|
Plagegeister aller Art und deren Bekämpfung: Claro Search entfernen?!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.12.2012, 17:47 | #1 |
| Claro Search entfernen?! Hey, wie einige andere auch habe ich mir Claro Search im Firefox eingefangen. Ich kann den unter Programme Deinstallieren in der Liste nicht finden. Wie krieg ich den los?! :/ Er stört mich zwar nicht, aber ich hab Angst das ich mir dadurch noch mehr einfange. lg brainInfect |
08.12.2012, 13:18 | #2 |
/// TB-Ausbilder | Claro Search entfernen?!Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Schritt 1 Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop (falls noch nicht vorhanden).
Code:
ATTFilter activex netsvcs msconfig drivers32 safebootminimal safebootnetwork hklm\software\clients\startmenuinternet|command /rs hklm\software\clients\startmenuinternet|command /64 /rs CREATERESTOREPOINT
Schritt 2 Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Schritt 3 Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit. Schritt 4 Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen. Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
08.12.2012, 15:15 | #3 |
| Claro Search entfernen?! Hey, habe alles so gemacht wie beschrieben. Da alles zusammen zu viele Zeichen sind, habe ich alle LOG-Files als rar-Datei im Anhang hochgeladen. Ich hoffe, dass ist in Ordnung?!
__________________lg |
08.12.2012, 20:34 | #4 |
/// TB-Ausbilder | Claro Search entfernen?! Servus, Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden. Bitte lade Junkware Removal Tool auf Deinen Desktop.
Schritt 3 Scan mit Combofix
Bitte poste mit deiner nächsten Antwort
|
08.12.2012, 20:59 | #5 |
| Claro Search entfernen?! Also die ersten beiden Schritte habe ich gemacht, nur bei ComboFix gibt es Probleme. Der zeigt mir an, dass Microsoft Security Essentials Antivirus und Antispyware aktiv sind, allerdings hatte ich Essential in der Taskleiste bereits deaktiviert und im Task Manager kann ich unter Dienste das Anti Malware Service nicht beenden. Was soll ich machen? Hier aber erstmal die beiden Logs der ersten beiden Schritte: ADWcleaner-Log Code:
ATTFilter # AdwCleaner v2.011 - Datei am 08/12/2012 um 20:36:30 erstellt # Aktualisiert am 02/12/2012 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : smoking caterpillar - SMOKINGCATERPIL # Bootmodus : Normal # Ausgeführt unter : C:\Users\smoking caterpillar\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml Datei Gelöscht : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\searchplugins\SweetIm.xml Datei Gelöscht : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\ugu86ww1.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\ugu86ww1.default\searchplugins\SweetIm.xml Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar Ordner Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com Ordner Gelöscht : C:\Program Files (x86)\SweetIM Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\Users\smoking caterpillar\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\smoking caterpillar\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\ugu86ww1.default\extensions\staged ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Headlight Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16455 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.claro-search.com/?affID=116198&tt=4312_1&babsrc=HP_ss&mntrId=f214fa1400000000000060d8198ce21b --> hxxp://www.google.com Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com -\\ Mozilla Firefox v17.0.1 (de) Profilname : default Datei : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\ugu86ww1.default\prefs.js Gelöscht : user_pref("browser.startup.homepage", "hxxp://start.icq.com/"); Profilname : Daniel [Profil par défaut] Datei : C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\prefs.js C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\user.js ... Gelöscht ! Gelöscht : user_pref("browser.search.defaultenginename", "Claro Search"); Gelöscht : user_pref("browser.search.order.1", "Claro Search"); Gelöscht : user_pref("browser.search.selectedEngine", "Claro Search"); Gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true); Gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.claro-search.com/?affID=116198&tt=431[...] Gelöscht : user_pref("extensions.DivXWebPlayer@divx.com.install-event-fired", true); Gelöscht : user_pref("extensions.claro.admin", false); Gelöscht : user_pref("extensions.claro.aflt", "babsst"); Gelöscht : user_pref("extensions.claro.appId", "{C3110516-8EFC-49D6-8B72-69354F332062}"); Gelöscht : user_pref("extensions.claro.dfltLng", "en"); Gelöscht : user_pref("extensions.claro.excTlbr", false); Gelöscht : user_pref("extensions.claro.id", "f214fa1400000000000060d8198ce21b"); Gelöscht : user_pref("extensions.claro.instlDay", "15639"); Gelöscht : user_pref("extensions.claro.instlRef", "sst"); Gelöscht : user_pref("extensions.claro.prdct", "claro"); Gelöscht : user_pref("extensions.claro.prtnrId", "claro"); Gelöscht : user_pref("extensions.claro.tlbrId", "claro"); Gelöscht : user_pref("extensions.claro.tlbrSrchUrl", ""); Gelöscht : user_pref("extensions.claro.vrsn", "1.8.3.10"); Gelöscht : user_pref("extensions.claro.vrsni", "1.8.3.10"); Gelöscht : user_pref("extensions.claro_i.smplGrp", "none"); Gelöscht : user_pref("extensions.claro_i.vrsnTs", "1.8.3.1019:57:51"); Profilname : default Datei : C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\3cbmkf59.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [7499 octets] - [08/12/2012 20:36:30] ########## EOF - C:\AdwCleaner[S1].txt - [7559 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 3.9.9 (12.08.2012:3) OS: Windows 7 Home Premium x64 Ran by smoking caterpillar on 08.12.2012 at 20:41:16,59 Blog: hxxp://thisisudax.blogspot.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] "hkey_current_user\software\sweetim" Successfully deleted: [Registry Key] "hkey_local_machine\software\systweak" ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted the following from C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\prefs.js user_pref("extensions.enabledItems", "personas@christopher.beard:1.6.1,eafo3fflauncher@ea.com:1.1,{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2,{20a82645-c095-46ed-80e3-08825 user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !impor user_pref("extensions.wrc.SearchRules.ask.com.url", "^http(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); user_pref("extensions.wrc.SearchRules.baidu.com.style", ".WRCN {display:none} .result .f .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}"); user_pref("extensions.wrc.SearchRules.baidu.com.url", "^http\\:\\/\\/www\\.baidu\\.com\\/.*"); user_pref("extensions.wrc.SearchRules.excite.com.style", ".WRCN {display:none} .listing .resultsLink + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-re user_pref("extensions.wrc.SearchRules.excite.com.url", "^http\\:\\/\\/msxml\\.excite\\.com\\/excite\\/ws\\/.+"); user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-r user_pref("weboftrust.search.ask.display", "Ask.com Web Search"); user_pref("weboftrust.search.baidu.display", "Baidu"); user_pref("weboftrust.search.baidu.ign", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*baidu\\.com\\/"); user_pref("weboftrust.search.baidu.prestyle", "[ATTR] { position: absolute; visibility: hidden; }"); user_pref("weboftrust.search.baidu.style", ".f a ~ [ATTR=\"NAME\"] { background: url(IMAGE) right no-repeat; margin-left: 4px; position: relative; visibility: visible; }"); user_pref("weboftrust.search.baidu.url", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*baidu\\.com\\/s\\\\?.+"); user_pref("weboftrust.search.dogpile.display", "Dogpile"); user_pref("weboftrust.search.dogpile.ign", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*dogpile\\.com\\/|^http\\:\\/\\/(.+\\.)?r\\.msn\\.com\\/"); user_pref("weboftrust.search.dogpile.pre0.match", 3); user_pref("weboftrust.search.dogpile.pre0.re", "^http(s)?\\:\\/\\/cs\\.(dogpile|infospace)\\.com\\/ClickHandler.+ru=(http[^&]+)"); user_pref("weboftrust.search.dogpile.prestyle", ".paidSearchResult [ATTR] { display: none ! important; } .searchResultsPane { max-width: 44.08em; } [ATTR] { position: absolute user_pref("weboftrust.search.dogpile.style", "a.resultTitle ~ [ATTR=\"NAME\"] { background: url(IMAGE) right no-repeat; margin-left: 4px; padding-bottom: 1px; position: relati user_pref("weboftrust.search.dogpile.url", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*dogpile\\.com\\/(info\\.[^\\/]+/)?(search\\/)?web.+"); user_pref("weboftrust.search.ixquick.display", "Ixquick"); user_pref("weboftrust.search.ixquick.ign", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*(ixquick|startpage|startingpage)\\.com\\/?"); user_pref("weboftrust.search.ixquick.pre0.match", 6); user_pref("weboftrust.search.ixquick.pre0.re", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)?google\\.(com?\\.[a-z]{2}|[a-z]{2,})\\/(url|pagead|interstitial|aclk).*\\\\?.*(q|adurl|url)=(. user_pref("weboftrust.search.ixquick.pre1.match", 4); user_pref("weboftrust.search.ixquick.pre1.re", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*(ixquick|startpage|startingpage)\\.com\\/do\\/highlight.*&u=(http[^&]*)"); user_pref("weboftrust.search.ixquick.prestyle", "[ATTR] { position: absolute; visibility: hidden; }"); user_pref("weboftrust.search.ixquick.style", "a.title ~ [ATTR=\"NAME\"], a.title2 ~ [ATTR=\"NAME\"], .result h3 > a ~ [ATTR=\"NAME\"] { background: url(IMAGE) right no-repeat; user_pref("weboftrust.search.ixquick.url", "^http(s)?\\:\\/\\/([\\w\\-]+\\.)*(ixquick|startpage|startingpage)\\.com\\/do\\/(meta)?search"); ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.12.2012 at 20:46:40,11 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
08.12.2012, 21:07 | #6 |
/// TB-Ausbilder | Claro Search entfernen?! Servus, Fahre mit ComboFix trotzdem fort, auch wenn angezeigt wird, dass MSE noch aktiv ist. |
08.12.2012, 21:23 | #7 |
| Claro Search entfernen?! Alles klar, hier dann der ComboFix-Log: Code:
ATTFilter ComboFix 12-12-07.01 - smoking caterpillar 08.12.2012 21:11:22.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4000.2551 [GMT 1:00] ausgeführt von:: c:\users\smoking caterpillar\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2012-11-08 bis 2012-12-08 )))))))))))))))))))))))))))))) . . 2012-12-08 20:15 . 2012-12-08 20:15 -------- d-----w- c:\users\Ich\AppData\Local\temp 2012-12-08 20:15 . 2012-12-08 20:15 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-12-08 19:41 . 2012-12-08 19:41 -------- d-----w- c:\windows\ERUNT 2012-12-08 19:41 . 2012-12-08 19:41 -------- d-----w- C:\JRT 2012-12-07 22:07 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E69494E2-DD0A-4422-A7F1-5183FE994AF3}\mpengine.dll 2012-12-07 13:26 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-12-04 16:16 . 2008-05-30 13:11 4991496 ----a-w- c:\windows\system32\D3DX9_38.dll 2012-12-04 16:16 . 2008-05-30 13:11 3850760 ----a-w- c:\windows\SysWow64\D3DX9_38.dll 2012-12-04 16:15 . 2012-12-05 02:06 -------- d-----w- c:\program files (x86)\Common Files\BioWare 2012-12-04 16:15 . 2012-12-04 16:15 -------- d-----w- c:\program files (x86)\Electronic Arts 2012-12-04 16:15 . 2012-12-04 16:15 -------- d-----w- c:\users\hedev 2012-12-03 00:28 . 2012-12-03 00:28 -------- d-----w- c:\users\smoking caterpillar\AppData\Local\DDMSettings 2012-12-03 00:25 . 2012-12-03 00:25 -------- d-----w- c:\program files\DivX 2012-12-03 00:25 . 2012-12-03 00:25 -------- d-----w- c:\program files (x86)\Common Files\DivX Shared 2012-12-03 00:24 . 2012-12-03 00:25 -------- d-----w- c:\program files (x86)\DivX 2012-12-03 00:23 . 2012-12-03 00:25 -------- d-----w- c:\programdata\DivX 2012-11-28 11:48 . 2012-11-28 11:48 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{890EBF68-D328-4658-8717-C84D5D34BBC7}\gapaengine.dll 2012-11-27 02:00 . 2012-11-27 02:00 -------- d-----w- c:\users\smoking caterpillar\.thumbnails 2012-11-27 01:58 . 2012-11-27 01:58 -------- d-----w- c:\users\smoking caterpillar\AppData\Local\fontconfig 2012-11-27 01:58 . 2012-12-07 16:33 -------- d-----w- c:\users\smoking caterpillar\.gimp-2.8 2012-11-27 01:58 . 2012-11-27 01:58 -------- d-----w- c:\users\smoking caterpillar\AppData\Local\gegl-0.2 2012-11-27 01:56 . 2012-11-27 01:57 -------- d-----w- c:\program files\GIMP 2 2012-11-22 20:50 . 2012-11-22 21:02 -------- d-----w- c:\users\smoking caterpillar\AppData\Roaming\TeamViewer 2012-11-16 15:26 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui 2012-11-16 15:26 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2012-11-16 15:26 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2012-11-16 15:26 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll 2012-11-16 15:19 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2012-11-16 15:19 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2012-11-16 15:19 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2012-11-16 15:19 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2012-11-16 15:19 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2012-11-16 15:19 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2012-11-16 15:19 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2012-11-16 04:29 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll 2012-11-16 04:29 . 2012-10-09 18:17 226816 ----a-w- c:\windows\system32\dhcpcore6.dll 2012-11-16 04:29 . 2012-10-09 17:40 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll 2012-11-16 04:29 . 2012-10-09 17:40 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-11-16 04:29 . 2012-10-18 18:25 3149824 ----a-w- c:\windows\system32\win32k.sys 2012-11-15 18:11 . 2012-11-15 20:47 -------- d-----w- c:\users\smoking caterpillar\AppData\Roaming\Mipony 2012-11-15 18:10 . 2012-11-15 18:11 -------- d-----w- c:\program files (x86)\MiPony 2012-11-15 16:29 . 2012-11-15 22:32 -------- d-----w- c:\users\smoking caterpillar\AppData\Roaming\calibre 2012-11-15 16:28 . 2012-11-15 16:29 -------- d-----w- c:\program files (x86)\Calibre2 2012-11-14 18:37 . 2012-11-14 18:37 -------- d-----w- c:\users\smoking caterpillar\AppData\Local\ElevatedDiagnostics 2012-11-13 20:29 . 2012-11-13 20:29 354216 ----a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl 2012-11-09 18:34 . 2012-11-09 18:36 -------- d-----w- c:\users\smoking caterpillar\AppData\Roaming\GetRight 2012-11-09 00:24 . 2012-11-14 18:55 -------- d-----w- c:\users\smoking caterpillar\AppData\Local\Google 2012-11-09 00:24 . 2012-11-09 00:24 -------- d-----w- c:\users\smoking caterpillar\AppData\Roaming\SUPERAntiSpyware.com 2012-11-09 00:24 . 2012-11-14 18:56 -------- d-----w- c:\program files (x86)\Google 2012-11-09 00:24 . 2012-11-09 14:30 -------- d-----w- c:\program files\SUPERAntiSpyware 2012-11-09 00:24 . 2012-11-09 00:24 -------- d-----w- c:\programdata\SUPERAntiSpyware.com . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-11-16 15:20 . 2012-10-02 15:28 66395536 ----a-w- c:\windows\system32\MRT.exe 2012-11-14 18:54 . 2012-10-02 16:24 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-11-14 18:54 . 2012-10-02 16:24 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-16 08:38 . 2012-11-28 13:19 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 13:19 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 13:19 561664 ----a-w- c:\windows\apppatch\AcLayers.dll 2012-10-05 06:16 . 2012-10-05 06:17 972192 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-10-02 19:25 . 2012-10-02 19:25 2887680 ----a-w- c:\windows\SysWow64\libmmd.dll 2012-10-02 18:43 . 2012-10-02 18:43 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-10-02 18:43 . 2012-10-02 18:43 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-10-02 18:43 . 2012-10-02 18:43 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll 2012-10-02 15:35 . 2012-10-02 15:35 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-10-02 15:35 . 2012-10-02 15:35 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-10-02 15:35 . 2012-10-02 15:35 89088 ----a-w- c:\windows\system32\ie4uinit.exe 2012-10-02 15:35 . 2012-10-02 15:35 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll 2012-10-02 15:35 . 2012-10-02 15:35 85504 ----a-w- c:\windows\system32\iesetup.dll 2012-10-02 15:35 . 2012-10-02 15:35 82432 ----a-w- c:\windows\system32\icardie.dll 2012-10-02 15:35 . 2012-10-02 15:35 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-10-02 15:35 . 2012-10-02 15:35 76800 ----a-w- c:\windows\system32\tdc.ocx 2012-10-02 15:35 . 2012-10-02 15:35 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-10-02 15:35 . 2012-10-02 15:35 74752 ----a-w- c:\windows\SysWow64\iesetup.dll 2012-10-02 15:35 . 2012-10-02 15:35 65024 ----a-w- c:\windows\system32\pngfilt.dll 2012-10-02 15:35 . 2012-10-02 15:35 63488 ----a-w- c:\windows\SysWow64\tdc.ocx 2012-10-02 15:35 . 2012-10-02 15:35 55296 ----a-w- c:\windows\system32\msfeedsbs.dll 2012-10-02 15:35 . 2012-10-02 15:35 534528 ----a-w- c:\windows\system32\ieapfltr.dll 2012-10-02 15:35 . 2012-10-02 15:35 49664 ----a-w- c:\windows\system32\imgutil.dll 2012-10-02 15:35 . 2012-10-02 15:35 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2012-10-02 15:35 . 2012-10-02 15:35 48640 ----a-w- c:\windows\system32\mshtmler.dll 2012-10-02 15:35 . 2012-10-02 15:35 452608 ----a-w- c:\windows\system32\dxtmsft.dll 2012-10-02 15:35 . 2012-10-02 15:35 448512 ----a-w- c:\windows\system32\html.iec 2012-10-02 15:35 . 2012-10-02 15:35 403248 ----a-w- c:\windows\system32\iedkcs32.dll 2012-10-02 15:35 . 2012-10-02 15:35 39936 ----a-w- c:\windows\system32\iernonce.dll 2012-10-02 15:35 . 2012-10-02 15:35 3695416 ----a-w- c:\windows\system32\ieapfltr.dat 2012-10-02 15:35 . 2012-10-02 15:35 367104 ----a-w- c:\windows\SysWow64\html.iec 2012-10-02 15:35 . 2012-10-02 15:35 35840 ----a-w- c:\windows\SysWow64\imgutil.dll 2012-10-02 15:35 . 2012-10-02 15:35 30720 ----a-w- c:\windows\system32\licmgr10.dll 2012-10-02 15:35 . 2012-10-02 15:35 282112 ----a-w- c:\windows\system32\dxtrans.dll 2012-10-02 15:35 . 2012-10-02 15:35 267776 ----a-w- c:\windows\system32\ieaksie.dll 2012-10-02 15:35 . 2012-10-02 15:35 249344 ----a-w- c:\windows\system32\webcheck.dll 2012-10-02 15:35 . 2012-10-02 15:35 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll 2012-10-02 15:35 . 2012-10-02 15:35 222208 ----a-w- c:\windows\system32\msls31.dll 2012-10-02 15:35 . 2012-10-02 15:35 197120 ----a-w- c:\windows\system32\msrating.dll 2012-10-02 15:35 . 2012-10-02 15:35 165888 ----a-w- c:\windows\system32\iexpress.exe 2012-10-02 15:35 . 2012-10-02 15:35 163840 ----a-w- c:\windows\system32\ieakui.dll 2012-10-02 15:35 . 2012-10-02 15:35 161792 ----a-w- c:\windows\SysWow64\msls31.dll 2012-10-02 15:35 . 2012-10-02 15:35 160256 ----a-w- c:\windows\system32\wextract.exe 2012-10-02 15:35 . 2012-10-02 15:35 160256 ----a-w- c:\windows\system32\ieakeng.dll 2012-10-02 15:35 . 2012-10-02 15:35 152064 ----a-w- c:\windows\SysWow64\wextract.exe 2012-10-02 15:35 . 2012-10-02 15:35 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2012-10-02 15:35 . 2012-10-02 15:35 149504 ----a-w- c:\windows\system32\occache.dll 2012-10-02 15:35 . 2012-10-02 15:35 145920 ----a-w- c:\windows\system32\iepeers.dll 2012-10-02 15:35 . 2012-10-02 15:35 135168 ----a-w- c:\windows\system32\IEAdvpack.dll 2012-10-02 15:35 . 2012-10-02 15:35 12288 ----a-w- c:\windows\system32\mshta.exe 2012-10-02 15:35 . 2012-10-02 15:35 11776 ----a-w- c:\windows\SysWow64\mshta.exe 2012-10-02 15:35 . 2012-10-02 15:35 114176 ----a-w- c:\windows\system32\admparse.dll 2012-10-02 15:35 . 2012-10-02 15:35 111616 ----a-w- c:\windows\system32\iesysprep.dll 2012-10-02 15:35 . 2012-10-02 15:35 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-10-02 15:35 . 2012-10-02 15:35 10752 ----a-w- c:\windows\system32\msfeedssync.exe 2012-10-02 15:35 . 2012-10-02 15:35 103936 ----a-w- c:\windows\system32\inseng.dll 2012-10-02 15:35 . 2012-10-02 15:35 101888 ----a-w- c:\windows\SysWow64\admparse.dll 2012-09-29 18:54 . 2012-10-06 16:38 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-09-20 15:02 . 2012-09-20 15:02 1832760 ----a-w- c:\windows\system32\LogiLDA.DLL 2012-09-18 22:58 . 2012-10-02 15:47 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AAA9FA5E-C541-4BC2-B0ED-2BB98B330CD3}\mpengine.dll 2012-09-14 19:19 . 2012-10-10 22:41 2048 ----a-w- c:\windows\system32\tzres.dll 2012-09-14 18:28 . 2012-10-10 22:41 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2012-09-12 13:57 . 2012-09-12 13:57 322048 ----a-w- c:\windows\WLXPGSS.SCR . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-09 5629312] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2012-11-01 1263512] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2011-12-16 17976] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R4 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2011-06-14 498688] R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-09-24 1328736] R4 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-09-24 656480] R4 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2011-06-14 986112] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2012-07-13 769432] S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456] S3 bpenum;Intel(R) Centrino(R) WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2011-05-19 84480] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912] S3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896] . . Inhalt des "geplante Tasks" Ordners . 2012-12-08 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-02 18:54] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Mit Mipony herunterladen - file://c:\program files (x86)\MiPony\Browser\IEContext.htm IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 445 FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2012-11-30 05:45; ich@maltegoetz.de; c:\users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\ich@maltegoetz.de FF - ExtSQL: 2012-12-03 01:25; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; c:\program files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF - ExtSQL: !HIDDEN! 2012-10-02 18:32; firejump@firejump.net; c:\users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\firejump@firejump.net . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}] @Denied: (A 2) (Everyone) @="FlashProp Class" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2012-12-08 21:19:19 ComboFix-quarantined-files.txt 2012-12-08 20:19 . Vor Suchlauf: 8 Verzeichnis(se), 81.162.346.496 Bytes frei Nach Suchlauf: 12 Verzeichnis(se), 84.050.731.008 Bytes frei . - - End Of File - - ED9B4AC47C730ED7AE45E5CB4B2AAC8F lg |
09.12.2012, 22:04 | #9 |
| Claro Search entfernen?! Hey, ist mir jetzt gerade erst aufgefallen.^^ ClaroSearch ist weg aus dem Firefox. o.o Jetzt ist da die Yahoo-Suchmaschine. xD Aber die stört mich nicht weiter, soll sie ruhig oben rechts in der Ecke vor sich hin stehen.^^ Wow, das ging ja echt schnell und problemlos. Hast du anhand der Logs denn anderweitige Probleme erkennen können? Ich spüre zwar nichts was den PC befallen hätte können, aber sicher ist sicher.^^ Hier der neue OTL-Log: Code:
ATTFilter OTL logfile created on: 09.12.2012 21:59:49 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\smoking caterpillar\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,91 Gb Total Physical Memory | 2,32 Gb Available Physical Memory | 59,49% Memory free 7,81 Gb Paging File | 6,05 Gb Available in Paging File | 77,43% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 119,24 Gb Total Space | 82,53 Gb Free Space | 69,21% Space Free | Partition Type: NTFS Drive D: | 153,85 Gb Total Space | 129,07 Gb Free Space | 83,89% Space Free | Partition Type: NTFS Computer Name: SMOKINGCATERPIL | User Name: smoking caterpillar | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.12.08 13:35:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\smoking caterpillar\Desktop\OTL.exe PRC - [2012.12.05 16:29:38 | 000,916,960 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2012.11.14 19:54:10 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe PRC - [2012.11.01 18:56:20 | 001,263,512 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe PRC - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.07.13 15:27:00 | 000,769,432 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe PRC - [2012.06.20 17:14:18 | 002,206,888 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winamp.exe PRC - [2010.10.27 20:21:54 | 001,155,072 | ---- | M] (Last.fm) -- C:\Program Files (x86)\Last.fm\LastFM.exe PRC - [2009.09.23 15:45:50 | 001,287,176 | ---- | M] (Panda Security) -- C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe ========== Modules (No Company Name) ========== MOD - [2012.12.09 21:09:05 | 000,206,336 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\winamp.lng MOD - [2012.12.09 21:09:05 | 000,007,680 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\vis_nsfs.lng MOD - [2012.12.09 21:09:05 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\winampa.lng MOD - [2012.12.09 21:09:04 | 000,156,160 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\vis_milk2.lng MOD - [2012.12.09 21:09:04 | 000,088,064 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\vis_avs.lng MOD - [2012.12.09 21:09:04 | 000,056,320 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_local.lng MOD - [2012.12.09 21:09:04 | 000,047,616 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_disc.lng MOD - [2012.12.09 21:09:04 | 000,047,104 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_pmp.lng MOD - [2012.12.09 21:09:04 | 000,039,424 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_wifi.lng MOD - [2012.12.09 21:09:04 | 000,036,864 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_ipod.lng MOD - [2012.12.09 21:09:04 | 000,036,352 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ombrowser.lng MOD - [2012.12.09 21:09:04 | 000,034,816 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_plg.lng MOD - [2012.12.09 21:09:04 | 000,023,040 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_mp3.lng MOD - [2012.12.09 21:09:04 | 000,020,480 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_android.lng MOD - [2012.12.09 21:09:04 | 000,020,480 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_midi.lng MOD - [2012.12.09 21:09:04 | 000,018,944 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_mod.lng MOD - [2012.12.09 21:09:04 | 000,016,384 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\out_ds.lng MOD - [2012.12.09 21:09:04 | 000,015,360 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_wm.lng MOD - [2012.12.09 21:09:04 | 000,014,848 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_wire.lng MOD - [2012.12.09 21:09:04 | 000,014,336 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_online.lng MOD - [2012.12.09 21:09:04 | 000,012,800 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_playlists.lng MOD - [2012.12.09 21:09:04 | 000,011,776 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_usb.lng MOD - [2012.12.09 21:09:04 | 000,011,776 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_nsv.lng MOD - [2012.12.09 21:09:04 | 000,011,264 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_vorbis.lng MOD - [2012.12.09 21:09:04 | 000,009,728 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_downloads.lng MOD - [2012.12.09 21:09:04 | 000,008,704 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_history.lng MOD - [2012.12.09 21:09:04 | 000,008,704 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_devices.lng MOD - [2012.12.09 21:09:04 | 000,008,192 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_transcode.lng MOD - [2012.12.09 21:09:04 | 000,007,680 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\out_wave.lng MOD - [2012.12.09 21:09:04 | 000,006,656 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_autotag.lng MOD - [2012.12.09 21:09:04 | 000,006,656 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_wav.lng MOD - [2012.12.09 21:09:04 | 000,006,656 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_dshow.lng MOD - [2012.12.09 21:09:04 | 000,006,144 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\tagz.lng MOD - [2012.12.09 21:09:04 | 000,006,144 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\out_disk.lng MOD - [2012.12.09 21:09:04 | 000,005,632 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_wave.lng MOD - [2012.12.09 21:09:04 | 000,005,632 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_flac.lng MOD - [2012.12.09 21:09:04 | 000,005,120 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_rg.lng MOD - [2012.12.09 21:09:04 | 000,005,120 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_impex.lng MOD - [2012.12.09 21:09:04 | 000,005,120 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_bookmarks.lng MOD - [2012.12.09 21:09:04 | 000,005,120 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_mp4.lng MOD - [2012.12.09 21:09:04 | 000,004,608 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_activesync.lng MOD - [2012.12.09 21:09:04 | 000,004,608 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_enqplay.lng MOD - [2012.12.09 21:09:04 | 000,004,608 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_wv.lng MOD - [2012.12.09 21:09:04 | 000,004,608 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_mkv.lng MOD - [2012.12.09 21:09:04 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_p4s.lng MOD - [2012.12.09 21:09:04 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_orb.lng MOD - [2012.12.09 21:09:04 | 000,003,584 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\pmp_njb.lng MOD - [2012.12.09 21:09:04 | 000,003,584 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_nowplaying.lng MOD - [2012.12.09 21:09:04 | 000,003,584 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\ml_addons.lng MOD - [2012.12.09 21:09:04 | 000,003,584 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_swf.lng MOD - [2012.12.09 21:09:04 | 000,003,584 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_linein.lng MOD - [2012.12.09 21:09:04 | 000,003,584 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_flv.lng MOD - [2012.12.09 21:09:04 | 000,003,072 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\playlist.lng MOD - [2012.12.09 21:09:03 | 000,069,120 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\burnlib.lng MOD - [2012.12.09 21:09:03 | 000,041,984 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_jumpex_original.lng MOD - [2012.12.09 21:09:03 | 000,041,984 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_jumpex.lng MOD - [2012.12.09 21:09:03 | 000,023,552 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_classicart.lng MOD - [2012.12.09 21:09:03 | 000,023,040 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_ff.lng MOD - [2012.12.09 21:09:03 | 000,021,504 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_ml.lng MOD - [2012.12.09 21:09:03 | 000,014,848 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_play_remove.lng MOD - [2012.12.09 21:09:03 | 000,014,336 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_cdda.lng MOD - [2012.12.09 21:09:03 | 000,013,824 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\dsp_sps.lng MOD - [2012.12.09 21:09:03 | 000,011,776 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_skinmanager.lng MOD - [2012.12.09 21:09:03 | 000,011,776 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_hotkeys.lng MOD - [2012.12.09 21:09:03 | 000,010,752 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_undo.lng MOD - [2012.12.09 21:09:03 | 000,010,752 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\auth.lng MOD - [2012.12.09 21:09:03 | 000,010,240 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_timerestore.lng MOD - [2012.12.09 21:09:03 | 000,009,728 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_nopro.lng MOD - [2012.12.09 21:09:03 | 000,008,192 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_tray.lng MOD - [2012.12.09 21:09:03 | 000,007,168 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_orgler.lng MOD - [2012.12.09 21:09:03 | 000,007,168 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_crasher.lng MOD - [2012.12.09 21:09:03 | 000,006,656 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\enc_fhgaac.lng MOD - [2012.12.09 21:09:03 | 000,006,144 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\enc_wma.lng MOD - [2012.12.09 21:09:03 | 000,005,632 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\enc_lame.lng MOD - [2012.12.09 21:09:03 | 000,005,120 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\in_avi.lng MOD - [2012.12.09 21:09:03 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\gen_find_on_disk.lng MOD - [2012.12.09 21:09:03 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\enc_wav.lng MOD - [2012.12.09 21:09:03 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\enc_vorbis.lng MOD - [2012.12.09 21:09:03 | 000,004,096 | ---- | M] () -- C:\Users\SMOKIN~1\AppData\Local\Temp\WLZ6DA.tmp\enc_flac.lng MOD - [2012.12.05 16:29:25 | 002,397,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012.11.14 19:54:09 | 014,586,808 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll MOD - [2012.11.01 18:57:10 | 000,100,248 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll MOD - [2012.11.01 18:56:20 | 001,263,512 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe MOD - [2012.10.02 19:43:19 | 000,015,848 | ---- | M] () -- C:\Program Files (x86)\Java\jre7\bin\jp2native.dll MOD - [2012.10.02 18:02:25 | 000,091,136 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\xml.w5s MOD - [2012.10.02 18:02:25 | 000,083,968 | ---- | M] () -- C:\Program Files (x86)\Winamp\tataki.dll MOD - [2012.10.02 18:02:25 | 000,064,512 | ---- | M] () -- C:\Program Files (x86)\Winamp\zlib.dll MOD - [2012.10.02 18:02:24 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\timer.w5s MOD - [2012.10.02 18:02:24 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\tagz.w5s MOD - [2012.10.02 18:02:23 | 000,623,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jnetlib.w5s MOD - [2012.10.02 18:02:23 | 000,154,624 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jpeg.w5s MOD - [2012.10.02 18:02:23 | 000,087,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\png.w5s MOD - [2012.10.02 18:02:23 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\playlist.w5s MOD - [2012.10.02 18:02:23 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\devices.w5s MOD - [2012.10.02 18:02:23 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gif.w5s MOD - [2012.10.02 18:02:23 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\bmp.w5s MOD - [2012.10.02 18:02:23 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\dlmgr.w5s MOD - [2012.10.02 18:02:23 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gracenote.w5s MOD - [2012.10.02 18:02:23 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\filereader.w5s MOD - [2012.10.02 18:02:23 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\primo.w5s MOD - [2012.10.02 18:02:22 | 000,174,080 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\auth.w5s MOD - [2012.10.02 18:02:22 | 000,113,664 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_wifi.dll MOD - [2012.10.02 18:02:22 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\albumart.w5s MOD - [2012.10.02 18:02:21 | 000,118,272 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_p4s.dll MOD - [2012.10.02 18:02:21 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_usb.dll MOD - [2012.10.02 18:02:21 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_njb.dll MOD - [2012.10.02 18:02:20 | 000,294,912 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_local.dll MOD - [2012.10.02 18:02:20 | 000,240,640 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll MOD - [2012.10.02 18:02:20 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll MOD - [2012.10.02 18:02:20 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll MOD - [2012.10.02 18:02:20 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_android.dll MOD - [2012.10.02 18:02:20 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_impex.dll MOD - [2012.10.02 18:02:20 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_ds.dll MOD - [2012.10.02 18:02:20 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_history.dll MOD - [2012.10.02 18:02:20 | 000,033,792 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll MOD - [2012.10.02 18:02:20 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll MOD - [2012.10.02 18:02:20 | 000,022,528 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_disk.dll MOD - [2012.10.02 18:02:20 | 000,018,432 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_wave.dll MOD - [2012.10.02 18:02:19 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wm.dll MOD - [2012.10.02 18:02:19 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll MOD - [2012.10.02 18:02:19 | 000,249,856 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll MOD - [2012.10.02 18:02:19 | 000,201,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_disc.dll MOD - [2012.10.02 18:02:19 | 000,075,264 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll MOD - [2012.10.02 18:02:19 | 000,052,736 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll MOD - [2012.10.02 18:02:19 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_bookmarks.dll MOD - [2012.10.02 18:02:19 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll MOD - [2012.10.02 18:02:19 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_swf.dll MOD - [2012.10.02 18:02:19 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wave.dll MOD - [2012.10.02 18:02:18 | 000,290,816 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll MOD - [2012.10.02 18:02:18 | 000,164,864 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mod.dll MOD - [2012.10.02 18:02:18 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_midi.dll MOD - [2012.10.02 18:02:18 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll MOD - [2012.10.02 18:02:17 | 001,737,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll MOD - [2012.10.02 18:02:17 | 000,340,992 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac MOD - [2012.10.02 18:02:17 | 000,318,976 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll MOD - [2012.10.02 18:02:17 | 000,185,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll MOD - [2012.10.02 18:02:17 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll MOD - [2012.10.02 18:02:17 | 000,072,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll MOD - [2012.10.02 18:02:17 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_avi.dll MOD - [2012.10.02 18:02:17 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flac.dll MOD - [2012.10.02 18:02:17 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flv.dll MOD - [2012.10.02 18:02:17 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll MOD - [2012.10.02 18:02:17 | 000,025,600 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll MOD - [2012.10.02 18:02:17 | 000,007,168 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_linein.dll MOD - [2012.10.02 18:02:15 | 000,417,280 | ---- | M] () -- C:\Program Files (x86)\Winamp\nsutil.dll MOD - [2012.10.02 18:02:15 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\libsndfile.dll MOD - [2012.10.02 18:02:15 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\Winamp\nde.dll MOD - [2010.10.27 20:23:04 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll MOD - [2010.10.27 20:22:52 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Last.fm\ext_messengernotify.dll MOD - [2010.10.27 20:22:42 | 000,058,880 | ---- | M] () -- C:\Program Files (x86)\Last.fm\ext_skypenotify.dll MOD - [2010.10.27 20:22:08 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\Last.fm\srv_madtranscode.dll MOD - [2010.10.27 20:22:00 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Last.fm\srv_httpinput.dll MOD - [2010.10.27 20:19:28 | 000,372,736 | ---- | M] () -- C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll MOD - [2010.10.27 20:19:06 | 000,025,088 | ---- | M] () -- C:\Program Files (x86)\Last.fm\breakpad.dll MOD - [2010.10.27 20:18:50 | 000,180,224 | ---- | M] () -- C:\Program Files (x86)\Last.fm\Moose1.dll MOD - [2010.10.27 20:18:34 | 000,540,672 | ---- | M] () -- C:\Program Files (x86)\Last.fm\LastFmTools1.dll MOD - [2010.10.27 20:13:52 | 001,382,507 | ---- | M] () -- C:\Program Files (x86)\Last.fm\libfftw3f-3.dll MOD - [2010.10.27 20:13:52 | 000,074,240 | ---- | M] () -- C:\Program Files (x86)\Last.fm\zlibwapi.dll MOD - [2008.04.16 16:42:30 | 000,376,832 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtNetwork4.dll MOD - [2008.04.16 16:42:16 | 000,524,288 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtSql4.dll MOD - [2008.04.16 16:42:02 | 006,701,056 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtGui4.dll MOD - [2008.04.16 16:36:38 | 000,376,832 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtXml4.dll MOD - [2008.04.16 16:36:34 | 001,654,784 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtCore4.dll MOD - [2008.04.02 13:26:50 | 000,233,472 | ---- | M] () -- C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll MOD - [2008.04.02 13:26:34 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll MOD - [2008.04.02 13:26:28 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll ========== Services (SafeList) ========== SRV - [2012.12.05 16:29:38 | 000,115,168 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.11.14 19:54:11 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012.09.24 13:46:16 | 001,328,736 | ---- | M] (Secunia) [Disabled | Stopped] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent) SRV - [2012.09.24 13:46:16 | 000,656,480 | ---- | M] (Secunia) [Disabled | Stopped] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent) SRV - [2012.09.12 20:21:48 | 000,368,896 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2012.09.12 20:21:48 | 000,022,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.07.17 14:14:44 | 002,292,480 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2012.07.13 15:27:00 | 000,769,432 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2012.07.11 19:54:58 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Programme\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE) SRV - [2011.06.14 09:31:06 | 000,498,688 | ---- | M] (Red Bend Ltd.) [Disabled | Stopped] -- C:\Programme\Intel\WiMAX\Bin\DMAgent.exe -- (DMAgent) SRV - [2011.06.14 09:26:20 | 000,986,112 | ---- | M] (Intel(R) Corporation) [Disabled | Stopped] -- C:\Programme\Intel\WiMAX\Bin\AppSrv.exe -- (WiMAXAppSrv) SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.08.30 21:03:48 | 000,128,456 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011.12.16 15:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI) DRV:64bit: - [2011.05.23 23:24:22 | 002,750,464 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:64bit: - [2011.05.19 12:25:00 | 000,084,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpenum.sys -- (bpenum) DRV:64bit: - [2011.05.05 19:32:56 | 001,439,792 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:64bit: - [2011.04.10 10:51:06 | 012,223,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010.11.21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010.11.21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2010.11.05 22:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2010.10.19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010.10.15 00:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) DRV:64bit: - [2010.08.24 16:55:44 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2008.05.23 16:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr) DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV) DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CC 88 C2 38 B0 A0 CD 01 [binary data] IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&k=0 IE - HKCU\..\SearchScopes\{28413F52-C3C2-46DB-B1CB-368141F6C2FF}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&mode=bounce&k=0 IE - HKCU\..\SearchScopes\{3F751673-DDA5-4D1E-B8DC-3468E47EA37F}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&mode=bounce&k=0 IE - HKCU\..\SearchScopes\{4623BECF-5FAB-4FED-8378-F2CAA48B6FCE}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&mode=bounce&k=0 IE - HKCU\..\SearchScopes\{85BF947F-DD9F-4C9E-B0D6-73AA3A22E83D}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&mode=bounce&k=0 IE - HKCU\..\SearchScopes\{8E02FD86-005F-44A7-BBB8-BF74A430A7AB}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&mode=bounce&k=0 IE - HKCU\..\SearchScopes\{DF4FDD1E-FDAC-4A22-BB8B-EFE3D030728C}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=d0f5499a-49a6-4941-be1e-ad6f0ab4a4e7&pid=murb&mode=bounce&k=0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "https://www.google.de/" FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20120926 FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.3 FF - prefs.js..extensions.enabledAddons: firejump%40firejump.net:1.0.2.5 FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:2.1.2.145 FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.3 FF - prefs.js..extensions.enabledAddons: info%40djzig.com:2.0.7 FF - prefs.js..network.proxy.http: "127.0.0.1" FF - prefs.js..network.proxy.http_port: 445 FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.12.03 01:25:50 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.12.05 16:29:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.10 19:01:45 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.12.03 17:38:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\smoking caterpillar\AppData\Roaming\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\firejump@firejump.net [2012.10.02 17:32:43 | 000,000,000 | ---D | M] [2012.10.02 16:14:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Extensions [2012.12.04 21:35:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\smf00mp5.default\extensions [2012.10.02 16:49:22 | 000,000,000 | ---D | M] (WOT) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\smf00mp5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2012.10.02 17:32:43 | 000,000,000 | ---D | M] (FireJump) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\smf00mp5.default\extensions\firejump@firejump.net [2012.11.30 05:45:00 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\smf00mp5.default\extensions\ich@maltegoetz.de [2012.10.15 13:04:44 | 000,000,000 | ---D | M] (LavaFox V2) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\smf00mp5.default\extensions\info@djzig.com [2012.10.16 22:13:17 | 000,000,000 | ---D | M] (LavaFox V2-Purple) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\smf00mp5.default\extensions\zigboom555@aol.com [2012.12.08 20:36:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\Profiles\ugu86ww1.default\extensions [2012.12.04 21:35:01 | 000,531,070 | ---- | M] () (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012.11.23 19:43:30 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012.10.02 17:32:27 | 000,001,864 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\searchplugins\{A4740E45-325C-4AC2-824F-15A8F100B9C3}.xml [2012.10.02 17:32:27 | 000,002,182 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\searchplugins\{A7EFC2A1-06B4-4121-AC5B-74D98DD39363}.xml [2012.10.02 17:32:27 | 000,002,071 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\searchplugins\{E2CF1BBF-F6D0-4886-9673-A16BA6F28D52}.xml [2012.12.08 20:36:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012.12.03 01:25:50 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 [2012.12.05 16:29:38 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.06.20 17:14:20 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2012.10.02 17:32:27 | 000,001,678 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.10.02 17:32:27 | 000,001,929 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.10.02 17:32:27 | 000,001,265 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.10.02 17:32:27 | 000,007,045 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.10.02 17:32:27 | 000,001,272 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.10.02 17:32:27 | 000,001,164 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.) O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: Mit Mipony herunterladen - C:\Program Files (x86)\MiPony\Browser\IEContext.htm () O8 - Extra context menu item: Mit Mipony herunterladen - C:\Program Files (x86)\MiPony\Browser\IEContext.htm () O9 - Extra Button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe (ICQ, LLC.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0299957A-77CA-4F97-9FCA-D730104978D9}: DhcpNameServer = 192.168.178.1 O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.12.09 02:18:27 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Documents\Family [2012.12.08 23:54:42 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2012.12.08 21:10:08 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012.12.08 21:10:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2012.12.08 20:57:59 | 000,406,528 | R--- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012.12.08 20:47:41 | 000,000,000 | ---D | C] -- C:\Qoobox [2012.12.08 20:47:27 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2012.12.08 20:41:14 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2012.12.08 20:41:05 | 000,000,000 | ---D | C] -- C:\JRT [2012.12.08 20:35:10 | 005,010,414 | R--- | C] (Swearware) -- C:\Users\smoking caterpillar\Desktop\ComboFix.exe [2012.12.08 20:34:52 | 000,447,007 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\smoking caterpillar\Desktop\JRT.exe [2012.12.08 13:36:17 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\smoking caterpillar\Desktop\tdsskiller.exe [2012.12.08 13:36:06 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Users\smoking caterpillar\Desktop\aswMBR.exe [2012.12.08 13:35:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\smoking caterpillar\Desktop\OTL.exe [2012.12.05 02:12:49 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Documents\HeroBlade Logs [2012.12.04 17:15:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts [2012.12.04 17:15:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BioWare [2012.12.03 01:28:21 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\DDMSettings [2012.12.03 01:25:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus [2012.12.03 01:25:19 | 000,000,000 | ---D | C] -- C:\Program Files\DivX [2012.12.03 01:25:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared [2012.12.03 01:24:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX [2012.12.03 01:23:37 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX [2012.11.27 03:00:08 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\.thumbnails [2012.11.27 02:58:33 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\fontconfig [2012.11.27 02:58:31 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\gegl-0.2 [2012.11.27 02:58:31 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\.gimp-2.8 [2012.11.27 02:56:53 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP 2 [2012.11.23 23:27:27 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2012.11.22 21:50:07 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer [2012.11.15 19:13:52 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Documents\Mipony [2012.11.15 19:11:09 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Mipony [2012.11.15 19:10:54 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiPony [2012.11.15 19:10:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony [2012.11.15 19:10:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MiPony [2012.11.15 17:29:23 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Documents\Calibre Bibliothek [2012.11.15 17:29:22 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\calibre [2012.11.15 17:28:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Calibre2 [2012.11.15 17:28:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management [2012.11.15 16:30:46 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Documents\Star Wars [2012.11.14 19:37:58 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\ElevatedDiagnostics [2012.11.13 21:29:04 | 000,354,216 | ---- | C] (DivX, Inc.) -- C:\Windows\SysWow64\DivXControlPanelApplet.cpl ========== Files - Modified Within 30 Days ========== [2012.12.09 21:24:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.12.09 14:20:28 | 000,022,512 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.12.09 14:20:28 | 000,022,512 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.12.09 14:19:39 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012.12.09 14:19:39 | 000,654,166 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012.12.09 14:19:39 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012.12.09 14:19:39 | 000,130,006 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012.12.09 14:19:39 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012.12.09 14:13:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.12.09 14:12:59 | 3145,826,304 | -HS- | M] () -- C:\hiberfil.sys [2012.12.09 05:09:17 | 000,022,666 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Local\recently-used.xbel [2012.12.09 05:03:45 | 000,193,191 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\schriftrolle-klein-1.png [2012.12.09 05:01:26 | 000,050,999 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\custom_order_jedi_logo_by_dakinquelia-d4vb642.png [2012.12.09 04:59:14 | 000,053,586 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\steamjedi_logo_by_gardek-d3b3zy9.png [2012.12.08 20:35:22 | 005,010,414 | R--- | M] (Swearware) -- C:\Users\smoking caterpillar\Desktop\ComboFix.exe [2012.12.08 20:34:58 | 000,447,007 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\smoking caterpillar\Desktop\JRT.exe [2012.12.08 20:34:40 | 000,540,743 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\adwcleaner.exe [2012.12.08 15:06:32 | 000,000,512 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\MBR.dat [2012.12.08 15:04:27 | 000,000,000 | ---- | M] () -- C:\Users\smoking caterpillar\defogger_reenable [2012.12.08 13:36:38 | 004,732,416 | ---- | M] (AVAST Software) -- C:\Users\smoking caterpillar\Desktop\aswMBR.exe [2012.12.08 13:36:19 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\smoking caterpillar\Desktop\tdsskiller.exe [2012.12.08 13:35:49 | 000,050,477 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\Defogger.exe [2012.12.08 13:35:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\smoking caterpillar\Desktop\OTL.exe [2012.11.27 16:16:12 | 000,271,096 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012.11.23 23:27:17 | 3286,211,295 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012.11.13 21:29:04 | 000,354,216 | ---- | M] (DivX, Inc.) -- C:\Windows\SysWow64\DivXControlPanelApplet.cpl ========== Files Created - No Company Name ========== [2012.12.09 05:09:17 | 000,022,666 | ---- | C] () -- C:\Users\smoking caterpillar\AppData\Local\recently-used.xbel [2012.12.09 05:03:45 | 000,193,191 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\schriftrolle-klein-1.png [2012.12.09 04:59:13 | 000,053,586 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\steamjedi_logo_by_gardek-d3b3zy9.png [2012.12.09 04:58:40 | 000,050,999 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\custom_order_jedi_logo_by_dakinquelia-d4vb642.png [2012.12.09 01:50:11 | 006,632,662 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\03-everything_ft._epilogue.mp3 [2012.12.09 01:50:11 | 006,121,782 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\11-moment_2008.mp3 [2012.12.09 01:50:11 | 006,024,447 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\04-falling_for.mp3 [2012.12.09 01:50:11 | 005,338,210 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\08-through_your_eyes.mp3 [2012.12.09 01:50:11 | 005,336,604 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\09-sky_and_sea.mp3 [2012.12.09 01:50:11 | 005,256,905 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\05-like_new_mix.mp3 [2012.12.09 01:50:10 | 006,714,027 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\01-calling_all_stations.mp3 [2012.12.09 01:50:10 | 005,537,376 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\02-stars.mp3 [2012.12.09 01:48:40 | 002,822,334 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\10 - Acoustic #3.mp3 [2012.12.09 01:36:24 | 002,801,657 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Thomas Newman - Homecoming (Brothers OST).mp3 [2012.12.09 01:35:56 | 004,763,393 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\The Perishers - Weekends.mp3 [2012.12.09 01:34:49 | 003,296,308 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Joshua Radin - Winter.mp3 [2012.12.09 01:34:24 | 007,012,178 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Clint Mansell Peter Broderick Not At Home (Last Night OST).mp3 [2012.12.08 21:10:08 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012.12.08 21:10:08 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012.12.08 21:10:08 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012.12.08 21:10:08 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012.12.08 21:10:08 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012.12.08 20:34:33 | 000,540,743 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\adwcleaner.exe [2012.12.08 15:06:32 | 000,000,512 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\MBR.dat [2012.12.08 15:04:27 | 000,000,000 | ---- | C] () -- C:\Users\smoking caterpillar\defogger_reenable [2012.12.08 13:35:49 | 000,050,477 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Defogger.exe [2012.12.03 17:38:42 | 000,002,098 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk [2012.11.27 02:57:55 | 000,000,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk [2012.11.23 23:27:17 | 3286,211,295 | ---- | C] () -- C:\Windows\MEMORY.DMP [2012.11.16 16:26:49 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012.11.16 16:19:24 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012.10.03 23:02:59 | 001,526,948 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012.10.02 17:32:34 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll [2012.10.01 23:32:21 | 000,003,584 | ---- | C] () -- C:\Users\smoking caterpillar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.05.05 19:30:46 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll [2011.04.10 10:49:08 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2011.04.10 10:49:08 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2011.04.10 10:49:08 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2011.04.10 10:42:48 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2011.04.10 10:18:22 | 013,356,032 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.10.27 03:07:55 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\AnvSoft [2012.10.27 23:37:20 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Audacity [2012.11.15 23:32:33 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\calibre [2012.10.26 21:31:04 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DeepBurner [2012.11.10 02:40:53 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DesktopIconForAmazon [2012.11.09 19:36:51 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\GetRight [2012.12.09 20:58:07 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ICQ [2012.11.15 21:47:46 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Mipony [2012.10.02 17:32:24 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\OCS [2012.10.02 17:32:27 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Opera [2012.10.02 19:10:07 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Sinvise Systems [2012.11.22 22:02:01 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer [2012.10.06 20:48:15 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Thunderbird [2012.10.24 03:12:11 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\TS3Client [2012.10.02 18:45:36 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\TuneUp Software ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:661DFA1C < End of report > |
09.12.2012, 22:24 | #10 |
/// TB-Ausbilder | Claro Search entfernen?! Servus, na das hört sich doch schon gut an. Wir führen noch ein paar Kontrollen durch. Schritt 1 Fixen mit OTL
Code:
ATTFilter :OTL [2012.10.02 17:32:27 | 000,001,864 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\searchplugins\{A4740E45-325C-4AC2-824F-15A8F100B9C3}.xml [2012.10.02 17:32:27 | 000,002,182 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\searchplugins\{A7EFC2A1-06B4-4121-AC5B-74D98DD39363}.xml [2012.10.02 17:32:27 | 000,002,071 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\firefox\profiles\smf00mp5.default\searchplugins\{E2CF1BBF-F6D0-4886-9673-A16BA6F28D52}.xml @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:661DFA1C :Commands [emptytemp]
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck
Bitte poste mit deiner nächsten Antwort
|
10.12.2012, 01:25 | #11 |
| Claro Search entfernen?! Alles nach Anleitung durchgeführt. Log-Dateien sind im Anhang. |
10.12.2012, 16:41 | #12 |
/// TB-Ausbilder | Claro Search entfernen?! Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Schritt 2 Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software / Programme deinstallieren--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Hacken für den McAfee SecurityScan bzw. Google Chrome. Schritt 3 Starte DeFogger und klicke auf Re-enable. Gegebenenfalls muss dein Rechner neu gestartet werden. Schritt 4 Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren. Windows-Taste + R drücke. Kopiere nun folgende Zeile in die Kommandozeile und klicke OK. Code:
ATTFilter Combofix /Uninstall Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch aus dieser die Schädlinge verschwinden. Nun die eben deaktivierten Programme wieder aktivieren. Schritt 5 Downloade dir bitte delfix auf deinen Desktop.
Schritt 6 Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
10.12.2012, 19:42 | #13 |
| Claro Search entfernen?! So, ich habe soweit die Liste abgearbeitet. Zu den Fragen/Problemen: Die älteren Java Installationen konnte ich nicht deinstallieren, da ich sie nicht gefunden habe. Unter Programme Deinstallieren finde ich auch nur die aktuellste Version, die ich eben runtergeladen habe?! Ich habe alles bis auf MVPs hosts file heruntergeladen. Irgendwie konnt ich mich nicht durch das Tutorial durchquelen, da mein Englisch nicht wirklich top ist. Würdest du es denn dringendst empfehlen? Ich habe eben das Programm SUPERAntiSpyware durchlaufen lassen, und der hat satte 22 Gefahren gefunden. Ist es normal, dass der soviel findet, obwohl ich mit dir meinen Rechner quasi reingewaschen habe?! Ich zeig dir mal den Log, würde gerne wissen was du dazu sagst. Log Code:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 12/10/2012 at 07:35 PM Application Version : 5.6.1014 Core Rules Database Version : 9631 Trace Rules Database Version: 7443 Scan type : Complete Scan Total Scan Time : 00:32:38 Operating System Information Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601) UAC On - Limited User Memory items scanned : 534 Memory threats detected : 0 Registry items scanned : 71919 Registry threats detected : 0 File items scanned : 42933 File threats detected : 22 Adware.Tracking Cookie C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\A5GDCMSS.txt [ /serving-sys.com ] C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\TVHI5K3R.txt [ /mediaplex.com ] C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\ZGT8235B.txt [ /ad4.adfarm1.adition.com ] C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\3URIKG3U.txt [ /doubleclick.net ] C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\201X8O1N.txt [ /adfarm1.adition.com ] C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\DNO2RFD8.txt [ /ad2.adfarm1.adition.com ] C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Cookies\7IMF7XJX.txt [ /apmebf.com ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\WZQGDMHE.txt [ Cookie:smoking caterpillar@c.atdmt.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\4JHET8QX.txt [ Cookie:smoking caterpillar@serving-sys.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\V7TPIHZL.txt [ Cookie:smoking caterpillar@invitemedia.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\TC2Y2VTN.txt [ Cookie:smoking caterpillar@atdmt.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\5LM8NUPE.txt [ Cookie:smoking caterpillar@adfarm1.adition.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\6IO0KA1U.txt [ Cookie:smoking caterpillar@adtech.de/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\77P6AJMW.txt [ Cookie:smoking caterpillar@xiti.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\K0RJC5JS.txt [ Cookie:smoking caterpillar@specificclick.net/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\TG1TC4ME.txt [ Cookie:smoking caterpillar@www.etracker.de/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\XP3CJW9F.txt [ Cookie:smoking caterpillar@adbrite.com/ ] C:\USERS\SMOKING CATERPILLAR\AppData\Roaming\Microsoft\Windows\Cookies\Low\2B3GW3QH.txt [ Cookie:smoking caterpillar@ad.yieldmanager.com/ ] C:\USERS\SMOKING CATERPILLAR\Cookies\A5GDCMSS.txt [ Cookie:smoking caterpillar@serving-sys.com/ ] C:\USERS\SMOKING CATERPILLAR\Cookies\TVHI5K3R.txt [ Cookie:smoking caterpillar@mediaplex.com/ ] C:\USERS\SMOKING CATERPILLAR\Cookies\201X8O1N.txt [ Cookie:smoking caterpillar@adfarm1.adition.com/ ] C:\USERS\SMOKING CATERPILLAR\Cookies\7IMF7XJX.txt [ Cookie:smoking caterpillar@apmebf.com/ ] |
10.12.2012, 20:07 | #14 |
/// TB-Ausbilder | Claro Search entfernen?! Servus, dann passt das mit Java schon. "MVPs hosts file" kann den Schutz erhöhen, aber zwingend brauchst du es nicht. SuperAntiSpyware hat nur Cookies gefunden. Dabei handelt es sich um ungefährliche Textdateien. Im "schlimmsten" Fall kann damit dein Surfverhalten beobachtet werden. Einen Schaden am PC können diese Dateien nicht anrichten. Ich bin froh, dass wir helfen konnten Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
10.12.2012, 20:20 | #15 |
| Claro Search entfernen?! Okay.^^ Ja, alles perfekt. Vielen vielen Dank!! |
Themen zu Claro Search entfernen?! |
andere, angst, claro, claro search, deinstalliere, deinstallieren, entferne, entfernen, firefox, infect, krieg, liste, programme, search, stört |