|
Plagegeister aller Art und deren Bekämpfung: OnlinebankingsperreWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.08.2010, 14:39 | #1 |
| Onlinebankingsperre Hallo, mein Konto wurde ebenfalls letzten Samstag gesperrt. Am Nachmittag konnte ich noch normale Überweisungen tätigen, abends nicht mehr. Ich habe die Sparkasse dann angerufen, und sie sagten mir, dass ich einen Virus hätte und es deswegen gesperrt wurde. Ich solle meinen Rechner "komplett platt machen". Es gäbe keine andere Lösung. Ich sitz seit heut morgen am Internet und suche nach doch anderen Lösungen. Ich habe 3 verschiedene Antivir- Programma durchlaufen lassen und einen Onlinescanner. Keiner konnte etwas finden. Internetrecherche hat zwar ergeben, dass es momentan einen Zeus 2 Virus gibt, aber den konnte ich auch nicht finden auf meinem Rechner. Habe extra DateiCommander und ProcessExplorer heruntergeladen, weil in einem Post von 2007 (ich habe nicht aufs Datum geachtet) stand, das man den nots.exe Virus damit beseitigen konnte. Hat auch nicht geklappt, bzw. der ist es auch nicht. Ich weiß jetzt nicht mehr weiter und habe erst in runde 2 Wochen wieder die Möglichkeit meinen Rechner zu formatieren, die ich die DVD's nicht dabei habe. Bin Student und das liegt alles zu Hause 500km entfernt. Könnt Ihr mir helfen? Danke jetzt schon für die Antworten. PS: nach Tan Nummern wurde ich nie gefragt. Mein Konto war einfach von jetzt auf gleich gesperrt. |
11.08.2010, 15:49 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | OnlinebankingsperreZitat:
Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
11.08.2010, 18:04 | #3 | |
| Onlinebankingsperre alles ist durchgelaufen.
__________________der Malwarebericht: Zitat:
OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 11.08.2010 18:47:30 - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Norman\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18928) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 52,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 75,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,88 Gb Total Space | 63,47 Gb Free Space | 56,72% Space Free | Partition Type: NTFS Drive D: | 111,00 Gb Total Space | 60,40 Gb Free Space | 54,41% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PARTY-UNI-SPAß Current User Name: Norman Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [DateiCommander] -- C:\Program Files\DateiCommander\DateiCommander.exe %1 (Ch.Lütgens & Co) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00B15CA3-0F75-4295-A82C-46C60BAEC009}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2E519345-D024-45CE-B3DA-784E8D6716FB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{37520156-1783-4468-89BA-3EAEF057CFF1}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{3857B036-F380-4C58-B27A-EE401EF19829}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{55339E3D-8E42-4A15-8E59-5A73705DD8BE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{740510DA-4EC1-4C22-AECF-1C19C8ABFABA}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{83A0E7EC-70EE-4165-B384-2B54DA9C2CEE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{920CE2D0-9FF4-4155-8B6B-C7AD3E8BC920}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{D6988F99-3C42-484E-BC70-D8A4BD013881}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{DC390AEF-03F3-402D-8431-B5FEC5D144BC}" = lport=2869 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{006586C3-4D33-46FB-B7C5-C1C34D5DB259}" = protocol=17 | dir=in | app=c:\program files\grisoft\avg7\avgemc.exe | "{092351D5-CFF7-44D8-883B-2990DB820824}" = protocol=6 | dir=in | app=c:\program files\ryu&soft\wonderking\load.exe | "{0A0F4E71-824D-498C-BE09-43EF25998BAB}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{0C8DBAA2-AD79-4F13-9E7E-CCBAADF14446}" = protocol=6 | dir=in | app=c:\program files\grisoft\avg7\avgamsvr.exe | "{1633AF2B-9328-4160-8B66-6430B6F351D3}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe | "{1A9E6B6A-6390-41BA-8DF6-A1507B1757EB}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe | "{21104421-873D-44AF-AB2A-3D228B89B1D4}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{221FA306-CE2A-48C7-86E8-3B2BF8CB02FD}" = protocol=17 | dir=in | app=c:\program files\ryu&soft\wonderking\hshield\hsupdate.exe | "{2CE72DA4-C776-4590-99AC-818B82A4C2B3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{30F2F81D-3E18-47FD-8B02-B82DABF1F350}" = protocol=17 | dir=in | app=c:\program files\grisoft\avg7\avgamsvr.exe | "{4FB3BDAB-2CF0-4C55-86B9-73A1E44A3483}" = protocol=17 | dir=in | app=c:\program files\grisoft\avg7\avgcc.exe | "{57001055-EE19-4A83-83FE-64625FAE8E77}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe | "{642CF92E-C4C6-47CD-8336-D7048E8D20C2}" = protocol=6 | dir=in | app=c:\program files\grisoft\avg7\avgcc.exe | "{86082147-C25C-4BAE-A551-CD5196487B05}" = protocol=6 | dir=in | app=c:\program files\grisoft\avg7\avgemc.exe | "{965FFFE9-A389-4EB6-8FB3-2F40AE07C690}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{A71039F9-F80E-43CE-A92C-8A32823D3CE8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{B56C8753-5AE5-4E8E-8614-68E7DFB38428}" = protocol=6 | dir=in | app=c:\program files\ryu&soft\wonderking\hshield\hsupdate.exe | "{B7F6A7EA-052A-40D2-BCCE-3B27B41F0467}" = protocol=6 | dir=in | app=c:\program files\grisoft\avg7\avginet.exe | "{C5942C8D-BCF9-4322-A8FA-C69E4BE08006}" = protocol=17 | dir=in | app=c:\program files\ryu&soft\wonderking\load.exe | "{C6B2690B-612B-4AC6-BEF0-FD13DA364230}" = protocol=17 | dir=in | app=c:\program files\grisoft\avg7\avginet.exe | "TCP Query User{05B8E3CB-FF73-4854-BD23-CD6E355198E7}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe | "TCP Query User{106040A1-C295-4969-BF54-CBC7606A5192}C:\program files\battle for wesnoth 1.6.5\wesnothd.exe" = protocol=6 | dir=in | app=c:\program files\battle for wesnoth 1.6.5\wesnothd.exe | "TCP Query User{10FA78E0-C1DC-4F38-9725-899B35CBA8DB}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{23B81F54-361B-4645-9442-83F5C97B71F9}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe | "TCP Query User{2DC6A918-ED8D-41B5-9CCA-DCE70429AC37}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{315D0B69-355A-493F-A175-B659044E1A5B}C:\program files\gnomon\gnomon-reader\ful-reader.exe" = protocol=6 | dir=in | app=c:\program files\gnomon\gnomon-reader\ful-reader.exe | "TCP Query User{606B2566-0047-4143-9365-DEB72C173BFA}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "TCP Query User{E0029397-D827-4F94-93E3-0C1E7E6F3BF0}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{0012D2E3-5736-4FCE-9026-7D1E2C1B5FDE}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{1274E55B-6E22-45CA-8075-58FDB22218A4}C:\program files\gnomon\gnomon-reader\ful-reader.exe" = protocol=17 | dir=in | app=c:\program files\gnomon\gnomon-reader\ful-reader.exe | "UDP Query User{2E01C8FF-3C2B-4F47-874E-4C7958DABA78}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | "UDP Query User{98D8342A-548F-4195-A57F-6F143E649D22}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "UDP Query User{C7D0CCFB-0292-4E28-894A-138A3485E00D}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe | "UDP Query User{CC25F1A9-566D-47FC-9145-07833D5808C7}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{E16A2214-2563-4459-8035-1F5BE15DD229}C:\program files\battle for wesnoth 1.6.5\wesnothd.exe" = protocol=17 | dir=in | app=c:\program files\battle for wesnoth 1.6.5\wesnothd.exe | "UDP Query User{FD056DFA-4672-41B9-8AFD-949CA7610CB7}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1 "{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6300 "{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) "{0EC85B2E-5F72-B7F6-7C2B-BE68F5A3325E}" = CCC Help English "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{17BC8ED4-356E-A916-82E9-6CE3813A0D8A}" = Catalyst Control Center Graphics Full Existing "{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.7 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 20 "{26A24AE4-039D-4CA4-87B4-2F83216016F0}" = Java(TM) 6 Update 16 "{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie "{2DFB5485-A3EF-4298-9280-4AF80C9F4BE9}" = Microsoft SQL Server VSS Writer "{308BD058-411C-4AF2-8BF6-A6C7CFD0270D}" = Easy Network Manager 4.0 "{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor "{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3D9F5B9D-9F36-A008-BAEC-CFD34F148473}" = ATI Catalyst Install Manager "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{547DCEC7-DD2A-47E9-82C7-5CF1EAB526DA}" = Microsoft SQL Server Native Client "{5CCD890F-C9CD-B85A-5C31-A4582BA780E1}" = ccc-utility "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager "{6FBCF7BB-BBF0-6BB8-40EA-B0A0C90E6316}" = Skins "{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera "{735105FD-05BC-4B99-525D-C775F42A9A06}" = Catalyst Control Center Core Implementation "{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B233975-3F27-8A78-EFE7-2017DB517AEC}" = Catalyst Control Center InstallProxy "{7B63B2922B174135AFC0E1377DD81EC2}" = "{7CDBE27D-87EC-434E-AFE4-D0116AE876BB}" = Microsoft Works Suite-Add-Ins für Microsoft Word "{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{84EAFDFA-C563-4B65-B6FA-92F1066E61EC}" = Wonderking "{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}" = Epson Easy Photo Print 2 "{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components "{911B0407-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{992CD0F2-C0A9-F53A-335E-A436A321792D}" = Catalyst Control Center Graphics Full New "{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1 "{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components "{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.3 - Deutsch "{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8 "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B632422A-A9A6-77F6-19D9-EB4616A03C10}" = Catalyst Control Center Graphics Light "{B6A98E5F-D6A7-46FB-9E9D-1F7BF4434001}" = Epson Printer Software Downloader "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver "{C3B233DC-0CA2-3740-4EBC-AA138573751A}" = Catalyst Control Center Localization German "{C4BEEB8C-B9D2-4CD9-A2AA-1F3A1F57DF21}" = Works Suite-Betriebssystem-Pack "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D3008D96-86EB-7713-AAFD-E435D8F3A059}" = ccc-core-static "{E05BD952-C7B4-0AF8-4F82-BF51D25D9DE4}" = CCC Help German "{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64 "{E713653C-8312-4BC6-AFC9-ADE1F2F04AB9}" = ATI PCI Express (3GIO) Filter Driver "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{EDDDC607-91D9-4758-9F57-265FDCD8A772}" = Microsoft Works 7.0 "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager "{F0581D83-9155-B015-B395-0258EBDA2D5B}" = Catalyst Control Center Graphics Previews Vista "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F64B9D07-14D4-4DC6-9C34-D28F0C644F9A}" = Catalyst Control Center - Branding "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F8413786-48E7-FA4F-474A-CF573131140D}" = Catalyst Control Center InstallProxy "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "3D Skat Demo_is1" = 3D Skat Demo "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Agere Systems Soft Modem" = Agere Systems HDA Modem "ArcSoft PhotoStudio 2000" = ArcSoft PhotoStudio 2000 "AVG9Uninstall" = AVG Free 9.0 "Battle for Wesnoth 1.6.5" = Battle for Wesnoth 1.6.5 "DateiCommander 11.1_is1" = DateiCommander "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "DivX Setup.divx.com" = DivX-Setup "Easy-WebPrint" = Easy-WebPrint "Epson Printer Software Downloader" = Epson Printer Software Downloader "EPSON Scanner" = EPSON Scan "Epson Stylus SX110_TX110 Benutzerhandbuch" = Epson Stylus SX110_TX110 Handbuch "EPSON SX110 Series" = EPSON SX110 Series Printer Uninstall "Ful Reader" = Ful Reader "InstallShield_{308BD058-411C-4AF2-8BF6-A6C7CFD0270D}" = Easy Network Manager 4.0 "InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Marvell Miniport Driver" = Marvell Miniport Driver "MediaNavigation.CDLabelPrint" = CD-LabelPrint "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8) "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 1.0.0 "Winamp" = Winamp "WinLiveSuite_Wave3" = Windows Live Essentials "Works2003Setup" = Microsoft Works 2003-Setup-Start ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Winamp Detect" = Winamp Erkennungs-Plug-in ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 21.07.2010 04:43:37 | Computer Name = Party-Uni-Spaß | Source = VSS | ID = 8194 Description = Error - 21.07.2010 06:14:42 | Computer Name = Party-Uni-Spaß | Source = EventSystem | ID = 4621 Description = Error - 21.07.2010 15:13:16 | Computer Name = Party-Uni-Spaß | Source = WinMgmt | ID = 10 Description = Error - 21.07.2010 19:01:25 | Computer Name = Party-Uni-Spaß | Source = EventSystem | ID = 4621 Description = Error - 21.07.2010 22:57:05 | Computer Name = Party-Uni-Spaß | Source = WinMgmt | ID = 10 Description = Error - 21.07.2010 23:00:28 | Computer Name = Party-Uni-Spaß | Source = MsiInstaller | ID = 10005 Description = Error - 21.07.2010 23:00:28 | Computer Name = Party-Uni-Spaß | Source = MsiInstaller | ID = 1024 Description = Error - 22.07.2010 16:22:33 | Computer Name = Party-Uni-Spaß | Source = EventSystem | ID = 4621 Description = Error - 22.07.2010 16:27:41 | Computer Name = Party-Uni-Spaß | Source = WinMgmt | ID = 10 Description = Error - 22.07.2010 17:44:20 | Computer Name = Party-Uni-Spaß | Source = EventSystem | ID = 4621 Description = [ System Events ] Error - 10.08.2010 14:34:33 | Computer Name = Party-Uni-Spaß | Source = Dhcp | ID = 1001 Description = Diesem Computer konnte keine Netzwerkadresse durch den DHCP-Server für die Netzwerkkarte mit der Netzwerkadresse 00216380FA84 zugeteilt werden. Der folgende Fehler ist aufgetreten: %%121. Es wird weiterhin im Hintergrund versucht, eine Adresse vom Netzwerkadressserver (DHCP) zugeteilt zu bekommen. Error - 10.08.2010 14:46:38 | Computer Name = Party-Uni-Spaß | Source = Dhcp | ID = 1001 Description = Diesem Computer konnte keine Netzwerkadresse durch den DHCP-Server für die Netzwerkkarte mit der Netzwerkadresse 00216380FA84 zugeteilt werden. Der folgende Fehler ist aufgetreten: %%121. Es wird weiterhin im Hintergrund versucht, eine Adresse vom Netzwerkadressserver (DHCP) zugeteilt zu bekommen. Error - 10.08.2010 21:02:40 | Computer Name = Party-Uni-Spaß | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Error - 10.08.2010 21:47:39 | Computer Name = Party-Uni-Spaß | Source = Dhcp | ID = 1001 Description = Diesem Computer konnte keine Netzwerkadresse durch den DHCP-Server für die Netzwerkkarte mit der Netzwerkadresse 00216380FA84 zugeteilt werden. Der folgende Fehler ist aufgetreten: %%1223. Es wird weiterhin im Hintergrund versucht, eine Adresse vom Netzwerkadressserver (DHCP) zugeteilt zu bekommen. Error - 11.08.2010 04:33:14 | Computer Name = Party-Uni-Spaß | Source = Service Control Manager | ID = 7000 Description = Error - 11.08.2010 04:34:49 | Computer Name = Party-Uni-Spaß | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 11.08.2010 06:59:19 | Computer Name = Party-Uni-Spaß | Source = Service Control Manager | ID = 7011 Description = Error - 11.08.2010 09:04:07 | Computer Name = Party-Uni-Spaß | Source = Service Control Manager | ID = 7000 Description = Error - 11.08.2010 09:04:46 | Computer Name = Party-Uni-Spaß | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 11.08.2010 09:08:23 | Computer Name = Party-Uni-Spaß | Source = Service Control Manager | ID = 7022 Description = < End of report > OTL 2. Bericht: OTL Logfile: Code:
ATTFilter OTL logfile created on: 11.08.2010 18:47:30 - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Norman\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18928) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 52,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 75,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,88 Gb Total Space | 63,47 Gb Free Space | 56,72% Space Free | Partition Type: NTFS Drive D: | 111,00 Gb Total Space | 60,40 Gb Free Space | 54,41% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PARTY-UNI-SPAß Current User Name: Norman Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Norman\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION) PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.) PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation) PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.) ========== Modules (SafeList) ========== MOD - C:\Users\Norman\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation) MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (avg9emc) -- C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.) SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation) SRV - (Samsung Update Plus) -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe () SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) SRV - (SQLWriter) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (EagleNT) -- C:\Windows\System32\drivers\EagleNT.sys File not found DRV - (ADDMEM) -- C:\Users\Norman\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS File not found DRV - (AvgTdiX) -- C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgLdx86) -- C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgMfx86) -- C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.) DRV - (VMC302) -- C:\Windows\System32\drivers\vmc302.sys (Vimicro Corporation) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell) DRV - (usbfilter) -- C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices Inc.) DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows (R) Codename Longhorn DDK provider) DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia) DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows (R) Codename Longhorn DDK provider) DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia) DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.) DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems) DRV - (btwaudio) -- C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (btwrchid) -- C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.) DRV - (btwavdt) -- C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation) DRV - (ialm) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (k750bus) Sony Ericsson 750 driver (WDM) -- C:\Windows\System32\drivers\k750bus.sys (MCCI) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "hxxp://google.de/" FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.23 FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010.07.21 21:11:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.24 19:28:20 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.07.25 10:05:48 | 000,000,000 | ---D | M] [2008.11.11 20:43:03 | 000,000,000 | ---D | M] -- C:\Users\Norman\AppData\Roaming\mozilla\Extensions [2010.08.11 15:28:20 | 000,000,000 | ---D | M] -- C:\Users\Norman\AppData\Roaming\mozilla\Firefox\Profiles\eq8cnehf.default\extensions [2010.08.11 15:28:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norman\AppData\Roaming\mozilla\Firefox\Profiles\eq8cnehf.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2010.08.06 12:05:47 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-1.xml [2009.08.09 21:44:51 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-10.xml [2008.11.15 19:51:41 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-2.xml [2008.12.21 23:58:17 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-3.xml [2009.03.11 00:46:45 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-4.xml [2009.03.30 15:35:34 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-5.xml [2009.04.23 21:24:36 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-6.xml [2009.04.30 19:43:33 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-7.xml [2009.06.14 20:21:57 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-8.xml [2009.07.23 10:48:41 | 000,000,950 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin-9.xml [2008.07.10 13:58:44 | 000,000,944 | ---- | M] () -- C:\Users\Norman\AppData\Roaming\Mozilla\FireFox\Profiles\eq8cnehf.default\searchplugins\icqplugin.xml [2010.05.27 22:29:01 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2008.11.12 15:06:14 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2010.05.27 22:29:01 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll [2010.01.14 00:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll [2010.03.13 23:10:18 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.03.13 23:10:18 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.03.13 23:10:18 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.03.13 23:10:18 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.03.13 23:10:18 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,736 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programme\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll () O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AVG9_TRAY] C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [EEventManager] C:\Programme\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation) O4 - HKCU..\Run: [{7B4C94DA-8BF2-1AAB-B392-03EF1E1BFC7B}] C:\Users\Norman\AppData\Roaming\Kivoyx\cydar.exe File not found O4 - HKCU..\Run: [EPSON SX110 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIFBE.EXE (SEIKO EPSON CORPORATION) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - Startup: C:\Users\Norman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe () O8 - Extra context menu item: Easy-WebPrint - Drucken - C:\Program Files\Canon\Easy-WebPrint\Resource.dll () O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - C:\Program Files\Canon\Easy-WebPrint\Resource.dll () O8 - Extra context menu item: Easy-WebPrint - Vorschau - C:\Program Files\Canon\Easy-WebPrint\Resource.dll () O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - C:\Program Files\Canon\Easy-WebPrint\Resource.dll () O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programme\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Norman\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Norman\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{0642fbca-8ed8-11dd-934f-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{0642fbca-8ed8-11dd-934f-806e6f6e6963}\Shell\AutoRun\command - "" = E:\shelexec.exe START.html -- File not found O33 - MountPoints2\{11b7b891-83aa-11df-8f5f-001377b0bff6}\Shell - "" = AutoRun O33 - MountPoints2\{11b7b891-83aa-11df-8f5f-001377b0bff6}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O33 - MountPoints2\{77f13e62-ebff-11de-835e-001377b0bff6}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe -- File not found O33 - MountPoints2\{77f13e62-ebff-11de-835e-001377b0bff6}\Shell\open\command - "" = F:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe -- File not found O33 - MountPoints2\{92ccbc8a-af35-11de-9ee9-001377b0bff6}\Shell - "" = AutoRun O33 - MountPoints2\{92ccbc8a-af35-11de-9ee9-001377b0bff6}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O33 - MountPoints2\{d3747cf9-2b31-11de-8c3f-001377b0bff6}\Shell\AutoRun\command - "" = F:\start.bat -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.08.11 17:17:16 | 000,000,000 | ---D | C] -- C:\Users\Norman\AppData\Roaming\Malwarebytes [2010.08.11 17:17:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.08.11 17:17:08 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.08.11 17:17:08 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2010.08.11 17:17:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.08.11 17:15:27 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Norman\Desktop\OTL.exe [2010.08.11 15:28:39 | 000,000,000 | ---D | C] -- C:\Users\Norman\AppData\Roaming\QuickScan [2010.08.11 14:25:19 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrrnde.dll [2010.08.11 14:25:18 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCT2.OCX [2010.08.11 14:25:18 | 000,224,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TABCTL32.OCX [2010.08.11 14:25:18 | 000,212,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RICHTX32.OCX [2010.08.11 14:25:18 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCDE.DLL [2010.08.11 14:25:18 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX [2010.08.11 14:25:18 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCC2DE.DLL [2010.08.11 14:25:18 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RCHTXDE.DLL [2010.08.11 14:25:18 | 000,028,672 | ---- | C] (Microsoft Corporation ) -- C:\Windows\System32\CMCT3DE.DLL [2010.08.11 14:25:18 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TABCTDE.DLL [2010.08.11 14:25:17 | 001,748,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\GdiPlus.dll [2010.08.11 14:25:17 | 000,368,128 | ---- | C] (Tools & Components) -- C:\Windows\System32\sevDataGrid2.ocx [2010.08.11 14:25:17 | 000,327,823 | ---- | C] (vbAccelerator) -- C:\Windows\System32\vbalTbar61.ocx [2010.08.11 14:25:17 | 000,307,200 | ---- | C] (DevPower Solutions) -- C:\Windows\System32\FlatBtn6.ocx [2010.08.11 14:25:17 | 000,132,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSINET.OCX [2010.08.11 14:25:17 | 000,126,976 | ---- | C] (vbAccelerator) -- C:\Windows\System32\cPopMenu6.ocx [2010.08.11 14:25:17 | 000,124,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSWINSCK.OCX [2010.08.11 14:25:17 | 000,102,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsoframer.ocx [2010.08.11 14:25:17 | 000,077,824 | ---- | C] (TimoSoft) -- C:\Windows\System32\SHEvent32.ocx [2010.08.11 14:25:17 | 000,040,960 | ---- | C] (vbAccelerator) -- C:\Windows\System32\SSubTmr6.dll [2010.08.11 14:25:17 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMDLGDE.DLL [2010.08.11 14:25:17 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WINSKDE.DLL [2010.08.11 14:25:16 | 000,276,992 | ---- | C] (IntelleSoft) -- C:\Windows\System32\BugTrap.dll [2010.08.11 14:25:16 | 000,265,216 | ---- | C] (Dieter Otter, Tools & Components) -- C:\Windows\System32\sevZip30.dll [2010.08.11 14:25:16 | 000,137,216 | ---- | C] (Tools & Components) -- C:\Windows\System32\sevMail32.ocx [2010.08.11 14:25:16 | 000,110,592 | ---- | C] (Chris) -- C:\Windows\System32\DCGraphBtn.ocx [2010.08.11 14:25:12 | 001,351,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMCTL32.OCX [2010.08.11 14:25:12 | 000,164,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMCT232.OCX [2010.08.11 14:25:12 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6DE.DLL [2010.08.11 14:25:12 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMCTLDE.DLL [2010.08.11 14:25:12 | 000,089,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB5DB.DLL [2010.08.11 14:25:12 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMCT2DE.DLL [2010.08.11 14:25:12 | 000,000,000 | ---D | C] -- C:\Users\Norman\AppData\Roaming\Dateicommander [2010.08.11 14:25:12 | 000,000,000 | ---D | C] -- C:\Programme\DateiCommander [2010.08.11 14:25:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Dateicommander [2010.08.09 12:02:13 | 000,000,000 | ---D | C] -- C:\Users\Norman\AppData\Roaming\Media Player Classic [2010.07.17 09:12:22 | 000,012,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll [2010.07.15 03:00:48 | 000,000,000 | ---D | C] -- C:\fdeec4c18f86f18b34364bdf885a [2 C:\Users\Norman\Desktop\*.tmp files -> C:\Users\Norman\Desktop\*.tmp -> ] [11 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.08.11 18:47:06 | 002,883,584 | -HS- | M] () -- C:\Users\Norman\ntuser.dat [2010.08.11 17:17:11 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.11 17:15:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Norman\Desktop\OTL.exe [2010.08.11 17:10:27 | 063,274,447 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm [2010.08.11 17:02:53 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.08.11 17:02:53 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.08.11 16:59:13 | 000,013,513 | ---- | M] () -- C:\Users\Norman\Desktop\HA.odt [2010.08.11 16:59:13 | 000,000,113 | -H-- | M] () -- C:\Users\Norman\Desktop\.~lock.HA.odt# [2010.08.11 15:09:34 | 001,480,748 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2010.08.11 15:09:34 | 000,644,136 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.08.11 15:09:34 | 000,600,690 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.08.11 15:09:34 | 000,136,322 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.08.11 15:09:34 | 000,108,572 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.08.11 15:02:56 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.08.11 15:02:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.08.11 15:01:31 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010.08.11 15:01:27 | 000,524,288 | -HS- | M] () -- C:\Users\Norman\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms [2010.08.11 15:01:27 | 000,065,536 | -HS- | M] () -- C:\Users\Norman\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2010.08.11 15:01:21 | 002,020,423 | -H-- | M] () -- C:\Users\Norman\AppData\Local\IconCache.db [2010.08.11 14:26:45 | 000,000,000 | RHS- | M] () -- C:\Users\Norman\AppData\Roaming\WkCD2.dll [2010.08.11 14:25:22 | 000,000,812 | ---- | M] () -- C:\Users\Norman\Desktop\DateiCommander.lnk [2010.08.11 12:55:42 | 000,011,313 | ---- | M] () -- C:\Users\Norman\Desktop\these und aufbau.odt [2010.08.11 11:26:01 | 000,000,242 | ---- | M] () -- C:\Windows\tasks\Epson Printer Software Downloader.job [2010.08.10 22:34:26 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6891D34D-C0D2-4B5B-BAF8-209BC113CF9C}.job [2010.07.28 18:29:51 | 000,000,680 | ---- | M] () -- C:\Users\Norman\AppData\Local\d3d9caps.dat [2010.07.28 18:16:59 | 000,000,919 | ---- | M] () -- C:\Users\Norman\Desktop\YouTube Downloader.lnk [2010.07.24 20:22:47 | 000,007,985 | ---- | M] () -- C:\Users\Norman\Desktop\playlist.odt [2010.07.19 12:58:45 | 000,093,696 | ---- | M] () -- C:\Users\Norman\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.07.18 22:39:12 | 204,833,036 | ---- | M] () -- C:\Windows\MEMORY.DMP [2010.07.17 09:12:23 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys [2010.07.17 09:12:22 | 000,012,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll [2010.07.17 09:12:14 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys [2 C:\Users\Norman\Desktop\*.tmp files -> C:\Users\Norman\Desktop\*.tmp -> ] [11 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.08.11 17:17:11 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.11 16:28:39 | 000,000,113 | -H-- | C] () -- C:\Users\Norman\Desktop\.~lock.HA.odt# [2010.08.11 16:28:37 | 000,013,513 | ---- | C] () -- C:\Users\Norman\Desktop\HA.odt [2010.08.11 14:26:45 | 000,000,000 | RHS- | C] () -- C:\Users\Norman\AppData\Roaming\WkCD2.dll [2010.08.11 14:25:22 | 000,000,812 | ---- | C] () -- C:\Users\Norman\Desktop\DateiCommander.lnk [2010.08.11 14:25:19 | 000,548,864 | ---- | C] () -- C:\Windows\System32\MSWORD9.OLB [2010.08.11 14:25:18 | 000,075,264 | ---- | C] () -- C:\Windows\System32\UNACEV2.DLL [2010.08.11 14:25:17 | 001,098,752 | ---- | C] () -- C:\Windows\System32\CBLCtlsU.ocx [2010.08.11 14:25:17 | 000,885,760 | ---- | C] () -- C:\Windows\System32\ExTvw.pdb [2010.08.11 14:25:17 | 000,753,729 | ---- | C] () -- C:\Windows\System32\ExTvw.ocx [2010.08.11 14:25:17 | 000,006,114 | ---- | C] () -- C:\Windows\System32\SHELLLNK.TLB [2010.08.11 14:25:16 | 001,024,000 | ---- | C] () -- C:\Windows\System32\ExLVwU.ocx [2010.08.11 14:25:16 | 000,493,568 | ---- | C] () -- C:\Windows\System32\DTCtlsU.ocx [2010.08.11 14:25:16 | 000,492,032 | ---- | C] () -- C:\Windows\System32\TabStripCtlU.ocx [2010.08.11 11:10:41 | 000,011,313 | ---- | C] () -- C:\Users\Norman\Desktop\these und aufbau.odt [2010.07.28 18:29:51 | 000,000,680 | ---- | C] () -- C:\Users\Norman\AppData\Local\d3d9caps.dat [2010.07.19 11:42:44 | 000,007,985 | ---- | C] () -- C:\Users\Norman\Desktop\playlist.odt [2010.07.18 21:14:40 | 204,833,036 | ---- | C] () -- C:\Windows\MEMORY.DMP [2010.04.20 11:19:55 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2010.02.27 17:44:07 | 000,000,572 | ---- | C] () -- C:\Windows\maxlink.ini [2010.02.27 17:43:09 | 000,000,000 | ---- | C] () -- C:\Windows\OP70.INI [2010.02.27 17:42:10 | 000,000,008 | ---- | C] () -- C:\Windows\phbase.ini [2010.02.27 17:41:22 | 000,000,160 | ---- | C] () -- C:\Windows\pstudio.ini [2010.02.27 17:41:22 | 000,000,028 | ---- | C] () -- C:\Windows\album.ini [2009.10.21 20:08:26 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.02.01 20:29:21 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2008.11.19 17:53:52 | 000,008,704 | ---- | C] () -- C:\Windows\System32\CNMVS78.DLL [2008.09.01 14:10:30 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini [2008.09.01 14:10:30 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini [2008.09.01 13:46:47 | 000,001,670 | ---- | C] () -- C:\Windows\HotFixList.ini [2008.09.01 09:46:46 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.03.09 09:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2004.01.22 19:06:32 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2001.11.14 05:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll [2001.09.17 13:20:02 | 000,009,216 | ---- | C] () -- C:\Windows\System32\cpuinf32.dll < End of report > Insgesamt sagte er mir, dass es keine Infizierungen gibt. Aber du hast da ja mehr Ahnung von Danke, dass du dir Zeit für mich nimmst. |
11.08.2010, 19:34 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Onlinebankingsperre Hm, die Logs hab ich noch nicht durchgesehen, aber mach Du schon weitere Logs um tiefer zu graben: Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus Anschließend den bootkit_remover herunterladen. Entpacke das Tool in einen eigenen Ordner auf dem Desktop und führe in diesem Ordner die Datei remove.exe aus. Wenn Du Windows Vista oder Windows 7 verwendest, musst Du die remover.exe über ein Rechtsklick => als Administrator ausführen Ein schwarzes Fenster wird sich öffnen und automatisch nach bösartigen Veränderungen im MBR suchen. Poste dann bitte, ob es Veränderungen gibt und wenn ja in welchem device. Am besten alles posten was die remover.exe ausgibt.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.08.2010, 20:36 | #5 |
| Onlinebankingsperre GMER wollte nicht, also OSAM OSAM Logfile: Code:
ATTFilter Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 21:34:24 on 11.08.2010 OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.8 Scanner Settings [x] Rootkits detection (hidden registry) [x] Rootkits detection (hidden files) [x] Retrieve files information [x] Check Microsoft signatures Filters [ ] Trusted entries [ ] Empty entries [x] Hidden registry entries (rootkit activity) [x] Exclusively opened files [x] Not found files [x] Files without detailed information [x] Existing files [ ] Non-startable services [ ] Non-startable drivers [x] Active entries [x] Disabled entries [Common] -----( %SystemRoot%\Tasks )----- "Epson Printer Software Downloader.job" - "SEIKO EPSON CORPORATION" - C:\Program Files\EPSON\EPAPDL\E_SAPDL2.EXE [Control Panel Objects] -----( %SystemRoot%\system32 )----- "DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl [Drivers] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "ADDMEM" (ADDMEM) - ? - C:\Users\Norman\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS (File not found) "AMD USB Filter Driver" (usbfilter) - "Advanced Micro Devices Inc." - C:\Windows\System32\DRIVERS\usbfilter.sys "avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys "avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys "EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found) "IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found) "IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found) "IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found) "pwlyyuoc" (pwlyyuoc) - ? - C:\Users\Norman\AppData\Local\Temp\pwlyyuoc.sys (Hidden registry entry, rootkit activity | File not found) "ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys [Explorer] -----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )----- {10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )----- {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll -----( HKLM\Software\Classes\Protocols\Handler )----- {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL {828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL {828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found) {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found) {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found) {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found) {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found) {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found) {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\msohev.dll {7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found) {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "Shell Extensions for RealOne Player" - ? - (File not found | COM-object registry key not found) {5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found) {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll {06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [Internet Explorer] -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found) <binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found) -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_20.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )----- "@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm "ICQ6" - "ICQ, LLC." - C:\Program Files\ICQ6.5\ICQ.exe -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- {9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll {327C2873-E90D-4c37-AA9D-10AC9BABA46C} "Easy-WebPrint" - ? - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} "AVG Safe Search" - ? - C:\Program Files\AVG\AVG9\avgssie.dll (File not found) {9421DD08-935F-4701-A9CA-22DF90AC4EA6} "Easy Photo Print" - "SEIKO EPSON CORPORATION / CyCom Technology Corp." - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll {9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll {5C255C8A-E604-49b4-9D64-90988571CECB} "{5C255C8A-E604-49b4-9D64-90988571CECB}" - ? - (File not found | COM-object registry key not found) [Logon] -----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\Users\Norman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "OpenOffice.org 3.1.lnk" - ? - C:\Program Files\OpenOffice.org 3\program\quickstart.exe (Shortcut exists | File found, but it contains no detailed information | File exists) -----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )----- "desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini "Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\OSA.EXE (Shortcut exists | File exists) -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )----- "{7B4C94DA-8BF2-1AAB-B392-03EF1E1BFC7B}" - ? - C:\Users\Norman\AppData\Roaming\Kivoyx\cydar.exe (File not found) -----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )----- "StartupPrograms" - ? - rdpclip (File not found) -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- "Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" "avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min "DivXUpdate" - ? - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "EEventManager" - "SEIKO EPSON CORPORATION" - C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe "LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" "StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [Print Monitors] -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- "Canon BJ Language Monitor iP4200" - "CANON INC." - C:\Windows\system32\CNMLM78.DLL [Services] -----( HKLM\SYSTEM\CurrentControlSet\Services )----- "@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe "Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe "Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe "Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe "LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe "Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE "Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe (File found, but it contains no detailed information) "SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe ===[ Logfile end ]=========================================[ Logfile end ]=== |
11.08.2010, 20:49 | #6 | |
| Onlinebankingsperre Den Text von Bootkit Remover kann ich nich kopieren, daher versuch ich ihn abzuschreiben: Zitat:
|
11.08.2010, 21:18 | #7 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | OnlinebankingsperreZitat:
Downloade Dir bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.08.2010, 22:10 | #8 | |
| Onlinebankingsperre wurde erledigt Zitat:
|
12.08.2010, 08:49 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Onlinebankingsperre Lösche bitte die vorhandenen MBRCheck.txt. Starte bitte MBRCheck.exe erneut. Diesmal tippe in das Fenster folgendes ein und bestätige jede Eingabe mit Enter bei
Nun findest Du 2 MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop. Poste mir den Inhalt von beiden .txt Dokumenten
__________________ Logfiles bitte immer in CODE-Tags posten |
12.08.2010, 10:15 | #10 | ||
| Onlinebankingsperre Hier der erste Log von deinen Anweisungen Zitat:
Zitat:
|
12.08.2010, 10:35 | #11 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | OnlinebankingsperreZitat:
Schau mal hier => Vista Notfall/Recovery-CD 32-Bit - Dr. Windows Lad das iso runter, brenn es per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten). Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Zur Kontrolle mbrcheck.exe nochmal ausführen und das Log posten.
__________________ Logfiles bitte immer in CODE-Tags posten |
12.08.2010, 10:44 | #12 |
| Onlinebankingsperre Mist, ist also hartnäckiger Trojaner, der sich nicht finden lassen will? Hab leider keinen Rohling vor Ort. Geht das auch mit einem USB-Stick? Ansonsten kann ich das erst Samstag machen. |
12.08.2010, 10:59 | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Onlinebankingsperre Geht auch mit einer Vista-Setup-DVD
__________________ Logfiles bitte immer in CODE-Tags posten |
15.08.2010, 19:32 | #14 | |
| Onlinebankingsperre Habe endlich einen Rohling autreiben können für den Fix. Jetzt der neue MBR-Check Zitat:
|
15.08.2010, 19:37 | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Onlinebankingsperre Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Onlinebankingsperre |
anderen, antworten, beseitigen, datum, dvd, ebenfalls, escan, formatieren, gen, internet, komplett, konto, morgen, onlinescan, rechner, runde, samstag, sparkasse, suche, tan, verschiedene, virus, woche, wochen, worte, zeus 2 |