Hallo, erstmal ein großes Lob an das Trojaner Board Forum, wie selbstlos hier geholfen wird, echt Klasse! Ich habe mir vor ein paar Tagen auch den GVU-Trojaner eingefangen. Bevor ich hier diese Anleitung zur Beseitigung gefunden habe, habe ich bereits folgendes unternommen:
Text files sind im Anhang, ich hoffe ihr könnt mir zur weiteren Bereinigung beihelfen, würde ungern das System neu aufsetzten. Vielen Dank Gruß Chris |
Da ist gar nicht mehr viel von dem Schädling übrig
Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Schritt 1: AdwCleaner: Werbeprogramme suchen und löschen Schritt 2: Kontrollscan mit OTL Schritt 3: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck
Danke für die Hilfe, hier die Logfiles
ATTFilter # AdwCleaner v2.008 - Datei am 19/11/2012 um 00:07:32 erstellt # Aktualisiert am 17/11/2012 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : Redfield - REDFIELD2 # Bootmodus : Normal # Ausgeführt unter : C:\Users\Redfield\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml Ordner Gelöscht : C:\Users\Redfield\AppData\Roaming\OpenCandy ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7601.17514 Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=110819&tt=100512_1_&babsrc=NT_ss&mntrId=d259e0fd000000000000002275ab4466 --> hxxp://www.google.com -\\ Mozilla Firefox v16.0.2 (de) Profilname : default Datei : C:\Users\Redfield\AppData\Roaming\Mozilla\Firefox\Profiles\8lc3ogm0.default\prefs.js C:\Users\Redfield\AppData\Roaming\Mozilla\Firefox\Profiles\8lc3ogm0.default\user.js ... Gelöscht ! Gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Gelöscht : user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); Gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)"); Gelöscht : user_pref("de.soerenrinne.googlebuttons.wholeshebang", "Calendar,3D Warehouse,Aardvark,Accounts,Ad M[...] Gelöscht : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Gelöscht : user_pref("extensions.BabylonToolbar_i.babExt", ""); Gelöscht : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=100512_1_"); Gelöscht : user_pref("extensions.BabylonToolbar_i.hardId", "d259e0fd000000000000002275ab4466"); Gelöscht : user_pref("extensions.BabylonToolbar_i.id", "d259e0fd000000000000002275ab4466"); Gelöscht : user_pref("extensions.BabylonToolbar_i.instlDay", "15473"); Gelöscht : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true); Gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=110819&tt=10051[...] Gelöscht : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Gelöscht : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Gelöscht : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Gelöscht : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Gelöscht : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsn", ""); Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsnTs", ""); Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsni", ""); Gelöscht : user_pref("keyword.URL", "hxxp://search.babylon.com/?affID=110819&tt=100512_1_&babsrc=KW_ss&mntrId=d[...] -\\ Google Chrome v7.0.517.44 Datei : C:\Users\Redfield\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.48] : homepage = "hxxp://search.babylon.com/?affID=110819&tt=100512_1_&babsrc=HP_ss&mntrId=d259e0fd000[...] ************************* AdwCleaner[R1].txt - [3757 octets] - [19/11/2012 00:07:04] AdwCleaner[S2].txt - [3651 octets] - [19/11/2012 00:07:32] ########## EOF - C:\AdwCleaner[S2].txt - [3711 octets] ########## Code:
ATTFilter OTL logfile created on: 19.11.2012 00:21:20 - Run 2 OTL by OldTimer - Version Folder = C:\Users\Redfield\Desktop\Anti Virus Programme 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,07 Gb Available Physical Memory | 51,73% Memory free 7,99 Gb Paging File | 5,99 Gb Available in Paging File | 74,97% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 155,06 Gb Free Space | 33,30% Space Free | Partition Type: NTFS Computer Name: REDFIELD2 | User Name: Redfield | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.11.18 02:03:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Redfield\Desktop\Anti Virus Programme\OTL.exe PRC - [2012.11.06 00:14:44 | 026,619,512 | ---- | M] (Dropbox, Inc.) -- C:\Users\Redfield\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2012.11.01 18:56:20 | 001,263,512 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\Avast5\AvastUI.exe PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\Avast5\AvastSvc.exe PRC - [2012.10.24 18:49:10 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012.10.23 10:47:48 | 002,848,168 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012.09.24 13:46:16 | 001,328,736 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe PRC - [2012.09.24 13:46:16 | 000,656,480 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe PRC - [2012.09.24 13:46:14 | 000,573,536 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe PRC - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.08.13 11:08:08 | 010,376,704 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\program\soffice.exe PRC - [2012.08.13 11:08:08 | 010,368,512 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\program\soffice.bin PRC - [2010.09.07 13:15:28 | 002,787,224 | ---- | M] (Razer USA Ltd) -- C:\Program Files (x86)\Razer\Imperator\RazerImperatorTray.exe PRC - [2009.10.15 14:06:46 | 000,223,464 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe PRC - [2009.10.15 14:06:42 | 000,375,000 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe PRC - [2009.08.24 14:38:06 | 000,068,136 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE PRC - [2009.04.07 13:53:32 | 000,030,440 | ---- | M] () -- C:\Program Files (x86)\dcmsvc\dcmsvc.exe PRC - [2008.10.06 15:03:04 | 000,147,456 | ---- | M] (Razer USA Ltd.) -- C:\Program Files (x86)\Razer\Arctosa\razerhid.exe PRC - [2008.03.25 17:21:56 | 000,219,656 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\GUI.exe ========== Modules (No Company Name) ========== MOD - [2012.11.01 18:57:10 | 000,100,248 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll MOD - [2012.11.01 18:56:20 | 001,263,512 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe MOD - [2012.10.24 18:49:23 | 002,295,264 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012.08.10 16:51:32 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\program\libxml2.dll MOD - [2010.07.28 15:00:02 | 002,351,175 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\Normal.dll MOD - [2010.07.20 15:23:56 | 000,196,608 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\GVTunner.dll MOD - [2010.06.10 15:52:24 | 000,110,592 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\AMD8.dll MOD - [2010.05.28 14:15:02 | 000,344,131 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\work.dll MOD - [2010.05.27 10:08:58 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\OCK.dll MOD - [2010.05.25 14:00:34 | 000,290,816 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\MFCCPU.DLL MOD - [2010.03.12 05:40:58 | 004,449,632 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\Platform.dll MOD - [2010.03.12 05:40:56 | 000,423,256 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\Device.dll MOD - [2010.01.12 17:09:20 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\SF.dll MOD - [2009.12.22 16:52:04 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\ycc.dll MOD - [2009.10.21 14:07:06 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\HM.dll MOD - [2009.06.27 10:11:12 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll MOD - [2009.04.15 14:04:38 | 000,104,520 | ---- | M] () -- C:\Windows\SysWOW64\OSD.dll MOD - [2009.04.07 13:53:32 | 000,030,440 | ---- | M] () -- C:\Program Files (x86)\dcmsvc\dcmsvc.exe MOD - [2008.05.07 15:22:58 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\CIAMIB.dll MOD - [2008.03.25 17:21:56 | 000,219,656 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\GUI.exe MOD - [2003.02.14 14:11:46 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Gigabyte\ET6\Sound.dll ========== Services (SafeList) ========== SRV:64bit: - [2010.04.06 16:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv) SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2012.11.18 21:29:53 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.11.13 19:37:50 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2012.10.23 10:47:48 | 002,848,168 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012.09.24 13:46:16 | 001,328,736 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent) SRV - [2012.09.24 13:46:16 | 000,656,480 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent) SRV - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.08.30 20:14:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.07.17 15:14:44 | 002,292,480 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2011.10.20 20:27:02 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010.11.11 14:39:34 | 000,128,928 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.02.19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.10.15 14:06:46 | 000,223,464 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService) SRV - [2009.08.24 14:38:06 | 000,068,136 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE -- (ES lite Service) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2005.02.09 12:59:00 | 000,014,165 | ---- | M] (Pinnacle Systems GmbH) [Auto | Stopped] -- C:\Windows\SysWOW64\drivers\Pclepci.sys -- (PCLEPCI) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.10.30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:64bit: - [2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:64bit: - [2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:64bit: - [2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:64bit: - [2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:64bit: - [2012.10.15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:64bit: - [2012.09.29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012.08.23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2012.08.23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2012.07.03 16:25:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011.12.16 15:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI) DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010.12.07 13:12:24 | 000,034,304 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandmodem64.sys -- (ANDModem) DRV:64bit: - [2010.12.07 13:12:24 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandgps64.sys -- (AndGps) DRV:64bit: - [2010.12.07 13:12:22 | 000,027,648 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lganddiag64.sys -- (AndDiag) DRV:64bit: - [2010.12.07 13:12:22 | 000,019,456 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandbus64.sys -- (Andbus) DRV:64bit: - [2010.11.25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.10 04:50:22 | 000,575,488 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:64bit: - [2010.10.21 08:45:20 | 000,034,816 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem) DRV:64bit: - [2010.10.21 08:45:18 | 000,028,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag) DRV:64bit: - [2010.10.21 08:45:18 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus) DRV:64bit: - [2010.04.27 11:56:38 | 000,021,544 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger) DRV:64bit: - [2010.03.22 10:57:20 | 000,347,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009.12.07 19:53:26 | 000,117,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:64bit: - [2009.12.07 19:36:48 | 000,246,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet) DRV:64bit: - [2009.11.10 15:50:18 | 000,014,336 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\copperhd.sys -- (copperhd) DRV:64bit: - [2009.10.12 15:23:22 | 000,114,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev) DRV:64bit: - [2009.09.29 07:15:02 | 000,016,384 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lgbtpt64.sys -- (LgBttPort) DRV:64bit: - [2009.09.29 07:15:00 | 000,017,408 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lgvmdm64.sys -- (LGVMODEM) DRV:64bit: - [2009.09.29 07:15:00 | 000,014,848 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lgbtbs64.sys -- (lgbusenum) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.09 02:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2005.10.21 17:01:22 | 000,019,200 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbicp.sys -- (uisp) DRV:64bit: - [2005.09.23 22:18:34 | 000,261,120 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MarvinBus64.sys -- (MarvinBus) DRV - [2012.11.19 00:10:29 | 000,030,528 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\GVTDrv64.sys -- (GVTDrv64) DRV - [2012.11.19 00:10:10 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv) DRV - [2011.03.24 16:18:14 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\etdrv.sys -- (etdrv) DRV - [2010.03.12 05:40:48 | 000,052,280 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys -- (AODDriver) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = AE 66 F7 28 0A 29 CD 01 [binary data] IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\..\SearchScopes\{1F083314-BBB0-4cec-B593-806EE997F993}: "URL" = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A4067623346&ie=UTF-8&q={searchTerms}&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4067623346 IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\..\SearchScopes\{234210F6-5BDB-43b5-889C-BFEA6D277DBE}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=STDVM IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\..\SearchScopes\{3A83BBF0-C1E7-4655-B9BE-D4E99F090694}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR2&pc=SPLH IE - HKU\S-1-5-21-864323817-4183604381-2794474725-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google.de" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledAddons: {5C46D283-ABDE-4dce-B83C-08881401921C}: FF - prefs.js..extensions.enabledAddons: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120926 FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10 FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.11 FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37 FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1474 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}: FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}: FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npdeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011.07.13 10:57:54 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Avast5\WebRep\FF [2012.11.18 21:17:49 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.11.18 21:48:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.11.18 22:16:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.11.18 19:00:29 | 000,000,000 | ---D | M] [2010.11.10 17:33:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Redfield\AppData\Roaming\mozilla\Extensions [2012.11.18 22:01:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Redfield\AppData\Roaming\mozilla\Firefox\Profiles\8lc3ogm0.default\extensions [2012.11.18 21:37:29 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Redfield\AppData\Roaming\mozilla\Firefox\Profiles\8lc3ogm0.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2010.12.01 14:21:47 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Redfield\AppData\Roaming\mozilla\Firefox\Profiles\8lc3ogm0.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012.11.01 11:04:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Redfield\AppData\Roaming\mozilla\Firefox\Profiles\8lc3ogm0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012.11.18 22:01:10 | 000,573,138 | ---- | M] () (No name found) -- C:\Users\Redfield\AppData\Roaming\mozilla\firefox\profiles\8lc3ogm0.default\extensions\testpilot@labs.mozilla.com.xpi [2011.10.15 15:03:10 | 000,372,140 | ---- | M] () (No name found) -- C:\Users\Redfield\AppData\Roaming\mozilla\firefox\profiles\8lc3ogm0.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2012.11.18 19:55:16 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Redfield\AppData\Roaming\mozilla\firefox\profiles\8lc3ogm0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012.05.22 17:07:59 | 000,002,101 | ---- | M] () -- C:\Users\Redfield\AppData\Roaming\mozilla\firefox\profiles\8lc3ogm0.default\searchplugins\googlede.xml [2012.11.18 22:16:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012.11.18 21:31:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012.11.18 21:17:49 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST5\WEBREP\FF [2012.10.24 18:50:04 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.10.24 23:03:12 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.10.24 23:03:11 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.10.24 23:03:12 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.10.24 23:03:12 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.10.24 23:03:12 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.10.24 23:03:11 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google () CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Redfield\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Redfield\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\\ O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\Avast5\aswWebRepIE64.dll (AVAST Software) O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics) O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Avast5\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\Avast5\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Avast5\aswWebRepIE.dll (AVAST Software) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Arctosa] C:\Program Files (x86)\Razer\Arctosa\razerhid.exe (Razer USA Ltd.) O4 - HKLM..\Run: [avast] C:\Program Files\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.) O4 - HKLM..\Run: [dcmsvc] C:\Program Files (x86)\dcmsvc\dcmsvc.exe () O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe () O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [Razer Imperator Driver] C:\Program Files (x86)\Razer\Imperator\RazerImperatorTray.exe (Razer USA Ltd) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-864323817-4183604381-2794474725-1000..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com) O4 - HKLM..\RunOnce: [EasyTuneVI] C:\Program Files (x86)\Gigabyte\ET6\ETCall.exe () O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Redfield\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O4 - Startup: C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Redfield\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Redfield\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Free YouTube Download - C:\Users\Redfield\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Redfield\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 10.9.2) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.7.0_09) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B92AE7C-2D19-4D4A-A3DB-34C4282C757B}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41BC4485-3030-4D59-AF88-9A68CD970967}: NameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A208DE6-C249-4AEE-9A37-AEAE01231BEA}: DhcpNameServer = O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010.12.01 13:05:41 | 000,000,107 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{ca211efd-3b0c-11e1-a613-1c6f65471c46}\Shell - "" = AutoRun O33 - MountPoints2\{ca211efd-3b0c-11e1-a613-1c6f65471c46}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{ca211f0d-3b0c-11e1-a613-1c6f65471c46}\Shell - "" = AutoRun O33 - MountPoints2\{ca211f0d-3b0c-11e1-a613-1c6f65471c46}\Shell\AutoRun\command - "" = E:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.11.18 22:23:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\sun [2012.11.18 22:22:57 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Roaming\OOo-dev [2012.11.18 22:12:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OOo-dev 3 [2012.11.18 21:55:12 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live [2012.11.18 21:53:01 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1 [2012.11.18 21:51:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\URE [2012.11.18 21:51:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\readmes [2012.11.18 21:51:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\share [2012.11.18 21:51:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\program [2012.11.18 21:51:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Basis [2012.11.18 21:24:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileHippo.com [2012.11.18 21:21:51 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\Secunia PSI [2012.11.18 21:21:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia [2012.11.18 21:17:51 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys [2012.11.18 13:31:23 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{E81DCE4A-2DA3-43F8-9207-723B73DDBDC9} [2012.11.17 19:24:22 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Roaming\Malwarebytes [2012.11.17 19:24:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.11.17 19:24:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.11.17 19:24:02 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012.11.17 19:24:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2012.11.17 13:27:52 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0 [2012.11.17 12:16:14 | 000,000,000 | ---D | C] -- C:\Users\Redfield\Desktop\Anti Virus Programme [2012.11.16 00:50:42 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{086F0D48-9C43-42F5-9337-B46477B11F14} [2012.11.15 17:53:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer [2012.11.13 21:29:04 | 000,354,216 | ---- | C] (DivX, Inc.) -- C:\Windows\SysWow64\DivXControlPanelApplet.cpl [2012.11.13 11:51:01 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{E91A6F1F-ACA4-49D8-8C39-939C77E4FF28} [2012.11.13 11:07:02 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Roaming\XBMC [2012.11.13 11:00:53 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XBMC [2012.11.13 11:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XBMC [2012.11.12 13:29:08 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{76EA2B4A-DF74-4B4F-B072-14C386E8E7A3} [2012.11.12 13:04:09 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{400ABCB4-103D-4547-A1B1-2167C1183AC6} [2012.11.12 00:31:24 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{2FF23E46-0D5D-4771-BED0-FF42441A8101} [2012.11.10 09:25:27 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{EE90E5BC-7D22-4ADA-B3DC-62B302E42943} [2012.11.09 02:51:45 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{8B617B1E-B503-437B-9A65-9AFE97CE8FB0} [2012.11.08 18:14:57 | 000,000,000 | R--D | C] -- C:\Users\Redfield\Dropbox [2012.11.08 18:09:58 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox [2012.11.08 18:09:19 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Roaming\Dropbox [2012.11.08 14:35:19 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{2466D8AC-E7C4-4E06-AC51-3523D9BCF28A} [2012.11.07 00:36:28 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{863FEED2-6E05-4EBA-AE02-BDF2C2641635} [2012.11.06 11:33:05 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{C11A074E-6200-452E-9471-11AA15667E57} [2012.11.04 19:06:47 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{4174A7DE-662D-4A46-9C9D-8171A70AC571} [2012.11.02 01:17:38 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{F18A9853-F0A5-410A-B202-070E28F53284} [2012.11.01 11:09:48 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{DDFF1322-4D08-452C-9A3F-00C358231736} [2012.10.31 18:36:27 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{487FE43F-A232-4074-817D-E75D437CE53D} [2012.10.28 14:16:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2012.10.28 05:09:16 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{EACF37DB-6D45-45F9-B6B6-E62523849B85} [2012.10.27 16:25:18 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{C3FE0CF2-FF59-44FE-8681-FC58CB123DA3} [2012.10.27 12:36:49 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{0BE2233C-2BBE-4CD0-8BE8-C90C7F9EA0BB} [2012.10.26 16:19:08 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{70ECF43D-EA90-456F-9665-E543BAA4A3F7} [2012.10.24 22:38:29 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{DDAED678-7C86-4BF9-8ED4-937DC825E5F2} [2012.10.23 22:38:59 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{7711A3F8-A632-4D09-8248-10960779194C} [2012.10.22 11:07:49 | 000,000,000 | ---D | C] -- C:\Users\Redfield\AppData\Local\{EE3F5D34-71F4-4547-8711-D42060BE2D23} ========== Files - Modified Within 30 Days ========== [2012.11.19 00:21:59 | 000,016,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.11.19 00:21:59 | 000,016,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.11.19 00:10:29 | 000,030,528 | ---- | M] () -- C:\Windows\GVTDrv64.sys [2012.11.19 00:10:29 | 000,000,004 | ---- | M] () -- C:\Windows\SysWow64\GVTunner.ref [2012.11.19 00:09:11 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.11.19 00:08:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.11.19 00:08:37 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys [2012.11.19 00:02:42 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.11.19 00:02:42 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.11.18 22:29:11 | 004,945,672 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012.11.18 22:22:49 | 000,001,044 | ---- | M] () -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2012.11.18 22:16:50 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012.11.18 21:53:01 | 000,000,994 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk [2012.11.18 21:42:28 | 000,001,742 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2012.11.18 21:40:30 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012.11.18 21:40:30 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012.11.18 21:40:30 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012.11.18 21:40:30 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012.11.18 21:40:30 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012.11.18 21:24:48 | 000,001,969 | ---- | M] () -- C:\Users\Redfield\Desktop\Update Checker.lnk [2012.11.18 21:21:46 | 000,001,106 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2012.11.18 21:17:51 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2012.11.18 19:00:29 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk [2012.11.18 02:02:53 | 000,000,000 | ---- | M] () -- C:\Users\Redfield\defogger_reenable [2012.11.17 19:24:03 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.11.16 14:02:13 | 095,023,320 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012.11.15 17:53:24 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk [2012.11.15 17:16:35 | 000,000,146 | ---- | M] () -- C:\Users\Redfield\Desktop\Sound - Verknüpfung.lnk [2012.11.14 00:04:11 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012.11.13 21:29:04 | 000,354,216 | ---- | M] (DivX, Inc.) -- C:\Windows\SysWow64\DivXControlPanelApplet.cpl [2012.11.13 11:00:53 | 000,001,873 | ---- | M] () -- C:\Users\Redfield\Desktop\XBMC.lnk [2012.11.08 18:14:57 | 000,001,043 | ---- | M] () -- C:\Users\Redfield\Desktop\Dropbox.lnk [2012.11.08 18:10:20 | 000,001,053 | ---- | M] () -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2012.10.30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys [2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys [2012.10.30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2012.10.30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe [2012.10.30 23:50:30 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2012.10.27 16:39:15 | 000,027,113 | ---- | M] () -- C:\Users\Redfield\Documents\Bauer.odt ========== Files Created - No Company Name ========== [2012.11.18 22:22:49 | 000,001,044 | ---- | C] () -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2012.11.18 21:53:01 | 000,000,994 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk [2012.11.18 21:24:48 | 000,001,999 | ---- | C] () -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk [2012.11.18 21:24:48 | 000,001,969 | ---- | C] () -- C:\Users\Redfield\Desktop\Update Checker.lnk [2012.11.18 21:21:46 | 000,001,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2012.11.18 21:21:46 | 000,001,069 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk [2012.11.18 19:00:29 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk [2012.11.18 19:00:29 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk [2012.11.18 02:02:53 | 000,000,000 | ---- | C] () -- C:\Users\Redfield\defogger_reenable [2012.11.17 19:24:03 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.11.16 13:47:35 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012.11.16 12:28:41 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012.11.16 12:22:58 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012.11.15 17:53:24 | 000,001,174 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk [2012.11.15 17:53:24 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk [2012.11.15 17:16:35 | 000,000,146 | ---- | C] () -- C:\Users\Redfield\Desktop\Sound - Verknüpfung.lnk [2012.11.15 00:10:48 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012.11.13 11:00:53 | 000,001,873 | ---- | C] () -- C:\Users\Redfield\Desktop\XBMC.lnk [2012.11.08 18:14:57 | 000,001,043 | ---- | C] () -- C:\Users\Redfield\Desktop\Dropbox.lnk [2012.11.08 18:10:20 | 000,001,053 | ---- | C] () -- C:\Users\Redfield\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2012.10.27 15:01:22 | 000,027,113 | ---- | C] () -- C:\Users\Redfield\Documents\Bauer.odt [2012.08.13 11:08:08 | 000,014,217 | ---- | C] () -- C:\Program Files (x86)\readme.html [2012.05.09 10:40:26 | 004,818,944 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll [2012.05.08 14:15:36 | 000,000,005 | ---- | C] () -- C:\Program Files (x86)\basis-link [2012.03.22 21:01:32 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2012.01.09 22:45:18 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2011.12.07 22:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll [2011.12.04 18:54:53 | 000,007,707 | ---- | C] () -- C:\Users\Redfield\.recently-used.xbel [2011.10.26 17:14:07 | 000,001,852 | ---- | C] () -- C:\Users\Redfield\AppData\Roaming\ImperatorProfile0.dat [2011.05.26 18:18:46 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll [2011.05.26 18:18:46 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini [2010.12.09 18:41:39 | 000,146,836 | ---- | C] () -- C:\Windows\hpoins44.dat [2010.12.09 18:41:39 | 000,000,512 | ---- | C] () -- C:\Windows\hpomdl44.dat [2010.12.01 16:02:38 | 000,027,136 | ---- | C] () -- C:\Users\Redfield\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.12.01 13:05:41 | 000,196,096 | ---- | C] () -- C:\Windows\SysWow64\macd32.dll [2010.12.01 13:05:41 | 000,138,752 | ---- | C] () -- C:\Windows\SysWow64\mase32.dll [2010.12.01 13:05:41 | 000,136,192 | ---- | C] () -- C:\Windows\SysWow64\mamc32.dll [2010.12.01 13:05:41 | 000,057,856 | ---- | C] () -- C:\Windows\SysWow64\masd32.dll [2010.12.01 13:05:41 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\ma32.dll [2010.11.11 15:17:08 | 000,007,642 | ---- | C] () -- C:\Users\Redfield\AppData\Local\Resmon.ResmonCfg ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2011.03.07 19:13:11 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Amazon [2011.07.21 12:20:40 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Canneverbe Limited [2012.03.09 11:00:13 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1 [2012.11.19 00:11:19 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Dropbox [2012.09.25 09:20:14 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\DVDVideoSoft [2011.03.24 18:05:03 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\DVDVideoSoftIEHelpers [2011.12.04 18:54:53 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\gtk-2.0 [2011.11.10 11:42:56 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\ML [2012.11.18 22:22:57 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\OOo-dev [2010.11.15 00:49:54 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\OpenOffice.org [2011.02.09 15:44:25 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Razer [2012.11.15 23:15:01 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Spotify [2012.11.13 23:56:14 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\uTorrent [2012.05.13 16:02:14 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Win7codecs [2010.12.03 13:42:07 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\Windows Live Writer [2012.11.16 12:12:27 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\XBMC [2011.04.01 14:48:54 | 000,000,000 | ---D | M] -- C:\Users\Redfield\AppData\Roaming\XMedia Recode ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 164 bytes -> C:\Users\Redfield\Documents\löwenzahn 3.jpg:3or4kl4x13tuuug3Byamue2s4b < End of report > Code:
ATTFilter Results of screen317's Security Check version 0.99.54 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 8 Out of date! ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Secunia PSI ( Malwarebytes Anti-Malware Version JavaFX 2.1.1 Java(TM) 6 Update 22 Java(TM) 6 Update 37 Java 7 Update 9 Adobe Flash Player 11.5.502.110 Mozilla Firefox (16.0.2) Google Chrome 7.0.517.44 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Redfield Desktop Anti Virus Programme OTL.exe Malwarebytes' Anti-Malware mbamscheduler.exe Avast5 AvastSvc.exe Avast5 AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Okay .... Resteverwertung ... Schritt 1: Fix mit OTL Schritt 2: Deinstalliere Spybot,µTOrrent, Java 6 U22 und U37 (weil alt) Warnung vor Filesharingprogrammen Hier:Schritt 3: Quick-Scan mit Malwarebytes Schritt 4: ESET Online Scanner
Schritt 5: Update: Internetexplorer Schritt 6: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck
Hier die neuen Logfiles, ich habe leider vergessen beim Eset Scanner die Firewall und das Antiviren Programm zu deaktivieren, ich hoffe das macht den Scan nicht unbrauchbar, der hat nebenbei über 10 Stunden gedauert...
ATTFilter C:\ProgramData\dsgsdgdsgdsgw.pad moved successfully. Unable to delete ADS C:\Users\Redfield\Documents\löwenzahn 3.jpg:3or4kl4x13tuuug3Byamue2s4b . ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Redfield ->Temp folder emptied: 208039720 bytes ->Temporary Internet Files folder emptied: 60961015 bytes ->Java cache emptied: 2786687 bytes ->FireFox cache emptied: 67224644 bytes ->Google Chrome cache emptied: 6442890 bytes ->Flash cache emptied: 15167384 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 61649336 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50568 bytes RecycleBin emptied: 164856814 bytes Total Files Cleaned = 560,00 mb OTL by OldTimer - Version log created on 11192012_141127 Files\Folders moved on Reboot... C:\Users\Redfield\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2012.11.17.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Redfield :: REDFIELD2 [Administrator] Schutz: Aktiviert 19.11.2012 14:42:36 mbam-log-2012-11-19 (14-42-36).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 226185 Laufzeit: 2 Minute(n), 30 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter C:\Users\Redfield\Downloads\PDFCreator-1_2_1_setup.exe Win32/Toolbar.Widgi application Code:
ATTFilter Results of screen317's Security Check version 0.99.54 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 8 Out of date! ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version JavaFX 2.1.1 Java 7 Update 9 Adobe Flash Player 11.5.502.110 Mozilla Firefox (16.0.2) Google Chrome 7.0.517.44 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe Avast5 AvastSvc.exe Avast5 AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
![]() | #6 | ||||
Prima! Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: Tools deinstallieren
Schritt 2: ESET deinstallieren (Optional) Schritt 3: Update: Internetexplorer Abschließend noch Tipps zu folgenden Themen:
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.
__________________ --> GVU Trojaner, Systembereinigung, Logfiles |
Vielen Vielen Dank für deine Mühe, nur noch eine Frage: Wieso macht ihr das eigentlich? Alleine aus meinem Bekanntenkreis kenne ich 5 Leute, die sich diesen miesen Trojaner eingefangen haben, da müssen sich ja hunderte bei euch melden... Ein Großes Lob an euch, ich werd was spenden! (Was seit ihr eigentlich für eine Konstitution, ihr bildet auch aus?)
ATTFilter # AdwCleaner v6.2 - Datei am 20/11/2012 um 16:46:28 erstellt # Aktualisiert am 11/11/2012 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : Redfield - REDFIELD2 # Ausgeführt unter : C:\Users\Redfield\Downloads\delfix.exe # Option [Löschen] ~~~~~~ Ordner ~~~~~~ Gelöscht : C:\_OTL ~~~~~~ Datei(en) ~~~~~~ Gelöscht : C:\AdwCleaner[R1].txt Gelöscht : C:\AdwCleaner[S2].txt Gelöscht : C:\Users\Redfield\Downloads\adwcleaner.exe Gelöscht : C:\Users\Redfield\Downloads\Defogger.exe Gelöscht : C:\Users\Redfield\Downloads\defogger_disable.log Gelöscht : C:\Users\Redfield\Downloads\esetsmartinstaller_enu.exe Gelöscht : C:\Users\Redfield\Downloads\Extras.Txt Gelöscht : C:\Users\Redfield\Downloads\OTL.Txt Gelöscht : C:\Users\Redfield\Downloads\OTL.exe Gelöscht : C:\Users\Redfield\Downloads\SecurityCheck(1).exe Gelöscht : C:\Users\Redfield\Downloads\SecurityCheck(2).exe Gelöscht : C:\Users\Redfield\Downloads\SecurityCheck.exe ~~~~~~ Registrierungsdatenbank ~~~~~~ Schlüssel gelöscht : HKLM\SOFTWARE\OldTimer Tools Schlüssel gelöscht : HKLM\SOFTWARE\AdwCleaner ~~~~~~ Sonstiges ~~~~~~ Deinstalliert : ESET Online Scanner -> Prefetch Geleert ************************* DelFix[S1].txt - [1254 octets] - [20/11/2012 16:46:28] ########## EOF - C:\DelFix[S1].txt - [1378 octets] ########## Chris |
Warum? Viele machen das aus Interesse und weil sie eben gerne helfen. ... ja sind schon eine Menge Viel SPass noch. Schön, dass wir helfen konnten Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen
__________________ ![]() ![]() Keine Hilfe per PM! |
Nachdem ich mit deiner Hilfe gestern (endgültig) den GVU Trojaner beseitigt habe, kam nach einem halben Tag ohne Probleme leider das nächste. Problemstellung: Nach dem Starten des Computers hängt sich der Windows Explorer ständig auf. Es kommt immer wieder die Meldung: ''Windows Explorer funktioniert nicht mehr'' und direkt danach ''Windows Explorer wird neu gestartet'' und das ganze in einer Endlosschleife, der PC lässt sich nicht mehr bedienen (außer TaskManager in dem man aber den Prozess auch nicht beenden kann). Ich weiß nicht ob es was damit zu tun hat, aber 2 Stunden vorher hatte ich CCleaner nochmal gestartet und darüber auch die Registry bereinigt (aber blöder Weise kein Backup eingerichtet ich hoffe mir kann erneut weitergeholfen werden... Gruß Chris Habe zusätzlich über die Kaspersky REscue Disk nochmal einen kompletten Scan durchgeführt > Nichts gefunden Habe dann über den Taskmanager Antimalware nochmal installiert und ausgeführt > ebenfalls ohne neg. Befunde, es kam aber nachdem beenden folgende Fehleranzeige: [Shell_NotifyIcon] Die Ausführung der gewünschten Aktion ist fehlgeschlagen. Fehlermeldung: 0. Ich glaube aber das hat nur was mit dem preozess explorer.exe den ich vorher beendet habe um überhaupt irgendwas zu tätigen zu können (hatte im web gefunden: Shell_NotifyIcon failed heißt eigentlich, das ein Hintergrundprozess etwas im Tray neben der Uhr einblenden möchte und das ist fehlgeschlagen. Gründe gibt es dafür viele, reicht vom defekten Tray bis hin zu Rechteprobleme. Schwer zu sagen....) Diese explorer.exe Fehlermeldung Endloschschleife (Loop) habe ich merhmals in diversen Foren gefunden, nur leider ohne direkte Lösungsansätze... Irgendjemand eine Idee?
Wollte nur nochmal kurz Rückmeldung geben, falls hier nochmal einer nachlesen sollte: Das Problem mit der explorer.exe Endloschleife hat eine Application hier von OpenOffice verursacht (welches ich neu runtergeladen hatte). Bei der Installation einiger Programmen integriert sich eine zusätzliche Funktion in das Rechtsklick Kontextmenu (welches auch zum explorer gehört) und verursacht einen Crash dieser .exe Datei. Den Übeltäter rausfinden kann man indem man im Taskmanager > neuen Task ausführen und dort eventvwr.exe eingibt, dann erscheint die Windows Fehlerursache mit ausführlichen Details, entprechendes Programm mit der die explorer.exe kollidiert über > neuen Task ausführen > control.exe (Systemsteurerung) löschen und neustarten. Das System sollte jetzt wieder normal laufen. Gruß Chris
