Nabend,
danke für Ihre schnelle Antwort.
Den
CCleaner Scan habe ich bereits durchgeführt, jedoch fiel mir zuletzt eines auf.
Als ich die Registry löschen wollte, bzw die Fehler beheben wollte, habe ich es, wie es in der Anleitung steht gemacht. "Fehler beheben" - "Fehler suchen" - "Fehler beheben" usw.
Dennoch nach 5-maligen wiederholen blieb dieser Eintrag vorhanden. Ich weiß nicht, ob es von Bedeutung ist, aber ich dachte mir, sicher ist sicher.
Zitat:
Die Dateiendung {80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} verweist auf eine ungültige Programmerkennung. Diese Verweise bleiben oft nach Deinstallationen übrig.
Lösung: Registrierungs-Wert löschen.
|
Desweiteren traten diese AntiVir Meldungen während des Scans mit mbam auf:
und
konnte beide allerdings nicht über AntiVir löschen. Der mbam Scan ist noch nicht abgeschlossen (habe den vollständigen Scan gewählt). Sobald er fertig ist, werde ich den Log und den anschließenend RSIT-log editieren.
Mbam Log Zitat:
Malwarebytes' Anti-Malware 1.44
Datenbank Version: 3607
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
30.03.2010 21:49:51
mbam-log-2010-03-30 (21-49-51).txt
Scan-Methode: Vollständiger Scan (C:\|)
Durchsuchte Objekte: 181736
Laufzeit: 1 hour(s), 4 minute(s), 7 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 59
Infizierte Registrierungswerte: 2
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 10
Infizierte Dateien: 77
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\baidubar.tool (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{d12f94fa-fc9a-41f7-b808-7fbb419dd7a6} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{05d8df21-d546-4434-a289-dfaddb94ab19} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{29880c3b-f5d4-4018-b1c3-390d705663ae} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3050dfa4-790f-4620-9151-426389b6ebe4} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3299e5d3-9e45-4d79-88be-1853d16f78cf} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3b197b06-06c2-4065-ba7f-648be27fae4c} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{40680a28-1182-4753-b3d1-c99dfa993d01} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4c2bfec9-f03c-4f74-932e-5723e603b4ac} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4d4de006-d38c-4d86-8383-a25304d006e7} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{52ce55d8-c53c-427d-8f67-c402e4249cd8} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5910207e-ee57-47b4-b68c-1d07e569c6ac} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{61daabb3-4458-416f-8bbd-0e35a2adc079} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741f4144-2899-4b31-a8cc-2a0efd9eaa51} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{75595d2a-a5ab-4480-bdd6-1157e4baee31} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7d9bfc8a-3b7d-4352-8c22-cf7a5b09b206} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7ef05eff-0e62-4040-8d81-73a10d8de60f} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8261d28b-1d3a-4e72-90fd-e1fdb9badbfb} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{942d9e02-8384-452e-ac65-bf9bf50da254} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9ada3d8a-7238-4aa2-b342-28be3a278ea0} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b602a534-b878-463a-9dd9-0b76ff3233bd} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b80b8410-85e5-46b9-b1bf-ac20ce5c8bf3} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b84b71a0-ebb8-4d1d-adcf-b6355dea8aea} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bc921b84-66b1-40f7-b15f-28578cce6249} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c3df940c-b88a-4866-bc6d-4419d048a68b} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c78b9769-51ff-4e6c-bcb7-5db8db5e84e3} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d158174c-004b-4a2e-9410-5442c10c60d2} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e413a618-b6b3-42da-ab8c-3740304bf0f2} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f5807d19-db8c-41a1-963c-f7eb97d51ef7} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f92873a7-68bf-4e24-aee1-7575ca6a8e91} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fc73df84-d242-41ef-b9cf-e99a8a4b17ad} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{77fef28e-eb96-44ff-b511-3185dea48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77fef28e-eb96-44ff-b511-3185dea48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77fef28e-eb96-44ff-b511-3185dea48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a7f05ee4-0426-454f-8013-c41e3596e9e9} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a7f05ee4-0426-454f-8013-c41e3596e9e9} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b580cf65-e151-49c3-b73f-70b13fca8e86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b580cf65-e151-49c3-b73f-70b13fca8e86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e5d5d4a1-17f0-41d7-b1c6-0979f91e6f46} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e5d5d4a1-17f0-41d7-b1c6-0979f91e6f46} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubar.tool.1 (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarex.bdhomepage (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarex.bdhomepage.1 (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarex.bdhomepage.2 (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarex.bdhomepage.3 (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarex.bdhomepage.4 (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarx.bandie (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarx.bandie.1 (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarx.toolband (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\baidubarx.toolband.1 (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\barbroker.bdbroker (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\barbroker.bdbroker.1 (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7a33ce9e-4f33-4b4e-b263-6aeeab6c3dc2} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5becd27b-dcf5-4def-b066-486a47245c03} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7a33ce9e-4f33-4b4e-b263-6aeeab6c3dc2} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3a8c9d89-3271-45f4-98c0-56b0f5a16172} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2923508c-9425-4a61-b9ce-a98239055916} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BaiduBarX (Adware.BDSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Baidu (Trojan.Cinmus) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b580cf65-e151-49c3-b73f-70b13fca8e86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b580cf65-e151-49c3-b73f-70b13fca8e86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\config (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\Custom Buttons (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\DownloadTmp (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Programme\Baidu (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\BaiduBarX_Tmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\config (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG (Adware.Baidu) -> Quarantined and deleted successfully.
Infizierte Dateien:
C:\Programme\Baidu\Toolbar\BaiduBarX.dll (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\BarBroker.exe (Adware.BDSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9083F780-473B-4D7F-BC07-55E9D3679402}\RP85\A0036176.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9083F780-473B-4D7F-BC07-55E9D3679402}\RP85\A0036285.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\iexp.dat (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\logex.dat (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\namedsites.dat (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\config\fengyun.xml (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\config\user.xml (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Baidu\Toolbar\Custom Buttons\custom.xml (Trojan.Cinmus) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\rc.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\BaiduBarX_Tmp\BaiduBarX.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\config\face.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\1.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\11.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\12.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\13.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\14.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\17.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\18.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\19.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\2.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\20.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\23.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\24.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\27.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\29.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\3.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\31.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\32.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\37.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\38.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\39.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\5.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\6.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\7.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\8.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\9.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\at.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\baidu.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\def.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\dengchu.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\denglu.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\ditu.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\down.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\fangdajing.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\fankui.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\fengyun.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\fengyun_high.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\film.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\flashbar.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\gechi.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\HighLight.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\image.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\Kongjian.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\lianmeng.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\logo.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\logobtn.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\medal.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\MediaSave1.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\MediaSave2.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\music.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\PageFind.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\resize.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\shezhi.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\soucang.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\webim_off.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\webim_on.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\xiezai.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\xiezai.ico (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\xinwen.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\xiongzhang.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\xuanxiang.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\yingpan.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\youyi.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\zhidao.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Programme\Baidu\Toolbar\IMG\zuoyi.bmp (Adware.Baidu) -> Quarantined and deleted successfully.
|
Rsit Scan Zitat:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Mike at 2010-03-30 21:52:50
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 392 GB (82%) free of 477 GB
Total RAM: 2047 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:52:53, on 30.03.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Creative\Shared Files\CTAudSvc.exe
C:\Programme\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Java\jre6\bin\jusched.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\PROGRA~1\SSS\SIMPLESCREENSHOT.EXE
C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Avira\AntiVir Desktop\avguard.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programme\Winamp\winamp.exe
C:\Programme\Skype\Phone\Skype.exe
C:\Programme\Skype\Plugin Manager\skypePM.exe
C:\Dokumente und Einstellungen\Mike\Desktop\RSIT.exe
C:\Programme\HijackThis\Mike.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PPVADownloader - {A986E409-30CC-4185-89BB-AB212C104524} - C:\Programme\PPLive\PPVA\DownloaderManager.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SimpleScreenshot] C:\PROGRA~1\SSS\SIMPLESCREENSHOT.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ Malwarebytes Anti-Malware (reboot)] "C:\Programme\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [msnmsgr] "C:\Programme\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\programme\steam\steam.exe" -silent
O4 - HKCU\..\Run: [PPAP] "C:\Programme\Gemeinsame Dateien\PPLiveNetwork\PPAP.exe" -background
O4 - HKCU\..\Run: [PPLive] "C:\Programme\PPLive\PPLive.exe" /LoadModule ppvod.dll
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [PPLiveVA] C:\Programme\PPLive\PPVA\PPLiveVA.exe /LoadModule PPVA.DLL /M REAL /S 0 /T 0
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Programme\Hamachi\hamachi.exe
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Programme\PPLive\PPTV\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Programme\PPLive\PPTV\PPLive.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - hxxp://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DABF8D5-8430-4985-9B7F-A30E53D709B3} (InstallHelper Class) - hxxp://cache.tv.qq.com/qqlive_ocx/QQLiveInstaller.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257011411701
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - hxxp://dl.uc.sina.com/cab/downloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{437375B7-95E5-4647-9F5C-0DA78A43C0E3}: NameServer = 192.168.2.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Programme\Gemeinsame Dateien\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Programme\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Update Service (gupdate1ca615b515a74a2) (gupdate1ca615b515a74a2) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Programme\Electronic Arts\Need for Speed ProStreet\PB\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Programme\Gemeinsame Dateien\Protexis\License Service\PsiService_2.exe
--
End of file - 8477 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Anmelde-Hilfsprogramm - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A986E409-30CC-4185-89BB-AB212C104524}]
Download_Bho Class - C:\Programme\PPLive\PPVA\DownloaderManager.dll [2009-12-15 513384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Programme\Java\jre6\bin\jp2ssv.dll [2009-10-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-31 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Programme\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2009-06-23 19456]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-09-27 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208]
"SunJavaUpdateSched"=C:\Programme\Java\jre6\bin\jusched.exe [2009-10-31 149280]
"QuickTime Task"=C:\Programme\QuickTime\qttask.exe [2009-09-05 417792]
"iTunesHelper"=C:\Programme\iTunes\iTunesHelper.exe [2009-10-28 141600]
"SimpleScreenshot"=C:\PROGRA~1\SSS\SIMPLESCREENSHOT.EXE [2005-04-14 962048]
"Adobe Reader Speed Launcher"=C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
" Malwarebytes Anti-Malware (reboot)"=C:\Programme\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Programme\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883840]
"Steam"=c:\programme\steam\steam.exe [2010-02-20 1217872]
"PPAP"=C:\Programme\Gemeinsame Dateien\PPLiveNetwork\PPAP.exe [2010-02-04 173512]
"PPLive"=C:\Programme\PPLive\PPLive.exe [2009-11-12 165280]
"Octoshape Streaming Services"=C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [2009-01-08 70936]
"PPLiveVA"=C:\Programme\PPLive\PPVA\PPLiveVA.exe [2009-12-30 71152]
"MSMSGS"=C:\Programme\Messenger\msmsgs.exe [2008-04-14 1695232]
C:\Dokumente und Einstellungen\Mike\Startmenü\Programme\Autostart
hamachi.lnk - C:\Programme\Hamachi\hamachi.exe
OpenOffice.org 3.1.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Programme\Windows Live\Messenger\wlcsdk.exe"="C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Programme\Windows Live\Messenger\msnmsgr.exe"="C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Programme\ICQ6.5\ICQ.exe"="C:\Programme\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Programme\Steam\Steam.exe"="C:\Programme\Steam\Steam.exe:*:Enabled:Steam"
"C:\Programme\Bonjour\mDNSResponder.exe"="C:\Programme\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Programme\iTunes\iTunes.exe"="C:\Programme\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Programme\Skype\Plugin Manager\skypePM.exe"="C:\Programme\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Programme\Tencent\QQLive\QQLive.exe"="C:\Programme\Tencent\QQLive\QQLive.exe:*:Enabled:QQLive"
"C:\Programme\Tencent\QQLive\QQLiveUp.exe"="C:\Programme\Tencent\QQLive\QQLiveUp.exe:*:Enabled:QQLive ??"
"C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temp\Report.exe"="C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temp\Report.exe:*:Enabled:QQLive ??"
"C:\Programme\PPLive\PPTV\PPLive.exe"="C:\Programme\PPLive\PPTV\PPLive.exe:*:Enabled:PPLive"
"C:\Programme\Gemeinsame Dateien\PPLiveNetwork\PPAP.exe"="C:\Programme\Gemeinsame Dateien\PPLiveNetwork\PPAP.exe:*:Enabled:PPLive"
"C:\Programme\PPLive\PPTV\PPLiveU.exe"="C:\Programme\PPLive\PPTV\PPLiveU.exe:*:Enabled:PPLiveU"
"C:\Programme\Messenger\msmsgs.exe"="C:\Programme\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Programme\PPLive\PPVA\PPLiveVA.exe"="C:\Programme\PPLive\PPVA\PPLiveVA.exe:*:Enabled:PPLiveVA"
"C:\Programme\PPLive\PPVA\PPLiveVA_U.exe"="C:\Programme\PPLive\PPVA\PPLiveVA_U.exe:*:Enabled:PPLiveVA"
"C:\Programme\PPLive\PPVA\FlvPick.exe"="C:\Programme\PPLive\PPVA\FlvPick.exe:*:Enabled:FlvPick"
"C:\Programme\PPLive\PPVA\crashreporter.exe"="C:\Programme\PPLive\PPVA\crashreporter.exe:*:Enabled:CrashUpload"
"C:\Programme\PPLive\PPVA\PPVADownload.exe"="C:\Programme\PPLive\PPVA\PPVADownload.exe:*:Enabledownload"
"C:\Programme\PPLive\PPVA\DownloadProgress.exe"="C:\Programme\PPLive\PPVA\DownloadProgress.exe:*:EnabledownloadProgress"
"C:\Programme\Skype\Phone\Skype.exe"="C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Programme\Windows Live\Messenger\wlcsdk.exe"="C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Programme\Windows Live\Messenger\msnmsgr.exe"="C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
======List of files/folders created in the last 2 months======
2010-03-29 12:38:22 ----SHD---- C:\Config.Msi
2010-03-29 12:38:08 ----D---- C:\Programme\Gemeinsame Dateien\Skype
2010-03-11 17:18:55 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-06 19:53:12 ----A---- C:\WINDOWS\system32\pscVSWIA.dll
2010-03-06 19:53:12 ----A---- C:\WINDOWS\system32\pscUD113.dll
2010-03-06 19:53:12 ----A---- C:\WINDOWS\system32\pscND113.exe
2010-03-06 19:53:12 ----A---- C:\WINDOWS\system32\PSCLU113.dll
2010-03-06 19:53:10 ----D---- C:\Programme\Canon
2010-03-06 19:53:06 ----A---- C:\WINDOWS\IsUn0407.exe
2010-03-06 14:01:24 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-02-26 19:57:41 ----D---- C:\Programme\mIRC
2010-02-26 19:57:41 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\mIRC
2010-02-25 07:00:49 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-02-10 00:24:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 00:24:09 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 00:23:15 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 00:23:12 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 00:23:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 00:23:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 00:23:02 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 00:22:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 00:22:49 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-01 14:15:51 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\PPLive
======List of files/folders modified in the last 2 months======
2010-03-30 21:52:51 ----D---- C:\WINDOWS\Prefetch
2010-03-30 21:52:51 ----D---- C:\Programme\HijackThis
2010-03-30 21:51:21 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Skype
2010-03-30 21:50:01 ----D---- C:\WINDOWS\system32\drivers
2010-03-30 21:50:01 ----D---- C:\WINDOWS\msapps
2010-03-30 21:49:51 ----RD---- C:\Programme
2010-03-30 20:40:50 ----D---- C:\Programme\Mozilla Firefox
2010-03-30 20:38:43 ----D---- C:\WINDOWS\Temp
2010-03-30 20:38:43 ----D---- C:\WINDOWS\Debug
2010-03-30 20:38:43 ----D---- C:\WINDOWS
2010-03-30 20:29:33 ----D---- C:\Programme\bla
2010-03-30 16:23:08 ----A---- C:\WINDOWS\win.ini
2010-03-30 16:00:12 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\skypePM
2010-03-30 14:03:00 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-03-30 13:06:46 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PPLive
2010-03-30 13:06:08 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Hamachi
2010-03-30 13:05:45 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-30 13:05:19 ----D---- C:\Programme\Steam
2010-03-30 13:05:17 ----D---- C:\Programme\SSS
2010-03-29 20:35:13 ----D---- C:\Programme\Warcraft III
2010-03-29 12:38:40 ----SHD---- C:\WINDOWS\Installer
2010-03-29 12:38:08 ----D---- C:\Programme\Gemeinsame Dateien
2010-03-28 23:35:34 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\ICQ
2010-03-28 23:19:48 ----D---- C:\WINDOWS\system32
2010-03-28 23:19:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-11 17:18:59 ----HD---- C:\WINDOWS\inf
2010-03-11 17:18:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-11 17:18:56 ----D---- C:\Programme\Movie Maker
2010-03-11 17:18:42 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-06 19:58:25 ----D---- C:\WINDOWS\twain_32
2010-03-02 07:30:12 ----A---- C:\WINDOWS\system32\MRT.exe
2010-02-28 23:33:05 ----SD---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\Microsoft
2010-02-28 16:35:18 ----D---- C:\Programme\Garena
2010-02-26 19:54:34 ----D---- C:\Programme\Gamers.IRC
2010-02-26 16:45:38 ----D---- C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\teamspeak2
2010-02-20 16:55:18 ----D---- C:\Programme\Gemeinsame Dateien\PPLiveNetwork
2010-02-06 14:11:06 ----D---- C:\FavoriteVideo
2010-02-04 19:33:53 ----D---- C:\Programme\Silkroad
2010-02-01 14:15:53 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Jlcm
2010-02-01 14:15:47 ----D---- C:\Programme\PPLive
2010-02-01 14:02:09 ----A---- C:\WINDOWS\user.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Programme\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816]
R2 regi;regi; \??\C:\WINDOWS\system32\drivers\regi.sys []
R3 Arp1394;1394-ARP-Clientprotokoll; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 COMMONFX.SYS;COMMONFX.SYS; C:\WINDOWS\System32\drivers\COMMONFX.SYS [2009-06-23 99352]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2009-06-23 511000]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2009-06-23 528408]
R3 CTAUDFX.SYS;CTAUDFX.SYS; C:\WINDOWS\System32\drivers\CTAUDFX.SYS [2009-06-23 555032]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2009-06-23 14360]
R3 CTSBLFX.SYS;CTSBLFX.SYS; C:\WINDOWS\System32\drivers\CTSBLFX.SYS [2009-06-23 566296]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2009-06-23 157208]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2009-06-23 92696]
R3 FETNDIS;VIA PCI 10/100-MBit/s-Fast Ethernetadapter-NT-Treiber; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2009-06-23 798744]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-11-09 25280]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2009-06-23 162840]
R3 hidusb;Microsoft HID Class-Treiber; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12288]
R3 NIC1394;1394-Netzwerktreiber; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-27 7655872]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2009-06-23 127512]
R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2-aktivierter Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Tastatur-HID-Treiber; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S3 catchme;catchme; \??\C:\DOKUME~1\Mike\LOKALE~1\Temp\catchme.sys []
S3 COMMONFX;COMMONFX; C:\WINDOWS\system32\drivers\COMMONFX.SYS [2009-06-23 99352]
S3 CTAUDFX;CTAUDFX; C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2009-06-23 555032]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2009-06-23 347080]
S3 CTERFXFX.SYS;CTERFXFX.SYS; C:\WINDOWS\System32\drivers\CTERFXFX.SYS [2009-06-23 100888]
S3 CTERFXFX;CTERFXFX; C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2009-06-23 100888]
S3 CTSBLFX;CTSBLFX; C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2009-06-23 566296]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOKUME~1\Mike\LOKALE~1\Temp\ZYC1EB.tmp []
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2009-06-23 189464]
S3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB-Druckerklasse; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB-Scannertreiber; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirSchedulerService;Avira AntiVir Planer; C:\Programme\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Programme\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 Apple Mobile Device;Apple Mobile Device; C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour-Dienst; C:\Programme\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CTAudSvcService;Creative Audio Service; C:\Programme\Creative\Shared Files\CTAudSvc.exe [2009-02-14 307200]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 iPod Service;iPod-Dienst; C:\Programme\iPod\bin\iPodService.exe [2009-10-28 545568]
S2 gupdate1ca615b515a74a2;Google Update Service (gupdate1ca615b515a74a2); C:\Programme\Google\Update\GoogleUpdate.exe [2009-11-09 133104]
S2 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2009-10-31 153376]
S2 PnkBstrA;PunkBuster; C:\Programme\Electronic Arts\Need for Speed ProStreet\PB\PnkBstrA.exe [2007-10-19 63040]
S2 PSI_SVC_2;Protexis Licensing V2; C:\Programme\Gemeinsame Dateien\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Programme\Gemeinsame Dateien\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
|
Wobei der Ordner C:\Programme\bla von mir angelegt und sauber ist.
Jedoch bekam ich gerade wieder eine Virusmeldung, den ich aber anscheinend erfolgreich über AntiVir löschen konnte.
Es ist nicht immer so mit den Virusmeldungen, heute 3x ist öfter als in den vergangen paar Wochen oder Monaten.
Hier der Screenshot.
Danke für die Hilfe.
Tut mir Leid, dass es ein bisschen viel geworden ist.
__________________