![]() |
|
Log-Analyse und Auswertung: Trojaner --> Java/Exploit.CVE-2012-1723.CWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
|
![]() | #1 |
![]() | ![]() Trojaner --> Java/Exploit.CVE-2012-1723.C Hallo Trojaner-Board-Mitglieder, Betriebssystem: Win7 32bit AntiVirus: ESET Nod32 Antivirus mit Version 5.2.9.12, aktuelle Signaturdatenbank heute morgen habe ich mit ESET Nod32 eine Smartprüfung bei dem Laptop meiner Freundin gemacht (Root, Arbeitsspeicher, C:/), dabei hat er 2 Infizierungen gefunden (siehe ESET Log) Ursache und Dauer der Infizierung: Die Ursache, woher der Virus kommen könnte, ist für mich nicht eindeutig. Ich hatte heute morgen aus Versehen eine "falsche" Amazon E-Mail über die GMX-Webseite aufgemacht, jedoch dort nichts angeklickt und gleich gelöscht. Deswegen hatte ich routinemäßig das AntiVirus angeschmissen, wo er die Infizierungen gefunden hatte. Ob jedoch die Mail in direktem Zusammenhang zu der Infizierung steht, ist für mich unklar, weswegen die Dauer der Infizierung stark variieren kann. Symptome: Der Laptop zeigt keine Symptome bzw. bemerke ich nichts außergewöhnliches, aber wie ihr auch schreibt, das heißt ja nicht, dass der Laptop sauber ist. Welche Schritte habe ich schon getätigt?: ESET hat die 2 Infizierungen entfernt und dementsprechend sind sie noch in der Quarantäne. Das Log ist gleich unter dem Absatz. Weitere eigenständige Schritte (außer vorsorglich wichtige Passwörter ändern) habe ich nicht unternommen. Log ESET Nod32 Smartprüfung Code:
ATTFilter Log Version der Signaturdatenbank: 7552 (20121005) Datum: 06.10.2012 Uhrzeit: 08:25:11 Geprüfte Laufwerke, Ordner und Dateien: Arbeitsspeicher;Bootsektor;C:\Bootsektor;C:\ C:\hiberfil.sys - Fehler beim Öffnen [4] C:\pagefile.sys - Fehler beim Öffnen [4] C:\$Recycle.Bin\S-1-5-21-2411468370-942828688-1296837544-1000\$RGR4A0R.rar = RAR = sof-tbbt.s05e13.avi - Teildatei des gesplitteten Archivs nicht gefunden C:\$Recycle.Bin\S-1-5-21-2411468370-942828688-1296837544-1000\$RJ9S4TI.rar = RAR = sof-tbbt.s05e15.avi - Teildatei des gesplitteten Archivs nicht gefunden C:\$Recycle.Bin\S-1-5-21-2411468370-942828688-1296837544-1000\$RPZ5MRL.rar = RAR = sof-tbbt.s05e17.avi - Teildatei des gesplitteten Archivs nicht gefunden C:\$Recycle.Bin\S-1-5-21-2411468370-942828688-1296837544-1000\$RW6PG1D.rar = RAR = sof-tbbt.s05e14.avi - Teildatei des gesplitteten Archivs nicht gefunden C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\ProPsWW.cab = CAB = HIRING_REQUISITION_CUSTOMIZED.FDT = MIME - - OK (eingebettete Archive NICHT geprüft) C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\ProPsWW.cab = CAB = PROCESS_LIBRARY.FDT = MIME - - OK (eingebettete Archive NICHT geprüft) C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\ProPsWW.cab = CAB = TRACK_ISSUES.FDT = MIME - - OK (eingebettete Archive NICHT geprüft) C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\ProPsWW2.cab = CAB = HIRING_REQUISITION.FDT = MIME - - OK (eingebettete Archive NICHT geprüft) C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\ProPsWW2.cab = CAB = POLICIES.FDT = MIME - - OK (eingebettete Archive NICHT geprüft) C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms\FormsTemplates\POLICIES.FDT = MIME - - OK (eingebettete Archive NICHT geprüft) C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\6\78\1E47Ed01 = GZIP = 1E47Ed01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\6\7D\B116Bd01 = GZIP = B116Bd01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\7\2A\D1C30d01 = GZIP = D1C30d01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\7\A6\76262d01 = CWS = file.swf - Archiv beschädigt - Datei kann nicht extrahiert werden C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\A\4C\A708Ed01 = GZIP = A708Ed01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\A\FB\36925d01 = GZIP = 36925d01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\C\6D\2F077d01 = GZIP = 2F077d01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\D\60\D8E45d01 = GZIP = D8E45d01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Mozilla\Firefox\Profiles\ag29r8e1.default\Cache.Trash29005\E\2E\F507Cd01 = GZIP = F507Cd01 - Fehler beim Lesen des Archivs C:\Users\***\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe = CAB = jusched - Archiv beschädigt - Datei kann nicht extrahiert werden C:\Users\***\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe = CAB = task.xml - Archiv beschädigt - Datei kann nicht extrahiert werden C:\Users\***\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe = CAB = task64.xml - Archiv beschädigt - Datei kann nicht extrahiert werden C:\Users\***\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78f1f6d0-26dbbe84 = ZIP = C2.class - Java/Exploit.CVE-2012-1723.C Trojaner C:\Users\***\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78f1f6d0-26dbbe84 = ZIP = C3.class - Variante von Java/Exploit.CVE-2012-1723.C Trojaner C:\Users\***\Downloads\codeblocks-10.05mingw-setup.exe = NSIS = cb_share_config.exe - - OK C:\Users\***\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78f1f6d0-26dbbe84 = ZIP = C2.class - Java/Exploit.CVE-2012-1723.C Trojaner - war Teil des gelöschten Objekts C:\Users\***\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78f1f6d0-26dbbe84 = ZIP = C3.class - Variante von Java/Exploit.CVE-2012-1723.C Trojaner - war Teil des gelöschten Objekts Geprüfte Objekte: 182157 Erkannte Bedrohungen: 2 Anzahl gesäuberter Objekte: 2 Abgeschlossen: 09:48:01 Benötigte Zeit: 4970 Sek. (01:22:50) Hinweise: [4] Objekt kann nicht geöffnet werden. Möglicherweise in Benutzung durch eine andere Anwendung oder das Betriebssystem. ![]() Überblick über das System: 1. Mit defogger wurde "disabled" 2. Log OTL Code:
ATTFilter OTL logfile created on: 06.10.2012 14:47:09 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\***\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 66,60% Memory free 3,98 Gb Paging File | 3,15 Gb Available in Paging File | 79,23% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,10 Gb Total Space | 50,49 Gb Free Space | 34,10% Space Free | Partition Type: NTFS Drive D: | 73,07 Gb Total Space | 17,87 Gb Free Space | 24,45% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.10.06 14:45:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe PRC - [2012.08.31 16:02:02 | 002,754,984 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe PRC - [2012.03.24 22:00:34 | 003,246,040 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\CDP\afcdpsrv.exe PRC - [2012.03.07 15:40:34 | 000,913,144 | ---- | M] (ESET) -- C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe PRC - [2012.03.07 15:40:28 | 003,117,344 | ---- | M] (ESET) -- C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe PRC - [2011.09.16 16:51:28 | 000,671,552 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe PRC - [2011.09.16 16:48:46 | 001,526,080 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe PRC - [2011.08.01 15:56:42 | 001,821,576 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliPoint\ipoint.exe PRC - [2011.06.29 17:22:02 | 002,468,168 | ---- | M] (O&O Software GmbH) -- C:\Programme\OO Software\Defrag\oodag.exe PRC - [2011.05.25 00:18:08 | 000,395,344 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedhlp.exe PRC - [2011.05.25 00:18:02 | 000,805,032 | ---- | M] (Acronis) -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe PRC - [2011.05.25 00:17:06 | 005,587,608 | ---- | M] (Acronis) -- C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 04:17:58 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 04:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.11.20 04:17:42 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2010.02.09 16:43:16 | 002,621,440 | R--- | M] (Brother Industries, Ltd.) -- C:\Programme\Browny02\Brother\BrStMonW.exe PRC - [2010.01.25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Programme\Browny02\BrYNSvc.exe PRC - [2009.10.26 14:46:54 | 001,458,176 | ---- | M] (Motorola Inc.) -- C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe ========== Modules (No Company Name) ========== MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll MOD - [2011.05.25 00:16:26 | 011,204,288 | ---- | M] () -- C:\Programme\Acronis\TrueImageHome\Common\ti_managers.dll MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF MOD - [2009.02.27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Programme\Brother\BrUtilities\BrLogAPI.dll ========== Services (SafeList) ========== SRV - [2012.09.09 15:51:04 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.08.31 16:02:02 | 002,754,984 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2012.03.24 22:00:34 | 003,246,040 | ---- | M] (Acronis) [Auto | Running] -- C:\Programme\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) SRV - [2012.03.07 15:40:34 | 000,913,144 | ---- | M] (ESET) [Auto | Running] -- C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn) SRV - [2011.09.16 16:48:46 | 001,526,080 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2011.09.16 16:44:28 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp) SRV - [2011.06.29 17:22:02 | 002,468,168 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\Programme\OO Software\Defrag\oodag.exe -- (OODefragAgent) SRV - [2011.06.12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.05.25 00:18:02 | 000,805,032 | ---- | M] (Acronis) [Auto | Running] -- C:\Programme\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2010.11.20 04:17:58 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.01.25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Programme\Browny02\BrYNSvc.exe -- (BrYNSvc) SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2003.04.18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\srvany.exe -- (KMService) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - [2012.03.24 22:00:35 | 000,167,968 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\afcdp.sys -- (afcdp) DRV - [2012.03.24 22:00:31 | 000,752,128 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tdrpm273.sys -- (tdrpman273) DRV - [2012.03.24 22:00:29 | 000,600,928 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\timntr.sys -- (timounter) DRV - [2012.03.24 22:00:23 | 000,170,528 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\snapman.sys -- (snapman) DRV - [2012.03.14 08:40:02 | 000,169,080 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm) DRV - [2012.03.14 08:40:02 | 000,120,152 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv) DRV - [2012.03.14 08:40:02 | 000,103,112 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfpr.sys -- (epfwwfpr) DRV - [2011.10.02 19:35:47 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011.06.06 16:03:54 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2010.11.20 04:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 04:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 04:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 02:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 02:21:16 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010.11.20 01:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 01:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 01:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.10.26 15:09:06 | 001,095,936 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.google.de" FF - prefs.js..extensions.enabledAddons: exify@dev13.version:1.2 FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35 FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.6 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.09 15:51:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012.06.11 16:33:04 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.09 15:51:04 | 000,000,000 | ---D | M] [2011.10.02 20:00:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2012.09.26 19:55:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\ag29r8e1.default\extensions [2012.07.19 15:26:45 | 000,010,220 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\ag29r8e1.default\extensions\exify@dev13.version.xpi [2012.09.26 19:55:31 | 000,529,316 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\ag29r8e1.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012.07.25 20:14:16 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\ag29r8e1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011.10.26 21:02:19 | 000,002,321 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\ag29r8e1.default\searchplugins\dictcc.xml [2012.09.24 11:11:16 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.09.09 15:51:01 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012.09.24 11:11:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012.09.24 11:11:16 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012.09.09 15:51:04 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.09.29 03:24:37 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.08.31 19:36:34 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.09.29 03:24:37 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.09.29 03:24:37 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.09.29 03:24:37 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.09.29 03:24:37 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation) O4 - HKLM..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C8C8976-08FC-47A3-8DB5-8A7EE292395D}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (OODBS) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.10.06 14:45:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2012.10.03 14:41:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader [2012.09.30 17:42:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\codeblocks [2012.09.30 17:42:23 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks [2012.09.30 17:42:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks [2012.09.30 17:42:21 | 000,000,000 | ---D | C] -- C:\Program Files\CodeBlocks [2012.09.16 19:04:30 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Auto [2012.09.09 16:05:38 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Bestellung [2012.09.09 15:51:00 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox ========== Files - Modified Within 30 Days ========== [2012.10.06 14:45:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2012.10.06 14:24:47 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable [2012.10.06 14:24:32 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.06 14:24:32 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.06 14:22:40 | 000,050,477 | ---- | M] () -- C:\Users\***\Desktop\Defogger.exe [2012.10.06 14:19:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.06 14:19:21 | 1603,084,288 | -HS- | M] () -- C:\hiberfil.sys [2012.10.06 14:19:21 | 000,576,752 | ---- | M] () -- C:\Windows\System32\oodbs.lor [2012.10.03 15:55:57 | 386,625,535 | ---- | M] () -- C:\THE_IDES_OF_MARCH.ISO [2012.10.03 14:41:05 | 000,001,096 | ---- | M] () -- C:\Users\Public\Desktop\Foxit Reader.lnk [2012.09.30 12:27:51 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.09.30 12:27:51 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.09.30 12:27:51 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.09.30 12:27:51 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.09.25 17:24:56 | 000,856,104 | R--- | M] () -- C:\Users\***\Desktop\TB396A-BoardingPass.pdf [2012.09.23 18:15:15 | 001,049,024 | ---- | M] () -- C:\Users\***\Desktop\Gliederung.jpg [2012.09.23 18:13:55 | 003,428,646 | ---- | M] () -- C:\Users\***\Desktop\Deckblatt.jpg [2012.09.09 19:18:18 | 000,025,214 | ---- | M] () -- C:\Users\***\Desktop\fcb_bestellung.pdf ========== Files Created - No Company Name ========== [2012.10.06 14:24:47 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable [2012.10.06 14:22:38 | 000,050,477 | ---- | C] () -- C:\Users\***\Desktop\Defogger.exe [2012.10.03 15:19:54 | 386,625,535 | ---- | C] () -- C:\THE_IDES_OF_MARCH.ISO [2012.10.03 14:41:05 | 000,001,096 | ---- | C] () -- C:\Users\Public\Desktop\Foxit Reader.lnk [2012.09.25 17:24:57 | 000,856,104 | R--- | C] () -- C:\Users\***\Desktop\TB396A-BoardingPass.pdf [2012.09.23 18:15:15 | 001,049,024 | ---- | C] () -- C:\Users\***\Desktop\Gliederung.jpg [2012.09.23 18:13:55 | 003,428,646 | ---- | C] () -- C:\Users\***\Desktop\Deckblatt.jpg [2012.09.09 19:18:31 | 000,025,214 | ---- | C] () -- C:\Users\***\Desktop\fcb_bestellung.pdf [2012.07.23 20:22:23 | 000,007,302 | ---- | C] () -- C:\Users\***\AppData\Local\recently-used.xbel [2012.07.05 19:39:23 | 000,000,050 | ---- | C] () -- C:\Windows\System32\BRIDF10A.DAT [2012.04.07 10:48:47 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Transportation [2012.04.07 10:48:47 | 000,000,268 | RH-- | C] () -- C:\Users\***\AppData\Roaming\Textures [2012.04.07 10:48:47 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLck.DAT [2012.04.07 10:48:44 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Treble Reduction [2012.04.07 10:48:44 | 000,000,268 | RH-- | C] () -- C:\Users\***\AppData\Roaming\Themes [2012.04.07 10:17:02 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLbx.DAT [2011.10.03 08:42:02 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI [2011.10.03 08:42:02 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI [2011.10.03 07:41:04 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf07a.dat [2011.10.02 20:17:22 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll [2011.10.02 19:55:27 | 000,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll [2011.10.02 19:48:01 | 000,008,192 | ---- | C] () -- C:\Windows\System32\srvany.exe [2011.10.02 12:22:48 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.10.02 12:22:42 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2011.06.10 06:34:52 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 04:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012.04.06 17:18:36 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Acronis [2012.03.24 22:00:36 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\CE4C3F7E-6E0C-4CF9-B52A-AD3311C51236 [2011.10.02 19:38:50 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DAEMON Tools Lite [2012.03.13 20:50:37 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\elsterformular [2012.09.20 15:51:57 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Foxit Software [2012.02.21 21:59:15 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\GetRightToGo [2012.05.24 20:09:45 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Mp3tag [2012.04.07 10:48:52 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Nikon [2011.12.19 19:45:34 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\TeamViewer [2011.10.02 21:39:48 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\TuneUp Software ========== Purity Check ========== < End of report > Code:
ATTFilter OTL Extras logfile created on: 06.10.2012 14:47:09 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\***\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,99 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 66,60% Memory free 3,98 Gb Paging File | 3,15 Gb Available in Paging File | 79,23% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,10 Gb Total Space | 50,49 Gb Free Space | 34,10% Space Free | Partition Type: NTFS Drive D: | 73,07 Gb Total Space | 17,87 Gb Free Space | 24,45% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [CEWE FOTOSCHAU] -- "C:\Program Files\dm\dm-Fotowelt\CEWE FOTOSCHAU.exe" -d "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [dm-Fotowelt] -- "C:\Program Files\dm\dm-Fotowelt\dm-Fotowelt.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3AC9B025-B383-488B-94CE-1D39F49211C8}" = rport=10243 | protocol=6 | dir=out | app=system | "{57AA19CB-CBEE-4457-9798-01E5B4BB8667}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner | "{58ABEA73-8A4A-4100-BF71-16F59BFD6CDD}" = lport=2869 | protocol=6 | dir=in | app=system | "{79DBEEDE-CA87-4451-8601-FD418F307CC8}" = lport=10243 | protocol=6 | dir=in | app=system | "{8FC19C96-53EA-4D50-9F8D-CB61DBD4905B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{98680BD8-5426-4FD9-88A7-AE4C702F15E8}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A0FC3055-B3CD-482E-B880-971D88E991D5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BBCE81E4-84D9-442B-8D8D-6D2BA4C83F4A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BBE7778E-182F-4FF4-8E5D-7AF9316C42E6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F8BC0797-4A6B-4823-9676-CE0AB23014EF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1E8D7B86-90D5-4E0F-9EBE-EB438782C9BB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{38A23086-DBB9-46F2-B4C1-0043C4A6A48D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{608BCEDE-BE9A-4725-9542-5BB3322DAF67}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe | "{6E0FF128-F9FE-420C-8979-61585DF8122F}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{713FEA0B-C924-45B5-BAC5-9AFE17A8819E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{79BE94F0-A224-4192-BD25-042A7805DEFD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{86E3C38A-7041-45A0-958E-B1BE82C6C3C6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{87A20072-1C0B-4D3B-83C2-DB75A6F4C7E7}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe | "{93D43748-AB8C-461C-80EB-390A2A4BC420}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{95A01875-A2FD-4C32-8647-1B877CF0F102}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe | "{A7036870-5F76-47AA-936C-115138F90553}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{AC136669-8BC4-4511-AA0E-1D6B3A5E9A39}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{ADDAAF59-2E47-4557-8E02-1396055408EF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{B8B9CA8D-67CF-43B3-8CBC-FB5BED814C99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{BEE41BA9-2FF5-4A5F-81F5-2AD6BA86D448}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D3C6FB77-DCE3-401F-BFE1-E917DA90E1A7}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe | "{EDF221EF-9AD3-4A4A-87BD-8C18879ED36E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F164A5ED-313F-4ED5-AD0F-017A1D8E2A01}" = protocol=6 | dir=out | app=system | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}" = Acronis*True*Image*Home 2011 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011 "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10 "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 35 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{486C6400-78D7-47A5-B715-6828B4A4759D}" = ESET NOD32 Antivirus "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE) "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10 "{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUS_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUS_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUS_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = Brother MFL-Pro Suite DCP-357C "{A6BA9745-45AC-4FB1-87FF-FF4DADDC8195}" = O&O Defrag Professional "{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10 "{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FB83EAC4-E3F6-4666-B45B-44522F2344B6}" = Brother MFL-Pro Suite DCP-J315W "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Capture NX 2" = Capture NX 2 "CutePDF Writer Installation" = CutePDF Writer 2.8 "DAEMON Tools Lite" = DAEMON Tools Lite "dm-Fotowelt" = dm-Fotowelt "DVD Flick_is1" = DVD Flick 1.3.0.7 "DVD Shrink_is1" = DVD Shrink 3.2 "ElsterFormular 13.1.1.8479p" = ElsterFormular "Foxit Reader_is1" = Foxit Reader "GIMP-2_is1" = GIMP 2.8.0 "HDMI" = Intel(R) Graphics Media Accelerator Driver "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2 "Mozilla Firefox 15.0 (x86 de)" = Mozilla Firefox 15.0 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Mp3tag" = Mp3tag v2.51 "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "SMSERIAL" = Motorola SM56 Speakerphone Modem "TeamViewer 7" = TeamViewer 7 "TuneUp Utilities 2011" = TuneUp Utilities 2011 "TVWiz" = Intel(R) TV Wizard "VLC media player" = VLC media player 2.0.0 "WinRAR archiver" = WinRAR 4.01 (32-Bit) ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "CodeBlocks" = CodeBlocks "Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de) ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 06.10.2012 08:49:35 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:49:35.546]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:50:10 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:50:10.771]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:50:45 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:50:45.996]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:51:21 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:51:21.221]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:51:56 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:51:56.445]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:52:31 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:52:31.670]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:53:06 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:53:06.895]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:53:42 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:53:42.120]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:54:17 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:54:17.345]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error Error - 06.10.2012 08:54:52 | Computer Name = ***-PC | Source = Brother BrLog | ID = 1001 Description = STI BrtSTI: [2012/10/06 14:54:52.570]: [00001932]: GetDeviceIpAddress: GetAddressByName [BRW0022589008EB] Error [ System Events ] Error - 09.06.2012 08:39:00 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error - 09.06.2012 08:39:00 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error - 09.06.2012 08:39:01 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error - 11.06.2012 10:33:22 | Computer Name = ***-PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 17.06.2012 14:33:04 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error - 17.06.2012 14:33:05 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error - 17.06.2012 14:33:06 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error - 01.07.2012 12:06:34 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error - 01.07.2012 12:06:35 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error - 01.07.2012 12:06:35 | Computer Name = ***-PC | Source = Disk | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. < End of report > Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-10-06 16:06:30 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 WDC_WD2500BEVS-22UST0 rev.01.01A01 Running: 4bubqbt3.exe; Driver: C:\Users\***\AppData\Local\Temp\pwdiqpob.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwCreateThread [0x907097F0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwLoadDriver [0x907098B0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSystemInformation [0x90709870] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSystemDebugControl [0x90709830] ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82A7A3C9 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AB3D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 1203 82ABAEB8 4 Bytes [F0, 97, 70, 90] .text ntkrnlpa.exe!KeRemoveQueueEx + 1313 82ABAFC8 4 Bytes [B0, 98, 70, 90] {MOV AL, 0x98; JO 0xffffffffffffff94} .text ntkrnlpa.exe!KeRemoveQueueEx + 161F 82ABB2D4 4 Bytes [70, 98, 70, 90] {JO 0xffffffffffffff9a; JO 0xffffffffffffff94} .text ntkrnlpa.exe!KeRemoveQueueEx + 1667 82ABB31C 4 Bytes [30, 98, 70, 90] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1732] kernel32.dll!SetUnhandledExceptionFilter 772DF4FB 4 Bytes [C2, 04, 00, 00] .text C:\Program Files\OO Software\Defrag\oodag.exe[1824] kernel32.dll!SetUnhandledExceptionFilter 772DF4FB 5 Bytes JMP 00402FB0 C:\Program Files\OO Software\Defrag\oodag.exe (O&O Defrag Agent (Win32)/O&O Software GmbH) ---- Devices - GMER 1.0.15 ---- Device Ntfs.sys (NT-Dateisystemtreiber/Microsoft Corporation) AttachedDevice tdrpm273.sys (Acronis Try&Decide Volume Filter Driver/Acronis) Device \Driver\ACPI_HAL \Device\00000049 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) Device volmgr.sys (Volume Manager Driver/Microsoft Corporation) AttachedDevice fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG14.00.00.01PROFESSIONAL AFF6D9426865C1876150D7A4396BA07DA3A8D8D42658B4E9436D968C5354B0267070FB84B13A06DAAE14834F72B2918757D62E858C9DCDD0A02302B7D8D02920C2F71F3CB0A7D716215862452CD7C1480E931549E0277C54935934BCBE5F56BF581CBD1B74226F278947953AE57F6542D8C57AFA31E58C2D0FD003BC465DBE92281AB5A38E96AC147E3E27B82340540E9187ADC9113EF0A94C8328A9B21D8B3B68EA49B1136214715B4F7F9EE8288AD852A66439198A3CAAC79BC04CCC640BEE19B2206F1D594A6BBBBE701EC33528617AA7351FE39629A5BFF84E4162EC307A79D0435F49C21CC08408AB3BC05C71FD2C3F9EA512A393FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C90994180F3D6C2113B5C3E209BE72901BAD639DD681082818E40754E983445335FA33BBA5641EA7D7DE6639263AED4D2B2D1A77511159576DF2F46BA87D6EED9737C7B9D61543C832528BDE78FB2930F075EDCBD9536C92F68695CE590A239D0031DAFB31135E4417C5BB97341AC5D6ABB1AA2F5DD5A8599FE0C7F97015096DED8C3406CB910827565FDFAEDEF5620BD63657BBCA66F23C68EF7ABF8791E6EEED473C51CFD122C8353D4D67266EF3C0629E2991A7D64F0EE9 ---- EOF - GMER 1.0.15 ---- ![]() Grüße bootsie |
Themen zu Trojaner --> Java/Exploit.CVE-2012-1723.C |
antivirus, application/pdf:, autorun, bho, defender, document, e-mail, eigenständige, error, eset nod32, explorer, fehler, firefox, flash player, format, helper, install.exe, installation, log, logfile, mozilla, mp3, plug-in, programme, recycle.bin, registry, rundll, scan, security, software, svchost.exe, trojaner, ändern |