|
Log-Analyse und Auswertung: Weißer Bildschirm, "Website kann nicht angezeigt werdenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.10.2012, 17:24 | #1 | |
| Weißer Bildschirm, "Website kann nicht angezeigt werden Hallo habe folgendes problem Beim Starten des PCs erscheint ein weißer Bildschirm mit der Botschaft "Website kann nicht angezeigt werden" als Problembehebung wird nur das Aktalisieren der Website vorgeschlagen. Kann weder auf Programme, Desktop etc. zugreifen, die Darstellung überdeckt alles. MFG Zitat:
|
23.10.2012, 07:56 | #2 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden Hi,
__________________Fixen mit OTL
Code:
ATTFilter :OTL O4 - HKLM..\Run: [ROC_ROC_NT] File not found O4 - HKU\Viktor_ON_D..\Run: [qovcazdihoegacq] D:\Windows\qovcazdi.exe () [2012/10/22 07:51:41 | 000,000,000 | ---D | C] -- D:\ProgramData\llpesmvihzxvnkp [2012/10/22 07:51:41 | 000,076,353 | ---- | M] () -- D:\ProgramData\ohlbxzxxfguuovt [2012/10/22 07:50:57 | 000,132,608 | ---- | M] () -- D:\Windows\qovcazdi.exe [2012/10/22 07:50:57 | 000,132,608 | ---- | M] () -- D:\ProgramData\qovcazdi.exe @Alternate Data Stream - 152 bytes -> D:\Users\Viktor\Desktop\Auto4.bmp:3or4kl4x13tuuug3Byamue2s4b @Alternate Data Stream - 152 bytes -> D:\Users\Viktor\Desktop\Auto3.bmp:3or4kl4x13tuuug3Byamue2s4b @Alternate Data Stream - 152 bytes -> D:\Users\Viktor\Desktop\Auto2.bmp:3or4kl4x13tuuug3Byamue2s4b @Alternate Data Stream - 152 bytes -> D:\Users\Viktor\Desktop\Auto1.bmp:3or4kl4x13tuuug3Byamue2s4b
Rechner normal booten, dann das hier: Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s %windir%\installer\*. /5 %localappdata%\*. /5 CREATERESTOREPOINT
__________________ |
23.10.2012, 14:12 | #3 | |
| Weißer Bildschirm, "Website kann nicht angezeigt werden leider kommt das bild immer noch und ich kann schritt 2 nicht ausführen
__________________hier ist das ergebnis von schritt eins Zitat:
|
23.10.2012, 14:14 | #4 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden Mach mal bitte mit OTLPE ein neues Scan-Logfile und poste es.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.10.2012, 16:10 | #5 |
| Weißer Bildschirm, "Website kann nicht angezeigt werden hier ist das ergebniss OTL Logfile: Code:
ATTFilter OTL logfile created on: 10/23/2012 9:45:07 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE 64bit-Windows 7 Home Premium (Version = 6.1.7600) - Type = System Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 88.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86) Drive C: | 100.00 Mb Total Space | 74.29 Mb Free Space | 74.29% Space Free | Partition Type: NTFS Drive D: | 160.88 Gb Total Space | 55.00 Gb Free Space | 34.19% Space Free | Partition Type: NTFS Drive E: | 290.78 Gb Total Space | 278.19 Gb Free Space | 95.67% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010/06/15 06:51:56 | 000,822,304 | ---- | M] (Acer Incorporated) [Auto] -- D:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe -- (ePowerSvc) SRV:64bit: - [2010/04/20 19:34:40 | 000,202,752 | ---- | M] (AMD) [Auto] -- D:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/01/28 19:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto] -- D:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service) SRV:64bit: - [2009/11/02 07:48:18 | 000,126,352 | ---- | M] (Intel(R) Corporation) [On_Demand] -- D:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost) SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- D:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2012/10/09 14:43:27 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/10/01 21:32:58 | 000,193,568 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- D:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd) SRV - [2012/10/01 21:32:04 | 005,783,672 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- D:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent) SRV - [2012/09/07 21:38:40 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand] -- D:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/09/07 11:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/09/07 11:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/08/13 07:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Disabled] -- D:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto] -- D:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010/11/21 05:49:24 | 000,247,608 | ---- | M] () [Disabled] -- D:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2010/09/30 09:00:28 | 000,253,264 | ---- | M] () [Auto] -- D:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe -- (UI Assistant Service) SRV - [2010/08/10 05:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto] -- D:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService) SRV - [2010/07/29 08:16:12 | 000,052,896 | ---- | M] (Atheros Commnucations) [Auto] -- D:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc) SRV - [2010/07/01 00:10:26 | 002,533,400 | ---- | M] (Intel Corporation) [Auto] -- D:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R) SRV - [2010/07/01 00:10:22 | 000,325,656 | ---- | M] (Intel Corporation) [Auto] -- D:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R) SRV - [2010/06/28 18:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto] -- D:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc) SRV - [2010/05/26 22:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand] -- D:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService) SRV - [2010/03/18 08:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/01/08 09:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto] -- D:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService) SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012/10/04 21:26:22 | 000,111,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot] -- D:\Windows\System32\drivers\avgmfx64.sys -- (Avgmfx64) DRV:64bit: - [2012/10/02 19:32:40 | 000,031,080 | ---- | M] (AVG Technologies) [Kernel | System] -- D:\Windows\System32\drivers\avgtpx64.sys -- (avgtp) DRV:64bit: - [2012/10/01 21:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- D:\Windows\System32\drivers\avgldx64.sys -- (Avgldx64) DRV:64bit: - [2012/09/20 21:46:04 | 000,200,032 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- D:\Windows\System32\drivers\avgtdia.sys -- (Avgtdia) DRV:64bit: - [2012/09/20 21:46:00 | 000,225,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot] -- D:\Windows\System32\drivers\avgloga.sys -- (Avgloga) DRV:64bit: - [2012/09/20 21:45:50 | 000,061,792 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot] -- D:\Windows\System32\drivers\avgidsha.sys -- (AVGIDSHA) DRV:64bit: - [2012/09/13 21:05:18 | 000,040,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot] -- D:\Windows\System32\drivers\avgrkx64.sys -- (Avgrkx64) DRV:64bit: - [2012/09/12 21:11:18 | 000,151,904 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System] -- D:\Windows\System32\drivers\avgidsdrivera.sys -- (AVGIDSDriver) DRV:64bit: - [2012/09/07 11:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- D:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/02/15 18:24:40 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) DRV:64bit: - [2012/02/15 18:24:38 | 000,099,384 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) DRV:64bit: - [2010/11/17 08:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand] -- D:\Windows\System32\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2010/07/29 08:16:30 | 000,270,496 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btfilter.sys -- (BtFilter) DRV:64bit: - [2010/07/29 08:16:28 | 000,295,072 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_a2dp.sys -- (BTATH_A2DP) DRV:64bit: - [2010/07/29 08:16:28 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_hcrp.sys -- (BTATH_HCRP) DRV:64bit: - [2010/07/29 08:16:28 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_rcp.sys -- (BTATH_RCP) DRV:64bit: - [2010/07/29 08:16:28 | 000,051,872 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_lwflt.sys -- (BTATH_LWFLT) DRV:64bit: - [2010/07/29 08:16:28 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_flt.sys -- (AthBTPort) DRV:64bit: - [2010/07/29 08:16:28 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btath_bus.sys -- (BTATH_BUS) DRV:64bit: - [2010/07/15 17:57:34 | 002,350,952 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\athrx.sys -- (athr) DRV:64bit: - [2010/06/24 22:33:36 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\L1C62x64.sys -- (L1C) DRV:64bit: - [2010/06/05 10:27:58 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\igdpmd64.sys -- (intelkmd) DRV:64bit: - [2010/05/05 17:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2010/04/20 21:15:04 | 006,406,144 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\atipmdag.sys -- (amdkmdag) DRV:64bit: - [2010/04/20 18:39:36 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010/02/10 03:02:00 | 000,158,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\Impcd.sys -- (Impcd) DRV:64bit: - [2009/11/02 07:48:02 | 000,013,784 | ---- | M] () [Kernel | Auto] -- D:\Windows\System32\drivers\TurboB.sys -- (TurboB) DRV:64bit: - [2009/10/29 14:28:24 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV:64bit: - [2009/10/29 14:28:24 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV:64bit: - [2009/10/29 14:28:24 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV:64bit: - [2009/10/29 14:28:24 | 000,011,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand] -- D:\Windows\System32\drivers\massfilter.sys -- (massfilter) DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\HECIx64.sys -- (HECIx64) Intel(R) DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- D:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/02 22:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System] -- D:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk) DRV:64bit: - [2009/06/02 22:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System] -- D:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter) DRV:64bit: - [2009/06/02 22:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System] -- D:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ) DRV:64bit: - [2009/05/26 09:32:38 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand] -- D:\Windows\system32\drivers\AmUStor.SYS -- (AmUStor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.funmoods.com/?f=1&a=fmtgl&chnl=fmtgl&cd=2XzuyEtN2Y1L1QzuzytBzy0F0F0AzytB0E0DzyzyyD0D0A0DtN0D0Tzu0CtCzyzytN1L2XzutBtFtCtFtDtFtAtDtC&cr=1525869463 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Viktor_ON_D\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_0&u=443F8AC41D7AC23FF253DE4F88C4F014 IE - HKU\Viktor_ON_D\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com IE - HKU\Viktor_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = IE - HKU\Viktor_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search" FF - prefs.js..browser.search.update: "" FF - prefs.js..backup.old.browser.search.defaultenginename: "" FF - prefs.js..backup.old.browser.search.selectedEngine: "" FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..browser.search.defaultthis.engineName: "" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.update: false FF - prefs.js..browser.search.useDBForOrder: "" FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..extensions.enabledItems: "" FF - prefs.js..extensions.enabledItems: "" FF - prefs.js..extensions.enabledItems: "" FF - prefs.js..extensions.enabledItems: "" FF - prefs.js..network.proxy.type: "" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\System32\Macromed\Flash\NPSWF64_11_4_402_287.dll () FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll () FF - HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: D:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: D:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: D:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\msntoolbar@msn.com: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/01/13 12:54:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/01/13 12:54:39 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/01/13 12:54:47 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\12.2.5.34\ FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 21:38:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/07 21:38:38 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}: C:\Users\Viktor\AppData\Roaming\14001.018 [2012/08/27 06:02:26 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 21:38:40 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/07 21:38:38 | 000,000,000 | ---D | M] [2012/10/02 19:26:31 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Viktor\AppData\Roaming\Mozilla\Extensions [2012/10/05 14:24:33 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Viktor\AppData\Roaming\Mozilla\Firefox\Profiles\pjq5x742.default\extensions [2012/03/28 21:15:34 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- D:\Users\Viktor\AppData\Roaming\Mozilla\Firefox\Profiles\pjq5x742.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} File not found (No name found) -- File not found (No name found) -- D:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} File not found (No name found) -- D:\PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION File not found (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\14001.003 File not found (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PJQ5X742.DEFAULT\EXTENSIONS\{87934C42-161D-45BC-8CEF-EF18ABE2A30C} File not found (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PJQ5X742.DEFAULT\EXTENSIONS\{99079A25-328F-4BD4-BE04-00955ACAA0A7} File not found (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PJQ5X742.DEFAULT\EXTENSIONS\{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} File not found (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PJQ5X742.DEFAULT\EXTENSIONS\BBRS_002@BLABBERS.COM File not found (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PJQ5X742.DEFAULT\EXTENSIONS\FFXTLBR@FUNMOODS.COM () (No name found) -- D:\USERS\VIKTOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PJQ5X742.DEFAULT\EXTENSIONS\TOOLBAR@GMX.NET.XPI [2012/09/07 21:38:40 | 000,266,720 | ---- | M] (Mozilla Foundation) -- D:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012/03/19 20:07:54 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - File not found O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll (Google Inc.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - File not found O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.) O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - D:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) O3:64bit: - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - D:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - File not found O3 - HKU\Viktor_ON_D\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O4 - HKLM..\Run: [AVG_UI] D:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [LManager] D:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKU\LocalService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\Viktor_ON_D..\Run: [qovcazdihoegacq] D:\Windows\qovcazdi.exe () O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class) O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) O18:64bit: - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/10/22 07:51:41 | 000,000,000 | ---D | C] -- D:\ProgramData\llpesmvihzxvnkp [2012/10/15 11:29:23 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG [2012/10/10 12:11:20 | 005,505,904 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ntoskrnl.exe [2012/10/10 12:11:19 | 003,958,128 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ntkrnlpa.exe [2012/10/10 12:11:19 | 003,902,832 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ntoskrnl.exe [2012/10/10 12:11:08 | 001,162,240 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\kernel32.dll [2012/10/10 12:11:08 | 000,425,984 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\KernelBase.dll [2012/10/10 12:11:08 | 000,338,432 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\conhost.exe [2012/10/10 12:11:08 | 000,215,040 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\winsrv.dll [2012/10/10 12:11:07 | 000,362,496 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wow64win.dll [2012/10/10 12:11:07 | 000,243,200 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wow64.dll [2012/10/10 12:11:07 | 000,025,600 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\setup16.exe [2012/10/10 12:11:07 | 000,016,384 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ntvdm64.dll [2012/10/10 12:11:07 | 000,014,336 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ntvdm64.dll [2012/10/10 12:11:07 | 000,013,312 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wow64cpu.dll [2012/10/10 12:11:07 | 000,007,680 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\instnm.exe [2012/10/10 12:11:07 | 000,005,120 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\wow32.dll [2012/10/10 12:11:06 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-security-base-l1-1-0.dll [2012/10/10 12:11:06 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2012/10/10 12:11:06 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-file-l1-1-0.dll [2012/10/10 12:11:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll [2012/10/10 12:11:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2012/10/10 12:11:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2012/10/10 12:11:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll [2012/10/10 12:11:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2012/10/10 12:11:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll [2012/10/10 12:11:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll [2012/10/10 12:11:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-util-l1-1-0.dll [2012/10/10 12:11:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll [2012/10/10 12:11:05 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll [2012/10/10 12:11:05 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll [2012/10/10 12:11:05 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2012/10/10 12:11:05 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-string-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-io-l1-1-0.dll [2012/10/10 12:11:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2012/10/10 12:11:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll [2012/10/10 12:11:03 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2012/10/10 12:11:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2012/10/10 12:11:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll [2012/10/10 12:11:02 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2012/10/10 12:11:02 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2012/10/10 12:11:02 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll [2012/10/10 12:11:02 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2012/10/10 12:11:02 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2012/10/10 12:11:02 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2012/10/10 12:11:02 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-console-l1-1-0.dll [2012/10/10 12:10:59 | 000,002,048 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\user.exe [2012/10/10 12:10:51 | 000,220,160 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wintrust.dll [2012/10/10 12:10:51 | 000,172,544 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\wintrust.dll [2012/10/10 12:10:38 | 001,462,784 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\crypt32.dll [2012/10/10 12:10:38 | 000,140,288 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\cryptnet.dll [2012/10/04 21:26:22 | 000,111,456 | ---- | C] (AVG Technologies CZ, s.r.o.) -- D:\Windows\System32\drivers\avgmfx64.sys [2012/10/03 00:52:03 | 002,237,440 | R--- | C] (OldTimer Tools) -- D:\OTLPE.exe [2012/10/02 21:04:28 | 000,000,000 | ---D | C] -- D:\Users\Viktor\AppData\Roaming\Malwarebytes [2012/10/02 21:04:06 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/10/02 21:04:06 | 000,000,000 | ---D | C] -- D:\ProgramData\Malwarebytes [2012/10/02 21:04:05 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- D:\Windows\System32\drivers\mbam.sys [2012/10/02 21:04:05 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware [2012/10/02 19:34:08 | 000,000,000 | ---D | C] -- D:\Users\Viktor\AppData\Roaming\AVG2013 [2012/10/02 19:32:40 | 000,031,080 | ---- | C] (AVG Technologies) -- D:\Windows\System32\drivers\avgtpx64.sys [2012/10/02 19:31:18 | 000,000,000 | -H-D | C] -- D:\$AVG [2012/10/02 19:31:17 | 000,000,000 | ---D | C] -- D:\ProgramData\AVG2013 [2012/10/02 19:30:28 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\AVG [2012/10/02 19:27:05 | 000,000,000 | -H-D | C] -- D:\ProgramData\Common Files [2012/10/02 19:27:05 | 000,000,000 | ---D | C] -- D:\Users\Viktor\AppData\Local\MFAData [2012/10/02 19:27:05 | 000,000,000 | ---D | C] -- D:\ProgramData\MFAData [2012/10/02 19:27:05 | 000,000,000 | ---D | C] -- D:\Users\Viktor\AppData\Local\Avg2013 [2012/10/01 23:55:58 | 000,000,000 | ---D | C] -- D:\_OTL [2012/10/01 21:30:38 | 000,185,696 | ---- | C] (AVG Technologies CZ, s.r.o.) -- D:\Windows\System32\drivers\avgldx64.sys [2012/09/24 14:21:31 | 000,000,000 | ---D | C] -- D:\Users\Viktor\AppData\Local\Macromedia [2012/09/24 14:15:08 | 000,696,760 | ---- | C] (Adobe Systems Incorporated) -- D:\Windows\SysWow64\FlashPlayerApp.exe [3 D:\Users\Viktor\AppData\Roaming\*.tmp files -> D:\Users\Viktor\AppData\Roaming\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/10/23 13:08:35 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat [2012/10/23 13:08:05 | 000,001,106 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/10/23 13:07:45 | 000,065,536 | ---- | M] () -- D:\Windows\System32\Ikeext.etl [2012/10/23 13:07:36 | 2960,510,976 | -HS- | M] () -- D:\hiberfil.sys [2012/10/22 16:47:21 | 000,009,696 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/10/22 16:47:21 | 000,009,696 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/10/22 09:43:55 | 265,040,132 | ---- | M] () -- D:\Windows\MEMORY.DMP [2012/10/22 08:43:17 | 000,000,884 | ---- | M] () -- D:\Windows\tasks\Adobe Flash Player Updater.job [2012/10/22 07:55:00 | 000,001,110 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/10/22 07:51:41 | 000,076,353 | ---- | M] () -- D:\ProgramData\ohlbxzxxfguuovt [2012/10/22 07:50:57 | 000,132,608 | ---- | M] () -- D:\Windows\qovcazdi.exe [2012/10/22 07:50:57 | 000,132,608 | ---- | M] () -- D:\ProgramData\qovcazdi.exe [2012/10/15 11:29:23 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG [2012/10/14 16:39:30 | 000,654,400 | ---- | M] () -- D:\Windows\System32\perfh007.dat [2012/10/14 16:39:30 | 000,616,242 | ---- | M] () -- D:\Windows\System32\perfh009.dat [2012/10/14 16:39:30 | 000,130,240 | ---- | M] () -- D:\Windows\System32\perfc007.dat [2012/10/14 16:39:30 | 000,106,622 | ---- | M] () -- D:\Windows\System32\perfc009.dat [2012/10/09 14:43:27 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- D:\Windows\SysWow64\FlashPlayerApp.exe [2012/10/09 14:43:27 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- D:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012/10/04 21:26:22 | 000,111,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Windows\System32\drivers\avgmfx64.sys [2012/10/02 21:04:06 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/10/02 20:55:43 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [2012/10/02 19:32:40 | 000,031,080 | ---- | M] (AVG Technologies) -- D:\Windows\System32\drivers\avgtpx64.sys [2012/10/01 21:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Windows\System32\drivers\avgldx64.sys [3 D:\Users\Viktor\AppData\Roaming\*.tmp files -> D:\Users\Viktor\AppData\Roaming\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/10/22 07:51:40 | 000,132,608 | ---- | C] () -- D:\Windows\qovcazdi.exe [2012/10/22 07:51:40 | 000,132,608 | ---- | C] () -- D:\ProgramData\qovcazdi.exe [2012/10/22 07:51:00 | 000,076,353 | ---- | C] () -- D:\ProgramData\ohlbxzxxfguuovt [2012/09/24 14:15:08 | 000,000,884 | ---- | C] () -- D:\Windows\tasks\Adobe Flash Player Updater.job [2012/08/28 18:19:34 | 000,065,536 | ---- | C] () -- D:\Users\Viktor\AppData\Roaming\pjq5x742.default.dat [2012/07/23 08:50:30 | 000,000,025 | ---- | C] () -- D:\Users\Viktor\AppData\Roaming\urhtps.dat [2011/06/14 05:36:39 | 000,000,064 | ---- | C] () -- D:\Windows\SysWow64\rp_stats.dat [2011/06/14 05:36:39 | 000,000,044 | ---- | C] () -- D:\Windows\SysWow64\rp_rules.dat [2011/04/13 15:59:14 | 000,059,904 | ---- | C] () -- D:\Windows\SysWow64\OVDecode.dll [2011/02/15 12:52:16 | 000,000,000 | ---- | C] () -- D:\Windows\nsreg.dat [2011/01/13 12:41:19 | 000,000,000 | ---- | C] () -- D:\Windows\ativpsrm.bin [2011/01/13 12:37:22 | 000,002,093 | ---- | C] () -- D:\Windows\SysWow64\atipblup.dat [2010/09/08 04:17:26 | 000,870,560 | ---- | C] () -- D:\Windows\SysWow64\igkrng575.bin [2010/09/08 04:17:26 | 000,208,896 | ---- | C] () -- D:\Windows\SysWow64\iglhsip32.dll [2010/09/08 04:17:26 | 000,143,360 | ---- | C] () -- D:\Windows\SysWow64\iglhcp32.dll [2010/09/08 04:17:26 | 000,104,636 | ---- | C] () -- D:\Windows\SysWow64\igfcg575m.bin [2010/09/08 04:17:25 | 000,127,868 | ---- | C] () -- D:\Windows\SysWow64\igcompkrng575.bin [2010/09/08 04:17:24 | 000,002,093 | ---- | C] () -- D:\Windows\SysWow64\atipblag.dat [2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- D:\Windows\bootstat.dat [2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- D:\Windows\SysWow64\NOISE.DAT [2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- D:\Windows\SysWow64\dssec.dat [2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- D:\Windows\mib.bin [2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- D:\Windows\SysWow64\DShowRdpFilter.dll [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- D:\Windows\SysWow64\ir32_32.dll [2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- D:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- D:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2010/09/08 03:52:37 | 000,000,000 | ---D | M] -- D:\ProgramData\Acer [2010/09/08 03:34:08 | 000,000,000 | ---D | M] -- D:\ProgramData\AmUStor [2011/02/12 18:24:14 | 000,000,000 | -HSD | M] -- D:\ProgramData\Anwendungsdaten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Application Data [2011/02/14 18:56:11 | 000,000,000 | ---D | M] -- D:\ProgramData\ashampoo [2012/10/03 02:53:13 | 000,000,000 | ---D | M] -- D:\ProgramData\AVAST Software [2012/10/02 20:07:38 | 000,000,000 | ---D | M] -- D:\ProgramData\AVG2013 [2010/09/08 04:04:17 | 000,000,000 | ---D | M] -- D:\ProgramData\BackupManager [2012/06/20 08:45:37 | 000,000,000 | ---D | M] -- D:\ProgramData\Battle.net [2012/05/31 11:28:27 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonBJ [2012/10/02 19:27:05 | 000,000,000 | -H-D | M] -- D:\ProgramData\Common Files [2011/02/14 19:10:19 | 000,000,000 | ---D | M] -- D:\ProgramData\createpart [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Desktop [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Documents [2011/02/12 18:24:14 | 000,000,000 | -HSD | M] -- D:\ProgramData\Dokumente [2011/01/13 12:42:32 | 000,000,000 | ---D | M] -- D:\ProgramData\EgisTec IPS [2010/09/08 03:39:41 | 000,000,000 | ---D | M] -- D:\ProgramData\eSobi [2011/02/14 19:09:58 | 000,000,000 | ---D | M] -- D:\ProgramData\explauncher [2011/02/12 18:24:14 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favoriten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favorites [2012/06/07 17:05:13 | 000,000,000 | ---D | M] -- D:\ProgramData\Friends Games [2012/07/24 14:18:25 | 000,000,000 | ---D | M] -- D:\ProgramData\GFI Software [2011/05/12 13:35:47 | 000,000,000 | ---D | M] -- D:\ProgramData\ICQ [2011/02/14 19:09:55 | 000,000,000 | ---D | M] -- D:\ProgramData\launcher [2012/10/22 07:51:41 | 000,000,000 | ---D | M] -- D:\ProgramData\llpesmvihzxvnkp [2012/10/22 06:22:08 | 000,000,000 | ---D | M] -- D:\ProgramData\MFAData [2010/09/08 03:48:10 | 000,000,000 | ---D | M] -- D:\ProgramData\OberonGameConsole [2011/02/12 11:26:58 | 000,000,000 | ---D | M] -- D:\ProgramData\oem [2012/06/08 04:13:07 | 000,000,000 | ---D | M] -- D:\ProgramData\Sandlot Games [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Start Menu [2011/02/12 18:24:14 | 000,000,000 | -HSD | M] -- D:\ProgramData\Startmenü [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Templates [2012/06/20 10:20:35 | 000,000,000 | ---D | M] -- D:\ProgramData\TuneUp Software [2011/02/12 18:24:14 | 000,000,000 | -HSD | M] -- D:\ProgramData\Vorlagen [2011/02/14 18:40:07 | 000,000,000 | -HSD | M] -- D:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2012/08/01 03:32:34 | 000,032,640 | ---- | M] () -- D:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
23.10.2012, 17:33 | #6 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden nanü, irgendwie will OTLPE mich foppen. Gleich nochmal. Inhalt der Codebox in die Box Benutzerdefinierte Scans/Fixes bei OTLPE kopieren, dann Fix drücken. Wenn das Tool fertig ist Rechner neustarten. Code:
ATTFilter :OTL O4 - HKU\Viktor_ON_D..\Run: [qovcazdihoegacq] D:\Windows\qovcazdi.exe () [2012/10/22 07:51:41 | 000,000,000 | ---D | C] -- D:\ProgramData\llpesmvihzxvnkp [2012/10/22 07:51:41 | 000,076,353 | ---- | M] () -- D:\ProgramData\ohlbxzxxfguuovt [2012/10/22 07:50:57 | 000,132,608 | ---- | M] () -- D:\Windows\qovcazdi.exe [2012/10/22 07:50:57 | 000,132,608 | ---- | M] () -- D:\ProgramData\qovcazdi.exe
__________________ --> Weißer Bildschirm, "Website kann nicht angezeigt werden |
23.10.2012, 19:35 | #7 | |
| Weißer Bildschirm, "Website kann nicht angezeigt werden hallo leider hat es wieder nicht geklappt :-( Zitat:
|
24.10.2012, 06:18 | #8 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden Downloade dir bitte Farbar Recovery Scan Tool 64-Bit und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager
Mit Windows CD/DVD
Wähle in den Reparaturoptionen Eingabeaufforderung
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.10.2012, 13:56 | #9 | |
| Weißer Bildschirm, "Website kann nicht angezeigt werden so hier ist das ergebniss Zitat:
|
24.10.2012, 14:15 | #10 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\Viktor\...\Run: [qovcazdihoegacq] C:\Windows\qovcazdi.exe [132608 2012-10-22] () HKU\Viktor\...\Winlogon: [Shell] 2012-10-22 03:51 - 2012-10-22 03:51 - 00076353 ____A C:\Users\All Users\ohlbxzxxfguuovt 2012-10-22 03:51 - 2012-10-22 03:51 - 00000000 ____D C:\Users\All Users\llpesmvihzxvnkp 2012-10-22 03:51 - 2012-10-22 03:50 - 00132608 ____A C:\Windows\qovcazdi.exe 2012-10-22 03:51 - 2012-10-22 03:50 - 00132608 ____A C:\Users\All Users\qovcazdi.exe 2012-10-22 03:50 - 2012-10-22 03:50 - 00132608 ____A C:\Users\Viktor\0.39205960266991524.exe
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.10.2012, 15:47 | #11 | |
| Weißer Bildschirm, "Website kann nicht angezeigt werden so hier die daten Zitat:
|
24.10.2012, 16:28 | #12 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden Reboot in Windows möglich?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.10.2012, 19:31 | #13 |
| Weißer Bildschirm, "Website kann nicht angezeigt werden ja er fährt wieder hoch vielen dank |
25.10.2012, 07:06 | #14 |
/// the machine /// TB-Ausbilder | Weißer Bildschirm, "Website kann nicht angezeigt werden Dann jetzt bitte das hier im normalen Windows: Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s %windir%\installer\*. /5 %localappdata%\*. /5 CREATERESTOREPOINT
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.11.2012, 19:21 | #15 | |
| Weißer Bildschirm, "Website kann nicht angezeigt werden guten tag der rechner hat noch mal das selbe problem das hat frst ausgespuckt Zitat:
|
Themen zu Weißer Bildschirm, "Website kann nicht angezeigt werden |
adobe, autorun, avg, avg secure search, avg security toolbar, bho, bildschirm, defender, desktop, device driver, error, firefox, flash player, format, helper, home, homepage, igdpmd64.sys, launch, logfile, mozilla, mywinlocker, plug-in, port, problem, registry, scan, secure search, security, services.exe, software, starten, usb |