|
Plagegeister aller Art und deren Bekämpfung: Antimalware Doctor, Security Suit Virus entfernenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.09.2010, 09:50 | #31 |
| Antimalware Doctor, Security Suit Virus entfernen Schritt 1 konnte nicht ausgeführt werden da sich der Pc beim ausführen aufhängt. Schritt 2 Code:
ATTFilter OTL logfile created on: 9/2/2010 8:18:14 PM - Run OTLPE by OldTimer - Version 3.1.40.0 Folder = X:\Programs\OTLPE Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 77.63 Gb Total Space | 29.78 Gb Free Space | 38.36% Space Free | Partition Type: NTFS Drive D: | 77.63 Gb Total Space | 59.77 Gb Free Space | 76.99% Space Free | Partition Type: NTFS Drive E: | 77.62 Gb Total Space | 55.38 Gb Free Space | 71.34% Space Free | Partition Type: NTFS Drive F: | 15.05 Gb Total Space | 13.96 Gb Free Space | 92.76% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive X: | 433.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO Current User Name: SYSTEM Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Standard Quick Scan Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand] -- C:\Programme\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper) getPlus(R) SRV - [2010/06/10 15:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2009/07/21 08:34:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2009/06/01 16:20:12 | 000,222,968 | ---- | M] () [Auto] -- C:\Programme\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2009/05/13 10:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2009/04/30 07:23:26 | 000,090,112 | ---- | M] () [Auto] -- C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service) SRV - [2007/09/05 12:46:02 | 000,374,272 | ---- | M] (Hauppauge Computer Works) [Auto] -- C:\Programme\WinTV\EPG Services\System\EPGService.exe -- (EPGService) SRV - [2007/08/09 03:27:52 | 000,073,728 | ---- | M] (HP) [Auto] -- C:\Windows\system32\HPZipm12.exe -- (Pml Driver HPZ12) SRV - [2007/07/12 11:36:12 | 000,354,840 | ---- | M] (Intel Corporation) [Auto] -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R) SRV - [2007/02/25 16:55:18 | 000,125,048 | ---- | M] (TOSHIBA CORPORATION) [Auto] -- c:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service) SRV - [2005/11/17 08:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand] -- C:\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) SRV - [2005/04/03 19:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT) SRV - [2003/07/28 07:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2003/06/19 18:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | System] -- -- (Changer) DRV - [2009/12/07 15:20:06 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto] -- C:\Windows\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2009/05/11 04:12:20 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Windows\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009/03/30 04:33:03 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Windows\system32\drivers\avipbb.sys -- (avipbb) DRV - [2009/02/13 06:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2008/06/03 20:34:08 | 000,122,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018mdm.sys -- (s1018mdm) DRV - [2008/06/03 20:34:08 | 000,115,368 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018mgmt.sys -- (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM) DRV - [2008/06/03 20:34:08 | 000,090,408 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018bus.sys -- (s1018bus) Sony Ericsson Device 1018 driver (WDM) DRV - [2008/06/03 20:34:08 | 000,025,768 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018nd5.sys -- (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS) DRV - [2008/06/03 20:34:06 | 000,117,544 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018unic.sys -- (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM) DRV - [2008/06/03 20:34:06 | 000,111,784 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018obex.sys -- (s1018obex) DRV - [2008/06/03 20:34:06 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s1018mdfl.sys -- (s1018mdfl) DRV - [2008/05/26 23:41:46 | 000,122,152 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017mdm.sys -- (s0017mdm) DRV - [2008/05/26 23:41:46 | 000,117,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) DRV - [2008/05/26 23:41:46 | 000,111,912 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017obex.sys -- (s0017obex) DRV - [2008/05/26 23:41:46 | 000,090,536 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM) DRV - [2008/05/26 23:41:46 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017mdfl.sys -- (s0017mdfl) DRV - [2008/05/26 23:41:44 | 000,115,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) DRV - [2008/05/26 23:41:44 | 000,025,768 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) DRV - [2008/04/13 05:53:26 | 000,101,376 | ---- | M] (Protect Software GmbH) [Kernel | Auto] -- C:\Windows\system32\drivers\ACEDRV07.sys -- (ACEDRV07) DRV - [2008/01/09 07:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\Windows\system32\drivers\seehcri.sys -- (seehcri) DRV - [2007/07/12 11:35:02 | 000,305,176 | ---- | M] (Intel Corporation) [Kernel | Boot] -- C:\Windows\system32\drivers\iaStor.sys -- (IASTOR) DRV - [2007/07/10 03:56:34 | 004,449,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007/05/22 16:35:00 | 006,346,688 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\nv4_mini.sys -- (nv) DRV - [2007/05/11 05:38:37 | 002,206,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel(R) DRV - [2007/04/11 09:32:58 | 000,036,112 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2007/04/11 09:32:52 | 000,034,832 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2007/03/30 12:19:08 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- C:\Windows\system32\drivers\tosrfusb.sys -- (tosrfusb) DRV - [2007/03/13 04:12:00 | 000,255,232 | ---- | M] (Marvell) [Kernel | On_Demand] -- C:\Windows\system32\drivers\yk51x86.sys -- (yukonwxp) DRV - [2007/03/01 11:53:12 | 000,073,728 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\Tosrfhid.sys -- (Tosrfhid) DRV - [2007/02/22 14:56:24 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- C:\Windows\system32\drivers\tosrfbd.sys -- (tosrfbd) DRV - [2007/02/01 03:38:54 | 000,033,792 | ---- | M] (KM Software Team) [Kernel | On_Demand] -- C:\Windows\system32\drivers\qkbfiltr.sys -- (qkbfiltr) DRV - [2007/01/29 20:20:04 | 000,361,728 | R--- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\emBDA.sys -- (USB28xxBGA) DRV - [2007/01/29 20:19:48 | 000,039,680 | R--- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\emOEM.sys -- (USB28xxOEM) DRV - [2007/01/22 05:43:26 | 000,053,376 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\TosRfSnd.sys -- (TosRfSnd) DRV - [2006/11/22 12:35:00 | 000,982,272 | ---- | M] (Motorola Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\smserial.sys -- (smserial) DRV - [2006/11/20 12:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\tosrfbnp.sys -- (tosrfbnp) DRV - [2006/10/10 14:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\tosporte.sys -- (tosporte) DRV - [2006/09/19 08:28:00 | 000,036,608 | R--- | M] (Infineon Technologies AG) [Kernel | On_Demand] -- C:\Windows\system32\drivers\ifxtpm.sys -- (IFXTPM) DRV - [2006/07/06 21:44:00 | 000,168,448 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\Windows\system32\drivers\tifm21.sys -- (tifm21) DRV - [2006/06/16 09:40:56 | 000,193,120 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\SynTP.sys -- (SynTP) DRV - [2006/02/28 08:00:00 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Boot] -- C:\Windows\system32\drivers\symc8xx.sys -- (symc8xx) DRV - [2006/02/28 08:00:00 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Boot] -- C:\Windows\system32\drivers\sym_u3.sys -- (sym_u3) DRV - [2005/08/01 11:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System] -- C:\Windows\system32\drivers\tosrfcom.sys -- (Tosrfcom) DRV - [2005/04/04 10:25:00 | 000,015,340 | ---- | M] (NT Kernel Resources) [Kernel | Boot] -- C:\WINDOWS\System32\drivers\ndisrd.sys -- (ndisrd) DRV - [2005/01/07 12:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand] -- C:\Windows\system32\drivers\Hdaudbus.sys -- (HDAudBus) DRV - [2005/01/06 08:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\tosrfnds.sys -- (tosrfnds) DRV - [2004/08/03 18:10:14 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\MPE.sys -- (MPE) DRV - [2004/08/03 18:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\USBAUDIO.sys -- (usbaudio) USB-Audiotreiber (WDM) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Dominik_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/default.aspx IE - HKU\Dominik_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\Dominik_ON_C\..\URLSearchHook: {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Programme\IsoBuster\tbIso0.dll File not found IE - HKU\Dominik_ON_C\..\URLSearchHook: {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Programme\Share_Accelerator_MM\tbSha1.dll (Conduit Ltd.) IE - HKU\Dominik_ON_C\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKU\Dominik_ON_C\..\URLSearchHook: {dac6ed64-8dd1-4ab8-aedf-b97892d28ffe} - C:\Programme\Multi_Media_Germany\tbMult.dll (Conduit Ltd.) IE - HKU\Dominik_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 IE - HKU\Dominik_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKU\Dominik_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = IE - HKU\Sono_Bello_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\Sono_Bello_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\Sono_Bello_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 34 29 93 1C 67 97 CA 01 [binary data] IE - HKU\Sono_Bello_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Programme\Real\RealPlayer\browserrecord [2009/05/18 04:43:44 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010/06/23 16:40:48 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010/06/23 16:40:48 | 000,000,000 | ---D | M] [2010/08/30 06:36:16 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2009/08/15 17:40:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2008/03/15 09:56:14 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2008/10/13 14:34:40 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2008/02/19 10:40:48 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2006/12/03 11:59:22 | 000,000,986 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2006/11/17 07:19:24 | 000,000,801 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006/02/28 08:00:00 | 000,000,820 | ---- | M]) - C:\Windows\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\toolbaru.dll (ICQ Inc.) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (IsoBuster Toolbar) - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Programme\IsoBuster\tbIso0.dll File not found O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programme\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Share Accelerator MM Toolbar) - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Programme\Share_Accelerator_MM\tbSha1.dll (Conduit Ltd.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programme\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.) O2 - BHO: (Multi Media Germany Toolbar) - {dac6ed64-8dd1-4ab8-aedf-b97892d28ffe} - C:\Programme\Multi_Media_Germany\tbMult.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programme\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll File not found O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (IsoBuster Toolbar) - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Programme\IsoBuster\tbIso0.dll File not found O3 - HKLM\..\Toolbar: (Share Accelerator MM Toolbar) - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Programme\Share_Accelerator_MM\tbSha1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Veoh Video Compass) - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Programme\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll File not found O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (Multi Media Germany Toolbar) - {dac6ed64-8dd1-4ab8-aedf-b97892d28ffe} - C:\Programme\Multi_Media_Germany\tbMult.dll (Conduit Ltd.) O3 - HKU\Dominik_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKU\Dominik_ON_C\..\Toolbar\WebBrowser: (IsoBuster Toolbar) - {266FCDCA-7BB3-4DA7-B3BF-F845DEA2EBD6} - C:\Programme\IsoBuster\tbIso0.dll File not found O3 - HKU\Dominik_ON_C\..\Toolbar\WebBrowser: (Share Accelerator MM Toolbar) - {4596013B-6C31-408B-A266-DEAE5C086DC2} - C:\Programme\Share_Accelerator_MM\tbSha1.dll (Conduit Ltd.) O3 - HKU\Dominik_ON_C\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKU\Dominik_ON_C\..\Toolbar\WebBrowser: (Multi Media Germany Toolbar) - {DAC6ED64-8DD1-4AB8-AEDF-B97892D28FFE} - C:\Programme\Multi_Media_Germany\tbMult.dll (Conduit Ltd.) O3 - HKU\Sono_Bello_ON_C\..\Toolbar\ShellBrowser: (Share Accelerator MM Toolbar) - {4596013B-6C31-408B-A266-DEAE5C086DC2} - C:\Programme\Share_Accelerator_MM\tbSha1.dll (Conduit Ltd.) O3 - HKU\Sono_Bello_ON_C\..\Toolbar\ShellBrowser: (Multi Media Germany Toolbar) - {DAC6ED64-8DD1-4AB8-AEDF-B97892D28FFE} - C:\Programme\Multi_Media_Germany\tbMult.dll (Conduit Ltd.) O3 - HKU\Sono_Bello_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKU\Sono_Bello_ON_C\..\Toolbar\WebBrowser: (IsoBuster Toolbar) - {266FCDCA-7BB3-4DA7-B3BF-F845DEA2EBD6} - C:\Programme\IsoBuster\tbIso0.dll File not found O3 - HKU\Sono_Bello_ON_C\..\Toolbar\WebBrowser: (Share Accelerator MM Toolbar) - {4596013B-6C31-408B-A266-DEAE5C086DC2} - C:\Programme\Share_Accelerator_MM\tbSha1.dll (Conduit Ltd.) O3 - HKU\Sono_Bello_ON_C\..\Toolbar\WebBrowser: (Multi Media Germany Toolbar) - {DAC6ED64-8DD1-4AB8-AEDF-B97892D28FFE} - C:\Programme\Multi_Media_Germany\tbMult.dll (Conduit Ltd.) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [asmcoxenwr.tmp] C:\DOKUME~1\Dominik\LOKALE~1\Temp\asmcoxenwr.tmp File not found O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation) O4 - HKLM..\Run: [BrMfcWnd] C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Programme\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation) O4 - HKLM..\Run: [ControlCenter3] C:\Programme\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [EPGServiceTool] C:\Programme\WinTV\EPG Services\System\EPGClient.exe (Hauppauge Inc.) O4 - HKLM..\Run: [HCWemmon] C:\WINDOWS\HCWemmon.exe (eMPIA Technology, Inc.) O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [IndexSearch] C:\Programme\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.) O4 - HKLM..\Run: [Keyboard Manager Utility] C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe (Quanta Computer, INC.) O4 - HKLM..\Run: [LanguageShortcut] C:\Programme\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [PaperPort PTD] C:\Programme\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [PPort11reminder] C:\Programme\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKLM..\Run: [SSBkgdUpdate] C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe File not found O4 - HKLM..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKU\Dominik_ON_C..\Run: [BitTorrent DNA] C:\Programme\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKU\Dominik_ON_C..\Run: [NCLaunch] C:\Windows\NCLAUNCH.EXe (Northcode Inc.) O4 - HKU\Dominik_ON_C..\Run: [Sony Ericsson PC Suite] C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB) O4 - HKU\Dominik_ON_C..\Run: [Steam] C:\Programme\Steam\Steam.exe (Valve Corporation) O4 - HKU\Dominik_ON_C..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKU\Dominik_ON_C..\Run: [VeohPlugin] C:\Programme\Veoh Networks\VeohWebPlayer\veohwebplayer.exe File not found O4 - HKU\Sono_Bello_ON_C..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\AutoStart IR.lnk = C:\Programme\WinTV\Ir.exe (Hauppauge Computer Works) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Bluetooth Manager.lnk = C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\HP Photosmart Premier – Schnellstart.lnk = C:\Programme\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.) O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\SetPoint.exe (Logitech Inc.) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Dominik_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Sono_Bello_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198241952502 (WUWebControl Class) O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} hxxp://icq.oberon-media.com/online//online2/luxor/mjolauncher.cab (MJLauncherCtrl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10) O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10) O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class) O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} hxxp://games.icq.com/online/online2/zuma/popcaploader_v6.cab (PopCapLoader Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Grüne Idylle.bmp O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Grüne Idylle.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found ========== Files/Folders - Created Within 90 Days ========== [2010/08/30 20:00:36 | 000,552,960 | R--- | C] (OldTimer Tools) -- C:\OTLPE.exe [2010/08/30 20:00:35 | 000,000,000 | ---D | C] -- C:\_OTL [2010/08/30 16:55:08 | 000,000,000 | --SD | C] -- C:\Dokumente und Einstellungen\Administrator\IETldCache [2010/08/13 18:11:11 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Temp [2010/07/21 14:27:22 | 000,000,000 | ---D | C] -- C:\Programme\iTunes [2010/06/23 16:40:20 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime [2010/06/23 16:37:29 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour [2008/07/15 15:12:04 | 023,766,320 | ---- | C] (Apple Inc.) -- C:\Programme\QuickTimeInstaller.exe [2008/04/23 08:28:47 | 059,782,440 | ---- | C] (Apple Inc.) -- C:\Programme\iTunesSetup.exe [2006/02/18 22:28:56 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) -- C:\Windows\Fonts\RandFont.dll ========== Files - Modified Within 90 Days ========== [2010/09/02 04:29:23 | 000,786,432 | -H-- | M] () -- C:\Dokumente und Einstellungen\Administrator\NTUSER.DAT [2010/09/01 12:36:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/09/01 12:36:06 | 2145,767,424 | -HS- | M] () -- C:\hiberfil.sys [2010/09/01 03:34:50 | 008,126,464 | -H-- | M] () -- C:\Dokumente und Einstellungen\Dominik\NTUSER.DAT [2010/08/30 06:48:00 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010/08/30 06:28:00 | 000,001,044 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job [2010/08/30 03:18:41 | 000,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010/08/30 03:16:50 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010/08/29 18:32:48 | 000,237,568 | -H-- | M] () -- C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT [2010/08/29 18:32:48 | 000,237,568 | -H-- | M] () -- C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT [2010/08/29 18:32:41 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat [2010/08/29 18:32:00 | 000,024,064 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\Apocalyptica end of me.doc [2010/08/29 12:00:00 | 000,000,396 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Dominik.job [2010/08/29 06:43:10 | 000,002,509 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Desktop\Microsoft Office Word 2003.lnk [2010/08/29 05:44:37 | 000,002,607 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Desktop\Microsoft Office Outlook 2003.lnk [2010/08/28 10:19:30 | 000,002,545 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Desktop\Microsoft Office PowerPoint 2003.lnk [2010/08/28 09:26:50 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010/07/28 14:20:03 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2010/07/26 18:19:56 | 000,025,600 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\Packliste.doc [2010/07/18 00:07:56 | 000,552,960 | R--- | M] (OldTimer Tools) -- C:\OTLPE.exe [2010/07/17 15:16:56 | 000,002,537 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Desktop\Microsoft Office Excel 2003.lnk [2010/07/09 01:36:15 | 006,092,918 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\123123.nrg [2010/07/08 16:46:55 | 031,895,762 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\Kathi Satelite.nrg [2010/06/30 12:48:58 | 000,001,755 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2010/06/27 16:57:18 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2010/06/26 08:58:59 | 038,809,951 | ---- | M] () -- C:\Memo (41).mp3 [2010/06/26 08:56:48 | 004,259,551 | ---- | M] () -- C:\Memo (40).mp3 [2010/06/26 08:56:33 | 039,154,015 | ---- | M] () -- C:\Memo (39).mp3 [2010/06/26 08:54:29 | 036,745,951 | ---- | M] () -- C:\Memo (42).mp3 [2010/06/23 14:24:03 | 000,001,846 | ---- | M] () -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk [2010/06/22 10:43:42 | 001,572,864 | -H-- | M] () -- C:\Dokumente und Einstellungen\Sono Bello\NTUSER.DAT ========== Files Created - No Company Name ========== [2010/09/01 12:31:27 | 2145,767,424 | -HS- | C] () -- C:\hiberfil.sys [2010/08/29 18:31:59 | 000,024,064 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\Apocalyptica end of me.doc [2010/07/26 18:19:55 | 000,025,600 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\Packliste.doc [2010/07/09 01:36:14 | 006,092,918 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\123123.nrg [2010/07/08 16:46:45 | 031,895,762 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Eigene Dateien\Kathi Satelite.nrg [2010/06/26 08:56:48 | 038,809,951 | ---- | C] () -- C:\Memo (41).mp3 [2010/06/26 08:56:34 | 004,259,551 | ---- | C] () -- C:\Memo (40).mp3 [2010/06/26 08:54:29 | 039,154,015 | ---- | C] () -- C:\Memo (39).mp3 [2010/06/26 08:52:32 | 036,745,951 | ---- | C] () -- C:\Memo (42).mp3 [2009/12/25 13:19:31 | 000,000,425 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI [2009/12/25 13:19:04 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll [2009/12/25 13:15:27 | 000,031,864 | ---- | C] () -- C:\WINDOWS\maxlink.ini [2009/10/16 13:34:53 | 000,000,760 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\setup_ldm.iss [2009/10/12 16:38:30 | 000,000,016 | -H-- | C] () -- C:\Dokumente und Einstellungen\Sono Bello\mxfilerelatedcache.mxc2 [2009/10/03 12:34:15 | 000,006,144 | ---- | C] () -- C:\Dokumente und Einstellungen\Sono Bello\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/09/09 15:09:05 | 000,000,143 | ---- | C] () -- C:\Dokumente und Einstellungen\Sono Bello\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat [2009/09/09 15:08:51 | 001,572,864 | -H-- | C] () -- C:\Dokumente und Einstellungen\Sono Bello\NTUSER.DAT [2009/09/09 15:08:51 | 000,008,192 | -H-- | C] () -- C:\Dokumente und Einstellungen\Sono Bello\ntuser.dat.LOG [2009/09/09 15:08:51 | 000,000,190 | -HS- | C] () -- C:\Dokumente und Einstellungen\Sono Bello\ntuser.ini [2009/06/16 11:05:41 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Crocclip.INI [2009/05/28 08:07:25 | 000,000,910 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2009/05/05 13:24:52 | 000,000,016 | -H-- | C] () -- C:\Programme\mxfilerelatedcache.mxc2 [2009/05/05 13:24:52 | 000,000,016 | -H-- | C] () -- C:\Dokumente und Einstellungen\Dominik\mxfilerelatedcache.mxc2 [2009/05/05 13:24:52 | 000,000,016 | -H-- | C] () -- C:\Dokumente und Einstellungen\Administrator\mxfilerelatedcache.mxc2 [2008/11/04 12:30:52 | 002,100,210 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\ProductContextC5100.log [2008/10/29 18:10:11 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll [2008/05/12 07:04:37 | 000,000,111 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\default.pls [2008/04/22 12:18:48 | 000,879,872 | ---- | C] () -- C:\Programme\Google_Updater.exe [2008/04/20 13:16:22 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2008/04/14 07:35:56 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI [2008/04/13 17:02:51 | 000,000,029 | ---- | C] () -- C:\WINDOWS\coolacm.ini [2008/04/13 17:01:18 | 000,000,037 | ---- | C] () -- C:\WINDOWS\coolmp3.ini [2008/04/13 17:01:18 | 000,000,029 | ---- | C] () -- C:\WINDOWS\wordpad.ini [2008/04/13 17:01:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\COOLSYS.INI [2008/04/13 17:01:16 | 000,010,677 | ---- | C] () -- C:\WINDOWS\coolkb2k.ini [2008/04/13 17:00:41 | 000,000,029 | ---- | C] () -- C:\WINDOWS\winzip32.ini [2008/04/13 16:59:28 | 000,007,232 | ---- | C] () -- C:\WINDOWS\COOL.INI [2008/04/13 05:57:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\musicmaker.INI [2008/04/13 05:43:05 | 000,038,912 | ---- | C] () -- C:\WINDOWS\System32\mgxasio.dll [2008/04/13 05:39:34 | 000,006,642 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini [2008/04/09 15:58:24 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI [2008/01/03 15:23:21 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI [2008/01/03 15:22:44 | 000,000,399 | ---- | C] () -- C:\WINDOWS\vtplus32.ini [2008/01/03 15:22:38 | 000,032,135 | ---- | C] () -- C:\WINDOWS\Irremote.ini [2008/01/03 15:22:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll [2008/01/03 15:22:08 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\hcwChDB.dll [2008/01/03 15:19:44 | 000,002,120 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI [2008/01/03 15:18:28 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\bdadll.dll [2008/01/03 15:18:18 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2007/12/25 11:54:04 | 000,000,864 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\reglog.txt [2007/12/25 08:03:20 | 000,083,968 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007/12/24 19:29:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI [2007/12/23 06:48:12 | 000,000,507 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2007/12/23 06:45:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI [2007/12/21 09:17:32 | 000,000,140 | ---- | C] () -- C:\Dokumente und Einstellungen\Dominik\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat [2007/12/21 08:14:18 | 008,126,464 | -H-- | C] () -- C:\Dokumente und Einstellungen\Dominik\NTUSER.DAT [2007/12/21 08:14:18 | 000,008,192 | -H-- | C] () -- C:\Dokumente und Einstellungen\Dominik\ntuser.dat.LOG [2007/12/21 08:14:18 | 000,000,300 | -HS- | C] () -- C:\Dokumente und Einstellungen\Dominik\ntuser.ini [2007/12/05 09:49:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2007/12/05 09:42:47 | 000,000,190 | -HS- | C] () -- C:\Dokumente und Einstellungen\Administrator\ntuser.ini [2007/12/05 09:42:46 | 000,786,432 | -H-- | C] () -- C:\Dokumente und Einstellungen\Administrator\NTUSER.DAT [2007/12/05 09:42:46 | 000,008,192 | -H-- | C] () -- C:\Dokumente und Einstellungen\Administrator\ntuser.dat.LOG [2007/12/05 09:40:56 | 000,237,568 | -H-- | C] () -- C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT [2007/12/05 09:40:56 | 000,237,568 | -H-- | C] () -- C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT [2007/12/05 09:40:56 | 000,008,192 | -H-- | C] () -- C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG [2007/12/05 09:40:56 | 000,008,192 | -H-- | C] () -- C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG [2007/12/05 09:40:56 | 000,000,020 | -HS- | C] () -- C:\Dokumente und Einstellungen\NetworkService\ntuser.ini [2007/12/05 09:40:56 | 000,000,020 | -HS- | C] () -- C:\Dokumente und Einstellungen\LocalService\ntuser.ini [2007/12/05 09:32:28 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2007/12/05 09:32:27 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2007/12/05 09:32:25 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2007/12/05 09:32:23 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2007/12/05 09:31:50 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\tifmicon.dll [2007/12/05 09:31:44 | 000,000,998 | ---- | C] () -- C:\WINDOWS\System32\OemInfo.ini [2007/12/05 09:31:27 | 000,262,144 | ---- | C] () -- C:\Windows\system32\config\systemprofile\ntuser.dat [2007/12/05 09:31:27 | 000,008,192 | -H-- | C] () -- C:\Windows\system32\config\systemprofile\ntuser.dat.LOG [2007/12/05 09:30:53 | 000,000,849 | ---- | C] () -- C:\WINDOWS\orun32.ini [2006/12/05 08:05:06 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll [2005/07/22 16:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll [2003/02/20 12:53:42 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [2001/07/06 22:00:00 | 000,003,254 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI ========== LOP Check ========== [2010/03/11 14:10:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Audacity [2009/12/05 18:15:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Azureus [2008/08/13 18:22:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\capella-software [2010/08/30 06:38:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\DNA [2008/11/03 07:25:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\ICQ [2008/04/15 03:02:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\ICQ Toolbar [2008/04/11 12:24:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Leadertech [2008/04/13 05:57:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\MAGIX [2009/10/23 09:57:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\NPLUTO Corporation [2009/01/02 09:26:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\ProtectDisc [2009/01/05 13:50:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Sony [2009/05/18 05:50:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\streamripper [2007/12/25 10:25:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\TOSHIBA [2008/04/14 07:44:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\Uniblue [2009/10/08 06:39:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Dominik\Anwendungsdaten\ZapSpot [2009/09/09 15:48:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sono Bello\Anwendungsdaten\TOSHIBA ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > [2010/07/18 00:07:56 | 000,552,960 | R--- | M] (OldTimer Tools) -- C:\OTLPE.exe < MD5 for: AGP440.SYS > [2006/02/28 08:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\Windows\i386\sp2.cab:AGP440.sys < MD5 for: ATAPI.SYS > [2006/02/28 08:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\Windows\i386\sp2.cab:atapi.sys [2006/02/28 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\Windows\system32\dllcache\atapi.sys [2006/02/28 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\Windows\system32\drivers\atapi.sys < MD5 for: EVENTLOG.DLL > [2006/02/28 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\Windows\system32\eventlog.dll < MD5 for: IASTOR.SYS > [2007/07/12 11:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Programme\Intel\Intel Matrix Storage Manager\Driver\IaStor.sys [2007/07/12 11:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\oemdrv\IaStor.sys [2007/07/12 11:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\system32\drivers\iaStor.sys [2007/07/12 11:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\Windows\system32\ReinstallBackups\0001\DriverFiles\iaStor.sys [2007/07/12 11:35:44 | 000,381,976 | ---- | M] (Intel Corporation) MD5=CEB53BB804B41C52AB0782505C8E2994 -- C:\Programme\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys < MD5 for: NETLOGON.DLL > [2006/02/28 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\Windows\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2006/02/28 08:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\Windows\system32\scecli.dll < %systemroot%\*. /mp /s > < CREATERESTOREPOINT > < %systemroot%\system32\*.dll /lockedfiles > [2006/06/26 13:40:34 | 000,148,480 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dnsapi.dll [2009/07/19 12:41:10 | 011,067,392 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll [2009/07/03 12:55:14 | 001,985,536 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\iertutil.dll [2006/02/28 08:00:00 | 000,280,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\mstask.dll [2006/02/28 08:00:00 | 000,067,072 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ntdsapi.dll [2007/10/25 12:42:48 | 008,501,248 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\shell32.dll < End of report > |
02.09.2010, 14:55 | #32 | |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernen Und wenn Du dieses Script verwendest:
__________________Zitat:
|
02.09.2010, 19:57 | #33 |
| Antimalware Doctor, Security Suit Virus entfernen Hat geklappt.
__________________========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\asmcoxenwr.tmp deleted successfully. ========== FILES ========== File\Folder C:\DOKUME~1\Dominik\LOKALE~1\Temp\asmcoxenwr.tmp not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Dominik ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Sono Bello ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes Total Files Cleaned = 0.00 mb OTLPE by OldTimer - Version 3.1.40.0 log created on 09032010_075312 |
02.09.2010, 21:32 | #34 |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernen Geht immer nocht kein abgesicherter Modus? |
02.09.2010, 22:04 | #35 |
| Antimalware Doctor, Security Suit Virus entfernen Nein er geht leider immer noch nicht. |
02.09.2010, 22:14 | #36 |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernen Wir geben hier nicht auf Morgen gehts weiter. Muss mal ins Bett. |
03.09.2010, 17:36 | #37 |
| Antimalware Doctor, Security Suit Virus entfernen Soll ich nochmal scannen??? |
03.09.2010, 17:57 | #38 |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernen Sag mir einmal genau wie weit Du im Normalmodus kommst und was dann genau passiert? Hättest Du eine WIndows CD zur Hand? |
03.09.2010, 18:07 | #39 |
| Antimalware Doctor, Security Suit Virus entfernen Wenn ich in ganz normal starte bekomme ich kein Bild und nach 30 sek geht der Lüfter aus und dann fängt er wieder neu an zu starten Wenn ich F8 drücke kommt der Bildschirm zur Auswahl der verschiedenen Modi und dann muss ich "Abgesicherter Modus" und Betriebssystem Windows auswählen. Dann läd er kurz und man erkennt in weißer Schrift "Anweisungen" oder sowas. Dann wird der Bildschirm kurz blau und dann wird der Bildschirm blau und alles geht aus. |
03.09.2010, 18:18 | #40 | |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernenZitat:
Keine Pieptöne? Hast Du eine Windows CD (Microsoft Windows XP Service Pack 2) zur Hand? |
03.09.2010, 18:27 | #41 |
| Antimalware Doctor, Security Suit Virus entfernen Ja ich hab halt einen externen Bildschirm an mienem Laptop, aber es gibt schon ein paar Pieptöne. Muss noch schauen. |
03.09.2010, 18:30 | #42 |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernen Ein paar?? wäre genau wichtig wie viele? lange oder kurze? Und wenn Du ohne externen Bildschirm arbeitest? genau das gleiche? |
03.09.2010, 18:38 | #43 |
| Antimalware Doctor, Security Suit Virus entfernen Es sind kurze hohe (ziemlich leise). Ich kann nur mit externem Bildschirm arbeitet, da der "Normale" defekt ist. Ich hab die Microsoft Office Professional Edition 2003 Service Pack 2 CD |
03.09.2010, 19:56 | #44 | |
/// Malwareteam | Antimalware Doctor, Security Suit Virus entfernenZitat:
Microsoft Office ist nicht was wir brauchen Wir benötigen die SystemCD von Windows. Hast zum Laptop keine bekommen? |
05.09.2010, 21:21 | #45 |
| Antimalware Doctor, Security Suit Virus entfernen Ich werde formatieren. Ich habe im Forum gelesen, dass einer seine Passwörter ändern sollte. (ebay,...) Besteht bei mir auch die gefahr dass sie ausgespäht wurden??? |
Themen zu Antimalware Doctor, Security Suit Virus entfernen |
ahnung, angezeigt, antimalware, antimalware doctor, antivir, dateien, eingefangen, entfernen, explorer, forum, funde, gen, interne, internet, internet explorer, langsamer, laptop, löschen, nicht mehr, programm, programme, security, security suit, suite, unerwünschtes programm, viren, virus, virus eingefangen, virus entfernen |