31 | 007,314,129 | ---- | M] () -- C:\Users\Tom\Desktop\Everything2.mp3 [2012/08/24 14:40:26 | 007,566,159 | ---- | M] () -- C:\Users\Tom\Desktop\Everything1.mp3 [2012/08/24 14:40:15 | 007,514,745 | ---- | M] () -- C:\Users\Tom\Desktop\No Way.mp3 [2012/08/20 16:48:11 | 000,000,128 | ---- | M] () -- C:\Users\Tom\defogger_reenable [2012/08/17 11:13:13 | 000,291,800 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/08/14 08:16:21 | 000,000,020 | ---- | M] () -- C:\Windows\°ô± [2012/08/14 08:14:30 | 000,000,020 | ---- | M] () -- C:\Windows\Ø÷b [2012/08/13 21:44:23 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys ========== Files Created - No Company Name ========== [2012/09/04 18:16:20 | 000,050,477 | ---- | C] () -- C:\Users\Tom\Desktop\Defogger.exe [2012/09/04 15:58:52 | 000,511,265 | ---- | C] () -- C:\Users\Tom\Desktop\adwcleaner.exe [2012/08/24 14:40:27 | 007,314,129 | ---- | C] () -- C:\Users\Tom\Desktop\Everything2.mp3 [2012/08/24 14:40:21 | 007,566,159 | ---- | C] () -- C:\Users\Tom\Desktop\Everything1.mp3 [2012/08/24 14:40:12 | 007,514,745 | ---- | C] () -- C:\Users\Tom\Desktop\No Way.mp3 [2012/08/20 16:48:11 | 000,000,128 | ---- | C] () -- C:\Users\Tom\defogger_reenable [2012/08/14 08:16:24 | 000,001,309 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk [2012/08/14 08:16:22 | 000,001,378 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk [2012/08/14 08:16:21 | 000,000,020 | ---- | C] () -- C:\Windows\°ô± [2012/08/14 08:14:29 | 000,000,020 | ---- | C] () -- C:\Windows\Ø÷b [2012/08/13 22:10:08 | 003,316,736 | ---- | C] () -- C:\Windows\SysNative\BootMan.exe [2012/08/13 22:10:08 | 002,468,520 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe [2012/08/13 22:10:08 | 000,100,232 | ---- | C] () -- C:\Windows\SysNative\setupempdrvx64.exe [2012/08/13 22:10:08 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe [2012/08/13 22:10:08 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll [2012/08/13 22:10:08 | 000,016,776 | ---- | C] () -- C:\Windows\SysNative\epmntdrv.sys [2012/08/13 22:10:08 | 000,016,256 | ---- | C] () -- C:\Windows\SysNative\EuEpmGdi.dll [2012/08/13 22:10:08 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys [2012/08/13 22:10:08 | 000,009,096 | ---- | C] () -- C:\Windows\SysNative\EuGdiDrv.sys [2012/08/13 22:10:08 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys [2012/05/03 04:54:46 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll [2012/02/14 21:55:51 | 002,580,552 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe [2011/11/25 21:51:29 | 000,064,847 | ---- | C] () -- C:\Windows\War3Unin.dat [2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2011/07/11 10:45:03 | 000,092,504 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat [2011/06/19 20:24:23 | 001,509,020 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/06/07 11:13:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll [2011/06/07 11:13:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll [2011/06/07 11:13:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll [2011/06/07 11:13:38 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll [2011/05/30 23:04:25 | 000,283,304 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2011/05/30 23:04:24 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2011/05/30 23:04:24 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2011/05/30 22:10:36 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2011/05/30 22:10:36 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/05/30 22:10:35 | 000,631,808 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2011/05/30 22:10:35 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2011/05/30 22:10:35 | 000,122,368 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll [2011/05/30 22:10:35 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2011/05/30 22:04:11 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat ========== LOP Check ========== [2012/09/01 15:37:53 | 000,000,000 | ---D | M] -- C:\Users\Carina\AppData\Roaming\SoftGrid Client [2011/12/03 17:38:13 | 000,000,000 | ---D | M] -- C:\Users\Carina\AppData\Roaming\Windows Live Writer [2011/06/26 18:59:54 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Bioshock2 [2011/07/31 15:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Blender Foundation [2011/07/25 22:09:51 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1 [2012/08/24 18:06:56 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\DAEMON Tools Lite [2012/09/02 17:13:20 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\DarknessII [2012/03/26 19:48:29 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\DVDVideoSoft [2011/11/28 11:34:11 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\LolClient [2011/09/19 18:26:04 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Miranda [2012/08/18 20:36:26 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Origin [2011/07/25 22:24:02 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Samsung [2012/09/03 23:45:04 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\SoftGrid Client [2012/07/22 11:24:40 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Steinberg [2011/06/19 20:25:00 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\TP [2012/01/31 00:26:48 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\TS3Client [2012/09/04 15:55:59 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Uwol [2011/06/26 11:43:33 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\Windows Live Writer [2011/08/22 10:24:06 | 000,000,000 | ---D | M] -- C:\Users\Tom\AppData\Roaming\{90140011-0066-0407-0000-0000000FF1CE} [2012/08/22 15:23:13 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
06.09.2012, 11:41 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Live Security PremiumCode:
ATTFilter OTL by OldTimer - Version 3.2.60.0
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Live Security Premium |
administrator, aktion, anti-malware, appdata, autostart, bösartige, code, dateien, erfolgreich, explorer, gen, live, malwarebytes, microsoft, neu, quarantäne, registrierung, security, service, software, speicher, temp, tmp, version |