|
Log-Analyse und Auswertung: Hijackthis-LogWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.11.2009, 08:19 | #1 | |
| Hijackthis-Log Hallo an ALLE, Unszwar habe ich mir ein Programm runtergeladen, diese Version war eine Portableversion. Viele User haben sicht bedankt um genau zusein 108 User. So nun habe ich mir gedacht lade ich, dass mir auch gleich mal. Der dritte User bzw. vierte schrieb dann rein Zitat:
Dieser Link führt Sie zur auswertung von dieser Exe auf www.virustotal.com Nun wollte ich hier mal nach meinem Reboot vom Pc, meine Hijackthis-Log einmal Posten weil ich mir nun jetzt nicht mehr sicher bin, ob alles auf meinem Pc reibungslos ist. Ich habe sie auch auswerten lassen auf der HijackThis Homepage da schien alles Sauber soweit zusein. So aber ich wollte es nochmal direkt von den Profis hören und das seid ihr ob alles in Ordnung ist. Ich hoffe ihr könnt mir helfen!!! Hier die Hijackthis-Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 07:53:52, on 19.11.2009 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O13 - Gopher Prefix: O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 4178 bytes Hier noch eine Frage könnte ein Prozess auch so laufen, dass man ihn nicht sieht bzw erkennt oder vll das HijackThis diesen Prozess auch nicht erkennt. Ich hoffe sowas ist nicht möglich. BITTE HELFT MIR!!! |
19.11.2009, 11:45 | #2 |
/// Selecta Jahrusso | Hijackthis-Log Bitte verwende eine Normale Schriftgröße und achte auf die Rechtschreibung. Hier ist kein Chat.
__________________Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
19.11.2009, 14:28 | #3 |
| Hijackthis-Log Teil1
__________________Code:
ATTFilter OTL logfile created on: 19.11.2009 14:23:25 - Run 1 OTL by OldTimer - Version 3.1.6.0 Folder = C:\Users\Kodiak\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,65 Gb Available Physical Memory | 66,37% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 232,79 Gb Total Space | 212,09 Gb Free Space | 91,11% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KODIAK-PC Current User Name: Kodiak Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Kodiak\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Users\Kodiak\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\Kodiak\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\vssapi.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\vsstrace.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\spp.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\srclient.dll (Microsoft Corporation) MOD - C:\Windows\SysWOW64\atl.dll (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (WwanSvc) -- C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation) SRV:64bit: - (WbioSrvc) -- C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation) SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) SRV:64bit: - (Power) -- C:\Windows\SysNative\umpo.dll (Microsoft Corporation) SRV:64bit: - (Themes) -- C:\Windows\SysNative\themeservice.dll (Microsoft Corporation) SRV:64bit: - (sppuinotify) -- C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation) SRV:64bit: - (SensrSvc) -- C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation) SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) SRV:64bit: - (PNRPsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation) SRV:64bit: - (p2pimsvc) -- C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation) SRV:64bit: - (HomeGroupProvider) -- C:\Windows\SysNative\provsvc.dll (Microsoft Corporation) SRV:64bit: - (RpcEptMapper) -- C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation) SRV:64bit: - (PNRPAutoReg) -- C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation) SRV:64bit: - (HomeGroupListener) -- C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation) SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation) SRV:64bit: - (Dhcp) -- C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation) SRV:64bit: - (defragsvc) -- C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation) SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) SRV:64bit: - (bthserv) -- C:\Windows\SysNative\bthserv.dll (Microsoft Corporation) SRV:64bit: - (BDESVC) -- C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation) SRV:64bit: - (AxInstSV) -- C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation) SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) SRV:64bit: - (AppIDSvc) -- C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation) SRV:64bit: - (WMPNetworkSvc) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV:64bit: - (wbengine) -- C:\Windows\SysNative\wbengine.exe (Microsoft Corporation) SRV:64bit: - (sppsvc) -- C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation) SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (VSS) -- C:\Windows\Vss [2009.07.14 04:20:14 | 00,000,000 | ---D | M] SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2009.07.14 04:20:14 | 00,000,000 | ---D | M] SRV - (HomeGroupProvider) -- C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation) SRV - (Dhcp) -- C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation) SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof () SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0) -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (idsvc) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (KSecPkg) -- C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (hwpolicy) -- C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation) DRV:64bit: - (FsDepends) -- C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (WIMMount) -- C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation) DRV:64bit: - (vhdmp) -- C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation) DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) DRV:64bit: - (vdrvroot) -- C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation) DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (rdyboost) -- C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation) DRV:64bit: - (pcw) -- C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation) DRV:64bit: - (CNG) -- C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation) DRV:64bit: - (fvevol) -- C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation) DRV:64bit: - (rdpbus) -- C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation) DRV:64bit: - (RDPREFMP) -- C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation) DRV:64bit: - (RasAgileVpn) -- C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation) DRV:64bit: - (WfpLwf) -- C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation) DRV:64bit: - (NdisCap) -- C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation) DRV:64bit: - (vwifibus) -- C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation) DRV:64bit: - (1394ohci) -- C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation) DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation) DRV:64bit: - (UmPass) -- C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation) DRV:64bit: - (mshidkmdf) -- C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation) DRV:64bit: - (WudfPf) -- C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation) DRV:64bit: - (MTConfig) -- C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation) DRV:64bit: - (CompositeBus) -- C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation) DRV:64bit: - (Beep) -- C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation) DRV:64bit: - (AppID) -- C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation) DRV:64bit: - (scfilter) -- C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation) DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) DRV:64bit: - (discache) -- C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation) DRV:64bit: - (HidBatt) -- C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation) DRV:64bit: - (CmBatt) -- C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation) DRV:64bit: - (AcpiPmi) -- C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation) DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) DRV:64bit: - (AmdPPM) -- C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation) DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation) DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys () DRV - (CSC) -- C:\Windows\CSC [2009.11.17 07:34:26 | 00,000,000 | ---D | M] DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (NetBIOS) -- C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation) DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof () DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 B7 9A 42 51 67 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: (824 bytes) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O13 - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 83.169.184.33 83.169.184.97 O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found 64bit: O35 - comfile [open] -- "%1" %* File not found 64bit: O35 - exefile [open] -- "%1" %* File not found O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found |
19.11.2009, 14:29 | #4 |
| Hijackthis-Log Teil2 Code:
ATTFilter ========== Files/Folders - Created Within 30 Days ========== [2009.11.19 14:21:47 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Users\Kodiak\Desktop\OTL.exe [2009.11.19 08:45:14 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\Documents\PDFV_Portable [2009.11.19 07:39:38 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro [2009.11.19 07:27:16 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\Nero [2009.11.17 19:46:04 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\Documents\MSD 0.655 [2009.11.17 09:53:31 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\teamspeak2 [2009.11.17 09:41:39 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\Documents\ESL Match Media [2009.11.17 09:06:20 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\WinRAR [2009.11.17 09:05:58 | 00,000,000 | ---D | C] -- C:\Programme\WinRAR [2009.11.17 08:52:07 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\ESL Wire Game Client [2009.11.17 08:51:36 | 00,000,000 | ---D | C] -- C:\ProgramData\ESL Wire [2009.11.17 08:51:36 | 00,000,000 | ---D | C] -- C:\ProgramData\ESL Wire [2009.11.17 08:51:36 | 00,000,000 | ---D | C] -- C:\Programme\EslWire [2009.11.17 08:47:02 | 00,034,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\lhacm.acm [2009.11.17 08:47:00 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Teamspeak2_RC2 [2009.11.17 08:41:50 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Steam [2009.11.17 08:41:50 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam [2009.11.17 08:38:14 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation [2009.11.17 08:38:04 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2009.11.17 08:38:04 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2009.11.17 08:37:44 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\AGEIA [2009.11.17 08:37:44 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2009.11.17 08:37:40 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2009.11.17 08:37:37 | 00,541,800 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvuninst.exe [2009.11.17 08:37:20 | 00,000,000 | ---D | C] -- C:\NVIDIA [2009.11.17 08:37:13 | 00,000,000 | ---D | C] -- C:\Windows\pss [2009.11.17 08:33:44 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt [2009.11.17 08:32:56 | 00,311,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msv1_0.dll [2009.11.17 08:32:56 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msv1_0.dll [2009.11.17 08:32:25 | 28,155,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MRT.exe [2009.11.17 08:31:12 | 14,629,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2009.11.17 08:31:11 | 11,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2009.11.17 08:31:11 | 01,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll [2009.11.17 08:31:11 | 01,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll [2009.11.17 08:31:11 | 00,982,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgkrnl.sys [2009.11.17 08:31:10 | 12,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL [2009.11.17 08:31:10 | 12,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL [2009.11.17 08:31:10 | 02,868,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2009.11.17 08:31:10 | 02,613,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe [2009.11.17 08:31:10 | 00,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2009.11.17 08:31:10 | 00,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2009.11.17 08:31:10 | 00,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll [2009.11.17 08:31:10 | 00,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll [2009.11.17 08:31:10 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll [2009.11.17 08:31:10 | 00,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll [2009.11.17 08:31:06 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll [2009.11.17 08:31:06 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msasn1.dll [2009.11.17 08:30:12 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\Tracing [2009.11.17 08:29:46 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft [2009.11.17 08:29:37 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft [2009.11.17 08:29:12 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live [2009.11.17 08:28:54 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2009.11.17 08:28:53 | 00,000,000 | -HSD | C] -- C:\Windows\Installer [2009.11.17 08:27:26 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live [2009.11.17 08:04:49 | 00,226,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MpSigStub.exe [2009.11.17 07:54:13 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\Macromedia [2009.11.17 07:54:13 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\Adobe [2009.11.17 07:53:10 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2009.11.17 07:52:11 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ClearProg [2009.11.17 07:44:03 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\Google [2009.11.17 07:43:54 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\Deployment [2009.11.17 07:43:54 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\Apps [2009.11.17 07:41:40 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Searches [2009.11.17 07:41:32 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\Identities [2009.11.17 07:41:30 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Contacts [2009.11.17 07:41:29 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\VirtualStore [2009.11.17 07:41:21 | 00,000,000 | --SD | C] -- C:\Users\Kodiak\AppData\Roaming\Microsoft [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Videos [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Saved Games [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Pictures [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Music [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Links [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Favorites [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Downloads [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Documents [2009.11.17 07:41:21 | 00,000,000 | R--D | C] -- C:\Users\Kodiak\Desktop [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Vorlagen [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Startmenü [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\SendTo [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Recent [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Netzwerkumgebung [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Lokale Einstellungen [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Documents\Eigene Videos [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Documents\Eigene Musik [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Eigene Dateien [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Documents\Eigene Bilder [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Druckumgebung [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Cookies [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\Anwendungsdaten [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\AppData\Local\Verlauf [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\AppData\Local\Temporary Internet Files [2009.11.17 07:41:21 | 00,000,000 | -HSD | C] -- C:\Users\Kodiak\AppData\Local\Anwendungsdaten [2009.11.17 07:41:21 | 00,000,000 | -H-D | C] -- C:\Users\Kodiak\AppData [2009.11.17 07:41:21 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Roaming\Media Center Programs [2009.11.17 07:41:21 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\Temp [2009.11.17 07:41:21 | 00,000,000 | ---D | C] -- C:\Users\Kodiak\AppData\Local\Microsoft [2009.11.17 07:40:48 | 00,000,000 | -HSD | C] -- C:\Recovery [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\Programme [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2009.11.17 07:40:47 | 00,000,000 | -HSD | C] -- C:\Programme\Gemeinsame Dateien [2009.11.17 07:36:37 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2009.11.17 07:34:05 | 00,000,000 | ---D | C] -- C:\Windows\Prefetch [2009.11.17 07:33:50 | 00,000,000 | -HSD | C] -- C:\System Volume Information [2009.11.17 07:32:46 | 00,000,000 | ---D | C] -- C:\Windows\Panther ========== Files - Modified Within 30 Days ========== [2009.11.19 14:23:41 | 01,310,720 | -HS- | M] () -- C:\Users\Kodiak\NTUSER.DAT [2009.11.19 14:21:50 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Users\Kodiak\Desktop\OTL.exe [2009.11.19 13:49:00 | 00,001,122 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4096240827-3495531322-1484870607-1001UA.job [2009.11.19 10:50:10 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2009.11.19 07:50:00 | 00,019,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2009.11.19 07:50:00 | 00,019,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2009.11.19 07:49:00 | 00,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4096240827-3495531322-1484870607-1001Core.job [2009.11.19 07:47:19 | 01,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2009.11.19 07:47:19 | 00,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2009.11.19 07:47:19 | 00,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2009.11.19 07:47:19 | 00,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2009.11.19 07:47:19 | 00,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2009.11.19 07:42:53 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2009.11.19 07:42:47 | 32,200,86784 | -HS- | M] () -- C:\hiberfil.sys [2009.11.19 07:42:08 | 01,331,658 | -H-- | M] () -- C:\Users\Kodiak\AppData\Local\IconCache.db [2009.11.18 13:15:51 | 00,260,455 | ---- | M] () -- C:\Users\Kodiak\Documents\release_afc_executable.zip [2009.11.17 11:00:54 | 03,298,977 | ---- | M] () -- C:\Users\Kodiak\Documents\2009-11-17_PhArAo_vs_VAGANT_(Demo_-_KC_-_VAGANT).zip [2009.11.17 09:05:20 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2009.11.17 08:47:02 | 00,034,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\lhacm.acm [2009.11.17 08:40:19 | 00,266,688 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2009.11.17 07:50:20 | 00,001,073 | ---- | M] () -- C:\Users\Kodiak\Desktop\Musik.lnk [2009.11.17 07:50:15 | 00,001,101 | ---- | M] () -- C:\Users\Kodiak\Desktop\Dokumente.lnk [2009.11.17 07:47:50 | 00,000,057 | ---- | M] () -- C:\Windows\SysWow64\mapisvc.inf [2009.11.17 07:45:53 | 00,524,288 | -HS- | M] () -- C:\Users\Kodiak\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2009.11.17 07:45:53 | 00,524,288 | -HS- | M] () -- C:\Users\Kodiak\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2009.11.17 07:45:53 | 00,065,536 | -HS- | M] () -- C:\Users\Kodiak\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2009.11.17 07:43:55 | 00,057,560 | ---- | M] () -- C:\Users\Kodiak\AppData\Local\GDIPFONTCACHEV1.DAT [2009.11.17 07:42:07 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_NuidFltr_01005.Wdf [2009.11.17 07:41:21 | 00,000,020 | -HS- | M] () -- C:\Users\Kodiak\ntuser.ini [2009.11.17 07:37:31 | 00,057,050 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2009.11.17 07:37:31 | 00,057,050 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2009.11.05 10:06:00 | 28,155,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MRT.exe [2009.11.02 20:42:06 | 00,226,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MpSigStub.exe ========== Files Created - No Company Name ========== [2009.11.18 13:15:51 | 00,260,455 | ---- | C] () -- C:\Users\Kodiak\Documents\release_afc_executable.zip [2009.11.17 11:00:51 | 03,298,977 | ---- | C] () -- C:\Users\Kodiak\Documents\2009-11-17_PhArAo_vs_VAGANT_(Demo_-_KC_-_VAGANT).zip [2009.11.17 09:05:20 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2009.11.17 07:50:20 | 00,001,073 | ---- | C] () -- C:\Users\Kodiak\Desktop\Musik.lnk [2009.11.17 07:50:15 | 00,001,101 | ---- | C] () -- C:\Users\Kodiak\Desktop\Dokumente.lnk [2009.11.17 07:45:52 | 01,331,658 | -H-- | C] () -- C:\Users\Kodiak\AppData\Local\IconCache.db [2009.11.17 07:44:04 | 00,001,122 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4096240827-3495531322-1484870607-1001UA.job [2009.11.17 07:44:03 | 00,001,070 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4096240827-3495531322-1484870607-1001Core.job [2009.11.17 07:43:55 | 00,057,560 | ---- | C] () -- C:\Users\Kodiak\AppData\Local\GDIPFONTCACHEV1.DAT [2009.11.17 07:42:07 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_NuidFltr_01005.Wdf [2009.11.17 07:41:21 | 01,310,720 | -HS- | C] () -- C:\Users\Kodiak\NTUSER.DAT [2009.11.17 07:41:21 | 00,524,288 | -HS- | C] () -- C:\Users\Kodiak\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2009.11.17 07:41:21 | 00,524,288 | -HS- | C] () -- C:\Users\Kodiak\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2009.11.17 07:41:21 | 00,065,536 | -HS- | C] () -- C:\Users\Kodiak\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2009.11.17 07:41:21 | 00,000,020 | -HS- | C] () -- C:\Users\Kodiak\ntuser.ini [2009.11.17 07:33:50 | 32,200,86784 | -HS- | C] () -- C:\hiberfil.sys [2009.08.03 00:21:54 | 00,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll [2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll [2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll [2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll [2009.07.14 06:32:39 | 00,043,318 | ---- | C] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont [2009.07.14 06:32:39 | 00,029,779 | ---- | C] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont [2009.07.14 06:32:39 | 00,026,489 | ---- | C] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont [2009.07.14 06:32:39 | 00,026,040 | ---- | C] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont [2009.07.14 05:54:24 | 00,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop.ini [2009.07.14 03:34:57 | 00,000,403 | ---- | C] () -- C:\Windows\win.ini [2009.07.14 03:34:57 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini [2009.07.14 00:42:10 | 00,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 22:03:59 | 00,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll < End of report > |
19.11.2009, 14:31 | #5 |
| Hijackthis-Log Teil3 Code:
ATTFilter OTL Extras logfile created on: 19.11.2009 14:23:25 - Run 1 OTL by OldTimer - Version 3.1.6.0 Folder = C:\Users\Kodiak\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,65 Gb Available Physical Memory | 66,37% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 232,79 Gb Total Space | 212,09 Gb Free Space | 91,11% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KODIAK-PC Current User Name: Kodiak Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1 .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html[@ = htmlfile] -- Reg Error: Key error. File not found .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1 .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = htmlfile] -- Reg Error: Key error. File not found .url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation) .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- C:\Users\Kodiak\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* File not found batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* File not found cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* File not found cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- Reg Error: Key error. htmlfile [opennew] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- Reg Error: Key error. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- Reg Error: Key error. htmlfile [opennew] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- Reg Error: Key error. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error. |
19.11.2009, 14:32 | #6 |
| Hijackthis-Log Teil4 Code:
ATTFilter ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "ESL Wire_is1" = ESL Wire 1.1.1 "NVIDIA Drivers" = NVIDIA Drivers "WinRAR archiver" = WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "ClearProg" = ClearProg 1.6.0 Final "HijackThis" = HijackThis 2.0.2 "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Steam App 240" = Counter-Strike: Source "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "WinLiveSuite_Wave3" = Windows Live Essentials ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 18.11.2009 10:40:45 | Computer Name = Kodiak-PC | Source = Windows Search Service | ID = 1019 Description = Error - 18.11.2009 10:40:48 | Computer Name = Kodiak-PC | Source = Windows Search Service | ID = 1019 Description = Error - 18.11.2009 11:48:47 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x02bf553e ID des fehlerhaften Prozesses: 0xd98 Startzeit der fehlerhaften Anwendung: 0x01ca6866582ec730 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: db29b0f0-d459-11de-a22c-001d6056314f Error - 19.11.2009 06:27:33 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x02d3553e ID des fehlerhaften Prozesses: 0xbe0 Startzeit der fehlerhaften Anwendung: 0x01ca6901f6990e30 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: 25737320-d4f6-11de-a48d-001d6056314f Error - 19.11.2009 07:16:49 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x0291553e ID des fehlerhaften Prozesses: 0xed8 Startzeit der fehlerhaften Anwendung: 0x01ca6905c46cd460 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: 0767a160-d4fd-11de-a48d-001d6056314f Error - 19.11.2009 07:39:49 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x028f553e ID des fehlerhaften Prozesses: 0xdcc Startzeit der fehlerhaften Anwendung: 0x01ca690a23866480 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: 3de815f0-d500-11de-a48d-001d6056314f Error - 19.11.2009 08:08:31 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x028f553e ID des fehlerhaften Prozesses: 0xa3c Startzeit der fehlerhaften Anwendung: 0x01ca690d6ff0e4f0 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: 4050dbc0-d504-11de-a48d-001d6056314f Error - 19.11.2009 08:38:31 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x01ed553e ID des fehlerhaften Prozesses: 0x85c Startzeit der fehlerhaften Anwendung: 0x01ca691194e05210 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: 71300280-d508-11de-a48d-001d6056314f Error - 19.11.2009 08:50:19 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x02bd553e ID des fehlerhaften Prozesses: 0xa00 Startzeit der fehlerhaften Anwendung: 0x01ca6915f48cfa70 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: 172edcf0-d50a-11de-a48d-001d6056314f Error - 19.11.2009 09:02:07 | Computer Name = Kodiak-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: hl2.exe, Version: 0.0.0.0, Zeitstempel: 0x4445c334 Name des fehlerhaften Moduls: filesystem_steam.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x47e2d72b Ausnahmecode: 0xc0000005 Fehleroffset: 0x028f553e ID des fehlerhaften Prozesses: 0x8d4 Startzeit der fehlerhaften Anwendung: 0x01ca691728a13be0 Pfad der fehlerhaften Anwendung: c:\program files (x86)\steam\steamapps\fightstreemer\counter-strike source\hl2.exe Pfad des fehlerhaften Moduls: filesystem_steam.dll Berichtskennung: bd2f8c20-d50b-11de-a48d-001d6056314f [ System Events ] Error - 17.11.2009 04:17:16 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 17.11.2009 07:31:31 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 17.11.2009 12:00:24 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 17.11.2009 19:18:19 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 18.11.2009 13:19:30 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 18.11.2009 20:01:17 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 19.11.2009 02:17:19 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error - 19.11.2009 02:17:19 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 19.11.2009 02:42:12 | Computer Name = Kodiak-PC | Source = Service Control Manager | ID = 7016 Description = Der Dienst "NVIDIA Display Driver Service" hat einen ungültigen aktuellen Status gemeldet: 32 Error - 19.11.2009 05:49:54 | Computer Name = Kodiak-PC | Source = Microsoft-Windows-HAL | ID = 12 Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. < End of report > |
19.11.2009, 14:49 | #7 |
/// Selecta Jahrusso | Hijackthis-Log Warum finde ich Kein Antiviren-Programm? Und generell finde ich keine einzigen Startup Eintrag. Kannst Du mir das erklären? Ich habe gesehen das du kein AntiViren-Programm auf deinem Rechner hast Bitte lade dir die Freeware Version von Avira 9 herunter und installiere es auf deinem Rechner schritt 2 der Link zu Virustotal ist down. schritt 3 Wende bitte Malwarebytes nach Anleitung an. (QuickScan reicht) schritt 4 Schliesse bitte alle laufenden Programme inkl Browser. Lösche bitte die Extra.txt von Deinem Desktop. Doppelklick auf die OTL.exe und poste beide Logfiles.
__________________ mfg, Daniel ASAP & UNITE Member Alliance of Security Analysis Professionals Unified Network of Instructors and Trusted Eliminators Lerne, zurück zu schlagen und unterstütze uns! TB Akademie |
19.11.2009, 15:13 | #8 |
| Hijackthis-Log Antivirusprogramm brauch ich nicht weil wenn einer einen Full Undetected Crypter hat nützt kein Antivirusprogramm... Der Link zu VIrustotal hat ein paar Backdoor etc.. sachen gezeigt auch jetz unwichtig. Ich mein bevor ich mein Pc mit irgend was zu Mülle Installier ich es halt neu danke trozdem für deine Hilfe! |
19.11.2009, 15:23 | #9 |
/// Selecta Jahrusso | Hijackthis-LogWiederschaun
__________________ mfg, Daniel ASAP & UNITE Member Alliance of Security Analysis Professionals Unified Network of Instructors and Trusted Eliminators Lerne, zurück zu schlagen und unterstütze uns! TB Akademie |
Themen zu Hijackthis-Log |
auswerten, auswertung, bho, exe, explorer, frage, google, hijack, homepage, internet, internet explorer, link, lsass.exe, micro, microsoft, nvidia, programm, prozess, software, spoolsv.exe, system32, syswow64, virus, windows, windows media player, wmp |