|
Plagegeister aller Art und deren Bekämpfung: Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
17.11.2012, 15:27 | #1 |
| Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Hallo, habe mir einen Verschlüselungstrojaner eingehandelt, habe gemäß Eurer ersten Anleitung einen vollständigen Scan mit Malwarebytes durchgeführt, aber noch nichts gelöscht, Bericht anbei: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Datenbank Version: v2012.11.17.02 Windows 7 Service Pack 1 x86 NTFS (Abgesichertenmodus/Netzwerkfähig) Internet Explorer 9.0.8112.16421 Administrator :: MARK-PC [Administrator] 17.11.2012 14:40:35 mbam-log-2012-11-17 (15-15-04).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 363594 Laufzeit: 26 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\Mark\AppData\Local\Temp\wgsdgsdgdsgsd.exe (Exploit.Drop.GS) -> Keine Aktion durchgeführt. C:\ProgramData\lsass.exe (Trojan.Delf) -> Keine Aktion durchgeführt. (Ende) Wie muß ich nun weiter vorgehen? Vorab schon mal besten Dank für Eure Unterstützung |
18.11.2012, 23:13 | #2 | |
/// TB-Ausbilder | Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Hallo brauchst du noch Hilfe?
__________________Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Customscan mit OTL
__________________ |
20.11.2012, 13:41 | #3 |
/// TB-Ausbilder | Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Fehlende Rückmeldung
__________________Dieses Thema wurde aus den Abos gelöscht. Somit bekomm ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen
__________________ |
24.11.2012, 12:56 | #4 |
| Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) OTL.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.11.2012 12:32:36 - Run 2 OTL by OldTimer - Version 3.2.61.5 Folder = C:\Users\Mark\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16438) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,50 Gb Total Physical Memory | 2,45 Gb Available Physical Memory | 69,93% Memory free 7,00 Gb Paging File | 5,93 Gb Available in Paging File | 84,76% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 323,63 Gb Total Space | 260,53 Gb Free Space | 80,50% Space Free | Partition Type: NTFS Drive D: | 335,34 Gb Total Space | 313,57 Gb Free Space | 93,51% Space Free | Partition Type: NTFS Computer Name: MARK-PC | User Name: Mark | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: On | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe () PRC - C:\Programme\Alwil Software\Avast5\AvastUI.exe (AVAST Software) PRC - C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) PRC - C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) PRC - C:\Programme\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) PRC - C:\Programme\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) PRC - C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Users\Mark\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Eraser\Eraser.exe (The Eraser Project) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Programme\VIA\VIAudioi\VDeck\VDeck.exe (VIA) ========== Modules (No Company Name) ========== MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\239d84cfdb9de9730c1efb43840ef2eb\System.Core.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll () MOD - C:\Programme\Western Digital\WD SmartWare\WDCollections.dll () MOD - C:\Programme\VIA\VIAudioi\VDeck\VMicApi.dll () MOD - C:\Programme\VIA\VIAudioi\VDeck\skin.dll () MOD - C:\Programme\VIA\VIAudioi\VDeck\QsApoApi.dll () MOD - C:\Programme\VIA\VIAudioi\VDeck\Dts2ApoApi.dll () ========== Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies) SRV - (HuaweiHiSuiteService.exe) -- C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe () SRV - (avast! Antivirus) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) SRV - (Stereo Service) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (WDRulesService) -- C:\Programme\Western Digital\WD SmartWare\WDRulesEngine.exe (Western Digital ) SRV - (WDFMEService) -- C:\Programme\Western Digital\WD SmartWare\WDFME.exe (Western Digital ) SRV - (WDDMService) -- C:\Programme\Western Digital\WD SmartWare\WDDMService.exe (WDC) SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV - (ACDaemon) -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (SandraAgentSrv) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\RpcAgentSrv.exe (SiSoftware) SRV - (uCamMonitor) -- C:\Programme\Hama\Hama Webcam Suite\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.) ========== Driver Services (SafeList) ========== DRV - (SNPSTD3) -- system32\DRIVERS\snpstd3.sys File not found DRV - (ALSysIO) -- C:\Users\Mark\AppData\Local\Temp\ALSysIO.sys File not found DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software) DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software) DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software) DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software) DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software) DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (RTL8192su) -- C:\Windows\System32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation ) DRV - (WinUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (FWLANUSB) -- C:\Windows\System32\drivers\fwlanusb.sys (AVM GmbH) DRV - (avmeject) -- C:\Windows\System32\drivers\avmeject.sys (AVM Berlin) DRV - (BVRPMPR5) -- C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software) DRV - (NVNET) -- C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation) DRV - (VIAHdAudAddService) -- C:\Windows\System32\drivers\viahduaa.sys (VIA Technologies, Inc.) DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys () DRV - (SANDRA) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\WNt500x86\sandra.sys (SiSoftware) DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation) DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation) DRV - (WDC_SAM) -- C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies) DRV - (ArcSoftKsUFilter) -- C:\Windows\System32\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.) DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.) DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys () DRV - (cmeu0wdm) -- C:\Windows\System32\drivers\cmeu0wdm.sys (Fujitsu Siemens) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/ IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 EB 46 26 EA BD CB 01 [binary data] IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\..\SearchScopes\{1B6E15C1-66CC-4AAC-AEC4-635EA87A497A}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.yahoo.de" FF - prefs.js..extensions.enabledAddons: {EE223D7A-F30F-11DD-8F0A-D2AD55D89593}:1.0.5 FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1474 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012.11.17 07:35:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.11.16 21:32:50 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.11.19 05:23:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.11.16 20:46:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011.01.27 11:37:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\Extensions [2011.01.27 11:37:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.11.19 04:48:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\kq62sfx6.default\extensions [2012.06.15 09:54:27 | 000,047,658 | ---- | M] () (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\kq62sfx6.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}.xpi [2012.11.21 07:28:06 | 000,001,610 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\kq62sfx6.default\searchplugins\ixquick---deutsch.xml [2012.11.16 21:32:46 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.11.17 07:35:14 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF [2012.11.16 21:32:50 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.10.02 10:25:49 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.08.31 23:33:21 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.10.02 10:25:49 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.10.02 10:25:49 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.02 10:25:49 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.10.02 10:25:49 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Eraser] C:\Programme\Eraser\Eraser.exe (The Eraser Project) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2777542180-2792119682-1362692570-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 10.7.2) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2BE13A16-C617-44E3-A483-5B24E2501C80}: DhcpNameServer = 192.168.42.129 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EC7950A5-48AB-4F56-BCCF-5EAB3F0961D2}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ED80D93A-DCBC-440C-BD94-DE79B5E542A1}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{44e503b0-576a-11e0-9b15-00040ec93d8e}\Shell - "" = AutoRun O33 - MountPoints2\{44e503b0-576a-11e0-9b15-00040ec93d8e}\Shell\AutoRun\command - "" = "K:\WD SmartWare.exe" autoplay=true O33 - MountPoints2\{d38caa4c-29d9-11e0-b5ff-0025226c922f}\Shell - "" = AutoRun O33 - MountPoints2\{d38caa4c-29d9-11e0-b5ff-0025226c922f}\Shell\AutoRun\command - "" = K:\pushinst.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^Users^Mark^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ctfmon.lnk - - File not found MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - State: "startup" - 2 MsConfig - State: "services" - 2 Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L) SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.11.19 05:36:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012.11.19 05:36:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2012.11.19 05:34:17 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\vlc [2012.11.19 05:34:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012.11.19 05:24:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2012.11.19 05:24:31 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2012.11.19 05:23:38 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2012.11.19 05:10:50 | 002,882,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012.11.19 05:10:50 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012.11.19 05:10:50 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012.11.19 05:10:50 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2012.11.19 05:10:50 | 000,745,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe [2012.11.19 05:10:50 | 000,718,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll [2012.11.19 05:10:50 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2012.11.19 05:10:50 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2012.11.19 05:10:50 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012.11.19 05:10:50 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2012.11.19 05:10:50 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2012.11.19 05:10:50 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2012.11.19 05:10:50 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012.11.19 05:10:50 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2012.11.19 05:10:50 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll [2012.11.19 05:10:50 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2012.11.19 05:10:50 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2012.11.19 05:10:50 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2012.11.19 05:10:50 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2012.11.19 05:10:50 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2012.11.19 05:10:50 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2012.11.19 05:10:50 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2012.11.19 05:10:50 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2012.11.19 05:10:50 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2012.11.19 05:10:50 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2012.11.19 05:10:50 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2012.11.19 05:10:50 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2012.11.19 05:10:50 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2012.11.19 05:10:50 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2012.11.19 05:10:50 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2012.11.19 05:10:50 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2012.11.19 05:10:50 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012.11.19 05:10:50 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2012.11.19 05:10:50 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2012.11.19 05:10:50 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2012.11.19 05:10:50 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2012.11.19 05:10:10 | 003,419,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2012.11.19 05:10:10 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmpeg2vdec.dll [2012.11.19 05:10:10 | 001,885,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll [2012.11.19 05:10:10 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll [2012.11.19 05:10:10 | 001,247,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2012.11.19 05:10:10 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2012.11.19 05:10:10 | 001,080,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll [2012.11.19 05:10:10 | 000,604,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll [2012.11.19 05:10:10 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll [2012.11.19 05:10:10 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2012.11.19 05:10:10 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2012.11.19 05:10:10 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll [2012.11.19 05:10:10 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll [2012.11.19 05:10:10 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll [2012.11.19 05:10:10 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll [2012.11.19 05:10:10 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll [2012.11.19 05:10:10 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll [2012.11.19 05:10:10 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll [2012.11.19 05:10:10 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll [2012.11.19 05:10:10 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll [2012.11.19 05:10:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll [2012.11.19 05:10:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll [2012.11.19 05:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll [2012.11.19 05:10:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll [2012.11.19 05:10:10 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll [2012.11.19 05:06:40 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys [2012.11.19 05:06:40 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [2012.11.19 05:06:38 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [2012.11.19 05:06:38 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RdpGroupPolicyExtension.dll [2012.11.19 05:06:32 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys [2012.11.19 05:06:26 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll [2012.11.19 05:06:26 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe [2012.11.19 05:06:26 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsRdpWebAccess.dll [2012.11.19 05:06:26 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll [2012.11.19 05:06:26 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [2012.11.19 05:06:26 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprtPS.dll [2012.11.19 05:06:25 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe [2012.11.19 05:06:25 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll [2012.11.19 05:06:25 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp_winip.dll [2012.11.19 05:06:23 | 002,739,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll [2012.11.19 05:05:38 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll [2012.11.19 04:10:50 | 000,000,000 | ---D | C] -- C:\WinOld [2012.11.18 08:19:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2012.11.18 07:41:36 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys [2012.11.18 07:41:36 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll [2012.11.18 07:41:08 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll [2012.11.18 07:41:03 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll [2012.11.18 07:41:03 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll [2012.11.17 05:49:48 | 000,000,000 | ---D | C] -- C:\ProgramData\HandSetService [2012.11.17 05:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite [2012.11.17 03:09:18 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcorehc.dll [2012.11.17 03:09:18 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll [2012.11.17 03:09:16 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll [2012.11.17 03:09:14 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcore6.dll [2012.11.17 03:09:13 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll [2012.11.16 21:32:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.11.16 20:46:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird [2012.11.16 19:58:07 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll [2012.11.16 19:58:05 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys ========== Files Created - No Company Name ========== [2012.11.19 05:42:19 | 000,004,806 | ---- | C] () -- C:\Users\Mark\Documents\cc_20121119_054217.reg [2012.11.19 05:34:11 | 000,001,028 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012.11.19 05:23:45 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk [2012.11.19 05:10:50 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2012.11.19 04:51:29 | 000,017,636 | ---- | C] () -- C:\Users\Mark\Documents\cc_20121119_045123.reg [2012.11.19 04:41:38 | 000,039,930 | ---- | C] () -- C:\Users\Mark\Documents\cc_20121119_044130.reg [2012.11.18 07:44:58 | 002,219,450 | -H-- | C] () -- C:\Users\Mark\AppData\Local\IconCache.db [2012.11.18 07:41:41 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012.11.18 07:41:02 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012.11.17 12:20:44 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012.11.17 07:32:51 | 011,318,679 | ---- | C] () -- C:\Users\Mark\Documents\2012-11-17_073158.pdf [2012.11.17 05:49:47 | 000,000,857 | ---- | C] () -- C:\Users\Public\Desktop\HiSuite.lnk [2012.08.01 13:32:06 | 011,718,656 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\Sandra.mdb [2012.07.21 22:12:35 | 000,254,382 | ---- | C] () -- C:\Users\Mark\AppData\Local\census.cache [2012.07.21 22:12:15 | 000,116,002 | ---- | C] () -- C:\Users\Mark\AppData\Local\ars.cache [2012.07.21 22:03:08 | 000,000,036 | ---- | C] () -- C:\Users\Mark\AppData\Local\housecall.guid.cache [2012.07.21 08:44:36 | 004,503,728 | ---- | C] () -- C:\ProgramData\kp_0loor.pad [2011.09.13 22:20:26 | 000,000,000 | ---- | C] () -- C:\Users\Mark\AppData\Local\{13B8127D-EBD4-4D92-BA38-BB849DC6E456} [2011.08.01 00:14:04 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin [2011.07.31 09:37:59 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll [2011.07.31 09:37:59 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys [2011.07.31 08:31:11 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011.07.31 01:16:48 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt [2011.07.31 01:07:41 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2011.07.10 19:25:59 | 000,007,651 | ---- | C] () -- C:\Users\Mark\AppData\Local\Resmon.ResmonCfg [2011.03.11 07:36:10 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{49f1c548-4b6b-11e0-9f41-a7134ff72251}.TMContainer00000000000000000002.regtrans-ms [2011.03.11 07:36:10 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{49f1c548-4b6b-11e0-9f41-a7134ff72251}.TMContainer00000000000000000001.regtrans-ms [2011.03.11 07:36:10 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{49f1c548-4b6b-11e0-9f41-a7134ff72251}.TM.blf [2011.03.10 03:54:13 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{f542de99-4abf-11e0-8189-90743f64f657}.TMContainer00000000000000000002.regtrans-ms [2011.03.10 03:54:13 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{f542de99-4abf-11e0-8189-90743f64f657}.TMContainer00000000000000000001.regtrans-ms [2011.03.10 03:54:13 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{f542de99-4abf-11e0-8189-90743f64f657}.TM.blf [2011.02.26 12:52:08 | 000,053,600 | ---- | C] () -- C:\Windows\System32\dosx.exe [2011.02.05 09:49:04 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{b54c0147-30ac-11e0-8877-00040ec93d8e}.TMContainer00000000000000000002.regtrans-ms [2011.02.05 09:49:04 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{b54c0147-30ac-11e0-8877-00040ec93d8e}.TMContainer00000000000000000001.regtrans-ms [2011.02.05 09:49:04 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{b54c0147-30ac-11e0-8877-00040ec93d8e}.TM.blf [2011.01.27 17:01:08 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{2e9d20ab-2a2b-11e0-b93b-00040ec93d8e}.TMContainer00000000000000000002.regtrans-ms [2011.01.27 17:01:08 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{2e9d20ab-2a2b-11e0-b93b-00040ec93d8e}.TMContainer00000000000000000001.regtrans-ms [2011.01.27 17:01:08 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{2e9d20ab-2a2b-11e0-b93b-00040ec93d8e}.TM.blf [2011.01.27 16:37:05 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{d3116a74-2a0f-11e0-a612-00040ec93d8e}.TMContainer00000000000000000002.regtrans-ms [2011.01.27 16:37:04 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{d3116a74-2a0f-11e0-a612-00040ec93d8e}.TMContainer00000000000000000001.regtrans-ms [2011.01.27 16:37:03 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{d3116a74-2a0f-11e0-a612-00040ec93d8e}.TM.blf [2011.01.27 13:08:43 | 000,000,055 | ---- | C] () -- C:\Windows\wininit.ini [2011.01.27 08:11:35 | 000,064,768 | ---- | C] () -- C:\Users\Mark\AppData\Local\GDIPFONTCACHEV1.DAT [2011.01.27 07:01:45 | 001,498,506 | ---- | C] () -- C:\Windows\System32\PerfStringBackup.INI [2011.01.27 06:58:23 | 000,000,020 | -HS- | C] () -- C:\Users\Mark\ntuser.ini [2011.01.27 06:58:22 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms [2011.01.27 06:58:22 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms [2011.01.27 06:58:22 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf [2011.01.27 06:58:21 | 002,621,440 | -HS- | C] () -- C:\Users\Mark\ntuser.dat ========== LOP Check ========== [2012.11.18 05:16:42 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DeepBurner [2011.07.31 08:46:16 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\DeepBurner [2012.11.19 04:29:28 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\IrfanView [2011.05.24 09:31:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Juniper Networks [2012.11.17 09:22:29 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\MyPhoneExplorer [2011.01.28 19:31:37 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\OpenOffice.org [2012.11.19 04:28:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Samsung [2012.04.07 07:23:06 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Softland [2012.11.19 05:45:45 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Software Informer [2011.01.27 11:37:04 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Thunderbird [2012.03.05 23:07:44 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\VoipBuster [2011.03.26 14:30:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Western Digital [2012.10.10 08:00:31 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2012.11.17 14:36:39 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2011.02.26 13:24:15 | 000,000,000 | -HSD | M] -- C:\Boot [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2010.11.05 18:10:07 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2012.02.05 09:07:17 | 000,000,000 | ---D | M] -- C:\Netgear [2011.01.27 09:19:07 | 000,000,000 | ---D | M] -- C:\NVIDIA [2011.10.02 09:46:15 | 000,000,000 | ---D | M] -- C:\PerfLogs [2012.11.19 05:24:31 | 000,000,000 | R--D | M] -- C:\Program Files [2012.11.17 12:20:44 | 000,000,000 | -H-D | M] -- C:\ProgramData [2010.11.05 18:10:07 | 000,000,000 | -HSD | M] -- C:\Programme [2011.01.27 06:58:08 | 000,000,000 | -HSD | M] -- C:\Recovery [2012.11.24 12:33:36 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012.11.17 14:36:26 | 000,000,000 | R--D | M] -- C:\Users [2012.11.20 08:01:58 | 000,000,000 | ---D | M] -- C:\Windows [2012.11.19 04:19:17 | 000,000,000 | ---D | M] -- C:\WinOld < %SYSTEMDRIVE%\*.* > [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat [2010.11.20 13:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr [2011.01.27 06:37:54 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2010.12.04 09:43:35 | 000,000,122 | ---- | M] () -- C:\CKINFO.TXT [2011.07.31 02:12:24 | 000,000,074 | ---- | M] () -- C:\CMLoader.log [2009.06.10 22:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys [2011.06.26 23:06:08 | 000,000,122 | ---- | M] () -- C:\delwpa.bat [2012.11.23 23:16:23 | 2818,023,424 | -HS- | M] () -- C:\hiberfil.sys [2010.11.18 20:08:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2010.11.18 20:08:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2012.11.23 23:16:25 | 3757,367,296 | -HS- | M] () -- C:\pagefile.sys < %PROGRAMFILES%\*.exe > Invalid Environment Variable: PROGRAMFILES(X86) < %systemroot%\*. /mp /s > < %windir%\installer\*. /10 > [2012.11.19 05:02:35 | 000,000,000 | ---D | M] -- C:\Windows\installer\{A45C5EC7-F13E-4414-99BE-47373935C0FE} [2012.11.19 05:23:44 | 000,000,000 | ---D | M] -- C:\Windows\installer\{AC76BA86-7AD7-1033-7B44-AB0000000001} [2012.11.19 05:36:48 | 000,000,000 | ---D | M] -- C:\Windows\installer\{EA17F4FC-FDBF-4CF8-A529-2D983132D053} < %appdata%\*. > [2011.01.27 09:09:27 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Adobe [2011.11.01 20:50:40 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\ArcSoft [2011.07.31 08:46:16 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\DeepBurner [2011.09.25 23:19:26 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Download Manager [2012.06.08 16:44:32 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\FastStone [2011.01.27 06:58:38 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Identities [2012.02.05 09:52:03 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\InstallShield [2012.11.19 04:29:28 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\IrfanView [2011.05.24 09:31:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Juniper Networks [2011.01.27 08:54:39 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Macromedia [2012.07.21 16:21:34 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Malwarebytes [2009.07.14 09:56:41 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Media Center Programs [2012.09.22 23:10:47 | 000,000,000 | --SD | M] -- C:\Users\Mark\AppData\Roaming\Microsoft [2011.01.27 08:13:27 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Mozilla [2012.11.17 09:22:29 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\MyPhoneExplorer [2012.11.19 04:32:00 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\NVIDIA [2011.01.28 19:31:37 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\OpenOffice.org [2012.11.19 04:28:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Samsung [2012.11.19 05:37:52 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Skype [2011.07.31 08:31:04 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\skypePM [2012.04.07 07:23:06 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Softland [2012.11.19 05:45:45 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Software Informer [2011.01.27 11:37:04 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Thunderbird [2012.11.19 05:34:42 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\vlc [2012.03.05 23:07:44 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\VoipBuster [2011.03.26 14:30:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Western Digital [2012.11.19 04:39:56 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Winamp < %appdata%\*.* > [2012.08.03 11:12:18 | 011,718,656 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\Sandra.mdb < %appdata%\*.exe /s > [2011.03.08 20:57:56 | 000,132,464 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\Juniper Networks\Setup Client\dsmmf.exe [2011.03.08 20:57:54 | 000,497,008 | ---- | M] (Juniper Networks) -- C:\Users\Mark\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe [2011.03.08 20:57:04 | 000,329,552 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClientOCX.exe [2011.03.08 20:55:28 | 000,217,952 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupXP.exe [2011.03.08 20:58:02 | 000,050,840 | ---- | M] (Juniper Networks) -- C:\Users\Mark\AppData\Roaming\Juniper Networks\Setup Client\uninstall.exe [2012.08.12 12:25:29 | 006,680,720 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\MyPhoneExplorer\HUAWEI U8510 [357191041511458]\Cache\sdcard\documents\DiscoPlus\MyPhoneExplorer_Setup_1.8.4.exe < %localappdata%\*. > [2011.01.27 09:09:27 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Adobe [2011.01.27 06:58:23 | 000,000,000 | -HSD | M] -- C:\Users\Mark\AppData\Local\Anwendungsdaten [2012.07.21 13:27:20 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Apps [2011.10.31 10:49:55 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\ArcSoft [2012.06.05 22:38:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Diagnostics [2012.09.02 00:00:17 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\ElevatedDiagnostics [2012.07.22 12:35:38 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Eraser 6 [2011.03.27 00:35:48 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Google [2012.11.17 05:50:52 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\HiSuite [2011.10.01 14:45:19 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Ilivid Player [2012.06.11 16:58:16 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Macromedia [2011.10.31 10:54:07 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Microsoft [2012.08.01 16:26:07 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Microsoft Games [2011.01.27 08:13:20 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Mozilla [2011.10.01 14:44:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\PackageAware [2012.09.09 00:34:03 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Passbild_Generator [2011.01.29 08:47:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\PDF24 [2011.10.31 10:54:07 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Programs [2012.08.04 08:23:07 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\RadioSure [2012.11.24 12:32:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Temp [2011.01.27 06:58:23 | 000,000,000 | -HSD | M] -- C:\Users\Mark\AppData\Local\Temporary Internet Files [2011.03.01 22:39:13 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Thunderbird [2011.01.27 06:58:23 | 000,000,000 | -HSD | M] -- C:\Users\Mark\AppData\Local\Verlauf [2012.06.10 17:57:09 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\VirtualStore [2011.03.26 14:29:23 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Western Digital [2011.10.02 10:45:15 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Local\Western_Digital < %localappdata%\*.* > [2012.07.21 22:12:15 | 000,116,002 | ---- | M] () -- C:\Users\Mark\AppData\Local\ars.cache [2012.07.21 22:12:35 | 000,254,382 | ---- | M] () -- C:\Users\Mark\AppData\Local\census.cache [2012.11.18 15:06:13 | 000,064,768 | ---- | M] () -- C:\Users\Mark\AppData\Local\GDIPFONTCACHEV1.DAT [2012.07.21 22:03:08 | 000,000,036 | ---- | M] () -- C:\Users\Mark\AppData\Local\housecall.guid.cache [2012.11.24 12:28:22 | 002,219,450 | -H-- | M] () -- C:\Users\Mark\AppData\Local\IconCache.db [2011.11.11 23:52:33 | 000,007,651 | ---- | M] () -- C:\Users\Mark\AppData\Local\Resmon.ResmonCfg [2011.09.13 22:20:26 | 000,000,000 | ---- | M] () -- C:\Users\Mark\AppData\Local\{13B8127D-EBD4-4D92-BA38-BB849DC6E456} < %localappdata%\*.exe /s > [2012.11.08 14:15:22 | 002,545,208 | ---- | M] () -- C:\Users\Mark\AppData\Local\HiSuite\userdata\ADB\adb.exe [2012.11.08 10:45:26 | 000,152,960 | ---- | M] (Igor Pavlov) -- C:\Users\Mark\AppData\Local\HiSuite\userdata\driver\all\7z.exe [2012.11.08 10:45:26 | 000,304,512 | ---- | M] () -- C:\Users\Mark\AppData\Local\HiSuite\userdata\driver\all\devsetup32.exe [2012.11.08 10:45:26 | 000,420,736 | ---- | M] () -- C:\Users\Mark\AppData\Local\HiSuite\userdata\driver\all\devsetup64.exe [2012.11.08 10:45:26 | 000,333,184 | ---- | M] () -- C:\Users\Mark\AppData\Local\HiSuite\userdata\driver\all\DriverSetup.exe [2012.11.08 10:45:26 | 000,333,184 | ---- | M] () -- C:\Users\Mark\AppData\Local\HiSuite\userdata\driver\all\DriverUninstall.exe [2012.11.19 04:26:07 | 000,245,760 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Mark\AppData\Local\Temp\InstallerMessageBox.exe [2011.07.31 08:26:32 | 000,029,696 | ---- | M] (Irfan Skiljan, IrfanView) -- C:\Users\Mark\AppData\Local\Temp\iv_uninstall.exe [2012.11.19 04:26:07 | 000,708,608 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Mark\AppData\Local\Temp\NPSInstallerProxy.exe [2012.11.19 05:35:56 | 029,304,496 | ---- | M] (Skype Technologies S.A.) -- C:\Users\Mark\AppData\Local\Temp\SkypeSetup.exe [2012.11.19 05:32:38 | 022,912,657 | ---- | M] () -- C:\Users\Mark\AppData\Local\Temp\vlc-2.0.4-win32.exe [154 C:\Users\Mark\AppData\Local\Temp\*.tmp files -> C:\Users\Mark\AppData\Local\Temp\*.tmp -> ] [2012.11.19 05:01:59 | 009,110,456 | ---- | M] (The Eraser Project) -- C:\Users\Mark\AppData\Local\Temp\eraser464421\1-Eraser 6.0.10.2620.exe [2012.07.21 22:03:10 | 002,425,152 | ---- | M] (Igor Pavlov) -- C:\Users\Mark\AppData\Local\Temp\HCBackup\hcpackage.exe [1 C:\Users\Mark\AppData\Local\Temp\HCBackup\*.tmp files -> C:\Users\Mark\AppData\Local\Temp\HCBackup\*.tmp -> ] [2010.09.29 09:51:40 | 000,192,512 | ---- | M] () -- C:\Users\Mark\AppData\Local\Temp\HouseCall\bspatch.exe [1 C:\Users\Mark\AppData\Local\Temp\HouseCall\*.tmp files -> C:\Users\Mark\AppData\Local\Temp\HouseCall\*.tmp -> ] [2012.08.31 23:33:20 | 000,270,304 | ---- | M] (Mozilla Foundation) -- C:\Users\Mark\AppData\Local\Temp\MozUpdater\updater.exe [2012.09.07 12:55:31 | 000,270,304 | ---- | M] (Mozilla Foundation) -- C:\Users\Mark\AppData\Local\Temp\MozUpdater-1\updater.exe [2012.10.15 22:10:13 | 000,270,816 | ---- | M] (Mozilla Foundation) -- C:\Users\Mark\AppData\Local\Temp\MozUpdater-2\updater.exe [2012.10.15 18:16:18 | 000,271,328 | ---- | M] (Mozilla Foundation) -- C:\Users\Mark\AppData\Local\Temp\MozUpdater-3\updater.exe [2012.09.07 19:25:48 | 000,303,936 | ---- | M] (OPSWAT, Inc.) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\64bitproxy.exe [2012.09.07 19:25:51 | 000,143,240 | ---- | M] (Ask.com) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\apnstub.exe [2012.09.07 19:25:52 | 003,904,680 | ---- | M] (Ask) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\apntoolbarinstaller.exe [2012.09.07 19:25:52 | 000,125,248 | ---- | M] () -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\appremover_64.exe [2012.09.07 19:25:54 | 000,378,176 | ---- | M] (OPSWAT, Inc.) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\appremover_cli.exe [2012.09.07 19:25:54 | 000,085,968 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avadmin.exe [2012.09.07 19:25:54 | 000,391,632 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avcenter.exe [2012.09.07 19:25:54 | 000,500,728 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avconfig.exe [2012.09.07 19:25:55 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avgnt.exe [2012.09.07 19:25:55 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avguard.exe [2012.09.07 19:25:55 | 000,304,120 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avnotify.exe [2012.09.07 19:25:55 | 000,182,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avrestart.exe [2012.09.07 19:25:55 | 000,468,472 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avscan.exe [2012.09.07 19:25:55 | 000,059,088 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avupgsvc.exe [2012.09.07 19:25:55 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avwebgrd.exe [2012.09.07 19:25:55 | 000,232,912 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avwebloader.exe [2012.09.07 19:25:56 | 000,117,688 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\avwsc.exe [2012.09.07 19:25:58 | 000,495,096 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\fact.exe [2012.09.07 19:25:58 | 000,174,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\guardgui.exe [2012.09.07 19:25:58 | 000,049,616 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\imp64b.exe [2012.09.07 19:25:58 | 000,169,936 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\inssda64.exe [2012.09.07 19:25:58 | 000,041,064 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\insthlp.exe [2012.09.07 19:25:59 | 000,086,992 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\ipmgui.exe [2012.09.07 19:25:59 | 000,106,344 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\licmgr.exe [2012.09.07 19:26:00 | 002,755,536 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\presetup.exe [2012.09.07 19:26:00 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\sched.exe [2012.09.07 19:26:00 | 000,716,792 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\setup.exe [2012.09.07 19:26:02 | 000,613,880 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\update.exe [2012.09.07 19:26:02 | 000,047,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\updrgui.exe [2012.01.21 00:22:22 | 004,995,416 | ---- | M] (Microsoft Corporation) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\vcredist_x86.exe [2012.09.07 19:26:03 | 000,080,848 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\wsctool.exe [2012.09.07 19:26:05 | 000,248,784 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\vista64\avshadow.exe [2012.09.07 19:26:05 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Users\Mark\AppData\Local\Temp\RarSFX0\xp\avshadow.exe [2012.07.21 12:48:16 | 002,152,752 | ---- | M] (CPUID) -- C:\Users\Mark\AppData\Local\Temp\Temp1_cpu-z-1613.zip\cpuz_x32.exe [2009.12.15 08:09:58 | 000,736,656 | ---- | M] (The Eraser Project) -- C:\Users\Mark\AppData\Local\Temp\Temp1_Eraser_5.8.8_Portable.zip\Eraser Standalone\Eraser.exe [2012.05.15 16:55:44 | 030,691,328 | ---- | M] () -- C:\Users\Mark\AppData\Local\Temp\Temp1_p95v277.win32(1).zip\prime95.exe [2012.07.28 13:24:33 | 030,691,328 | R--- | M] () -- C:\Users\Mark\AppData\Local\Temp\Temp1_p95v277.win32.zip\prime95.exe < %allusersprofile%\*. > [2012.11.19 05:24:07 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe [2011.01.27 14:10:34 | 000,000,000 | ---D | M] -- C:\ProgramData\Alwil Software [2011.01.27 06:58:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2011.11.01 20:50:40 | 000,000,000 | -H-D | M] -- C:\ProgramData\ArcSoft [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2011.01.27 06:58:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente [2011.01.27 06:58:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites [2012.11.17 05:49:48 | 000,000,000 | ---D | M] -- C:\ProgramData\HandSetService [2012.09.02 18:37:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Huawei [2012.09.16 23:10:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes [2011.10.02 10:20:18 | 000,000,000 | ---D | M] -- C:\ProgramData\mcShoutCast [2011.08.01 00:01:34 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft [2012.04.28 11:54:39 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla [2012.11.23 23:16:27 | 000,000,000 | ---D | M] -- C:\ProgramData\NVIDIA [2011.01.27 09:20:07 | 000,000,000 | ---D | M] -- C:\ProgramData\NVIDIA Corporation [2011.07.31 09:38:42 | 000,000,000 | ---D | M] -- C:\ProgramData\Samsung [2012.11.19 05:36:51 | 000,000,000 | ---D | M] -- C:\ProgramData\Skype [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2011.01.27 06:58:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü [2011.01.27 11:18:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2011.01.27 06:58:08 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen [2011.03.26 14:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WD_SmartWareCommon [2011.07.31 09:02:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Western Digital < %allusersprofile%\*.* > [2012.11.17 12:21:46 | 095,023,320 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012.07.21 10:08:52 | 004,503,728 | ---- | M] () -- C:\ProgramData\kp_0loor.pad [2011.07.31 02:53:20 | 000,000,000 | ---- | M] () -- C:\ProgramData\LauncherAccess.dt < %allusersprofile%\*.exe /s > [2012.01.03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\20370\AcrobatUpdater.exe [2012.01.03 08:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\20370\AdobeARM.exe [2012.01.03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\20370\AdobeARMHelper.exe [2012.01.03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\20370\ReaderUpdater.exe [2012.01.03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\916\AcrobatUpdater.exe [2012.01.03 08:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\916\AdobeARM.exe [2012.01.03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\916\AdobeARMHelper.exe [2012.01.03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\ARM\Reader_10.1.1\916\ReaderUpdater.exe [2012.09.24 04:47:39 | 000,364,224 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\setup.exe [2011.10.31 10:53:55 | 002,564,863 | ---- | M] (ArcSoft Inc. ) -- C:\ProgramData\ArcSoft\Global Deploy\CheckUpdate\ArcConnect.exe [2012.11.08 10:45:26 | 000,142,688 | ---- | M] () -- C:\ProgramData\HandSetService\HSService.exe [2012.11.08 10:45:26 | 000,161,120 | ---- | M] () -- C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe [2012.11.08 10:45:26 | 000,200,032 | ---- | M] () -- C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [2012.11.08 13:51:36 | 000,171,104 | ---- | M] (Igor Pavlov) -- C:\ProgramData\Huawei\HiSuite\7z.exe [2012.11.08 13:51:48 | 000,553,568 | ---- | M] () -- C:\ProgramData\Huawei\HiSuite\HiSuite.exe [2012.11.08 12:47:40 | 000,456,032 | ---- | M] () -- C:\ProgramData\Huawei\HiSuite\HiSuiteDownLoader.exe [2012.11.17 05:49:47 | 000,158,531 | ---- | M] () -- C:\ProgramData\Huawei\HiSuite\uninst.exe [2012.11.08 14:15:22 | 002,545,208 | ---- | M] () -- C:\ProgramData\Huawei\HiSuite\ADB\adb.exe [2012.11.17 14:37:22 | 010,669,952 | ---- | M] (Malwarebytes Corporation ) -- C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe [2012.11.17 03:37:00 | 000,115,168 | ---- | M] () -- C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{0C75BBEB-183C-9A85-6AF5-CB40B337D767}-maintenanceservice.exe [2012.11.24 00:41:48 | 000,210,044 | ---- | M] () -- C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{6157DA6B-D13A-F67E-2634-2E0C8EAEBFAE}-uninstall.exe [2011.05.21 05:01:00 | 000,194,152 | ---- | M] (NVIDIA Corporation) -- C:\ProgramData\NVIDIA\Updatus\WLMerger.exe [1970.01.01 01:00:00 | 000,114,887 | ---- | M] () -- C:\ProgramData\NVIDIA\Updatus\Download\3FB908F6\drsupdate.r275_21-10165912_RUNASUSER.exe [2012.11.23 23:18:49 | 000,114,886 | ---- | M] () -- C:\ProgramData\NVIDIA\Updatus\Packages\00000000\drsupdate.r275_21-10165912_RUNASUSER.exe ========== Alternate Data Streams ========== @Alternate Data Stream - 965 bytes -> C:\Users\Mark\Documents\Your Qatar Airways Booking - Reference No 5PUXSZ.eml:OECustomProperty < End of report > |
24.11.2012, 13:01 | #5 | |
/// TB-Ausbilder | Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Dann geht es weiter: Schritt 1: Fix mit OTL Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen Schritt 3: Kontrollscan mit OTL Schritt 4: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
24.11.2012, 13:12 | #6 |
| Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) ergebnis von otl nach fix Code:
ATTFilter All processes killed ========== OTL ========== C:\ProgramData\dsgsdgdsgdsgw.pad moved successfully. C:\ProgramData\kp_0loor.pad moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 545140 bytes ->Temporary Internet Files folder emptied: 20993270 bytes ->FireFox cache emptied: 65125982 bytes ->Flash cache emptied: 492 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33198 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gast ->Temp folder emptied: 1045159 bytes ->Temporary Internet Files folder emptied: 1548352 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 70753610 bytes ->Flash cache emptied: 506 bytes User: Mark ->Temp folder emptied: 435727025 bytes ->Temporary Internet Files folder emptied: 105076 bytes ->Java cache emptied: 16471096 bytes ->FireFox cache emptied: 65566438 bytes ->Flash cache emptied: 548 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33184 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 155848745 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 795,00 mb OTL by OldTimer - Version 3.2.61.5 log created on 11242012_130718 Files\Folders moved on Reboot... C:\Users\Mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Kontrollscan OTL: OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.11.2012 13:20:18 - Run 3 OTL by OldTimer - Version 3.2.61.5 Folder = C:\Users\Mark\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16438) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,50 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 71,22% Memory free 7,00 Gb Paging File | 5,99 Gb Available in Paging File | 85,62% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 323,63 Gb Total Space | 261,48 Gb Free Space | 80,80% Space Free | Partition Type: NTFS Drive D: | 335,34 Gb Total Space | 313,57 Gb Free Space | 93,51% Space Free | Partition Type: NTFS Computer Name: MARK-PC | User Name: Mark | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.11.17 03:31:04 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe PRC - [2012.11.16 21:32:50 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2012.11.08 10:45:26 | 000,161,120 | ---- | M] () -- C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\Alwil Software\Avast5\AvastUI.exe PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe PRC - [2012.10.10 21:15:04 | 001,258,856 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2012.10.02 20:29:14 | 000,864,616 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\NvXDSync.exe PRC - [2012.10.02 20:28:55 | 001,820,520 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.09.16 22:56:50 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Mark\Desktop\OTL.exe PRC - [2012.05.22 08:13:12 | 000,980,920 | ---- | M] (The Eraser Project) -- C:\Programme\Eraser\Eraser.exe PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.08.11 11:32:14 | 001,690,224 | R--- | M] (VIA) -- C:\Programme\VIA\VIAudioi\VDeck\VDeck.exe PRC - [2009.07.14 02:14:46 | 000,115,200 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE ========== Modules (No Company Name) ========== MOD - [2012.11.17 08:32:48 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll MOD - [2012.11.17 08:32:36 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\239d84cfdb9de9730c1efb43840ef2eb\System.Core.ni.dll MOD - [2012.11.17 03:31:04 | 014,586,808 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_110.dll MOD - [2012.11.17 03:25:02 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll MOD - [2012.11.17 03:24:57 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll MOD - [2012.11.17 03:24:33 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll MOD - [2012.11.17 03:24:28 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll MOD - [2012.11.17 03:24:14 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll MOD - [2012.11.16 21:32:49 | 002,295,264 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2010.08.11 11:32:20 | 000,100,976 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\VMicApi.dll MOD - [2010.08.11 11:32:10 | 064,663,664 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\skin.dll MOD - [2010.08.11 11:32:06 | 000,080,496 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\QsApoApi.dll MOD - [2010.08.11 11:32:04 | 000,113,264 | R--- | M] () -- C:\Programme\VIA\VIAudioi\VDeck\Dts2ApoApi.dll ========== Services (SafeList) ========== SRV - [2012.11.17 03:31:04 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.11.16 20:46:49 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.11.09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.11.08 10:45:26 | 000,161,120 | ---- | M] () [Auto | Running] -- C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe -- (HuaweiHiSuiteService.exe) SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2012.10.10 21:15:04 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.08.01 09:11:38 | 001,091,984 | ---- | M] (Western Digital ) [Disabled | Stopped] -- C:\Programme\Western Digital\WD SmartWare\WDRulesEngine.exe -- (WDRulesService) SRV - [2011.08.01 09:11:36 | 001,592,208 | ---- | M] (Western Digital ) [Disabled | Stopped] -- C:\Programme\Western Digital\WD SmartWare\WDFME.exe -- (WDFMEService) SRV - [2011.08.01 09:11:32 | 000,263,056 | ---- | M] (WDC) [Disabled | Stopped] -- C:\Programme\Western Digital\WD SmartWare\WDDMService.exe -- (WDDMService) SRV - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Disabled | Stopped] -- C:\Programme\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon) SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.06.13 18:47:02 | 000,068,760 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\RpcAgentSrv.exe -- (SandraAgentSrv) SRV - [2008.09.18 10:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Disabled | Stopped] -- C:\Programme\Hama\Hama Webcam Suite\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\snpstd3.sys -- (SNPSTD3) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Mark\AppData\Local\Temp\ALSysIO.sys -- (ALSysIO) DRV - [2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012.10.30 23:51:57 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012.10.15 17:59:28 | 000,044,784 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr) DRV - [2012.10.10 21:14:28 | 010,837,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012.08.23 15:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2012.08.23 15:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.25 06:59:16 | 000,603,240 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL8192su.sys -- (RTL8192su) DRV - [2010.11.20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB) DRV - [2010.10.22 02:00:00 | 000,265,088 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB) DRV - [2010.10.22 02:00:00 | 000,004,352 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avmeject.sys -- (avmeject) DRV - [2010.09.27 03:10:30 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5) DRV - [2010.08.12 11:07:48 | 000,298,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET) DRV - [2010.08.04 21:17:00 | 001,143,920 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV - [2010.06.14 08:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk) DRV - [2009.08.07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\WNt500x86\sandra.sys -- (SANDRA) DRV - [2009.07.14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.07.13 23:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD) DRV - [2009.02.13 11:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM) DRV - [2008.04.24 14:06:40 | 000,017,920 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter) DRV - [2006.11.10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc) DRV - [2006.07.24 15:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2004.09.06 11:39:44 | 000,042,729 | ---- | M] (Fujitsu Siemens) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cmeu0wdm.sys -- (cmeu0wdm) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/ IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 EB 46 26 EA BD CB 01 [binary data] IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\..\SearchScopes\{1B6E15C1-66CC-4AAC-AEC4-635EA87A497A}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2777542180-2792119682-1362692570-1003\..\SearchScopes,DefaultScope = ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.yahoo.de" FF - prefs.js..extensions.enabledAddons: {EE223D7A-F30F-11DD-8F0A-D2AD55D89593}:1.0.5 FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1474 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012.11.17 07:35:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.11.16 21:32:50 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.11.19 05:23:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.11.16 20:46:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011.01.27 11:37:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\Extensions [2011.01.27 11:37:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.11.19 04:48:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\kq62sfx6.default\extensions [2012.06.15 09:54:27 | 000,047,658 | ---- | M] () (No name found) -- C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\kq62sfx6.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}.xpi [2012.11.24 12:45:35 | 000,001,610 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\kq62sfx6.default\searchplugins\ixquick---deutsch.xml [2012.11.16 21:32:46 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2012.11.17 07:35:14 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF [2012.11.16 21:32:50 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.10.02 10:25:49 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.08.31 23:33:21 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.10.02 10:25:49 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.10.02 10:25:49 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.02 10:25:49 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.10.02 10:25:49 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Eraser] C:\Programme\Eraser\Eraser.exe (The Eraser Project) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2777542180-2792119682-1362692570-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 10.7.2) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2BE13A16-C617-44E3-A483-5B24E2501C80}: DhcpNameServer = 192.168.42.129 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EC7950A5-48AB-4F56-BCCF-5EAB3F0961D2}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ED80D93A-DCBC-440C-BD94-DE79B5E542A1}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{44e503b0-576a-11e0-9b15-00040ec93d8e}\Shell - "" = AutoRun O33 - MountPoints2\{44e503b0-576a-11e0-9b15-00040ec93d8e}\Shell\AutoRun\command - "" = "K:\WD SmartWare.exe" autoplay=true O33 - MountPoints2\{d38caa4c-29d9-11e0-b5ff-0025226c922f}\Shell - "" = AutoRun O33 - MountPoints2\{d38caa4c-29d9-11e0-b5ff-0025226c922f}\Shell\AutoRun\command - "" = K:\pushinst.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.11.24 13:07:18 | 000,000,000 | ---D | C] -- C:\_OTL [2012.11.19 05:36:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012.11.19 05:36:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2012.11.19 05:34:17 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\vlc [2012.11.19 05:34:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2012.11.19 05:24:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2012.11.19 05:24:31 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2012.11.19 05:23:38 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2012.11.19 04:10:50 | 000,000,000 | ---D | C] -- C:\WinOld [2012.11.18 08:19:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2012.11.17 05:49:48 | 000,000,000 | ---D | C] -- C:\ProgramData\HandSetService [2012.11.17 05:49:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite [2012.11.16 21:32:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012.11.16 20:46:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird ========== Files - Modified Within 30 Days ========== [2012.11.24 13:22:17 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.11.24 13:22:17 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.11.24 13:22:17 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.11.24 13:22:17 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.11.24 13:21:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.11.24 13:16:32 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.11.24 13:16:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.11.24 13:16:05 | 2818,023,424 | -HS- | M] () -- C:\hiberfil.sys [2012.11.24 13:15:23 | 000,005,872 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.11.24 13:15:23 | 000,005,872 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.11.24 13:13:53 | 000,543,531 | ---- | M] () -- C:\Users\Mark\Desktop\adwcleaner.exe [2012.11.24 12:30:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.11.19 05:42:21 | 000,004,806 | ---- | M] () -- C:\Users\Mark\Documents\cc_20121119_054217.reg [2012.11.19 05:36:48 | 000,002,505 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2012.11.19 05:34:11 | 000,001,028 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012.11.19 05:10:50 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2012.11.19 05:08:06 | 000,001,032 | ---- | M] () -- C:\Users\Public\Desktop\Software Informer.lnk [2012.11.19 05:02:35 | 000,001,747 | ---- | M] () -- C:\Users\Public\Desktop\Eraser.lnk [2012.11.19 04:51:31 | 000,017,636 | ---- | M] () -- C:\Users\Mark\Documents\cc_20121119_045123.reg [2012.11.19 04:43:02 | 000,039,930 | ---- | M] () -- C:\Users\Mark\Documents\cc_20121119_044130.reg [2012.11.19 04:38:18 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012.11.18 07:46:09 | 000,297,496 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.11.17 14:38:06 | 000,001,187 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.11.17 07:35:14 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2012.11.17 07:32:53 | 011,318,679 | ---- | M] () -- C:\Users\Mark\Documents\2012-11-17_073158.pdf [2012.11.17 05:49:47 | 000,000,857 | ---- | M] () -- C:\Users\Public\Desktop\HiSuite.lnk [2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2012.10.30 23:51:57 | 000,058,680 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2012.10.30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2012.10.30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe ========== Files Created - No Company Name ========== [2012.11.24 13:13:48 | 000,543,531 | ---- | C] () -- C:\Users\Mark\Desktop\adwcleaner.exe [2012.11.19 05:42:19 | 000,004,806 | ---- | C] () -- C:\Users\Mark\Documents\cc_20121119_054217.reg [2012.11.19 05:34:11 | 000,001,028 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012.11.19 05:23:45 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk [2012.11.19 05:10:50 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2012.11.19 04:51:29 | 000,017,636 | ---- | C] () -- C:\Users\Mark\Documents\cc_20121119_045123.reg [2012.11.19 04:41:38 | 000,039,930 | ---- | C] () -- C:\Users\Mark\Documents\cc_20121119_044130.reg [2012.11.18 07:41:41 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012.11.18 07:41:02 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012.11.17 07:32:51 | 011,318,679 | ---- | C] () -- C:\Users\Mark\Documents\2012-11-17_073158.pdf [2012.11.17 05:49:47 | 000,000,857 | ---- | C] () -- C:\Users\Public\Desktop\HiSuite.lnk [2012.08.01 13:32:06 | 011,718,656 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\Sandra.mdb [2012.07.21 22:12:35 | 000,254,382 | ---- | C] () -- C:\Users\Mark\AppData\Local\census.cache [2012.07.21 22:12:15 | 000,116,002 | ---- | C] () -- C:\Users\Mark\AppData\Local\ars.cache [2012.07.21 22:03:08 | 000,000,036 | ---- | C] () -- C:\Users\Mark\AppData\Local\housecall.guid.cache [2011.09.13 22:20:26 | 000,000,000 | ---- | C] () -- C:\Users\Mark\AppData\Local\{13B8127D-EBD4-4D92-BA38-BB849DC6E456} [2011.08.01 00:14:04 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin [2011.07.31 09:37:59 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll [2011.07.31 09:37:59 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys [2011.07.31 08:31:11 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011.07.31 01:16:48 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt [2011.07.31 01:07:41 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2011.07.10 19:25:59 | 000,007,651 | ---- | C] () -- C:\Users\Mark\AppData\Local\Resmon.ResmonCfg [2011.01.27 13:08:43 | 000,000,055 | ---- | C] () -- C:\Windows\wininit.ini ========== LOP Check ========== [2012.11.18 05:16:42 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DeepBurner [2011.07.31 08:46:16 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\DeepBurner [2012.11.19 04:29:28 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\IrfanView [2011.05.24 09:31:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Juniper Networks [2012.11.17 09:22:29 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\MyPhoneExplorer [2011.01.28 19:31:37 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\OpenOffice.org [2012.11.19 04:28:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Samsung [2012.04.07 07:23:06 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Softland [2012.11.19 05:45:45 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Software Informer [2011.01.27 11:37:04 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Thunderbird [2012.03.05 23:07:44 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\VoipBuster [2011.03.26 14:30:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Western Digital [2012.10.10 08:00:31 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 965 bytes -> C:\Users\Mark\Documents\Your Qatar Airways Booking - Reference No 5PUXSZ.eml:OECustomProperty < End of report > Schritt 4 (Security Check): Code:
ATTFilter Results of screen317's Security Check version 0.99.55 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.65.1.1000 CCleaner JavaFX 2.1.1 Java 7 Update 7 Java version out of Date! Adobe Flash Player 11.5.502.110 Mozilla Firefox 16.0.2 Firefox out of Date! Mozilla Thunderbird 16.0.2 Thunderbird out of Date! ````````Process Check: objlist.exe by Laurent```````` Alwil Software Avast5 AvastSvc.exe Alwil Software Avast5 AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
24.11.2012, 18:50 | #7 | |
/// TB-Ausbilder | Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Gut! Wir müssen jetzt noch ein paar Kontrollen machen. Schritt 1: Quick-Scan mit Malwarebytes Schritt 2: ESET Online Scanner Zitat:
Schritt 3: Java Update (Windows XP, Vista, 7) Dein Java ist nicht mehr aktuell. Ältere Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.Schritt 4: Thunderbird und Firefox Update durchführen. Schritt 5: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
24.11.2012, 21:27 | #8 |
| Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Schritt 1: Quickscan Malwarebytes Code:
ATTFilter Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Datenbank Version: v2012.11.24.08 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.10.9200.16438 Mark :: MARK-PC [Administrator] 24.11.2012 21:22:05 mbam-log-2012-11-24 (21-22-05).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 251553 Laufzeit: 3 Minute(n), 32 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter D:\Markus\Freizeit\Computer\Software\MediaTools\Videoplayer\SoftonicDownloader_fuer_total-video-player.exe a variant of Win32/SoftonicDownloader.A application Schritt 5 - Security Check: Code:
ATTFilter Results of screen317's Security Check version 0.99.55 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.65.1.1000 CCleaner Java 7 Update 9 Adobe Flash Player 11.5.502.110 Mozilla Firefox (17.0) Mozilla Thunderbird (17.0.) ````````Process Check: objlist.exe by Laurent```````` Alwil Software Avast5 AvastSvc.exe Alwil Software Avast5 AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
25.11.2012, 12:15 | #9 | ||||||
/// TB-Ausbilder | Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Kein Wunder, wenn du dich selbst mit Werbung zumüllst ... Zitat:
Ansonsten ... Prima! Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: Tools deinstallieren
Schritt 2: ESET deinstallieren (Optional) Abschließend noch Tipps zu folgenden Themen:
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
25.11.2012, 16:28 | #10 |
| Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Hallo Ryder, habe alles abgeschlossen und Deine Hinweise gelesen, vielen, vielen Dank für Deine Unterstützung, |
25.11.2012, 16:43 | #11 |
/// TB-Ausbilder | Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) Schön, dass wir helfen konnten Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
Themen zu Verschlüsselungstrojaner eingehandelt (wgsdgsdgdsgsd) |
aktion, anleitung, anti-malware, appdata, autostart, bericht, beste, besten, bösartige, dateien, durchgeführt, exploit.drop.gs, explorer, gelöscht, lsass.exe, malwarebytes, minute, nichts, registrierung, scan, service, speicher, temp, trojan.delf, unterstützung, version, vorgehen, wgsdgsdgdsgsd.exe |