|
Plagegeister aller Art und deren Bekämpfung: Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :(Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
26.09.2010, 22:34 | #1 |
| Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( Hallo zusammen, ich habe seit einigen Tagen folgendes Problem: *Fast alle Internetseiten laden nicht mehr / oder unvollständig. *Habe Mc Afee installiert. Es lässt sich nicht mehr öffnen, auch deinstallieren und eine Neuinstallation klappt nicht. Ich habe einen Scan im Schutzmodus mit a-squared durchgeführt. Folgendes kam raus : Emsisoft Anti-Malware - Version 5.0 Letztes Update: 24.09.2010 23:03:28 Scan Einstellungen: Scan Methode: N/A Objekte: Speicher, Traces, Cookies, C:\ Archiv Scan: Aus Heuristik: Aus ADS Scan: An Scan Beginn: 24.09.2010 23:04:15 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@advertising[1].txt gefunden: Trace.TrackingCookie.advertising!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@advertising[3].txt gefunden: Trace.TrackingCookie.advertising!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@bs.serving-sys[2].txt gefunden: Trace.TrackingCookie.bs.serving-sys!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@fastclick[1].txt gefunden: Trace.TrackingCookie.fastclick!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@serving-sys[2].txt gefunden: Trace.TrackingCookie.serving-sys!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\Low\linda@com[1].txt gefunden: Trace.TrackingCookie.com!A2 C:\Users\Linda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K75C283U\index[1].php gefunden: Riskware.JS.Obfuscator!IK Gescannt Dateien: 146995 Traces: 591375 Cookies: 84 Prozesse: 84 Gefunden Dateien: 1 Traces: 0 Cookies: 6 Prozesse: 0 Registry Keys: 0 Scan Ende: 25.09.2010 01:43:07 Scan Zeit: 2:38:52 C:\Users\Linda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K75C283U\index[1].php Quarantäne Riskware.JS.Obfuscator!IK C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\Low\linda@com[1].txt Quarantäne Trace.TrackingCookie.com!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@serving-sys[2].txt Quarantäne Trace.TrackingCookie.serving-sys!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@fastclick[1].txt Quarantäne Trace.TrackingCookie.fastclick!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@bs.serving-sys[2].txt Quarantäne Trace.TrackingCookie.bs.serving-sys!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@advertising[1].txt Quarantäne Trace.TrackingCookie.advertising!A2 C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Cookies\linda@advertising[3].txt Quarantäne Trace.TrackingCookie.advertising!A2 Quarantäne Dateien: 1 Traces: 0 Cookies: 6 Ich habe alle gefundenen Viren gelöscht. Danach erneuter Scan - nichts mehr gefunden , aber die Probleme sind weiterhin da. Erneuter Scan mit Dr Web, der Erste Komplett-Scan hat nach 5 Std abgebrochen. Der Zweite hat 10,5 Std gedauert mit folg. Meldung : SlgClientServicesRedists.exe\1.file;C:\Program Files\eMachines Games\Cake Mania\SlgClientServicesRedists.exe;Adware.SpywareStorm;; SlgClientServicesRedists.exe;C:\Program Files\eMachines Games\Cake Mania;Container enthält infizierte Objekte;Verschoben.; Ich bin ratlos, wie werde ich den Scheiss wieder los ? Kann mir hier irgendjemand helfen ? Falls ja bitte ich um eine Idiotensichere Anleitung, ich bin PC Unerfahren Vielen Dank im Voraus! |
27.09.2010, 11:14 | #2 |
/// Malware-holic | Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( ootl:
__________________Systemscan mit OTL download otl: http://filepony.de/download-otl/ Doppelklick auf die OTL.exe (user von Windows 7 und Vista: Rechtsklick als Administrator ausführen) 1. Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output 2. Hake an "scan all users" 3. Unter "Extra Registry wähle: "Use Safelist" "LOP Check" "Purity Check" 4. Kopiere in die Textbox: netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT 5. Klicke "Scan" 6. 2 reporte werden erstellt: OTL.Txt Extras.Txt beide posten |
27.09.2010, 21:10 | #3 |
| Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( Danke für die schnelle Antwort!
__________________Scan erledigt , hier das Ergebnis : OTL.txtOTL Logfile: Code:
ATTFilter OTL logfile created on: 27.09.2010 21:34:52 - Run 1 OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\Linda\Desktop Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18943) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 953,00 Mb Total Physical Memory | 161,00 Mb Available Physical Memory | 17,00% Memory free 2,00 Gb Paging File | 1,00 Gb Available in Paging File | 43,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 139,04 Gb Total Space | 91,13 Gb Free Space | 65,54% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: GUCCI Current User Name: Linda Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Linda\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\a-squared Free\a2service.exe (Emsi Software GmbH) PRC - C:\Programme\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) PRC - C:\Programme\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) PRC - C:\Programme\Napster\napster.exe (Napster) PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe (Google) PRC - C:\Programme\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.) PRC - C:\Programme\McAfee\MSM\McSmtFwk.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\MSC\McUICnt.exe (McAfee, Inc.) PRC - C:\Programme\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) PRC - C:\Users\Linda\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Windows\System32\conime.exe (Microsoft Corporation) PRC - C:\Programme\eMachines\eMachines Power Management\ePowerTray.exe (Acer Incorporated) PRC - C:\Programme\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated) PRC - C:\Programme\eMachines\eMachines Power Management\ePowerEvent.exe (Acer Incorporated) PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.) PRC - C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Programme\McAfee\SiteAdvisor\McSACore.exe () PRC - C:\Programme\eMachines\eMachines Recovery Management\NotificationCenter\Notification.exe () PRC - C:\Programme\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) PRC - C:\Windows\System32\igfxext.exe (Intel Corporation) PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Programme\Lexmark 2500 Series\lxddmon.exe () PRC - C:\Windows\System32\lxddcoms.exe ( ) PRC - C:\Programme\Lexmark 2500 Series\lxddamon.exe () PRC - C:\Programme\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) PRC - C:\Programme\Common Files\aol\acs\AOLacsd.exe (AOL LLC) PRC - C:\Programme\Common Files\aol\1254045464\ee\aolsoftware.exe (America Online, Inc.) ========== Modules (SafeList) ========== MOD - C:\Users\Linda\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation) MOD - C:\Programme\eMachines\eMachines Power Management\SysHook.dll (Acer Incorporated) MOD - C:\Programme\McAfee\SiteAdvisor\sahook.dll () MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (a2free) -- C:\Program Files\a-squared Free\a2service.exe (Emsi Software GmbH) SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe () SRV - (mfevtp) -- C:\Programme\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) SRV - (GoogleDesktopManager-051210-111108) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SRV - (MSK80Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation) SRV - (ePowerSvc) -- C:\Programme\eMachines\eMachines Power Management\ePowerSvc.exe (Acer Incorporated) SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe () SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.) SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.) SRV - (GameConsoleService) -- C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe (WildTangent, Inc.) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (lxdd_device) -- C:\Windows\System32\lxddcoms.exe ( ) SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) SRV - (AOL ACS) -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (mfehidk) -- C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.) DRV - (mfefirek) -- C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.) DRV - (mfewfpk) -- C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.) DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.) DRV - (mfeapfk) -- C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.) DRV - (mferkdet) -- C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.) DRV - (mfenlfk) -- C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.) DRV - (cfwids) -- C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.) DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.) DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (L1C) -- C:\Windows\System32\drivers\L1C60x86.sys (Atheros Communications, Inc.) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (NETw5v32) Intel(R) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation) DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.) DRV - (UBHelper) -- C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (BCM43XX) -- C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corp.) DRV - (regi) -- C:\Windows\System32\drivers\regi.sys (InterVideo) DRV - (wanatw) WAN Miniport (ATW) -- C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.) DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.) DRV - (DritekPortIO) -- C:\Programme\Launch Manager\DPortIO.sys (Dritek System Inc.) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vb32&d=0709&m=e525 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vb32&d=0709&m=e525 IE - HKLM\..\URLSearchHook: {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Programme\Spesoft\tbSpes.dll (Conduit Ltd.) IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vb32&d=0709&m=e525 IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vb32&d=0709&m=e525 IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..\URLSearchHook: {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Programme\Spesoft\tbSpes.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.) IE - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010.09.27 21:28:51 | 000,000,000 | ---D | M] O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.) O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Programme\McAfee\MSK\mskapbho.dll () O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100829010450.dll File not found O2 - BHO: (Spesoft Toolbar) - {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Programme\Spesoft\tbSpes.dll (Conduit Ltd.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Programme\Google\GoogleToolbar1.dll (Google Germany GmbH) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\3.1.415.1646\swg.dll (Google Inc.) O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll () O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Programme\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc) O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll () O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Programme\Google\GoogleToolbar1.dll (Google Germany GmbH) O3 - HKLM\..\Toolbar: (Spesoft Toolbar) - {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Programme\Spesoft\tbSpes.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Programme\Google\GoogleToolbar1.dll (Google Germany GmbH) O3 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..\Toolbar\WebBrowser: (Spesoft Toolbar) - {94817C02-FEAC-4AA8-99D8-1CB47BF4D4C0} - C:\Programme\Spesoft\tbSpes.dll (Conduit Ltd.) O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\eMachines\eMachines Power Management\ePowerTray.exe (Acer Incorporated) O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) O4 - HKLM..\Run: [HostManager] C:\Programme\Common Files\aol\1254045464\ee\aolsoftware.exe (America Online, Inc.) O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [lxddamon] C:\Program Files\Lexmark 2500 Series\lxddamon.exe () O4 - HKLM..\Run: [lxddmon.exe] C:\Program Files\Lexmark 2500 Series\lxddmon.exe () O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKLM..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe (Napster) O4 - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [WarReg_PopUp] C:\Programme\eMachines\WR_PopUp\WarReg_PopUp.exe (eMachines) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000..\Run: [AOL Fast Start] C:\Program Files\AOL 9.0 VR\AOL.EXE (AOL, LLC.) O4 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000..\Run: [Messenger (Yahoo!)] C:\Programme\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) O4 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..Trusted Domains: aol.com ([objects] * is out of zone range - 5) O15 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKU\S-1-5-21-1522387202-2609338358-952053818-1000\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5843/mcfscan.cab (McFreeScan Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation) O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll () O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Users\Linda\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Linda\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{0926a1f7-7fa8-11df-96de-00038a000015}\Shell\AutoRun\command - "" = E:\rcaeasyrip_setup.exe -- File not found O33 - MountPoints2\{0926a1f7-7fa8-11df-96de-00038a000015}\Shell\install\command - "" = E:\rcaeasyrip_setup.exe -- File not found O33 - MountPoints2\{0926a1f7-7fa8-11df-96de-00038a000015}\Shell\usermanualEnglish\command - "" = E:\rcaeasyrip_setup.exe -- File not found O33 - MountPoints2\{0926a1f7-7fa8-11df-96de-00038a000015}\Shell\usermanualFrench\command - "" = E:\rcaeasyrip_setup.exe -- File not found O33 - MountPoints2\{0926a1f7-7fa8-11df-96de-00038a000015}\Shell\usermanualSpanish\command - "" = E:\rcaeasyrip_setup.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - File not found NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation) NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootMin: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: McMPFSvc - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootNet: mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootNet: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) SafeBootNet: Messenger - Service SafeBootNet: mfefire - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) SafeBootNet: mfefirek - C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.) SafeBootNet: mfefirek.sys - C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.) SafeBootNet: mfehidk - C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.) SafeBootNet: mfehidk.sys - C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.) SafeBootNet: mfevtp - C:\Programme\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfPf - Driver SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error. ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) CREATERESTOREPOINT Error creating restore point. ========== Files/Folders - Created Within 30 Days ========== [2010.09.27 21:30:52 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Linda\Desktop\OTL.exe [2010.09.26 07:23:28 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2010.09.26 00:40:44 | 000,000,000 | ---D | C] -- C:\Users\Linda\DoctorWeb [2010.09.25 06:59:27 | 000,000,000 | ---D | C] -- C:\Users\Linda\Desktop\AOL Gespeicherte Ablage [2010.09.24 23:00:42 | 000,000,000 | ---D | C] -- C:\Programme\Emsisoft Anti-Malware [2010.09.24 23:00:42 | 000,000,000 | ---D | C] -- C:\Users\Linda\Documents\Anti-Malware [2010.09.23 22:38:11 | 000,000,000 | ---D | C] -- C:\Programme\AVG [2010.09.23 22:38:10 | 000,000,000 | ---D | C] -- C:\ProgramData\avg9 [2010.09.19 00:39:43 | 000,000,000 | ---D | C] -- C:\Users\Linda\Documents\Neuer Ordner [2010.09.15 22:32:30 | 000,317,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP4SDECD.DLL [2010.09.02 01:25:55 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Roxio Shared [2010.09.02 01:25:55 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Napster Shared [2010.09.02 01:22:24 | 013,431,752 | ---- | C] (Macrovision Corporation) -- C:\Users\Linda\Desktop\NapsterSetup-DE-NCOM-4.6.4.0.exe [2010.08.31 19:53:53 | 000,000,000 | ---D | C] -- C:\Users\Linda\Desktop\shoot [2010.08.29 01:04:48 | 000,009,344 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeclnk.sys [2010.08.29 01:04:08 | 000,386,712 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys [2010.08.29 01:04:08 | 000,312,904 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfefirek.sys [2010.08.29 01:04:08 | 000,164,808 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfewfpk.sys [2010.08.29 01:04:08 | 000,152,992 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys [2010.08.29 01:04:08 | 000,095,600 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys [2010.08.29 01:04:08 | 000,084,264 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys [2010.08.29 01:04:08 | 000,064,304 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfenlfk.sys [2010.08.29 01:04:08 | 000,055,840 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\cfwids.sys [2010.08.29 01:04:08 | 000,052,104 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys [2009.09.28 22:06:42 | 000,999,424 | ---- | C] ( ) -- C:\Windows\System32\lxddusb1.dll [2009.09.28 22:06:42 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxddinpa.dll [2009.09.28 22:06:42 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxddiesc.dll [2009.09.28 22:06:42 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXDDhcp.dll [2009.09.28 22:06:41 | 001,232,896 | ---- | C] ( ) -- C:\Windows\System32\lxddserv.dll [2009.09.28 22:06:41 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxddpmui.dll [2009.09.28 22:06:41 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxddprox.dll [2009.09.28 22:06:41 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxddpplc.dll [2009.09.28 22:06:40 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxddlmpm.dll [2009.09.28 22:06:39 | 000,700,416 | ---- | C] ( ) -- C:\Windows\System32\lxddhbn3.dll [2009.09.28 22:06:37 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxddcomc.dll [2009.09.28 22:06:37 | 000,425,984 | ---- | C] ( ) -- C:\Windows\System32\lxddcomm.dll ========== Files - Modified Within 30 Days ========== [2010.09.27 21:36:57 | 001,572,864 | -HS- | M] () -- C:\Users\Linda\ntuser.dat [2010.09.27 21:31:11 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Linda\Desktop\OTL.exe [2010.09.27 21:25:37 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.09.27 21:25:37 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.09.27 21:23:45 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.09.27 21:23:42 | 000,001,693 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk [2010.09.27 21:23:17 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.09.27 21:23:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.09.27 21:23:07 | 1000,325,120 | -HS- | M] () -- C:\hiberfil.sys [2010.09.26 23:52:46 | 000,524,288 | -HS- | M] () -- C:\Users\Linda\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms [2010.09.26 23:52:46 | 000,065,536 | -HS- | M] () -- C:\Users\Linda\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf [2010.09.26 23:52:13 | 002,433,995 | -H-- | M] () -- C:\Users\Linda\AppData\Local\IconCache.db [2010.09.26 23:00:48 | 000,000,256 | ---- | M] () -- C:\Users\Linda\Desktop\DrWeb.csv [2010.09.26 22:55:42 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.09.26 07:23:22 | 124,747,458 | ---- | M] () -- C:\Windows\MEMORY.DMP [2010.09.26 00:32:36 | 049,922,264 | ---- | M] () -- C:\Users\Linda\Desktop\drweb-cureit.exe [2010.09.21 20:15:34 | 000,015,360 | ---- | M] () -- C:\Users\Linda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.09.06 02:09:07 | 000,216,224 | ---- | M] () -- C:\Users\Linda\Desktop\Bearbeitet4.jpg [2010.09.04 14:09:24 | 000,386,712 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys [2010.09.04 14:09:24 | 000,312,904 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfefirek.sys [2010.09.04 14:09:24 | 000,164,808 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfewfpk.sys [2010.09.04 14:09:24 | 000,152,992 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys [2010.09.04 14:09:24 | 000,095,600 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys [2010.09.04 14:09:24 | 000,084,264 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys [2010.09.04 14:09:24 | 000,064,304 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfenlfk.sys [2010.09.04 14:09:24 | 000,055,840 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\cfwids.sys [2010.09.04 14:09:24 | 000,052,104 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys [2010.09.04 14:09:24 | 000,009,344 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeclnk.sys [2010.09.02 23:55:51 | 000,127,258 | ---- | M] () -- C:\Users\Linda\Documents\Groupon-3750721D1D.pdf [2010.09.02 01:23:32 | 000,001,668 | ---- | M] () -- C:\Users\Public\Desktop\Napster.lnk [2010.09.02 01:22:37 | 013,431,752 | ---- | M] (Macrovision Corporation) -- C:\Users\Linda\Desktop\NapsterSetup-DE-NCOM-4.6.4.0.exe [2010.08.29 01:35:56 | 000,001,889 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk ========== Files Created - No Company Name ========== [2010.09.26 23:00:48 | 000,000,256 | ---- | C] () -- C:\Users\Linda\Desktop\DrWeb.csv [2010.09.26 07:23:23 | 1000,325,120 | -HS- | C] () -- C:\hiberfil.sys [2010.09.26 07:23:22 | 124,747,458 | ---- | C] () -- C:\Windows\MEMORY.DMP [2010.09.26 00:32:19 | 049,922,264 | ---- | C] () -- C:\Users\Linda\Desktop\drweb-cureit.exe [2010.09.08 22:25:39 | 000,001,693 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk [2010.09.06 02:08:27 | 000,216,224 | ---- | C] () -- C:\Users\Linda\Desktop\Bearbeitet4.jpg [2010.09.02 23:55:47 | 000,127,258 | ---- | C] () -- C:\Users\Linda\Documents\Groupon-3750721D1D.pdf [2010.08.29 01:34:38 | 000,001,889 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2010.08.21 14:58:13 | 000,000,680 | ---- | C] () -- C:\Users\Linda\AppData\Local\d3d9caps.dat [2010.01.10 18:30:37 | 000,000,174 | ---- | C] () -- C:\Users\Linda\AppData\Roaming\wklnhst.dat [2009.09.28 22:07:31 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxddrwrd.ini [2009.09.28 22:06:42 | 000,286,720 | ---- | C] () -- C:\Windows\System32\LXDDinst.dll [2009.09.28 22:06:39 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxddgrd.dll [2009.09.27 16:05:29 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.09.27 13:05:52 | 000,015,360 | ---- | C] () -- C:\Users\Linda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.09.26 22:47:22 | 000,000,114 | ---- | C] () -- C:\Windows\wininit.ini [2009.03.04 09:30:53 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1591.dll [2007.01.23 19:40:04 | 000,065,536 | ---- | C] () -- C:\Windows\System32\lxddcaps.dll [2007.01.09 17:13:08 | 000,692,224 | ---- | C] () -- C:\Windows\System32\lxdddrs.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.10.06 17:08:04 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxddcnv4.dll ========== LOP Check ========== [2010.09.25 23:14:08 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Amazon [2009.11.15 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\DeepBurner [2010.08.24 01:13:14 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\gtk-2.0 [2010.06.25 00:01:58 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Softplicity [2010.06.25 00:09:36 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Spesoft Audio Converter [2010.01.10 18:30:51 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Template [2010.05.10 23:16:07 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\tonemaker [2010.09.26 23:53:08 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2009.09.27 22:22:17 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Adobe [2010.09.25 23:14:08 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Amazon [2010.09.25 06:59:42 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\AOL [2009.11.15 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\DeepBurner [2010.08.29 15:24:12 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\DivX [2009.09.26 19:56:27 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Google [2010.08.24 01:13:14 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\gtk-2.0 [2009.09.26 19:32:16 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Identities [2010.01.19 22:19:50 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\InstallShield [2009.09.26 19:31:13 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Macromedia [2010.09.26 07:35:36 | 000,000,000 | --SD | M] -- C:\Users\Linda\AppData\Roaming\Microsoft [2010.06.24 21:55:12 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Roxio [2010.06.25 00:01:58 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Softplicity [2010.06.25 00:09:36 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Spesoft Audio Converter [2010.01.10 18:30:51 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Template [2010.05.10 23:16:07 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\tonemaker [2009.12.03 05:13:23 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\WinRAR [2010.08.06 00:42:34 | 000,000,000 | ---D | M] -- C:\Users\Linda\AppData\Roaming\Yahoo! < %APPDATA%\*.exe /s > < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys [2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys [2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys [2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys [2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys [2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys < MD5 for: ATAPI.SYS > [2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys [2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys [2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys [2008.01.21 04:32:21 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys [2008.01.21 04:32:21 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys [2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys < MD5 for: CNGAUDIT.DLL > [2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll [2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll < MD5 for: EXPLORER.EXE > [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe [2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe [2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe [2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe [2008.01.21 04:34:05 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe < MD5 for: IASTORV.SYS > [2008.01.21 04:32:49 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys [2008.01.21 04:32:49 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys [2008.01.21 04:32:49 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys [2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys < MD5 for: NETLOGON.DLL > [2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll [2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll [2008.01.21 04:33:41 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll < MD5 for: NVSTOR.SYS > [2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2008.01.21 04:32:47 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys [2008.01.21 04:32:47 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys [2008.01.21 04:32:47 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys < MD5 for: SCECLI.DLL > [2008.01.21 04:34:39 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll [2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll [2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll < MD5 for: USER32.DLL > [2008.01.21 04:34:02 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll [2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll [2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll < MD5 for: USERINIT.EXE > [2008.01.21 04:34:37 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe [2008.01.21 04:34:37 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe < MD5 for: WINLOGON.EXE > [2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe [2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe [2008.01.21 04:34:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe < MD5 for: WS2IFSL.SYS > [2008.01.21 04:34:35 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys [2008.01.21 04:34:35 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2008.01.21 05:31:11 | 015,716,352 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV [2008.01.21 05:31:01 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV [2008.01.21 05:31:12 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV [2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV [2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2009.04.11 08:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll [2009.04.11 08:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll < End of report > Extras.txtOTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 27.09.2010 21:34:52 - Run 1 OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\Linda\Desktop Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18943) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 953,00 Mb Total Physical Memory | 161,00 Mb Available Physical Memory | 17,00% Memory free 2,00 Gb Paging File | 1,00 Gb Available in Paging File | 43,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 139,04 Gb Total Space | 91,13 Gb Free Space | 65,54% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: GUCCI Current User Name: Linda Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{11C67D60-C2C8-4601-B7AE-E5CC9A26CC9E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{1EC42749-9A2E-4331-B2F7-3EFD6A27CCD5}" = rport=138 | protocol=17 | dir=out | app=system | "{26A7E125-9DFE-41FD-A632-6042BCC204C5}" = rport=139 | protocol=6 | dir=out | app=system | "{2B6D0EA3-3EA5-40E0-8D71-5532247EF252}" = lport=139 | protocol=6 | dir=in | app=system | "{44377F43-5810-4307-AE6E-C3009A6489A1}" = lport=137 | protocol=17 | dir=in | app=system | "{534C9267-462F-4DD0-BAEC-B5AE51CB483C}" = lport=138 | protocol=17 | dir=in | app=system | "{94979F14-8DE9-4341-86F0-C44B18AC47EB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{953D66CB-B5B4-4979-8874-13DEE889C6A3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{B22B09F8-ADFE-4DD5-B8DE-9E506C611E2C}" = rport=137 | protocol=17 | dir=out | app=system | "{BF5D61DA-A270-4654-B4EB-859B2012F928}" = lport=2869 | protocol=6 | dir=in | app=system | "{CFE71406-012B-4A3C-B5F6-047259014BBF}" = rport=445 | protocol=6 | dir=out | app=system | "{E4DB2687-DF12-4496-B746-164CAE9E83BC}" = lport=445 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{035E00E1-BAD5-4BEC-80B3-1A76EE278FE4}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe | "{03FF2CFE-15E6-4196-9522-A603F7618EE0}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{04921BF5-C9F6-4FD6-9879-19F685132C86}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe | "{0AC67C33-EF69-4117-B722-5950D9669DB4}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{1B5D8A87-AB20-45B2-A11C-5EEC15F0D930}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe | "{1FB864C7-D10B-455D-86C4-6FE188FE2D03}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{1FFE36A4-DDCC-4018-A8B1-E07478419250}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe | "{2DF33788-FDA2-4B15-8B26-F829E9695208}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe | "{333A99A0-950E-4EBF-9C04-8FBC93AAA789}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe | "{3617D793-681F-4A22-9C8F-A10F2F550B83}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{398D04A4-27BF-47D2-B6D4-D33089D36AEF}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{4C89E6E5-762D-4E7C-8C6F-A717561B1C1D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{4EB241BC-30BD-4C55-8BD6-4FDEDC18C556}" = protocol=17 | dir=in | app=c:\program files\aol 9.0 vr\waol.exe | "{4F3E2743-0717-4152-A874-667F4F6D5658}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{51AD431A-ECA0-4BD4-85BF-9583C176904F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{5785A8AF-86F1-47E3-8114-025B41E271DC}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | "{5C694904-DE9A-4F71-895E-5434F1DF443C}" = protocol=17 | dir=in | app=c:\program files\aol 9.0 vr\aol.exe | "{5DAB6C2C-DABF-4418-BEBB-24E5CCEB1BA2}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe | "{5EC7D3E3-B6C8-4FBE-84A8-1EC7CB6B4ACE}" = protocol=17 | dir=in | app=c:\program files\common files\aol\1254045464\ee\aolsoftware.exe | "{5ED1E8A7-0426-4AB5-82C2-48C5E6412009}" = protocol=6 | dir=in | app=c:\program files\common files\aol\1254045464\ee\aolsoftware.exe | "{661ECE9D-EBDE-4768-9694-87C35B040ADA}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe | "{6BA2298C-84BD-4C67-9E71-25B21BD1AD9F}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | "{6DFA8363-B9BE-48B3-A65C-67B01BA119FE}" = protocol=6 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe | "{7180C75D-CD0F-4891-A6F0-33EA45F13AEA}" = protocol=17 | dir=in | app=c:\windows\system32\lxddcoms.exe | "{835C8879-3356-4883-935E-0E18F323BBE4}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{83F3E919-D1E4-4A32-8AEB-C8017B3C550B}" = protocol=17 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe | "{8F0D36A7-3579-4BB0-95FC-6CF9057CED51}" = protocol=6 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe | "{A0A30B7B-1C87-4203-B598-F6777DF91E8B}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | "{A238BBAF-E2CE-43CA-9985-B7A98D350547}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | "{B21DFC25-8621-4C14-9105-EF3FA02D8E4E}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{B2C02B92-E2F1-4C80-B1E9-4DFFBBAFFD63}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "{B5374C8E-5F24-4BE5-A9A6-0550B859C411}" = protocol=6 | dir=in | app=c:\windows\system32\lxddcoms.exe | "{B63710E2-470F-4391-953C-7DD98D7801B1}" = protocol=6 | dir=in | app=c:\program files\aol 9.0 vr\aol.exe | "{B65739C9-A6DF-4A2D-8248-7C63F55D5DBD}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{B69F27CE-E781-4A53-9DE0-D45D589C728E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C128657D-EA2A-4DF4-B54E-4C68FACCA67F}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe | "{CB09E254-722A-49EC-AE5C-CD6CC7817AF4}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe | "{CB52BD71-5FC1-4891-A7EA-3BB30B8FAF16}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "{D11AE00D-08FD-4EA4-ADD7-095C5501E5D3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D5681B23-BCB6-4D5E-9129-8A85B36E2528}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe | "{D579A272-D927-43A4-9C3B-7C81E0DD876E}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{DB837616-4B14-4F81-B29E-B9C2FE5DEDD1}" = protocol=17 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe | "{E0A32D91-869B-4CCB-944E-6661CE38935F}" = protocol=6 | dir=in | app=c:\program files\aol 9.0 vr\waol.exe | "{FFE5CEC3-95A0-4236-A947-C3CAAA1B97DC}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "TCP Query User{166C35C5-6BD5-46C3-B29C-101EF5C8258D}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "TCP Query User{1AFC84DC-4942-45BD-9BEC-8FCA90F2C757}C:\program files\lexmark 2500 series\lxddamon.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe | "UDP Query User{0EEBFDA8-A148-4B5D-9343-CF9F40C9228E}C:\program files\lexmark 2500 series\lxddamon.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe | "UDP Query User{E2D8DEB9-6180-4AD3-BA20-FEEB5EA4191C}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard "{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18 "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3DB0448D-AD82-4923-B305-D001E521A964}" = eMachines Power Management "{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update "{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail "{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works "{6B96DADA-1A27-4A04-8CB2-CC45168D05FA}" = Windows Live Fotogalerie "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management "{81821BF8-DA20-4F8C-AA87-F70A274828D4}" = Windows Live Writer "{835686C5-8650-49EB-8CA0-4528B4035495}" = Windows Live Call "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}" = Windows Live Messenger "{8C1E2925-14F8-45AA-B999-1E2A74BF5607}" = Windows Live Sync "{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9770FACD-C79A-499F-84C3-88F033197402}" = ToneMaker "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch "{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{DF5F687F-8018-4542-9F98-7084E9022917}" = Windows Live Essentials "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{E9787678-119F-4D52-B551-6739B2B22101}" = Adobe Help Center 1.0 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "AOL Deinstallation" = AOL Deinstallation "a-squared Free_is1" = a-squared Free 4.5 "Dream Day First Home" = Dream Day First Home (entfernen) "eMachines Screensaver" = eMachines ScreenSaver "FastImageResizer" = FastImageResizer (remove only) "Google Chrome" = Google Chrome "Google Desktop" = Google Desktop "HDMI" = Intel(R) Graphics Media Accelerator Driver "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5 "InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8 "InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "IrfanView" = IrfanView (remove only) "Lexmark 2500 Series" = Lexmark 2500 Series "LManager" = Launch Manager "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "MSC" = McAfee Internet Security "Spesoft Audio Converter_is1" = Spesoft Audio Converter 1.80 "Spesoft Toolbar" = Spesoft Toolbar "SynTPDeinstKey" = Synaptics Pointing Device Driver "Total Audio Converter_is1" = TotalAudioConverter "ViewpointMediaPlayer" = Viewpoint Media Player "WildTangent emachines Master Uninstall" = eMachines Games "WinGimp-2.0_is1" = GIMP 2.6.10 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1522387202-2609338358-952053818-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "SteuerFuchs Signier-Tool" = SteuerFuchs Signier-Tool ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 17.09.2010 09:58:27 | Computer Name = Gucci | Source = WinMgmt | ID = 10 Description = Error - 17.09.2010 14:53:50 | Computer Name = Gucci | Source = WinMgmt | ID = 10 Description = Error - 18.09.2010 05:11:58 | Computer Name = Gucci | Source = WinMgmt | ID = 10 Description = Error - 18.09.2010 05:16:45 | Computer Name = Gucci | Source = MsiInstaller | ID = 11606 Description = Error - 18.09.2010 05:16:45 | Computer Name = Gucci | Source = MsiInstaller | ID = 11606 Description = Error - 18.09.2010 05:16:45 | Computer Name = Gucci | Source = MsiInstaller | ID = 1024 Description = Error - 18.09.2010 05:17:12 | Computer Name = Gucci | Source = MsiInstaller | ID = 11606 Description = Error - 18.09.2010 05:17:12 | Computer Name = Gucci | Source = MsiInstaller | ID = 11606 Description = Error - 18.09.2010 05:17:38 | Computer Name = Gucci | Source = MsiInstaller | ID = 11606 Description = Error - 18.09.2010 05:17:38 | Computer Name = Gucci | Source = MsiInstaller | ID = 11606 Description = [ System Events ] Error - 25.09.2010 18:42:39 | Computer Name = Gucci | Source = DCOM | ID = 10005 Description = Error - 25.09.2010 18:45:42 | Computer Name = Gucci | Source = DCOM | ID = 10010 Description = Error - 25.09.2010 18:58:58 | Computer Name = Gucci | Source = DCOM | ID = 10005 Description = Error - 26.09.2010 01:23:29 | Computer Name = Gucci | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am 26.09.2010 um 07:22:10 unerwartet heruntergefahren. Error - 26.09.2010 01:29:00 | Computer Name = Gucci | Source = Service Control Manager | ID = 7022 Description = Error - 26.09.2010 01:30:24 | Computer Name = Gucci | Source = DCOM | ID = 10010 Description = Error - 26.09.2010 17:10:18 | Computer Name = Gucci | Source = DCOM | ID = 10010 Description = Error - 27.09.2010 15:25:48 | Computer Name = Gucci | Source = Dhcp | ID = 1002 Description = Die IP-Adresslease 192.168.1.2 für die Netzwerkkarte mit der Netzwerkadresse 002622129946 wurde durch den DHCP-Server 0.0.0.0 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet). Error - 27.09.2010 15:28:38 | Computer Name = Gucci | Source = DCOM | ID = 10010 Description = Error - 27.09.2010 15:29:32 | Computer Name = Gucci | Source = DCOM | ID = 10010 Description = < End of report > |
28.09.2010, 10:03 | #4 |
/// Malware-holic | Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( bitte erstelle und poste ein combofix log. Ein Leitfaden und Tutorium zur Nutzung von ComboFix |
28.09.2010, 11:34 | #5 |
| Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( Combofix Log Combofix Logfile: Code:
ATTFilter ComboFix 10-09-27.05 - Linda 28.09.2010 11:51:42.1.1 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.49.1031.18.953.192 [GMT 2:00] ausgeführt von:: c:\users\Linda\Desktop\ComboFix.exe * Im Speicher befindliches AV aktiv. . ((((((((((((((((((((((( Dateien erstellt von 2010-08-28 bis 2010-09-28 )))))))))))))))))))))))))))))) . 2010-09-28 10:09 . 2010-09-28 10:09 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-09-25 22:40 . 2010-09-26 12:57 -------- d-----w- c:\users\Linda\DoctorWeb 2010-09-24 21:00 . 2010-09-25 20:13 -------- d-----w- c:\program files\Emsisoft Anti-Malware 2010-09-23 20:38 . 2010-09-23 20:38 -------- d-----w- c:\program files\AVG 2010-09-23 20:38 . 2010-09-25 22:04 -------- d-----w- c:\programdata\avg9 2010-09-15 20:32 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe 2010-09-15 20:32 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL 2010-09-15 20:32 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll 2010-09-15 20:31 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll 2010-09-01 23:25 . 2010-09-01 23:25 -------- d-----w- c:\program files\Common Files\Roxio Shared 2010-09-01 23:25 . 2010-09-01 23:25 -------- d-----w- c:\program files\Common Files\Napster Shared . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-27 19:28 . 2010-05-03 23:12 -------- d-----w- c:\program files\McAfee 2010-09-25 22:19 . 2009-12-26 18:36 -------- d-----w- c:\program files\a-squared Free 2010-09-25 21:27 . 2010-08-20 20:37 -------- d-----w- c:\programdata\DivX 2010-09-25 21:27 . 2009-09-27 10:55 -------- d-----w- c:\program files\DivX 2010-09-25 21:25 . 2010-08-28 23:30 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe 2010-09-25 21:20 . 2009-03-04 00:30 -------- d-----w- c:\programdata\Microsoft Help 2010-09-25 21:14 . 2010-06-24 20:44 -------- d-----w- c:\users\Linda\AppData\Roaming\Amazon 2010-09-25 21:14 . 2010-06-24 20:41 -------- d-----w- c:\program files\Amazon 2010-09-25 21:06 . 2009-09-27 09:57 -------- d-----w- c:\program files\Common Files\aol 2010-09-25 21:06 . 2009-09-27 09:57 -------- d-----w- c:\programdata\AOL 2010-09-25 20:56 . 2009-03-04 00:23 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-09-25 20:56 . 2009-03-04 00:38 -------- d-----w- c:\program files\Google 2010-09-25 20:56 . 2010-08-23 22:48 -------- d-----w- c:\program files\GIMP-2.0 2010-09-25 20:56 . 2009-09-27 09:57 -------- d-----w- c:\program files\Common Files\aolshare 2010-09-25 20:56 . 2009-09-27 09:57 -------- d-----w- c:\program files\AOL 9.0 VR 2010-09-25 04:59 . 2009-09-27 10:04 -------- d-----w- c:\users\Linda\AppData\Roaming\AOL 2010-09-23 22:26 . 2010-09-23 22:26 4093792 ----a-w- c:\programdata\avg9\update\backup\avgui.exe 2010-09-23 22:26 . 2010-09-23 22:26 3586912 ----a-w- c:\programdata\avg9\update\backup\setup.exe 2010-09-23 22:26 . 2010-09-23 22:26 620896 ----a-w- c:\programdata\avg9\update\backup\avgnsx.exe 2010-09-23 22:26 . 2010-09-23 22:26 1619296 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll 2010-09-23 22:26 . 2010-09-23 22:26 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll 2010-09-23 22:26 . 2010-09-23 22:26 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll 2010-09-23 22:26 . 2010-09-23 22:26 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll 2010-09-23 22:26 . 2010-09-23 22:26 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll 2010-09-23 22:23 . 2010-09-23 22:23 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll 2010-09-16 09:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-09-04 12:09 . 2010-08-28 23:04 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys 2010-09-04 12:09 . 2010-08-28 23:04 95600 ----a-w- c:\windows\system32\drivers\mfeapfk.sys 2010-09-04 12:09 . 2010-08-28 23:04 84264 ----a-w- c:\windows\system32\drivers\mferkdet.sys 2010-09-04 12:09 . 2010-08-28 23:04 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys 2010-09-04 12:09 . 2010-08-28 23:04 55840 ----a-w- c:\windows\system32\drivers\cfwids.sys 2010-09-04 12:09 . 2010-08-28 23:04 52104 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2010-09-04 12:09 . 2010-08-28 23:04 386712 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2010-09-04 12:09 . 2010-08-28 23:04 312904 ----a-w- c:\windows\system32\drivers\mfefirek.sys 2010-09-04 12:09 . 2010-08-28 23:04 164808 ----a-w- c:\windows\system32\drivers\mfewfpk.sys 2010-09-04 12:09 . 2010-08-28 23:04 152992 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2010-09-01 23:25 . 2010-01-19 20:21 -------- d-----w- c:\program files\Common Files\PX Storage Engine 2010-09-01 23:24 . 2010-01-19 20:20 -------- d-----w- c:\program files\Napster 2010-08-29 13:24 . 2010-08-20 20:41 -------- d-----w- c:\users\Linda\AppData\Roaming\DivX 2010-08-29 00:02 . 2010-05-03 23:12 -------- d-----w- c:\program files\McAfee.com 2010-08-29 00:00 . 2010-08-20 20:42 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll 2010-08-28 23:35 . 2009-03-04 00:53 -------- d-----w- c:\program files\Common Files\Adobe 2010-08-28 23:14 . 2010-05-03 23:12 -------- d-----w- c:\program files\Common Files\McAfee 2010-08-23 23:13 . 2010-08-23 22:55 -------- d-----w- c:\users\Linda\AppData\Roaming\gtk-2.0 2010-08-21 12:58 . 2010-08-21 12:58 680 ----a-w- c:\users\Linda\AppData\Local\d3d9caps.dat 2010-08-14 22:23 . 2009-03-04 00:32 -------- d-----w- c:\program files\Microsoft Works 2010-08-05 22:42 . 2009-09-26 20:47 -------- d-----w- c:\users\Linda\AppData\Roaming\Yahoo! 2010-08-05 20:53 . 2010-08-05 20:53 27288728 ----a-w- c:\programdata\Yahoo!\YUpdater\msgup1000_1270_de.exe . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}"= "c:\program files\Spesoft\tbSpes.dll" [2009-06-08 2124824] [HKEY_CLASSES_ROOT\clsid\{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}] 2009-06-08 07:55 2124824 ----a-w- c:\program files\Spesoft\tbSpes.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}"= "c:\program files\Spesoft\tbSpes.dll" [2009-06-08 2124824] [HKEY_CLASSES_ROOT\clsid\{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{94817C02-FEAC-4AA8-99D8-1CB47BF4D4C0}"= "c:\program files\Spesoft\tbSpes.dll" [2009-06-08 2124824] [HKEY_CLASSES_ROOT\clsid\{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2010-06-01 5252408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "AOL Fast Start"="c:\program files\AOL 9.0 VR\AOL.EXE" [2007-06-21 50480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-02-11 6724128] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-24 30192] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-11-05 150040] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-11-05 178712] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-11-05 154136] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-01-09 1418536] "LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2009-02-12 862728] "Acer ePower Management"="c:\program files\eMachines\eMachines Power Management\ePowerTray.exe" [2009-04-03 698912] "WarReg_PopUp"="c:\program files\eMachines\WR_PopUp\WarReg_PopUp.exe" [2008-11-04 57344] "HostManager"="c:\program files\Common Files\AOL\1254045464\ee\AOLSoftware.exe" [2006-09-26 50736] "lxddmon.exe"="c:\program files\Lexmark 2500 Series\lxddmon.exe" [2007-06-11 291760] "lxddamon"="c:\program files\Lexmark 2500 Series\lxddamon.exe" [2007-04-30 20480] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-02-11 1833504] "NapsterShell"="c:\program files\Napster\napster.exe" [2010-07-20 323280] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-08-04 1180976] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 136176] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-24 30192] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-09-04 84264] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-09-04 64304] S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-09-04 164808] S2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2010-09-25 1872320] S2 ePowerSvc;Acer ePower Service;c:\program files\eMachines\eMachines Power Management\ePowerSvc.exe [2009-04-03 723488] S2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-05-25 537520] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-01-23 203280] S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2009-12-14 271480] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-09-04 188136] S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-09-04 141792] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632] S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-09-04 55840] S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C60x86.sys [2009-01-15 49664] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-09-04 312904] S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-09-24 3666432] --- Andere Dienste/Treiber im Speicher --- *Deregistered* - mfeavfk01 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Inhalt des "geplante Tasks" Ordners 2010-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 21:50] 2010-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 21:50] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vb32&d=0709&m=e525 mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vb32&d=0709&m=e525 uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2010-09-28 12:10 Windows 6.0.6002 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- - - - - - - - > 'Explorer.exe'(4636) c:\program files\McAfee\SiteAdvisor\saHook.dll c:\program files\eMachines\eMachines Power Management\SysHook.dll . Zeit der Fertigstellung: 2010-09-28 12:19:17 ComboFix-quarantined-files.txt 2010-09-28 10:19 Vor Suchlauf: 8 Verzeichnis(se), 97.735.512.064 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 98.423.373.824 Bytes frei - - End Of File - - 52B7B81D5CDC89F37D316359D4397679 |
28.09.2010, 11:36 | #6 |
/// Malware-holic | Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( download malwarebytes: Malwarebytes instalieren, öffnen, registerkarte aktualisierung, programm updaten. schalte alle laufenden programme ab, trenne die internetverbindung. registerkarte scanner, komplett scan, funde entfernen, log posten. |
28.09.2010, 12:58 | #7 |
| Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( Mein McAfee sendet wieder Lebenzeichen nach combofix..und sagt das mein Computer gefährdet ist , da MCAfee nicht aktualisiert ist. Habe bisher nichts gemacht. Hier das Log : Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4710 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18943 28.09.2010 13:50:39 mbam-log-2010-09-28 (13-50-39).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 260909 Laufzeit: 1 Stunde(n), 5 Minute(n), 30 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
28.09.2010, 19:20 | #8 |
| Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( Weiß nicht ob es relevant is, zur Sicherheit schreib ich es mal.. Als ich das Notebook gerade hochgefahren habe, hat automatisch eine Indexüberprüfung gestartet und kurz danach kam die Meldung das 2 verlorene Dateien widerhergestellt wurden. Ansonsten läuft McAfee wieder und auch die Internetseiten laden wieder ! ) Gibt es noch was das ich tun muss / kann ? Ich danke Dir jetzt schonmal für die tolle Hilfe !!!!!!!!! Ohne Dich hätte ich das Ding aus dem Fenster geschmissen ...! |
28.09.2010, 19:24 | #9 |
/// Malware-holic | Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( welche version von mc afee nutzt du? |
28.09.2010, 19:33 | #10 |
| Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( Die Neueste, ich habe alles aktualisiert und auf den neuesten Stand gebracht. Gibt es etwas was ich zusätzlich downloaden sollte um sowas in Zukunft zu vermeiden ? |
28.09.2010, 19:55 | #11 |
/// Malware-holic | Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( 2. dep aktivieren: dep für alle prozesse: Datenausführungsverhinderung (DEP) • "Datenausführungsverhinderung für alle Programme und Dienste mit Ausnahme der ausgewählten einschalten:". wenn es zu problemen kommen sollte, kann man die betroffenen prozesse aus der Überwachung entfernen. 3. sehop aktivieren: SEHOP aktivieren: Aktivieren von SEHOP (Structured Exception Handling Overwrite Protection) in Windows-Betriebssystemen klicke auf "Feature automatisch aktivieren" und folge den anweisungen dieser tipp, gilt auch für windows 7 4. einer der sichersten browser ist opera. Opera Webbrowser | Schneller & sicherer | Die neuen Internet-Browser kostenlos herunterladen 6. um das surfen sicherer zu machen, würde ich Sandboxie empfehlen. Download: drop.io (als pdf) hier noch ein paar zusatzeinstellungen, nicht verunsichern lassen, wenn ihr das programm instaliert habt, werden sie klar. den direkten datei zugriff bitte auf opera beschrenken, bei Internetzugriff: opera.exe öffne dann sandboxie, dann oben im menü auf sandbox klickem, wähle deine sandbox aus und klicke dann auf sandboxeinstellung. dort auf anwendung, webbrowser, andere dort auf direkten zugriff auf opera bookmarks erlauben. dann auf hinzufügen und ok. somit kannst du deine lesezeichen auch in der sandbox dauerhaft abspeichern. wenn du mit dem programm gut auskommst, ist ne lizenz zu empfehlen. 1. es gibt dann noch ein paar mehr funktionen. 2. kommt nach nem monat die anzeige, dass das programm freeware ist, die verschwindet erst nach ner zeit, find ich n bissel nerfig. 3. ist die lizenz lebenslang gültig, kostenpunkt rund 30 €, und du kannst sie auf allen pcs in deinem haushalt einsetzen. 7. autorun für usb deaktivieren: über diesen weg werden sehr häufig schaddateien verbreitet, schalte die funktion also ab. Tipparchiv - Autorun/Autoplay gezielt für Laufwerkstypen oder -buchstaben abschalten - WinTotal.de usb sticks, festplatten etc, sollte man mit panda vaccine impfen: ANTIMALWARE: Panda USB Vaccine - Download FREE - PANDA SECURITY so holt man sich keine infektionen ins haus, wenn man mal die festplatte etc verleit. hake an: hake an: run panda usb vaccine automatically when computer boots automatically vaccine any new insert usb key enable ntfs file suport 8. updates: Updates sind für dein system genauso wichtig, wie ein antivirenscanner. Sehr häufig gelangen schädlinge nur aufs system, weil der user veraltete software nutzt. instaliere die folgenden update checker. Secunia: http://www.trojaner-board.de/83959-s...ector-psi.html und file hippo update checker: FileHippo.com Update Checker - FileHippo.com das file Hippo Symbol wird im infobereich neben der uhr auftauchen, mache bitte nen rechtsklick darauf, wähle settings, results, setze einen haken bei "hide beta updates" klicke ok. dann doppelklicke file hippo, eine Internetseite wird geöffnet, auf der dier die aktuellsten updates gezeigt werden, diese downloaden und instalieren. Beide programme sollten im autostart bleiben, und sobald eines der programme updates anzeigt sollten diese umgehend instaliert werden. 9. regelmäßige Backups des systems sind sehr wichtig, du weist nie, ob deine festplatte mal kaputt geht. Acronis True Image 2011 - Festplatten-Backup-Software, Datei-Backup und Disk Imaging, Wiederherstellung von Anwendungseinstellungen, Backup von Musik, Videos, Fotos und Outlook-Mails außerdem kannst du, bei neuerlichem malware befall das system zurücksetzen. Das Backup sollte möglichst auf eine externe festplatte etc emacht werden, nicht auf die selbe, wo sich die zu sichernden daten befinden. Von sehr wichtigen Daten könnte man noch eine zusätzliche Sicherung auf dvds/cds erstellen, dazu könnte man auch wiederbeschreibbare verwenden (rws) falls die sammlung mal erneuert werden soll. bitte nur noch in Sandboxie surfen, mit klick auf sandboxed web browser |
Themen zu Mc Afee öffnet sich nicht mehr!Internetseiten laden nicht!HILFE :( |
advertising, anti-malware, appdata, einstellungen, emachines, folge, index, infizierte, internetseite, laden, microsoft, nicht mehr, nicht mehr öffnen, problem, probleme, ratlos, roaming, scan, seite, seiten, seiten laden nicht, speicher, traces, update, viren, windows, öffnen, öffnet |