Plagegeister aller Art und deren Bekämpfung: BKA-Trojaner auf Vista-32bit PC mit XP als 2. BS
![]() ![]() | ![]() BKA-Trojaner auf Vista-32bit PC mit XP als 2. BS Hallo zusammen, Habe seit kurzem einen BKA-Trojaner auf meinem PC. Es kam das bekannte Bild mit der Aufforderung,100€ zu zahlen.Kein Zugriff mehr auf den Rechner über Vista. Beim Neustart nur noch white screen. Glücklicherweise habe ich auch XP auf dem Rechner und kann evtl darüber zugreifen, nach einem Neustart kann ich zw. den BS auswählen. Vista läuft nicht. Leider lieferten auch alle Scans mit Antiviren-SW (AVIRA, usw.) und auch Kaspersky-rescue nichts. Auch in der registry konnte ich keine Einträge finden (unter HKEYLOCALMACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon steht “explorer.exe”). Auch Foren, wie gutefrage.net, chip.de, computerbase.de/forum, usw. konnten bisher nicht helfen. Leider habe ich zurzeit auch keinen Internetzugang mehr auf dem PC, wurde durch Trojaner lahmgelegt. ![]() Wer kann mir hier helfen? ############################################### Hier das txt-logfile von malware, ich habe nur Suchlauf gemacht und noch nichts gelöscht: Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2012.12.14.11 Windows Vista Service Pack 2 x86 NTFS (Abgesichertenmodus) Internet Explorer 9.0.8112.16421 MrM :: MRM-PC [Administrator] 20.03.2013 18:46:08 mbam-log-2013-03-20 (18-46-08).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 690621 Laufzeit: 1 Stunde(n), 41 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|shell (Trojan.Agent.RNS) -> Daten: explorer.exe,C:\Users\MrM\AppData\Roaming\skype.dat -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 5 C:\Users\MrM\XP statt Vista\RemoveWGA.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt. C:\Users\MrM\XP statt Vista\RemoveWGA12.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt. D:\MrM\XP statt Vista\RemoveWGA.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt. D:\MrM\XP statt Vista\RemoveWGA12.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt. C:\Users\MrM\AppData\Roaming\skype.dat (Trojan.Agent) -> Keine Aktion durchgeführt. /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() BKA-Trojaner auf Vista-32bit PC mit XP als 2. BS Hallo MrMaho und
__________________![]() Mein Name ist Leo und ich werde dich durch die Bereinigung deines Rechners begleiten. Eine Bereinigung beinhaltet nebst dem Entfernen von Malware auch das Schliessen von Sicherheitslücken und sollte gründlich durchgeführt werden. Sie erfolgt deshalb in mehreren Schritten und bedeutet einigen Aufwand für dich. Beachte: Das Verschwinden der offensichtlichen Symptome bedeutet nicht, dass das System schon sauber ist. Arbeite daher in deinem eigenen Interesse solange mit, bis du das OK bekommst, dass alles erledigt ist. ![]()
![]() Zitat:
Schritt 1
Ab hier wieder im normalen Modus: Schritt 2 Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
Schritt 3 Warnung für Mitleser: Combofix sollte nur dann ausgeführt werden, wenn dies explizit von einem Teammitglied angewiesen wurde! Downloade dir bitte Combofix.
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
Schritt 4 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ |
![]() ![]() | ![]() BKA-Trojaner auf Vista-32bit PC mit XP als 2. BS Hier der txt-file vo Malwarebytes:
__________________Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2012.12.14.11 Windows Vista Service Pack 2 x86 NTFS (Abgesichertenmodus) Internet Explorer 9.0.8112.16421 MrM :: MRM-PC [Administrator] 21.03.2013 17:33:38 mbam-log-2013-03-21 (17-33-38).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 233853 Laufzeit: 4 Minute(n), 28 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|shell (Trojan.Agent.RNS) -> Daten: explorer.exe,C:\Users\MrM\AppData\Roaming\skype.dat -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\MrM\AppData\Roaming\skype.dat (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) ################################################## Juhuuu: PC startet wieder ..... ![]() .... (fast) "normal", nur sieht immer noch alles (Taskleiste, Arbeitsplatz usw.) irgendwie "komisch" aus. Also nicht meine Einstellungen - meine ich. ![]() PS: Internet geht noch immer nicht .... und das Windows Sicherheits-Center funktioniert auch (noch) nicht :-( ################################################### hier das logfile von adwcleaner: AdwCleaner Logfile: Code:
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux8"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2012-10-11 20:56 59280 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt] 2012-08-09 14:53 348664 ----a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe] 2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EnergySettings] 2008-09-19 09:44 113664 ----a-w- c:\program files\Fujitsu Siemens Computers\Energy Settings\EnergySettings.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google EULA Launcher] 2008-05-28 11:40 20480 ----a-w- c:\program files\Google\Google EULA\GoogleEULALauncher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon] 2007-04-26 15:54 774168 ----a-w- c:\program files\Common Files\Logitech\LCD Manager\LCDMon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint] 2012-12-12 09:28 163000 ----a-w- c:\program files\PDF24\pdf24.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2012-10-25 02:12 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] 2004-11-02 19:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2008-08-27 15:55 6281760 ----a-w- c:\windows\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr] 2008-04-14 05:19 536576 ----a-w- c:\windows\Samsung\PanelMgr\SSMMgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-07-03 07:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] 2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management] 2007-05-31 08:21 648072 ----a-w- c:\windows\WindowsMobile\wmdcBase.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-03-06 21:28 1630672 ----a-w- c:\program files\Google\Chrome\Application\25.0.1364.152\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-11-23 09:11] . 2013-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-11-23 09:11] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = about:blank mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: DhcpNameServer = FF - ProfilePath - c:\users\MrM\AppData\Roaming\Mozilla\Firefox\Profiles\6sbpq4ea.default\ FF - prefs.js: browser.search.selectedEngine - FF - ExtSQL: 2013-03-10 11:41; FFPDFArchitectConverter@pdfarchitect.com; c:\program files\PDF Architect\FFPDFArchitectExt . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{3bbd3c14-4c16-4989-8366-95bc9179779d} - (no file) WebBrowser-{3BBD3C14-4C16-4989-8366-95BC9179779D} - (no file) HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe HKU-Default-Run-fsc-reg - c:\fsc-reg\fscreg.exe SafeBoot-WudfPf SafeBoot-WudfRd . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-03-23 15:16 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\BFE] "ImagePath"="." . [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MpsSvc] "ImagePath"="." . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\conime.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE . ************************************************************************** . Zeit der Fertigstellung: 2013-03-23 15:21:57 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-03-23 14:21 . Vor Suchlauf: 17 Verzeichnis(se), Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 29.595.885.568 Bytes frei . - - End Of File - - 5BF3106B1FDB91C0083EA7079C68AC81 ######################################################## und zum schluss noch OTL.txt: OTL Logfile: Code:
ATTFilter OTL logfile created on: 23.03.2013 15:27:16 - Run 2 OTL by OldTimer - Version Folder = C:\Users\MrM\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,31 Gb Available Physical Memory | 77,15% Memory free 6,19 Gb Paging File | 5,76 Gb Available in Paging File | 93,05% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 153,63 Gb Total Space | 27,64 Gb Free Space | 17,99% Space Free | Partition Type: NTFS Drive D: | 303,34 Gb Total Space | 132,59 Gb Free Space | 43,71% Space Free | Partition Type: NTFS Computer Name: MRM-PC | User Name: MrM | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.03.20 21:16:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\MrM\Desktop\OTL.exe PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe ========== Modules (No Company Name) ========== MOD - [2010.07.04 22:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll MOD - [2008.09.16 19:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (MpsSvc) SRV - File not found [On_Demand | Stopped] -- -- (BFE) SRV - [2013.01.09 17:36:06 | 000,795,208 | ---- | M] (pdfforge GbR) [Disabled | Stopped] -- C:\Program Files\PDF Architect\ConversionService.exe -- (PDF Architect Service) SRV - [2013.01.09 17:34:26 | 001,324,104 | ---- | M] (pdfforge GbR) [Disabled | Stopped] -- C:\Program Files\PDF Architect\HelperService.exe -- (PDF Architect Helper Service) SRV - [2013.01.08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.12.29 11:26:54 | 001,260,472 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.12.29 02:53:20 | 000,383,416 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.05.08 19:34:47 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.05.08 19:34:41 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.04.27 14:01:16 | 000,314,368 | ---- | M] (Uwe Sieber - www.uwe-sieber.de) [Disabled | Stopped] -- C:\Users\MrM\Desktop\USBDLM\USBDLM.exe -- (USBDLM) SRV - [2009.01.02 20:14:28 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2008.12.18 13:21:16 | 000,341,264 | ---- | M] (Fujitsu Siemens Computers) [Disabled | Stopped] -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2008.01.21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007.05.31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007.05.31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) SRV - [2006.12.14 17:00:00 | 000,544,768 | ---- | M] (Magix AG) [Disabled | Stopped] -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- (UPnPService) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev) DRV - File not found [Kernel | Boot | Stopped] -- system32\drivers\TfSysMon.sys -- (TfSysMon) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\TfNetMon.sys -- (TfNetMon) DRV - File not found [Kernel | Boot | Stopped] -- system32\drivers\TfFsMon.sys -- (TfFsMon) DRV - File not found [File_System | On_Demand | Stopped] -- -- (StarOpen) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\nmwcdnsu.sys -- (nmwcdnsu) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\MrM\AppData\Local\Temp\mbr.sys -- (mbr) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\FsUsbExDisk.SYS -- (FsUsbExDisk) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbnet.sys -- (ewusbnet) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwrchid.sys -- (btwrchid) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwavdt.sys -- (btwavdt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio) DRV - [2012.12.29 11:26:54 | 008,904,632 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012.05.08 19:34:48 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.05.08 19:34:48 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2011.02.08 11:46:58 | 000,673,792 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hcw66xxx.sys -- (hcw66xxx) DRV - [2010.11.25 06:59:16 | 000,541,800 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL8192su.sys -- (RTL8192su) DRV - [2010.10.22 02:00:00 | 000,586,752 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fwlanusbn.sys -- (fwlanusbn) DRV - [2010.10.22 02:00:00 | 000,004,352 | R--- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avmeject.sys -- (avmeject) DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2010.01.09 00:42:40 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss) DRV - [2009.04.11 05:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb) DRV - [2008.11.11 15:05:18 | 000,003,768 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SndTVideo.sys -- (SndTVideo) DRV - [2008.11.11 15:05:16 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SndTAudio.sys -- (SndTAudio) DRV - [2008.07.22 09:21:08 | 000,015,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu) DRV - [2008.07.08 02:32:52 | 001,050,656 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD) DRV - [2008.05.27 12:55:54 | 000,173,576 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ahcix86s.sys -- (ahcix86s) DRV - [2008.04.03 13:58:46 | 000,076,688 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID) DRV - [2008.01.10 02:34:43 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT) DRV - [2008.01.10 02:34:42 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\DGIVECP.SYS -- (DgiVecp) DRV - [2007.12.11 09:52:12 | 000,026,784 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tbhsd.sys -- (tbhsd) DRV - [2007.04.24 17:52:10 | 000,016,688 | ---- | M] (IBM) [Kernel | System | Running] -- C:\Windows\System32\drivers\LUMDriver.sys -- (LUMDriver) DRV - [2006.02.17 20:34:24 | 000,083,344 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k510obex.sys -- (k510obex) DRV - [2006.02.17 20:34:22 | 000,085,408 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k510mgmt.sys -- (k510mgmt) DRV - [2006.02.17 20:34:17 | 000,094,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k510mdm.sys -- (k510mdm) DRV - [2006.02.17 20:34:15 | 000,008,336 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k510mdfl.sys -- (k510mdfl) DRV - [2006.02.17 20:34:10 | 000,058,288 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k510bus.sys -- (k510bus) DRV - [2005.10.28 04:38:18 | 000,402,432 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZD1211BU.sys -- (ZD1211BU(ZyDAS) DRV - [2004.10.25 12:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZDPSp50.sys -- (ZDPSp50) DRV - [2004.05.02 09:47:08 | 000,023,040 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\GVCplDrv.sys -- (GVCplDrv) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FUJC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\..\SearchScopes\{1993C63F-2963-4CC7-9B04-BAE0986821CE}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms} IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FUJC IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.openintab: true FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4 FF - prefs.js..extensions.enabledItems: sammelfreund@webmiles.de:1.12 FF - prefs.js..extensions.enabledItems: firefox1@myibay.com:1.1.8 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: FF - prefs.js..extensions.enabledItems: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f}: FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: engine@conduit.com: FF - prefs.js..extensions.enabledItems: {f4e6547e-325b-403c-a3bb-ad29ed37a92f}: FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.01.08 15:04:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files\PDF Architect\FFPDFArchitectExt [2013.03.10 11:41:00 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.09 09:23:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.01.05 13:31:18 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2013.01.05 13:31:18 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files\Mozilla Sunbird\plugins [2012.10.22 18:56:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MrM\AppData\Roaming\mozilla\Extensions [2012.03.05 23:13:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MrM\AppData\Roaming\mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28} [2013.03.08 17:07:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MrM\AppData\Roaming\mozilla\Firefox\Profiles\6sbpq4ea.default\extensions [2013.02.24 10:55:21 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\MrM\AppData\Roaming\mozilla\Firefox\Profiles\6sbpq4ea.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012.12.16 11:15:03 | 000,000,000 | ---D | M] (SaveByclick) -- C:\Users\MrM\AppData\Roaming\mozilla\Firefox\Profiles\6sbpq4ea.default\extensions\50cd9c8a1087a@50cd9c8a108b4.com [2012.03.05 23:13:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MrM\AppData\Roaming\mozilla\Sunbird\Profiles\v4xtg7wk.default\extensions [2013.03.08 17:07:58 | 000,538,938 | ---- | M] () (No name found) -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\extensions\toolbar@web.de.xpi [2012.11.30 22:21:31 | 000,077,690 | ---- | M] () (No name found) -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}.xpi [2012.08.30 19:48:29 | 000,002,209 | ---- | M] () -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\searchplugins\englische-ergebnisse.xml [2012.08.30 19:48:29 | 000,010,506 | ---- | M] () -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\searchplugins\gmx-suche.xml [2009.10.29 01:00:16 | 000,000,950 | ---- | M] () -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\searchplugins\icqplugin-4.xml [2012.08.30 19:48:29 | 000,002,368 | ---- | M] () -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\searchplugins\lastminute.xml [2012.08.30 19:48:29 | 000,005,489 | ---- | M] () -- C:\Users\MrM\AppData\Roaming\mozilla\firefox\profiles\6sbpq4ea.default\searchplugins\webde-suche.xml [2013.03.23 14:56:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2009.08.12 17:08:47 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2013.03.09 09:23:22 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.07.12 17:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012.06.09 17:21:44 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.10.01 06:14:06 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.06.09 17:21:44 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.06.09 17:21:44 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.06.09 17:21:44 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.06.09 17:21:44 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: facemoods (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = CHR - homepage: hxxp://www.google.com CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.152\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll CHR - plugin: DNA Plug-in (Enabled) = C:\Program Files\DNA\plugins\npbtdna.dll CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Windows\system32\npDeployJava1.dll CHR - Extension: Google Drive = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Google-Suche = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\\ CHR - Extension: Google Mail = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ CHR - Extension: Google Drive = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Google-Suche = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\\ CHR - Extension: Google Mail = C:\Users\MrM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2013.03.23 15:16:02 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found. O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2444975696-2725477063-918493955-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93EE8C1B-E6AA-477C-BCF4-83EB576532FA}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6C9CDA8-C6B7-477D-9E42-8375C52BB421}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CEC4CDDA-2E91-4054-B793-810AF647FA13}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F28C8241-B159-4809-A324-152F55DBB8AE}: DhcpNameServer = O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img35.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img35.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.03.23 15:21:59 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.03.23 15:21:59 | 000,000,000 | ---D | C] -- C:\Users\MrM\AppData\Local\temp [2013.03.23 15:16:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013.03.23 15:02:09 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.03.23 15:02:09 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.03.23 15:02:09 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.03.23 15:01:55 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.03.23 15:01:33 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.03.23 14:56:15 | 005,042,224 | R--- | C] (Swearware) -- C:\Users\MrM\Desktop\ComboFix.exe [2013.03.20 21:23:52 | 000,000,000 | ---D | C] -- C:\Users\MrM\Desktop\log files [2013.03.20 21:18:44 | 000,000,000 | ---D | C] -- C:\Users\MrM\Desktop\Neuer Ordner (2) [2013.03.20 21:18:15 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\MrM\Desktop\OTL.exe [2013.03.20 18:45:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.03.20 18:45:31 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2013.03.20 18:45:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2013.03.10 16:29:08 | 000,000,000 | ---D | C] -- C:\Users\MrM\Desktop\REACh [2013.03.10 11:41:09 | 000,000,000 | ---D | C] -- C:\Users\MrM\Documents\PDF Architect Files [2013.03.10 11:41:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect [2013.03.10 11:40:44 | 000,000,000 | ---D | C] -- C:\Program Files\PDF Architect ========== Files - Modified Within 30 Days ========== [2013.03.23 15:28:16 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.03.23 15:22:02 | 000,628,504 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.03.23 15:22:02 | 000,595,798 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.03.23 15:22:02 | 000,126,248 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.03.23 15:22:02 | 000,103,872 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.03.23 15:16:20 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.23 15:16:19 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.23 15:16:02 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2013.03.23 15:15:54 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.03.23 15:14:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.03.23 14:50:44 | 005,042,224 | R--- | M] (Swearware) -- C:\Users\MrM\Desktop\ComboFix.exe [2013.03.23 14:50:28 | 000,609,993 | ---- | M] () -- C:\Users\MrM\Desktop\adwcleaner.exe [2013.03.20 21:22:36 | 000,050,477 | ---- | M] () -- C:\Users\MrM\Desktop\Defogger.exe [2013.03.20 21:20:49 | 000,130,048 | ---- | M] () -- C:\Users\MrM\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013.03.20 21:17:18 | 000,377,856 | ---- | M] () -- C:\Users\MrM\Desktop\gmer_2.1.19155.exe [2013.03.20 21:16:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\MrM\Desktop\OTL.exe [2013.03.20 18:45:32 | 000,000,878 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.03.20 05:58:03 | 000,410,144 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.03.17 11:49:14 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.03.12 19:45:22 | 000,001,356 | ---- | M] () -- C:\Users\MrM\AppData\Local\d3d9caps.dat [2013.03.10 11:36:08 | 000,009,239 | ---- | M] () -- C:\Users\MrM\Desktop\Zahlungsbeleg -GOLDEN THAI- PayPal.pdf [2013.03.02 10:00:46 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2013.03.02 10:00:46 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2013.02.24 14:09:33 | 000,101,995 | ---- | M] () -- C:\Users\MrM\Desktop\Mode Online Shop - Kleidung - Schuhe - Möbel kaufen BAUR Versand.pdf [2013.02.24 12:41:26 | 000,175,419 | ---- | M] () -- C:\Users\MrM\Desktop\BoardingPassHOECHERLMARIO.pdf [2013.02.23 10:54:13 | 005,109,966 | ---- | M] () -- C:\Users\MrM\Desktop\Neuer Ordner.zip [2013.02.23 10:53:36 | 000,404,996 | ---- | M] () -- C:\Users\MrM\Desktop\kaufvertrag_allgemein[1].pdf ========== Files Created - No Company Name ========== [2013.03.23 15:02:09 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.03.23 15:02:09 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.03.23 15:02:09 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.03.23 15:02:09 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.03.23 15:02:09 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.03.23 14:56:15 | 000,609,993 | ---- | C] () -- C:\Users\MrM\Desktop\adwcleaner.exe [2013.03.20 21:23:41 | 000,050,477 | ---- | C] () -- C:\Users\MrM\Desktop\Defogger.exe [2013.03.20 21:18:15 | 000,377,856 | ---- | C] () -- C:\Users\MrM\Desktop\gmer_2.1.19155.exe [2013.03.20 18:45:32 | 000,000,878 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.03.10 11:36:05 | 000,009,239 | ---- | C] () -- C:\Users\MrM\Desktop\Zahlungsbeleg -GOLDEN THAI- PayPal.pdf [2013.03.03 21:38:38 | 000,869,238 | ---- | C] () -- C:\Users\MrM\Desktop\anwohnerparkausweis.jpg [2013.03.03 21:37:52 | 000,340,736 | ---- | C] () -- C:\Users\MrM\Desktop\fax barclay.pdf [2013.02.24 14:09:35 | 000,101,995 | ---- | C] () -- C:\Users\MrM\Desktop\Mode Online Shop - Kleidung - Schuhe - Möbel kaufen BAUR Versand.pdf [2013.02.24 12:41:26 | 000,175,419 | ---- | C] () -- C:\Users\MrM\Desktop\BoardingPassHOECHERLMARIO.pdf [2013.02.23 10:54:08 | 005,109,966 | ---- | C] () -- C:\Users\MrM\Desktop\Neuer Ordner.zip [2013.02.23 10:53:35 | 000,404,996 | ---- | C] () -- C:\Users\MrM\Desktop\kaufvertrag_allgemein[1].pdf [2013.01.13 11:19:04 | 000,106,574 | ---- | C] () -- C:\Users\MrM\attachment.pdf [2012.12.21 16:37:31 | 000,426,370 | ---- | C] () -- C:\Users\MrM\perso_vo.jpg [2012.12.21 16:37:31 | 000,400,394 | ---- | C] () -- C:\Users\MrM\perso_ru.jpg [2012.12.15 10:19:19 | 000,000,138 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc [2011.10.03 10:23:34 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE [2011.10.02 18:02:07 | 000,015,565 | ---- | C] () -- C:\Windows\System32\drivers\fwlanusbn.bin [2011.10.01 21:49:40 | 000,028,672 | ---- | C] () -- C:\Windows\System32\InsDrvZD.dll [2011.10.01 21:49:40 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ZyDelReg.exe [2011.10.01 21:49:40 | 000,015,872 | ---- | C] () -- C:\Windows\System32\InsDrvZD64.DLL [2011.10.01 21:49:40 | 000,013,312 | ---- | C] () -- C:\Windows\System32\VistaRundll.exe [2011.08.28 19:17:36 | 000,004,447 | ---- | C] () -- C:\Windows\HCWPNP.INI [2011.06.20 18:31:14 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011.04.22 10:33:10 | 000,163,840 | ---- | C] () -- C:\Windows\System32\12kUBusd.dll [2011.04.22 10:28:26 | 000,000,000 | ---- | C] () -- C:\Windows\UI.INI [2011.02.26 09:39:45 | 001,456,640 | ---- | C] () -- C:\Program Files\Common Files\Falk Navi-Manager.msi [2010.08.15 19:06:46 | 000,000,205 | ---- | C] () -- C:\Users\MrM\AppData\Roaming\mdbu.bin [2010.04.10 11:59:05 | 000,001,356 | ---- | C] () -- C:\Users\MrM\AppData\Local\d3d9caps.dat [2010.03.13 10:58:00 | 001,029,272 | ---- | C] () -- C:\Users\MrM\Ein Geld Kleid.pdf [2010.02.18 19:24:14 | 000,310,593 | ---- | C] () -- C:\Users\MrM\Toyota Avensis Forum Old...pdf [2010.02.04 00:10:38 | 002,003,705 | ---- | C] () -- C:\Users\MrM\Migraenekalender.pdf [2010.02.03 23:57:03 | 001,932,534 | ---- | C] () -- C:\Users\MrM\netdoktor-kopfschmerzkalender.pdf [2009.12.19 22:16:11 | 000,000,148 | ---- | C] () -- C:\Users\MrM\AppData\Roaming\AVSMediaPlayer.m3u [2009.12.13 20:51:58 | 000,001,383 | ---- | C] () -- C:\Users\MrM\remove_WGA.rtf [2009.10.22 06:25:12 | 000,127,663 | ---- | C] () -- C:\Users\MrM\img177.jpg [2009.10.22 06:25:12 | 000,125,090 | ---- | C] () -- C:\Users\MrM\img178.jpg [2009.10.20 22:09:32 | 003,680,024 | ---- | C] () -- C:\Users\MrM\blechumformung.pdf [2009.10.20 22:08:01 | 000,278,293 | ---- | C] () -- C:\Users\MrM\umform-grundlagen.pdf [2009.10.20 22:07:53 | 002,263,047 | ---- | C] () -- C:\Users\MrM\umformen_allg.pdf [2009.10.20 11:16:16 | 000,085,672 | ---- | C] () -- C:\Users\MrM\bar hemingway_stralsund_cocktails.pdf [2009.07.01 18:17:40 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib [2009.03.22 21:29:58 | 000,201,071 | ---- | C] () -- C:\Users\MrM\impfen_impfbuch.pdf [2009.03.22 21:29:58 | 000,087,623 | R--- | C] () -- C:\Users\MrM\liniennetz_tschech.pdf [2009.03.22 21:29:58 | 000,032,980 | ---- | C] () -- C:\Users\MrM\service.gmx.pdf [2008.12.31 02:28:08 | 000,130,048 | ---- | C] () -- C:\Users\MrM\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== Alternate Data Streams ========== @Alternate Data Stream - /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() BKA-Trojaner auf Vista-32bit PC mit XP als 2. BS Hi, dann das: Schritt 1 Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinen Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers. Schritt 2 Downloade dir bitte Farbars Service Scanner und speichere es auf den Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
The ServiceDll of Dnscache service is OK. Checking LEGACY_Dnscache: ATTENTION!=====> Unable to open LEGACY_Dnscache\0000 registry key. The key does not exist. Dhcp Service is not running. Checking service configuration: The start type of Dhcp service is set to Disabled. The default start type is Auto. The ImagePath of Dhcp: "%SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted". The ServiceDll of Dhcp service is OK. Checking LEGACY_Dhcp: ATTENTION!=====> Unable to open LEGACY_Dhcp\0000 registry key. The key does not exist. IpSec Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open IpSec registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open IpSec registry key. The service key does not exist. Checking LEGACY_IpSec: ATTENTION!=====> Unable to open LEGACY_IpSec\0000 registry key. The key does not exist. Connection Status: ============== Attempt to access Local Host IP returned error: Localhost is blocked: Other errors LAN connected. Attempt to access Google IP returned error. Other errors Attempt to access Google.com returned error: Other errors Attempt to access Yahoo IP returned error. Other errors Attempt to access Yahoo.com returned error: Other errors Windows Firewall: ============= sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is OK. The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK. Checking LEGACY_sharedaccess: ATTENTION!=====> Unable to open LEGACY_sharedaccess\0000 registry key. The key does not exist. netman Service is not running. Checking service configuration: The start type of netman service is set to Disabled. The default start type is 3. The ImagePath of netman: "%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted". The ServiceDll of netman service is OK. Checking LEGACY_netman: ATTENTION!=====> Unable to open LEGACY_netman\0000 registry key. The key does not exist. Firewall Disabled Policy: ================== System Restore: ============ Srservice Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open Srservice registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open Srservice registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open Srservice registry key. The service key does not exist. Checking LEGACY_Srservice: ATTENTION!=====> Unable to open LEGACY_Srservice\0000 registry key. The key does not exist. sr Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open sr registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open sr registry key. The service key does not exist. Checking LEGACY_sr: ATTENTION!=====> Unable to open LEGACY_sr\0000 registry key. The key does not exist. System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ BITS Service is not running. Checking service configuration: The start type of BITS service is set to Demand. The default start type is Auto. The ImagePath of BITS service is OK. The ServiceDll of BITS service is OK. Checking LEGACY_BITS: ATTENTION!=====> Unable to open LEGACY_BITS\0000 registry key. The key does not exist. EventSystem Service is not running. Checking service configuration: The start type of EventSystem service is set to Disabled. The default start type is 3. The ImagePath of EventSystem: "%SystemRoot%\system32\svchost.exe -k LocalService". The ServiceDll of EventSystem service is OK. Checking LEGACY_EventSystem: ATTENTION!=====> Unable to open LEGACY_EventSystem\0000 registry key. The key does not exist. Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\netbt.sys [2009-05-28 19:02] - [2009-04-11 05:45] - 0185856 ____A (Microsoft Corporation) ECD64230A59CBD93C85F1CD1CAB9F3F6 C:\Windows\system32\Drivers\tcpip.sys [2013-02-13 19:49] - [2013-01-04 12:28] - 0905576 ____A (Microsoft Corporation) 74E2D020C47BB2B2FCCBA29A518A7EB4 ATTENTION!=====> C:\Windows\system32\Drivers\ipsec.sys FILE IS MISSING AND SHOULD BE RESTORED. C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\ipnathlp.dll [2008-01-21 03:24] - [2008-01-21 03:24] - 0288256 ____A (Microsoft Corporation) E1499BD0FF76B1B2FBBF1AF339D91165 C:\Windows\system32\netman.dll [2008-01-21 03:24] - [2008-01-21 03:24] - 0274432 ____A (Microsoft Corporation) C8052711DAECC48B982434C5116CA401 C:\Windows\system32\wbem\WMIsvc.dll [2009-05-28 19:02] - [2009-04-11 07:28] - 0162304 ____A (Microsoft Corporation) 6B2A1D0E80110E3D04E6863C6E62FD8A ATTENTION!=====> C:\Windows\system32\srsvc.dll FILE IS MISSING AND SHOULD BE RESTORED. ATTENTION!=====> C:\Windows\system32\Drivers\sr.sys FILE IS MISSING AND SHOULD BE RESTORED. C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit ATTENTION!=====> C:\Windows\system32\wuauserv.dll FILE IS MISSING AND SHOULD BE RESTORED. C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\services.exe [2009-05-28 19:02] - [2009-04-11 07:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B Extra List: ======= RFCOMM(10) Smb(9) Tcpip(3) Tcpip6(8) tdx(4) 0x0B0000000500000001000000020000000300000004000000060000000700000008000000090000000A0000000B000000 ATTENTION!=====> IpSec Tag value should be 5. ATTENTION!=====> IpSec Tag value is missing and it should be 5. **** End of log **** Geändert von MrMaho (23.03.2013 um 20:13 Uhr) |
Schritt 2
Bitte poste in deiner nächsten Antwort:
__________________ --> BKA-Trojaner auf Vista-32bit PC mit XP als 2. BS |
__________________ cheers, Leo |
![]() Wie läuft das Vista jetzt? Noch Probleme?
Wie läuft das Vista jetzt? Noch Probleme?
__________________ cheers, Leo |
Hier die OTL.txt:
