|
Log-Analyse und Auswertung: lumviexdopag.exe - Trojaner?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.10.2012, 15:19 | #1 |
| lumviexdopag.exe - Trojaner? Guten Tag, ich habe seit ein paar Tagen vermutlich einen Trojaner auf dem PC, der sich unter dem Namen lumviexdopag.exe verbirgt, eine ausführbare Datei also. Wenn ich den PC hochfahre, fragt Windows, ob lumviexdopag.exe ausgeführt werden soll. "Abbrechen" kann nicht angeklickt werden. Seit dem ist das Sicherheitscenter standardmäßig deaktiviert und kann nicht wieder eingeschaltet werden. Ich bekomme beim runterfahren auch häufiger (aber nicht immer) einen Bluescreen. Ich hab die lumviexdopag.exe auch bei virustotal.com analysieren lassen: https://www.virustotal.com/file/c7ac43bc8385b47fb3c9d6870f15bf769634df6862e148fefe10de2dd99854fd/analysis/1350217734/ Die entsprechenden Logfiles habe ich angehängt. Was kann ich tun? |
16.10.2012, 15:44 | #2 |
/// TB-Ausbilder | lumviexdopag.exe - Trojaner?Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen. Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Dies garantiert, dass Du Hilfe von einem ausgebildeten Helfer bekommst. Ich bedanke mich für deine Geduld
__________________ |
16.10.2012, 16:11 | #3 | |||
/// TB-Ausbilder | lumviexdopag.exe - Trojaner?Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Warnung: Registry-Cleaner
Schritt 1: Fix mit OTL
Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen Schritt 3: Kontrollscan mit OTL
__________________ |
16.10.2012, 17:14 | #4 |
| lumviexdopag.exe - Trojaner? Vielen Dank, ryder, für deine Hilfe! Dies ist das Ergebnis von Schritt 1: Code:
ATTFilter All processes killed ========== OTL ========== No active process named lumivexdopag.exe was found! No active process named lumivexdopag.exe was found! Error: No service named f4330dc14e93e30a was found to stop! Service\Driver key f4330dc14e93e30a not found. File C:\Windows\System32\drivers\f4330dc14e93e30a.sys not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\lumivexdopag deleted successfully. C:\ProgramData\lumivexdopag.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lumivexdopag deleted successfully. C:\Users\***\lumivexdopag.exe moved successfully. File C:\Users\***\lumivexdopag.exe not found. File C:\ProgramData\lumivexdopag.exe not found. File C:\ProgramData\lumivexdopag.exe not found. File C:\Users\***\lumivexdopag.exe not found. File C:\Windows\System32\drivers\f4330dc14e93e30a.sys not found. File move failed. C:\ProgramData\69p20cfih3.exe scheduled to be moved on reboot. File move failed. C:\Users\***\69p20cfih3.exe scheduled to be moved on reboot. C:\Users\***\AppData\Local\s3VsuXj31mV7R moved successfully. ADS C:\Windows:33CDFA6762F1E0FD deleted successfully. ADS C:\ProgramData\TEMP:F768B6EF deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: lukas ->Temp folder emptied: 27286531 bytes ->Temporary Internet Files folder emptied: 7899107 bytes ->Java cache emptied: 15924558 bytes ->FireFox cache emptied: 940722080 bytes ->Flash cache emptied: 3174 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 5928284 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 952,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10162012_173344 Files\Folders moved on Reboot... File move failed. C:\ProgramData\69p20cfih3.exe scheduled to be moved on reboot. File move failed. C:\Users\lukas\69p20cfih3.exe scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter # AdwCleaner v2.005 - Datei am 16/10/2012 um 18:16:19 erstellt # Aktualisiert am 14/10/2012 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium (32 bits) # Benutzer : *** - ***-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\***\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\***\Documents\Uninstall.exe Ordner Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\q6thin34.default\extensions\vshare@toolbar ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} ***** [Internet Browser] ***** -\\ Internet Explorer v7.0.6000.17037 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v15.0.1 (de) Profilname : default Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\q6thin34.default\prefs.js Gelöscht : user_pref("vshare.install.date", "1285632000000"); Gelöscht : user_pref("vshare.install.finished", "1.0.0"); Gelöscht : user_pref("vshare.install.guid", "{35898eda-0cd4-4eda-a662-ef90a9d71736}"); Gelöscht : user_pref("vshare.install.isDisabled", true); Gelöscht : user_pref("vshare.install.laststatreq", "1300147200000"); Gelöscht : user_pref("vshare.install.newtab", false); ************************* AdwCleaner[S1].txt - [1517 octets] - [16/10/2012 18:16:19] ########## EOF - C:\AdwCleaner[S1].txt - [1577 octets] ########## Code:
ATTFilter OTL logfile created on: 16.10.2012 18:33:59 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = c:\Users\***\Downloads Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.17037) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 63,15% Memory free 4,23 Gb Paging File | 3,36 Gb Available in Paging File | 79,54% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 303,35 Gb Total Space | 51,33 Gb Free Space | 16,92% Space Free | Partition Type: NTFS Drive D: | 150,69 Gb Total Space | 150,60 Gb Free Space | 99,94% Space Free | Partition Type: NTFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.10.16 15:12:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- c:\Users\***\Downloads\OTL.exe PRC - [2012.10.13 15:02:52 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012.08.11 11:45:55 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.08 15:48:51 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2010.07.09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010.03.24 19:50:00 | 002,516,296 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE PRC - [2010.03.02 20:52:00 | 000,140,640 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe PRC - [2009.08.30 20:55:58 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2009.05.27 10:07:48 | 002,230,024 | ---- | M] () -- C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe PRC - [2009.05.07 02:01:00 | 001,904,640 | ---- | M] (AVM Berlin) -- C:\Program Files\avmwlanstick\WLanGUI.exe PRC - [2009.05.07 02:01:00 | 000,368,640 | ---- | M] (AVM Berlin) -- C:\Program Files\avmwlanstick\WlanNetService.exe PRC - [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2007.09.03 18:39:22 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe ========== Modules (No Company Name) ========== MOD - [2012.10.13 15:02:51 | 002,294,240 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll ========== Services (SafeList) ========== SRV - [2012.10.14 16:17:25 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012.10.13 15:02:51 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.17 19:33:18 | 000,069,832 | ---- | M] () [Unknown (-1) | Unknown] -- C:\Windows\System32\drivers\f4330dc14e93e30a.sys -- (f4330dc14e93e30a) SRV - [2012.05.08 15:48:51 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.08 15:48:50 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010.07.09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2009.08.24 14:47:07 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc) SRV - [2009.05.27 10:07:48 | 002,230,024 | ---- | M] () [Auto | Running] -- C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe -- (ClipInc001) SRV - [2009.05.07 02:01:00 | 000,368,640 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2005.11.17 16:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2012.05.17 19:33:18 | 000,069,832 | ---- | M] () [Unknown (-1) | Unknown (-1) | Unknown] -- C:\Windows\System32\drivers\f4330dc14e93e30a.sys -- (f4330dc14e93e30a) DRV - [2012.05.08 15:48:51 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.08 15:48:51 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.09.16 17:08:07 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.07.10 00:37:00 | 011,008,040 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\nvlddmkm.sys -- (nvlddmkm) DRV - [2010.02.23 13:30:59 | 000,211,968 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb10.sys -- (mrxsmb10) DRV - [2010.02.23 13:30:53 | 000,058,368 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb20.sys -- (mrxsmb20) DRV - [2010.02.23 13:30:49 | 000,102,912 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb.sys -- (mrxsmb) DRV - [2010.02.20 23:30:16 | 000,396,800 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HTTP.sys -- (HTTP) DRV - [2010.02.18 14:04:38 | 000,025,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\tunnel.sys -- (tunnel) DRV - [2010.02.18 14:04:30 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\tunmp.sys -- (tunmp) DRV - [2010.02.18 13:51:51 | 000,818,688 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\tcpip.sys -- (Tcpip6) DRV - [2010.02.18 13:51:51 | 000,818,688 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\tcpip.sys -- (Tcpip) DRV - [2009.12.11 14:01:24 | 000,307,200 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srv.sys -- (srv) DRV - [2009.12.11 14:01:06 | 000,084,992 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srvnet.sys -- (srvnet) DRV - [2009.11.04 19:08:32 | 000,278,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2009.11.04 19:08:31 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\lirsgt.sys -- (lirsgt) DRV - [2009.10.08 17:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.09.14 11:50:54 | 000,130,048 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srv2.sys -- (srv2) DRV - [2009.06.16 01:20:33 | 000,408,136 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecdd.sys -- (KSecDD) DRV - [2009.05.05 22:36:34 | 000,025,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\hamachi.sys -- (hamachi) DRV - [2008.07.30 07:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11) DRV - [2008.02.14 09:25:03 | 000,110,080 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mrxdav.sys -- (MRxDAV) DRV - [2008.02.14 09:23:38 | 000,495,160 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Wdf01000.sys -- (Wdf01000) DRV - [2008.02.14 09:23:37 | 000,054,784 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\i8042prt.sys -- (i8042prt) DRV - [2008.02.14 09:23:37 | 000,035,384 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\kbdclass.sys -- (kbdclass) DRV - [2008.02.14 09:23:37 | 000,034,360 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\mouclass.sys -- (mouclass) DRV - [2008.02.14 09:23:37 | 000,019,968 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sermouse.sys -- (sermouse) DRV - [2008.02.14 09:23:37 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mouhid.sys -- (mouhid) DRV - [2008.02.14 09:23:37 | 000,015,872 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\kbdhid.sys -- (kbdhid) DRV - [2008.02.14 09:22:05 | 000,211,000 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volsnap.sys -- (volsnap) DRV - [2008.02.14 09:22:05 | 000,017,976 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\intelide.sys -- (intelide) DRV - [2008.02.14 09:22:04 | 000,154,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\nwifi.sys -- (NativeWifiP) DRV - [2007.12.20 02:04:00 | 000,265,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\fwlanusb.sys -- (FWLANUSB) DRV - [2007.12.20 02:04:00 | 000,004,352 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avmeject.sys -- (avmeject) DRV - [2007.12.17 00:52:59 | 001,061,944 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\ntfs.sys -- (Ntfs) DRV - [2007.12.16 11:50:45 | 000,041,984 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\monitor.sys -- (monitor) DRV - [2007.10.22 21:19:54 | 000,193,536 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbhub.sys -- (usbhub) DRV - [2007.10.22 21:19:53 | 000,073,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbccgp.sys -- (usbccgp) DRV - [2007.10.22 21:19:53 | 000,038,400 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbehci.sys -- (usbehci) DRV - [2007.10.22 21:19:53 | 000,023,040 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbuhci.sys -- (usbuhci) DRV - [2007.10.22 20:33:31 | 000,184,320 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\netbt.sys -- (netbt) DRV - [2007.10.22 20:32:21 | 000,048,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ndproxy.sys -- (NDProxy) DRV - [2007.10.22 20:32:21 | 000,020,480 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndistapi.sys -- (NdisTapi) DRV - [2007.10.22 20:32:20 | 000,061,952 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\wanarp.sys -- (Wanarpv6) DRV - [2007.10.22 20:32:20 | 000,061,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\wanarp.sys -- (Wanarp) DRV - [2007.10.22 20:32:19 | 000,070,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\pacer.sys -- (PSched) DRV - [2007.10.22 20:22:17 | 000,143,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pci.sys -- (pci) DRV - [2007.10.22 20:22:17 | 000,053,432 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\termdd.sys -- (TermDD) DRV - [2007.10.22 20:22:17 | 000,052,920 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volmgr.sys -- (volmgr) DRV - [2007.10.22 20:22:17 | 000,031,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mssmbios.sys -- (mssmbios) DRV - [2007.10.22 20:22:17 | 000,016,568 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\msisadrv.sys -- (msisadrv) DRV - [2007.10.22 20:22:17 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\swenum.sys -- (swenum) DRV - [2007.10.22 20:20:17 | 000,070,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\tdx.sys -- (tdx) DRV - [2007.10.22 20:08:20 | 000,055,296 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\USBSTOR.SYS -- (USBSTOR) DRV - [2007.10.22 19:57:35 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\hidusb.sys -- (HidUsb) DRV - [2007.10.22 19:51:43 | 000,063,488 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mpsdrv.sys -- (mpsdrv) DRV - [2007.10.22 19:42:56 | 000,034,816 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\umbus.sys -- (umbus) DRV - [2007.10.22 19:37:22 | 000,061,952 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ohci1394.sys -- (ohci1394) DRV - [2007.10.22 19:30:58 | 000,503,480 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ndis.sys -- (NDIS) DRV - [2007.10.22 19:30:23 | 000,082,688 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\WUDFRd.sys -- (WUDFRd) DRV - [2007.10.22 19:25:01 | 000,225,792 | ---- | M] () [File_System | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\udfs.sys -- (udfs) DRV - [2007.10.22 19:22:26 | 000,066,048 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\smb.sys -- (Smb) DRV - [2007.10.22 19:20:19 | 000,012,800 | ---- | M] () [Recognizer | System | Unknown] -- C:\Windows\System32\drivers\fs_rec.sys -- (Fs_Rec) DRV - [2007.10.22 19:17:48 | 000,074,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\rasl2tp.sys -- (Rasl2tp) DRV - [2007.10.22 19:17:48 | 000,060,928 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\raspptp.sys -- (PptpMiniport) DRV - [2007.08.03 10:44:58 | 000,091,648 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\Rtlh86.sys -- (RTL8169) DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32) DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32) DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID) DRV - [2006.11.02 14:34:31 | 000,031,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qwavedrv.sys -- (QWAVEdrv) DRV - [2006.11.02 11:51:30 | 000,290,408 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volmgrx.sys -- (volmgrx) DRV - [2006.11.02 11:51:14 | 000,183,912 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\System32\drivers\fltmgr.sys -- (FltMgr) DRV - [2006.11.02 11:51:12 | 000,168,552 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\msiscsi.sys -- (iScsiPrt) DRV - [2006.11.02 11:51:12 | 000,167,528 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\pcmcia.sys -- (pcmcia) DRV - [2006.11.02 11:51:09 | 000,160,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msrpc.sys -- (MsRPC) DRV - [2006.11.02 11:50:40 | 000,106,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nv_agp.sys -- (nv_agp) DRV - [2006.11.02 11:50:24 | 000,047,208 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\isapnp.sys -- (isapnp) DRV - [2006.11.02 11:50:24 | 000,046,696 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\System32\Drivers\mup.sys -- (Mup) DRV - [2006.11.02 11:50:23 | 000,049,256 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\partmgr.sys -- (partmgr) DRV - [2006.11.02 11:50:17 | 000,080,488 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\msdsm.sys -- (msdsm) DRV - [2006.11.02 11:50:16 | 000,078,952 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\mpio.sys -- (mpio) DRV - [2006.11.02 11:50:16 | 000,076,392 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sbp2port.sys -- (sbp2port) DRV - [2006.11.02 11:50:04 | 000,058,984 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gagp30kx.sys -- (gagp30kx) DRV - [2006.11.02 11:50:04 | 000,058,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uliagpkx.sys -- (uliagpkx) DRV - [2006.11.02 11:49:59 | 000,056,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uagp35.sys -- (uagp35) DRV - [2006.11.02 11:49:57 | 000,054,888 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mountmgr.sys -- (MountMgr) DRV - [2006.11.02 11:49:52 | 000,054,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\viaagp.sys -- (viaagp) DRV - [2006.11.02 11:49:49 | 000,027,752 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\i2omp.sys -- (i2omp) DRV - [2006.11.02 11:49:44 | 000,023,144 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\msahci.sys -- (msahci) DRV - [2006.11.02 11:49:38 | 000,019,560 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wd.sys -- (Wd) DRV - [2006.11.02 11:49:35 | 000,018,536 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\spldr.sys -- (spldr) DRV - [2006.11.02 11:49:20 | 000,013,416 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\pciide.sys -- (pciide) DRV - [2006.11.02 11:14:58 | 000,018,944 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbprint.sys -- (usbprint) DRV - [2006.11.02 11:04:35 | 000,878,080 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\peauth.sys -- (PEAUTH) DRV - [2006.11.02 11:03:00 | 000,242,688 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\rdpdr.sys -- (rdpdr) DRV - [2006.11.02 11:02:15 | 000,160,256 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpwd.sys -- (RDPWD) DRV - [2006.11.02 11:02:07 | 000,023,552 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\tssecsrv.sys -- (tssecsrv) DRV - [2006.11.02 11:02:01 | 000,028,672 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdtcp.sys -- (TDTCP) DRV - [2006.11.02 11:02:01 | 000,017,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdpipe.sys -- (TDPIPE) DRV - [2006.11.02 11:02:01 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\rdpencdd.sys -- (RDPENCDD) DRV - [2006.11.02 11:02:01 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\RDPCDD.sys -- (RDPCDD) DRV - [2006.11.02 10:58:52 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\modem.sys -- (Modem) DRV - [2006.11.02 10:58:26 | 000,015,872 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2006.11.02 10:58:14 | 000,118,784 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndiswan.sys -- (NdisWan) DRV - [2006.11.02 10:58:13 | 000,011,776 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\rasacd.sys -- (RasAcd) DRV - [2006.11.02 10:58:12 | 000,041,472 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\raspppoe.sys -- (RasPppoe) DRV - [2006.11.02 10:58:09 | 000,099,840 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipnat.sys -- (IPNAT) DRV - [2006.11.02 10:58:04 | 000,047,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipfltdrv.sys -- (IpFilterDriver) DRV - [2006.11.02 10:57:47 | 000,027,648 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tcpipreg.sys -- (tcpipreg) DRV - [2006.11.02 10:57:30 | 000,016,384 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\nsiproxy.sys -- (nsiproxy) DRV - [2006.11.02 10:57:26 | 000,035,840 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\DRIVERS\netbios.sys -- (NetBIOS) DRV - [2006.11.02 10:57:22 | 000,016,896 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndisuio.sys -- (Ndisuio) DRV - [2006.11.02 10:57:04 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\irenum.sys -- (IRENUM) DRV - [2006.11.02 10:56:49 | 000,060,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\rspndr.sys -- (rspndr) DRV - [2006.11.02 10:56:49 | 000,047,104 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\lltdio.sys -- (lltdio) DRV - [2006.11.02 10:55:22 | 000,029,184 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\hidbth.sys -- (HidBth) DRV - [2006.11.02 10:55:09 | 000,068,608 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbcir.sys -- (usbcir) DRV - [2006.11.02 10:55:05 | 000,019,456 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbohci.sys -- (usbohci) DRV - [2006.11.02 10:55:01 | 000,021,504 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\hidir.sys -- (HidIr) DRV - [2006.11.02 10:53:56 | 000,026,112 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\vgapnp.sys -- (vga) DRV - [2006.11.02 10:53:56 | 000,025,088 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\vga.sys -- (VgaSave) DRV - [2006.11.02 10:52:52 | 000,020,608 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wacompen.sys -- (WacomPen) DRV - [2006.11.02 10:51:40 | 000,013,312 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sfloppy.sys -- (sfloppy) DRV - [2006.11.02 10:51:40 | 000,012,800 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sffp_sd.sys -- (sffp_sd) DRV - [2006.11.02 10:51:40 | 000,012,800 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sffp_mmc.sys -- (sffp_mmc) DRV - [2006.11.02 10:51:38 | 000,013,312 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sffdisk.sys -- (sffdisk) DRV - [2006.11.02 10:51:32 | 000,020,480 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\flpydisk.sys -- (flpydisk) DRV - [2006.11.02 10:51:30 | 000,083,456 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\serial.sys -- (Serial) DRV - [2006.11.02 10:51:30 | 000,079,360 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\parport.sys -- (Parport) DRV - [2006.11.02 10:51:25 | 000,017,920 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\serenum.sys -- (Serenum) DRV - [2006.11.02 10:51:23 | 000,008,704 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\parvdm.sys -- (Parvdm) DRV - [2006.11.02 10:51:15 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSKSSRV.sys -- (MSKSSRV) DRV - [2006.11.02 10:51:14 | 000,005,504 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSPQM.sys -- (MSPQM) DRV - [2006.11.02 10:51:13 | 000,006,016 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSTEE.sys -- (MSTEE) DRV - [2006.11.02 10:51:13 | 000,005,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSPCLOCK.sys -- (MSPCLOCK) DRV - [2006.11.02 10:51:05 | 000,004,608 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\null.sys -- (Null) DRV - [2006.11.02 10:42:03 | 000,065,536 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ipmidrv.sys -- (IPMIDRV) DRV - [2006.11.02 10:35:03 | 000,011,264 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wmiacpi.sys -- (WmiAcpi) DRV - [2006.11.02 10:33:07 | 000,083,456 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\System32\drivers\luafv.sys -- (luafv) DRV - [2006.11.02 10:31:26 | 000,222,208 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\DRIVERS\rdbss.sys -- (rdbss) DRV - [2006.11.02 10:30:57 | 000,034,816 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\npfs.sys -- (Npfs) DRV - [2006.11.02 10:30:56 | 000,022,528 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\msfs.sys -- (Msfs) DRV - [2006.11.02 10:30:19 | 000,039,424 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\viac7.sys -- (ViaC7) DRV - [2006.11.02 10:30:18 | 000,039,424 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\intelppm.sys -- (intelppm) DRV - [2006.11.02 10:30:18 | 000,038,400 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\processr.sys -- (Processor) DRV - [2006.11.02 09:36:49 | 000,235,520 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledAddons: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.7 FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.15 FF - prefs.js..extensions.enabledAddons: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.9 FF - prefs.js..extensions.enabledAddons: youtubemp3podcaster@jeremy.d.gregorio.com:2.7.0 FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 44 FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625 FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10 FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.5 FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.22.1 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..network.proxy.http: "70.158.130.207" FF - prefs.js..network.proxy.http_port: 8080 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\***\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.13 15:02:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.13 15:02:46 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.13 15:02:52 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.13 15:02:46 | 000,000,000 | ---D | M] [2008.09.03 22:17:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2012.10.16 18:16:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions [2010.08.04 23:03:17 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2009.09.09 18:04:58 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2008.03.27 18:39:14 | 000,000,000 | ---D | M] ("Bazzacuda Image Saver") -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{FFBC0836-1BCF-4FE5-9B2B-E2E6F53CBDE7} [2012.10.03 16:55:37 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\foxyproxy@eric.h(35).jung [2012.10.11 14:23:39 | 000,000,000 | ---D | M] (Youtube MP3 Podcaster) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\youtubemp3podcaster@jeremy.d.gregorio.com [2011.07.18 16:21:12 | 000,097,169 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi [2012.10.09 18:01:38 | 000,211,935 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2012.09.01 18:03:48 | 000,590,708 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2012.08.11 11:52:51 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012.09.13 22:01:22 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2011.05.07 16:29:08 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2012.10.13 13:34:29 | 000,001,451 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\chipde---forum.xml [2012.10.13 13:34:30 | 000,001,263 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\chipdownloads.xml [2012.10.13 13:34:29 | 000,002,125 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\flickr-tags.xml [2012.10.13 13:34:29 | 000,002,081 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\lautde.xml [2012.10.13 13:34:30 | 000,001,961 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-en.xml [2012.10.13 13:34:30 | 000,001,969 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-es.xml [2012.10.13 13:34:30 | 000,001,973 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-fr.xml [2012.10.13 13:34:29 | 000,000,971 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\onvista.xml [2012.10.13 13:34:29 | 000,001,242 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\plattentestsde-all.xml [2012.07.15 12:47:46 | 000,000,821 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\youtube-deutschland.xml [2012.10.13 15:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.10.13 15:02:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012.10.13 15:02:52 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.07.06 16:24:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.14 23:19:24 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.07.06 16:24:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.07.06 16:24:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.06 16:24:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.06 16:24:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files\avmwlanstick\wlangui.exe (AVM Berlin) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Last.fm Helper.lnk = File not found O7 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data] O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A257D804-4C79-4B59-B390-FDBD44407EE3}: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\***\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{0577b080-5415-11de-9cb1-00040ec99c43}\Shell\AutoRun\command - "" = L:\StartPortableApps.exe O33 - MountPoints2\{12688a14-b54f-11dc-bd6c-00192148fa5f}\Shell - "" = AutoRun O33 - MountPoints2\{12688a14-b54f-11dc-bd6c-00192148fa5f}\Shell\AutoRun\command - "" = L:\pushinst.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012.10.16 17:47:04 | 000,000,000 | ---D | C] -- C:\Users\lukas\Desktop\Neuer Ordner [2012.10.16 17:33:44 | 000,000,000 | ---D | C] -- C:\_OTL [2012.10.13 15:02:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.10.12 16:10:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.10.12 16:10:08 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files - Modified Within 30 Days ========== [2012.10.16 18:30:03 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{AFEFAEC0-F9A3-4BF2-A18C-126AB0F0C32C}.job [2012.10.16 18:22:11 | 000,641,106 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.10.16 18:22:11 | 000,609,944 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.10.16 18:22:11 | 000,116,500 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.10.16 18:22:11 | 000,103,726 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.10.16 18:17:55 | 000,121,741 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012.10.16 18:17:54 | 000,121,741 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012.10.16 18:17:44 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.16 18:17:44 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.16 18:17:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.16 18:17:35 | 2146,754,560 | -HS- | M] () -- C:\hiberfil.sys [2012.10.16 16:16:37 | 000,019,992 | ---- | M] () -- C:\Users\***\Documents\logfiles.zip [2012.10.16 15:01:48 | 169,650,795 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012.10.12 16:10:09 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.09.28 12:40:32 | 000,002,631 | ---- | M] () -- C:\Users\***\Desktop\Microsoft Office Word 2007.lnk [2012.09.19 00:30:57 | 000,098,816 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== Files Created - No Company Name ========== [2012.10.16 16:16:37 | 000,019,992 | ---- | C] () -- C:\Users\***\Documents\logfiles.zip [2012.10.12 16:20:36 | 169,650,795 | ---- | C] () -- C:\Windows\MEMORY.DMP [2012.10.12 16:10:09 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.01 23:44:46 | 000,001,024 | ---- | C] () -- C:\Users\***\Desktop\hbedv.key [2012.05.17 19:33:18 | 000,069,832 | ---- | C] () -- C:\Windows\System32\drivers\f4330dc14e93e30a.sys [2012.05.17 19:32:47 | 000,038,400 | ---- | C] () -- C:\ProgramData\69p20cfih3.exe [2012.05.17 14:51:28 | 000,038,400 | ---- | C] () -- C:\Users\***\69p20cfih3.exe [2012.04.11 14:56:34 | 000,141,021 | ---- | C] () -- C:\Users\***\.recently-used.xbel [2012.03.17 16:27:46 | 000,137,928 | ---- | C] () -- C:\Windows\System32\drivers\avipbb.sys [2012.03.17 16:27:46 | 000,036,000 | ---- | C] () -- C:\Windows\System32\drivers\avkmgr.sys [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2010.08.11 18:25:56 | 000,121,741 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010.08.11 18:25:55 | 000,121,741 | ---- | C] () -- C:\ProgramData\nvModes.dat [2008.09.11 19:05:21 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib [2008.04.09 13:49:05 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat [2008.02.02 13:58:33 | 000,001,356 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2007.12.30 16:10:57 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html [2007.12.29 19:40:15 | 000,098,816 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] "ThreadingModel" = Both "" = shell32.dll -- [2008.11.06 14:59:14 | 011,320,832 | ---- | M] (Microsoft Corporation) [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2008.11.06 14:59:14 | 011,320,832 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = fastprox.dll -- [2009.03.03 06:16:12 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2006.11.02 11:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2009.01.10 16:04:37 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Activision [2008.01.21 18:19:02 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\dBpoweramp [2011.06.12 01:29:40 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.11 14:56:34 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\gtk-2.0 [2012.03.23 18:36:29 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\ICQ [2008.12.10 18:49:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\MAGIX [2010.08.28 17:02:41 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mp3DirectCut [2008.12.12 18:46:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\MP3toiPodAudioBookConverter [2009.01.09 18:26:11 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\ProtectDisc [2011.12.30 00:38:17 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Sports Interactive [2011.11.05 00:58:21 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\temp [2008.09.21 14:51:53 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Tobit [2011.12.12 20:55:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Tropico 3 [2011.12.23 15:26:02 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Ubisoft ========== Purity Check ========== < End of report > Geändert von Fallobst (16.10.2012 um 17:45 Uhr) |
16.10.2012, 19:52 | #5 | ||
/// TB-Ausbilder | lumviexdopag.exe - Trojaner? Okay. Wir probieren das nochmal anders. Schritt 1: Fix mit OTL Schritt 2: Boote in den normalen Modus. Schritt 3: Kontrollscan mit OTL Schritt 4: Scan mit dem TDSS-Killer Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
17.10.2012, 15:20 | #6 |
| lumviexdopag.exe - Trojaner? Mein System ist also noch nicht clean? Ich frage deshalb, weil lumviesdopag.exe nicht mehr da ist. Versteh ich das richtig, dass ich Schritt 1 im abgesicherten Modus ausführen soll? |
17.10.2012, 15:22 | #7 |
/// TB-Ausbilder | lumviexdopag.exe - Trojaner? Es sind noch andere Teile der Infektion vorhanden. Ja bitte im abgesichterten Modus durchführen.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
17.10.2012, 16:00 | #8 |
| lumviexdopag.exe - Trojaner?Code:
ATTFilter ========== OTL ========== Error: No service named f4330dc14e93e30a was found to stop! Service\Driver key f4330dc14e93e30a not found. File move failed. C:\Windows\System32\drivers\f4330dc14e93e30a.sys scheduled to be moved on reboot. Error: No service named f4330dc14e93e30a was found to stop! Service\Driver key f4330dc14e93e30a not found. File move failed. C:\Windows\System32\drivers\f4330dc14e93e30a.sys scheduled to be moved on reboot. File move failed. C:\Windows\System32\drivers\f4330dc14e93e30a.sys scheduled to be moved on reboot. File move failed. C:\ProgramData\69p20cfih3.exe scheduled to be moved on reboot. File move failed. C:\Users\lukas\69p20cfih3.exe scheduled to be moved on reboot. OTL by OldTimer - Version 3.2.69.0 log created on 10172012_164358 Files\Folders moved on Reboot... File\Folder C:\Windows\System32\drivers\f4330dc14e93e30a.sys not found! File move failed. C:\ProgramData\69p20cfih3.exe scheduled to be moved on reboot. File move failed. C:\Users\lukas\69p20cfih3.exe scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter OTL logfile created on: 17.10.2012 16:46:55 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = c:\Users\lukas\Downloads Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.17037) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,16 Gb Available Physical Memory | 58,01% Memory free 4,23 Gb Paging File | 3,37 Gb Available in Paging File | 79,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 303,35 Gb Total Space | 51,48 Gb Free Space | 16,97% Space Free | Partition Type: NTFS Drive D: | 150,69 Gb Total Space | 150,60 Gb Free Space | 99,94% Space Free | Partition Type: NTFS Computer Name: LUKAS-PC | User Name: lukas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.10.16 15:12:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- c:\Users\lukas\Downloads\OTL.exe PRC - [2012.10.13 15:02:52 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012.08.11 11:45:55 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.08 15:48:51 | 000,086,992 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\program files\avira\antivir desktop\ipmGui.exe PRC - [2012.05.08 15:48:51 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2010.07.09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010.03.24 19:50:00 | 002,516,296 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE PRC - [2010.03.02 20:52:00 | 000,140,640 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe PRC - [2009.08.30 20:55:58 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2009.05.27 10:07:48 | 002,230,024 | ---- | M] () -- C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe PRC - [2009.05.07 02:01:00 | 001,904,640 | ---- | M] (AVM Berlin) -- C:\Program Files\avmwlanstick\WLanGUI.exe PRC - [2009.05.07 02:01:00 | 000,368,640 | ---- | M] (AVM Berlin) -- C:\Program Files\avmwlanstick\WlanNetService.exe PRC - [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2007.09.03 18:39:22 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe ========== Modules (No Company Name) ========== MOD - [2012.10.13 15:02:51 | 002,294,240 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll ========== Services (SafeList) ========== SRV - [2012.10.14 16:17:25 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012.10.13 15:02:51 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.05.17 19:33:18 | 000,069,832 | ---- | M] () [Unknown (-1) | Unknown] -- C:\Windows\System32\drivers\f4330dc14e93e30a.sys -- (f4330dc14e93e30a) SRV - [2012.05.08 15:48:51 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.08 15:48:50 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010.07.09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2009.08.24 14:47:07 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc) SRV - [2009.05.27 10:07:48 | 002,230,024 | ---- | M] () [Auto | Running] -- C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe -- (ClipInc001) SRV - [2009.05.07 02:01:00 | 000,368,640 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2005.11.17 16:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2012.05.17 19:33:18 | 000,069,832 | ---- | M] () [Unknown (-1) | Unknown (-1) | Unknown] -- C:\Windows\System32\drivers\f4330dc14e93e30a.sys -- (f4330dc14e93e30a) DRV - [2012.05.08 15:48:51 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.08 15:48:51 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.09.16 17:08:07 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.07.10 00:37:00 | 011,008,040 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\nvlddmkm.sys -- (nvlddmkm) DRV - [2010.02.23 13:30:59 | 000,211,968 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb10.sys -- (mrxsmb10) DRV - [2010.02.23 13:30:53 | 000,058,368 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb20.sys -- (mrxsmb20) DRV - [2010.02.23 13:30:49 | 000,102,912 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb.sys -- (mrxsmb) DRV - [2010.02.20 23:30:16 | 000,396,800 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HTTP.sys -- (HTTP) DRV - [2010.02.18 14:04:38 | 000,025,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\tunnel.sys -- (tunnel) DRV - [2010.02.18 14:04:30 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\tunmp.sys -- (tunmp) DRV - [2010.02.18 13:51:51 | 000,818,688 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\tcpip.sys -- (Tcpip6) DRV - [2010.02.18 13:51:51 | 000,818,688 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\tcpip.sys -- (Tcpip) DRV - [2009.12.11 14:01:24 | 000,307,200 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srv.sys -- (srv) DRV - [2009.12.11 14:01:06 | 000,084,992 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srvnet.sys -- (srvnet) DRV - [2009.11.04 19:08:32 | 000,278,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2009.11.04 19:08:31 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\lirsgt.sys -- (lirsgt) DRV - [2009.10.08 17:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.09.14 11:50:54 | 000,130,048 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srv2.sys -- (srv2) DRV - [2009.06.16 01:20:33 | 000,408,136 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecdd.sys -- (KSecDD) DRV - [2009.05.05 22:36:34 | 000,025,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\hamachi.sys -- (hamachi) DRV - [2008.07.30 07:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11) DRV - [2008.02.14 09:25:03 | 000,110,080 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mrxdav.sys -- (MRxDAV) DRV - [2008.02.14 09:23:41 | 000,224,824 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\CLFS.sys -- (CLFS) DRV - [2008.02.14 09:23:38 | 000,495,160 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Wdf01000.sys -- (Wdf01000) DRV - [2008.02.14 09:23:37 | 000,054,784 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\i8042prt.sys -- (i8042prt) DRV - [2008.02.14 09:23:37 | 000,035,384 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\kbdclass.sys -- (kbdclass) DRV - [2008.02.14 09:23:37 | 000,034,360 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\mouclass.sys -- (mouclass) DRV - [2008.02.14 09:23:37 | 000,019,968 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sermouse.sys -- (sermouse) DRV - [2008.02.14 09:23:37 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mouhid.sys -- (mouhid) DRV - [2008.02.14 09:23:37 | 000,015,872 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\kbdhid.sys -- (kbdhid) DRV - [2008.02.14 09:22:05 | 000,211,000 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volsnap.sys -- (volsnap) DRV - [2008.02.14 09:22:05 | 000,017,976 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\intelide.sys -- (intelide) DRV - [2008.02.14 09:22:04 | 000,154,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\nwifi.sys -- (NativeWifiP) DRV - [2007.12.20 02:04:00 | 000,265,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\fwlanusb.sys -- (FWLANUSB) DRV - [2007.12.20 02:04:00 | 000,004,352 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avmeject.sys -- (avmeject) DRV - [2007.12.17 00:52:59 | 001,061,944 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\ntfs.sys -- (Ntfs) DRV - [2007.12.16 11:50:45 | 000,041,984 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\monitor.sys -- (monitor) DRV - [2007.10.22 21:19:54 | 000,193,536 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbhub.sys -- (usbhub) DRV - [2007.10.22 21:19:53 | 000,073,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbccgp.sys -- (usbccgp) DRV - [2007.10.22 21:19:53 | 000,038,400 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbehci.sys -- (usbehci) DRV - [2007.10.22 21:19:53 | 000,023,040 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbuhci.sys -- (usbuhci) DRV - [2007.10.22 21:02:47 | 000,135,864 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ecache.sys -- (Ecache) DRV - [2007.10.22 20:54:01 | 000,621,568 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dxgkrnl.sys -- (DXGKrnl) DRV - [2007.10.22 20:33:31 | 000,184,320 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\netbt.sys -- (netbt) DRV - [2007.10.22 20:32:21 | 000,048,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ndproxy.sys -- (NDProxy) DRV - [2007.10.22 20:32:21 | 000,020,480 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndistapi.sys -- (NdisTapi) DRV - [2007.10.22 20:32:20 | 000,061,952 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\wanarp.sys -- (Wanarpv6) DRV - [2007.10.22 20:32:20 | 000,061,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\wanarp.sys -- (Wanarp) DRV - [2007.10.22 20:32:19 | 000,070,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\pacer.sys -- (PSched) DRV - [2007.10.22 20:22:17 | 000,143,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pci.sys -- (pci) DRV - [2007.10.22 20:22:17 | 000,053,432 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\termdd.sys -- (TermDD) DRV - [2007.10.22 20:22:17 | 000,052,920 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volmgr.sys -- (volmgr) DRV - [2007.10.22 20:22:17 | 000,031,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mssmbios.sys -- (mssmbios) DRV - [2007.10.22 20:22:17 | 000,016,568 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\msisadrv.sys -- (msisadrv) DRV - [2007.10.22 20:22:17 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\swenum.sys -- (swenum) DRV - [2007.10.22 20:20:17 | 000,070,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\tdx.sys -- (tdx) DRV - [2007.10.22 20:08:20 | 000,055,296 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\USBSTOR.SYS -- (USBSTOR) DRV - [2007.10.22 19:57:35 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\hidusb.sys -- (HidUsb) DRV - [2007.10.22 19:51:43 | 000,063,488 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mpsdrv.sys -- (mpsdrv) DRV - [2007.10.22 19:42:56 | 000,034,816 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\umbus.sys -- (umbus) DRV - [2007.10.22 19:37:22 | 000,061,952 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ohci1394.sys -- (ohci1394) DRV - [2007.10.22 19:30:58 | 000,503,480 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ndis.sys -- (NDIS) DRV - [2007.10.22 19:30:23 | 000,082,688 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\WUDFRd.sys -- (WUDFRd) DRV - [2007.10.22 19:25:01 | 000,225,792 | ---- | M] () [File_System | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\udfs.sys -- (udfs) DRV - [2007.10.22 19:22:26 | 000,066,048 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\smb.sys -- (Smb) DRV - [2007.10.22 19:20:19 | 000,012,800 | ---- | M] () [Recognizer | System | Unknown] -- C:\Windows\System32\drivers\fs_rec.sys -- (Fs_Rec) DRV - [2007.10.22 19:17:48 | 000,074,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\rasl2tp.sys -- (Rasl2tp) DRV - [2007.10.22 19:17:48 | 000,060,928 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\raspptp.sys -- (PptpMiniport) DRV - [2007.08.03 10:44:58 | 000,091,648 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\Rtlh86.sys -- (RTL8169) DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32) DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32) DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID) DRV - [2006.11.02 14:34:31 | 000,031,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qwavedrv.sys -- (QWAVEdrv) DRV - [2006.11.02 11:51:30 | 000,290,408 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volmgrx.sys -- (volmgrx) DRV - [2006.11.02 11:51:14 | 000,183,912 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\System32\drivers\fltmgr.sys -- (FltMgr) DRV - [2006.11.02 11:51:12 | 000,168,552 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\msiscsi.sys -- (iScsiPrt) DRV - [2006.11.02 11:51:12 | 000,167,528 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\pcmcia.sys -- (pcmcia) DRV - [2006.11.02 11:51:09 | 000,160,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msrpc.sys -- (MsRPC) DRV - [2006.11.02 11:50:40 | 000,106,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nv_agp.sys -- (nv_agp) DRV - [2006.11.02 11:50:24 | 000,047,208 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\isapnp.sys -- (isapnp) DRV - [2006.11.02 11:50:24 | 000,046,696 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\System32\Drivers\mup.sys -- (Mup) DRV - [2006.11.02 11:50:23 | 000,049,256 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\partmgr.sys -- (partmgr) DRV - [2006.11.02 11:50:17 | 000,080,488 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\msdsm.sys -- (msdsm) DRV - [2006.11.02 11:50:16 | 000,078,952 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\mpio.sys -- (mpio) DRV - [2006.11.02 11:50:16 | 000,076,392 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sbp2port.sys -- (sbp2port) DRV - [2006.11.02 11:50:04 | 000,058,984 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gagp30kx.sys -- (gagp30kx) DRV - [2006.11.02 11:50:04 | 000,058,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uliagpkx.sys -- (uliagpkx) DRV - [2006.11.02 11:49:59 | 000,056,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uagp35.sys -- (uagp35) DRV - [2006.11.02 11:49:58 | 000,056,424 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\System32\drivers\fileinfo.sys -- (FileInfo) DRV - [2006.11.02 11:49:57 | 000,054,888 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mountmgr.sys -- (MountMgr) DRV - [2006.11.02 11:49:52 | 000,054,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\viaagp.sys -- (viaagp) DRV - [2006.11.02 11:49:51 | 000,052,840 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\disk.sys -- (disk) DRV - [2006.11.02 11:49:49 | 000,027,752 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\i2omp.sys -- (i2omp) DRV - [2006.11.02 11:49:44 | 000,023,144 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\msahci.sys -- (msahci) DRV - [2006.11.02 11:49:43 | 000,022,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk) DRV - [2006.11.02 11:49:38 | 000,019,560 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wd.sys -- (Wd) DRV - [2006.11.02 11:49:35 | 000,018,536 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\spldr.sys -- (spldr) DRV - [2006.11.02 11:49:32 | 000,018,280 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\compbatt.sys -- (Compbatt) DRV - [2006.11.02 11:49:20 | 000,013,416 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\pciide.sys -- (pciide) DRV - [2006.11.02 11:14:58 | 000,018,944 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbprint.sys -- (usbprint) DRV - [2006.11.02 11:04:35 | 000,878,080 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\peauth.sys -- (PEAUTH) DRV - [2006.11.02 11:03:00 | 000,242,688 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\rdpdr.sys -- (rdpdr) DRV - [2006.11.02 11:02:15 | 000,160,256 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpwd.sys -- (RDPWD) DRV - [2006.11.02 11:02:07 | 000,023,552 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\tssecsrv.sys -- (tssecsrv) DRV - [2006.11.02 11:02:01 | 000,028,672 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdtcp.sys -- (TDTCP) DRV - [2006.11.02 11:02:01 | 000,017,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdpipe.sys -- (TDPIPE) DRV - [2006.11.02 11:02:01 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\rdpencdd.sys -- (RDPENCDD) DRV - [2006.11.02 11:02:01 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\RDPCDD.sys -- (RDPCDD) DRV - [2006.11.02 10:58:52 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\modem.sys -- (Modem) DRV - [2006.11.02 10:58:26 | 000,015,872 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2006.11.02 10:58:14 | 000,118,784 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndiswan.sys -- (NdisWan) DRV - [2006.11.02 10:58:13 | 000,011,776 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\rasacd.sys -- (RasAcd) DRV - [2006.11.02 10:58:12 | 000,041,472 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\raspppoe.sys -- (RasPppoe) DRV - [2006.11.02 10:58:09 | 000,099,840 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipnat.sys -- (IPNAT) DRV - [2006.11.02 10:58:04 | 000,047,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipfltdrv.sys -- (IpFilterDriver) DRV - [2006.11.02 10:57:47 | 000,027,648 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tcpipreg.sys -- (tcpipreg) DRV - [2006.11.02 10:57:30 | 000,016,384 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\nsiproxy.sys -- (nsiproxy) DRV - [2006.11.02 10:57:26 | 000,035,840 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\DRIVERS\netbios.sys -- (NetBIOS) DRV - [2006.11.02 10:57:22 | 000,016,896 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndisuio.sys -- (Ndisuio) DRV - [2006.11.02 10:57:04 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\irenum.sys -- (IRENUM) DRV - [2006.11.02 10:56:49 | 000,060,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\rspndr.sys -- (rspndr) DRV - [2006.11.02 10:56:49 | 000,047,104 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\lltdio.sys -- (lltdio) DRV - [2006.11.02 10:55:23 | 000,039,936 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\bthmodem.sys -- (BTHMODEM) DRV - [2006.11.02 10:55:22 | 000,029,184 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\hidbth.sys -- (HidBth) DRV - [2006.11.02 10:55:09 | 000,068,608 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbcir.sys -- (usbcir) DRV - [2006.11.02 10:55:08 | 000,035,328 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\circlass.sys -- (circlass) DRV - [2006.11.02 10:55:05 | 000,019,456 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbohci.sys -- (usbohci) DRV - [2006.11.02 10:55:01 | 000,021,504 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\hidir.sys -- (HidIr) DRV - [2006.11.02 10:54:59 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\drmkaud.sys -- (drmkaud) DRV - [2006.11.02 10:53:56 | 000,026,112 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\vgapnp.sys -- (vga) DRV - [2006.11.02 10:53:56 | 000,025,088 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\vga.sys -- (VgaSave) DRV - [2006.11.02 10:52:52 | 000,020,608 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wacompen.sys -- (WacomPen) DRV - [2006.11.02 10:51:44 | 000,067,072 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\cdrom.sys -- (cdrom) DRV - [2006.11.02 10:51:40 | 000,013,312 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sfloppy.sys -- (sfloppy) DRV - [2006.11.02 10:51:40 | 000,012,800 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sffp_sd.sys -- (sffp_sd) DRV - [2006.11.02 10:51:40 | 000,012,800 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sffp_mmc.sys -- (sffp_mmc) DRV - [2006.11.02 10:51:38 | 000,013,312 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sffdisk.sys -- (sffdisk) DRV - [2006.11.02 10:51:33 | 000,025,088 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\fdc.sys -- (fdc) DRV - [2006.11.02 10:51:32 | 000,020,480 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\flpydisk.sys -- (flpydisk) DRV - [2006.11.02 10:51:30 | 000,083,456 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\serial.sys -- (Serial) DRV - [2006.11.02 10:51:30 | 000,079,360 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\parport.sys -- (Parport) DRV - [2006.11.02 10:51:25 | 000,017,920 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\serenum.sys -- (Serenum) DRV - [2006.11.02 10:51:23 | 000,008,704 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\parvdm.sys -- (Parvdm) DRV - [2006.11.02 10:51:15 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSKSSRV.sys -- (MSKSSRV) DRV - [2006.11.02 10:51:14 | 000,005,504 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSPQM.sys -- (MSPQM) DRV - [2006.11.02 10:51:13 | 000,006,016 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSTEE.sys -- (MSTEE) DRV - [2006.11.02 10:51:13 | 000,005,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSPCLOCK.sys -- (MSPCLOCK) DRV - [2006.11.02 10:51:05 | 000,004,608 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\null.sys -- (Null) DRV - [2006.11.02 10:42:03 | 000,065,536 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ipmidrv.sys -- (IPMIDRV) DRV - [2006.11.02 10:35:03 | 000,011,264 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wmiacpi.sys -- (WmiAcpi) DRV - [2006.11.02 10:33:07 | 000,083,456 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\System32\drivers\luafv.sys -- (luafv) DRV - [2006.11.02 10:32:55 | 000,027,648 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\filetrace.sys -- (Filetrace) DRV - [2006.11.02 10:31:26 | 000,222,208 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\DRIVERS\rdbss.sys -- (rdbss) DRV - [2006.11.02 10:31:04 | 000,074,752 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\Drivers\dfsc.sys -- (DfsC) DRV - [2006.11.02 10:30:57 | 000,034,816 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\npfs.sys -- (Npfs) DRV - [2006.11.02 10:30:56 | 000,022,528 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\msfs.sys -- (Msfs) DRV - [2006.11.02 10:30:50 | 000,070,144 | ---- | M] () [File_System | Disabled | Running] -- C:\Windows\System32\DRIVERS\cdfs.sys -- (cdfs) DRV - [2006.11.02 10:30:49 | 000,142,336 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fastfat.sys -- (fastfat) DRV - [2006.11.02 10:30:19 | 000,039,424 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\viac7.sys -- (ViaC7) DRV - [2006.11.02 10:30:18 | 000,039,424 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\intelppm.sys -- (intelppm) DRV - [2006.11.02 10:30:18 | 000,038,912 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\crusoe.sys -- (Crusoe) DRV - [2006.11.02 10:30:18 | 000,038,400 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\processr.sys -- (Processor) DRV - [2006.11.02 09:36:49 | 000,235,520 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledAddons: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.7 FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.15 FF - prefs.js..extensions.enabledAddons: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.9 FF - prefs.js..extensions.enabledAddons: youtubemp3podcaster@jeremy.d.gregorio.com:2.7.0 FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 44 FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625 FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10 FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.5 FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.22.1 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..network.proxy.http: "70.158.130.207" FF - prefs.js..network.proxy.http_port: 8080 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\lukas\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.13 15:02:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.13 15:02:46 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.13 15:02:52 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.13 15:02:46 | 000,000,000 | ---D | M] [2008.09.03 22:17:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\Extensions [2012.10.16 18:16:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions [2010.08.04 23:03:17 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2009.09.09 18:04:58 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2008.03.27 18:39:14 | 000,000,000 | ---D | M] ("Bazzacuda Image Saver") -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{FFBC0836-1BCF-4FE5-9B2B-E2E6F53CBDE7} [2012.10.03 16:55:37 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\foxyproxy@eric.h(35).jung [2012.10.11 14:23:39 | 000,000,000 | ---D | M] (Youtube MP3 Podcaster) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\youtubemp3podcaster@jeremy.d.gregorio.com [2011.07.18 16:21:12 | 000,097,169 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi [2012.10.09 18:01:38 | 000,211,935 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2012.09.01 18:03:48 | 000,590,708 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2012.08.11 11:52:51 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012.09.13 22:01:22 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2011.05.07 16:29:08 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2012.10.13 13:34:29 | 000,001,451 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\chipde---forum.xml [2012.10.13 13:34:30 | 000,001,263 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\chipdownloads.xml [2012.10.13 13:34:29 | 000,002,125 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\flickr-tags.xml [2012.10.13 13:34:29 | 000,002,081 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\lautde.xml [2012.10.13 13:34:30 | 000,001,961 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-en.xml [2012.10.13 13:34:30 | 000,001,969 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-es.xml [2012.10.13 13:34:30 | 000,001,973 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-fr.xml [2012.10.13 13:34:29 | 000,000,971 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\onvista.xml [2012.10.13 13:34:29 | 000,001,242 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\plattentestsde-all.xml [2012.07.15 12:47:46 | 000,000,821 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\youtube-deutschland.xml [2012.10.13 15:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.10.13 15:02:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012.10.13 15:02:52 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.07.06 16:24:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.14 23:19:24 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.07.06 16:24:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.07.06 16:24:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.06 16:24:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.06 16:24:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files\avmwlanstick\wlangui.exe (AVM Berlin) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - Startup: C:\Users\lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Last.fm Helper.lnk = File not found O7 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data] O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35) O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A257D804-4C79-4B59-B390-FDBD44407EE3}: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\lukas\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\lukas\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{0577b080-5415-11de-9cb1-00040ec99c43}\Shell\AutoRun\command - "" = L:\StartPortableApps.exe O33 - MountPoints2\{12688a14-b54f-11dc-bd6c-00192148fa5f}\Shell - "" = AutoRun O33 - MountPoints2\{12688a14-b54f-11dc-bd6c-00192148fa5f}\Shell\AutoRun\command - "" = L:\pushinst.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012.10.16 17:47:04 | 000,000,000 | ---D | C] -- C:\Users\lukas\Desktop\Neuer Ordner [2012.10.16 17:33:44 | 000,000,000 | ---D | C] -- C:\_OTL [2012.10.13 15:02:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.10.12 16:10:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.10.12 16:10:08 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files - Modified Within 30 Days ========== [2012.10.17 16:45:18 | 000,121,741 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012.10.17 16:45:18 | 000,121,741 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012.10.17 16:44:48 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.17 16:44:48 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.17 16:44:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.17 16:44:39 | 2146,754,560 | -HS- | M] () -- C:\hiberfil.sys [2012.10.17 16:34:23 | 000,640,358 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.10.17 16:34:23 | 000,609,532 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.10.17 16:34:23 | 000,116,122 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.10.17 16:34:23 | 000,103,314 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.10.16 18:30:03 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{AFEFAEC0-F9A3-4BF2-A18C-126AB0F0C32C}.job [2012.10.16 16:16:37 | 000,019,992 | ---- | M] () -- C:\Users\lukas\Documents\logfiles.zip [2012.10.16 15:01:48 | 169,650,795 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012.10.12 16:10:09 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.09.28 12:40:32 | 000,002,631 | ---- | M] () -- C:\Users\lukas\Desktop\Microsoft Office Word 2007.lnk [2012.09.19 00:30:57 | 000,098,816 | ---- | M] () -- C:\Users\lukas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== Files Created - No Company Name ========== [2012.10.17 16:44:39 | 2146,754,560 | -HS- | C] () -- C:\hiberfil.sys [2012.10.16 16:16:37 | 000,019,992 | ---- | C] () -- C:\Users\lukas\Documents\logfiles.zip [2012.10.12 16:20:36 | 169,650,795 | ---- | C] () -- C:\Windows\MEMORY.DMP [2012.10.12 16:10:09 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.01 23:44:46 | 000,001,024 | ---- | C] () -- C:\Users\lukas\Desktop\hbedv.key [2012.05.17 19:33:18 | 000,069,832 | ---- | C] () -- C:\Windows\System32\drivers\f4330dc14e93e30a.sys [2012.05.17 19:32:47 | 000,038,400 | ---- | C] () -- C:\ProgramData\69p20cfih3.exe [2012.05.17 14:51:28 | 000,038,400 | ---- | C] () -- C:\Users\lukas\69p20cfih3.exe [2012.04.11 14:56:34 | 000,141,021 | ---- | C] () -- C:\Users\lukas\.recently-used.xbel [2012.03.17 16:27:46 | 000,137,928 | ---- | C] () -- C:\Windows\System32\drivers\avipbb.sys [2012.03.17 16:27:46 | 000,036,000 | ---- | C] () -- C:\Windows\System32\drivers\avkmgr.sys [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2010.08.11 18:25:56 | 000,121,741 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010.08.11 18:25:55 | 000,121,741 | ---- | C] () -- C:\ProgramData\nvModes.dat [2008.09.11 19:05:21 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib [2008.04.09 13:49:05 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat [2008.02.02 13:58:33 | 000,001,356 | ---- | C] () -- C:\Users\lukas\AppData\Local\d3d9caps.dat [2007.12.30 16:10:57 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html [2007.12.29 19:40:15 | 000,098,816 | ---- | C] () -- C:\Users\lukas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] "ThreadingModel" = Both "" = shell32.dll -- [2008.11.06 14:59:14 | 011,320,832 | ---- | M] (Microsoft Corporation) [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2008.11.06 14:59:14 | 011,320,832 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = fastprox.dll -- [2009.03.03 06:16:12 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2006.11.02 11:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2009.01.10 16:04:37 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Activision [2008.01.21 18:19:02 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\dBpoweramp [2011.06.12 01:29:40 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.11 14:56:34 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\gtk-2.0 [2012.03.23 18:36:29 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\ICQ [2008.12.10 18:49:06 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\MAGIX [2010.08.28 17:02:41 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\mp3DirectCut [2008.12.12 18:46:24 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\MP3toiPodAudioBookConverter [2009.01.09 18:26:11 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\ProtectDisc [2011.12.30 00:38:17 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Sports Interactive [2011.11.05 00:58:21 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\temp [2008.09.21 14:51:53 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Tobit [2011.12.12 20:55:49 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Tropico 3 [2011.12.23 15:26:02 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Ubisoft ========== Purity Check ========== < End of report > Code:
ATTFilter 16:54:45.0644 2996 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47 16:54:45.0815 2996 ============================================================ 16:54:45.0815 2996 Current date / time: 2012/10/17 16:54:45.0815 16:54:45.0815 2996 SystemInfo: 16:54:45.0815 2996 16:54:45.0815 2996 OS Version: 6.0.6000 ServicePack: 0.0 16:54:45.0815 2996 Product type: Workstation 16:54:45.0815 2996 ComputerName: LUKAS-PC 16:54:45.0815 2996 UserName: lukas 16:54:45.0815 2996 Windows directory: C:\Windows 16:54:45.0815 2996 System windows directory: C:\Windows 16:54:45.0815 2996 Processor architecture: Intel x86 16:54:45.0815 2996 Number of processors: 4 16:54:45.0815 2996 Page size: 0x1000 16:54:45.0815 2996 Boot type: Normal boot 16:54:45.0815 2996 ============================================================ 16:54:53.0940 2996 Raw registry subsystem init failed! 16:54:54.0190 2996 !crdlk 16:54:54.0190 2996 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A' 16:54:54.0206 2996 ============================================================ 16:54:54.0206 2996 \Device\Harddisk0\DR0: 16:54:54.0222 2996 MBR partitions: 16:54:54.0222 2996 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1770800, BlocksNum 0x25EB1800 16:54:54.0222 2996 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27622000, BlocksNum 0x12D63800 16:54:54.0222 2996 ============================================================ 16:54:54.0253 2996 C: <-> \Device\Harddisk0\DR0\Partition1 16:54:54.0300 2996 D: <-> \Device\Harddisk0\DR0\Partition2 16:54:54.0300 2996 ============================================================ 16:54:54.0300 2996 Initialize success 16:54:54.0300 2996 ============================================================ 16:55:49.0159 0704 ============================================================ 16:55:49.0159 0704 Scan started 16:55:49.0159 0704 Mode: Manual; TDLFS; 16:55:49.0159 0704 ============================================================ 16:55:49.0159 0704 ================ Scan system memory ======================== 16:55:49.0159 0704 System memory - ok 16:55:49.0159 0704 ================ Scan services ============================= 16:55:49.0159 0704 ================ Scan global =============================== 16:55:49.0237 0704 [ 329CF3C97CE4C19375C8ABCABAE258B0 ] C:\Windows\system32\services.exe 16:55:49.0237 0704 [Global] - ok 16:55:49.0253 0704 ================ Scan MBR ================================== 16:55:49.0284 0704 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 16:55:49.0565 0704 \Device\Harddisk0\DR0 - ok 16:55:49.0565 0704 ================ Scan VBR ================================== 16:55:49.0565 0704 [ 76FC9C428A66B4D11AE59863A03AD458 ] \Device\Harddisk0\DR0\Partition1 16:55:49.0565 0704 \Device\Harddisk0\DR0\Partition1 - ok 16:55:49.0581 0704 [ 9AC047E3A097EAB7B8C8CC8320C92A42 ] \Device\Harddisk0\DR0\Partition2 16:55:49.0597 0704 \Device\Harddisk0\DR0\Partition2 - ok 16:55:49.0597 0704 ============================================================ 16:55:49.0597 0704 Scan finished 16:55:49.0597 0704 ============================================================ 16:55:49.0597 3056 Detected object count: 0 16:55:49.0597 3056 Actual detected object count: 0 |
17.10.2012, 16:39 | #9 | ||
/// TB-Ausbilder | lumviexdopag.exe - Trojaner? Das will nicht so wie ich das will ... Scan mit Combofix
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
17.10.2012, 17:53 | #10 |
| lumviexdopag.exe - Trojaner? Das hat ComboFix rausgegeben: Code:
ATTFilter ComboFix 12-10-17.03 - lukas 17.10.2012 18:05:33.1.4 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.49.1031.18.2047.1332 [GMT 2:00] ausgeführt von:: c:\users\lukas\Downloads\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\drivers\f4330dc14e93e30a.sys c:\windows\system32\msstdfmt.dll c:\windows\system32\Thumbs.db . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_nvsvc -------\Legacy_f4330dc14e93e30a -------\Service_f4330dc14e93e30a . . ((((((((((((((((((((((( Dateien erstellt von 2012-09-17 bis 2012-10-17 )))))))))))))))))))))))))))))) . . 2012-10-17 16:12 . 2012-10-17 16:15 -------- d-----w- c:\users\lukas\AppData\Local\temp 2012-10-16 15:33 . 2012-10-16 15:33 -------- d-----w- C:\_OTL 2012-10-12 14:10 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-10-07 11:21 . 2012-10-07 11:21 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C5073116-8F03-4BC6-A97C-991BBFEE60FC}\offreg.dll 2012-10-07 10:56 . 2012-10-07 10:56 477168 ----a-w- c:\windows\system32\npdeployJava1.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-11 12:50 . 2012-04-09 11:00 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-11 12:50 . 2011-06-26 10:56 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-07 10:56 . 2011-02-11 17:26 473072 ----a-w- c:\windows\system32\deployJava1.dll 2012-10-13 13:02 . 2012-10-13 13:02 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 4702208] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2009-05-07 1904640] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-30 198160] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-24 2516296] "IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-03-02 140640] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-11 348664] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\users\lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Last.fm Helper.lnk - c:\program files\Last.fm\LastFMHelper.exe [N/A] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClipIncSrvTray] 2009-03-16 08:52 668424 ----a-w- c:\program files\Tobit ClipInc\Player\ClipIncTray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2007-12-12 13:23 21686568 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2012-09-14 15:47 1353080 ----a-w- c:\program files\Steam\Steam.exe . S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2012-10-16 c:\windows\Tasks\User_Feed_Synchronization-{AFEFAEC0-F9A3-4BF2-A18C-126AB0F0C32C}.job - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: Free YouTube to Mp3 Converter - c:\users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\q6thin34.default\ FF - ExtSQL: 2012-10-07 12:56; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} . - - - - Entfernte verwaiste Registrierungseinträge - - - - . MSConfigStartUp-AnyDVD - c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2012-10-17 18:15 Windows 6.0.6000 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-697571881-3444188392-3486144138-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:e3,20,ef,75,e7,0f,52,43,15,5e,a4,e0,93,84,f5,66,bc,73,b6,8c,a0,77,a1, 27,d5,fc,38,d6,85,f6,76,60,69,45,de,80,d3,94,69,3a,de,67,a9,75,b2,77,7f,ca,\ "??"=hex:07,c5,cd,9e,60,af,71,ca,ce,c6,48,33,0b,ed,76,fc . [HKEY_USERS\S-1-5-21-697571881-3444188392-3486144138-1000\Software\SecuROM\License information*] "datasecu"=hex:44,98,e6,fd,45,d0,05,07,5c,64,11,e0,0f,8b,58,de,5c,f3,3c,ba,83, 05,94,a2,61,ca,1e,c0,a2,a7,66,d0,97,70,c5,05,71,d3,66,f5,c3,67,24,ac,13,75,\ "rkeysecu"=hex:11,7d,52,73,64,06,6a,53,8f,64,f8,f0,21,b5,33,f6 . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\Avira\AntiVir Desktop\sched.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\avmwlanstick\WlanNetService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Tobit ClipInc\Server\ClipInc-Server.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe c:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\system32\WUDFHost.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\windows\RtHDVCpl.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Zeit der Fertigstellung: 2012-10-17 18:24:01 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2012-10-17 16:23 . Vor Suchlauf: 21 Verzeichnis(se), 53.817.069.568 Bytes frei Nach Suchlauf: 26 Verzeichnis(se), 54.320.873.472 Bytes frei . - - End Of File - - 2401C646A30606E0BE5A43DB90327FF7 |
17.10.2012, 18:23 | #11 | |||
/// TB-Ausbilder | lumviexdopag.exe - Trojaner? Prima Das war schon ein guter Schritt, wir müssen jetzt noch einen Überrest entfernen und dann ist noch eine Menge für dich zu tun Schritt 1: Combofix-Skript Schritt 2: Quick-Scan mit Malwarebytes Schritt 3: ESET Online Scanner Zitat:
Schritt 4: Windows Vista Service Pack 2 installieren Schritt 5: Java Update Schritt 6: Kontrollscan mit OTL
Fragen:
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
20.10.2012, 09:36 | #12 |
/// TB-Ausbilder | lumviexdopag.exe - Trojaner? Hallo, benötigst Du noch weiterhin Hilfe ? Sollte ich innerhalb der nächsten 24 Stunden keine Antwort von dir erhalten, werde ich dein Thema aus meinen Abos nehmen und bekomme dadurch keine Nachricht über neue Antworten. Das Verschwinden der Symptome bedeutet nicht, dass dein System schon sauber ist
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
20.10.2012, 19:00 | #13 |
| lumviexdopag.exe - Trojaner? Sorry, hatte die letzten Tage wenig Zeit. Ich poste schonmal die Logs aus den Schritten 1-3, bin grad noch dabei, die Service Packs zu installieren. ComboFix: Code:
ATTFilter ComboFix 12-10-18.03 - lukas 19.10.2012 15:30:54.2.4 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.49.1031.18.2047.1320 [GMT 2:00] ausgeführt von:: c:\users\lukas\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\lukas\Desktop\CFScript.txt . . ((((((((((((((((((((((( Dateien erstellt von 2012-09-19 bis 2012-10-19 )))))))))))))))))))))))))))))) . . 2012-10-19 13:38 . 2012-10-19 13:40 -------- d-----w- c:\users\lukas\AppData\Local\temp 2012-10-19 13:38 . 2012-10-19 13:38 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-10-18 10:48 . 2012-10-18 10:48 -------- d-----w- c:\program files\Common Files\Skype 2012-10-18 10:48 . 2012-10-18 10:48 -------- d-----r- c:\program files\Skype 2012-10-17 16:38 . 2012-10-17 00:32 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F94B7EB9-20A4-4D0A-9423-819E58CE44C2}\mpengine.dll 2012-10-16 15:33 . 2012-10-16 15:33 -------- d-----w- C:\_OTL 2012-10-12 14:10 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-10-07 10:56 . 2012-10-07 10:56 477168 ----a-w- c:\windows\system32\npdeployJava1.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-11 12:50 . 2012-04-09 11:00 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-11 12:50 . 2011-06-26 10:56 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-07 10:56 . 2011-02-11 17:26 473072 ----a-w- c:\windows\system32\deployJava1.dll 2012-10-13 13:02 . 2012-10-13 13:02 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 4702208] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2009-05-07 1904640] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-30 198160] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-24 2516296] "IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-03-02 140640] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-11 348664] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\users\lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Last.fm Helper.lnk - c:\program files\Last.fm\LastFMHelper.exe [N/A] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClipIncSrvTray] 2009-03-16 08:52 668424 ----a-w- c:\program files\Tobit ClipInc\Player\ClipIncTray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2012-07-13 11:33 17418928 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2012-09-14 15:47 1353080 ----a-w- c:\program files\Steam\Steam.exe . S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2012-10-19 c:\windows\Tasks\User_Feed_Synchronization-{AFEFAEC0-F9A3-4BF2-A18C-126AB0F0C32C}.job - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: Free YouTube to Mp3 Converter - c:\users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\q6thin34.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia (de) FF - ExtSQL: 2012-10-07 12:56; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2012-10-19 15:40 Windows 6.0.6000 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-697571881-3444188392-3486144138-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:e3,20,ef,75,e7,0f,52,43,15,5e,a4,e0,93,84,f5,66,bc,73,b6,8c,a0,77,a1, 27,d5,fc,38,d6,85,f6,76,60,69,45,de,80,d3,94,69,3a,de,67,a9,75,b2,77,7f,ca,\ "??"=hex:07,c5,cd,9e,60,af,71,ca,ce,c6,48,33,0b,ed,76,fc . [HKEY_USERS\S-1-5-21-697571881-3444188392-3486144138-1000\Software\SecuROM\License information*] "datasecu"=hex:44,98,e6,fd,45,d0,05,07,5c,64,11,e0,0f,8b,58,de,5c,f3,3c,ba,83, 05,94,a2,61,ca,1e,c0,a2,a7,66,d0,97,70,c5,05,71,d3,66,f5,c3,67,24,ac,13,75,\ "rkeysecu"=hex:11,7d,52,73,64,06,6a,53,8f,64,f8,f0,21,b5,33,f6 . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\Avira\AntiVir Desktop\sched.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\avmwlanstick\WlanNetService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Tobit ClipInc\Server\ClipInc-Server.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe c:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\system32\WUDFHost.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\windows\system32\conime.exe c:\windows\RtHDVCpl.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE . ************************************************************************** . Zeit der Fertigstellung: 2012-10-19 15:45:24 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2012-10-19 13:44 ComboFix2.txt 2012-10-17 16:24 . Vor Suchlauf: 24 Verzeichnis(se), 50.527.428.608 Bytes frei Nach Suchlauf: 25 Verzeichnis(se), 50.813.526.016 Bytes frei . - - End Of File - - C08B0ACE3E6454B1F95C3E446FDAC07C Code:
ATTFilter C:\Users\lukas\Downloads\HSS-1.21-install-anchorfree-76-conduit.zip a variant of Win32/HotSpotShield application C:\Users\lukas\Downloads\HSS-1.37-install-anchorfree-76-conduit.exe a variant of Win32/HotSpotShield application C:\_OTL\MovedFiles\10162012_173344\C_ProgramData\lumivexdopag.exe Win32/Wigon.PB trojan C:\_OTL\MovedFiles\10162012_173344\C_Users\lukas\lumivexdopag.exe Win32/Wigon.PB trojan C:\_OTL\MovedFiles\10172012_164358\C_ProgramData\69p20cfih3.exe a variant of Win32/Kryptik.AGJE trojan C:\_OTL\MovedFiles\10172012_164358\C_Users\lukas\69p20cfih3.exe a variant of Win32/Kryptik.AGJE trojan Code:
ATTFilter Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Datenbank Version: v2012.10.19.09 Windows Vista x86 NTFS Internet Explorer 7.0.6000.17037 lukas :: LUKAS-PC [Administrator] 19.10.2012 15:53:30 mbam-log-2012-10-19 (15-53-30).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 195480 Laufzeit: 5 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) OTL-Kontrollscan: Code:
ATTFilter OTL logfile created on: 21.10.2012 14:33:24 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = c:\users\lukas\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 7.0.6002.18005) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,19 Gb Available Physical Memory | 59,74% Memory free 4,24 Gb Paging File | 3,25 Gb Available in Paging File | 76,70% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 303,35 Gb Total Space | 80,43 Gb Free Space | 26,51% Space Free | Partition Type: NTFS Drive D: | 150,69 Gb Total Space | 150,60 Gb Free Space | 99,94% Space Free | Partition Type: NTFS Computer Name: LUKAS-PC | User Name: lukas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.10.16 15:12:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- c:\users\lukas\Downloads\OTL.exe PRC - [2012.08.11 11:45:55 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.05.08 15:48:51 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2012.05.08 15:48:50 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2012.05.08 15:48:50 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2010.07.09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010.03.24 19:50:00 | 002,516,296 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE PRC - [2010.03.02 20:52:00 | 000,140,640 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe PRC - [2009.08.30 20:55:58 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2009.05.27 10:07:48 | 002,230,024 | ---- | M] () -- C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe PRC - [2009.05.07 02:01:00 | 001,904,640 | ---- | M] (AVM Berlin) -- C:\Program Files\avmwlanstick\WLanGUI.exe PRC - [2009.05.07 02:01:00 | 000,368,640 | ---- | M] (AVM Berlin) -- C:\Program Files\avmwlanstick\WlanNetService.exe PRC - [2009.04.10 23:28:16 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE PRC - [2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.10 23:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2007.09.03 18:39:22 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe ========== Modules (No Company Name) ========== MOD - [2007.09.20 19:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll ========== Services (SafeList) ========== SRV - [2012.10.14 16:17:25 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012.10.13 15:02:51 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.05.08 15:48:51 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.08 15:48:50 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010.07.09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2009.08.24 13:36:45 | 000,377,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc) SRV - [2009.05.27 10:07:48 | 002,230,024 | ---- | M] () [Auto | Running] -- C:\Program Files\Tobit ClipInc\Server\ClipInc-Server.exe -- (ClipInc001) SRV - [2009.05.07 02:01:00 | 000,368,640 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service) SRV - [2008.01.18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2005.11.17 16:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2012.05.08 15:48:51 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.08 15:48:51 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.09.16 17:08:07 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2010.07.10 00:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.11.04 19:08:32 | 000,278,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2009.11.04 19:08:31 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2009.10.08 17:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.05.05 22:36:34 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2008.07.30 07:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11) DRV - [2007.12.20 02:04:00 | 000,265,088 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB) DRV - [2007.12.20 02:04:00 | 000,004,352 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avmeject.sys -- (avmeject) DRV - [2007.08.03 10:44:58 | 000,091,648 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32) DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32) DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledAddons: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.7 FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.15 FF - prefs.js..extensions.enabledAddons: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.9 FF - prefs.js..extensions.enabledAddons: youtubemp3podcaster@jeremy.d.gregorio.com:2.7.0 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 FF - prefs.js..extensions.enabledItems: 6 FF - prefs.js..extensions.enabledItems: 2 FF - prefs.js..extensions.enabledItems: 44 FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625 FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10 FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.5 FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.22.1 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..network.proxy.http: "70.158.130.207" FF - prefs.js..network.proxy.http_port: 8080 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\lukas\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.13 15:02:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.13 15:02:46 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.13 15:02:52 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.10.13 15:02:46 | 000,000,000 | ---D | M] [2008.09.03 22:17:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\Extensions [2012.10.16 18:16:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions [2010.08.04 23:03:17 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2009.09.09 18:04:58 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2008.03.27 18:39:14 | 000,000,000 | ---D | M] ("Bazzacuda Image Saver") -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\{FFBC0836-1BCF-4FE5-9B2B-E2E6F53CBDE7} [2012.10.03 16:55:37 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\foxyproxy@eric.h(35).jung [2012.10.11 14:23:39 | 000,000,000 | ---D | M] (Youtube MP3 Podcaster) -- C:\Users\lukas\AppData\Roaming\mozilla\Firefox\Profiles\q6thin34.default\extensions\youtubemp3podcaster@jeremy.d.gregorio.com [2011.07.18 16:21:12 | 000,097,169 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi [2012.10.09 18:01:38 | 000,211,935 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2012.09.01 18:03:48 | 000,590,708 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2012.08.11 11:52:51 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012.09.13 22:01:22 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2011.05.07 16:29:08 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2012.10.20 14:23:00 | 000,001,451 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\chipde---forum.xml [2012.10.20 14:23:02 | 000,001,263 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\chipdownloads.xml [2012.10.20 14:23:00 | 000,002,125 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\flickr-tags.xml [2012.10.20 14:23:00 | 000,002,081 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\lautde.xml [2012.10.20 14:23:02 | 000,001,961 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-en.xml [2012.10.20 14:23:02 | 000,001,969 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-es.xml [2012.10.20 14:23:02 | 000,001,973 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\leo-de-fr.xml [2012.10.20 14:23:01 | 000,000,971 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\onvista.xml [2012.10.20 14:23:01 | 000,001,242 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\plattentestsde-all.xml [2012.07.15 12:47:46 | 000,000,821 | ---- | M] () -- C:\Users\lukas\AppData\Roaming\mozilla\firefox\profiles\q6thin34.default\searchplugins\youtube-deutschland.xml [2012.10.21 14:24:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.10.13 15:02:52 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.07.06 16:24:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.09.14 23:19:24 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.07.06 16:24:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.07.06 16:24:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.06 16:24:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.06 16:24:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.10.17 18:12:26 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [AVMWlanClient] C:\Program Files\avmwlanstick\wlangui.exe (AVM Berlin) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - Startup: C:\Users\lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Last.fm Helper.lnk = File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data] O7 - HKU\S-1-5-21-697571881-3444188392-3486144138-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.9.2) O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A257D804-4C79-4B59-B390-FDBD44407EE3}: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\lukas\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\lukas\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012.10.21 13:33:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES [2012.10.21 13:33:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES [2012.10.21 13:33:37 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN [2012.10.21 13:29:53 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview [2012.10.21 13:13:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders [2012.10.20 17:56:31 | 000,000,000 | ---D | C] -- C:\PerfLogs [2012.10.19 16:01:50 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012.10.19 16:01:39 | 002,322,184 | ---- | C] (ESET) -- C:\Users\lukas\Desktop\esetsmartinstaller_enu.exe [2012.10.19 15:45:27 | 000,000,000 | ---D | C] -- C:\Windows\temp [2012.10.19 15:45:27 | 000,000,000 | ---D | C] -- C:\Users\lukas\AppData\Local\temp [2012.10.19 15:40:06 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2012.10.19 15:23:21 | 004,984,103 | R--- | C] (Swearware) -- C:\Users\lukas\Desktop\ComboFix.exe [2012.10.18 12:48:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012.10.18 12:48:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2012.10.18 12:48:51 | 000,000,000 | R--D | C] -- C:\Program Files\Skype [2012.10.17 18:01:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012.10.17 18:01:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012.10.17 18:01:44 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe [2012.10.17 18:01:44 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2012.10.17 18:01:26 | 000,000,000 | ---D | C] -- C:\Qoobox [2012.10.17 18:01:17 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2012.10.16 17:47:04 | 000,000,000 | ---D | C] -- C:\Users\lukas\Desktop\Neuer Ordner [2012.10.16 17:33:44 | 000,000,000 | ---D | C] -- C:\_OTL [2012.10.13 15:02:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.10.12 16:10:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.10.12 16:10:08 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.10.21 14:34:26 | 000,618,204 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.10.21 14:34:26 | 000,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.10.21 14:34:26 | 000,122,442 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.10.21 14:34:26 | 000,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.10.21 14:27:07 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012.10.21 14:27:07 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012.10.21 14:26:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.10.21 14:26:34 | 2146,754,560 | -HS- | M] () -- C:\hiberfil.sys [2012.10.21 13:37:22 | 000,291,008 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.10.21 13:32:40 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf [2012.10.20 20:09:17 | 000,098,816 | ---- | M] () -- C:\Users\lukas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.10.20 17:39:30 | 000,101,888 | ---- | M] (Infineon Technologies AG) -- C:\Windows\System32\ifxcardm.dll [2012.10.20 17:39:15 | 000,082,432 | ---- | M] (Gemalto, Inc.) -- C:\Windows\System32\axaltocm.dll [2012.10.20 17:29:31 | 000,327,680 | ---- | M] () -- C:\Windows\SPInstall.etl [2012.10.20 16:42:31 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{AFEFAEC0-F9A3-4BF2-A18C-126AB0F0C32C}.job [2012.10.19 16:01:46 | 002,322,184 | ---- | M] (ESET) -- C:\Users\lukas\Desktop\esetsmartinstaller_enu.exe [2012.10.19 15:52:20 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.19 15:23:40 | 004,984,103 | R--- | M] (Swearware) -- C:\Users\lukas\Desktop\ComboFix.exe [2012.10.18 12:48:58 | 000,001,880 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2012.10.17 18:12:26 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2012.10.17 16:45:18 | 000,121,741 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012.10.17 16:45:18 | 000,121,741 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012.10.16 16:16:37 | 000,019,992 | ---- | M] () -- C:\Users\lukas\Documents\logfiles.zip [2012.10.16 15:01:48 | 169,650,795 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012.09.28 12:40:32 | 000,002,631 | ---- | M] () -- C:\Users\lukas\Desktop\Microsoft Office Word 2007.lnk [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.10.21 13:32:40 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf [2012.10.21 13:19:48 | 000,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf [2012.10.21 13:19:45 | 000,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml [2012.10.21 13:19:45 | 000,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml [2012.10.21 13:19:32 | 000,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf [2012.10.21 13:19:29 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2012.10.21 13:19:19 | 000,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf [2012.10.21 13:18:43 | 011,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex [2012.10.21 13:18:41 | 000,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF [2012.10.21 13:18:34 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2012.10.21 13:18:34 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2012.10.21 13:18:31 | 000,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs [2012.10.21 13:18:31 | 000,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man [2012.10.21 13:18:30 | 000,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd [2012.10.20 18:09:28 | 000,000,955 | ---- | C] () -- C:\Users\lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012.10.20 17:13:55 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf [2012.10.20 17:12:38 | 000,144,909 | ---- | C] () -- C:\Windows\System32\fsmgmt.msc [2012.10.20 17:12:37 | 000,012,198 | ---- | C] () -- C:\Windows\System32\gatherWiredInfo.vbs [2012.10.20 17:12:30 | 000,195,122 | ---- | C] () -- C:\Windows\System32\winrm.vbs [2012.10.20 17:08:03 | 000,327,680 | ---- | C] () -- C:\Windows\SPInstall.etl [2012.10.17 18:01:44 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012.10.17 18:01:44 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012.10.17 18:01:44 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012.10.17 18:01:44 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012.10.17 18:01:44 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012.10.17 16:44:39 | 2146,754,560 | -HS- | C] () -- C:\hiberfil.sys [2012.10.16 16:16:37 | 000,019,992 | ---- | C] () -- C:\Users\lukas\Documents\logfiles.zip [2012.10.12 16:20:36 | 169,650,795 | ---- | C] () -- C:\Windows\MEMORY.DMP [2012.10.12 16:10:09 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.01 23:44:46 | 000,001,024 | ---- | C] () -- C:\Users\lukas\Desktop\hbedv.key [2012.04.11 14:56:34 | 000,141,021 | ---- | C] () -- C:\Users\lukas\.recently-used.xbel [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2010.08.11 18:25:56 | 000,121,741 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010.08.11 18:25:55 | 000,121,741 | ---- | C] () -- C:\ProgramData\nvModes.dat [2008.09.11 19:05:21 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib [2008.04.09 13:49:05 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat [2008.02.02 13:58:33 | 000,001,356 | ---- | C] () -- C:\Users\lukas\AppData\Local\d3d9caps.dat [2007.12.30 16:10:57 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html [2007.12.29 19:40:15 | 000,098,816 | ---- | C] () -- C:\Users\lukas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009.04.10 23:28:26 | 011,584,000 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.10 23:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2009.01.10 16:04:37 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Activision [2008.01.21 18:19:02 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\dBpoweramp [2011.06.12 01:29:40 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\DVDVideoSoftIEHelpers [2012.04.11 14:56:34 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\gtk-2.0 [2012.03.23 18:36:29 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\ICQ [2008.12.10 18:49:06 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\MAGIX [2010.08.28 17:02:41 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\mp3DirectCut [2008.12.12 18:46:24 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\MP3toiPodAudioBookConverter [2009.01.09 18:26:11 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\ProtectDisc [2011.12.30 00:38:17 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Sports Interactive [2011.11.05 00:58:21 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\temp [2008.09.21 14:51:53 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Tobit [2011.12.12 20:55:49 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Tropico 3 [2011.12.23 15:26:02 | 000,000,000 | ---D | M] -- C:\Users\lukas\AppData\Roaming\Ubisoft ========== Purity Check ========== < End of report >
konnte ich nicht ausführen, da ich den Reiter nicht gefunden habe. Über Systemsteuerung -> Programme und Funktionen kann ich Programme lediglich deinstallieren. Hm, offenbar hat er das doch in den gestrigen Beitrag gepostet. Sehr seltsam |
21.10.2012, 14:19 | #14 | ||||
/// TB-Ausbilder | lumviexdopag.exe - Trojaner? Prima! Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: ESET-Funde löschen Schritt 2: Combofix deinstallieren Schritt 3: Toolbereinigung mit OTL Schritt 4: AdwCleaner entfernen Schritt 5: ESET deinstallieren (Optional) Abschließend noch Tipps zu folgenden Themen:
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
21.10.2012, 14:52 | #15 |
| lumviexdopag.exe - Trojaner? Wunderbar, alles läuft wieder einwandfrei. Ich danke dir für deine Hilfe ryder, alleine hätte ich das nie geschafft. Super Service hier im trojaner-board! |
Themen zu lumviexdopag.exe - Trojaner? |
abbrechen, analysieren, angeklickt, ausführbare, ausführbare datei, ausgeführt, bluescree, datei, deaktiviert, fragt, geklickt, guten, häufiger, logfiles, namen, runterfahren, sicherheitscenter, tagen, troja, trojaner, trojaner?, verbirgt, vermutlich, virus, virustotal.com, windows |