|
Plagegeister aller Art und deren Bekämpfung: GVU Fragezeichen?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.03.2013, 17:28 | #1 |
| GVU Fragezeichen? Guten Abend. Ich habe folgendes Problem. Seit heute öffnet sich ein Fenster nach dem Booten dass ich auf herkömmlicherweise nicht schließen kann. Ähnlich wie beim GVU. Man kann allerdings über den Taskmanager die betroffene exe beenden (cvaetzwc.exe) und somit das Fenster schließen. Zu Beginn war auch noch die vom GVU bekannte wpbt0.dll im Manager, aber die ist irgendwie verschwunden. Ich seh auch im Process Explorer welcher Prozess dieses Fenster startet. Ich hab nun Malwarebytes durchlaufenlassen und die cvaetzwc.exe gefunden sowie eine Abwandlung von ihr in der Reg, als auch die wpbt0.dll Ich hab nur keinen Plan was ich machen soll... Malwarebytes Anti-Malware 1.70.0.1100 Malwarebytes : Free Anti-Malware download Datenbank Version: v2013.03.09.07 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 09.03.2013 16:06:11 mbam-log-2013-03-09 (16-06-11).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 445557 Laufzeit: 44 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|cvaetzwcgsogagn (Trojan.EOFail) -> Daten: C:\ProgramData\cvaetzwc.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 5 C:\ProgramData\cvaetzwc.exe (Trojan.EOFail) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\geraldo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HG1417VS\Prv[1].bin (Trojan.EOFail) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\geraldo\AppData\Local\Temp\wpbt0.dll (Trojan.EOFail) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
10.03.2013, 13:44 | #2 |
/// TB-Ausbilder | GVU Fragezeichen?Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
So geht es weiter: Schritt 1 Downloade dir bitte DDS ( von sUBs ) von einem der folgenden Downloadspiegel und speichere die Datei auf deinem Desktop. dds.com dds.exe
Schritt 2 Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Schritt 3 Bitte lade dir GMER herunter: (Dateiname zufällig)
Tauchen Probleme auf?
Bitte poste mit deiner nächsten Antwort
|
10.03.2013, 15:25 | #3 |
| GVU Fragezeichen? OK, hab jetzt alles gemacht. Nur ein Problem: Ich konnte die Logdatei von GMER nicht so speichern wie beschrieben. Also auf Save klicken hat nichts bewirkt obwohl ich alles befolgt habe, habs auch im Abgesicherten Modus versucht, schlussendlich habe ich Copy und dann in ein Wordpad gespeichert, hoffentlich kommt das aufs selbe...
__________________DDS DDS Logfile: Code:
ATTFilter DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.10.2 Run at 14:06:06 on 2013-03-10 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8105.6819 [GMT 1:00] . AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF} AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe C:\Program Files\Common Files\WireHelpSvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxpers.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\rundll32.exe C:\Program Files (x86)\XFastUsb\XFastUsb.exe C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe C:\Program Files (x86)\A1\A1 Diagnose\A1Diagnose.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/?affID=113480&babsrc=HP_ss&mntrId=fe956921000000000000002522c22eef uURLSearchHooks: SearchHook Class: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll mWinlogon: Userinit = userinit.exe BHO: SmartView VisualBookmark: {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\DeviceVM\SmartView\SmartView.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ips\ipsbho.dll BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coieplg.dll uRun: [ASRockXTU] <no file> mRun: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe /StartRunKey mRun: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r mRun: [UpdReg] C:\Windows\UpdReg.EXE mRun: [SmartViewAgent] "C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml mRun: [A1Diagnose] C:\Program Files (x86)\A1\A1 Diagnose\A1Diagnose.exe /auto mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" StartupFolder: C:\Users\geraldo\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: NameServer = 10.0.0.138 TCP: Interfaces\{22BED806-6C8D-45B6-97C9-D8B6C312695D} : DHCPNameServer = 10.0.0.138 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll SSODL: WebCheck - <orphaned> IFEO: taskmgr.exe - "C:\USERS\GERALDO\APPDATA\LOCAL\TEMP\RAR$EXA0.997\PROCEXP.EXE" x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - <orphaned> x64-IFEO: taskmgr.exe - "C:\USERS\GERALDO\APPDATA\LOCAL\TEMP\RAR$EXA0.997\PROCEXP.EXE" . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\ FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-02-24 11:38; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF - ExtSQL: 2013-02-24 11:38; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn FF - ExtSQL: 2013-02-24 13:25; exif_viewer@mozilla.doslash.org; C:\Users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1207020.003\symds64.sys [2012-7-9 450680] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1207020.003\symefa64.sys [2012-7-9 912504] R1 AsrAppCharger;AsrAppCharger;C:\Windows\System32\drivers\AsrAppCharger.sys [2012-7-6 15368] R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2012-10-11 27800] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120823.007\BHDrvx64.sys [2012-9-1 1161376] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-12-2 283200] R1 FNETURPX;FNETURPX;C:\Windows\System32\drivers\FNETURPX.SYS [2012-7-6 15936] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120831.001\IDSviA64.sys [2012-9-1 512672] R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1207020.003\ironx64.sys [2012-7-9 171128] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1207020.003\symnets.sys [2012-7-9 386168] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-6-11 239616] R2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-10-11 86752] R2 AntiVirService;Avira Echtzeit-Scanner;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-10-11 110816] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2012-10-11 99912] R2 ESLWireAC;ESLWireAC;C:\Windows\System32\drivers\ESLWireACD.sys [2012-7-6 147472] R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2012-9-5 6364024] R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe [2012-7-9 130008] R2 SmartViewService;SmartView service;C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [2010-9-2 125216] R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-6 2656280] R2 WCUService;SmartView Software Updater Service;C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [2010-9-2 456976] R2 WireHelpSvc;WireHelpSvc;C:\Program Files\Common Files\WireHelpSvc.exe [2012-7-6 168864] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-2-23 95760] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-17 138912] R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2011-2-8 39936] R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2011-2-8 64512] R3 gbxavs;Maschine Midi;C:\Windows\System32\drivers\gbxavs.sys [2011-7-7 357968] R3 gbxusb_svc;Maschine Controller;C:\Windows\System32\drivers\gbxusb.sys [2011-7-7 68688] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-7-6 428136] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2012-7-6 79360] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-7-6 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-7-6 79360] S3 FNETTBOH_305;FNETTBOH_305;C:\Windows\System32\drivers\FNETTBOH_305.SYS [2012-7-21 31808] S3 gbxavs_x64;gbxavs_x64;C:\Windows\System32\drivers\gbxavs_x64.sys [2009-10-8 45136] S3 gbxusb_x64;gbxusb_x64;C:\Windows\System32\drivers\gbxusb_x64.sys [2009-10-8 300624] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] . =============== Created Last 30 ================ . 2013-03-09 15:04:23 344576 ----a-w- C:\Windows\System32\utilman.exe 2013-03-09 13:29:21 -------- d-----w- C:\ProgramData\Astroburn Lite 2013-03-09 13:29:21 -------- d-----w- C:\Program Files (x86)\Astroburn Lite 2013-03-09 11:08:51 -------- d-----w- C:\Users\geraldo\AppData\Roaming\Malwarebytes 2013-03-09 11:08:43 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys 2013-03-09 11:08:43 -------- d-----w- C:\ProgramData\Malwarebytes 2013-03-09 11:08:42 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-03-09 11:08:34 -------- d-----w- C:\Users\geraldo\AppData\Local\Programs 2013-03-08 23:06:50 -------- d-----w- C:\ProgramData\hikwhymogrxznoo 2013-02-24 12:51:54 -------- d-----w- C:\Users\geraldo\AppData\Local\Macromedia 2013-02-24 12:24:57 -------- d-----w- C:\Users\geraldo\AppData\Local\Mozilla 2013-02-24 12:23:03 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service 2013-02-17 12:52:30 -------- d-----w- C:\Users\geraldo\AppData\Local\Apple Computer 2013-02-17 12:52:00 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2013-02-17 12:51:32 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-17 12:51:32 -------- d-----w- C:\Program Files\iTunes 2013-02-17 12:51:32 -------- d-----w- C:\Program Files\iPod 2013-02-17 12:51:32 -------- d-----w- C:\Program Files (x86)\iTunes 2013-02-17 12:46:41 -------- d-----w- C:\Users\geraldo\AppData\Local\Apple 2013-02-17 12:46:19 -------- d-----w- C:\Program Files\Bonjour 2013-02-17 12:46:19 -------- d-----w- C:\Program Files (x86)\Bonjour . ==================== Find3M ==================== . 2013-01-03 13:59:24 95184 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-03 13:59:24 859072 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-01-03 13:59:24 779704 ----a-w- C:\Windows\SysWow64\deployJava1.dll 2013-01-03 13:56:50 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll 2013-01-03 13:56:49 959976 ----a-w- C:\Windows\System32\deployJava1.dll 2013-01-03 13:56:49 1081320 ----a-w- C:\Windows\System32\npDeployJava1.dll 2012-12-11 18:27:30 99912 ----a-w- C:\Windows\System32\drivers\avgntflt.sys 2012-07-03 14:41:12 168864 ----a-w- C:\Program Files\Common Files\WireHelpSvc.exe . ============= FINISH: 14:06:19,52 =============== defogger_disable.log Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 14:15 on 10/03/2013 (geraldo) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- GMER Logfile: Code:
ATTFilter GMER 2.1.19155 - hxxp://www.gmer.net Rootkit scan 2013-03-10 14:52:04 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 WDC_WD5000AAKX-001CA0 rev.15.01H15 465,76GB Running: b6j43ent.exe; Driver: C:\Users\geraldo\AppData\Local\Temp\pwtirfow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82 00000000737b17fa 2 bytes CALL 773a1199 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88 00000000737b1860 2 bytes CALL 773a1199 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98 00000000737b1942 2 bytes JMP 7720c29f C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109 00000000737b194d 2 bytes JMP 7720418d C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077cd1401 2 bytes JMP 773beb26 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077cd1419 2 bytes JMP 773cb513 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077cd1431 2 bytes JMP 77448609 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000077cd144a 2 bytes CALL 773a1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000077cd14dd 2 bytes JMP 77447efe C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000077cd14f5 2 bytes JMP 774480d8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000077cd150d 2 bytes JMP 77447df4 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077cd1525 2 bytes JMP 774481c2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000077cd153d 2 bytes JMP 773bf088 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077cd1555 2 bytes JMP 773cb885 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000077cd156d 2 bytes JMP 774486c1 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077cd1585 2 bytes JMP 77448222 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000077cd159d 2 bytes JMP 77447db8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000077cd15b5 2 bytes JMP 773bf121 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000077cd15cd 2 bytes JMP 773cb29f C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000077cd16b2 2 bytes JMP 77448584 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000077cd16bd 2 bytes JMP 77447d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?CreateDifferenceFile@CC2CDifferenceFile@@UAEGPAD00@Z 00000000667236bd 5 bytes JMP 0000000101c900b0 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?RestoreOriginalFile@CC2CDifferenceFile@@UAEGPAD00@Z 0000000066723e40 5 bytes JMP 0000000101c90150 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?MakeAsciiDifferenceFile@CC2CDifferenceFile@@UAEGPAD0@Z 00000000667243c1 5 bytes JMP 0000000101c90100 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?LoadJumpDbFromBuffer@CJumpRun@@UAEGKPAE@Z 000000006672a952 5 bytes JMP 0000000101c903c0 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?LoadJumpDbFromBuffer@CJumpRun@@UAEGKPAE@Z + 126 000000006672a9d0 13 bytes [2A, 9D, FF, 95, 2E, C4, 1E, ...] .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?GetKeyData@CKeyBasic@@UAEGPAE@Z 000000006672e35f 5 bytes JMP 0000000101c90630 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformXor@@UAEGVCDataArea@@0@Z 000000006672ea2f 5 bytes JMP 0000000101c8f970 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformXor@@UAEGVCDataArea@@0@Z + 768 000000006672ed2f 15 bytes [90, 6A, 23, E7, 76, 50, 88, ...] .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformRandomAccumulate@@UAEGVCDataArea@@0@Z 000000006672ee42 5 bytes JMP 0000000101c8f700 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?PerformTransform@CTransformRandomAccumulate@@UAEGVCDataArea@@0@Z + 850 000000006672f194 5 bytes JMP 0000000101c8a050 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?LoadModuleDetails@CModuleMonitor@@QAEGPAD@Z 0000000066733ce7 5 bytes JMP 0000000101c8f220 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?ScanModule@CModuleMonitor@@QAEGKG@Z 00000000667342f0 5 bytes JMP 0000000101c8f490 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?IsModuleChecksumOkay@CModuleMonitor@@QAEGXZ 0000000066734a23 5 bytes JMP 0000000101c90b10 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?IsModuleWithinLimits@CModuleMonitor@@QAEGKKK@Z 0000000066734a59 5 bytes JMP 0000000101c90da0 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?SetupInterruptHandler@CAltAsc@@QAEGPAX00PAK1@Z 00000000667590d5 5 bytes JMP 0000000101c90010 .text C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe[3280] C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0064\~df394b.tmp!?RestoreInterruptHandler@CAltAsc@@QAEGXZ 0000000066759569 5 bytes JMP 0000000101c91300 .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077cd1401 2 bytes JMP 773beb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077cd1419 2 bytes JMP 773cb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077cd1431 2 bytes JMP 77448609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000077cd144a 2 bytes CALL 773a1dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000077cd14dd 2 bytes JMP 77447efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000077cd14f5 2 bytes JMP 774480d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000077cd150d 2 bytes JMP 77447df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077cd1525 2 bytes JMP 774481c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000077cd153d 2 bytes JMP 773bf088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077cd1555 2 bytes JMP 773cb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000077cd156d 2 bytes JMP 774486c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077cd1585 2 bytes JMP 77448222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000077cd159d 2 bytes JMP 77447db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000077cd15b5 2 bytes JMP 773bf121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000077cd15cd 2 bytes JMP 773cb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000077cd16b2 2 bytes JMP 77448584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000077cd16bd 2 bytes JMP 77447d4d C:\Windows\syswow64\kernel32.dll ? C:\Windows\system32\mssprxy.dll [2608] entry point in ".rdata" section 0000000071cc71e6 ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2288:4828] 000007fefc322a74 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2288:4836] 000007feeeee7cc0 ---- EOF - GMER 2.1 ----v Geändert von HeAdAche (10.03.2013 um 15:31 Uhr) |
11.03.2013, 17:05 | #4 |
/// TB-Ausbilder | GVU Fragezeichen? Servus, Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Scan mit Combofix
Bitte poste mit deiner nächsten Antwort
|
11.03.2013, 18:02 | #5 |
| GVU Fragezeichen? Hey Matthias! Also, hab jetzt alles durchführen können. Ging auch recht zügig. Zwei Dinge die aufgefallen sind. Bei dem Combofix hat er zwei mal angeschlagen dass Avira läuft, wobei ich es eigentlich geschlossen hatte. Und es gab keinen automatischen Reboot. Edit: Hab mich vertan, dachte bei Combo gibt es auch nen Reboot. AdwCleaner[1] AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.114 - Datei am 11/03/2013 um 17:33:32 erstellt # Aktualisiert am 05/03/2013 von Xplode # Betriebssystem : Windows 7 Ultimate (64 bits) # Benutzer : geraldo - GERALDO-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\geraldo\Desktop\trojan\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\user.js Gelöscht mit Neustart : C:\ProgramData\Babylon Gelöscht mit Neustart : C:\Users\geraldo\AppData\Local\Babylon Gelöscht mit Neustart : C:\Users\geraldo\AppData\Local\Temp\BabylonToolbar Gelöscht mit Neustart : C:\Users\geraldo\AppData\LocalLow\BabylonToolbar Gelöscht mit Neustart : C:\Users\geraldo\AppData\Roaming\Babylon Gelöscht mit Neustart : C:\Users\geraldo\AppData\Roaming\dvdvideosoftiehelpers ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7600.16385 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=113480&babsrc=HP_ss&mntrId=fe956921000000000000002522c22eef --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=113480&babsrc=NT_ss&mntrId=fe956921000000000000002522c22eef --> hxxp://www.google.com -\\ Mozilla Firefox v19.0.2 (de) Datei : C:\Users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\prefs.js [OK] Die Datei ist sauber. -\\ Opera v12.0.1467.0 Datei : C:\Users\geraldo\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [3589 octets] - [11/03/2013 17:33:32] ########## EOF - C:\AdwCleaner[S1].txt - [3649 octets] ########## [/CODE] JRT JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.6.9 (03.06.2013:1) OS: Windows 7 Ultimate x64 Ran by geraldo on 11.03.2013 at 17:39:22,87 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\babylon" ~~~ FireFox Emptied folder: C:\Users\geraldo\AppData\Roaming\mozilla\firefox\profiles\2igtq7nb.default\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.03.2013 at 17:43:58,46 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Combofix [CODE] Combofix Logfile: Code:
ATTFilter ComboFix 13-03-11.01 - geraldo 11.03.2013 17:49:29.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8105.6447 [GMT 1:00] ausgeführt von:: c:\users\geraldo\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\A1 c:\program files (x86)\A1\A1 Bandbreiten-Optimierer\A1_Bandbreiten_Optimierer.exe c:\program files (x86)\A1\A1 Breitband\A1Breitband.chm c:\program files (x86)\A1\A1 Breitband\A1Breitband.exe c:\program files (x86)\A1\A1 Breitband\Browser\FF_Setup.exe c:\program files (x86)\A1\A1 Breitband\inifiles.dat c:\program files (x86)\A1\A1 Breitband\ipworks6.dll c:\program files (x86)\A1\A1 Diagnose\A1CMDTool.exe c:\program files (x86)\A1\A1 Diagnose\A1Diagnose.exe c:\program files (x86)\A1\A1 Diagnose\A1Mailboxen.exe c:\program files (x86)\A1\A1 Diagnose\A1Modemkonfigurator.exe c:\program files (x86)\A1\A1 Diagnose\A1WLANAssistent.exe c:\program files (x86)\A1\A1 Diagnose\inifiles.dat c:\program files (x86)\A1\A1 Diagnose\ipworks6.dll c:\program files (x86)\A1\A1 Diagnose\KCO.exe c:\program files (x86)\A1\A1 Modemwechsel\A1Modemwechsel.chm c:\program files (x86)\A1\A1 Modemwechsel\A1Modemwechsel.exe c:\program files (x86)\A1\A1 Modemwechsel\inifiles.dat c:\program files (x86)\A1\A1 Modemwechsel\ipworks6.dll c:\program files (x86)\A1\A1 Servicecenter\A1Servicecenter.chm c:\program files (x86)\A1\A1 Servicecenter\A1Servicecenter.exe c:\program files (x86)\A1\A1 Servicecenter\Content\broadband.html c:\program files (x86)\A1\A1 Servicecenter\Content\cd_index.html c:\program files (x86)\A1\A1 Servicecenter\Content\fonts\a1ta_medium_web01-webfont.ttf c:\program files (x86)\A1\A1 Servicecenter\Content\fonts\a1ta_regular_web01-webfont.ttf c:\program files (x86)\A1\A1 Servicecenter\Content\img\01a_a1_breitband_200x300.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\01a_weitere_services.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\01a_wlan_einrichten.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02a_a1_breitband_installieren_200x366.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02a_modemkonfigurationssoftware.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02a_modemwechselsoftware.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_breitband_unterwegs.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_breitband_zuhause.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_hinzufuegen.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_installation.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\02b_wiederherstellen.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\03_zusaetzliche_wlan_geraete.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\03_zusaetzliche_wlan_sicherheitseinstellungen.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\1x1_white_15.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\AdobeX_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\arrow_down_black.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\arrow_down_green.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\arrow_up_green.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\back.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_box_big.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_box_small.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_faq.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_faq_open.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_overlay.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_sliderButtonLeft.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\bg_sliderButtonRight.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\btn_close.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\cd_intro.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\FF_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\footer_trenner.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\icon_info.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\IE_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_bl.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_br.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_tl.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\info_tr.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\intro.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_active_center.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_active_left.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_active_right.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow_back.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow_back_black.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\link_arrow_black.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\loader.gif c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo.jpg c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_chrome_150.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_chrome_48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_glas_48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\logo_kabel_48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\mm_icon_48x48.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\productslider_next.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\productslider_prev.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_diagnose.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_diagnose_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_internet.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_internet_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_mail.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_mail_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_manuals.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_manuals_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_wlan.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_wlan_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_zusatzsoftware.png c:\program files (x86)\A1\A1 Servicecenter\Content\img\start_zusatzsoftware_green.png c:\program files (x86)\A1\A1 Servicecenter\Content\includes\main.css c:\program files (x86)\A1\A1 Servicecenter\Content\includes\main.js c:\program files (x86)\A1\A1 Servicecenter\Content\index.html c:\program files (x86)\A1\A1 Servicecenter\Content\manuals.html c:\program files (x86)\A1\A1 Servicecenter\Content\software.html c:\program files (x86)\A1\A1 Servicecenter\Content\wlan.html c:\program files (x86)\A1\A1 Servicecenter\icudt42.dll c:\program files (x86)\A1\A1 Servicecenter\libcef.dll c:\program files (x86)\A1\A1 Servicecenter\reqdata.cfg c:\program files (x86)\A1\A1 Servicecenter\Start.exe c:\program files (x86)\A1\A1 Servicecenter\Start.ini c:\program files (x86)\A1\A1 Update\M2Updater.exe c:\windows\SysWow64\tmp37C2.tmp c:\windows\SysWow64\tmp37D2.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-11 bis 2013-03-11 )))))))))))))))))))))))))))))) . . 2013-03-11 16:53 . 2013-03-11 16:53 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-11 16:39 . 2013-03-11 16:39 -------- d-----w- c:\windows\ERUNT 2013-03-11 16:39 . 2013-03-11 16:39 -------- d-----w- C:\JRT 2013-03-11 16:33 . 2013-03-11 16:33 400 ----a-w- c:\windows\DeleteOnReboot.bat 2013-03-09 15:04 . 2009-07-14 01:39 344576 ----a-w- c:\windows\system32\utilman.exe 2013-03-09 14:38 . 2013-03-09 14:39 -------- d-----w- c:\users\Administrator 2013-03-09 13:29 . 2013-03-09 13:29 -------- d-----w- c:\program files (x86)\Astroburn Lite 2013-03-09 13:29 . 2013-03-09 13:29 -------- d-----w- c:\programdata\Astroburn Lite 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\users\geraldo\AppData\Roaming\Malwarebytes 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\programdata\Malwarebytes 2013-03-09 11:08 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\users\geraldo\AppData\Local\Programs 2013-03-08 23:06 . 2013-03-08 23:07 -------- d-----w- c:\programdata\hikwhymogrxznoo 2013-02-24 12:51 . 2013-02-24 12:51 -------- d-----w- c:\users\geraldo\AppData\Local\Macromedia 2013-02-24 12:24 . 2013-02-24 12:24 -------- d-----w- c:\users\geraldo\AppData\Local\Mozilla 2013-02-24 12:23 . 2013-03-09 12:48 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2013-02-17 12:52 . 2013-02-17 12:58 -------- d-----w- c:\users\geraldo\AppData\Roaming\Apple Computer 2013-02-17 12:52 . 2013-02-17 12:52 -------- d-----w- c:\users\geraldo\AppData\Local\Apple Computer 2013-02-17 12:52 . 2013-02-17 12:52 -------- dc----w- c:\windows\system32\DRVSTORE 2013-02-17 12:52 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files\iTunes 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files (x86)\iTunes 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\programdata\Apple Computer 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files\iPod 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\users\geraldo\AppData\Local\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files (x86)\Apple Software Update 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files\Common Files\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files\Bonjour 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files (x86)\Bonjour 2013-02-17 12:46 . 2013-02-17 12:51 -------- d-----w- c:\program files (x86)\Common Files\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\programdata\Apple . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-03 13:59 . 2013-01-03 13:59 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-01-03 13:59 . 2013-01-03 13:59 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-03 13:59 . 2013-01-03 13:59 95184 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-03 13:56 . 2013-01-03 13:56 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-01-03 13:56 . 2013-01-03 13:56 308200 ----a-w- c:\windows\system32\javaws.exe 2013-01-03 13:56 . 2013-01-03 13:56 188392 ----a-w- c:\windows\system32\javaw.exe 2013-01-03 13:56 . 2013-01-03 13:56 188392 ----a-w- c:\windows\system32\java.exe 2013-01-03 13:56 . 2012-07-11 14:41 959976 ----a-w- c:\windows\system32\deployJava1.dll 2013-01-03 13:56 . 2012-07-11 14:41 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-12-11 18:27 . 2012-10-11 15:17 99912 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2012-12-11 18:27 . 2012-10-11 15:17 129216 ----a-w- c:\windows\system32\drivers\avipbb.sys 2012-07-03 14:41 . 2012-07-06 18:31 168864 ----a-w- c:\program files\Common Files\WireHelpSvc.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"= "c:\program files (x86)\DeviceVM\SmartView\AddressBarSearch.dll" [2010-09-02 162080] . [HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1] [HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-02-25 1602984] "ESL Wire"="c:\program files\EslWire\wire.exe" [2012-07-03 3890176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2012-07-06 4942336] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195] "VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "SmartViewAgent"="c:\program files (x86)\DeviceVM\SmartView\SmartViewAgent.exe" [2010-09-02 948504] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-02-07 385248] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [x] R3 gbxavs_x64;gbxavs_x64;c:\windows\system32\Drivers\gbxavs_x64.sys [x] R3 gbxusb_x64;gbxusb_x64;c:\windows\system32\Drivers\gbxusb_x64.sys [x] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1207020.003\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1207020.003\SYMEFA64.SYS [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120823.007\BHDrvx64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120831.001\IDSvia64.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [x] S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [x] S2 SmartViewService;SmartView service;c:\program files (x86)\DeviceVM\SmartView\SmartViewService.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 WCUService;SmartView Software Updater Service;c:\program files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [x] S2 WireHelpSvc;WireHelpSvc;c:\program files\Common Files\WireHelpSvc.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x] S3 gbxavs;Maschine Midi;c:\windows\system32\Drivers\gbxavs.sys [x] S3 gbxusb_svc;Maschine Controller;c:\windows\system32\Drivers\gbxusb.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-30 11660904] "RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube to MP3 Converter - c:\users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 10.0.0.138 FF - ProfilePath - c:\users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\ FF - ExtSQL: 2013-02-24 11:38; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF - ExtSQL: 2013-02-24 11:38; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn FF - ExtSQL: 2013-02-24 13:25; exif_viewer@mozilla.doslash.org; c:\users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-ASRockXTU - (no file) Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file) Wow6432Node-HKLM-Run-A1Diagnose - c:\program files (x86)\A1\A1 Diagnose\A1Diagnose.exe AddRemove-Native Instruments Maschine Controller Driver - c:\programdata\{3C6B30C3-46C9-4FD1-AAC3-6011E43BF0D1}\Maschine Controller Driver Setup.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe AddRemove-Sylenth1_is1 - c:\program files (x86)\Steinberg\VSTPlugins\Sylenth1\unins000.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\diMaster.dll\" /prefetch:1" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-11 17:54:53 ComboFix-quarantined-files.txt 2013-03-11 16:54 . Vor Suchlauf: 10 Verzeichnis(se), 255.358.676.992 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 255.365.537.792 Bytes frei . - - End Of File - - EB95E95C3049B6EA88DD660B26256348 Geändert von HeAdAche (11.03.2013 um 18:09 Uhr) |
11.03.2013, 20:02 | #6 | |
/// TB-Ausbilder | GVU Fragezeichen? Servus, Schritt 1 Mir ist aufgefallen, dass Du mehr als ein Anti-Virus-Programm mit Hintergrundwächter laufen hast: Code:
ATTFilter Norton Internet Security Avira Berichte, für welches Anti-Virus-Programm Du Dich entschieden hast. Zitat:
Schritt 2 Combofix-Skript
Schritt 3 Starte bitte OTL.exe und drücke den Quick Scan Button. Poste die OTL.txt hier in deinen Thread. Bitte poste mit deiner nächsten Antwort
|
11.03.2013, 20:55 | #7 |
| GVU Fragezeichen? Hey! Also bei dem Combofix meldete Avira dass der Zugriff auf eine Reg geblockt wurde, obwohl ich es ausgemacht habe.. Hier die Logs Combofix Logfile: Code:
ATTFilter ComboFix 13-03-11.01 - geraldo 11.03.2013 20:30:15.2.4 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8105.6529 [GMT 1:00] ausgeführt von:: c:\users\geraldo\Desktop\ComboFix.exe Benutzte Befehlsschalter :: c:\users\geraldo\Desktop\CFScript.txt AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\hikwhymogrxznoo c:\programdata\hikwhymogrxznoo\at-flag.png c:\programdata\hikwhymogrxznoo\at-image.png c:\programdata\hikwhymogrxznoo\btn-green.png c:\programdata\hikwhymogrxznoo\corners-btn.png c:\programdata\hikwhymogrxznoo\corners1.png c:\programdata\hikwhymogrxznoo\corners2.png c:\programdata\hikwhymogrxznoo\corners3.png c:\programdata\hikwhymogrxznoo\corners4.png c:\programdata\hikwhymogrxznoo\ie6-7.css c:\programdata\hikwhymogrxznoo\jquery.main.js c:\programdata\hikwhymogrxznoo\McAfee.png c:\programdata\hikwhymogrxznoo\pay17.png c:\programdata\hikwhymogrxznoo\steps-de.png c:\programdata\hikwhymogrxznoo\steps-en.png c:\programdata\hikwhymogrxznoo\style.css c:\programdata\hikwhymogrxznoo\tabs.png c:\programdata\hikwhymogrxznoo\wait.html . . ((((((((((((((((((((((( Dateien erstellt von 2013-02-11 bis 2013-03-11 )))))))))))))))))))))))))))))) . . 2013-03-11 19:36 . 2013-03-11 19:36 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-03-11 16:39 . 2013-03-11 16:39 -------- d-----w- c:\windows\ERUNT 2013-03-11 16:39 . 2013-03-11 16:39 -------- d-----w- C:\JRT 2013-03-11 16:33 . 2013-03-11 16:33 400 ----a-w- c:\windows\DeleteOnReboot.bat 2013-03-09 15:04 . 2009-07-14 01:39 344576 ----a-w- c:\windows\system32\utilman.exe 2013-03-09 14:38 . 2013-03-09 14:39 -------- d-----w- c:\users\Administrator 2013-03-09 13:29 . 2013-03-09 13:29 -------- d-----w- c:\program files (x86)\Astroburn Lite 2013-03-09 13:29 . 2013-03-09 13:29 -------- d-----w- c:\programdata\Astroburn Lite 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\users\geraldo\AppData\Roaming\Malwarebytes 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\programdata\Malwarebytes 2013-03-09 11:08 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-03-09 11:08 . 2013-03-09 11:08 -------- d-----w- c:\users\geraldo\AppData\Local\Programs 2013-02-24 12:51 . 2013-02-24 12:51 -------- d-----w- c:\users\geraldo\AppData\Local\Macromedia 2013-02-24 12:24 . 2013-02-24 12:24 -------- d-----w- c:\users\geraldo\AppData\Local\Mozilla 2013-02-24 12:23 . 2013-03-09 12:48 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2013-02-17 12:52 . 2013-02-17 12:58 -------- d-----w- c:\users\geraldo\AppData\Roaming\Apple Computer 2013-02-17 12:52 . 2013-02-17 12:52 -------- d-----w- c:\users\geraldo\AppData\Local\Apple Computer 2013-02-17 12:52 . 2013-02-17 12:52 -------- dc----w- c:\windows\system32\DRVSTORE 2013-02-17 12:52 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files\iTunes 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files (x86)\iTunes 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\programdata\Apple Computer 2013-02-17 12:51 . 2013-02-17 12:51 -------- d-----w- c:\program files\iPod 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\users\geraldo\AppData\Local\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files (x86)\Apple Software Update 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files\Common Files\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files\Bonjour 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\program files (x86)\Bonjour 2013-02-17 12:46 . 2013-02-17 12:51 -------- d-----w- c:\program files (x86)\Common Files\Apple 2013-02-17 12:46 . 2013-02-17 12:46 -------- d-----w- c:\programdata\Apple . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-03 13:59 . 2013-01-03 13:59 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-01-03 13:59 . 2013-01-03 13:59 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-03 13:59 . 2013-01-03 13:59 95184 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-03 13:56 . 2013-01-03 13:56 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-01-03 13:56 . 2013-01-03 13:56 308200 ----a-w- c:\windows\system32\javaws.exe 2013-01-03 13:56 . 2013-01-03 13:56 188392 ----a-w- c:\windows\system32\javaw.exe 2013-01-03 13:56 . 2013-01-03 13:56 188392 ----a-w- c:\windows\system32\java.exe 2013-01-03 13:56 . 2012-07-11 14:41 959976 ----a-w- c:\windows\system32\deployJava1.dll 2013-01-03 13:56 . 2012-07-11 14:41 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-07-03 14:41 . 2012-07-06 18:31 168864 ----a-w- c:\program files\Common Files\WireHelpSvc.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"= "c:\program files (x86)\DeviceVM\SmartView\AddressBarSearch.dll" [2010-09-02 162080] . [HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1] [HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-02-25 1602984] "ESL Wire"="c:\program files\EslWire\wire.exe" [2012-07-03 3890176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2012-07-06 4942336] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195] "VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112] "SmartViewAgent"="c:\program files (x86)\DeviceVM\SmartView\SmartViewAgent.exe" [2010-09-02 948504] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-02-07 385248] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-07-06 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-07-06 79360] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [2012-07-21 31808] R3 gbxavs_x64;gbxavs_x64;c:\windows\system32\Drivers\gbxavs_x64.sys [2009-10-08 45136] R3 gbxusb_x64;gbxusb_x64;c:\windows\system32\Drivers\gbxusb_x64.sys [2009-10-08 300624] R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2012-07-06 79360] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1207020.003\SYMDS64.SYS [2011-01-27 450680] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1207020.003\SYMEFA64.SYS [2011-03-15 912504] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [2010-06-11 15368] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-09-24 27800] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120823.007\BHDrvx64.sys [2012-06-18 1161376] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-02 283200] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2012-07-06 15936] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120831.001\IDSvia64.sys [2012-08-19 512672] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [2011-01-27 171128] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [2011-04-21 386168] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2013-02-07 86752] S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys [2012-07-03 147472] S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2012-09-05 6364024] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [2011-04-17 130008] S2 SmartViewService;SmartView service;c:\program files (x86)\DeviceVM\SmartView\SmartViewService.exe [2010-09-02 125216] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280] S2 WCUService;SmartView Software Updater Service;c:\program files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [2010-09-02 456976] S2 WireHelpSvc;WireHelpSvc;c:\program files\Common Files\WireHelpSvc.exe [2012-07-03 168864] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-10 138912] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-02-08 39936] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-02-08 64512] S3 gbxavs;Maschine Midi;c:\windows\system32\Drivers\gbxavs.sys [2011-07-07 357968] S3 gbxusb_svc;Maschine Controller;c:\windows\system32\Drivers\gbxusb.sys [2011-07-07 68688] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-02-16 428136] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-30 11660904] "RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 10.0.0.138 FF - ProfilePath - c:\users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\ FF - ExtSQL: 2013-02-24 11:38; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF - ExtSQL: 2013-02-24 11:38; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn FF - ExtSQL: 2013-02-24 13:25; exif_viewer@mozilla.doslash.org; c:\users\geraldo\AppData\Roaming\Mozilla\Firefox\Profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-Native Instruments Maschine Controller Driver - c:\programdata\{3C6B30C3-46C9-4FD1-AAC3-6011E43BF0D1}\Maschine Controller Driver Setup.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe AddRemove-Sylenth1_is1 - c:\program files (x86)\Steinberg\VSTPlugins\Sylenth1\unins000.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.7.2.3\diMaster.dll\" /prefetch:1" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-03-11 20:37:30 ComboFix-quarantined-files.txt 2013-03-11 19:37 ComboFix2.txt 2013-03-11 16:54 . Vor Suchlauf: 12 Verzeichnis(se), 255.413.817.344 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 255.113.019.392 Bytes frei . - - End Of File - - CE7FA2242D83F2430522E3068649FA07 OTL Logfile: Code:
ATTFilter OTL logfile created on: 11.03.2013 20:43:55 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\geraldo\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 5,97 Gb Available Physical Memory | 75,45% Memory free 15,83 Gb Paging File | 13,77 Gb Available in Paging File | 86,98% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 238,05 Gb Free Space | 51,12% Space Free | Partition Type: NTFS Computer Name: PC | User Name: geraldo | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.03.11 20:42:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe PRC - [2013.03.08 13:27:44 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2013.02.07 15:13:59 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2013.02.07 15:13:33 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.02.07 15:13:33 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2012.11.17 13:22:51 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2012.07.06 17:33:13 | 004,942,336 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFastUsb\XFastUsb.exe PRC - [2011.04.17 01:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe PRC - [2011.02.22 11:14:40 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011.02.22 11:14:34 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010.09.02 16:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe PRC - [2010.09.02 16:01:22 | 000,948,504 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe PRC - [2010.09.02 13:26:08 | 000,456,976 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe PRC - [2009.07.14 02:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe PRC - [2009.05.04 18:05:04 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe PRC - [2009.02.23 04:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe ========== Modules (No Company Name) ========== MOD - [2013.03.08 13:27:44 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012.11.28 14:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.11.28 14:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2010.09.02 16:01:22 | 000,948,504 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe MOD - [2010.09.02 15:54:26 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\sqlite3.dll MOD - [2009.04.20 10:55:58 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL MOD - [2009.02.06 17:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL ========== Services (SafeList) ========== SRV:64bit: - [2012.06.11 18:19:14 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2013.03.08 13:27:44 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.02.25 07:39:32 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013.02.07 15:13:59 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.02.07 15:13:33 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.11.17 13:22:51 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2012.11.09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.09.05 19:38:06 | 006,364,024 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService) SRV - [2012.07.06 17:35:21 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service) SRV - [2012.07.06 17:34:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service) SRV - [2012.07.06 17:34:31 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service) SRV - [2012.07.03 15:41:12 | 000,168,864 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\WireHelpSvc.exe -- (WireHelpSvc) SRV - [2011.04.17 01:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe -- (NIS) SRV - [2011.02.22 11:14:40 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011.02.22 11:14:34 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010.09.02 16:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe -- (SmartViewService) SRV - [2010.09.02 13:26:08 | 000,456,976 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe -- (WCUService) SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.02.23 04:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.12.11 19:27:30 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2012.12.11 19:27:30 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2012.12.02 22:06:13 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012.09.24 08:58:11 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr) DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2012.07.21 21:22:59 | 000,031,808 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305) DRV:64bit: - [2012.07.06 18:49:31 | 000,174,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent) DRV:64bit: - [2012.07.06 17:33:14 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX) DRV:64bit: - [2012.07.03 15:41:04 | 000,147,472 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC) DRV:64bit: - [2012.06.11 19:59:38 | 010,248,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012.06.11 17:26:14 | 000,367,616 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012.02.23 13:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2011.07.07 11:54:28 | 000,357,968 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\gbxavs.sys -- (gbxavs) DRV:64bit: - [2011.07.07 11:54:28 | 000,068,688 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\gbxusb.sys -- (gbxusb_svc) DRV:64bit: - [2011.04.21 02:37:49 | 000,386,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1207020.003\symnets.sys -- (SymNetS) DRV:64bit: - [2011.04.10 04:51:06 | 012,223,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2011.03.31 04:00:09 | 000,744,568 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1207020.003\srtsp64.sys -- (SRTSP) DRV:64bit: - [2011.03.31 04:00:09 | 000,040,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1207020.003\srtspx64.sys -- (SRTSPX) DRV:64bit: - [2011.03.15 03:31:23 | 000,912,504 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1207020.003\symefa64.sys -- (SymEFA) DRV:64bit: - [2011.02.16 10:11:08 | 000,428,136 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011.02.08 06:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI) DRV:64bit: - [2011.02.08 06:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3) DRV:64bit: - [2011.01.27 07:47:10 | 000,450,680 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1207020.003\symds64.sys -- (SymDS) DRV:64bit: - [2011.01.27 06:07:06 | 000,171,128 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1207020.003\ironx64.sys -- (SymIRON) DRV:64bit: - [2010.10.19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010.06.11 13:37:14 | 000,015,368 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger) DRV:64bit: - [2009.11.04 19:54:48 | 000,359,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm) DRV:64bit: - [2009.11.04 19:54:47 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus) DRV:64bit: - [2009.11.04 19:54:47 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb) DRV:64bit: - [2009.11.04 19:54:47 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr) DRV:64bit: - [2009.10.08 13:09:02 | 000,045,136 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gbxavs_x64.sys -- (gbxavs_x64) DRV:64bit: - [2009.10.08 13:08:59 | 000,300,624 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gbxusb_x64.sys -- (gbxusb_x64) DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2012.08.26 19:55:26 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120903.025\ex64.sys -- (NAVEX15) DRV - [2012.08.26 19:55:25 | 000,125,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120903.025\eng64.sys -- (NAVENG) DRV - [2012.08.19 21:45:41 | 000,512,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120831.001\IDSviA64.sys -- (IDSVia64) DRV - [2012.08.10 15:29:14 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl) DRV - [2012.08.10 15:29:14 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2012.06.18 23:03:24 | 001,161,376 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120823.007\BHDrvx64.sys -- (BHDrvx64) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7A 79 A6 79 96 5B CD 01 [binary data] IE - HKCU\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK IE - HKCU\..\SearchScopes\{D9F17454-3E51-41e2-8C1E-B51C57C1956F}: "URL" = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: exif_viewer%40mozilla.doslash.org:2.00 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2013.03.11 20:24:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 [2013.03.11 20:24:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 13:27:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 13:27:44 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.02.24 13:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\Extensions [2013.02.24 13:25:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\Firefox\Profiles\2igtq7nb.default\extensions [2013.02.24 13:25:41 | 000,230,013 | ---- | M] () (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\firefox\profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi [2013.03.08 13:27:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013.03.08 13:27:44 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2013.02.16 05:15:47 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.02.16 05:15:47 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2013.02.16 05:15:47 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2013.02.16 05:15:47 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2013.02.16 05:15:47 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2013.02.16 05:15:47 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013.03.11 20:36:30 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL (Symantec Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll (Symantec Corporation) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.) O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd) O4 - HKLM..\Run: [SmartViewAgent] C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe () O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKLM..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe (FNet Co., Ltd.) O4 - HKCU..\Run: [ESL Wire] C:\Program Files\EslWire\wire.exe (Turtle Entertainment GmbH) O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation) O4 - Startup: C:\Users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: blank ([]about in Local intranet) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22BED806-6C8D-45B6-97C9-D8B6C312695D}: DhcpNameServer = 10.0.0.138 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.03.11 20:42:53 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe [2013.03.11 20:37:32 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.03.11 17:48:11 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.03.11 17:48:11 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.03.11 17:48:11 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.03.11 17:46:46 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.03.11 17:46:35 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.03.11 17:45:55 | 005,037,889 | R--- | C] (Swearware) -- C:\Users\geraldo\Desktop\ComboFix.exe [2013.03.11 17:39:20 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2013.03.11 17:39:08 | 000,000,000 | ---D | C] -- C:\JRT [2013.03.10 14:05:14 | 000,000,000 | ---D | C] -- C:\Users\geraldo\Desktop\trojan [2013.03.09 14:29:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite [2013.03.09 14:29:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Astroburn Lite [2013.03.09 14:29:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Astroburn Lite [2013.03.09 12:49:12 | 234,009,856 | ---- | C] (Emsisoft GmbH ) -- C:\Users\geraldo\Desktop\EmsisoftAntiMalwareSetup_7.0.0.18.exe [2013.03.09 12:08:51 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Malwarebytes [2013.03.09 12:08:43 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.03.09 12:08:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.03.09 12:08:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.03.09 12:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.03.09 12:08:34 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Programs [2013.03.08 13:27:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.02.27 22:11:03 | 000,000,000 | ---D | C] -- C:\Users\geraldo\Documents\Geraldo [2013.02.24 13:51:54 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Macromedia [2013.02.24 13:24:57 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Mozilla [2013.02.24 13:24:57 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Mozilla [2013.02.24 13:23:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2013.02.24 13:23:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2013.02.17 13:52:30 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Apple Computer [2013.02.17 13:52:30 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Apple Computer [2013.02.17 13:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2013.02.17 13:52:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2013.02.17 13:46:41 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Apple [2013.02.17 13:46:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2013.02.17 13:46:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2013.02.17 13:46:19 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2013.02.17 13:46:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour [2013.02.17 13:46:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2013.02.17 13:46:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple ========== Files - Modified Within 30 Days ========== [2013.03.11 20:42:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe [2013.03.11 20:36:30 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013.03.11 20:33:22 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.11 20:33:22 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.11 20:32:26 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.03.11 20:32:26 | 000,645,502 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.03.11 20:32:26 | 000,607,530 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.03.11 20:32:26 | 000,126,822 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.03.11 20:32:26 | 000,103,908 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.03.11 20:27:50 | 005,037,889 | R--- | M] (Swearware) -- C:\Users\geraldo\Desktop\ComboFix.exe [2013.03.11 20:25:23 | 000,001,404 | ---- | M] () -- C:\Users\geraldo\Desktop\Games.lnk [2013.03.11 20:24:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.03.11 20:24:41 | 2078,806,015 | -HS- | M] () -- C:\hiberfil.sys [2013.03.11 17:33:57 | 000,000,400 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2013.03.10 14:39:48 | 000,377,856 | ---- | M] () -- C:\Users\geraldo\Desktop\hskobdf1.exe [2013.03.10 14:14:45 | 000,000,168 | ---- | M] () -- C:\Users\geraldo\defogger_reenable [2013.03.10 14:03:22 | 000,377,856 | ---- | M] () -- C:\Users\geraldo\Desktop\b6j43ent.exe [2013.03.09 14:29:23 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk [2013.03.09 13:43:56 | 322,961,408 | ---- | M] () -- C:\Users\geraldo\Desktop\pmagic_2013_02_28.iso [2013.03.09 13:29:55 | 001,160,893 | ---- | M] () -- C:\Users\geraldo\Desktop\ProcessExplorer.zip [2013.03.09 12:56:03 | 234,009,856 | ---- | M] (Emsisoft GmbH ) -- C:\Users\geraldo\Desktop\EmsisoftAntiMalwareSetup_7.0.0.18.exe [2013.03.09 00:06:50 | 000,074,126 | ---- | M] () -- C:\ProgramData\gqcbupulgcceydk [2013.02.26 18:33:22 | 014,018,244 | ---- | M] () -- C:\Users\geraldo\Desktop\hurensohn.wav [2013.02.24 13:23:06 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.02.19 20:15:41 | 000,193,401 | ---- | M] () -- C:\Users\geraldo\Documents\Das Erleben u. bew. einer Koronarintervention.pdf [2013.02.10 17:35:23 | 000,001,048 | ---- | M] () -- C:\Users\geraldo\Documents\ILUVTOEAT.rtf ========== Files Created - No Company Name ========== [2013.03.11 17:48:11 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.03.11 17:48:11 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.03.11 17:48:11 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.03.11 17:48:11 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.03.11 17:48:11 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.03.11 17:33:52 | 000,000,400 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat [2013.03.10 14:39:47 | 000,377,856 | ---- | C] () -- C:\Users\geraldo\Desktop\hskobdf1.exe [2013.03.10 14:14:45 | 000,000,168 | ---- | C] () -- C:\Users\geraldo\defogger_reenable [2013.03.10 14:05:25 | 000,377,856 | ---- | C] () -- C:\Users\geraldo\Desktop\b6j43ent.exe [2013.03.09 14:29:22 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk [2013.03.09 13:33:12 | 322,961,408 | ---- | C] () -- C:\Users\geraldo\Desktop\pmagic_2013_02_28.iso [2013.03.09 13:29:54 | 001,160,893 | ---- | C] () -- C:\Users\geraldo\Desktop\ProcessExplorer.zip [2013.03.09 00:06:34 | 000,074,126 | ---- | C] () -- C:\ProgramData\gqcbupulgcceydk [2013.03.06 22:22:33 | 000,001,404 | ---- | C] () -- C:\Users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk [2013.03.06 22:22:33 | 000,001,404 | ---- | C] () -- C:\Users\geraldo\Desktop\Games.lnk [2013.02.26 18:33:22 | 014,018,244 | ---- | C] () -- C:\Users\geraldo\Desktop\hurensohn.wav [2013.02.24 13:23:06 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.02.24 13:23:05 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.02.19 20:15:20 | 000,193,401 | ---- | C] () -- C:\Users\geraldo\Documents\Das Erleben u. bew. einer Koronarintervention.pdf [2013.02.17 13:46:40 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2013.02.10 17:35:23 | 000,001,048 | ---- | C] () -- C:\Users\geraldo\Documents\ILUVTOEAT.rtf [2012.11.17 13:20:03 | 000,282,296 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2012.11.17 13:20:02 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2012.11.17 13:20:02 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2012.07.06 20:10:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2012.07.06 19:31:05 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe [2012.07.06 17:35:37 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini [2012.07.06 17:35:37 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini [2012.07.06 17:35:37 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini [2012.07.06 17:35:26 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2012.07.06 17:35:26 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2012.07.06 17:29:03 | 013,356,032 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll [2012.07.06 17:29:03 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2012.07.06 17:29:03 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2012.07.06 17:29:03 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2012.07.06 17:29:03 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2012.06.11 17:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012.06.11 17:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012.05.10 15:35:16 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2011.09.12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.09.04 15:53:15 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\A1 Servicecenter [2012.10.26 14:41:34 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Antares [2012.12.02 22:07:59 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DAEMON Tools Lite [2012.07.06 17:39:06 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DeviceVm [2012.10.23 21:36:32 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DVDVideoSoft [2012.11.02 13:04:46 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\EurekaLog [2012.07.14 15:33:24 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\F4 [2012.10.10 09:54:37 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Image-Line [2012.07.19 14:18:06 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\LolClient [2012.09.04 15:46:56 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\mquadr.at [2012.10.23 18:24:28 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\OpenOffice.org [2012.07.06 17:45:58 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Opera [2012.10.18 15:45:00 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Publish Providers [2012.10.18 15:44:50 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Sony [2013.03.09 13:17:12 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\TS3Client ========== Purity Check ========== < End of report > [/CODE] OTL Extra OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 11.03.2013 20:43:55 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\geraldo\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 5,97 Gb Available Physical Memory | 75,45% Memory free 15,83 Gb Paging File | 13,77 Gb Available in Paging File | 86,98% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 238,05 Gb Free Space | 51,12% Space Free | Partition Type: NTFS Computer Name: PC | User Name: geraldo | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{06EE5741-6BBB-423B-AAC2-21BCEFAB7481}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{07B00B63-6FC3-4E17-8C6D-EA56E07F2E02}" = rport=138 | protocol=17 | dir=out | app=system | "{153F0032-1B32-4AAE-A0DA-C5395E22DDF7}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{200551DF-CEFF-4C3D-B759-E67857549CC0}" = rport=139 | protocol=6 | dir=out | app=system | "{2EF2308B-167F-4D1F-97A3-AD4157317E16}" = rport=10243 | protocol=6 | dir=out | app=system | "{35C542D6-017E-4B37-B73F-CB13B84E5C06}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{43C52136-3DE2-49C6-A546-64D458860A08}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{45E27FEE-F28E-48C0-B22F-75D97A975A8A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{55834FB7-547E-46F6-A273-0BB80EA9FD93}" = lport=57516 | protocol=6 | dir=in | name=pando media booster | "{6164592F-DEC7-476D-A825-458EDF71B9F5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7966BE70-D027-4311-8088-66DDE8085007}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{85B38B46-119E-407B-837D-C0E32317DEC9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{89860529-15BD-479B-A5DE-8AA40090862D}" = lport=138 | protocol=17 | dir=in | app=system | "{8B6C0117-2052-46CD-AA3D-C58317D23B18}" = lport=445 | protocol=6 | dir=in | app=system | "{98C291C3-DBF4-4AE9-B038-5A8A9A045B8C}" = lport=137 | protocol=17 | dir=in | app=system | "{A7FB3AA9-B51A-4F74-A592-9B91C57903A1}" = lport=57516 | protocol=17 | dir=in | name=pando media booster | "{AF530982-6289-4E64-9DE9-2DC38B9163C0}" = lport=57516 | protocol=6 | dir=in | name=pando media booster | "{B4DE78CA-ED61-49F9-A3AC-EFC7644F3A2E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CA156C7D-6522-43BE-A990-60B642B10E3A}" = rport=445 | protocol=6 | dir=out | app=system | "{E1C4705E-593B-4626-893A-F8E8FB4E7C45}" = lport=139 | protocol=6 | dir=in | app=system | "{F0E1F392-1F3A-4D68-8631-E213F6C1294B}" = lport=10243 | protocol=6 | dir=in | app=system | "{F12145E9-F417-4245-A9EC-F342BD216D36}" = lport=57516 | protocol=17 | dir=in | name=pando media booster | "{F7373232-2A24-4183-92D8-53C386B161D6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F946F36E-2C49-42B8-8D81-CAB67D67EAD1}" = rport=137 | protocol=17 | dir=out | app=system | "{FB481A4A-1111-413E-8725-50CC6A2D7CF9}" = lport=2869 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02C1AF92-0533-4DAC-B419-31943F2CEB32}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{0385803A-783C-4CE4-97B8-AB4A82D7811D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0B18D062-EA28-418D-B030-24F61CD03E53}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm | "{0FFEB2BF-26CC-449A-B9DF-D6FEA950DF96}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{1287BDEA-66C8-4C3A-98B7-96505E7F3E58}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "{16E09CD3-7AA6-464B-BB91-C0882F685EE5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{18499742-CD97-4A46-85B1-CBA1F3EE9279}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe | "{1B9040B6-C2A7-40F1-B1B7-86498101D229}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{212FE492-49D3-437E-A8AE-5D32BAA3AF42}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 bandbreiten-optimierer\a1_bandbreiten_optimierer.exe | "{25F4BC8A-A3CF-463C-8D92-DCF35A857AD4}" = dir=in | app=c:\program files\eslwire\wire.exe | "{268B5730-E510-4397-8E58-B26E47ABC33D}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1diagnose.exe | "{2A0BAE53-760D-4F6B-B673-65E158C721BF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe | "{2B591381-7506-4CF5-A21E-1089DB6F0AFC}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{2F1F53E5-C371-4F3E-88B1-1AB70336E59D}" = protocol=6 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe | "{2F63D7BD-C16C-413B-B769-05EA8FEFC317}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{2FFCE0D7-E0C7-4709-A7C1-D36973791AAF}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 bandbreiten-optimierer\a1_bandbreiten_optimierer.exe | "{35565D41-6614-4AB1-831F-FC258BAD5E43}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1diagnose.exe | "{35B2683A-9B54-495A-B260-713284C84875}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm | "{35FD5D99-F54B-47D3-8EFE-DBDA3EE48B13}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{38A29908-1E55-4E7E-A187-3DAEC2B7C821}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{3DC585AE-4B89-431A-918B-D98D5D220263}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | "{3F6FD4C3-641E-4BAE-823F-42F49E0C1574}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{41C00A48-51B1-4029-B43D-E07A9939C619}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe | "{44699787-D69F-41CE-825F-5766C414F5CD}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1modemkonfigurator.exe | "{4865F19A-93A8-4786-B8C2-8B54E676FD82}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1diagnose.exe | "{4A19CFAD-B6F3-40B9-A861-F70FB21FD9F4}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{544E0EF1-3325-4030-BB27-5BEA99E7B079}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1wlanassistent.exe | "{5A4F614A-DBB4-4EA3-A26B-8B6EC3E5612A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{6176DC4E-322B-4399-B8B5-810A83E0EC5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe | "{6E480C5F-19A4-4559-BC01-A32BC55C0B83}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{6F80159B-A2B9-4090-979B-2013BA765475}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{6F81A2C1-72FD-4E29-BCE5-840959C91836}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{733912B7-04C5-4B6F-AA2A-92025A7A11D2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{7C5194BE-8494-4765-9E01-5E72E9D09890}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{83910DBE-98C7-4FF0-8C1D-8864F26B64B9}" = dir=out | app=c:\program files\eslwire\wire.exe | "{88CEFBF8-8F2E-47F0-98BB-8E2090381BE2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe | "{89223D11-7603-4578-9AA6-C1AB5F880BA2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8A7F97D4-6DF1-4771-B5CD-FEF4A33E299C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{8D367DA6-3730-4E83-BE24-D7340A536234}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 servicecenter\a1servicecenter.exe | "{901FF39E-73C8-46A1-8EE8-A87750F33E35}" = protocol=17 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\xrengine.exe | "{9102480D-3F56-4DE2-A4FB-D29A8E6375D9}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{94F51426-22AF-4507-B89C-9654C8BC1895}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 modemwechsel\a1modemwechsel.exe | "{989B8EBE-5DBB-4CDC-9120-7E4B0B1B680D}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{99C29F98-A1E4-46E1-A340-3C8F9C92C443}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{A173148C-0737-44B5-9D98-836E6193C5F2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{A3CF74D5-9F70-44D6-8BA4-28FA01321388}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A4D1F5C2-7E4D-4C80-B159-9213D8572CC8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\don_batalhador\counter-strike source\hl2.exe | "{A520B091-8658-4DA8-AC74-256764FAA4A0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | "{A8ACBFE6-CB0C-4533-8F24-0B40E6B06DBF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{A8E36909-431B-42E8-B8DD-653379185602}" = protocol=6 | dir=out | app=system | "{A90ED488-2831-4A8B-9669-1AB553C37BB9}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1wlanassistent.exe | "{AC5B0261-D359-457A-8928-FDE011AC743C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B4CEB701-9A62-4E9C-A028-7FE7BD34F0A1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{B83D297E-0F6D-4DD5-8B60-F847119A3FB9}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{B98FCDBB-97C0-485E-810F-425F9B7ED22E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{B9D34B7B-F1CB-423D-840E-93C2DAA5FF99}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{BAA5B9E0-4F51-43D5-81E3-91820CE0260A}" = protocol=6 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe | "{BEC5772D-117E-4BBE-BA7D-D137DC49C8CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{BF11680A-6531-4716-B43A-3C40F26F3500}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 servicecenter\a1servicecenter.exe | "{BF4AAC80-5394-4560-8692-7619D03161F1}" = protocol=17 | dir=in | app=c:\program files (x86)\bitcomposer games\s.t.a.l.k.e.r. - call of pripyat\bin\dedicated\xrengine.exe | "{C16489EF-2BF5-48D4-9832-57DAE17DAFAA}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1modemkonfigurator.exe | "{C3E407B2-3127-46E8-AF92-0C6BC0BC705F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C50B14B6-D0AE-464F-8954-A58884234E3F}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 diagnose\a1diagnose.exe | "{C5454D1A-C6BC-41C0-B2B4-5D9A5A440CF9}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 modemwechsel\a1modemwechsel.exe | "{C5741BD7-9CF1-4FA4-8F3B-95EA47300B7F}" = protocol=6 | dir=in | app=c:\program files (x86)\a1\a1 breitband\a1breitband.exe | "{C5D3566A-F6C7-427F-954B-17FF249F3B1C}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{C77F95C3-47B2-427E-9681-36A31960F950}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "{CE23366E-4C24-4353-B42F-7C11EC750D1E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe | "{CEA12292-F8B5-47E8-8ECB-773B801623C0}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{D13E8DE7-D60C-48D0-9549-618216481B55}" = protocol=17 | dir=in | app=c:\program files (x86)\a1\a1 breitband\a1breitband.exe | "{D20D80F3-1E47-4463-93B2-FC20D9F149B6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D353AA18-9BF1-4AB9-BBE6-11A12B307A6B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe | "{D586DB5B-FEBC-4EDC-ABEE-149F01BCB86F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{D5E18545-5E81-4644-BA7B-87EE8F735606}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{D5EA0F52-BA8D-4128-9597-34A20C1BD9B0}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{D672D106-BFEB-4CF5-AAA2-82D8B3F0AE82}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{E505BA6C-9EBC-49A1-8FDE-117E5408D174}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\don_batalhador\counter-strike source\hl2.exe | "{E5174AEE-1D72-4ED5-9CE7-19BA045F4875}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe | "{E828B1F9-37F4-4DC7-A447-1B0B7A52C1F9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E9B79C43-AC47-400B-8932-F728FE068C9D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe | "{ECB289DE-7B67-4D2A-92F3-BC8D4E4A4EA9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | "{F2164BEB-DC45-42CD-9CCE-157709E26C30}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{F880986C-B50F-4443-B91D-33D28984180C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{FA9C445F-8248-4577-8FB7-A8BEA5CA76EA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{FC4FAFF1-0383-4590-B1E3-21C8386A0BE7}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "TCP Query User{0A5599E8-A91B-44D4-8812-C1F26BEA1F09}C:\program files (x86)\jdownloader\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jdownloader\jre\bin\javaw.exe | "TCP Query User{BCD3F4DD-9FA6-4852-9721-AE99FB5ABBF5}C:\program files (x86)\steam\steamapps\don_batalhador\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\don_batalhador\counter-strike source\hl2.exe | "UDP Query User{9848371E-9B76-409F-800D-FE8FDDA7AB81}C:\program files (x86)\steam\steamapps\don_batalhador\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\don_batalhador\counter-strike source\hl2.exe | "UDP Query User{9FB9235C-84AA-4B39-9ECB-A904751C024A}C:\program files (x86)\jdownloader\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jdownloader\jre\bin\javaw.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01D57CF6-B5BC-4D03-AFF5-7960CFBD05A9}" = Native Instruments Guitar Rig 5 "{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor "{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center "{0CB2E2BC-A312-5821-C5C7-A295A1BEFD08}" = AMD Catalyst Install Manager "{0E086923-AAA3-4F98-A6E2-48B64CE27553}" = Native Instruments Reaktor Factory Selection "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64 "{267B3E82-C941-47D8-BCD3-1BBBB56FCBC6}" = Native Instruments Maschine Controller "{26A24AE4-039D-4CA4-87B4-2F86417010FF}" = Java 7 Update 10 (64-bit) "{2BBE23DB-F92C-4319-9179-7E79717EE9AC}" = Native Instruments Komplete 8 Players "{42A2440F-7A5D-6956-3EF0-815814399EAA}" = AMD Accelerated Video Transcoding "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64 "{491DF203-7B61-4F0E-BDCB-A1218C4DAFE9}" = Native Instruments Massive "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4E021D2A-16ED-4FFF-87CB-774F4F62A1A1}" = ccc-utility64 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5552453B-BB76-45E3-973D-F95E458ED780}" = Native Instruments Kontakt 5 "{572788F2-0AB7-FA0E-6E91-B98044F4B7E6}" = AMD Media Foundation Decoders "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{82EE86D9-60B9-1025-9960-97E9B7C7B4B4}" = AMD Drag and Drop Transcoding "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64 "{8812511F-8D8C-49D3-A711-C9650B2F5566}" = Native Instruments Guitar Rig Factory Selection for Maschine "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64 "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64 "{B0FC9E28-1CE6-4A40-BEF1-C6E6EDFCA070}" = Native Instruments Kontakt Factory Selection "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64 "{D207019F-D0A5-11DF-A282-0013D3D69929}" = Vegas Pro 10.0 (64-bit) "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{D81C035E-D0A5-11DF-9450-0013D3D69929}" = MSVCRT Redists "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{E9EA5F38-6299-45A1-9D23-F21729A19357}" = Native Instruments Reaktor 5 "{EF728EC1-799C-4570-9AE0-8A9A54E4670A}" = Native Instruments Driver "{FC6AFD44-EDF9-4A03-AB9E-16A5391FE24F}" = Native Instruments Maschine "ASRock App Charger_is1" = ASRock App Charger v1.0.4 "ESL Wire_is1" = ESL Wire 1.13 "WinRAR archiver" = WinRAR 4.20 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{14DDF23F-414A-46DB-4762-56569080292C}" = CCC Help Russian "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{21D6A73A-48E6-2195-C408-2158273A914E}" = Catalyst Control Center Localization All "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{2596DB11-997F-FC5B-F5C2-737623D9D8B6}" = Catalyst Control Center "{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10 "{28904D9A-13A6-ECA2-48D8-21542759D998}" = CCC Help Polish "{2C8BBDA6-79A7-B2DE-3E5B-287E7F667C67}" = CCC Help Danish "{2E119961-E99B-C147-9AC3-A93683172DC1}" = CCC Help Swedish "{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help "{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1" = S.T.A.L.K.E.R. - Call Of Pripyat [v1.6.01] "{44ED90A1-453B-5C9A-D9ED-80D8AB0258B8}" = CCC Help Thai "{45E00595-897E-64B6-28F9-5D0927EBA4A5}" = CCC Help Chinese Standard "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR "{46DE5F4E-BA8B-AC9E-0EED-05B7D93AD215}" = CCC Help Spanish "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5B04E832-4530-B8FF-F742-8BE25ADD43BD}" = CCC Help German "{5B0CE14A-B9B6-4E25-A1BE-3EEC1998AC2C}" = SmartView Software Updater "{5D58EACA-0317-4CFF-9E13-53CCD525DE32}" = Catalyst Control Center InstallProxy "{5ED93D68-5EAA-9343-9B74-B1E276217264}" = CCC Help Dutch "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{6D185295-DE89-9C39-18E6-310C148836EB}" = CCC Help Chinese Traditional "{71A8F958-D272-E262-7C9A-7B8F713EE0C3}" = CCC Help French "{7513D3F0-55BC-273C-7A53-488394EDBFCC}" = CCC Help Italian "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79AA9BFA-F962-A1E9-71CE-D0887A92444C}" = CCC Help Portuguese "{7ACEF1BF-9306-5AD7-5F30-ECE72A81E924}" = CCC Help Finnish "{7E4FBD52-148F-49EE-AFCC-96FB498F4D7D}" = A1 Servicecenter "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C1EC871-05B9-03B7-96F6-9BD5C0D8F41D}" = Catalyst Control Center Graphics Previews Common "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9 "{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86 "{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story "{C4129D57-5C83-3BF0-A11A-3798C008C6C7}" = CCC Help Greek "{C448EA30-BB7F-4D42-83BC-385EBA140AF2}" = SmartView for IE "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support "{D0BC4101-6C30-ECFF-F693-63408134F29B}" = CCC Help Czech "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D2402DAD-B180-A4A0-261D-4A8933BFBFEE}" = CCC Help Japanese "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{DA7E8D81-2B14-415B-8FC5-02CE4CF9F839}" = CCC Help Hungarian "{DB3FBD3C-A061-34C9-0A2B-6CCDD8C96640}" = CCC Help Turkish "{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "{E086E914-2928-48F9-364B-0C715DFF6A45}" = CCC Help Korean "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding "{E8F30BD6-ABAB-C24E-E9A7-BF67EB96152C}" = CCC Help Norwegian "{E9A5B6CD-7ABB-F295-2E11-F25BC322FF80}" = CCC Help English "{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}" = Sound Blaster X-Fi MB "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "5513-1208-7298-9440" = JDownloader 0.9 "A1 Servicecenter" = A1 Servicecenter "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Antares Autotune Evo VST RTAS_is1" = Antares Autotune Evo VST RTAS v6.0.9 "ASIO4ALL" = ASIO4ALL "ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.78 "ASRock InstantBoot_is1" = ASRock InstantBoot v1.26 "Astroburn Lite" = Astroburn Lite "Avira AntiVir Desktop" = Avira Free Antivirus "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "DAEMON Tools Lite" = DAEMON Tools Lite "Diablo III" = Diablo III "Edirol HQ Orchestral VSTi v1.03" = Edirol HQ Orchestral VSTi v1.03 "Effectrix" = Effectrix "f42012" = f4 2012 "FL Studio 10" = FL Studio 10 "IL Download Manager" = IL Download Manager "InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "KaloMa_is1" = KaloMa 4.92 "LUXONIX_Purity" = LUXONIX Purity "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100 "Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "Native Instruments Controller Editor" = Native Instruments Controller Editor "Native Instruments Driver" = Native Instruments Driver "Native Instruments Guitar Rig 5" = Native Instruments Guitar Rig 5 "Native Instruments Guitar Rig Factory Selection for Maschine" = Native Instruments Guitar Rig Factory Selection for Maschine "Native Instruments Komplete 8 Players" = Native Instruments Komplete 8 Players "Native Instruments Kontakt 5" = Native Instruments Kontakt 5 "Native Instruments Kontakt Factory Selection" = Native Instruments Kontakt Factory Selection "Native Instruments Maschine" = Native Instruments Maschine "Native Instruments Maschine Controller" = Native Instruments Maschine Controller "Native Instruments Maschine Controller Driver" = Native Instruments Maschine Controller Driver "Native Instruments Massive" = Native Instruments Massive "Native Instruments Reaktor 5" = Native Instruments Reaktor 5 "Native Instruments Reaktor Factory Selection" = Native Instruments Reaktor Factory Selection "Native Instruments Service Center" = Native Instruments Service Center "NIS" = Norton Internet Security "Opera 12.00.1467" = Opera 12.00 "PunkBusterSvc" = PunkBuster Services "reFX Nexus_is1" = reFX Nexus VSTi RTAS v2.2.0 "Steam App 240" = Counter-Strike: Source "Steam App 24960" = Battlefield: Bad Company 2 "Steam App 42910" = Magicka "Sylenth1_is1" = Sylenth1 v2.20 "Tone2 Gladiator VSTi_is1" = Tone2 Gladiator VSTi v2.2 "VLC media player" = VLC media player 2.0.2 "XFastUsb" = XFastUsb ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "TeamSpeak 3 Client" = TeamSpeak 3 Client ========== Last 20 Event Log Errors ========== [ System Events ] Error - 11.03.2013 12:45:33 | Computer Name = PC | Source = DCOM | ID = 10010 Description = Error - 11.03.2013 12:52:05 | Computer Name = PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 11.03.2013 12:53:20 | Computer Name = PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 11.03.2013 12:53:51 | Computer Name = PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 11.03.2013 15:34:53 | Computer Name = PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 11.03.2013 15:36:10 | Computer Name = PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 11.03.2013 15:36:10 | Computer Name = PC | Source = Application Popup | ID = 1060 Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error - 11.03.2013 15:36:32 | Computer Name = PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. < End of report > Geändert von HeAdAche (11.03.2013 um 21:03 Uhr) |
12.03.2013, 16:15 | #8 |
/// TB-Ausbilder | GVU Fragezeichen? Servus, du hast mir nicht zugehört... deinstalliere entweder Avira oder Norton. Poste anschließend eine neue Logdatei von OTL. |
12.03.2013, 21:39 | #9 |
| GVU Fragezeichen? Tut mir leid, ich kann mich erst am Wochenende dem Problem widmen, da ich wegen einer Operation verhindert bin. |
13.03.2013, 16:08 | #10 |
/// TB-Ausbilder | GVU Fragezeichen? Servus, alles Gute für die Operation. Ich warte bis Sonntag auf deine Rückmeldung. |
18.03.2013, 11:19 | #11 |
| GVU Fragezeichen? OTL Logfile: Code:
ATTFilter OTL logfile created on: 18.03.2013 11:10:42 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\geraldo\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 6,26 Gb Available Physical Memory | 79,09% Memory free 15,83 Gb Paging File | 13,91 Gb Available in Paging File | 87,87% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 238,17 Gb Free Space | 51,15% Space Free | Partition Type: NTFS Computer Name: GERALDO-PC | User Name: geraldo | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.03.18 11:05:26 | 000,059,964 | ---- | M] (Macrovision Europe Ltd.) -- C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 PRC - [2013.03.11 20:42:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe PRC - [2013.03.08 13:27:44 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2013.02.07 15:13:59 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2013.02.07 15:13:33 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.02.07 15:13:33 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2012.11.17 13:22:51 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2012.07.06 17:34:31 | 000,079,360 | ---- | M] (Creative Labs) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe PRC - [2012.07.06 17:33:13 | 004,942,336 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFastUsb\XFastUsb.exe PRC - [2011.02.22 11:14:40 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011.02.22 11:14:34 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010.09.02 16:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe PRC - [2010.09.02 16:01:22 | 000,948,504 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe PRC - [2010.09.02 13:26:08 | 000,456,976 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe PRC - [2009.07.14 02:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe PRC - [2009.07.08 14:32:50 | 001,233,195 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe PRC - [2009.05.04 18:05:04 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe PRC - [2009.02.23 04:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe ========== Modules (No Company Name) ========== MOD - [2013.03.18 11:05:29 | 000,592,896 | ---- | M] () -- C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~de6248.tmp MOD - [2013.03.18 11:05:28 | 000,697,884 | ---- | M] () -- C:\Users\geraldo\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~df394b.tmp MOD - [2013.03.08 13:27:44 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2012.11.28 14:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012.11.28 14:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2010.09.02 16:01:22 | 000,948,504 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe MOD - [2010.09.02 15:54:26 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\SmartView\sqlite3.dll MOD - [2009.04.20 10:55:58 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL MOD - [2009.02.06 17:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL ========== Services (SafeList) ========== SRV:64bit: - [2012.06.11 18:19:14 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2013.03.08 13:27:44 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.02.25 07:39:32 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013.02.07 15:13:59 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.02.07 15:13:33 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.11.17 13:22:51 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2012.11.09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.09.05 19:38:06 | 006,364,024 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService) SRV - [2012.07.06 17:35:21 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service) SRV - [2012.07.06 17:34:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service) SRV - [2012.07.06 17:34:31 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service) SRV - [2012.07.03 15:41:12 | 000,168,864 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\WireHelpSvc.exe -- (WireHelpSvc) SRV - [2011.02.22 11:14:40 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011.02.22 11:14:34 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010.09.02 16:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe -- (SmartViewService) SRV - [2010.09.02 13:26:08 | 000,456,976 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe -- (WCUService) SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.02.23 04:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012.12.11 19:27:30 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2012.12.11 19:27:30 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2012.12.02 22:06:13 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2012.09.24 08:58:11 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr) DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2012.07.21 21:22:59 | 000,031,808 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305) DRV:64bit: - [2012.07.06 17:33:14 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX) DRV:64bit: - [2012.07.03 15:41:04 | 000,147,472 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC) DRV:64bit: - [2012.06.11 19:59:38 | 010,248,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012.06.11 17:26:14 | 000,367,616 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012.02.23 13:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2011.07.07 11:54:28 | 000,357,968 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\gbxavs.sys -- (gbxavs) DRV:64bit: - [2011.07.07 11:54:28 | 000,068,688 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\gbxusb.sys -- (gbxusb_svc) DRV:64bit: - [2011.04.10 04:51:06 | 012,223,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2011.02.16 10:11:08 | 000,428,136 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2011.02.08 06:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI) DRV:64bit: - [2011.02.08 06:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3) DRV:64bit: - [2010.10.19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:64bit: - [2010.06.11 13:37:14 | 000,015,368 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger) DRV:64bit: - [2009.11.04 19:54:48 | 000,359,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm) DRV:64bit: - [2009.11.04 19:54:47 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus) DRV:64bit: - [2009.11.04 19:54:47 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb) DRV:64bit: - [2009.11.04 19:54:47 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr) DRV:64bit: - [2009.10.08 13:09:02 | 000,045,136 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gbxavs_x64.sys -- (gbxavs_x64) DRV:64bit: - [2009.10.08 13:08:59 | 000,300,624 | ---- | M] (Native Instruments GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\gbxusb_x64.sys -- (gbxusb_x64) DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7A 79 A6 79 96 5B CD 01 [binary data] IE - HKCU\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK IE - HKCU\..\SearchScopes\{D9F17454-3E51-41e2-8C1E-B51C57C1956F}: "URL" = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: exif_viewer%40mozilla.doslash.org:2.00 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 13:27:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 13:27:44 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.02.24 13:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\Extensions [2013.02.24 13:25:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\Firefox\Profiles\2igtq7nb.default\extensions [2013.02.24 13:25:41 | 000,230,013 | ---- | M] () (No name found) -- C:\Users\geraldo\AppData\Roaming\mozilla\firefox\profiles\2igtq7nb.default\extensions\exif_viewer@mozilla.doslash.org.xpi [2013.03.08 13:27:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013.03.08 13:27:44 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2013.02.16 05:15:47 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.02.16 05:15:47 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2013.02.16 05:15:47 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2013.02.16 05:15:47 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2013.02.16 05:15:47 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2013.02.16 05:15:47 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013.03.11 20:36:30 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.) O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd) O4 - HKLM..\Run: [SmartViewAgent] C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe () O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKLM..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe (FNet Co., Ltd.) O4 - HKCU..\Run: [ESL Wire] C:\Program Files\EslWire\wire.exe (Turtle Entertainment GmbH) O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation) O4 - Startup: C:\Users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: blank ([]about in Local intranet) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22BED806-6C8D-45B6-97C9-D8B6C312695D}: DhcpNameServer = 10.0.0.138 O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.03.18 11:05:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013.03.11 20:42:53 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe [2013.03.11 20:37:32 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.03.11 17:48:11 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.03.11 17:48:11 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.03.11 17:48:11 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.03.11 17:46:46 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.03.11 17:46:35 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.03.11 17:45:55 | 005,037,889 | R--- | C] (Swearware) -- C:\Users\geraldo\Desktop\ComboFix.exe [2013.03.11 17:39:20 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2013.03.11 17:39:08 | 000,000,000 | ---D | C] -- C:\JRT [2013.03.10 14:05:14 | 000,000,000 | ---D | C] -- C:\Users\geraldo\Desktop\trojan [2013.03.09 14:29:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite [2013.03.09 14:29:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Astroburn Lite [2013.03.09 14:29:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Astroburn Lite [2013.03.09 12:49:12 | 234,009,856 | ---- | C] (Emsisoft GmbH ) -- C:\Users\geraldo\Desktop\EmsisoftAntiMalwareSetup_7.0.0.18.exe [2013.03.09 12:08:51 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Malwarebytes [2013.03.09 12:08:43 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.03.09 12:08:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.03.09 12:08:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.03.09 12:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.03.09 12:08:34 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Programs [2013.03.08 13:27:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.02.27 22:11:03 | 000,000,000 | ---D | C] -- C:\Users\geraldo\Documents\Geraldo [2013.02.24 13:51:54 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Macromedia [2013.02.24 13:24:57 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Mozilla [2013.02.24 13:24:57 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Mozilla [2013.02.24 13:23:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2013.02.24 13:23:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2013.02.17 13:52:30 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Roaming\Apple Computer [2013.02.17 13:52:30 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Apple Computer [2013.02.17 13:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2013.02.17 13:52:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2013.02.17 13:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2013.02.17 13:46:41 | 000,000,000 | ---D | C] -- C:\Users\geraldo\AppData\Local\Apple [2013.02.17 13:46:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2013.02.17 13:46:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2013.02.17 13:46:19 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2013.02.17 13:46:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour [2013.02.17 13:46:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2013.02.17 13:46:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple ========== Files - Modified Within 30 Days ========== [2013.03.18 11:13:36 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.18 11:13:36 | 000,013,536 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.18 11:12:49 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.03.18 11:12:49 | 000,645,502 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.03.18 11:12:49 | 000,607,530 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.03.18 11:12:49 | 000,126,822 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.03.18 11:12:49 | 000,103,908 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.03.18 11:05:38 | 000,001,404 | ---- | M] () -- C:\Users\geraldo\Desktop\Games.lnk [2013.03.18 11:05:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.03.18 11:05:03 | 2078,806,015 | -HS- | M] () -- C:\hiberfil.sys [2013.03.11 20:42:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\geraldo\Desktop\OTL.exe [2013.03.11 20:36:30 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013.03.11 20:27:50 | 005,037,889 | R--- | M] (Swearware) -- C:\Users\geraldo\Desktop\ComboFix.exe [2013.03.11 17:33:57 | 000,000,400 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2013.03.10 14:39:48 | 000,377,856 | ---- | M] () -- C:\Users\geraldo\Desktop\hskobdf1.exe [2013.03.10 14:14:45 | 000,000,168 | ---- | M] () -- C:\Users\geraldo\defogger_reenable [2013.03.10 14:03:22 | 000,377,856 | ---- | M] () -- C:\Users\geraldo\Desktop\b6j43ent.exe [2013.03.09 14:29:23 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk [2013.03.09 13:43:56 | 322,961,408 | ---- | M] () -- C:\Users\geraldo\Desktop\pmagic_2013_02_28.iso [2013.03.09 13:29:55 | 001,160,893 | ---- | M] () -- C:\Users\geraldo\Desktop\ProcessExplorer.zip [2013.03.09 12:56:03 | 234,009,856 | ---- | M] (Emsisoft GmbH ) -- C:\Users\geraldo\Desktop\EmsisoftAntiMalwareSetup_7.0.0.18.exe [2013.03.09 00:06:50 | 000,074,126 | ---- | M] () -- C:\ProgramData\gqcbupulgcceydk [2013.02.26 18:33:22 | 014,018,244 | ---- | M] () -- C:\Users\geraldo\Desktop\hurensohn.wav [2013.02.24 13:23:06 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.02.19 20:15:41 | 000,193,401 | ---- | M] () -- C:\Users\geraldo\Documents\Das Erleben u. bew. einer Koronarintervention.pdf ========== Files Created - No Company Name ========== [2013.03.11 17:48:11 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.03.11 17:48:11 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.03.11 17:48:11 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.03.11 17:48:11 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.03.11 17:48:11 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.03.11 17:33:52 | 000,000,400 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat [2013.03.10 14:39:47 | 000,377,856 | ---- | C] () -- C:\Users\geraldo\Desktop\hskobdf1.exe [2013.03.10 14:14:45 | 000,000,168 | ---- | C] () -- C:\Users\geraldo\defogger_reenable [2013.03.10 14:05:25 | 000,377,856 | ---- | C] () -- C:\Users\geraldo\Desktop\b6j43ent.exe [2013.03.09 14:29:22 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk [2013.03.09 13:33:12 | 322,961,408 | ---- | C] () -- C:\Users\geraldo\Desktop\pmagic_2013_02_28.iso [2013.03.09 13:29:54 | 001,160,893 | ---- | C] () -- C:\Users\geraldo\Desktop\ProcessExplorer.zip [2013.03.09 00:06:34 | 000,074,126 | ---- | C] () -- C:\ProgramData\gqcbupulgcceydk [2013.03.06 22:22:33 | 000,001,404 | ---- | C] () -- C:\Users\geraldo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk [2013.03.06 22:22:33 | 000,001,404 | ---- | C] () -- C:\Users\geraldo\Desktop\Games.lnk [2013.02.26 18:33:22 | 014,018,244 | ---- | C] () -- C:\Users\geraldo\Desktop\hurensohn.wav [2013.02.24 13:23:06 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.02.24 13:23:05 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.02.19 20:15:20 | 000,193,401 | ---- | C] () -- C:\Users\geraldo\Documents\Das Erleben u. bew. einer Koronarintervention.pdf [2013.02.17 13:46:40 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2012.11.17 13:20:03 | 000,282,296 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2012.11.17 13:20:02 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2012.11.17 13:20:02 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2012.07.06 20:10:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2012.07.06 19:31:05 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe [2012.07.06 17:35:37 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini [2012.07.06 17:35:37 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini [2012.07.06 17:35:37 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini [2012.07.06 17:35:26 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2012.07.06 17:35:26 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2012.07.06 17:29:03 | 013,356,032 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll [2012.07.06 17:29:03 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2012.07.06 17:29:03 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2012.07.06 17:29:03 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2012.07.06 17:29:03 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2012.06.11 17:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012.06.11 17:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012.05.10 15:35:16 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2011.09.12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.09.04 15:53:15 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\A1 Servicecenter [2012.10.26 14:41:34 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Antares [2012.12.02 22:07:59 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DAEMON Tools Lite [2012.07.06 17:39:06 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DeviceVm [2012.10.23 21:36:32 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\DVDVideoSoft [2012.11.02 13:04:46 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\EurekaLog [2012.07.14 15:33:24 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\F4 [2012.10.10 09:54:37 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Image-Line [2012.07.19 14:18:06 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\LolClient [2012.09.04 15:46:56 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\mquadr.at [2012.10.23 18:24:28 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\OpenOffice.org [2012.07.06 17:45:58 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Opera [2012.10.18 15:45:00 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Publish Providers [2012.10.18 15:44:50 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\Sony [2013.03.09 13:17:12 | 000,000,000 | ---D | M] -- C:\Users\geraldo\AppData\Roaming\TS3Client ========== Purity Check ========== < End of report > |
18.03.2013, 16:08 | #12 |
/// TB-Ausbilder | GVU Fragezeichen? Servus, bitte beantworte mir die folgenden Fragen, bevor wir weitermachen: Wie läuft dein Rechner derzeit? Gibt es noch Probleme mit Malware? Wenn ja, welche? |
18.03.2013, 16:48 | #13 |
| GVU Fragezeichen? Also mein Rechner läuft normal. So wie davor, es gibt kein Fenster(Welches beim GVU auftritt) mehr nach dem Startup, die Leistung sollte die selbe sein. Mit Maleware gibts eigentlich keine ersichtlichen Probleme. PS: Sry dass ich so spät geantwortet habe, aber ging leider nicht früher. |
18.03.2013, 16:55 | #14 |
/// TB-Ausbilder | GVU Fragezeichen? Servus, wir entfernen noch ein paar Reste und kontrollieren alles: Schritt 1 Fixen mit OTL
Code:
ATTFilter :OTL O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\geraldo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found [2013.03.11 17:33:57 | 000,000,400 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat [2013.03.09 00:06:50 | 000,074,126 | ---- | M] () -- C:\ProgramData\gqcbupulgcceydk :commands [Emptytemp]
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
20.03.2013, 15:55 | #15 |
| GVU Fragezeichen? hey, kann ich später darauf antworten? aufgrund von komplikationen musste ich nochmal operiert werden, wahrscheinlich komm ich erst am WE raus, und meine freundin ist damit völlig überfordert. |
Themen zu GVU Fragezeichen? |
.dll, beenden, bekannte, booten, exe, explorer, fenster, folge, folgendes, fragezeichen, gefunde, guten, heute, malwarebytes, nicht schließen, process, prozess, schließe, schließen, starte, taskma, taskmanager, trojan.eofail, wpbt0.dll, öffnet |