|
Log-Analyse und Auswertung: GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit EingabeaufforderungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
20.04.2013, 19:41 | #16 |
/// TB-Ausbilder | GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Und die andere Datei?
__________________ cheers, Leo |
20.04.2013, 19:52 | #17 |
| GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung So hier bitte :
__________________https://www.virustotal.com/de/file/36ad87b380baa11b2fac2f9ddad37b45b944f00061af4cf912ce34e953c6d29e/analysis/1366483654/ |
20.04.2013, 20:00 | #18 |
/// TB-Ausbilder | GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Ok.
__________________Schritt 1
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ |
20.04.2013, 20:20 | #19 |
| GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Log von OTL: Code:
ATTFilter OTL logfile created on: 20.04.2013 21:10:37 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Aga\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,25 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 61,44% Memory free 6,69 Gb Paging File | 5,46 Gb Available in Paging File | 81,61% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 698,63 Gb Total Space | 443,72 Gb Free Space | 63,51% Space Free | Partition Type: NTFS Computer Name: MARCIN-PC | User Name: Aga | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.20 15:52:05 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2013.04.20 15:51:40 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2013.04.20 15:51:36 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2013.04.20 15:51:35 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.04.20 00:01:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Aga\Desktop\OTL.exe PRC - [2013.04.13 16:16:12 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2013.02.26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2013.01.18 16:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2013.01.18 16:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe PRC - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.10 18:29:46 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012.12.10 18:29:44 | 001,435,568 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe PRC - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2009.08.18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2009.04.10 23:28:16 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE PRC - [2009.04.10 23:28:04 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2008.01.21 04:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe ========== Modules (No Company Name) ========== MOD - [2013.04.13 16:16:12 | 003,133,336 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - [2013.04.20 15:52:05 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.04.20 15:51:36 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013.04.13 16:16:12 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.04.10 14:05:09 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.02.26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.12.10 18:29:44 | 001,435,568 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012.10.04 12:58:13 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2003.07.28 12:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva397.sys -- (XDva397) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - [2013.04.20 15:52:20 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2013.04.20 15:52:19 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013.04.20 15:52:19 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013.04.20 15:52:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2013.02.26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2011.12.11 15:23:55 | 000,101,376 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV07.sys -- (ACEDRV07) DRV - [2011.09.21 20:21:20 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2009.05.25 08:50:44 | 000,164,864 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2009.03.18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2006.10.18 07:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = hxxp://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = hxxp://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.b1.org/?bsrc=hmior&chid=c167991 IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Before = hxxp://www.google.com IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BF 41 29 60 0C 73 CC 01 [binary data] IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.google.com IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = hxxp://www.dnsbasic.com/?prt=dnsbsc50r1&sp=&keywords={searchTerms} IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{60EE36B1-4EAF-4162-92F9-F6235AB56247}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=fb750bf9-0a1b-4df3-9bbb-48b4b475fe5b&apn_sauid=DC67BF41-828F-4976-82BE-5967EF15BB5C IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF}: "URL" = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p18_serp_ie_de_display?ie=UTF8&tag=bds-p18-serp-de-ie-21&tagbase=bds-p18&tbrId=v1_abb-channel-18_d41eaec6f430451b8967d51d039a34e3_18_38_20121216_DE_ie_ds_OC1&query={searchTerms} IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1001\..\SearchScopes,DefaultScope = ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:1.0.10 FF - prefs.js..extensions.enabledAddons: %7B650EED71-89E2-453B-8DCF-2AA1B4AE6EF3%7D:1.0 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Aga\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Aga\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.13 16:16:12 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.13 16:16:12 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.15 09:40:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\Extensions [2013.04.20 16:21:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\Firefox\Profiles\nycp6mbp.default\extensions [2012.10.12 14:17:26 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Aga\AppData\Roaming\mozilla\Firefox\Profiles\nycp6mbp.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2013.03.23 16:08:06 | 000,502,957 | ---- | M] () (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\extensions\toolbar@gmx.net.xpi [2013.03.25 19:25:14 | 000,213,470 | ---- | M] () (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\extensions\torntv2@torntv.com.xpi [2012.12.16 17:25:32 | 000,002,845 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\amazon-distro.xml [2013.04.20 15:53:52 | 000,002,344 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\askcom.xml [2013.03.03 23:30:12 | 000,001,090 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\dvdvideosofttb-de-customized-web-search.xml [2013.03.07 22:03:26 | 000,002,273 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\englische-ergebnisse.xml [2013.03.07 22:03:26 | 000,010,563 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\gmx-suche.xml [2013.03.07 22:03:26 | 000,002,432 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\lastminute.xml [2013.03.07 22:03:26 | 000,005,545 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\webde-suche.xml [2013.04.20 03:14:18 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.20 03:14:18 | 000,000,000 | ---D | M] (DnsBasic) -- C:\Programme\Mozilla Firefox\extensions\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3} [2013.04.13 16:16:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013.04.13 16:16:08 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2013.04.13 16:16:08 | 000,000,000 | ---D | M] (Modul zur Link-Untersuchung) -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 [2013.04.20 03:14:18 | 000,000,000 | ---D | M] (DnsBasic) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3} [2013.04.13 16:16:12 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2013.03.03 23:29:53 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.03.03 23:29:53 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.03.03 23:29:53 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.09.21 20:20:37 | 000,000,143 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\foxsearch.src [2013.03.03 23:29:53 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.03.03 23:29:53 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.03.03 23:29:53 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://www.google.de/ CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: registryAccess (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo\7.15.9.29524_0\background/registryAccess.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm\10.13.1.89_0\plugins/ConduitChromeApiPlugin.dll CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm\10.13.1.89_0\plugins/np-cwmp.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Google Update (Enabled) = C:\Users\Aga\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Enabled) = C:\Windows\system32\npDeployJava1.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: Battlefield Heroes = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0\ CHR - Extension: Adblock Plus = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\ O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found. O3 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\Toolbar\WebBrowser: (no name) - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No CLSID value found. O3 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000..\Run: [RMF FM Miasto Muzyki] File not found O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000..\Run: [RMFon] File not found O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1001..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Aga\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5FB1D97C-81D0-47AC-8246-4B2758E92BF3}: DhcpNameServer = 7.254.254.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE72C859-98BF-4B4B-B736-43AD1E2D6359}: DhcpNameServer = 192.168.2.1 192.168.1.100 O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000 Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Aga\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Aga\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{411a3a26-e479-11e0-97f2-90e6ba694f59}\Shell - "" = AutoRun O33 - MountPoints2\{411a3a26-e479-11e0-97f2-90e6ba694f59}\Shell\AutoRun\command - "" = E:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.04.20 21:10:10 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\PC [2013.04.20 15:59:33 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Avira [2013.04.20 15:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2013.04.20 15:53:20 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Local\APN [2013.04.20 15:53:07 | 000,135,136 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2013.04.20 15:53:07 | 000,084,744 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2013.04.20 15:53:07 | 000,037,352 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2013.04.20 15:53:07 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2013.04.20 15:53:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2013.04.20 15:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2013.04.20 03:09:33 | 000,000,000 | ---D | C] -- C:\Program Files\DnsBasic [2013.04.20 02:38:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Aga\Desktop\OTL.exe [2013.04.19 23:24:56 | 000,000,000 | -HSD | C] -- C:\found.000 [2013.04.18 18:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.15 21:08:47 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\Neuer Ordner (2) [2013.04.14 22:41:55 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Mael [2013.04.14 22:32:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor [2013.04.14 22:32:30 | 000,000,000 | ---D | C] -- C:\Program Files\HxD [2013.04.14 22:30:31 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bruteforce Save Data [2013.04.14 22:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Bruteforce Save Data [2013.04.14 22:11:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bruteforce Save Data [2013.04.14 21:47:04 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\Neuer Ordner [2013.04.13 16:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.10 16:40:39 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\dvdcss [2013.04.10 16:34:29 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\mama [2013.03.26 14:46:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aerosoft [2013.03.25 22:39:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.2 [2013.03.25 22:39:54 | 000,000,000 | ---D | C] -- C:\Program Files\Cheat Engine 6.2 [2013.03.25 18:42:31 | 000,000,000 | ---D | C] -- C:\Program Files\Aerosoft [2013.03.25 16:18:07 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Local\B1E [2013.03.25 16:18:00 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\B1Toolbar [2013.03.24 21:44:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2013.03.24 21:14:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.03.24 21:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.03.22 15:06:58 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\.minecraft ========== Files - Modified Within 30 Days ========== [2013.04.20 21:13:09 | 000,686,552 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.04.20 21:13:09 | 000,631,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.04.20 21:13:09 | 000,149,292 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.04.20 21:13:09 | 000,118,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.04.20 21:08:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.04.20 21:05:32 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.20 21:05:32 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.20 21:05:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.20 21:05:23 | 3488,735,232 | -HS- | M] () -- C:\hiberfil.sys [2013.04.20 20:16:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-423745193-3980066226-3922103518-1000UA.job [2013.04.20 16:11:17 | 000,139,264 | ---- | M] () -- C:\Users\Aga\Desktop\SystemLook.exe [2013.04.20 15:54:04 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2013.04.20 15:52:20 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2013.04.20 15:52:19 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2013.04.20 15:52:19 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2013.04.20 15:52:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2013.04.20 03:19:44 | 000,000,554 | ---- | M] () -- C:\Users\Aga\Desktop\adw22cleaner - Verknüpfung.lnk [2013.04.20 03:09:35 | 000,000,000 | ---- | M] () -- C:\ProgramData\25282137263c54382a_c [2013.04.20 02:08:01 | 274,468,614 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013.04.20 01:16:19 | 000,000,000 | ---- | M] () -- C:\Users\Aga\defogger_reenable [2013.04.20 01:07:30 | 000,358,800 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.20 00:56:37 | 000,001,356 | ---- | M] () -- C:\Users\Aga\AppData\Local\d3d9caps.dat [2013.04.20 00:01:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Aga\Desktop\OTL.exe [2013.04.19 15:16:00 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-423745193-3980066226-3922103518-1000Core.job [2013.04.10 14:18:40 | 000,002,032 | ---- | M] () -- C:\Users\Aga\Desktop\Google Chrome.lnk [2013.03.26 14:46:13 | 000,000,713 | ---- | M] () -- C:\Users\Public\Desktop\OMSI.lnk [2013.03.26 14:46:10 | 000,000,973 | ---- | M] () -- C:\Users\Public\Desktop\Aerosoft Launcher.lnk [2013.03.25 16:18:07 | 000,000,047 | ---- | M] () -- C:\chid ========== Files Created - No Company Name ========== [2013.04.20 16:40:32 | 000,139,264 | ---- | C] () -- C:\Users\Aga\Desktop\SystemLook.exe [2013.04.20 15:54:04 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2013.04.20 03:19:44 | 000,000,554 | ---- | C] () -- C:\Users\Aga\Desktop\adw22cleaner - Verknüpfung.lnk [2013.04.20 03:09:35 | 000,000,000 | ---- | C] () -- C:\ProgramData\25282137263c54382a_c [2013.04.20 02:08:01 | 274,468,614 | ---- | C] () -- C:\Windows\MEMORY.DMP [2013.04.20 01:16:19 | 000,000,000 | ---- | C] () -- C:\Users\Aga\defogger_reenable [2013.04.20 01:07:22 | 3488,735,232 | -HS- | C] () -- C:\hiberfil.sys [2013.03.26 14:46:13 | 000,000,713 | ---- | C] () -- C:\Users\Public\Desktop\OMSI.lnk [2013.03.26 14:46:10 | 000,000,973 | ---- | C] () -- C:\Users\Public\Desktop\Aerosoft Launcher.lnk [2013.03.25 16:18:07 | 000,000,047 | ---- | C] () -- C:\chid [2011.11.06 13:10:39 | 000,000,004 | ---- | C] () -- C:\Users\Aga\AppData\Roaming\steam_md4.dat [2011.11.04 18:24:17 | 000,017,408 | ---- | C] () -- C:\Users\Aga\AppData\Local\WebpageIcons.db [2011.10.04 15:51:41 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat [2011.09.28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011.09.22 20:10:56 | 000,010,240 | ---- | C] () -- C:\Users\Aga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.09.17 13:28:05 | 000,139,648 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2011.09.17 13:27:40 | 000,282,296 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2011.09.17 13:27:39 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2011.09.16 12:18:47 | 000,138,056 | ---- | C] () -- C:\Users\Aga\AppData\Roaming\PnkBstrK.sys [2011.09.15 10:03:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011.09.14 20:19:48 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011.09.14 18:15:39 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2011.09.14 18:15:01 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2011.09.14 18:15:01 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2011.09.14 17:02:41 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2011.09.14 17:01:48 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys [2011.09.14 17:01:42 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini [2011.09.14 17:01:38 | 000,017,799 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [2011.09.14 17:00:03 | 000,001,356 | ---- | C] () -- C:\Users\Aga\AppData\Local\d3d9caps.dat ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.10 23:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2013.04.14 15:10:18 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\.minecraft [2013.03.25 16:18:00 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\B1Toolbar [2012.10.24 14:58:41 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2012.08.06 17:06:15 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\DAEMON Tools Lite [2012.12.08 13:50:31 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\DVDVideoSoft [2012.11.28 17:02:47 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\go [2012.07.02 12:42:34 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Gutscheinmieze [2012.03.26 19:47:29 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\LolClient [2013.04.14 22:41:55 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Mael [2012.08.01 13:01:03 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Mumble [2012.03.11 12:37:10 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Notepad++ [2012.07.11 12:29:20 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Origin [2012.10.24 14:52:47 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Publish Providers [2012.10.24 18:36:47 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Sony [2013.03.03 23:21:29 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\TS3Client [2011.10.06 17:24:35 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Tunngle [2013.04.20 03:07:58 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\uTorrent [2012.05.26 12:50:54 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\wargaming.net [2012.01.14 20:59:21 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\wxMozBrowserLib ========== Purity Check ========== < End of report > |
20.04.2013, 20:26 | #20 |
/// TB-Ausbilder | GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Gut. Wie läuft der Rechner im Moment? Schritt 1
Code:
ATTFilter :OTL [2013.04.20 03:14:18 | 000,000,000 | ---D | M] (DnsBasic) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3} [2013.04.20 03:14:18 | 000,000,000 | ---D | M] (DnsBasic) -- C:\Programme\Mozilla Firefox\extensions\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3} [2013.04.20 15:53:52 | 000,002,344 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\askcom.xml FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = hxxp://www.dnsbasic.com/?prt=dnsbsc50r1&sp=&keywords={searchTerms} IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{60EE36B1-4EAF-4162-92F9-F6235AB56247}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=fb750bf9-0a1b-4df3-9bbb-48b4b475fe5b&apn_sauid=DC67BF41-828F-4976-82BE-5967EF15BB5C IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.b1.org/?bsrc=hmior&chid=c167991 IE - HKU\S-1-5-18\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = hxxp://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms} IE - HKU\.DEFAULT\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = hxxp://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms} [2013.03.25 16:18:07 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Local\B1E [2013.03.25 16:18:00 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\B1Toolbar [2013.04.20 03:09:33 | 000,000,000 | ---D | C] -- C:\Program Files\DnsBasic :commands [emptytemp]
Schritt 2 Downloade dir bitte Malwarebytes Anti-Malware .
Schritt 3 Lade das Setup des ESET Online Scanners herunter und speichere es auf den Desktop.
Schritt 4 Downloade dir bitte SecurityCheck (Link 2).
Schritt 5 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
21.04.2013, 00:25 | #21 |
| GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Alle 5 Schritte durchgeführt nun poste ich der Reihenfolge nach : Fixlog von OTL Code:
ATTFilter ========== OTL ========== C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3}\defaults\preferences folder moved successfully. C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3}\defaults folder moved successfully. C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3}\chrome folder moved successfully. C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3} folder moved successfully. Folder C:\Programme\Mozilla Firefox\extensions\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3}\ not found. C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\askcom.xml moved successfully. Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "Ask.com" removed from browser.search.defaultenginename Prefs.js: "Ask.com" removed from browser.search.order.1 Registry key HKEY_USERS\S-1-5-21-423745193-3980066226-3922103518-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}\ not found. Registry key HKEY_USERS\S-1-5-21-423745193-3980066226-3922103518-1000\Software\Microsoft\Internet Explorer\SearchScopes\{60EE36B1-4EAF-4162-92F9-F6235AB56247}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60EE36B1-4EAF-4162-92F9-F6235AB56247}\ not found. HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully! Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}\ not found. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}\ not found. C:\Users\Aga\AppData\Local\B1E folder moved successfully. C:\Users\Aga\AppData\Roaming\B1Toolbar folder moved successfully. C:\Program Files\DnsBasic folder moved successfully. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.69.0 log created on 04202013_213119 Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.04.20.09 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Aga :: MARCIN-PC [Administrator] Schutz: Aktiviert 20.04.2013 21:36:34 mbam-log-2013-04-20 (21-36-34).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 224802 Laufzeit: 4 Minute(n), 39 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211101158} (PUP.215Apps) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211101158} (PUP.215Apps) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Aga\Downloads\setup.exe (PUP.BundleInstaller.VG) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter C:\_OTL\MovedFiles\04202013_213119\C_PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{650EED71-89E2-453B-8DCF-2AA1B4AE6EF3}\chrome\dnsbasic.jar Win32/Adware.OneStep application Log von SecurityCheck Code:
ATTFilter Results of screen317's Security Check version 0.99.62 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner JavaFX 2.1.1 Java 7 Update 21 Java version out of Date! Adobe Flash Player 11.7.700.169 Adobe Reader 10.1.6 Adobe Reader out of Date! Mozilla Firefox (20.0.1) Google Chrome 26.0.1410.43 Google Chrome 26.0.1410.64 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Code:
ATTFilter OTL logfile created on: 21.04.2013 00:55:20 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Aga\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,25 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 53,69% Memory free 6,72 Gb Paging File | 5,43 Gb Available in Paging File | 80,85% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 698,63 Gb Total Space | 443,59 Gb Free Space | 63,49% Space Free | Partition Type: NTFS Computer Name: MARCIN-PC | User Name: Aga | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.04.20 15:52:05 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2013.04.20 15:51:40 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2013.04.20 15:51:36 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2013.04.20 15:51:35 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.04.20 00:01:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Aga\Desktop\OTL.exe PRC - [2013.04.13 16:16:12 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2013.02.26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2013.01.18 16:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2013.01.18 16:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe PRC - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.10 18:29:46 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012.12.10 18:29:44 | 001,435,568 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe PRC - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2009.08.18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.10 23:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2008.01.21 04:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe ========== Modules (No Company Name) ========== MOD - [2013.04.13 16:16:12 | 003,133,336 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2011.07.18 23:04:08 | 000,296,448 | ---- | M] () -- C:\Programme\Notepad++\NppShell_04.dll MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll ========== Services (SafeList) ========== SRV - [2013.04.20 15:52:05 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.04.20 15:51:36 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013.04.13 16:16:12 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.04.10 14:05:09 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2013.02.26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.12.10 18:29:44 | 001,435,568 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012.10.04 12:58:13 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2003.07.28 12:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva397.sys -- (XDva397) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Aga\AppData\Local\Temp\pxdiypog.sys -- (pxdiypog) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - [2013.04.20 15:52:20 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2013.04.20 15:52:19 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013.04.20 15:52:19 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013.04.20 15:52:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2013.02.26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2011.12.11 15:23:55 | 000,101,376 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV07.sys -- (ACEDRV07) DRV - [2011.09.21 20:21:20 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2009.05.25 08:50:44 | 000,164,864 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2009.03.18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2006.10.18 07:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Before = hxxp://www.google.com IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BF 41 29 60 0C 73 CC 01 [binary data] IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.google.com IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF}: "URL" = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p18_serp_ie_de_display?ie=UTF8&tag=bds-p18-serp-de-ie-21&tagbase=bds-p18&tbrId=v1_abb-channel-18_d41eaec6f430451b8967d51d039a34e3_18_38_20121216_DE_ie_ds_OC1&query={searchTerms} IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-423745193-3980066226-3922103518-1001\..\SearchScopes,DefaultScope = ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "" FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:1.0.10 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Aga\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Aga\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.13 16:16:12 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.13 16:16:12 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.15 09:40:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\Extensions [2013.04.20 16:21:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\Firefox\Profiles\nycp6mbp.default\extensions [2012.10.12 14:17:26 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Aga\AppData\Roaming\mozilla\Firefox\Profiles\nycp6mbp.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2013.03.23 16:08:06 | 000,502,957 | ---- | M] () (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\extensions\toolbar@gmx.net.xpi [2013.03.25 19:25:14 | 000,213,470 | ---- | M] () (No name found) -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\extensions\torntv2@torntv.com.xpi [2012.12.16 17:25:32 | 000,002,845 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\amazon-distro.xml [2013.03.03 23:30:12 | 000,001,090 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\dvdvideosofttb-de-customized-web-search.xml [2013.03.07 22:03:26 | 000,002,273 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\englische-ergebnisse.xml [2013.03.07 22:03:26 | 000,010,563 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\gmx-suche.xml [2013.03.07 22:03:26 | 000,002,432 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\lastminute.xml [2013.03.07 22:03:26 | 000,005,545 | ---- | M] () -- C:\Users\Aga\AppData\Roaming\mozilla\firefox\profiles\nycp6mbp.default\searchplugins\webde-suche.xml [2013.04.20 21:31:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.13 16:16:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013.04.13 16:16:08 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Programme\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2013.04.13 16:16:08 | 000,000,000 | ---D | M] (Modul zur Link-Untersuchung) -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 [2013.04.13 16:16:12 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2013.03.03 23:29:53 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.03.03 23:29:53 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.03.03 23:29:53 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.09.21 20:20:37 | 000,000,143 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\foxsearch.src [2013.03.03 23:29:53 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.03.03 23:29:53 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.03.03 23:29:53 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR - homepage: hxxp://www.google.de/ CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll CHR - plugin: registryAccess (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo\7.15.9.29524_0\background/registryAccess.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm\10.13.1.89_0\plugins/ConduitChromeApiPlugin.dll CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm\10.13.1.89_0\plugins/np-cwmp.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Google Update (Enabled) = C:\Users\Aga\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Enabled) = C:\Windows\system32\npDeployJava1.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: Battlefield Heroes = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0\ CHR - Extension: Adblock Plus = C:\Users\Aga\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\ O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found. O3 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\Toolbar\WebBrowser: (no name) - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No CLSID value found. O3 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000..\Run: [RMF FM Miasto Muzyki] File not found O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000..\Run: [RMFon] File not found O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found O4 - HKU\S-1-5-21-423745193-3980066226-3922103518-1001..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Aga\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5FB1D97C-81D0-47AC-8246-4B2758E92BF3}: DhcpNameServer = 7.254.254.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE72C859-98BF-4B4B-B736-43AD1E2D6359}: DhcpNameServer = 192.168.2.1 192.168.1.100 O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKU\S-1-5-21-423745193-3980066226-3922103518-1000 Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Aga\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Aga\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{411a3a26-e479-11e0-97f2-90e6ba694f59}\Shell - "" = AutoRun O33 - MountPoints2\{411a3a26-e479-11e0-97f2-90e6ba694f59}\Shell\AutoRun\command - "" = E:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.04.20 21:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2013.04.20 21:48:58 | 002,347,384 | ---- | C] (ESET) -- C:\Users\Aga\Desktop\esetsmartinstaller_enu.exe [2013.04.20 21:35:33 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Malwarebytes [2013.04.20 21:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.04.20 21:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.04.20 21:35:26 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2013.04.20 21:35:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2013.04.20 21:32:56 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\PC rettung [2013.04.20 21:31:19 | 000,000,000 | ---D | C] -- C:\_OTL [2013.04.20 21:10:10 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\PC [2013.04.20 15:59:33 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Avira [2013.04.20 15:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2013.04.20 15:53:20 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Local\APN [2013.04.20 15:53:07 | 000,135,136 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2013.04.20 15:53:07 | 000,084,744 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2013.04.20 15:53:07 | 000,037,352 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2013.04.20 15:53:07 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2013.04.20 15:53:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2013.04.20 15:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2013.04.20 02:38:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Aga\Desktop\OTL.exe [2013.04.19 23:24:56 | 000,000,000 | -HSD | C] -- C:\found.000 [2013.04.18 18:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.04.15 21:08:47 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\Neuer Ordner (2) [2013.04.14 22:41:55 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Mael [2013.04.14 22:32:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor [2013.04.14 22:32:30 | 000,000,000 | ---D | C] -- C:\Program Files\HxD [2013.04.14 22:30:31 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bruteforce Save Data [2013.04.14 22:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Bruteforce Save Data [2013.04.14 22:11:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bruteforce Save Data [2013.04.14 21:47:04 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\Neuer Ordner [2013.04.13 16:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.10 16:40:39 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\dvdcss [2013.04.10 16:34:29 | 000,000,000 | ---D | C] -- C:\Users\Aga\Desktop\mama [2013.03.26 14:46:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aerosoft [2013.03.25 22:39:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.2 [2013.03.25 22:39:54 | 000,000,000 | ---D | C] -- C:\Program Files\Cheat Engine 6.2 [2013.03.25 18:42:31 | 000,000,000 | ---D | C] -- C:\Program Files\Aerosoft [2013.03.24 21:44:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2013.03.24 21:14:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.03.24 21:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.03.22 15:06:58 | 000,000,000 | ---D | C] -- C:\Users\Aga\AppData\Roaming\.minecraft ========== Files - Modified Within 30 Days ========== [2013.04.21 00:48:36 | 000,890,815 | ---- | M] () -- C:\Users\Aga\Desktop\SecurityCheck.exe [2013.04.21 00:16:02 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-423745193-3980066226-3922103518-1000UA.job [2013.04.21 00:08:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.04.20 23:43:36 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.20 23:43:36 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.20 21:49:52 | 000,686,552 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.04.20 21:49:52 | 000,631,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.04.20 21:49:52 | 000,149,292 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.04.20 21:49:52 | 000,118,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.04.20 21:47:31 | 002,347,384 | ---- | M] (ESET) -- C:\Users\Aga\Desktop\esetsmartinstaller_enu.exe [2013.04.20 21:43:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.20 21:43:29 | 3488,735,232 | -HS- | M] () -- C:\hiberfil.sys [2013.04.20 21:35:27 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.04.20 16:11:17 | 000,139,264 | ---- | M] () -- C:\Users\Aga\Desktop\SystemLook.exe [2013.04.20 15:54:04 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2013.04.20 15:52:20 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2013.04.20 15:52:19 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys [2013.04.20 15:52:19 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys [2013.04.20 15:52:19 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys [2013.04.20 03:19:44 | 000,000,554 | ---- | M] () -- C:\Users\Aga\Desktop\adw22cleaner - Verknüpfung.lnk [2013.04.20 03:09:35 | 000,000,000 | ---- | M] () -- C:\ProgramData\25282137263c54382a_c [2013.04.20 02:08:01 | 274,468,614 | ---- | M] () -- C:\Windows\MEMORY.DMP [2013.04.20 01:16:19 | 000,000,000 | ---- | M] () -- C:\Users\Aga\defogger_reenable [2013.04.20 01:07:30 | 000,358,800 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.20 00:56:37 | 000,001,356 | ---- | M] () -- C:\Users\Aga\AppData\Local\d3d9caps.dat [2013.04.20 00:01:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Aga\Desktop\OTL.exe [2013.04.19 15:16:00 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-423745193-3980066226-3922103518-1000Core.job [2013.04.10 14:18:40 | 000,002,032 | ---- | M] () -- C:\Users\Aga\Desktop\Google Chrome.lnk [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2013.03.26 14:46:13 | 000,000,713 | ---- | M] () -- C:\Users\Public\Desktop\OMSI.lnk [2013.03.26 14:46:10 | 000,000,973 | ---- | M] () -- C:\Users\Public\Desktop\Aerosoft Launcher.lnk [2013.03.25 16:18:07 | 000,000,047 | ---- | M] () -- C:\chid ========== Files Created - No Company Name ========== [2013.04.21 00:49:04 | 000,890,815 | ---- | C] () -- C:\Users\Aga\Desktop\SecurityCheck.exe [2013.04.20 21:35:27 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.04.20 16:40:32 | 000,139,264 | ---- | C] () -- C:\Users\Aga\Desktop\SystemLook.exe [2013.04.20 15:54:04 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk [2013.04.20 03:19:44 | 000,000,554 | ---- | C] () -- C:\Users\Aga\Desktop\adw22cleaner - Verknüpfung.lnk [2013.04.20 03:09:35 | 000,000,000 | ---- | C] () -- C:\ProgramData\25282137263c54382a_c [2013.04.20 02:08:01 | 274,468,614 | ---- | C] () -- C:\Windows\MEMORY.DMP [2013.04.20 01:16:19 | 000,000,000 | ---- | C] () -- C:\Users\Aga\defogger_reenable [2013.04.20 01:07:22 | 3488,735,232 | -HS- | C] () -- C:\hiberfil.sys [2013.03.26 14:46:13 | 000,000,713 | ---- | C] () -- C:\Users\Public\Desktop\OMSI.lnk [2013.03.26 14:46:10 | 000,000,973 | ---- | C] () -- C:\Users\Public\Desktop\Aerosoft Launcher.lnk [2013.03.25 16:18:07 | 000,000,047 | ---- | C] () -- C:\chid [2011.11.06 13:10:39 | 000,000,004 | ---- | C] () -- C:\Users\Aga\AppData\Roaming\steam_md4.dat [2011.11.04 18:24:17 | 000,017,408 | ---- | C] () -- C:\Users\Aga\AppData\Local\WebpageIcons.db [2011.10.04 15:51:41 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat [2011.09.28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011.09.22 20:10:56 | 000,010,240 | ---- | C] () -- C:\Users\Aga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.09.17 13:28:05 | 000,139,648 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2011.09.17 13:27:40 | 000,282,296 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2011.09.17 13:27:39 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2011.09.16 12:18:47 | 000,138,056 | ---- | C] () -- C:\Users\Aga\AppData\Roaming\PnkBstrK.sys [2011.09.15 10:03:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011.09.14 20:19:48 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011.09.14 18:15:39 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2011.09.14 18:15:01 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2011.09.14 18:15:01 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2011.09.14 17:02:41 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2011.09.14 17:01:48 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys [2011.09.14 17:01:42 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini [2011.09.14 17:01:38 | 000,017,799 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [2011.09.14 17:00:03 | 000,001,356 | ---- | C] () -- C:\Users\Aga\AppData\Local\d3d9caps.dat ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.10 23:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2013.04.14 15:10:18 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\.minecraft [2012.10.24 14:58:41 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2012.08.06 17:06:15 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\DAEMON Tools Lite [2012.12.08 13:50:31 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\DVDVideoSoft [2012.11.28 17:02:47 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\go [2012.07.02 12:42:34 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Gutscheinmieze [2012.03.26 19:47:29 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\LolClient [2013.04.14 22:41:55 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Mael [2012.08.01 13:01:03 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Mumble [2012.03.11 12:37:10 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Notepad++ [2012.07.11 12:29:20 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Origin [2012.10.24 14:52:47 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Publish Providers [2012.10.24 18:36:47 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Sony [2013.03.03 23:21:29 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\TS3Client [2011.10.06 17:24:35 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\Tunngle [2013.04.20 03:07:58 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\uTorrent [2012.05.26 12:50:54 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\wargaming.net [2012.01.14 20:59:21 | 000,000,000 | ---D | M] -- C:\Users\Aga\AppData\Roaming\wxMozBrowserLib ========== Purity Check ========== < End of report > |
21.04.2013, 13:50 | #22 |
/// TB-Ausbilder | GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Hi, well done, das sieht alles gut aus. Bleibt nur noch das Aufräumen: Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts Aktualität von System und Software Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
Sicherheits-Software Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
(Un-)Sicheres Verhalten im Internet Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
Allgemeine Hinweise Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen.
__________________ cheers, Leo |
27.04.2013, 21:26 | #23 |
| GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Danke schön für Deine professionele Hilfe.Alles erledigt.Versuche jetzt achtsam zu sein.Ich habe keine Fragen mehr.Danke. |
28.04.2013, 10:47 | #24 |
/// TB-Ausbilder | GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung Danke für die Rückmeldung. Freut mich, dass wir helfen konnten. Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun. Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten. Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu GVU-Trojaner, PC funktioniert nur im abgesicherten Modus mit Eingabeaufforderung |
abgesicherte, abgesicherten, abgesicherten modus, anhang, brauche, brauche dringend eure hilfe, dringend, eingabeaufforderung, ellung, forum, funktionier, funktioniert, gestern, gesuch, gesucht, gvu-trojaner, hilfestellung, informationen, logfiles, modus, plötzlich, seite, vorgehen, weiße, weiße seite |