Log-Analyse und Auswertung: Trojan.FakeMSWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.
![]() | ![]() Trojan.FakeMS Hallo zusammen, beim wöchentlichen Scan hat Malwarebytes einen Trojaner entdeckt, der sich nicht "normal" löschen lässt und immer wieder gefunden wird. Hier der logfile: Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.04.30.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Oliver :: LAPTOP [Administrator] 01.05.2013 11:07:13 MBAM-log-2013-05-01 (13-32-21).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 346037 Laufzeit: 1 Stunde(n), 26 Minute(n), 18 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Oliver\AppData\Roaming\Iwlyu\libnspr4.dll (Trojan.FakeMS) -> Keine Aktion durchgeführt. Würde mich freuen, wenn ihr mir weiterhelfen könntet. Viele Grüße Cayman |
![]() | ![]() Trojan.FakeMS Malwarebytes:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.04.30.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Oliver :: LAPTOP [Administrator] 01.05.2013 11:07:13 MBAM-log-2013-05-01 (13-32-21).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 346037 Laufzeit: 1 Stunde(n), 26 Minute(n), 18 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Oliver\AppData\Roaming\Iwlyu\libnspr4.dll (Trojan.FakeMS) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter OTL logfile created on: 01.05.2013 15:14:37 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Oliver\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,20 Gb Available Physical Memory | 73,42% Memory free 6,00 Gb Paging File | 5,13 Gb Available in Paging File | 85,62% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 115,70 Gb Total Space | 73,00 Gb Free Space | 63,09% Space Free | Partition Type: NTFS Drive D: | 117,18 Gb Total Space | 65,78 Gb Free Space | 56,13% Space Free | Partition Type: NTFS Computer Name: LAPTOP | User Name: Oliver | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.01 15:12:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe PRC - [2013.03.28 08:29:22 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2013.03.28 08:29:02 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2013.03.28 08:29:01 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2013.03.28 08:28:57 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.03.28 08:28:57 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2013.01.29 15:28:32 | 000,188,760 | ---- | M] () -- C:\Programme\Web Assistant\ExtensionUpdaterService.exe PRC - [2012.12.19 07:38:57 | 000,044,280 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.18 13:14:27 | 000,642,816 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.06.18 15:19:30 | 000,935,208 | ---- | M] (Nero AG) -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe PRC - [2007.05.31 16:21:28 | 000,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe ========== Modules (No Company Name) ========== MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF MOD - [2011.03.02 12:40:51 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll MOD - [2009.02.27 16:39:29 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ========== Services (SafeList) ========== SRV - [2013.04.12 09:17:32 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.04.12 08:47:28 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.03.28 08:29:22 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.03.28 08:29:02 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2013.03.28 08:28:57 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013.01.29 15:28:32 | 000,188,760 | ---- | M] () [Auto | Running] -- C:\Programme\Web Assistant\ExtensionUpdaterService.exe -- (Web Assistant) SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.09.20 14:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.05.31 18:22:18 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2011.04.03 01:04:22 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.06.18 15:19:30 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2007.05.31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007.05.31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\SBREdrv.sys -- (SBRE) DRV - [2013.03.28 08:29:29 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013.03.28 08:29:29 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013.03.28 08:29:29 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2012.08.20 15:48:44 | 000,015,576 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdrvio.sys -- (pwdrvio) DRV - [2012.08.20 15:48:44 | 000,010,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdspio.sys -- (pwdspio) DRV - [2012.03.09 10:45:00 | 002,877,952 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2011.08.17 10:03:58 | 000,137,472 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu) DRV - [2011.04.03 00:18:41 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD) DRV - [2007.07.11 02:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2006.11.14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 D3 C4 80 DE 6F CD 01 [binary data] IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) IE - HKCU\..\SearchScopes,DefaultScope = {1C601F91-9AD3-4187-ACF7-CC4159348895} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0693ED09-8732-4106-A438-0E919069D218}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=68733934-3d40-4baf-a878-6f42a7bb9682&apn_sauid=6F3BC58E-F34F-4566-98BD-FF0B1285EA60 IE - HKCU\..\SearchScopes\{1C601F91-9AD3-4187-ACF7-CC4159348895}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz= IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.05 11:08:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2013.03.04 20:06:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\Program Files\Web Assistant\Firefox [2013.03.04 20:06:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 09:17:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 09:17:32 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.12 09:17:27 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 09:17:32 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2013.01.17 02:11:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.01.17 02:11:04 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.01.17 02:11:04 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2013.01.17 02:11:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.01.17 02:11:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.01.17 02:11:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Programme\Web Assistant\Extension32.dll () O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKCU\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation) O4 - HKCU..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe File not found O4 - HKCU..\Run: [Iksoaq] C:\Users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe (Piriform Ltd) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: fernuni-hagen.de ([ca] https in Vertrauenswürdige Sites) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A796E61-3503-45D0-B1BC-BFA015045CB1}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{62A31B90-7141-41ED-9299-9FD6F125D11A}: DhcpNameServer = O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\System32\acaptuser32.dll (Adobe Systems Incorporated) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{367f7bfa-656b-11e1-820d-001e686463a0}\Shell - "" = AutoRun O33 - MountPoints2\{367f7bfa-656b-11e1-820d-001e686463a0}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.05.01 15:12:46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe [2013.05.01 13:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.05.01 08:55:50 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7D0A7876-6FD8-4B3B-A53A-12833DDB9977} [2013.04.30 20:15:10 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F34E8E13-E0F4-4BFD-B9C7-4BCA326A81B3} [2013.04.30 08:14:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B1669DA-70D4-41C7-85F7-21851925DE2E} [2013.04.29 20:14:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6E0732D6-6B6E-4AD6-BD96-59E9BE13932E} [2013.04.28 10:04:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{09679B53-7DC4-436B-B4D9-106F621BE2D0} [2013.04.27 11:57:25 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{149C75A8-81DC-4792-AB52-C5531C963077} [2013.04.26 21:50:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6F2200DC-4C70-4F46-93B0-F02283F339A9} [2013.04.26 07:41:41 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4BE21668-2EF9-4C50-8779-AA4E6ECC2BDA} [2013.04.25 19:41:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7E0B55AB-8517-4B16-A7EC-6ABDE891F0BD} [2013.04.25 07:40:50 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{8ED88EF8-E49B-4A7F-9E01-A3401F0EBF96} [2013.04.24 11:25:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{E505FB62-5A02-4B5A-A5C6-4D8F5F5CA63A} [2013.04.23 23:25:01 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{93A14D85-91E4-4ABA-BA60-622E3812BF79} [2013.04.23 10:45:51 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4535BA50-1234-4AF1-9D94-777F21640F1C} [2013.04.22 22:45:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B251B02-73D4-4D1C-9D06-699A8D10206A} [2013.04.22 10:45:01 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F26B92A0-B289-4090-B99A-3830D2FB40B1} [2013.04.21 22:44:36 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7555AAE4-B08E-465C-84D7-850BFD79ECF9} [2013.04.21 09:46:48 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C7B53541-E43D-40E3-ADD3-A4E299119B0C} [2013.04.20 11:50:04 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{CA67BA15-7788-4DE7-A6C5-B098DA46A5B2} [2013.04.19 20:00:34 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{BEA9A1AA-D3EB-44D1-BE70-3A518DEE6D90} [2013.04.19 08:00:08 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4B03B4FD-3C82-401A-B152-6285545EA41C} [2013.04.18 19:43:06 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{99AF9A84-19C7-4C73-91F6-581B0CB3057A} [2013.04.18 07:42:41 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{CA60498B-B827-473D-AD38-714E953595AC} [2013.04.17 19:36:45 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4813189C-E6C7-439B-9EAB-A4927299F303} [2013.04.17 07:36:20 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4D5C7B0E-62C7-4302-845D-B42C67C66EF2} [2013.04.16 19:23:58 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{378196D0-1B5D-4A1C-B28D-9BDDDB68D02D} [2013.04.16 07:23:33 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F18E84A7-96AC-4839-AADD-2080E5665D29} [2013.04.15 10:36:39 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{AC437D14-D2A6-4964-9E70-4D2D92208640} [2013.04.14 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{EFB95736-9DCB-467C-8F28-42B83C0DD923} [2013.04.14 10:29:45 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{5D65ABB3-4D09-4D08-960B-E74BC34804CB} [2013.04.13 22:29:19 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{5DD30C54-1D07-4CC8-9B8D-ECD1B9BCFDA4} [2013.04.13 10:28:54 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A128FB87-701F-4CD7-97A7-5993D33DBFAD} [2013.04.12 21:49:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{B97FEC69-3FD0-4795-8631-F1EF59A7A7DA} [2013.04.12 09:48:53 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{58D96E71-8B8E-46D1-B945-41D8CD2C9CEC} [2013.04.12 09:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.11 21:48:27 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A0BF509F-7CDA-4DF6-A0C0-422D3E4E7302} [2013.04.11 09:48:02 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{65ED8209-664B-48BD-9891-7BB78C1BE98A} [2013.04.10 21:39:57 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{DF2E58FE-3E8C-4609-8B7D-B7AECD6426FE} [2013.04.10 08:12:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3B88BE66-7B84-41B0-8872-2279B15B25EF} [2013.04.09 20:12:19 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{EB8350BF-667B-4052-AD38-21BA0EBCBA2A} [2013.04.09 08:11:54 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A90F1D58-7F59-4FAD-880E-5ACA84740271} [2013.04.08 20:11:28 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C3AE5CF7-4E02-4610-AAFA-3B8C6DCD1832} [2013.04.08 08:11:03 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F7C4114D-1956-4027-A724-570FD8FEEA04} [2013.04.08 07:57:03 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B447BF2-6E73-4E3A-A1BC-A82A4E21EC3F} [2013.04.07 13:23:20 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{775F8C10-CF2F-40D7-B5E4-B7ED62C249A6} [2013.04.06 10:36:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{D51A987E-2A6D-43CE-99F9-1C33E1A7D01B} [2013.04.05 20:55:23 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{291AFA36-D81D-4E73-B189-4923E1517F42} [2013.04.05 19:36:40 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{52C463DF-EA46-4316-9287-BD20130A2806} [2013.04.05 07:07:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7CCB01BC-4023-4F64-9D7E-7BD7F801DFF7} [2013.04.04 11:50:38 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6CDC7233-2D04-45A7-A3C5-A84D19789E27} [2013.04.03 07:30:29 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3BEB27D8-8DCE-45B7-8C9F-11A20665895C} [2013.04.02 13:04:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{DE8C1FFA-DE8E-410E-90DC-49BDC735121D} ========== Files - Modified Within 30 Days ========== [2013.05.01 15:18:05 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.01 15:18:05 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.01 15:18:02 | 000,654,400 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.01 15:18:02 | 000,616,242 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.01 15:18:02 | 000,130,240 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.01 15:18:02 | 000,106,622 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.01 15:12:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe [2013.05.01 15:10:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.01 15:10:17 | 2415,120,384 | -HS- | M] () -- C:\hiberfil.sys [2013.05.01 15:09:16 | 000,000,020 | ---- | M] () -- C:\Users\Oliver\defogger_reenable [2013.05.01 15:07:27 | 000,050,477 | ---- | M] () -- C:\Users\Oliver\Desktop\Defogger.exe [2013.05.01 15:03:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.04.20 19:58:56 | 000,002,040 | ---- | M] () -- C:\Users\Oliver\Desktop\Avira Free Antivirus.lnk [2013.04.20 17:13:25 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.04.12 08:40:27 | 000,411,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2013.05.01 15:08:05 | 000,000,020 | ---- | C] () -- C:\Users\Oliver\defogger_reenable [2013.05.01 15:07:27 | 000,050,477 | ---- | C] () -- C:\Users\Oliver\Desktop\Defogger.exe [2013.04.20 19:58:56 | 000,002,040 | ---- | C] () -- C:\Users\Oliver\Desktop\Avira Free Antivirus.lnk [2013.04.20 17:13:25 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.20 10:10:03 | 002,872,000 | ---- | C] () -- C:\Windows\System32\pwNative.exe [2012.10.20 10:10:02 | 000,015,576 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys [2012.10.20 10:09:36 | 000,010,200 | ---- | C] () -- C:\Windows\System32\pwdspio.sys [2012.10.02 12:58:17 | 000,433,590 | ---- | C] () -- C:\Users\Oliver\AppData\Local\census.cache [2012.10.02 12:57:56 | 000,106,606 | ---- | C] () -- C:\Users\Oliver\AppData\Local\ars.cache [2012.10.02 10:33:03 | 000,000,036 | ---- | C] () -- C:\Users\Oliver\AppData\Local\housecall.guid.cache [2012.10.01 15:05:55 | 000,000,494 | ---- | C] () -- C:\Windows\wininit.ini [2012.09.26 20:57:14 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.09.26 20:57:14 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.09.26 20:57:14 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.09.26 20:57:14 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2012.08.28 13:47:19 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll [2011.05.26 09:58:29 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.05.08 00:11:58 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat [2011.05.08 00:11:56 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat [2011.04.02 22:27:21 | 2415,120,384 | -HS- | C] () -- \hiberfil.sys [2011.04.02 22:05:24 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK [2009.07.14 04:04:04 | 000,000,024 | ---- | C] () -- \autoexec.bat [2009.07.14 04:04:04 | 000,000,010 | ---- | C] () -- \config.sys [2006.11.09 14:48:07 | 000,383,786 | RHS- | C] () -- \bootmgr ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== ========== Purity Check ========== < End of report > |
Trojan.FakeMS

Hi,

ja das läuft noch was..

Schritt 1

Downloade Dir bitte AdwCleaner
Schritt 2 Scan mit Combofix
Schritt 3 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
![]() | ![]() Trojan.FakeMS Adwcleaner: Code:
ATTFilter # AdwCleaner v2.300 - Datei am 01/05/2013 um 17:44:04 erstellt # Aktualisiert am 28/04/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzer : Oliver - LAPTOP # Bootmodus : Normal # Ausgeführt unter : C:\Users\Oliver\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : Web Assistant ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Windows\system32\ImhxxpComm.dll Ordner Gelöscht : C:\Program Files\Ask.com Ordner Gelöscht : C:\Program Files\ICQ6Toolbar Ordner Gelöscht : C:\Program Files\Web Assistant Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\ProgramData\InstallMate Ordner Gelöscht : C:\ProgramData\Premium Ordner Gelöscht : C:\Users\Oliver\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\Oliver\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Oliver\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Ordner Gelöscht : C:\Windows\system32\WNLT ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\APN Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\WNLT Schlüssel Gelöscht : HKLM\Software\APN Schlüssel Gelöscht : HKLM\Software\AskToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96} Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00F1A65D97AD1E11D8D76334268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\029DEE7E67AD1E113852DB04268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\03576BC0A7AD1E1188A9A434268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04CFD72C0A6D1E1179AC85E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07B0B68797AD1E118A6A4E24268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0828D86187AD1E1129764B14268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\088A41FE97AD1E114BD41434268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\090E991ED42E1E11D93A5C2F168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0F968E620A6D1E11B999E6D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF1D43997AD1E11FA430034268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2010C0B997AD1E111983F034268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20414E2897AD1E116B041F24268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\241E1DAF97AD1E11CBD65434268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BDF3E992C0908741B7C11F4B4E0F775 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D5CB10287AD1E112AF1CB14268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41B9E26133CD1E114A4E096D168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42B7416F0A6D1E112971B6E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\435ED11E0A6D1E1138C146E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\466B1A160A6D1E11DAFD1AD3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\600642CA97AD1E11EB30A134268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61C07F78D42E1E113849882F168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\638A55350A6D1E114AE6C9D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\63C6A3960A6D1E1199A78AD3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65BE09BB77AD1E1129594214268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\67F9C62077AD1E11BA0CBC04268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6967575E4ADD1E11E9E591AF068807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A0601CF0A6D1E11EA66D6E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B3BC4CF5ECE1F54BBA174C13A1AB907 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D34269C97AD1E11DAE42334268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DE790BA0A6D1E111B7A93E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F874FC077AD1E11FB2CCC04268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72D3312E1E95E8C4AAA81BADB30D5FC0 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74E6A1B4EEAA8A942B405B51643FD2FC Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\800967B40A6D1E1129B8C8D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\814DDE340A6D1E11B833B8D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\818F60F20A6D1E1149E987D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8225E07F67AD1E1138657C04268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\83011A2A97AD1E1139DD6134268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85D3F53D0A6D1E112BC9F5E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\860F3B99848D1E119B5569D6168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87B1CC30A7AD1E117BC59434268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8849E84D67AD1E11A8881B04268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8A7FEEA8848D1E11D8ABF7D6168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B065BD72ADD1E116B25978F068807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B58DAA50A6D1E11C924D9D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B8DC47DD42E1E119948EB2F168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8BCF643B0A6D1E113A80C4E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C52E23087AD1E11BB364914268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980D2637EBB4E31449BDFE2D7447AE03 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D0E499F53381f84992C7A212CF1D8F5 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A301910E5ADD1E11CBD5C1BF068807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A51CAA4F77AD1E116923D714268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6EA75AD0A6D1E116B9506E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A81E6B410A6D1E11B98E66D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD31AEF90A6D1E112B67A2E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF79D8530A6D1E11296968D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA82713BF2918244BB38D4D3626E2F31 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEABAA33A5E68374DBF197F2A00CD011 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C5A5C56BD42E1E11AA061B2F168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C61425DC0A6D1E11488AE5E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6D6135E97AD1E11783A0434268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6D68CEE0A6D1E1129B096E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB5F24F10A6D1E118B7AD6D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB61AF52AD64B6B45930BE969F316720 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CBE5FFA897AD1E11CA349F24268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC46BC9AD42E1E11B93ADA2F168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E0B84F7CD42E1E113A65AB2F168807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E0C668D287AD1E117AAAFB14268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E318FDD30A6D1E115956A8D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E58C26300A6D1E11EBCF16D3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E81243990A6D1E117B9C52E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E90A558E0A6D1E111A4356E3268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E942FF4ABC342DA42A4C40617E8ADC8C Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF874E5B67AD1E113A7B2A04268807B9 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT Schlüssel Gelöscht : HKLM\Software\Web Assistant Schlüssel Gelöscht : HKLM\Software\WNLT Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0.1 (de) Datei : C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\16uj6s6f.default\prefs.js C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\16uj6s6f.default\user.js ... Gelöscht ! Gelöscht : user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=too[...] Gelöscht : user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] ************************* AdwCleaner[S1].txt - [20992 octets] - [01/05/2013 17:44:04] ########## EOF - C:\AdwCleaner[S1].txt - [21053 octets] ########## Code:
ATTFilter ComboFix 13-05-01.03 - Oliver 01.05.2013 17:53:57.1.2 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3071.1979 [GMT 2:00] ausgeführt von:: c:\users\Oliver\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Oliver\AppData\Roaming\Adpyh c:\users\Oliver\AppData\Roaming\Adpyh\oxdi.obo c:\users\Oliver\AppData\Roaming\Ylecy c:\users\Oliver\AppData\Roaming\Ylecy\ucipn.ufs c:\windows\system32\drivers\etc\hosts.ics c:\windows\system32\muzapp.exe c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-04-01 bis 2013-05-01 )))))))))))))))))))))))))))))) . . 2013-05-01 16:01 . 2013-05-01 16:01 -------- d-----w- c:\users\Oliver\AppData\Local\temp 2013-05-01 16:01 . 2013-05-01 16:01 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-05-01 15:01 . 2013-05-01 15:01 -------- d-----w- c:\program files\7-Zip 2013-05-01 11:46 . 2013-05-01 11:46 -------- d-----w- c:\program files\Common Files\Java 2013-05-01 11:45 . 2013-04-04 03:35 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-04-27 20:42 . 2013-05-01 15:47 -------- d-----w- c:\users\Oliver\AppData\Roaming\Hasax 2013-04-27 20:42 . 2013-05-01 11:35 -------- d-----w- c:\users\Oliver\AppData\Roaming\Iwlyu 2013-04-24 06:02 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-11 05:31 . 2013-03-01 03:09 2347008 ----a-w- c:\windows\system32\win32k.sys 2013-04-11 05:31 . 2013-01-24 04:47 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys 2013-04-11 05:31 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-04-11 05:31 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-04-11 05:31 . 2013-03-19 04:48 38912 ----a-w- c:\windows\system32\csrsrv.dll 2013-04-11 05:31 . 2013-03-19 02:49 69632 ----a-w- c:\windows\system32\smss.exe 2013-04-11 05:31 . 2013-02-15 04:37 3217408 ----a-w- c:\windows\system32\mstscax.dll 2013-04-11 05:31 . 2013-02-15 04:34 131584 ----a-w- c:\windows\system32\aaclient.dll 2013-04-11 05:31 . 2013-02-15 03:25 36864 ----a-w- c:\windows\system32\tsgqec.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-12 06:47 . 2012-04-03 08:42 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-04-12 06:47 . 2011-05-24 18:22 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-04-04 12:50 . 2012-10-01 11:10 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-03-28 06:29 . 2012-10-17 11:59 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-03-28 06:29 . 2012-10-17 11:59 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-03-28 06:29 . 2012-10-17 11:59 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-03-06 08:24 . 2012-06-28 09:34 861088 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-03-06 08:24 . 2011-04-02 21:02 782240 ----a-w- c:\windows\system32\deployJava1.dll 2013-03-04 08:07 . 2012-08-28 11:47 632656 ----a-w- c:\windows\system32\msvcr80.dll 2013-03-04 08:07 . 2012-08-28 11:47 554832 ----a-w- c:\windows\system32\msvcp80.dll 2013-03-04 08:07 . 2012-08-28 11:47 479232 ----a-w- c:\windows\system32\msvcm80.dll 2013-02-12 04:48 . 2013-03-13 06:51 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-13 06:51 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-02-12 03:32 . 2013-03-26 06:44 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys 2013-04-12 07:17 . 2013-04-12 07:17 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "Iksoaq"="c:\users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe" [2012-10-09 458240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664] "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-12-18 642816] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-12-19 44280] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-03-28 345312] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\acaptuser32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync] 2010-03-13 12:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe . R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [x] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . . Inhalt des "geplante Tasks" Ordners . 2013-05-01 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 06:47] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll Trusted Zone: fernuni-hagen.de\ca TCP: DhcpNameServer = FF - ProfilePath - c:\users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\16uj6s6f.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . MSConfigStartUp-Kuyqinyf - c:\users\Oliver\AppData\Roaming\Myxio\uzsy.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-05-01 18:03:17 ComboFix-quarantined-files.txt 2013-05-01 16:03 . Vor Suchlauf: 10 Verzeichnis(se), 78.297.477.120 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 78.074.441.728 Bytes frei . - - End Of File - - 2899EBC50AE8BC89065FDAFB56ED8212 Code:
ATTFilter OTL logfile created on: 01.05.2013 18:05:09 - Run 2 OTL by OldTimer - Version Folder = C:\Users\Oliver\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,99 Gb Available Physical Memory | 66,45% Memory free 6,00 Gb Paging File | 4,99 Gb Available in Paging File | 83,16% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 115,70 Gb Total Space | 72,78 Gb Free Space | 62,90% Space Free | Partition Type: NTFS Drive D: | 117,18 Gb Total Space | 65,78 Gb Free Space | 56,13% Space Free | Partition Type: NTFS Computer Name: LAPTOP | User Name: Oliver | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.01 15:12:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe PRC - [2013.04.12 09:17:32 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2013.03.28 08:29:22 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2013.03.28 08:29:02 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2013.03.28 08:29:01 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2013.03.28 08:28:57 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.03.28 08:28:57 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.18 13:14:27 | 000,642,816 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.06.18 15:19:30 | 000,935,208 | ---- | M] (Nero AG) -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe PRC - [2007.05.31 16:21:28 | 000,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe ========== Modules (No Company Name) ========== MOD - [2013.04.12 09:17:32 | 003,133,336 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF MOD - [2011.03.02 12:40:51 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll MOD - [2009.02.27 16:39:29 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ========== Services (SafeList) ========== SRV - [2013.04.12 09:17:32 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.04.12 08:47:28 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.03.28 08:29:22 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.03.28 08:29:02 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2013.03.28 08:28:57 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.09.20 14:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.05.31 18:22:18 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2011.04.03 01:04:22 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.06.18 15:19:30 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2007.05.31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007.05.31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\SBREdrv.sys -- (SBRE) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\ComboFix\mbr.sys -- (mbr) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Oliver\AppData\Local\Temp\catchme.sys -- (catchme) DRV - [2013.03.28 08:29:29 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013.03.28 08:29:29 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013.03.28 08:29:29 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2012.08.20 15:48:44 | 000,015,576 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdrvio.sys -- (pwdrvio) DRV - [2012.08.20 15:48:44 | 000,010,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdspio.sys -- (pwdspio) DRV - [2012.03.09 10:45:00 | 002,877,952 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2011.08.17 10:03:58 | 000,137,472 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu) DRV - [2011.04.03 00:18:41 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD) DRV - [2007.07.11 02:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2006.11.14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 D3 C4 80 DE 6F CD 01 [binary data] IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{0693ED09-8732-4106-A438-0E919069D218}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=68733934-3d40-4baf-a878-6f42a7bb9682&apn_sauid=6F3BC58E-F34F-4566-98BD-FF0B1285EA60 IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{1C601F91-9AD3-4187-ACF7-CC4159348895}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz= IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.05 11:08:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 09:17:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 09:17:32 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.12 09:17:27 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 09:17:32 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2013.01.17 02:11:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.01.17 02:11:04 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.01.17 02:11:04 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2013.01.17 02:11:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.01.17 02:11:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.01.17 02:11:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013.05.01 18:01:31 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000..\Run: [Iksoaq] C:\Users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe (Piriform Ltd) O4 - HKU\@1..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\@1\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O15 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..Trusted Domains: fernuni-hagen.de ([ca] https in Vertrauenswürdige Sites) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A796E61-3503-45D0-B1BC-BFA015045CB1}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{62A31B90-7141-41ED-9299-9FD6F125D11A}: DhcpNameServer = O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\Windows\System32\acaptuser32.dll) - C:\Windows\System32\acaptuser32.dll (Adobe Systems Incorporated) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.05.01 18:03:20 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013.05.01 18:03:20 | 000,000,000 | -HSD | C] -- \$RECYCLE.BIN [2013.05.01 18:03:19 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.05.01 18:03:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\temp [2013.05.01 17:51:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.05.01 17:51:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.05.01 17:51:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.05.01 17:51:31 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.05.01 17:51:31 | 000,000,000 | ---D | C] -- \Qoobox [2013.05.01 17:51:09 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.05.01 17:49:16 | 005,064,153 | R--- | C] (Swearware) -- C:\Users\Oliver\Desktop\ComboFix.exe [2013.05.01 17:01:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.05.01 17:01:48 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.05.01 15:12:46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe [2013.05.01 13:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.05.01 08:55:50 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7D0A7876-6FD8-4B3B-A53A-12833DDB9977} [2013.04.30 20:15:10 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F34E8E13-E0F4-4BFD-B9C7-4BCA326A81B3} [2013.04.30 08:14:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B1669DA-70D4-41C7-85F7-21851925DE2E} [2013.04.29 20:14:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6E0732D6-6B6E-4AD6-BD96-59E9BE13932E} [2013.04.28 10:04:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{09679B53-7DC4-436B-B4D9-106F621BE2D0} [2013.04.27 11:57:25 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{149C75A8-81DC-4792-AB52-C5531C963077} [2013.04.26 21:50:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6F2200DC-4C70-4F46-93B0-F02283F339A9} [2013.04.26 07:41:41 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4BE21668-2EF9-4C50-8779-AA4E6ECC2BDA} [2013.04.25 19:41:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7E0B55AB-8517-4B16-A7EC-6ABDE891F0BD} [2013.04.25 07:40:50 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{8ED88EF8-E49B-4A7F-9E01-A3401F0EBF96} [2013.04.24 11:25:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{E505FB62-5A02-4B5A-A5C6-4D8F5F5CA63A} [2013.04.23 23:25:01 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{93A14D85-91E4-4ABA-BA60-622E3812BF79} [2013.04.23 10:45:51 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4535BA50-1234-4AF1-9D94-777F21640F1C} [2013.04.22 22:45:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B251B02-73D4-4D1C-9D06-699A8D10206A} [2013.04.22 10:45:01 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F26B92A0-B289-4090-B99A-3830D2FB40B1} [2013.04.21 22:44:36 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7555AAE4-B08E-465C-84D7-850BFD79ECF9} [2013.04.21 09:46:48 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C7B53541-E43D-40E3-ADD3-A4E299119B0C} [2013.04.20 11:50:04 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{CA67BA15-7788-4DE7-A6C5-B098DA46A5B2} [2013.04.19 20:00:34 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{BEA9A1AA-D3EB-44D1-BE70-3A518DEE6D90} [2013.04.19 08:00:08 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4B03B4FD-3C82-401A-B152-6285545EA41C} [2013.04.18 19:43:06 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{99AF9A84-19C7-4C73-91F6-581B0CB3057A} [2013.04.18 07:42:41 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{CA60498B-B827-473D-AD38-714E953595AC} [2013.04.17 19:36:45 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4813189C-E6C7-439B-9EAB-A4927299F303} [2013.04.17 07:36:20 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4D5C7B0E-62C7-4302-845D-B42C67C66EF2} [2013.04.16 19:23:58 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{378196D0-1B5D-4A1C-B28D-9BDDDB68D02D} [2013.04.16 07:23:33 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F18E84A7-96AC-4839-AADD-2080E5665D29} [2013.04.15 10:36:39 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{AC437D14-D2A6-4964-9E70-4D2D92208640} [2013.04.14 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{EFB95736-9DCB-467C-8F28-42B83C0DD923} [2013.04.14 10:29:45 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{5D65ABB3-4D09-4D08-960B-E74BC34804CB} [2013.04.13 22:29:19 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{5DD30C54-1D07-4CC8-9B8D-ECD1B9BCFDA4} [2013.04.13 10:28:54 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A128FB87-701F-4CD7-97A7-5993D33DBFAD} [2013.04.12 21:49:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{B97FEC69-3FD0-4795-8631-F1EF59A7A7DA} [2013.04.12 09:48:53 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{58D96E71-8B8E-46D1-B945-41D8CD2C9CEC} [2013.04.12 09:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.11 21:48:27 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A0BF509F-7CDA-4DF6-A0C0-422D3E4E7302} [2013.04.11 09:48:02 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{65ED8209-664B-48BD-9891-7BB78C1BE98A} [2013.04.10 21:39:57 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{DF2E58FE-3E8C-4609-8B7D-B7AECD6426FE} [2013.04.10 08:12:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3B88BE66-7B84-41B0-8872-2279B15B25EF} [2013.04.09 20:12:19 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{EB8350BF-667B-4052-AD38-21BA0EBCBA2A} [2013.04.09 08:11:54 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A90F1D58-7F59-4FAD-880E-5ACA84740271} [2013.04.08 20:11:28 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C3AE5CF7-4E02-4610-AAFA-3B8C6DCD1832} [2013.04.08 08:11:03 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F7C4114D-1956-4027-A724-570FD8FEEA04} [2013.04.08 07:57:03 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B447BF2-6E73-4E3A-A1BC-A82A4E21EC3F} [2013.04.07 13:23:20 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{775F8C10-CF2F-40D7-B5E4-B7ED62C249A6} [2013.04.06 10:36:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{D51A987E-2A6D-43CE-99F9-1C33E1A7D01B} [2013.04.05 20:55:23 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{291AFA36-D81D-4E73-B189-4923E1517F42} [2013.04.05 19:36:40 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{52C463DF-EA46-4316-9287-BD20130A2806} [2013.04.05 07:07:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7CCB01BC-4023-4F64-9D7E-7BD7F801DFF7} [2013.04.04 11:50:38 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6CDC7233-2D04-45A7-A3C5-A84D19789E27} [2013.04.03 07:30:29 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3BEB27D8-8DCE-45B7-8C9F-11A20665895C} [2013.04.02 13:04:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{DE8C1FFA-DE8E-410E-90DC-49BDC735121D} ========== Files - Modified Within 30 Days ========== [2013.05.01 18:03:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.01 18:01:31 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2013.05.01 17:53:14 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.01 17:53:14 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.01 17:50:12 | 000,654,400 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.01 17:50:12 | 000,616,242 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.01 17:50:12 | 000,130,240 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.01 17:50:12 | 000,106,622 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.01 17:49:31 | 005,064,153 | R--- | M] (Swearware) -- C:\Users\Oliver\Desktop\ComboFix.exe [2013.05.01 17:45:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.01 17:45:37 | 2415,120,384 | -HS- | M] () -- C:\hiberfil.sys [2013.05.01 17:42:25 | 000,628,743 | ---- | M] () -- C:\Users\Oliver\Desktop\adwcleaner.exe [2013.05.01 17:03:32 | 000,023,845 | ---- | M] () -- C:\Users\Oliver\Desktop\Logfiles.zip [2013.05.01 17:00:52 | 001,110,476 | ---- | M] () -- C:\Users\Oliver\Desktop\7z920.exe [2013.05.01 15:31:34 | 000,377,856 | ---- | M] () -- C:\Users\Oliver\Desktop\gmer_2.1.19163.exe [2013.05.01 15:12:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe [2013.05.01 15:09:16 | 000,000,020 | ---- | M] () -- C:\Users\Oliver\defogger_reenable [2013.05.01 15:07:27 | 000,050,477 | ---- | M] () -- C:\Users\Oliver\Desktop\Defogger.exe [2013.04.20 19:58:56 | 000,002,040 | ---- | M] () -- C:\Users\Oliver\Desktop\Avira Free Antivirus.lnk [2013.04.20 17:13:25 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.04.12 08:40:27 | 000,411,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2013.05.01 17:51:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.05.01 17:51:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.05.01 17:51:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.05.01 17:51:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.05.01 17:51:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.05.01 17:42:25 | 000,628,743 | ---- | C] () -- C:\Users\Oliver\Desktop\adwcleaner.exe [2013.05.01 17:03:31 | 000,023,845 | ---- | C] () -- C:\Users\Oliver\Desktop\Logfiles.zip [2013.05.01 17:00:50 | 001,110,476 | ---- | C] () -- C:\Users\Oliver\Desktop\7z920.exe [2013.05.01 15:31:34 | 000,377,856 | ---- | C] () -- C:\Users\Oliver\Desktop\gmer_2.1.19163.exe [2013.05.01 15:08:05 | 000,000,020 | ---- | C] () -- C:\Users\Oliver\defogger_reenable [2013.05.01 15:07:27 | 000,050,477 | ---- | C] () -- C:\Users\Oliver\Desktop\Defogger.exe [2013.04.20 19:58:56 | 000,002,040 | ---- | C] () -- C:\Users\Oliver\Desktop\Avira Free Antivirus.lnk [2013.04.20 17:13:25 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.20 10:10:03 | 002,872,000 | ---- | C] () -- C:\Windows\System32\pwNative.exe [2012.10.20 10:10:02 | 000,015,576 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys [2012.10.20 10:09:36 | 000,010,200 | ---- | C] () -- C:\Windows\System32\pwdspio.sys [2012.10.02 12:58:17 | 000,433,590 | ---- | C] () -- C:\Users\Oliver\AppData\Local\census.cache [2012.10.02 12:57:56 | 000,106,606 | ---- | C] () -- C:\Users\Oliver\AppData\Local\ars.cache [2012.10.02 10:33:03 | 000,000,036 | ---- | C] () -- C:\Users\Oliver\AppData\Local\housecall.guid.cache [2012.09.26 20:57:14 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.09.26 20:57:14 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.09.26 20:57:14 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.09.26 20:57:14 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2011.05.26 09:58:29 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.05.08 00:11:58 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat [2011.05.08 00:11:56 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat [2011.04.02 22:27:21 | 2415,120,384 | -HS- | C] () -- \hiberfil.sys [2011.04.02 22:05:24 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK [2009.07.14 04:04:04 | 000,000,024 | ---- | C] () -- \autoexec.bat [2009.07.14 04:04:04 | 000,000,010 | ---- | C] () -- \config.sys [2006.11.09 14:48:07 | 000,383,786 | RHS- | C] () -- \bootmgr ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Anwendungsdaten [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Application Data [2011.04.03 00:17:43 | 000,000,000 | ---D | M] -- C:\Users\All Users\DAEMON Tools Lite [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Desktop [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Documents [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Dokumente [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Favoriten [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Favorites [2012.08.01 14:03:10 | 000,000,000 | ---D | M] -- C:\Users\All Users\GFI Software [2011.06.16 14:43:36 | 000,000,000 | ---D | M] -- C:\Users\All Users\ICQ [2012.12.05 15:58:06 | 000,000,000 | ---D | M] -- C:\Users\All Users\Samsung [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Start Menu [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Startmenü [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Templates [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Vorlagen [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Anwendungsdaten [2009.07.14 04:37:05 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Application Data [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Desktop [2011.04.02 22:54:28 | 000,000,000 | R--D | M] -- C:\Users\Default\Documents [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Downloads [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Druckumgebung [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Eigene Dateien [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Favorites [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Links [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Local Settings [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Lokale Einstellungen [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Music [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\My Documents [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\NetHood [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Netzwerkumgebung [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Pictures [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\PrintHood [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Recent [2009.07.14 04:04:25 | 000,000,000 | ---D | M] -- C:\Users\Default\Saved Games [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\SendTo [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Start Menu [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Startmenü [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Templates [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Videos [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Vorlagen [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Anwendungsdaten [2011.04.02 22:54:45 | 000,000,000 | -H-D | M] -- C:\Users\Oliver\AppData [2012.07.12 09:33:53 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Contacts [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Cookies [2013.05.01 17:49:31 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Desktop [2013.02.23 22:58:06 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Documents [2013.01.20 19:44:16 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Downloads [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Druckumgebung [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Eigene Dateien [2013.01.20 19:03:11 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Favorites [2012.07.12 09:33:55 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Links [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Lokale Einstellungen [2012.07.12 09:33:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Music [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Netzwerkumgebung [2012.07.12 09:33:53 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Pictures [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Recent [2012.07.12 09:33:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Saved Games [2012.07.12 09:33:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Searches [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\SendTo [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Startmenü [2011.12.09 17:44:12 | 000,000,000 | ---D | M] -- C:\Users\Oliver\Tracing [2012.07.12 09:33:53 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Videos [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Vorlagen [2013.05.01 18:03:18 | 000,000,000 | ---D | M] -- C:\Users\Public\AppData [2013.04.20 17:13:25 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop [2012.11.02 18:48:40 | 000,000,000 | R--D | M] -- C:\Users\Public\Documents [2009.07.14 06:41:57 | 000,000,000 | R--D | M] -- C:\Users\Public\Downloads [2009.07.14 04:04:25 | 000,000,000 | RH-D | M] -- C:\Users\Public\Favorites [2011.05.31 18:19:33 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries [2011.04.04 21:46:05 | 000,000,000 | R--D | M] -- C:\Users\Public\Music [2009.07.14 06:41:57 | 000,000,000 | R--D | M] -- C:\Users\Public\Pictures [2009.07.14 10:56:56 | 000,000,000 | R--D | M] -- C:\Users\Public\Recorded TV [2011.04.04 21:46:15 | 000,000,000 | R--D | M] -- C:\Users\Public\Videos ========== Purity Check ========== < End of report > |
Trojan.FakeMS

Hallo,

wie läuft der Rechner jetzt?

So weiter:

Schritt 1

Fixen mit OTL
ATTFilter :OTL O4 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000..\Run: [Iksoaq] C:\Users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe (Piriform Ltd) IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{0693ED09-8732-4106-A438-0E919069D218}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=68733934-3d40-4baf-a878-6f42a7bb9682&apn_sauid=6F3BC58E-F34F-4566-98BD-FF0B1285EA60 :files c:\users\Oliver\AppData\Roaming\Hasax c:\users\Oliver\AppData\Roaming\Iwlyu :commands [emptytemp]
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Schritt 5 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
__________________ --> Trojan.FakeMS |
![]() | ![]() Trojan.FakeMS Hi Leo, Rechner läuft sehr gut. Fixlog von OTL: Code:
ATTFilter All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Iksoaq deleted successfully. C:\Users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe moved successfully. Registry key HKEY_USERS\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0693ED09-8732-4106-A438-0E919069D218}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0693ED09-8732-4106-A438-0E919069D218}\ not found. ========== FILES ========== c:\users\Oliver\AppData\Roaming\Hasax folder moved successfully. c:\users\Oliver\AppData\Roaming\Iwlyu folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Oliver ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 2826841 bytes ->Java cache emptied: 12454456 bytes ->FireFox cache emptied: 4686737 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 19,00 mb OTL by OldTimer - Version log created on 05012013_220538 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.04.30.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Oliver :: LAPTOP [Administrator] 01.05.2013 22:09:59 mbam-log-2013-05-01 (22-09-59).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 212977 Laufzeit: 13 Minute(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=ecb083dd5351ea4996f4403121864c24 # engine=13735 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-01 09:44:13 # local_time=2013-05-01 11:44:13 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 9932 232867943 2712 0 # compatibility_mode=5893 16776574 100 94 17044442 119075844 0 0 # scanned=39401 # found=0 # cleaned=0 # scan_time=4134 ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=ecb083dd5351ea4996f4403121864c24 # engine=13735 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-02 07:38:56 # local_time=2013-05-02 09:38:56 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 9086 232903626 1867 0 # compatibility_mode=5893 16776574 100 94 17080125 119111527 0 0 # scanned=161291 # found=0 # cleaned=0 # scan_time=8084 Code:
ATTFilter Results of screen317's Security Check version 0.99.62 Windows 7 Service Pack 1 x86 Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version CCleaner Java 7 Update 21 Java version out of Date! Adobe Flash Player 11.7.700.169 Adobe Reader XI Mozilla Firefox (20.0.1) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter OTL logfile created on: 02.05.2013 09:49:17 - Run 3 OTL by OldTimer - Version Folder = C:\Users\Oliver\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,98 Gb Available Physical Memory | 66,00% Memory free 6,00 Gb Paging File | 4,96 Gb Available in Paging File | 82,65% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 115,70 Gb Total Space | 74,42 Gb Free Space | 64,32% Space Free | Partition Type: NTFS Drive D: | 117,18 Gb Total Space | 65,78 Gb Free Space | 56,13% Space Free | Partition Type: NTFS Drive G: | 14,53 Gb Total Space | 3,52 Gb Free Space | 24,25% Space Free | Partition Type: FAT32 Computer Name: LAPTOP | User Name: Oliver | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.05.01 15:12:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe PRC - [2013.04.12 09:17:32 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2013.03.28 08:29:22 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2013.03.28 08:29:02 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe PRC - [2013.03.28 08:29:01 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2013.03.28 08:28:57 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.03.28 08:28:57 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.12.18 13:14:27 | 000,642,816 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2011.03.28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2009.06.18 15:19:30 | 000,935,208 | ---- | M] (Nero AG) -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe PRC - [2007.05.31 16:21:28 | 000,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe ========== Modules (No Company Name) ========== MOD - [2013.04.12 09:17:32 | 003,133,336 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF MOD - [2011.03.02 12:40:51 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll MOD - [2009.02.27 16:39:29 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ========== Services (SafeList) ========== SRV - [2013.04.12 09:17:32 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.04.12 08:47:28 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.03.28 08:29:22 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.03.28 08:29:02 | 000,565,472 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService) SRV - [2013.03.28 08:28:57 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.09.20 14:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011.05.31 18:22:18 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2011.04.03 01:04:22 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011.03.28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) SRV - [2009.07.14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.06.18 15:19:30 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Programme\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2007.05.31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007.05.31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\SBREdrv.sys -- (SBRE) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Oliver\AppData\Local\Temp\catchme.sys -- (catchme) DRV - [2013.03.28 08:29:29 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2013.03.28 08:29:29 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013.03.28 08:29:29 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.08.27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2012.08.20 15:48:44 | 000,015,576 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdrvio.sys -- (pwdrvio) DRV - [2012.08.20 15:48:44 | 000,010,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdspio.sys -- (pwdspio) DRV - [2012.03.09 10:45:00 | 002,877,952 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2011.08.17 10:03:58 | 000,137,472 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu) DRV - [2011.04.03 00:18:41 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009.10.03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD) DRV - [2007.07.11 02:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2006.11.14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 D3 C4 80 DE 6F CD 01 [binary data] IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{1C601F91-9AD3-4187-ACF7-CC4159348895}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz= IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.05 11:08:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 09:17:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.12 09:17:32 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.12 09:17:27 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.12 09:17:32 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2013.01.17 02:11:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.01.17 02:11:04 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.01.17 02:11:04 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2013.01.17 02:11:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.01.17 02:11:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.01.17 02:11:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2013.05.01 18:01:31 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000..\Run: [Iksoaq] C:\Users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O15 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000\..Trusted Domains: fernuni-hagen.de ([ca] https in Vertrauenswürdige Sites) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A796E61-3503-45D0-B1BC-BFA015045CB1}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{62A31B90-7141-41ED-9299-9FD6F125D11A}: DhcpNameServer = O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\Windows\System32\acaptuser32.dll) - C:\Windows\System32\acaptuser32.dll (Adobe Systems Incorporated) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.05.02 09:25:46 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3281567F-A2AD-43AC-9528-0F916D590BFC} [2013.05.01 22:31:39 | 002,347,384 | ---- | C] (ESET) -- C:\Users\Oliver\Desktop\esetsmartinstaller_enu.exe [2013.05.01 22:05:38 | 000,000,000 | ---D | C] -- C:\_OTL [2013.05.01 22:05:38 | 000,000,000 | ---D | C] -- \_OTL [2013.05.01 20:56:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C1364996-9616-489F-A07F-F6973CCFA511} [2013.05.01 18:03:20 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2013.05.01 18:03:20 | 000,000,000 | -HSD | C] -- \$RECYCLE.BIN [2013.05.01 18:03:19 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.05.01 18:03:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\temp [2013.05.01 17:51:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.05.01 17:51:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.05.01 17:51:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.05.01 17:51:31 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.05.01 17:51:31 | 000,000,000 | ---D | C] -- \Qoobox [2013.05.01 17:51:09 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.05.01 17:49:16 | 005,064,153 | R--- | C] (Swearware) -- C:\Users\Oliver\Desktop\ComboFix.exe [2013.05.01 17:01:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2013.05.01 17:01:48 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2013.05.01 15:12:46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe [2013.05.01 13:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013.05.01 08:55:50 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7D0A7876-6FD8-4B3B-A53A-12833DDB9977} [2013.04.30 20:15:10 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F34E8E13-E0F4-4BFD-B9C7-4BCA326A81B3} [2013.04.30 08:14:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B1669DA-70D4-41C7-85F7-21851925DE2E} [2013.04.29 20:14:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6E0732D6-6B6E-4AD6-BD96-59E9BE13932E} [2013.04.28 10:04:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{09679B53-7DC4-436B-B4D9-106F621BE2D0} [2013.04.27 11:57:25 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{149C75A8-81DC-4792-AB52-C5531C963077} [2013.04.26 21:50:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6F2200DC-4C70-4F46-93B0-F02283F339A9} [2013.04.26 07:41:41 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4BE21668-2EF9-4C50-8779-AA4E6ECC2BDA} [2013.04.25 19:41:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7E0B55AB-8517-4B16-A7EC-6ABDE891F0BD} [2013.04.25 07:40:50 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{8ED88EF8-E49B-4A7F-9E01-A3401F0EBF96} [2013.04.24 11:25:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{E505FB62-5A02-4B5A-A5C6-4D8F5F5CA63A} [2013.04.23 23:25:01 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{93A14D85-91E4-4ABA-BA60-622E3812BF79} [2013.04.23 10:45:51 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4535BA50-1234-4AF1-9D94-777F21640F1C} [2013.04.22 22:45:26 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B251B02-73D4-4D1C-9D06-699A8D10206A} [2013.04.22 10:45:01 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F26B92A0-B289-4090-B99A-3830D2FB40B1} [2013.04.21 22:44:36 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7555AAE4-B08E-465C-84D7-850BFD79ECF9} [2013.04.21 09:46:48 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C7B53541-E43D-40E3-ADD3-A4E299119B0C} [2013.04.20 11:50:04 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{CA67BA15-7788-4DE7-A6C5-B098DA46A5B2} [2013.04.19 20:00:34 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{BEA9A1AA-D3EB-44D1-BE70-3A518DEE6D90} [2013.04.19 08:00:08 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4B03B4FD-3C82-401A-B152-6285545EA41C} [2013.04.18 19:43:06 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{99AF9A84-19C7-4C73-91F6-581B0CB3057A} [2013.04.18 07:42:41 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{CA60498B-B827-473D-AD38-714E953595AC} [2013.04.17 19:36:45 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4813189C-E6C7-439B-9EAB-A4927299F303} [2013.04.17 07:36:20 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{4D5C7B0E-62C7-4302-845D-B42C67C66EF2} [2013.04.16 19:23:58 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{378196D0-1B5D-4A1C-B28D-9BDDDB68D02D} [2013.04.16 07:23:33 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F18E84A7-96AC-4839-AADD-2080E5665D29} [2013.04.15 10:36:39 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{AC437D14-D2A6-4964-9E70-4D2D92208640} [2013.04.14 22:36:14 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{EFB95736-9DCB-467C-8F28-42B83C0DD923} [2013.04.14 10:29:45 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{5D65ABB3-4D09-4D08-960B-E74BC34804CB} [2013.04.13 22:29:19 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{5DD30C54-1D07-4CC8-9B8D-ECD1B9BCFDA4} [2013.04.13 10:28:54 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A128FB87-701F-4CD7-97A7-5993D33DBFAD} [2013.04.12 21:49:18 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{B97FEC69-3FD0-4795-8631-F1EF59A7A7DA} [2013.04.12 09:48:53 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{58D96E71-8B8E-46D1-B945-41D8CD2C9CEC} [2013.04.12 09:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.11 21:48:27 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A0BF509F-7CDA-4DF6-A0C0-422D3E4E7302} [2013.04.11 09:48:02 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{65ED8209-664B-48BD-9891-7BB78C1BE98A} [2013.04.10 21:39:57 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{DF2E58FE-3E8C-4609-8B7D-B7AECD6426FE} [2013.04.10 08:12:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3B88BE66-7B84-41B0-8872-2279B15B25EF} [2013.04.09 20:12:19 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{EB8350BF-667B-4052-AD38-21BA0EBCBA2A} [2013.04.09 08:11:54 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{A90F1D58-7F59-4FAD-880E-5ACA84740271} [2013.04.08 20:11:28 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{C3AE5CF7-4E02-4610-AAFA-3B8C6DCD1832} [2013.04.08 08:11:03 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{F7C4114D-1956-4027-A724-570FD8FEEA04} [2013.04.08 07:57:03 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{0B447BF2-6E73-4E3A-A1BC-A82A4E21EC3F} [2013.04.07 13:23:20 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{775F8C10-CF2F-40D7-B5E4-B7ED62C249A6} [2013.04.06 10:36:44 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{D51A987E-2A6D-43CE-99F9-1C33E1A7D01B} [2013.04.05 20:55:23 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{291AFA36-D81D-4E73-B189-4923E1517F42} [2013.04.05 19:36:40 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{52C463DF-EA46-4316-9287-BD20130A2806} [2013.04.05 07:07:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{7CCB01BC-4023-4F64-9D7E-7BD7F801DFF7} [2013.04.04 11:50:38 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{6CDC7233-2D04-45A7-A3C5-A84D19789E27} [2013.04.03 07:30:29 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{3BEB27D8-8DCE-45B7-8C9F-11A20665895C} [2013.04.02 13:04:16 | 000,000,000 | ---D | C] -- C:\Users\Oliver\AppData\Local\{DE8C1FFA-DE8E-410E-90DC-49BDC735121D} ========== Files - Modified Within 30 Days ========== [2013.05.02 09:45:28 | 000,890,815 | ---- | M] () -- C:\Users\Oliver\Desktop\SecurityCheck.exe [2013.05.02 09:03:02 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.02 07:09:33 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.05.02 07:09:33 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.05.02 07:06:26 | 000,654,400 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.05.02 07:06:26 | 000,616,242 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.05.02 07:06:26 | 000,130,240 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.05.02 07:06:26 | 000,106,622 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.05.02 07:02:39 | 000,000,431 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2013.05.02 07:02:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.05.02 07:01:16 | 2415,120,384 | -HS- | M] () -- C:\hiberfil.sys [2013.05.01 22:31:44 | 002,347,384 | ---- | M] (ESET) -- C:\Users\Oliver\Desktop\esetsmartinstaller_enu.exe [2013.05.01 18:01:31 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2013.05.01 17:49:31 | 005,064,153 | R--- | M] (Swearware) -- C:\Users\Oliver\Desktop\ComboFix.exe [2013.05.01 17:42:25 | 000,628,743 | ---- | M] () -- C:\Users\Oliver\Desktop\adwcleaner.exe [2013.05.01 17:03:32 | 000,023,845 | ---- | M] () -- C:\Users\Oliver\Desktop\Logfiles.zip [2013.05.01 17:00:52 | 001,110,476 | ---- | M] () -- C:\Users\Oliver\Desktop\7z920.exe [2013.05.01 15:31:34 | 000,377,856 | ---- | M] () -- C:\Users\Oliver\Desktop\gmer_2.1.19163.exe [2013.05.01 15:12:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Oliver\Desktop\OTL.exe [2013.05.01 15:09:16 | 000,000,020 | ---- | M] () -- C:\Users\Oliver\defogger_reenable [2013.05.01 15:07:27 | 000,050,477 | ---- | M] () -- C:\Users\Oliver\Desktop\Defogger.exe [2013.04.20 19:58:56 | 000,002,040 | ---- | M] () -- C:\Users\Oliver\Desktop\Avira Free Antivirus.lnk [2013.04.20 17:13:25 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.04.12 08:40:27 | 000,411,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2013.05.02 09:45:27 | 000,890,815 | ---- | C] () -- C:\Users\Oliver\Desktop\SecurityCheck.exe [2013.05.01 17:51:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.05.01 17:51:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.05.01 17:51:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.05.01 17:51:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.05.01 17:51:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.05.01 17:42:25 | 000,628,743 | ---- | C] () -- C:\Users\Oliver\Desktop\adwcleaner.exe [2013.05.01 17:03:31 | 000,023,845 | ---- | C] () -- C:\Users\Oliver\Desktop\Logfiles.zip [2013.05.01 17:00:50 | 001,110,476 | ---- | C] () -- C:\Users\Oliver\Desktop\7z920.exe [2013.05.01 15:31:34 | 000,377,856 | ---- | C] () -- C:\Users\Oliver\Desktop\gmer_2.1.19163.exe [2013.05.01 15:08:05 | 000,000,020 | ---- | C] () -- C:\Users\Oliver\defogger_reenable [2013.05.01 15:07:27 | 000,050,477 | ---- | C] () -- C:\Users\Oliver\Desktop\Defogger.exe [2013.04.20 19:58:56 | 000,002,040 | ---- | C] () -- C:\Users\Oliver\Desktop\Avira Free Antivirus.lnk [2013.04.20 17:13:25 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.10.20 10:10:03 | 002,872,000 | ---- | C] () -- C:\Windows\System32\pwNative.exe [2012.10.20 10:10:02 | 000,015,576 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys [2012.10.20 10:09:36 | 000,010,200 | ---- | C] () -- C:\Windows\System32\pwdspio.sys [2012.10.02 12:58:17 | 000,433,590 | ---- | C] () -- C:\Users\Oliver\AppData\Local\census.cache [2012.10.02 12:57:56 | 000,106,606 | ---- | C] () -- C:\Users\Oliver\AppData\Local\ars.cache [2012.10.02 10:33:03 | 000,000,036 | ---- | C] () -- C:\Users\Oliver\AppData\Local\housecall.guid.cache [2012.09.26 20:57:14 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll [2012.09.26 20:57:14 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll [2012.09.26 20:57:14 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll [2012.09.26 20:57:14 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll [2011.05.26 09:58:29 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.05.08 00:11:58 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat [2011.05.08 00:11:56 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat [2011.04.02 22:27:21 | 2415,120,384 | -HS- | C] () -- \hiberfil.sys [2011.04.02 22:05:24 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK [2009.07.14 04:04:04 | 000,000,024 | ---- | C] () -- \autoexec.bat [2009.07.14 04:04:04 | 000,000,010 | ---- | C] () -- \config.sys [2006.11.09 14:48:07 | 000,383,786 | RHS- | C] () -- \bootmgr ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Anwendungsdaten [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Application Data [2011.04.03 00:17:43 | 000,000,000 | ---D | M] -- C:\Users\All Users\DAEMON Tools Lite [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Desktop [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Documents [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Dokumente [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Favoriten [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Favorites [2012.08.01 14:03:10 | 000,000,000 | ---D | M] -- C:\Users\All Users\GFI Software [2011.06.16 14:43:36 | 000,000,000 | ---D | M] -- C:\Users\All Users\ICQ [2012.12.05 15:58:06 | 000,000,000 | ---D | M] -- C:\Users\All Users\Samsung [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Start Menu [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Startmenü [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Templates [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Vorlagen [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Anwendungsdaten [2009.07.14 04:37:05 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Application Data [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Desktop [2011.04.02 22:54:28 | 000,000,000 | R--D | M] -- C:\Users\Default\Documents [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Downloads [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Druckumgebung [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Eigene Dateien [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Favorites [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Links [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Local Settings [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Lokale Einstellungen [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Music [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\My Documents [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\NetHood [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Netzwerkumgebung [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Pictures [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\PrintHood [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Recent [2009.07.14 04:04:25 | 000,000,000 | ---D | M] -- C:\Users\Default\Saved Games [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\SendTo [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Start Menu [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Startmenü [2009.07.14 06:53:55 | 000,000,000 | -HSD | M] -- C:\Users\Default\Templates [2009.07.14 04:04:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Videos [2011.04.02 22:54:28 | 000,000,000 | -HSD | M] -- C:\Users\Default\Vorlagen [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Anwendungsdaten [2011.04.02 22:54:45 | 000,000,000 | -H-D | M] -- C:\Users\Oliver\AppData [2012.07.12 09:33:53 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Contacts [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Cookies [2013.05.02 09:47:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Desktop [2013.02.23 22:58:06 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Documents [2013.01.20 19:44:16 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Downloads [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Druckumgebung [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Eigene Dateien [2013.01.20 19:03:11 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Favorites [2012.07.12 09:33:55 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Links [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Lokale Einstellungen [2012.07.12 09:33:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Music [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Netzwerkumgebung [2012.07.12 09:33:53 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Pictures [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Recent [2012.07.12 09:33:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Saved Games [2012.07.12 09:33:54 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Searches [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\SendTo [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Startmenü [2011.12.09 17:44:12 | 000,000,000 | ---D | M] -- C:\Users\Oliver\Tracing [2012.07.12 09:33:53 | 000,000,000 | R--D | M] -- C:\Users\Oliver\Videos [2011.04.02 22:54:45 | 000,000,000 | -HSD | M] -- C:\Users\Oliver\Vorlagen [2013.05.01 18:03:18 | 000,000,000 | ---D | M] -- C:\Users\Public\AppData [2013.04.20 17:13:25 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop [2012.11.02 18:48:40 | 000,000,000 | R--D | M] -- C:\Users\Public\Documents [2009.07.14 06:41:57 | 000,000,000 | R--D | M] -- C:\Users\Public\Downloads [2009.07.14 04:04:25 | 000,000,000 | RH-D | M] -- C:\Users\Public\Favorites [2011.05.31 18:19:33 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries [2011.04.04 21:46:05 | 000,000,000 | R--D | M] -- C:\Users\Public\Music [2009.07.14 06:41:57 | 000,000,000 | R--D | M] -- C:\Users\Public\Pictures [2009.07.14 10:56:56 | 000,000,000 | R--D | M] -- C:\Users\Public\Recorded TV [2011.04.04 21:46:15 | 000,000,000 | R--D | M] -- C:\Users\Public\Videos ========== Purity Check ========== < End of report > |
![]() | #8 |
Trojan.FakeMS

Hallo,

prima, dann haben wir es. Noch aufräumen:

Warnung: Infostealer

Aus deinen Logs ist ersichtlich, dass du Malware eingefangen hast, die es speziell auf deine sensitiven Daten (Benutzernamen, Passwörter, Onlinebankingzugangsdaten, etc.) abgesehen hat. Man kann nicht genau wissen, was alles mitgeloggt wurde, aber sicherheitshalber würd ich alle auf diesem Rechner eingegebenen Daten und Passwörter als bekannt voraussetzen.

Ich würde dir daher raten, zum Schluss oder von einem sauberen Rechner aus sämtliche Zugangsdaten, welche an diesem Rechner verwendet wurden, zu ändern.

Schritt 1
ATTFilter :OTL O4 - HKU\S-1-5-21-2336976170-3934522553-1032375680-1000..\Run: [Iksoaq] C:\Users\Oliver\AppData\Roaming\Iwlyu\wiahc.exe File not found
Schritt 2 Downloade und installiere den Internet Explorer 10. Der Internet Explorer sollte auch dann aktuell gehalten werden, wenn er nicht zum Surfen verwendet wird. Überprüfe dann mit diesem Plugin-Check, ob nun alle deine verwendeten Versionen aktuell sind und update sie anderenfalls. Cleanup Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
>> OK << Wir sind durch, deine Logs sehen für mich im Moment sauber aus. ![]() Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst. Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann. Epilog: Tipps, Dos & Don'ts ![]() Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
Auch die installierte Software sollte immer in der aktuellsten Version vorliegen. Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
![]() Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt). Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt. Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
![]() Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert. Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
![]() Abschliessend noch ein paar grundsätzliche Bemerkungen:
Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen. Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. ![]()
__________________ cheers, Leo |
![]() | ![]() Trojan.FakeMS Hi Leo, alles erledigt. Vielen, vielen Dank für die super schnelle, unkomplizierte und kompetente Hilfe! ![]() ![]() |
Trojan.FakeMS

Danke für die Rückmeldung.

Freut mich, dass wir helfen konnten.

Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun.

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten.

Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter.

Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
