|
Log-Analyse und Auswertung: Polizeitrojaner Österreich auf Windows XP eingefangenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.10.2013, 13:42 | #1 |
| Polizeitrojaner Österreich auf Windows XP eingefangen Hallo zusammen, mein Vater hat sich nun auch den österr. Bundestrojaner auf seinem Windows XP Rechner eingefangen. Ich habe das OTL Scanfile angehängt und hoffe, dass ihr mir hierbei helfen könnt. VG racer416 |
16.10.2013, 14:01 | #2 |
/// the machine /// TB-Ausbilder | Polizeitrojaner Österreich auf Windows XP eingefangen Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
16.10.2013, 14:05 | #3 |
| Polizeitrojaner Österreich auf Windows XP eingefangen Entschuldigung.
__________________Code:
ATTFilter OTL logfile created on: 10/16/2013 3:33:55 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 767.00 Mb Total Physical Memory | 561.00 Mb Available Physical Memory | 73.00% Memory free 707.00 Mb Paging File | 586.00 Mb Available in Paging File | 83.00% Paging File free Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 39.06 Gb Total Space | 17.76 Gb Free Space | 45.47% Space Free | Partition Type: NTFS Drive D: | 35.47 Gb Total Space | 34.25 Gb Free Space | 96.56% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand] -- -- (AppMgmt) SRV - [2013/10/14 14:09:05 | 000,176,128 | ---- | M] (Borland Software Corporation) [Auto] -- C:\DOKUME~1\ALLUSE~1\ANWEND~1\nb2nb2lw.plz -- (winmgmt) SRV - [2013/10/09 06:21:55 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/09/10 16:40:04 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013/09/10 16:39:37 | 000,815,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled] -- C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService) SRV - [2013/09/10 16:39:28 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012/04/24 06:53:32 | 000,215,688 | ---- | M] (SPAMfighter ApS) [Auto] -- C:\Programme\Fighters\SPAMfighter\sfus.exe -- (SPAMfighter Update Service) SRV - [2012/01/23 07:40:12 | 001,324,680 | ---- | M] (SPAMfighter ApS) [Auto] -- C:\Programme\Fighters\FighterSuiteService.exe -- (Suite Service) SRV - [2006/02/02 11:30:51 | 000,068,608 | ---- | M] () [Disabled] -- C:\Programme\Gemeinsame Dateien\Autodata Limited Shared\Service\ADCDLicSvc.exe -- (Autodata Limited License Service) SRV - [2003/07/28 07:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2002/09/20 10:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto] -- C:\Programme\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default)) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand] -- -- (NETFRITZ) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) DRV - File not found [Kernel | Auto] -- -- (ASInsHelp) DRV - [2013/09/10 16:40:10 | 000,136,672 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2013/09/10 16:40:10 | 000,088,840 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013/08/13 02:49:45 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2013/08/13 02:49:45 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011/08/17 04:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2011/08/17 04:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011/08/17 04:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2011/08/17 04:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2008/11/07 11:36:46 | 000,101,632 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2007/11/15 16:30:48 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf) DRV - [2004/10/14 05:52:27 | 000,004,962 | R--- | M] () [Kernel | System] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO) DRV - [2003/03/21 06:34:08 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc) DRV - [2002/09/10 20:00:00 | 000,484,176 | ---- | M] (AVM Berlin) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\fpcibase.sys -- (fpcibase) DRV - [2002/09/10 20:00:00 | 000,037,568 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\avmwan.sys -- (AVMWAN) DRV - [2001/10/22 18:00:00 | 000,059,520 | ---- | M] (AVM Berlin) [Kernel | Auto] -- C:\WINDOWS\System32\drivers\avmport.sys -- (AVMPORT) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.utanet.at/ IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms} IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/ IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CC 19 69 30 C8 4C CE 01 [binary data] IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.bing.com/search?q={searchTerms} IE - HKU\Kisler_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.bing.com/search?q={searchTerms} IE - HKU\Kisler_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=ds&q={searchTerms}&installDate=08/05/2013 IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=hp&installDate=08/05/2013 IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=ds&q={searchTerms}&installDate=08/05/2013 IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=ds&q={searchTerms}&installDate=08/05/2013 IE - HKU\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=ds&q={searchTerms}&installDate=08/05/2013 IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=hp&installDate=08/05/2013 IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=ds&q={searchTerms}&installDate=08/05/2013 IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=AT&userid=fa77fca9-d114-42a5-a613-2671656bcbdb&searchtype=ds&q={searchTerms}&installDate=08/05/2013 IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll () FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll () O1 HOSTS File: ([2006/03/28 17:33:20 | 000,000,874 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found. O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKU\Kisler_ON_C\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [sfagent] C:\Programme\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS) O4 - HKU\Kisler_ON_C..\Run: [EPSON Stylus SX200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE (SEIKO EPSON CORPORATION) O4 - Startup: C:\Dokumente und Einstellungen\Kisler\Startmenü\Programme\Autostart\wl2bn2bn.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Kisler_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} hxxp://www.plan.at/download/mgaxctrlde.cab (Autodesk MapGuide ActiveX Control) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130501833296 (WUWebControl Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1376380845531 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} hxxp://www.o2c.de/download/O2CPlayer.CAB (O2C-Player (ELECO Software GmbH)) O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/10/28 07:29:46 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{c8f5d5da-ace1-11dd-bd51-0013d48e10f9}\Shell - "" = AutoRun O33 - MountPoints2\{c8f5d5da-ace1-11dd-bd51-0013d48e10f9}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{c8f5d5da-ace1-11dd-bd51-0013d48e10f9}\Shell\AutoRun\command - "" = L:\AutoRun.exe O33 - MountPoints2\{c8f5d5dd-ace1-11dd-bd51-0013d48e10f9}\Shell - "" = AutoRun O33 - MountPoints2\{c8f5d5dd-ace1-11dd-bd51-0013d48e10f9}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{c8f5d5dd-ace1-11dd-bd51-0013d48e10f9}\Shell\AutoRun\command - "" = L:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2013/10/14 14:09:05 | 000,176,128 | ---- | C] (Borland Software Corporation) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\nb2nb2lw.plz [2013/09/27 11:02:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\NewSoft [2013/09/27 10:53:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Folder [2013/09/27 10:53:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Aufträge [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/10/16 08:10:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013/10/16 08:06:09 | 095,025,368 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wl2bn2bn.pff [2013/10/16 08:05:53 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wl2bn2bn.ctrl [2013/10/16 08:05:47 | 000,000,104 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2013/10/16 08:04:50 | 000,013,684 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013/10/14 14:21:15 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2013/10/14 14:09:26 | 000,000,802 | ---- | M] () -- C:\Dokumente und Einstellungen\Kisler\Startmenü\Programme\Autostart\wl2bn2bn.lnk [2013/10/14 14:09:05 | 000,176,128 | ---- | M] (Borland Software Corporation) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\nb2nb2lw.plz [2013/10/09 06:21:53 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2013/10/09 06:21:53 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2013/09/24 08:41:08 | 000,002,451 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Microsoft-Maus.lnk [2013/09/18 07:12:58 | 000,002,523 | ---- | M] () -- C:\Dokumente und Einstellungen\Kisler\Desktop\Microsoft Excel.lnk [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/10/14 14:09:25 | 000,000,802 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Startmenü\Programme\Autostart\wl2bn2bn.lnk [2013/10/14 14:09:23 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wl2bn2bn.ctrl [2013/10/14 14:09:09 | 095,025,368 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wl2bn2bn.pff [2013/06/03 12:39:36 | 000,000,021 | ---- | C] () -- C:\WINDOWS\System32\ComCenter.ini [2012/02/22 05:02:53 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012/01/28 12:21:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI [2011/08/14 06:04:59 | 001,067,520 | ---- | C] () -- C:\WINDOWS\System32\iFolderCtrl.dll [2011/08/14 06:04:59 | 000,958,976 | ---- | C] () -- C:\WINDOWS\System32\iPostCtl.dll [2011/08/14 06:04:58 | 001,411,584 | ---- | C] () -- C:\WINDOWS\System32\iFaxCtrl.dll [2011/08/07 07:58:09 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2009/10/25 09:34:30 | 000,018,226 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\yzesyqos.reg [2009/10/25 09:34:30 | 000,017,567 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\yduniquc.ban [2009/10/25 09:34:30 | 000,016,737 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\obuju.pif [2009/10/25 09:34:30 | 000,013,426 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\uducu.dat [2009/10/25 05:45:01 | 000,018,687 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\varoqaxumi.pif [2009/10/25 05:45:01 | 000,017,402 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\nogaka.ban [2009/10/25 05:45:01 | 000,017,032 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\ufuxuro.dll [2009/10/25 05:45:01 | 000,013,173 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\vyduxe.dat [2009/09/26 08:40:55 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat [2009/09/26 08:40:55 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat [2009/09/26 08:40:55 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat [2009/09/26 08:40:55 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat [2009/09/26 08:40:55 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat [2009/09/26 08:40:55 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat [2009/09/26 08:40:55 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat [2009/09/26 08:40:55 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat [2009/09/26 08:40:55 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat [2009/09/26 08:40:55 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat [2009/09/26 08:40:55 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat [2009/09/26 08:40:55 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat [2009/09/26 08:40:55 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat [2009/09/26 08:40:55 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat [2009/09/26 08:40:55 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat [2009/09/26 08:40:55 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat [2009/09/26 08:40:55 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat [2009/09/26 08:40:55 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat [2009/09/26 08:40:55 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2009/09/26 08:38:56 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE SX200DEFGIPS.ini [2009/01/29 12:55:13 | 000,000,038 | ---- | C] () -- C:\WINDOWS\augros.ini [2007/03/06 15:15:22 | 000,000,016 | -H-- | C] () -- C:\Dokumente und Einstellungen\Kisler\mxfilerelatedcache.mxc2 [2007/02/25 13:40:24 | 000,000,016 | -H-- | C] () -- C:\Programme\mxfilerelatedcache.mxc2 [2006/09/19 14:04:43 | 000,006,642 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini [2006/04/22 19:00:10 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll [2006/03/28 17:36:24 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html [2006/02/01 13:55:04 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\ManzSaveXP.dll [2005/11/19 08:34:14 | 000,084,511 | ---- | C] () -- C:\WINDOWS\QSETUP1.EXE [2005/11/16 12:44:26 | 000,028,160 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2005/10/29 02:44:59 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2005/10/28 11:04:24 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVSye.DLL [2005/10/28 11:04:12 | 000,000,599 | ---- | C] () -- C:\WINDOWS\System32\CNCMP51.INI [2005/10/28 09:26:16 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini [2005/10/28 09:24:55 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll [2005/10/28 09:20:42 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll [2005/10/28 09:20:42 | 000,004,962 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys [2005/10/28 09:19:49 | 000,061,440 | R--- | C] () -- C:\WINDOWS\System32\vuins32.dll [2005/10/28 08:35:08 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll [2005/10/28 08:32:52 | 000,004,001 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2005/10/28 08:32:51 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2005/10/28 08:13:49 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2005/10/28 08:12:53 | 000,221,632 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2005/10/28 07:31:37 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2005/10/28 07:27:29 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2005/06/15 05:20:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2005/06/15 05:20:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe [2005/06/15 05:20:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2005/06/15 05:20:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe [2005/06/15 05:20:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2005/06/15 05:20:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll [2005/06/15 05:20:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2005/06/15 05:20:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe [2005/06/15 05:20:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe [2005/06/15 05:20:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2004/08/02 08:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2003/04/02 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2003/04/02 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2003/04/02 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2003/04/02 08:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat [2003/04/02 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2003/04/02 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2003/04/02 08:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat [2003/04/02 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2003/04/02 08:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2003/04/02 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [2003/04/02 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2003/03/12 22:24:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2002/05/23 19:00:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll [2002/05/23 19:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll [2001/08/14 05:47:08 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\vxpsapi.dll ========== LOP Check ========== [2013/01/12 08:18:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\.oit [2005/11/16 13:20:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\Canon [2005/10/29 02:40:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\CDZilla [2013/09/27 11:17:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\ComCenter [2012/02/08 09:07:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\Ektyqo [2012/01/28 09:39:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\EPSON [2011/11/07 11:35:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\Faebv [2012/05/17 03:09:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\Fighters [2007/07/02 12:31:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\Leadertech [2007/02/25 14:00:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\MAGIX [2010/01/26 12:23:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\mquadr.at [2013/09/27 11:02:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\NewSoft [2013/01/12 06:39:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\TuneUp Software [2006/03/25 08:35:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\VERITAS [2008/02/29 13:59:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kisler\Anwendungsdaten\VUPlayer [2012/05/17 03:09:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Fighters [2006/02/02 11:31:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Autodata Limited [2006/03/28 17:37:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avg7 [2013/01/12 06:27:32 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files [2012/01/28 09:35:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\EPSON [2012/05/17 03:09:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Fighters [2010/02/10 02:22:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IM [2010/01/26 12:23:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\m2backup [2007/02/15 13:46:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MAGIX [2010/01/26 12:24:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\mquadr.at [2013/05/09 11:27:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2012/01/28 09:33:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UDL [2013/01/12 06:57:18 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{121AD2BC-C528-40F6-AA74-A5E1962657DF} [2013/01/12 06:57:18 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{7FDC9DDA-8828-4A49-A615-2E0A4EE0F0E2} [2013/01/12 06:57:18 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2013/01/12 06:57:18 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D692DF95-0D76-4FE0-9096-9B56DEAE4205} [2013/01/12 06:57:19 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{DEC678D1-B2BE-43DD-B123-21503011D8C9} ========== Purity Check ========== ========== Files - Unicode (All) ========== [2013/10/02 09:28:27 | 098,743,931 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\嗂聋哜6 [2013/10/02 09:28:27 | 098,743,931 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\嗂聋哜6 [2013/09/25 04:49:23 | 097,673,008 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\崜襁哜6 [2013/09/25 04:49:23 | 097,673,008 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\崜襁哜6 < End of report > |
17.10.2013, 08:17 | #4 |
/// the machine /// TB-Ausbilder | Polizeitrojaner Österreich auf Windows XP eingefangenFixen mit OTL
Code:
ATTFilter :OTL O4 - Startup: C:\Dokumente und Einstellungen\Kisler\Startmenü\Programme\Autostart\wl2bn2bn.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation) [2013/10/14 14:09:26 | 000,000,802 | ---- | M] () -- C:\Dokumente und Einstellungen\Kisler\Startmenü\Programme\Autostart\wl2bn2bn.lnk [2013/10/14 14:09:05 | 000,176,128 | ---- | M] (Borland Software Corporation) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\nb2nb2lw.plz [2013/10/14 14:09:25 | 000,000,802 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Startmenü\Programme\Autostart\wl2bn2bn.lnk [2013/10/14 14:09:23 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wl2bn2bn.ctrl [2013/10/14 14:09:09 | 095,025,368 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wl2bn2bn.pff [2009/10/25 09:34:30 | 000,018,226 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\yzesyqos.reg [2009/10/25 09:34:30 | 000,017,567 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\yduniquc.ban [2009/10/25 09:34:30 | 000,016,737 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\obuju.pif [2009/10/25 09:34:30 | 000,013,426 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\uducu.dat [2009/10/25 05:45:01 | 000,018,687 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\varoqaxumi.pif [2009/10/25 05:45:01 | 000,017,402 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\nogaka.ban [2009/10/25 05:45:01 | 000,017,032 | ---- | C] () -- C:\Dokumente und Einstellungen\Kisler\Lokale Einstellungen\Anwendungsdaten\ufuxuro.dll [2009/10/25 05:45:01 | 000,013,173 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\vyduxe.dat
Rechner normal starten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.10.2013, 07:36 | #5 |
| Polizeitrojaner Österreich auf Windows XP eingefangen Danke schön. Hallo nochmal, die Lösung hat leider nur temporär funktioniert und gestern am späten Abend hat er dann wieder zugeschlagen. Ich habe nun einen neuen Scan durchgeführt: Code:
ATTFilter OTL logfile created on: 10/18/2013 9:27:32 AM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 767.00 Mb Total Physical Memory | 570.00 Mb Available Physical Memory | 74.00% Memory free 707.00 Mb Paging File | 588.00 Mb Available in Paging File | 83.00% Paging File free Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 39.06 Gb Total Space | 18.11 Gb Free Space | 46.38% Space Free | Partition Type: NTFS Drive D: | 35.47 Gb Total Space | 34.25 Gb Free Space | 96.56% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [Auto] -- -- (winmgmt) SRV - File not found [On_Demand] -- -- (AppMgmt) SRV - [2013/10/09 06:21:55 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/09/10 16:40:04 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013/09/10 16:39:37 | 000,815,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled] -- C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService) SRV - [2013/09/10 16:39:28 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012/04/24 06:53:32 | 000,215,688 | ---- | M] (SPAMfighter ApS) [Auto] -- C:\Programme\Fighters\SPAMfighter\sfus.exe -- (SPAMfighter Update Service) SRV - [2012/01/23 07:40:12 | 001,324,680 | ---- | M] (SPAMfighter ApS) [Auto] -- C:\Programme\Fighters\FighterSuiteService.exe -- (Suite Service) SRV - [2006/02/02 11:30:51 | 000,068,608 | ---- | M] () [Disabled] -- C:\Programme\Gemeinsame Dateien\Autodata Limited Shared\Service\ADCDLicSvc.exe -- (Autodata Limited License Service) SRV - [2003/07/28 07:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2002/09/20 10:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto] -- C:\Programme\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default)) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand] -- -- (NETFRITZ) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) DRV - File not found [Kernel | Auto] -- -- (ASInsHelp) DRV - [2013/09/10 16:40:10 | 000,136,672 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2013/09/10 16:40:10 | 000,088,840 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2013/08/13 02:49:45 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2013/08/13 02:49:45 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2011/08/17 04:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2011/08/17 04:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011/08/17 04:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2011/08/17 04:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2008/11/07 11:36:46 | 000,101,632 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2007/11/15 16:30:48 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf) DRV - [2004/10/14 05:52:27 | 000,004,962 | R--- | M] () [Kernel | System] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO) DRV - [2003/03/21 06:34:08 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc) DRV - [2002/09/10 20:00:00 | 000,484,176 | ---- | M] (AVM Berlin) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\fpcibase.sys -- (fpcibase) DRV - [2002/09/10 20:00:00 | 000,037,568 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\avmwan.sys -- (AVMWAN) DRV - [2001/10/22 18:00:00 | 000,059,520 | ---- | M] (AVM Berlin) [Kernel | Auto] -- C:\WINDOWS\System32\drivers\avmport.sys -- (AVMPORT) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll () FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll () O1 HOSTS File: ([2006/03/28 17:33:20 | 000,000,874 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found. O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [sfagent] C:\Programme\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} hxxp://www.plan.at/download/mgaxctrlde.cab (Autodesk MapGuide ActiveX Control) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130501833296 (WUWebControl Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1376380845531 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} hxxp://www.o2c.de/download/O2CPlayer.CAB (O2C-Player (ELECO Software GmbH)) O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/10/28 07:29:46 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2013/10/17 23:11:39 | 002,237,440 | R--- | C] (OldTimer Tools) -- C:\OTLPE.exe [2013/10/17 23:11:38 | 000,000,000 | ---D | C] -- C:\_OTL [2013/10/17 17:33:15 | 000,176,128 | ---- | C] (Корпорация Майкрософт) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\t7rftab0.plz [2013/09/27 10:53:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Folder [2013/09/27 10:53:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Aufträge [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/10/17 17:38:20 | 095,025,368 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\0batfr7t.pff [2013/10/17 17:38:12 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\0batfr7t.ctrl [2013/10/17 17:38:09 | 000,000,104 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2013/10/17 17:38:05 | 000,013,684 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013/10/17 17:38:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013/10/17 17:33:15 | 000,176,128 | ---- | M] (Корпорация Майкрософт) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\t7rftab0.plz [2013/10/17 17:21:15 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2013/10/09 06:21:53 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2013/10/09 06:21:53 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2013/09/24 08:41:08 | 000,002,451 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Microsoft-Maus.lnk [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/10/17 17:33:29 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\0batfr7t.ctrl [2013/10/17 17:33:16 | 095,025,368 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\0batfr7t.pff [2013/06/03 12:39:36 | 000,000,021 | ---- | C] () -- C:\WINDOWS\System32\ComCenter.ini [2012/02/22 05:02:53 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012/01/28 12:21:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI [2011/08/14 06:04:59 | 001,067,520 | ---- | C] () -- C:\WINDOWS\System32\iFolderCtrl.dll [2011/08/14 06:04:59 | 000,958,976 | ---- | C] () -- C:\WINDOWS\System32\iPostCtl.dll [2011/08/14 06:04:58 | 001,411,584 | ---- | C] () -- C:\WINDOWS\System32\iFaxCtrl.dll [2011/08/07 07:58:09 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2009/09/26 08:40:55 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat [2009/09/26 08:40:55 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat [2009/09/26 08:40:55 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat [2009/09/26 08:40:55 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat [2009/09/26 08:40:55 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat [2009/09/26 08:40:55 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat [2009/09/26 08:40:55 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat [2009/09/26 08:40:55 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat [2009/09/26 08:40:55 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat [2009/09/26 08:40:55 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat [2009/09/26 08:40:55 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat [2009/09/26 08:40:55 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat [2009/09/26 08:40:55 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat [2009/09/26 08:40:55 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat [2009/09/26 08:40:55 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat [2009/09/26 08:40:55 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat [2009/09/26 08:40:55 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat [2009/09/26 08:40:55 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat [2009/09/26 08:40:55 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2009/09/26 08:38:56 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE SX200DEFGIPS.ini [2009/01/29 12:55:13 | 000,000,038 | ---- | C] () -- C:\WINDOWS\augros.ini [2007/02/25 13:40:24 | 000,000,016 | -H-- | C] () -- C:\Programme\mxfilerelatedcache.mxc2 [2006/09/19 14:04:43 | 000,006,642 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini [2006/04/22 19:00:10 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll [2006/03/28 17:36:24 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html [2006/02/01 13:55:04 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\ManzSaveXP.dll [2005/11/19 08:34:14 | 000,084,511 | ---- | C] () -- C:\WINDOWS\QSETUP1.EXE [2005/10/29 02:44:59 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2005/10/28 11:04:24 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVSye.DLL [2005/10/28 11:04:12 | 000,000,599 | ---- | C] () -- C:\WINDOWS\System32\CNCMP51.INI [2005/10/28 09:26:16 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini [2005/10/28 09:24:55 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll [2005/10/28 09:20:42 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll [2005/10/28 09:20:42 | 000,004,962 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys [2005/10/28 09:19:49 | 000,061,440 | R--- | C] () -- C:\WINDOWS\System32\vuins32.dll [2005/10/28 08:35:08 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll [2005/10/28 08:32:52 | 000,004,001 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2005/10/28 08:32:51 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2005/10/28 08:13:49 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2005/10/28 08:12:53 | 000,221,632 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2005/10/28 07:31:37 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2005/10/28 07:27:29 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2005/06/15 05:20:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2005/06/15 05:20:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe [2005/06/15 05:20:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2005/06/15 05:20:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe [2005/06/15 05:20:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2005/06/15 05:20:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll [2005/06/15 05:20:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2005/06/15 05:20:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe [2005/06/15 05:20:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe [2005/06/15 05:20:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2004/08/02 08:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2003/04/02 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2003/04/02 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2003/04/02 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2003/04/02 08:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat [2003/04/02 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2003/04/02 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2003/04/02 08:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat [2003/04/02 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2003/04/02 08:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2003/04/02 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [2003/04/02 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2003/03/12 22:24:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2002/05/23 19:00:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll [2002/05/23 19:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll [2001/08/14 05:47:08 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\vxpsapi.dll ========== LOP Check ========== [2006/02/02 11:31:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Autodata Limited [2006/03/28 17:37:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avg7 [2013/01/12 06:27:32 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files [2012/01/28 09:35:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\EPSON [2012/05/17 03:09:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Fighters [2010/02/10 02:22:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IM [2010/01/26 12:23:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\m2backup [2007/02/15 13:46:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MAGIX [2010/01/26 12:24:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\mquadr.at [2013/05/09 11:27:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software [2012/01/28 09:33:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UDL [2013/01/12 06:57:18 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{121AD2BC-C528-40F6-AA74-A5E1962657DF} [2013/01/12 06:57:18 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{7FDC9DDA-8828-4A49-A615-2E0A4EE0F0E2} [2013/01/12 06:57:18 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2013/01/12 06:57:18 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D692DF95-0D76-4FE0-9096-9B56DEAE4205} [2013/01/12 06:57:19 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{DEC678D1-B2BE-43DD-B123-21503011D8C9} ========== Purity Check ========== ========== Files - Unicode (All) ========== [2013/10/17 15:29:48 | 101,604,844 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䙩蕸哜6 [2013/10/17 15:29:48 | 101,604,844 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䙩蕸哜6 [2013/10/02 09:28:27 | 098,743,931 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\嗂聋哜6 [2013/10/02 09:28:27 | 098,743,931 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\嗂聋哜6 [2013/09/25 04:49:23 | 097,673,008 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\崜襁哜6 [2013/09/25 04:49:23 | 097,673,008 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\崜襁哜6 < End of report > racer416 |
18.10.2013, 15:22 | #6 |
/// the machine /// TB-Ausbilder | Polizeitrojaner Österreich auf Windows XP eingefangenFixen mit OTL
Code:
ATTFilter :OTL [2013/10/17 17:33:15 | 000,176,128 | ---- | C] (Корпорация Майкрософт) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\t7rftab0.plz [2013/10/17 17:38:20 | 095,025,368 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\0batfr7t.pff [2013/10/17 17:38:12 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\0batfr7t.ctrl
__________________ --> Polizeitrojaner Österreich auf Windows XP eingefangen |
Themen zu Polizeitrojaner Österreich auf Windows XP eingefangen |
angehängt, bundes, bundestrojaner, eingefangen, file, gefangen, gen, hallo zusammen, hierbei, hoffe, polizei, polizeitrojaner, rechner, vater, windows, windows xp, zusammen, Österreich |