Log-Analyse und Auswertung: GVU Trojaner Windows 7 64 BitWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.
GVU Trojaner Windows 7 64 Bit Hallo liebe Community, habe mir bereits einige der artverwandten Fälle angesehen und mich nun dazu entschlossen euch um eure fachkundige Hilfe zu bitten. Es handelt sich um den Computer eines guten Freundes von mir. Kleinere Probleme kriege ich in der Regel auch selbst beseitigt. Allerdings musste ich feststellen, dass bei ihm noch einiges mehr im Argen lag bzw. liegt. (In erster Linie bin ich aber schon hier wegen dem GVU-Trojaner. Der abgesicherte Modus mit Netzwerktreibern geht nicht, hatte ich gestern Abend schon kurz ausprobiert. Aber ich glaube er kann sich noch mit einem anderen Benutzer anmelden.) Java war nicht auf dem aktuellen Stand, er besucht offenbar teils recht "ominöse" Websites, verwendet bislang sonst auch gerne nicht aktuelle Software, ... . Konnte ihn nun tatsächlich von dem Sinn und Zweck des Leitfadens "Das sichere Windows System" von Paule (weiß nicht ob ich den Link hier posten darf) überzeugen. Der Gute hat mir versprochen in Zukunft mit Bedacht zu surfen und den Anschnallgurt anzulegen. Fahre später direkt zu ihm und werde versuchen die Log-Files zu posten, Frage vorab: Farbar's Recovery Scan Tool oder OTLPENet.exe von OldTimer ? Bereits im Voraus vielen Dank für eure Hilfe, Lou Schalter Edit: Bitte entschuldigt, hatte die Punkte überlesen: Ich habe Windows Vista, 7 oder 8 Erzeuge ein FRST-Logfile nach dieser Anleitung: Scan mit Farbar Recovery Scan Tool Ich habe Windows XP Erzeuge ein Logfile, das du mit OTLpe erstellt hast: Scan mit Otlpe => Werde mit FRST ein Logfile erstellen und gleich hier posten.
GVU Trojaner Windows 7 64 Bit Hi,
Sobald das Log da ist, kann ich den Rechner entsperren.
GVU Trojaner Windows 7 64 Bit Wenn ich im Abgesicherten Modus (sowohl Netzwerktreiber als auch Eingabeaufforderung) starten will bleibt es bei WINDOWS\system32\drivers\CLASSPNP.sys hängen und danach fährt sich der Rechner automatisch wieder selbst herunter.
Bei der Auswahl von "Computer reparieren" in den erweiterten Startoptionen kommt der Fehler: Status 0xc000000e Info: Fehler bei der Startauswahl. Zugriff auf ein erforderliches Gerät nicht möglich. Hm. Da ist guter Rat teuer. Habe jetzt alles Moegliche versucht, mit OTLPE hatte ich schliesslich Erfolg. Hoffe das ist o.k. Mit FRST ging garnichts, da bin ich einfach nicht weiter gekommen. Hier die Logs. Extras.txt OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 10/8/2013 11:17:52 PM - Run OTLPE by OldTimer - Version Folder = X:\Programs\OTLPE 64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 87.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS Drive F: | 273.20 Gb Total Space | 17.62 Gb Free Space | 6.45% Space Free | Partition Type: NTFS Drive G: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- E:\Windows\System32\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- E:\Windows\SysWow64\control.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 File not found htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding "{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64 "{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding "{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64 "{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64) "{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Logitech Gaming Software" = Logitech Gaming Software 8.20 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack "Microsoft Security Client" = Microsoft Security Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding "{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64 "{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding "{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64 "{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64) "{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Logitech Gaming Software" = Logitech Gaming Software 8.20 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack "Microsoft Security Client" = Microsoft Security Essentials ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\*****_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "JNLP" = JNLP "TeamSpeak 3 Client" = TeamSpeak 3 Client < End of report > OLT.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 10/8/2013 11:17:52 PM - Run OTLPE by OldTimer - Version Folder = X:\Programs\OTLPE 64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 87.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS Drive F: | 273.20 Gb Total Space | 17.62 Gb Free Space | 6.45% Space Free | Partition Type: NTFS Drive G: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011/11/09 23:11:32 | 000,204,288 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2008/01/19 04:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2008/01/19 04:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt) SRV - [2011/08/06 01:14:15 | 000,411,432 | ---- | M] (Valve Corporation) [Disabled] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010/11/20 23:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\seclogon.dll -- (seclogon) SRV - [2010/06/23 19:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto] -- E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh) SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/03/08 16:55:54 | 000,075,064 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2009/07/13 21:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\qwave.dll -- (QWAVE) SRV - [2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/27 19:00:00 | 000,356,352 | ---- | M] (AVM Berlin) [Auto] -- E:\Program Files (x86)\avmwlanstick\WLanNetService.exe -- (AVM WLAN Connection Service) SRV - [2006/10/18 10:26:16 | 000,285,216 | ---- | M] (Acronis) [Auto] -- E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2011/11/09 22:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010/12/07 14:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK) DRV:64bit: - [2009/07/14 10:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum) DRV:64bit: - [2009/04/21 13:08:10 | 000,012,800 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand] -- E:\Windows\System32\drivers\danew.sys -- (danewFltr) DRV:64bit: - [2007/02/16 10:36:21 | 000,629,536 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\timntr.sys -- (timounter) DRV:64bit: - [2007/02/16 10:36:20 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\snapman.sys -- (snapman) DRV:64bit: - [2006/12/27 19:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB) DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2005/03/28 20:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 62 77 37 8F B3 C3 CE 01 [binary data] IE - HKU\Administrator_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\Administrator_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 AC 4D D3 F3 F7 CC 01 [binary data] IE - HKU\*****_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\*****_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\LocalService_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\NetworkService_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.4: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.7: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) [2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions [2011/11/18 11:49:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2010/06/20 17:02:25 | 000,000,000 | ---D | M] (Adobe Flash) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82e4700b-58f2-4aa0-8949-964b59155c87} [2011/12/20 21:09:49 | 000,000,000 | ---D | M] (Default) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/03/11 12:08:03 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2009/02/12 16:56:10 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [2010/02/15 16:52:08 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2010/06/28 12:11:23 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010/11/27 14:00:28 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011/12/20 21:09:48 | 000,025,560 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll [2011/12/20 21:09:48 | 000,140,760 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll [2007/04/10 12:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- E:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2010/09/14 23:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011/12/20 21:09:48 | 000,067,032 | ---- | M] (mozilla.org) -- E:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll [2011/06/06 06:55:30 | 000,183,696 | ---- | M] (Adobe Systems Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2011/03/12 16:14:17 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011/03/12 16:14:17 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011/03/12 16:14:17 | 000,002,371 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\google.xml [2011/03/12 16:14:17 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011/03/12 16:14:17 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011/03/12 16:14:17 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml [2011/05/15 21:20:36 | 000,000,849 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - File not found O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - File not found O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - File not found O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - File not found O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (af0.Adblock.BHO) - {90EFF544-3981-4d46-85C9-C0361D0931D6} - E:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - File not found O2 - BHO: (no name) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - Reg Error: Value error. File not found O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found. O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - File not found O3 - HKU\Administrator_ON_F\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - File not found O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4:64bit: - HKLM..\Run: [IAAnotif] File not found O4:64bit: - HKLM..\Run: [Launch LCore] File not found O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] E:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.) O4:64bit: - HKLM..\Run: [MSC] File not found O4:64bit: - HKLM..\Run: [SoundMAX] File not found O4 - HKLM..\Run: [DeathAdder] E:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () O4 - HKLM..\Run: [DigidesignMMERefresh] E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..) O4 - HKLM..\Run: [SoundMAXPnP] E:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [VirtualCloneDrive] File not found O4 - HKLM..\Run: [vmware-tray] File not found O4 - HKU\*****_ON_F..\Run: [Google Update] File not found O4 - HKU\*****_ON_F..\Run: [SpybotSD TeaTimer] File not found O4 - HKU\LocalService_ON_F..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_F..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\LocalService_ON_F..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_F..\RunOnce: [mctadmin] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O7 - HKU\Administrator_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\*****_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\System32\nlaapi.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\System32\NapiNSP.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\System32\winrnr.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15:64bit: - .DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15:64bit: - .DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15:64bit: - .DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15:64bit: - .DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15:64bit: - *****_ON_F\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15:64bit: - *****_ON_F\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15:64bit: - *****_ON_F\..Trusted Domains: soe.com ([]* in Trusted sites) O15:64bit: - *****_ON_F\..Trusted Domains: sony.com ([]* in Trusted sites) O15:64bit: - *****_ON_F\..Trusted Ranges: Range1 ([http] in Trusted sites) O15:64bit: - *****_ON_F\..Trusted Ranges: Range1 ([https] in Trusted sites) O15:64bit: - LocalService_ON_F\..Trusted Domains: clonewarsadventures.com ([]* in ) O15:64bit: - LocalService_ON_F\..Trusted Domains: freerealms.com ([]* in ) O15:64bit: - LocalService_ON_F\..Trusted Domains: soe.com ([]* in ) O15:64bit: - LocalService_ON_F\..Trusted Domains: sony.com ([]* in ) O15:64bit: - NetworkService_ON_F\..Trusted Domains: clonewarsadventures.com ([]* in ) O15:64bit: - NetworkService_ON_F\..Trusted Domains: freerealms.com ([]* in ) O15:64bit: - NetworkService_ON_F\..Trusted Domains: soe.com ([]* in ) O15:64bit: - NetworkService_ON_F\..Trusted Domains: sony.com ([]* in ) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - E:\Windows\System32\inetcomm.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - E:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O29:64bit: - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O30:64bit: - LSA: Authentication Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (kerberos) - E:\Windows\System32\kerberos.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (schannel) - E:\Windows\System32\schannel.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (wdigest) - E:\Windows\System32\wdigest.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (tspkg) - E:\Windows\System32\tspkg.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (pku2u) - File not found O30:64bit: - LSA: Security Packages - (livessp) - File not found O30 - LSA: Security Packages - (kerberos) - E:\Windows\SysWow64\kerberos.dll (Microsoft Corporation) O30 - LSA: Security Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (schannel) - E:\Windows\SysWow64\schannel.dll (Microsoft Corporation) O30 - LSA: Security Packages - (wdigest) - E:\Windows\SysWow64\wdigest.dll (Microsoft Corporation) O30 - LSA: Security Packages - (tspkg) - E:\Windows\SysWow64\tspkg.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - File not found O30 - LSA: Security Packages - (livessp) - File not found O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2013/10/08 23:11:50 | 000,000,000 | -HSD | C] -- E:\RECYCLER [2013/10/08 14:35:33 | 001,954,124 | ---- | C] (Farbar) -- F:\Users\Administrator\Desktop\FRST64.exe [2013/10/07 19:47:21 | 004,095,448 | ---- | C] (BrightFort LLC ) -- F:\Users\Administrator\Desktop\spywareblastersetup50.exe [2013/10/07 19:43:00 | 001,032,220 | ---- | C] (Thisisu) -- F:\Users\Administrator\Desktop\JRT.exe [2013/09/26 16:21:33 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Steam [3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\*.tmp files -> E:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/10/08 13:57:58 | 001,954,124 | ---- | M] (Farbar) -- F:\Users\Administrator\Desktop\FRST64.exe [2013/10/07 19:47:21 | 004,095,448 | ---- | M] (BrightFort LLC ) -- F:\Users\Administrator\Desktop\spywareblastersetup50.exe [2013/10/07 19:43:07 | 001,032,220 | ---- | M] (Thisisu) -- F:\Users\Administrator\Desktop\JRT.exe [2013/10/07 19:24:22 | 001,045,226 | ---- | M] () -- F:\Users\Administrator\Desktop\adwcleaner.exe [3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\*.tmp files -> E:\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/10/07 19:24:02 | 001,045,226 | ---- | C] () -- F:\Users\Administrator\Desktop\adwcleaner.exe [2012/01/09 17:01:06 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin [2012/01/04 18:06:52 | 000,217,088 | ---- | C] () -- E:\Windows\SysWow64\qtmlClient.dll [2011/11/09 17:39:44 | 000,059,904 | ---- | C] () -- E:\Windows\SysWow64\OpenVideo.dll [2011/11/09 17:39:32 | 000,054,784 | ---- | C] () -- E:\Windows\SysWow64\OVDecode.dll [2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe [2011/10/08 23:37:34 | 000,000,732 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps64.dat [2011/09/12 19:06:16 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat [2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat [2010/12/22 18:05:26 | 000,001,356 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps.dat [2010/11/27 13:56:32 | 000,000,120 | ---- | C] () -- E:\Users\*****\AppData\default.pls [2010/06/06 14:15:17 | 000,122,992 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat [2010/03/08 16:55:54 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe [2010/02/05 10:34:43 | 000,000,093 | ---- | C] () -- E:\Users\*****\AppData\Local\fusioncache.dat [2009/12/09 20:29:02 | 000,052,736 | ---- | C] () -- E:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/11/22 21:00:42 | 000,000,000 | ---- | C] () -- E:\Windows\SysWow64\Access.dat [2009/11/08 12:37:00 | 000,044,544 | ---- | C] () -- E:\Windows\SysWow64\Gif89.dll [2009/09/27 09:13:48 | 000,000,033 | ---- | C] () -- E:\Windows\Multimedia manager.INI [2009/01/23 18:40:27 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat [2009/01/01 12:00:39 | 000,043,520 | ---- | C] () -- E:\Windows\SysWow64\CmdLineExt03.dll [2008/11/27 19:29:00 | 000,096,801 | ---- | C] () -- E:\Windows\War3Unin.dat [2008/08/25 15:34:16 | 000,000,466 | RHS- | C] () -- E:\ProgramData\ntuser.pol [2008/08/12 16:17:52 | 000,003,308 | ---- | C] () -- E:\Windows\bthservsdp.dat [2008/08/08 15:57:05 | 000,106,605 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchema.bin [2008/08/08 15:57:05 | 000,018,904 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin [2008/07/29 12:02:05 | 000,000,000 | ---- | C] () -- E:\ProgramData\LauncherAccess.dt [2008/07/29 12:00:03 | 000,005,632 | ---- | C] () -- E:\Windows\SysWow64\drivers\StarOpen.sys [2008/04/22 17:46:56 | 000,368,640 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll [2008/04/22 17:46:42 | 000,060,124 | ---- | C] () -- E:\Windows\SysWow64\tcpmon.ini [2008/02/18 16:26:18 | 000,001,167 | ---- | C] () -- E:\Windows\mozver.dat [2008/02/14 13:32:04 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat [2008/02/12 15:46:22 | 000,214,864 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe [2008/02/12 15:46:21 | 000,669,184 | ---- | C] () -- E:\Windows\SysWow64\pbsvc.exe [2008/02/12 15:46:21 | 000,075,064 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe [2008/02/11 15:22:15 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini [2007/05/19 09:22:17 | 001,499,938 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI [2006/11/02 11:35:48 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat [2006/11/02 11:00:58 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll [2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat [2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT [2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat [2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin ========== LOP Check ========== [2008/02/12 08:04:51 | 000,000,000 | ---D | M] -- E:\ProgramData\Acronis [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data [2011/02/03 14:59:54 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente [2011/11/18 11:48:32 | 000,000,000 | ---D | M] -- E:\ProgramData\Easybits GO [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites [2011/05/23 07:23:38 | 000,000,000 | ---D | M] -- E:\ProgramData\HighAndes [2012/01/04 19:05:27 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy [2011/09/23 11:31:20 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic [2012/02/02 19:24:32 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files [2010/03/15 16:13:37 | 000,000,000 | ---D | M] -- E:\ProgramData\Samsung [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen [2010/02/15 11:14:21 | 000,000,000 | ---D | M] -- E:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3} [2010/06/28 11:47:55 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2012/02/02 20:09:36 | 000,032,606 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT [2012/02/02 20:05:00 | 000,000,420 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{67EDA5FC-0019-45FD-BD8F-60FFCB19790F}.job [2012/02/02 20:07:06 | 000,000,454 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{FF4DA3C5-B76D-406A-8828-716AE39A637B}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 128 bytes -> E:\Windows:nlsPreferences @Alternate Data Stream - 1264 bytes -> E:\ProgramData\Microsoft:SQasxH89fAhVdXZTo4rQsa1lB8 @Alternate Data Stream - 1257 bytes -> E:\ProgramData\Microsoft:mF4IF8xPxZPwwlfGMSTyMdmOB @Alternate Data Stream - 1241 bytes -> E:\ProgramData\Microsoft:DsK0QpZjrH4Bu7uFCcUC3mv2JNM @Alternate Data Stream - 1237 bytes -> E:\ProgramData\Microsoft:BzN69YMHrh8PpgVkajVTf @Alternate Data Stream - 1126 bytes -> E:\Program Files (x86)\Common Files\System:8pBA6f4chx8LvxmXGoa @Alternate Data Stream - 1075 bytes -> E:\Users\*****\AppData\Local:Gy1L44sVjSHClQdReyzsUh8 < End of report > |
GVU Trojaner Windows 7 64 Bit Hallo, und du bist dir sicher, dass hier Malware das Problem ist? (Hat man den GVU-Sperrschirm gesehen?) In diesem Log kann ich keine Spur davon erkennen..
GVU Trojaner Windows 7 64 Bit Hallo Leo, der Form halber zunaechst einmal vielen Dank! Finde das toll, dass du mir bei der Sache weiter hilfst. Ja, ich bin mir sehr sicher. Sobald ich mich unter dem Benutzer anmelde kommt der Sperrschirm. Soll ich mal so starten und dir eine Hardcopy davon einstellen? Mit FRST habe ich es nicht hin bekommen, siehe obig beschriebene Fehlermeldung. Dann habe ich es mit OTLPE versucht. Ging zunaechst auch nicht, dann habe ich mir eine Start-CD damit erstellt und es hin bekommen. Sitze gerade am betroffenen Computer und nutze den InternetExplorer der Benutzeroberflaeche von der gebooteten CD. Soll ich mal bei den Scans ueberall auf ALL einstellen? Die Windows-Installation ist hier ein wenig merkwuerdig gestaltet ... es ist ein Raid, aber das System ist auf der Platte F so wie es aussieht. Edit Er hat gestern Abend offenbar noch diverse AntiMalware-Software installiert und mit einem dieser Programme drueber gebuegelt meint er gerade. Also vom Administrator-Benutzerkonto aus. Da kann man sich nach wie vor anmelden. Zudem hat er gestern Abend noch 30 Windows-Updates gestartet, welche es noch heruntergeladen hatte bevor der Rechner aus gegangen ist. Vorhin hat es mir beim Booten die ganze Zeit angezeigt, dass etwas beim Windows-Update schief gelaufen sei, es wuerde rueckgaengig gemacht werden, hernach konnte ich mich ganz normal als Admin anmelden. Habe dann mal unter dem Admin-Kondo prophylaktisch die Windows-Updates fuer den Moment wieder komplett rausgenommen, diese duerften uns jetzt gerade kaum weiterhelfen. Edit 2 Auf der Festplatte E sitzt auch noch ein Betriebtssystem, vielleicht hat es sich ja dort versteckt ... ? Hier die OLT.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 10/9/2013 12:26:53 AM - Run OTLPE by OldTimer - Version Folder = X:\Programs\OTLPE 64bit-Windows Vista (TM) Ultimate Service Pack 1 (Version = 6.0.6001) - Type = System Internet Explorer (Version = 8.0.6001.19048) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 93.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS Drive F: | 273.20 Gb Total Space | 17.62 Gb Free Space | 6.45% Space Free | Partition Type: NTFS Drive G: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011/11/09 23:11:32 | 000,204,288 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2008/05/01 20:49:54 | 000,160,272 | ---- | M] (Logitech, Inc.) [Auto] -- E:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV:64bit: - [2008/01/19 04:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2008/01/19 04:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt) SRV - [2011/10/15 04:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2011/10/14 19:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2011/08/06 01:14:15 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010/06/23 19:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto] -- E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh) SRV - [2010/06/17 17:50:00 | 003,890,920 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand] -- E:\Windows\SysWow64\GameMon.des -- (npggsvc) SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/03/08 16:55:54 | 000,075,064 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2009/07/21 09:34:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2009/06/07 07:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto] -- E:\Windows\SysWOW64\NlsSrv32.exe -- (nlsX86cc) SRV - [2009/05/13 11:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/27 19:00:00 | 000,356,352 | ---- | M] (AVM Berlin) [Auto] -- E:\Program Files (x86)\avmwlanstick\WLanNetService.exe -- (AVM WLAN Connection Service) SRV - [2006/10/18 10:26:16 | 000,285,216 | ---- | M] (Acronis) [Auto] -- E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2011/11/09 22:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2011/10/17 13:40:40 | 000,090,128 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand] -- E:\Windows\System32\drivers\AtihdLH6.sys -- (AtiHDAudioService) DRV:64bit: - [2011/08/02 12:38:56 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2011/02/03 15:00:31 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System] -- E:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2010/12/07 14:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK) DRV:64bit: - [2010/06/13 20:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand] -- E:\Windows\System32\drivers\TFsExDisk.sys -- (TFsExDisk) DRV:64bit: - [2010/04/26 22:25:14 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm) DRV:64bit: - [2010/04/26 22:25:14 | 000,127,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) DRV:64bit: - [2010/04/26 22:25:14 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl) DRV:64bit: - [2010/03/18 21:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- E:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2009/12/07 16:32:51 | 000,074,880 | ---- | M] (Avira GmbH) [File_System | Auto] -- E:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2009/09/30 10:32:44 | 000,120,336 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2009/09/09 14:25:14 | 000,871,408 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- E:\Windows\System32\drivers\sptd.sys -- (sptd) DRV:64bit: - [2009/09/09 13:17:41 | 000,033,344 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV:64bit: - [2009/07/14 10:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum) DRV:64bit: - [2009/04/21 13:08:10 | 000,012,800 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand] -- E:\Windows\System32\drivers\danew.sys -- (danewFltr) DRV:64bit: - [2008/02/28 21:17:08 | 000,041,488 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt) DRV:64bit: - [2008/02/28 21:17:00 | 000,112,144 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE) DRV:64bit: - [2008/02/28 21:16:52 | 000,057,360 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV:64bit: - [2008/02/28 21:16:44 | 000,054,800 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV:64bit: - [2008/02/28 21:16:28 | 000,113,680 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou) DRV:64bit: - [2008/01/19 02:47:12 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WpdUsb.sys -- (WpdUsb) DRV:64bit: - [2008/01/19 02:34:08 | 000,048,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\avc.sys -- (Avc) DRV:64bit: - [2008/01/19 02:34:06 | 000,058,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\61883.sys -- (61883) DRV:64bit: - [2008/01/19 02:34:04 | 000,061,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\msdv.sys -- (MSDV) DRV:64bit: - [2007/02/16 10:36:21 | 000,629,536 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\timntr.sys -- (timounter) DRV:64bit: - [2007/02/16 10:36:21 | 000,065,312 | ---- | M] (Acronis) [File_System | Auto] -- E:\Windows\System32\drivers\tifsfilt.sys -- (tifsfilter) DRV:64bit: - [2007/02/16 10:36:20 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\snapman.sys -- (snapman) DRV:64bit: - [2007/01/12 12:43:40 | 000,037,552 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\frmupgr.sys -- (DFUBTUSB) DRV:64bit: - [2006/12/27 19:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB) DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2005/03/28 20:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) DRV - [2010/06/13 20:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand] -- E:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk) DRV - [2006/07/24 10:05:00 | 000,005,632 | ---- | M] () [File_System | System] -- E:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen) DRV - [2005/01/04 05:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand] -- E:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\*****_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\*****_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\*****_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\Lisa_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034" FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034" FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034" FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=: FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\*****\Music\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WPF,version=3.5: E:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/11 21:28:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/12/20 21:09:49 | 000,000,000 | ---D | M] [2010/06/01 15:33:19 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Extensions [2010/06/05 22:12:15 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions [2009/11/19 07:39:36 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010/06/05 22:12:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2009/11/19 07:39:36 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions\staged-xpis [2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions [2011/04/18 07:52:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010/06/05 22:12:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011/04/18 07:52:28 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8} [2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions [2011/11/18 11:49:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2010/06/20 17:02:25 | 000,000,000 | ---D | M] (Adobe Flash) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82e4700b-58f2-4aa0-8949-964b59155c87} [2010/06/28 12:11:23 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010/11/27 14:00:28 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} File not found (No name found) -- E:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C} File not found (No name found) -- E:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{B13721C7-F507-4982-B2E5-502A71474FED} [2010/09/14 23:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011/03/12 16:14:17 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011/03/12 16:14:17 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011/03/12 16:14:17 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011/03/12 16:14:17 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011/03/12 16:14:17 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe Flash) - {82E4700B-58F2-4AA0-8949-964B59155C87} - E:\Users\*****\AppData\Roaming\AdobeFlash\IE\AdobeFlash.dll (Adobe Systems, Incorporated) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4:64bit: - HKLM..\Run: [Bluetooth Connection Assistant] File not found O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] E:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4:64bit: - HKLM..\Run: [Launch LCDMon] E:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LGDCore] E:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] E:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] E:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.) O4:64bit: - HKLM..\Run: [Windows Defender] E:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [AcronisTimounterMonitor] E:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis) O4 - HKLM..\Run: [APSDaemon] E:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [AVMWlanClient] E:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin) O4 - HKLM..\Run: [DeathAdder] E:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () O4 - HKLM..\Run: [DigidesignMMERefresh] E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..) O4 - HKLM..\Run: [DivXUpdate] E:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [TrueImageMonitor.exe] E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) O4 - HKU\*****_ON_E..\Run: [AutoStartNPSAgent] D:\Anwendungen\NewPCStudio\NPSAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKU\*****_ON_E..\Run: [avupdate] File not found O4 - HKU\*****_ON_E..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] E:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\*****_ON_E..\Run: [DAEMON Tools Lite] D:\Anwendungen\Daemon\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\Lisa_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation) O4 - HKU\LocalService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\LocalService_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation) O4 - HKU\NetworkService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation) O4 - HKU\UpdatusUser_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\UpdatusUser_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation) O4 - HKU\Lisa_ON_E..\RunOnce: [FlashPlayerUpdate] E:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_Plugin.exe (Adobe Systems, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKU\*****_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data] O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - E:\Users\*****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - E:\Users\*****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - File not found O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - E:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - E:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - E:\Windows\System32\DreamScene.dll (Microsoft Corporation) O24 - Desktop WallPaper: D:\#Sicherung\200SATA\Internet Explorer Wallpaper.bmp O24 - Desktop BackupWallPaper: D:\#Sicherung\200SATA\Internet Explorer Wallpaper.bmp O30:64bit: - LSA: Authentication Packages - (relog_ap) - E:\Windows\System32\relog_ap.dll (Acronis) O30 - LSA: Authentication Packages - (relog_ap) - E:\Windows\SysWow64\relog_ap.dll (Acronis) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{325ed12e-aac4-11de-9084-00040ec6ee83}\Shell\AutoRun\command - "" = K:\installer.exe O33 - MountPoints2\{325ed12e-aac4-11de-9084-00040ec6ee83}\Shell\verb\command - "" = K:\installer.exe O33 - MountPoints2\{399d00a2-2fc5-11e0-a0cd-001a922d4236}\Shell - "" = AutoRun O33 - MountPoints2\{399d00a2-2fc5-11e0-a0cd-001a922d4236}\Shell\AutoRun\command - "" = I:\Autorun.exe O33 - MountPoints2\{399d00a9-2fc5-11e0-a0cd-001a922d4236}\Shell - "" = AutoRun O33 - MountPoints2\{399d00a9-2fc5-11e0-a0cd-001a922d4236}\Shell\AutoRun\command - "" = J:\Autorun.exe O33 - MountPoints2\{c86c8c10-d80a-11dc-9404-00040ec6ee83}\Shell\AutoRun\command - "" = E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe O33 - MountPoints2\{fbb62ea3-9d70-11de-a731-00040ec6ee83}\Shell - "" = AutoRun O33 - MountPoints2\{fbb62ea3-9d70-11de-a731-00040ec6ee83}\Shell\AutoRun\command - "" = I:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2013/10/08 23:11:50 | 000,000,000 | -HSD | C] -- E:\RECYCLER [2013/09/26 16:21:33 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Steam [3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\*.tmp files -> E:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\*.tmp files -> E:\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/01/09 17:01:06 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin [2012/01/04 18:06:52 | 000,217,088 | ---- | C] () -- E:\Windows\SysWow64\qtmlClient.dll [2011/11/09 17:39:44 | 000,059,904 | ---- | C] () -- E:\Windows\SysWow64\OpenVideo.dll [2011/11/09 17:39:32 | 000,054,784 | ---- | C] () -- E:\Windows\SysWow64\OVDecode.dll [2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe [2011/10/08 23:37:34 | 000,000,732 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps64.dat [2011/09/12 19:06:16 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat [2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat [2010/12/22 18:05:26 | 000,001,356 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps.dat [2010/11/27 13:56:32 | 000,000,120 | ---- | C] () -- E:\Users\*****\AppData\default.pls [2010/06/06 14:15:17 | 000,122,992 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat [2010/03/08 16:55:54 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe [2010/02/05 10:34:43 | 000,000,093 | ---- | C] () -- E:\Users\*****\AppData\Local\fusioncache.dat [2009/12/09 20:29:02 | 000,052,736 | ---- | C] () -- E:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/11/22 21:00:42 | 000,000,000 | ---- | C] () -- E:\Windows\SysWow64\Access.dat [2009/11/08 12:37:00 | 000,044,544 | ---- | C] () -- E:\Windows\SysWow64\Gif89.dll [2009/09/27 09:13:48 | 000,000,033 | ---- | C] () -- E:\Windows\Multimedia manager.INI [2009/01/23 18:40:27 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat [2009/01/01 12:00:39 | 000,043,520 | ---- | C] () -- E:\Windows\SysWow64\CmdLineExt03.dll [2008/11/27 19:29:00 | 000,096,801 | ---- | C] () -- E:\Windows\War3Unin.dat [2008/08/25 15:34:16 | 000,000,466 | RHS- | C] () -- E:\ProgramData\ntuser.pol [2008/08/12 16:17:52 | 000,003,308 | ---- | C] () -- E:\Windows\bthservsdp.dat [2008/08/08 15:57:05 | 000,106,605 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchema.bin [2008/08/08 15:57:05 | 000,018,904 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin [2008/07/29 12:02:05 | 000,000,000 | ---- | C] () -- E:\ProgramData\LauncherAccess.dt [2008/07/29 12:00:03 | 000,005,632 | ---- | C] () -- E:\Windows\SysWow64\drivers\StarOpen.sys [2008/04/22 17:46:56 | 000,368,640 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll [2008/04/22 17:46:42 | 000,060,124 | ---- | C] () -- E:\Windows\SysWow64\tcpmon.ini [2008/02/18 16:26:18 | 000,001,167 | ---- | C] () -- E:\Windows\mozver.dat [2008/02/14 13:32:04 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat [2008/02/12 15:46:22 | 000,214,864 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe [2008/02/12 15:46:21 | 000,669,184 | ---- | C] () -- E:\Windows\SysWow64\pbsvc.exe [2008/02/12 15:46:21 | 000,075,064 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe [2008/02/11 15:22:15 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini [2007/05/19 09:22:17 | 001,499,938 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI [2006/11/02 11:35:48 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat [2006/11/02 11:00:58 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll [2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat [2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT [2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat [2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin ========== LOP Check ========== [2008/02/12 08:04:51 | 000,000,000 | ---D | M] -- E:\ProgramData\Acronis [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data [2011/02/03 14:59:54 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente [2011/11/18 11:48:32 | 000,000,000 | ---D | M] -- E:\ProgramData\Easybits GO [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites [2011/05/23 07:23:38 | 000,000,000 | ---D | M] -- E:\ProgramData\HighAndes [2012/01/04 19:05:27 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy [2011/09/23 11:31:20 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic [2012/02/02 19:24:32 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files [2010/03/15 16:13:37 | 000,000,000 | ---D | M] -- E:\ProgramData\Samsung [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen [2010/02/15 11:14:21 | 000,000,000 | ---D | M] -- E:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3} [2010/06/28 11:47:55 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2012/02/02 20:09:36 | 000,032,606 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT [2012/02/02 20:05:00 | 000,000,420 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{67EDA5FC-0019-45FD-BD8F-60FFCB19790F}.job [2012/02/02 20:07:06 | 000,000,454 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{FF4DA3C5-B76D-406A-8828-716AE39A637B}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 128 bytes -> E:\Windows:nlsPreferences @Alternate Data Stream - 1264 bytes -> E:\ProgramData\Microsoft:SQasxH89fAhVdXZTo4rQsa1lB8 @Alternate Data Stream - 1257 bytes -> E:\ProgramData\Microsoft:mF4IF8xPxZPwwlfGMSTyMdmOB @Alternate Data Stream - 1241 bytes -> E:\ProgramData\Microsoft:DsK0QpZjrH4Bu7uFCcUC3mv2JNM @Alternate Data Stream - 1237 bytes -> E:\ProgramData\Microsoft:BzN69YMHrh8PpgVkajVTf @Alternate Data Stream - 1126 bytes -> E:\Program Files (x86)\Common Files\System:8pBA6f4chx8LvxmXGoa @Alternate Data Stream - 1075 bytes -> E:\Users\*****\AppData\Local:Gy1L44sVjSHClQdReyzsUh8 < End of report > [/CODE] Geändert von Lou Schalter (08.10.2013 um 22:31 Uhr) |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Trojaner Windows 7 64 Bit Hallo, Zitat:
Gehe bitte in diesen Admin-Account und mach dort einen FRST-Scan wie folgt: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
GVU Trojaner Windows 7 64 Bit Das hatte ich vorhin bereits probiert. Da hatte es dann als es bei SCHEDLGU.txt war erstmal gehangen, danach kam die Fehlermeldung Line 11324 File G{backslash}FRST64.exe Error in expression EDIT Bin gerade als Administrator angemeldet, habe mit FRST64 gescannt, hier die (leere) Logdatei: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by Administrator at 2013-10-09 00:49:59 Running from C:\Users\Administrator\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AutoIt Error Line 11324 (File "C:\Users\Administrator\Desktop\FRST64.exe"): Error: Error in Expression Und vorher, während dem Scannen hat sich Microsoft Security Essentials gemeldet und angezeigt: Von Security Essentials wurden unbekannte Elemente auf dem PC gefunden. (...) Dateipfad: C:\ProgramData\4wcl7hv.plz EDIT 2 Hier noch der Log von Gmer (auch auf dem Admin-Konto ausgeführt) Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-10-09 01:28:18 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk2\DR2 -> \Device\Scsi\mv64xx1Port1Path0Target0Lun0 MARVELL_ rev.1.01 273,31GB Running: gmer_2.1.19163.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\pwtoapod.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!GetInformation + 7 0000000010001047 18 bytes [10, 33, C4, 89, 44, 24, 1C, ...] .text C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!GetInformation + 26 000000001000105a 10 bytes [10, 8D, 4C, 24, 10, C7, 44, ...] .text ... * 11 .text C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!getSubProductCode + 6 00000000100010d6 3 bytes [A1, 94, D0] .text C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!getSubProductCode + 10 00000000100010da 8 bytes [10, 33, C4, 89, 84, 24, 20, ...] .text C:\Windows\system32\hasplms.exe[2836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76] .text C:\Windows\system32\hasplms.exe[2836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76] .text ... * 2 .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072dc1a22 2 bytes [DC, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072dc1ad0 2 bytes [DC, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072dc1b08 2 bytes [DC, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072dc1bba 2 bytes [DC, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072dc1bda 2 bytes [DC, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076fb1465 2 bytes [FB, 76] .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076fb14bb 2 bytes [FB, 76] .text ... * 2 .text C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefd8d4ed0 9 bytes [68, 78, 03, FE, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW 000007fefbc65c54 7 bytes [68, 08, 03, FE, 02, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet 000007fefbc65c64 9 bytes [68, 40, 03, FE, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefee617a0 9 bytes [68, B0, 03, FE, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A 0000000076e1f578 7 bytes JMP 0000000103340570 .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W 0000000076e2b0cc 7 bytes JMP 00000001033405a8 .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\kernel32.dll!CreateThread 0000000076cf6580 9 bytes JMP 00000001033404c8 .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefdaa75f0 7 bytes [68, E0, 05, 34, 03, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefd871180 10 bytes [68, C0, 06, 34, 03, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefd871320 7 bytes [68, 50, 06, 34, 03, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefd874450 6 bytes [68, 18, 06, 34, 03, C3] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefd876720 10 bytes [68, 88, 06, 34, 03, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefd8d4ed0 9 bytes [68, 78, 03, 34, 03, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW 000007fefbc65c54 7 bytes [68, 08, 03, 34, 03, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet 000007fefbc65c64 9 bytes [68, 40, 03, 34, 03, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefee617a0 9 bytes [68, B0, 03, 34, 03, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A 0000000076e1f578 7 bytes JMP 0000000102ff0570 .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W 0000000076e2b0cc 7 bytes JMP 0000000102ff05a8 .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\kernel32.dll!CreateThread 0000000076cf6580 9 bytes JMP 0000000102ff04c8 .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefdaa75f0 7 bytes [68, E0, 05, FF, 02, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefd871180 10 bytes [68, C0, 06, FF, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefd871320 7 bytes [68, 50, 06, FF, 02, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefd874450 6 bytes [68, 18, 06, FF, 02, C3] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefd876720 10 bytes [68, 88, 06, FF, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefd8d4ed0 9 bytes [68, 78, 03, FF, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW 000007fefbc65c54 7 bytes [68, 08, 03, FF, 02, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet 000007fefbc65c64 9 bytes [68, 40, 03, FF, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefee617a0 9 bytes [68, B0, 03, FF, 02, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A 0000000076e1f578 7 bytes JMP 0000000100bd0570 .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W 0000000076e2b0cc 7 bytes JMP 0000000100bd05a8 .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\kernel32.dll!CreateThread 0000000076cf6580 9 bytes JMP 0000000100bd04c8 .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefdaa75f0 7 bytes [68, E0, 05, BD, 00, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefd871180 10 bytes [68, C0, 06, BD, 00, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefd871320 7 bytes [68, 50, 06, BD, 00, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefd874450 6 bytes [68, 18, 06, BD, 00, C3] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefd876720 10 bytes [68, 88, 06, BD, 00, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefd8d4ed0 9 bytes [68, 78, 03, BD, 00, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW 000007fefbc65c54 7 bytes [68, 08, 03, BD, 00, C3, CC] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet 000007fefbc65c64 9 bytes [68, 40, 03, BD, 00, C3, CC, ...] .text C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefee617a0 9 bytes [68, B0, 03, BD, 00, C3, CC, ...] ---- Threads - GMER 2.1 ---- Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:5052] 0000000075df7587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:3020] 000000006db50cb3 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:4144] 0000000077032e65 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:3004] 0000000077033e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:10040] 0000000077033e85 ---- EOF - GMER 2.1 ---- Es ist spaet, frage mich gerade wo diese ominoese Partition G auf einmal herkommt ... jedenfalls ist hier auch ein Betriebssystem installiert. Hier die Logfiles. OTL.txt Code:
ATTFilter OTL logfile created on: 10/9/2013 2:58:46 AM - Run OTLPE by OldTimer - Version Folder = X:\Programs\OTLPE 64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS Drive F: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32 Drive G: | 273.20 Gb Total Space | 17.53 Gb Free Space | 6.42% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011/11/09 23:11:32 | 000,204,288 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2008/01/19 04:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2008/01/19 04:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt) SRV - [2011/08/06 01:14:15 | 000,411,432 | ---- | M] (Valve Corporation) [Disabled] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010/11/20 23:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand] -- G:\Windows\System32\seclogon.dll -- (seclogon) SRV - [2010/06/23 19:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto] -- E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh) SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/03/08 16:55:54 | 000,075,064 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2009/07/13 21:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand] -- G:\Windows\System32\qwave.dll -- (QWAVE) SRV - [2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/27 19:00:00 | 000,356,352 | ---- | M] (AVM Berlin) [Auto] -- E:\Program Files (x86)\avmwlanstick\WLanNetService.exe -- (AVM WLAN Connection Service) SRV - [2006/10/18 10:26:16 | 000,285,216 | ---- | M] (Acronis) [Auto] -- E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2011/11/09 22:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010/12/07 14:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK) DRV:64bit: - [2009/07/14 10:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum) DRV:64bit: - [2009/04/21 13:08:10 | 000,012,800 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand] -- E:\Windows\System32\drivers\danew.sys -- (danewFltr) DRV:64bit: - [2007/02/16 10:36:21 | 000,629,536 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\timntr.sys -- (timounter) DRV:64bit: - [2007/02/16 10:36:20 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\snapman.sys -- (snapman) DRV:64bit: - [2006/12/27 19:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB) DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2005/03/28 20:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 62 77 37 8F B3 C3 CE 01 [binary data] IE - HKU\Administrator_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\Administrator_ON_G\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 AC 4D D3 F3 F7 CC 01 [binary data] IE - HKU\*****_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\*****_ON_G\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\LocalService_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\NetworkService_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: File not found FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.4: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.7: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.0: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) [2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions [2011/11/18 11:49:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2010/06/20 17:02:25 | 000,000,000 | ---D | M] (Adobe Flash) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82e4700b-58f2-4aa0-8949-964b59155c87} [2011/12/20 21:09:49 | 000,000,000 | ---D | M] (Default) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/03/11 12:08:03 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2009/02/12 16:56:10 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [2010/02/15 16:52:08 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2010/06/28 12:11:23 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010/11/27 14:00:28 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011/12/20 21:09:48 | 000,025,560 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll [2011/12/20 21:09:48 | 000,140,760 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll [2007/04/10 12:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- E:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2010/09/14 23:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011/12/20 21:09:48 | 000,067,032 | ---- | M] (mozilla.org) -- E:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll [2011/06/06 06:55:30 | 000,183,696 | ---- | M] (Adobe Systems Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2011/03/12 16:14:17 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2011/03/12 16:14:17 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2011/03/12 16:14:17 | 000,002,371 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\google.xml [2011/03/12 16:14:17 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2011/03/12 16:14:17 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2011/03/12 16:14:17 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml [2011/05/15 21:20:36 | 000,000,849 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - File not found O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - File not found O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - File not found O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - File not found O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (af0.Adblock.BHO) - {90EFF544-3981-4d46-85C9-C0361D0931D6} - E:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - File not found O2 - BHO: (no name) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - Reg Error: Value error. File not found O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found. O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - File not found O3 - HKU\Administrator_ON_G\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - File not found O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4:64bit: - HKLM..\Run: [IAAnotif] File not found O4:64bit: - HKLM..\Run: [Launch LCore] File not found O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] E:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.) O4:64bit: - HKLM..\Run: [MSC] File not found O4:64bit: - HKLM..\Run: [SoundMAX] File not found O4 - HKLM..\Run: [DeathAdder] E:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () O4 - HKLM..\Run: [DigidesignMMERefresh] E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..) O4 - HKLM..\Run: [SoundMAXPnP] E:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [VirtualCloneDrive] File not found O4 - HKLM..\Run: [vmware-tray] File not found O4 - HKU\*****_ON_G..\Run: [Google Update] File not found O4 - HKU\*****_ON_G..\Run: [SpybotSD TeaTimer] File not found O4 - HKU\LocalService_ON_G..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_G..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\LocalService_ON_G..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_G..\RunOnce: [mctadmin] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O7 - HKU\Administrator_ON_G\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\*****_ON_G\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\System32\nlaapi.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\System32\NapiNSP.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\System32\winrnr.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - File not found O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\System32\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15:64bit: - .DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15:64bit: - .DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15:64bit: - .DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15:64bit: - .DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15:64bit: - *****_ON_G\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15:64bit: - *****_ON_G\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15:64bit: - *****_ON_G\..Trusted Domains: soe.com ([]* in Trusted sites) O15:64bit: - *****_ON_G\..Trusted Domains: sony.com ([]* in Trusted sites) O15:64bit: - *****_ON_G\..Trusted Ranges: Range1 ([http] in Trusted sites) O15:64bit: - *****_ON_G\..Trusted Ranges: Range1 ([https] in Trusted sites) O15:64bit: - LocalService_ON_G\..Trusted Domains: clonewarsadventures.com ([]* in ) O15:64bit: - LocalService_ON_G\..Trusted Domains: freerealms.com ([]* in ) O15:64bit: - LocalService_ON_G\..Trusted Domains: soe.com ([]* in ) O15:64bit: - LocalService_ON_G\..Trusted Domains: sony.com ([]* in ) O15:64bit: - NetworkService_ON_G\..Trusted Domains: clonewarsadventures.com ([]* in ) O15:64bit: - NetworkService_ON_G\..Trusted Domains: freerealms.com ([]* in ) O15:64bit: - NetworkService_ON_G\..Trusted Domains: soe.com ([]* in ) O15:64bit: - NetworkService_ON_G\..Trusted Domains: sony.com ([]* in ) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - E:\Windows\System32\inetcomm.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - E:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O29:64bit: - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O30:64bit: - LSA: Authentication Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (kerberos) - E:\Windows\System32\kerberos.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (schannel) - E:\Windows\System32\schannel.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (wdigest) - E:\Windows\System32\wdigest.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (tspkg) - E:\Windows\System32\tspkg.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (pku2u) - File not found O30:64bit: - LSA: Security Packages - (livessp) - File not found O30 - LSA: Security Packages - (kerberos) - E:\Windows\SysWow64\kerberos.dll (Microsoft Corporation) O30 - LSA: Security Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (schannel) - E:\Windows\SysWow64\schannel.dll (Microsoft Corporation) O30 - LSA: Security Packages - (wdigest) - E:\Windows\SysWow64\wdigest.dll (Microsoft Corporation) O30 - LSA: Security Packages - (tspkg) - E:\Windows\SysWow64\tspkg.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - File not found O30 - LSA: Security Packages - (livessp) - File not found O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2013/10/08 23:11:50 | 000,000,000 | -HSD | C] -- E:\RECYCLER [2013/09/26 16:21:33 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Steam [3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\*.tmp files -> E:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\*.tmp files -> E:\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/01/09 17:01:06 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin [2012/01/04 18:06:52 | 000,217,088 | ---- | C] () -- E:\Windows\SysWow64\qtmlClient.dll [2011/11/09 17:39:44 | 000,059,904 | ---- | C] () -- E:\Windows\SysWow64\OpenVideo.dll [2011/11/09 17:39:32 | 000,054,784 | ---- | C] () -- E:\Windows\SysWow64\OVDecode.dll [2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe [2011/10/08 23:37:34 | 000,000,732 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps64.dat [2011/09/12 19:06:16 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat [2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat [2010/12/22 18:05:26 | 000,001,356 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps.dat [2010/11/27 13:56:32 | 000,000,120 | ---- | C] () -- E:\Users\*****\AppData\default.pls [2010/06/06 14:15:17 | 000,122,992 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat [2010/03/08 16:55:54 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe [2010/02/05 10:34:43 | 000,000,093 | ---- | C] () -- E:\Users\*****\AppData\Local\fusioncache.dat [2009/12/09 20:29:02 | 000,052,736 | ---- | C] () -- E:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/11/22 21:00:42 | 000,000,000 | ---- | C] () -- E:\Windows\SysWow64\Access.dat [2009/11/08 12:37:00 | 000,044,544 | ---- | C] () -- E:\Windows\SysWow64\Gif89.dll [2009/09/27 09:13:48 | 000,000,033 | ---- | C] () -- E:\Windows\Multimedia manager.INI [2009/01/23 18:40:27 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat [2009/01/01 12:00:39 | 000,043,520 | ---- | C] () -- E:\Windows\SysWow64\CmdLineExt03.dll [2008/11/27 19:29:00 | 000,096,801 | ---- | C] () -- E:\Windows\War3Unin.dat [2008/08/25 15:34:16 | 000,000,466 | RHS- | C] () -- E:\ProgramData\ntuser.pol [2008/08/12 16:17:52 | 000,003,308 | ---- | C] () -- E:\Windows\bthservsdp.dat [2008/08/08 15:57:05 | 000,106,605 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchema.bin [2008/08/08 15:57:05 | 000,018,904 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin [2008/07/29 12:02:05 | 000,000,000 | ---- | C] () -- E:\ProgramData\LauncherAccess.dt [2008/07/29 12:00:03 | 000,005,632 | ---- | C] () -- E:\Windows\SysWow64\drivers\StarOpen.sys [2008/04/22 17:46:56 | 000,368,640 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll [2008/04/22 17:46:42 | 000,060,124 | ---- | C] () -- E:\Windows\SysWow64\tcpmon.ini [2008/02/18 16:26:18 | 000,001,167 | ---- | C] () -- E:\Windows\mozver.dat [2008/02/14 13:32:04 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat [2008/02/12 15:46:22 | 000,214,864 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe [2008/02/12 15:46:21 | 000,669,184 | ---- | C] () -- E:\Windows\SysWow64\pbsvc.exe [2008/02/12 15:46:21 | 000,075,064 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe [2008/02/11 15:22:15 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini [2007/05/19 09:22:17 | 001,499,938 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI [2006/11/02 11:35:48 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat [2006/11/02 11:00:58 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll [2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat [2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT [2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat [2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin ========== LOP Check ========== [2008/02/12 08:04:51 | 000,000,000 | ---D | M] -- E:\ProgramData\Acronis [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data [2011/02/03 14:59:54 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente [2011/11/18 11:48:32 | 000,000,000 | ---D | M] -- E:\ProgramData\Easybits GO [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites [2011/05/23 07:23:38 | 000,000,000 | ---D | M] -- E:\ProgramData\HighAndes [2012/01/04 19:05:27 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy [2011/09/23 11:31:20 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic [2012/02/02 19:24:32 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files [2010/03/15 16:13:37 | 000,000,000 | ---D | M] -- E:\ProgramData\Samsung [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü [2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates [2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen [2010/02/15 11:14:21 | 000,000,000 | ---D | M] -- E:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3} [2010/06/28 11:47:55 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2012/02/02 20:09:36 | 000,032,606 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT [2012/02/02 20:05:00 | 000,000,420 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{67EDA5FC-0019-45FD-BD8F-60FFCB19790F}.job [2012/02/02 20:07:06 | 000,000,454 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{FF4DA3C5-B76D-406A-8828-716AE39A637B}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 128 bytes -> E:\Windows:nlsPreferences @Alternate Data Stream - 1264 bytes -> E:\ProgramData\Microsoft:SQasxH89fAhVdXZTo4rQsa1lB8 @Alternate Data Stream - 1257 bytes -> E:\ProgramData\Microsoft:mF4IF8xPxZPwwlfGMSTyMdmOB @Alternate Data Stream - 1241 bytes -> E:\ProgramData\Microsoft:DsK0QpZjrH4Bu7uFCcUC3mv2JNM @Alternate Data Stream - 1237 bytes -> E:\ProgramData\Microsoft:BzN69YMHrh8PpgVkajVTf @Alternate Data Stream - 1126 bytes -> E:\Program Files (x86)\Common Files\System:8pBA6f4chx8LvxmXGoa @Alternate Data Stream - 1075 bytes -> E:\Users\*****\AppData\Local:Gy1L44sVjSHClQdReyzsUh8 < End of report > Code:
ATTFilter OTL Extras logfile created on: 10/9/2013 2:58:46 AM - Run OTLPE by OldTimer - Version Folder = X:\Programs\OTLPE 64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS Drive F: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32 Drive G: | 273.20 Gb Total Space | 17.53 Gb Free Space | 6.42% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- E:\Windows\System32\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- E:\Windows\SysWow64\control.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 File not found htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding "{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64 "{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding "{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64 "{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64) "{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Logitech Gaming Software" = Logitech Gaming Software 8.20 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack "Microsoft Security Client" = Microsoft Security Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding "{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64 "{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding "{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64 "{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64) "{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Logitech Gaming Software" = Logitech Gaming Software 8.20 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack "Microsoft Security Client" = Microsoft Security Essentials ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\*****_ON_G\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "JNLP" = JNLP "TeamSpeak 3 Client" = TeamSpeak 3 Client < End of report > Geändert von Lou Schalter (08.10.2013 um 23:33 Uhr) |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Trojaner Windows 7 64 Bit Hallo, Zitat:
Wenn FRST nicht läuft, dann versuch bitte, im Admin-Account mit OTL (nicht OTLpe..) zu scannen wie folgt: Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
GVU Trojaner Windows 7 64 Bit Hi Leo, hier die Logs von OTL: (danke fürs nochmalige Erwähnen: "nicht OTLpe", sonst hätt' ich letzteres genommen) Code:
ATTFilter OTL logfile created on: 09.10.2013 19:42:01 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Administrator\Desktop 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 11,99 Gb Total Physical Memory | 10,13 Gb Available Physical Memory | 84,47% Memory free 23,98 Gb Paging File | 21,81 Gb Available in Paging File | 90,95% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 273,20 Gb Total Space | 17,66 Gb Free Space | 6,46% Space Free | Partition Type: NTFS Drive D: | 465,76 Gb Total Space | 313,53 Gb Free Space | 67,32% Space Free | Partition Type: NTFS Drive E: | 465,76 Gb Total Space | 6,35 Gb Free Space | 1,36% Space Free | Partition Type: NTFS Drive G: | 7,26 Gb Total Space | 7,26 Gb Free Space | 99,99% Space Free | Partition Type: FAT32 Computer Name: *****-PC | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - File not found -- PRC - [2013.10.09 19:41:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\OTL.exe PRC - [2013.09.15 19:53:00 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2012.03.03 01:17:18 | 003,246,040 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.12.07 22:11:56 | 000,659,224 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech Gaming Software\Applets\LCDMedia.exe PRC - [2011.04.14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe PRC - [2011.03.29 16:33:08 | 000,598,312 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe PRC - [2011.03.26 00:42:04 | 000,129,648 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe PRC - [2011.03.25 23:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe PRC - [2011.03.21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe PRC - [2010.12.11 20:17:48 | 000,358,944 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe PRC - [2010.10.22 03:00:00 | 000,376,832 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe PRC - [2010.06.24 01:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) -- C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe PRC - [2010.04.27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe PRC - [2010.01.22 01:21:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe PRC - [2009.06.04 20:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2009.05.18 14:29:16 | 003,866,624 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe PRC - [2007.12.19 11:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe ========== Modules (No Company Name) ========== MOD - [2011.04.14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe MOD - [2011.03.21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe MOD - [2010.04.27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe ========== Services (SafeList) ========== SRV:64bit: - [2013.03.29 03:34:18 | 000,241,152 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2012.06.28 10:53:00 | 004,941,768 | ---- | M] (SafeNet Inc.) [Auto | Running] -- C:\Windows\SysNative\hasplms.exe -- (hasplms) SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:64bit: - [2009.06.05 18:42:04 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters) SRV - [2013.10.08 00:48:41 | 000,060,512 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\ProgramData\vh7lcw4.pzz -- (Winmgmt) SRV - [2013.09.19 23:45:28 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.09.15 19:53:00 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2013.01.27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2013.01.27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.03.03 01:17:18 | 003,246,040 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.03.29 16:33:08 | 000,598,312 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2011.03.26 00:42:16 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP) SRV - [2011.03.26 00:42:00 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service) SRV - [2011.03.26 00:41:50 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService) SRV - [2011.03.25 23:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService) SRV - [2011.03.16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010.12.11 20:18:12 | 001,064,584 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2010.10.22 03:00:00 | 000,376,832 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service) SRV - [2010.08.19 14:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60) SRV - [2010.06.24 01:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto | Running] -- C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.01.22 01:21:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service) SRV - [2010.01.18 14:14:24 | 001,141,712 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe -- (sdCoreService) SRV - [2010.01.09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2009.12.09 15:23:34 | 000,365,280 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe -- (sdAuxService) SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009.06.04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.03.29 04:35:02 | 011,658,752 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2013.03.29 03:09:44 | 000,581,120 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2013.02.14 13:41:10 | 000,096,768 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2013.01.20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2012.11.07 09:49:58 | 000,025,600 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rzdaendpt.sys -- (rzdaendpt) DRV:64bit: - [2012.11.07 09:49:54 | 000,023,040 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rzvkeyboard.sys -- (rzvkeyboard) DRV:64bit: - [2012.11.07 09:49:46 | 000,113,664 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd) DRV:64bit: - [2012.06.28 10:51:36 | 000,139,592 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aksfridge.sys -- (aksfridge) DRV:64bit: - [2012.03.03 01:17:20 | 000,285,280 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp) DRV:64bit: - [2012.03.03 01:17:16 | 001,263,200 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm273.sys -- (tdrpman273) DRV:64bit: - [2012.03.03 01:17:14 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter) DRV:64bit: - [2012.03.03 01:17:10 | 000,277,088 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman) DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2011.11.22 16:14:54 | 000,078,208 | ---- | M] (SafeNet Inc.) [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013.10.08 01:15:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Razer
[2013.06.16 23:43:52 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\.minecraft [2012.03.03 01:32:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Acronis [2013.09.10 20:42:40 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Digidesign [2013.02.17 16:34:29 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DVDVideoSoft [2012.03.04 00:51:27 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LolClient [2012.06.14 14:31:52 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LolClient2 [2013.08.01 00:21:08 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Origin [2013.09.10 20:19:25 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PACE Anti-Piracy [2012.03.03 23:11:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Razer [2013.10.08 00:28:44 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\TS3Client ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2 @Alternate Data Stream - 1337 bytes -> C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP @Alternate Data Stream - 1283 bytes -> C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw @Alternate Data Stream - 1264 bytes -> C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX @Alternate Data Stream - 1217 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr @Alternate Data Stream - 1206 bytes -> C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8 @Alternate Data Stream - 1088 bytes -> C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI < End of report > Code:
ATTFilter 09.10. Trojan:JS/Reveton.A 08.10. Trojan:Win32/Reveton.V 08.10. Trojan:Win32/Reveton.V (Eintrag doppelt) 06.10. Exploit:Java/CVE-2013-2465 und bei "unter Quarantäne gestellte Elemente": 09.10.13 Trojan:JS/Reveton.A 08.10.13 Trojan:Win32/Reveton.V 05.05.13 Trojan:Win32/Urausy.C 21.03.13 PWS:Win32/Zbot 18.03.13 Exploit:Win64/Anogre.gen!A 26.02.13 Exploit:Win64/Anogre.gen!A 23.02.13 Exploit:Win64/Anogre.gen!A 18.01.13 Exploit:Win64/Anogre.gen!A 06.01.13 Trojan:Win32/Meredrop 28.12.12 Trojan:Win32/Reveton!Ink (jeweils unterschiedliche Uhrzeiten) 28.12.12 Trojan:Win32/Reveton!Ink 28.12.12 Trojan:Win32/Reveton!Ink 28.12.12 Trojan:Win32/Reveton!Ink 28.12.12 Trojan:Win32/Reveton!Ink |
![]() | #12 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Trojaner Windows 7 64 Bit Hi, ich seh da einen Hinweis im Log, dass auch noch ein Bootkit (schätzungsweise Wistler; ein Befall des MBR = Masterbootsektors) vorliegt... Dem müssen wir danach auch unbedingt noch nachgehen. Aber zuerst zum Sperrbildschirm: Mach bitte folgenden OTL-Fix im Admin-Konto. Kannst du danach den Rechner wieder normal in das betroffene Benutzerkonto starten, ohne dass dir irgendwas den Weg versperrt?
ATTFilter :OTL [2013.10.09 21:36:09 | 001,313,301 | ---- | M] () -- C:\ProgramData\vh7lcw4.pff [2013.10.09 21:36:03 | 000,000,000 | ---- | M] () -- C:\ProgramData\vh7lcw4.ctrl [2012.10.23 00:45:31 | 000,076,351 | ---- | C] () -- C:\ProgramData\kuksclqtviclkhm @Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2 @Alternate Data Stream - 1337 bytes -> C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP @Alternate Data Stream - 1283 bytes -> C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw @Alternate Data Stream - 1264 bytes -> C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX @Alternate Data Stream - 1217 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr @Alternate Data Stream - 1206 bytes -> C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8 @Alternate Data Stream - 1088 bytes -> C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI :files c:\users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vh7lcw4.lnk :commands [emptytemp]
__________________ cheers, Leo |
![]() | #13 |
![]() | ![]() GVU Trojaner Windows 7 64 Bit Hier der Log vom OTL Fix: Code:
ATTFilter All processes killed ========== OTL ========== C:\ProgramData\vh7lcw4.pff moved successfully. C:\ProgramData\vh7lcw4.ctrl moved successfully. C:\ProgramData\kuksclqtviclkhm moved successfully. ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully. ADS C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP deleted successfully. ADS C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw deleted successfully. ADS C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX deleted successfully. ADS C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr deleted successfully. ADS C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk deleted successfully. ADS C:\ProgramData\TEMP:5C321E34 deleted successfully. ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully. ADS C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI deleted successfully. ========== FILES ========== c:\users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vh7lcw4.lnk moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 18806 bytes ->Temporary Internet Files folder emptied: 225863737 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 1783 bytes User: All Users User: ***** ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 1392778 bytes ->Java cache emptied: 2455154 bytes ->Google Chrome cache emptied: 225237102 bytes ->Flash cache emptied: 10983 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 8410484 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 442,00 mb OTL by OldTimer - Version log created on 10102013_201521 Files\Folders moved on Reboot... C:\Users\Administrator\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C50ECY5D\142714-gvu-trojaner-windows-7-64-bit-2[1].htm moved successfully. C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2476.log moved successfully. File move failed. C:\Windows\temp\TmpFile1 scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Jawoll, bin jetzt wieder unter dem normalen Benutzer angemeldet. ![]() |
![]() | #14 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() GVU Trojaner Windows 7 64 Bit Ok, dann ab jetzt im betroffenen Konto weitermachen: Downloade dir bitte ![]()
__________________ cheers, Leo |
![]() | #15 |
![]() | ![]() GVU Trojaner Windows 7 64 Bit Er frägt mich ob ich von Version auf Version updaten will. Denke das dürfte nix schaden, ich update mal. |
![]() |
Themen zu GVU Trojaner Windows 7 64 Bit |
aktuelle, anderen, benutzer, besucht, computer, direkt, farbar recovery scan tool, frage, guten, lag, link, modus, netzwerk, probleme, recht, recovery, scan, software, surfen, system, tool, trojaner, websites, windows, windows 7, zweck |