|
Plagegeister aller Art und deren Bekämpfung: 20 Tan Trojaner - SparkasseWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.10.2010, 12:45 | #1 | |||
| 20 Tan Trojaner - Sparkasse Liebe Leute, habe seit geraumer Zeit den 20 Tan Trojaner (Sparkasse) am Hals. Neues Online Banking wurde beantragt etc.. der Trojaner ist jedoch immer noch drauf. Was bisher geschah: Antivir, Spyhunter, Malwarebytes, OTL, CCleaner und Hijackthis. Spyhunter OTL OTL Logfile: Code:
ATTFilter OTL logfile created on: 13.10.2010 13:52:35 - Run 1 OTL by OldTimer - Version 3.2.15.2 Folder = C:\Downloads Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 30,00% Memory free 6,00 Gb Paging File | 4,00 Gb Available in Paging File | 64,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 298,09 Gb Total Space | 184,88 Gb Free Space | 62,02% Space Free | Partition Type: NTFS Computer Name: TEST-PC | User Name: Test | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Programme\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Programme\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.) PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Programme\Trend Micro\HijackThis\HijackThis.exe (Trend Micro Inc.) PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitdm.exe (Orbitdownloader.com) PRC - C:\Programme\DAEMON Tools Pro\DTProShellHlp.exe (DT Soft Ltd) PRC - C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH) PRC - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitnet.exe (Orbitdownloader.com) PRC - C:\Programme\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH) PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.) PRC - C:\Programme\Avira\AntiVir Desktop\avscan.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Microsoft Office\Office14\GROOVEMN.EXE (Microsoft Corporation) PRC - C:\Windows\System32\OSPPSVC.EXE (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) ========== Modules (SafeList) ========== MOD - C:\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (SpyHunter 4 Service) -- C:\Programme\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.) SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (NIHardwareService) -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation) SRV - (osppsvc) -- C:\Windows\System32\OSPPSVC.EXE (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (BCASPROT) -- C:\Program Files\Systweak\Advanced System Protector\sasprot32.sys File not found DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys () DRV - (esgiguard) -- C:\Programme\Enigma Software Group\SpyHunter\esgiguard.sys () DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (ISODrive) -- C:\Programme\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.) DRV - (SiFilter) -- C:\Windows\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.) DRV - (SiRemFil) -- C:\Windows\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.) DRV - (Si3531) -- C:\Windows\system32\DRIVERS\Si3531.sys (Silicon Image, Inc) DRV - (WsAudioDevice_383) -- C:\Windows\System32\drivers\WsAudioDevice_383.sys (Wondershare) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (ahcix86s) -- C:\Windows\system32\drivers\ahcix86s.sys (AMD Technologies Inc.) DRV - (HdAudAddService) -- C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.) DRV - (nvrd32) -- C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation) DRV - (nvstor32) -- C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation) DRV - (JRAID) -- C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.) DRV - (NETw4v32) Intel(R) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation) DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell) DRV - (iaNvStor) Intel(R) -- C:\Windows\system32\DRIVERS\iaNvStor.sys (Intel Corporation) DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation) DRV - (IntcHdmiAddService) Intel(R) -- C:\Windows\System32\drivers\IntcHdmi.sys (Intel(R) Corporation) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "facebook.com" FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.7 FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.4 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.09.10 23:45:27 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.09.15 16:07:28 | 000,000,000 | ---D | M] [2010.02.01 14:54:49 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\mozilla\Extensions [2010.10.12 19:56:30 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions [2010.02.05 00:07:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010.02.01 14:56:03 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2010.10.12 19:56:24 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.08.14 14:42:50 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2010.01.16 03:15:29 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.01.16 03:15:29 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.01.16 03:15:29 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.01.16 03:15:29 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.01.16 03:15:29 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.10.13 10:40:27 | 000,001,243 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 practivate.adobe.com O1 - Hosts: 127.0.0.1 ereg.adobe.com O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com O1 - Hosts: 127.0.0.1 wip3.adobe.com O1 - Hosts: 127.0.0.1 3dns-3.adobe.com O1 - Hosts: 127.0.0.1 3dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com O1 - Hosts: 127.0.0.1 activate-sea.adobe.com O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitcth.dll (Orbitdownloader.com) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [GrooveMonitor] C:\Programme\Microsoft Office\Office14\GROOVEMN.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4 - HKLM..\Run: [IaNvSrv] C:\Programme\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe (Intel Corporation) O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O8 - Extra context menu item: &Download by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: &Grab video by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Down&load all by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: S&end to OneNote - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Linked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Linked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Users\Test\Pictures\2010-08-23\067.JPG O24 - Desktop BackupWallPaper: C:\Users\Test\Pictures\2010-08-23\067.JPG O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{e61f3165-1abe-11df-acb5-00140b3fe3d4}\Shell - "" = AutoRun O33 - MountPoints2\{e61f3165-1abe-11df-acb5-00140b3fe3d4}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (sasnative32) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found ========== Files/Folders - Created Within 30 Days ========== [2010.10.13 10:08:16 | 000,000,000 | ---D | C] -- C:\Users\Test\AppData\Roaming\Malwarebytes [2010.10.13 10:08:04 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.10.13 10:08:00 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.10.13 10:08:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.10.13 10:07:59 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2010.10.12 23:55:01 | 000,630,784 | ---- | C] (On2.com) -- C:\Windows\System32\vp7vfw.dll [2010.10.12 23:55:01 | 000,039,936 | ---- | C] (Disappearing Inc.) -- C:\Windows\System32\huffyuv.dll [2010.10.12 23:38:27 | 000,839,680 | ---- | C] (hxxp://www.mp3dev.org/) -- C:\Windows\System32\lameACM.acm [2010.10.12 23:38:27 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\Windows\System32\yv12vfw.dll [2010.10.12 23:38:27 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\System32\ac3acm.acm [2010.10.12 23:38:25 | 000,000,000 | ---D | C] -- C:\Programme\K-Lite Codec Pack [2010.10.12 20:11:19 | 000,000,000 | ---D | C] -- C:\Users\Test\Documents\Wondershare Streaming Audio Recorder [2010.10.12 20:09:45 | 000,016,640 | ---- | C] (Wondershare) -- C:\Windows\System32\drivers\WsAudioDevice_383.sys [2010.10.12 19:58:09 | 000,000,000 | ---D | C] -- C:\Users\Test\dwhelper [2010.10.12 17:48:28 | 000,000,000 | ---D | C] -- C:\Users\Test\Documents\Skylook [2010.10.10 20:36:27 | 000,000,000 | ---D | C] -- C:\Programme\Lame for Audacity [2010.10.10 20:21:21 | 000,000,000 | ---D | C] -- C:\Programme\Free M4a to MP3 Converter [2010.10.10 20:15:14 | 000,000,000 | ---D | C] -- C:\Users\Test\AppData\Roaming\Audacity [2010.10.10 20:15:00 | 000,000,000 | ---D | C] -- C:\Programme\Audacity 1.3 Beta (Unicode) [2010.10.04 12:18:38 | 000,000,000 | ---D | C] -- C:\Users\Test\Documents\Theater [2010.09.29 15:15:54 | 000,000,000 | ---D | C] -- C:\Users\Test\AppData\Local\Microsoft Games [2010.09.15 16:08:23 | 000,032,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msonpmon.dll [2010.09.15 16:07:25 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Works [2010.09.15 16:05:47 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Visual Studio [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.10.13 13:44:01 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2577750887-1694976949-513453921-1000UA.job [2010.10.13 13:24:01 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.10.13 12:24:54 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.13 12:24:54 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.13 11:59:31 | 000,096,696 | ---- | M] () -- C:\Users\Test\Desktop\prozesse.jpg [2010.10.13 11:55:08 | 000,014,460 | ---- | M] () -- C:\Users\Test\Desktop\spyhunter.jpg [2010.10.13 11:41:04 | 000,020,451 | ---- | M] () -- C:\Users\Test\Desktop\20tantrojaner.jpg [2010.10.13 10:26:24 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.10.13 10:24:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.10.13 10:24:46 | 3211,173,888 | -HS- | M] () -- C:\hiberfil.sys [2010.10.13 10:23:03 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010.10.13 10:08:08 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.12 22:44:00 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2577750887-1694976949-513453921-1000Core.job [2010.10.12 20:01:25 | 000,000,000 | ---- | M] () -- C:\Users\Test\Desktop\Hungarian Dance No. 1 (Brahms) - Raymond Dessaints, Ensemble Amati - Brahms Hungarian Dances for string orchestra.mp3 [2010.10.10 20:15:09 | 000,000,851 | ---- | M] () -- C:\Users\Test\Desktop\Audacity 1.3 Beta (Unicode).lnk [2010.10.07 00:06:25 | 000,621,346 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.10.07 00:06:25 | 000,590,082 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.10.07 00:06:25 | 000,123,686 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.10.07 00:06:25 | 000,102,094 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.09.20 17:54:26 | 001,726,968 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010.09.20 17:38:17 | 000,041,478 | ---- | M] () -- C:\Users\Test\Desktop\outlookaccounts.reg [2010.09.20 17:36:27 | 001,424,281 | ---- | M] () -- C:\Users\Test\inboxmon.CSV [2010.09.20 17:36:22 | 000,009,309 | ---- | M] () -- C:\Users\Test\AppData\Roaming\Comma Separated Values (Windows).EML [2010.09.20 17:34:51 | 000,512,512 | ---- | M] () -- C:\Users\Test\Documents\skizze so36.msg [2010.09.14 10:00:00 | 000,108,032 | ---- | M] () -- C:\Windows\System32\ff_vfw.dll [2010.09.14 10:00:00 | 000,000,038 | ---- | M] () -- C:\Windows\avisplitter.ini [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.10.13 11:59:31 | 000,096,696 | ---- | C] () -- C:\Users\Test\Desktop\prozesse.jpg [2010.10.13 11:55:07 | 000,014,460 | ---- | C] () -- C:\Users\Test\Desktop\spyhunter.jpg [2010.10.13 11:41:04 | 000,020,451 | ---- | C] () -- C:\Users\Test\Desktop\20tantrojaner.jpg [2010.10.13 10:08:08 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.12 23:38:28 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2010.10.12 23:38:28 | 000,000,414 | ---- | C] () -- C:\Windows\System32\lame_acm.xml [2010.10.12 23:38:28 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2010.10.12 23:38:27 | 000,790,528 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010.10.12 23:38:27 | 000,134,144 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010.10.12 23:38:27 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2010.10.12 20:01:25 | 000,000,000 | ---- | C] () -- C:\Users\Test\Desktop\Hungarian Dance No. 1 (Brahms) - Raymond Dessaints, Ensemble Amati - Brahms Hungarian Dances for string orchestra.mp3 [2010.10.10 20:15:09 | 000,000,851 | ---- | C] () -- C:\Users\Test\Desktop\Audacity 1.3 Beta (Unicode).lnk [2010.09.20 17:38:17 | 000,041,478 | ---- | C] () -- C:\Users\Test\Desktop\outlookaccounts.reg [2010.09.20 17:36:22 | 000,009,309 | ---- | C] () -- C:\Users\Test\AppData\Roaming\Comma Separated Values (Windows).EML [2010.09.20 17:36:10 | 001,424,281 | ---- | C] () -- C:\Users\Test\inboxmon.CSV [2010.09.20 17:34:50 | 000,512,512 | ---- | C] () -- C:\Users\Test\Documents\skizze so36.msg [2010.03.10 18:11:24 | 000,011,776 | ---- | C] () -- C:\Users\Test\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.02.02 17:36:29 | 000,001,183 | ---- | C] () -- C:\ProgramData\hpzinstall.log [2010.01.28 14:16:16 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys [2010.01.28 12:50:28 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.01.18 11:34:57 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2010.01.18 11:34:55 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll [2010.01.18 11:34:54 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll [2010.01.18 11:34:54 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1283.dll [2010.01.18 11:34:51 | 000,167,936 | ---- | C] () -- C:\Windows\System32\nvccoin.dll [2010.01.18 11:28:34 | 000,006,648 | ---- | C] () -- C:\Users\Test\AppData\Local\d3d9caps.dat [2008.02.11 20:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll [2007.05.10 01:39:28 | 000,003,584 | ---- | C] () -- C:\Windows\System32\CNCFLdNL.DLL [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini ========== LOP Check ========== [2010.10.12 23:58:42 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Audacity [2010.09.04 11:11:49 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\BE931B4CFB1CEE9643432EEA35D0ED34 [2010.01.28 14:54:40 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\DAEMON Tools Pro [2010.08.02 21:43:10 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Evyt [2010.06.27 12:18:38 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Facebook [2010.02.01 22:01:08 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\GrabPro [2010.10.04 02:39:15 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Iphi [2010.08.05 12:23:35 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Miugix [2010.10.13 13:51:34 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Orbit [2010.10.05 12:26:18 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Poim [2010.08.15 11:15:21 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Systweak [2010.01.18 11:43:00 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\TMP [2010.10.07 18:22:17 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\uTorrent [2010.10.13 10:23:06 | 000,031,798 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Hijackthis Zitat:
Zitat:
Zitat:
Geändert von hamfok (13.10.2010 um 13:02 Uhr) |
13.10.2010, 12:56 | #2 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse hi, wer sein windows nicht aktuell hällt sollte sich nicht wundern.
__________________ich möchte nen blick aufs bs werfen, danach wirst du wohl neu aufsetzen müssen, dann helfe ich dir beim absichern. ootl: Systemscan mit OTL download otl: http://filepony.de/download-otl/ Doppelklick auf die OTL.exe (user von Windows 7 und Vista: Rechtsklick als Administrator ausführen) 1. Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output 2. Hake an "scan all users" 3. Unter "Extra Registry wähle: "Use Safelist" "LOP Check" "Purity Check" 4. Kopiere in die Textbox: netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT 5. Klicke "Scan" 6. 2 reporte werden erstellt: OTL.Txt Extras.Txt beide posten |
13.10.2010, 13:15 | #3 |
| 20 Tan Trojaner - Sparkasse OTL.Txt
__________________OTL Logfile: Code:
ATTFilter OTL logfile created on: 13.10.2010 14:04:49 - Run 1 OTL by OldTimer - Version 3.2.15.2 Folder = C:\Downloads Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 29,00% Memory free 6,00 Gb Paging File | 4,00 Gb Available in Paging File | 63,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 298,09 Gb Total Space | 184,88 Gb Free Space | 62,02% Space Free | Partition Type: NTFS Computer Name: TEST-PC | User Name: Test | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Programme\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Programme\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.) PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Programme\Trend Micro\HijackThis\HijackThis.exe (Trend Micro Inc.) PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitdm.exe (Orbitdownloader.com) PRC - C:\Programme\DAEMON Tools Pro\DTProShellHlp.exe (DT Soft Ltd) PRC - C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH) PRC - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitnet.exe (Orbitdownloader.com) PRC - C:\Programme\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH) PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.) PRC - C:\Programme\Avira\AntiVir Desktop\avscan.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Microsoft Office\Office14\GROOVEMN.EXE (Microsoft Corporation) PRC - C:\Windows\System32\OSPPSVC.EXE (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) ========== Modules (SafeList) ========== MOD - C:\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (SpyHunter 4 Service) -- C:\Programme\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.) SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (NIHardwareService) -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation) SRV - (osppsvc) -- C:\Windows\System32\OSPPSVC.EXE (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (IAANTMON) Intel(R) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (BCASPROT) -- C:\Program Files\Systweak\Advanced System Protector\sasprot32.sys File not found DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys () DRV - (esgiguard) -- C:\Programme\Enigma Software Group\SpyHunter\esgiguard.sys () DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (ISODrive) -- C:\Programme\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.) DRV - (SiFilter) -- C:\Windows\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.) DRV - (SiRemFil) -- C:\Windows\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.) DRV - (Si3531) -- C:\Windows\system32\DRIVERS\Si3531.sys (Silicon Image, Inc) DRV - (WsAudioDevice_383) -- C:\Windows\System32\drivers\WsAudioDevice_383.sys (Wondershare) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (ahcix86s) -- C:\Windows\system32\drivers\ahcix86s.sys (AMD Technologies Inc.) DRV - (HdAudAddService) -- C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.) DRV - (nvrd32) -- C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation) DRV - (nvstor32) -- C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation) DRV - (JRAID) -- C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.) DRV - (NETw4v32) Intel(R) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation) DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell) DRV - (iaNvStor) Intel(R) -- C:\Windows\system32\DRIVERS\iaNvStor.sys (Intel Corporation) DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation) DRV - (IntcHdmiAddService) Intel(R) -- C:\Windows\System32\drivers\IntcHdmi.sys (Intel(R) Corporation) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2577750887-1694976949-513453921-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ IE - HKU\S-1-5-21-2577750887-1694976949-513453921-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-2577750887-1694976949-513453921-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "facebook.com" FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.7 FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.4 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.09.10 23:45:27 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.09.15 16:07:28 | 000,000,000 | ---D | M] [2010.02.01 14:54:49 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\mozilla\Extensions [2010.10.12 19:56:30 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions [2010.02.05 00:07:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010.02.01 14:56:03 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2010.10.12 19:56:24 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Test\AppData\Roaming\mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010.08.14 14:42:50 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions [2010.01.16 03:15:29 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.01.16 03:15:29 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.01.16 03:15:29 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.01.16 03:15:29 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.01.16 03:15:29 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.10.13 10:40:27 | 000,001,243 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 practivate.adobe.com O1 - Hosts: 127.0.0.1 ereg.adobe.com O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com O1 - Hosts: 127.0.0.1 wip3.adobe.com O1 - Hosts: 127.0.0.1 3dns-3.adobe.com O1 - Hosts: 127.0.0.1 3dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com O1 - Hosts: 127.0.0.1 activate-sea.adobe.com O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitcth.dll (Orbitdownloader.com) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [GrooveMonitor] C:\Programme\Microsoft Office\Office14\GROOVEMN.EXE (Microsoft Corporation) O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4 - HKLM..\Run: [IaNvSrv] C:\Programme\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe (Intel Corporation) O4 - HKLM..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-2577750887-1694976949-513453921-1000..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O8 - Extra context menu item: &Download by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: &Grab video by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Down&load all by Orbit - C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: S&end to OneNote - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Linked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Linked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Users\Test\Pictures\2010-08-23\067.JPG O24 - Desktop BackupWallPaper: C:\Users\Test\Pictures\2010-08-23\067.JPG O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{e61f3165-1abe-11df-acb5-00140b3fe3d4}\Shell - "" = AutoRun O33 - MountPoints2\{e61f3165-1abe-11df-acb5-00140b3fe3d4}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (sasnative32) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKU\S-1-5-21-2577750887-1694976949-513453921-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - File not found NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation) NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: AdobeCS4ServiceManager - hkey= - key= - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: Advanced System Protector - hkey= - key= - C:\Program Files\Systweak\Advanced System Protector\ASP.exe File not found MsConfig - StartUpReg: BCSSync - hkey= - key= - C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) MsConfig - StartUpReg: BMIMZMHMFM - hkey= - key= - C:\Users\Test\AppData\Local\Temp\Pfi.exe File not found MsConfig - StartUpReg: DAEMON Tools Pro Agent - hkey= - key= - C:\Program Files\DAEMON Tools Pro\DTProAgent.exe (DT Soft Ltd) MsConfig - StartUpReg: FIC HotKey - hkey= - key= - C:\Programme\Hotkey Utility\tray.exe () MsConfig - StartUpReg: Google Update - hkey= - key= - C:\Users\Test\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) MsConfig - StartUpReg: HP Software Update - hkey= - key= - C:\Programme\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.) MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig - StartUpReg: LosAlamos - hkey= - key= - C:\Users\Test\AppData\Local\Temp\sshnas21.DLL File not found MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.) MsConfig - StartUpReg: Sidebar - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: TkBellExe - hkey= - key= - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) MsConfig - StartUpReg: uTorrent - hkey= - key= - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.) MsConfig - StartUpReg: Windows Defender - hkey= - key= - File not found MsConfig - StartUpReg: WindowsWelcomeCenter - hkey= - key= - File not found MsConfig - State: "startup" - 2 SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {AD52BAFF-8898-A932-A295-121E62601890} - Microsoft Windows Media Player 11.0 ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler) Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (hxxp://www.mp3dev.org/) Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.) Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll () Drivers32: VIDC.HFYU - C:\Windows\System32\huffyuv.dll (Disappearing Inc.) Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com) Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll () Drivers32: vidc.yv12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2010.10.13 10:08:16 | 000,000,000 | ---D | C] -- C:\Users\Test\AppData\Roaming\Malwarebytes [2010.10.13 10:08:04 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.10.13 10:08:00 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.10.13 10:08:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.10.13 10:07:59 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2010.10.12 23:55:01 | 000,630,784 | ---- | C] (On2.com) -- C:\Windows\System32\vp7vfw.dll [2010.10.12 23:55:01 | 000,039,936 | ---- | C] (Disappearing Inc.) -- C:\Windows\System32\huffyuv.dll [2010.10.12 23:38:27 | 000,839,680 | ---- | C] (hxxp://www.mp3dev.org/) -- C:\Windows\System32\lameACM.acm [2010.10.12 23:38:27 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\Windows\System32\yv12vfw.dll [2010.10.12 23:38:27 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\System32\ac3acm.acm [2010.10.12 23:38:25 | 000,000,000 | ---D | C] -- C:\Programme\K-Lite Codec Pack [2010.10.12 20:11:19 | 000,000,000 | ---D | C] -- C:\Users\Test\Documents\Wondershare Streaming Audio Recorder [2010.10.12 20:09:45 | 000,016,640 | ---- | C] (Wondershare) -- C:\Windows\System32\drivers\WsAudioDevice_383.sys [2010.10.12 19:58:09 | 000,000,000 | ---D | C] -- C:\Users\Test\dwhelper [2010.10.12 17:48:28 | 000,000,000 | ---D | C] -- C:\Users\Test\Documents\Skylook [2010.10.10 20:36:27 | 000,000,000 | ---D | C] -- C:\Programme\Lame for Audacity [2010.10.10 20:21:21 | 000,000,000 | ---D | C] -- C:\Programme\Free M4a to MP3 Converter [2010.10.10 20:15:14 | 000,000,000 | ---D | C] -- C:\Users\Test\AppData\Roaming\Audacity [2010.10.10 20:15:00 | 000,000,000 | ---D | C] -- C:\Programme\Audacity 1.3 Beta (Unicode) [2010.10.04 12:18:38 | 000,000,000 | ---D | C] -- C:\Users\Test\Documents\Theater [2010.09.29 15:15:54 | 000,000,000 | ---D | C] -- C:\Users\Test\AppData\Local\Microsoft Games [2010.09.15 16:08:23 | 000,032,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msonpmon.dll [2010.09.15 16:07:25 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Works [2010.09.15 16:05:47 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Visual Studio [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010.10.13 13:44:01 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2577750887-1694976949-513453921-1000UA.job [2010.10.13 13:24:01 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.10.13 12:24:54 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.10.13 12:24:54 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.10.13 11:59:31 | 000,096,696 | ---- | M] () -- C:\Users\Test\Desktop\prozesse.jpg [2010.10.13 11:55:08 | 000,014,460 | ---- | M] () -- C:\Users\Test\Desktop\spyhunter.jpg [2010.10.13 11:41:04 | 000,020,451 | ---- | M] () -- C:\Users\Test\Desktop\20tantrojaner.jpg [2010.10.13 10:26:24 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.10.13 10:24:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.10.13 10:24:46 | 3211,173,888 | -HS- | M] () -- C:\hiberfil.sys [2010.10.13 10:23:03 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010.10.13 10:08:08 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.12 22:44:00 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2577750887-1694976949-513453921-1000Core.job [2010.10.12 20:01:25 | 000,000,000 | ---- | M] () -- C:\Users\Test\Desktop\Hungarian Dance No. 1 (Brahms) - Raymond Dessaints, Ensemble Amati - Brahms Hungarian Dances for string orchestra.mp3 [2010.10.10 20:15:09 | 000,000,851 | ---- | M] () -- C:\Users\Test\Desktop\Audacity 1.3 Beta (Unicode).lnk [2010.10.07 00:06:25 | 000,621,346 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.10.07 00:06:25 | 000,590,082 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.10.07 00:06:25 | 000,123,686 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.10.07 00:06:25 | 000,102,094 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.09.20 17:54:26 | 001,726,968 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010.09.20 17:38:17 | 000,041,478 | ---- | M] () -- C:\Users\Test\Desktop\outlookaccounts.reg [2010.09.20 17:36:27 | 001,424,281 | ---- | M] () -- C:\Users\Test\inboxmon.CSV [2010.09.20 17:36:22 | 000,009,309 | ---- | M] () -- C:\Users\Test\AppData\Roaming\Comma Separated Values (Windows).EML [2010.09.20 17:34:51 | 000,512,512 | ---- | M] () -- C:\Users\Test\Documents\skizze so36.msg [2010.09.14 10:00:00 | 000,108,032 | ---- | M] () -- C:\Windows\System32\ff_vfw.dll [2010.09.14 10:00:00 | 000,000,038 | ---- | M] () -- C:\Windows\avisplitter.ini [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.10.13 11:59:31 | 000,096,696 | ---- | C] () -- C:\Users\Test\Desktop\prozesse.jpg [2010.10.13 11:55:07 | 000,014,460 | ---- | C] () -- C:\Users\Test\Desktop\spyhunter.jpg [2010.10.13 11:41:04 | 000,020,451 | ---- | C] () -- C:\Users\Test\Desktop\20tantrojaner.jpg [2010.10.13 10:08:08 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.10.12 23:38:28 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2010.10.12 23:38:28 | 000,000,414 | ---- | C] () -- C:\Windows\System32\lame_acm.xml [2010.10.12 23:38:28 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2010.10.12 23:38:27 | 000,790,528 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010.10.12 23:38:27 | 000,134,144 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010.10.12 23:38:27 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2010.10.12 20:01:25 | 000,000,000 | ---- | C] () -- C:\Users\Test\Desktop\Hungarian Dance No. 1 (Brahms) - Raymond Dessaints, Ensemble Amati - Brahms Hungarian Dances for string orchestra.mp3 [2010.10.10 20:15:09 | 000,000,851 | ---- | C] () -- C:\Users\Test\Desktop\Audacity 1.3 Beta (Unicode).lnk [2010.09.20 17:38:17 | 000,041,478 | ---- | C] () -- C:\Users\Test\Desktop\outlookaccounts.reg [2010.09.20 17:36:22 | 000,009,309 | ---- | C] () -- C:\Users\Test\AppData\Roaming\Comma Separated Values (Windows).EML [2010.09.20 17:36:10 | 001,424,281 | ---- | C] () -- C:\Users\Test\inboxmon.CSV [2010.09.20 17:34:50 | 000,512,512 | ---- | C] () -- C:\Users\Test\Documents\skizze so36.msg [2010.03.10 18:11:24 | 000,011,776 | ---- | C] () -- C:\Users\Test\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.02.02 17:36:29 | 000,001,183 | ---- | C] () -- C:\ProgramData\hpzinstall.log [2010.01.28 14:16:16 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys [2010.01.28 12:50:28 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.01.18 11:34:57 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2010.01.18 11:34:55 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll [2010.01.18 11:34:54 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll [2010.01.18 11:34:54 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1283.dll [2010.01.18 11:34:51 | 000,167,936 | ---- | C] () -- C:\Windows\System32\nvccoin.dll [2010.01.18 11:28:34 | 000,006,648 | ---- | C] () -- C:\Users\Test\AppData\Local\d3d9caps.dat [2008.02.11 20:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll [2007.05.10 01:39:28 | 000,003,584 | ---- | C] () -- C:\Windows\System32\CNCFLdNL.DLL [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini ========== LOP Check ========== [2010.08.14 05:13:51 | 000,000,000 | ---D | M] -- C:\Users\Gast\AppData\Roaming\Systweak [2010.04.18 16:10:26 | 000,000,000 | ---D | M] -- C:\Users\MONDTAG\AppData\Roaming\Systweak [2010.10.12 23:58:42 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Audacity [2010.09.04 11:11:49 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\BE931B4CFB1CEE9643432EEA35D0ED34 [2010.01.28 14:54:40 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\DAEMON Tools Pro [2010.08.02 21:43:10 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Evyt [2010.06.27 12:18:38 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Facebook [2010.02.01 22:01:08 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\GrabPro [2010.10.04 02:39:15 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Iphi [2010.08.05 12:23:35 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Miugix [2010.10.13 13:51:34 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Orbit [2010.10.05 12:26:18 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Poim [2010.08.15 11:15:21 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Systweak [2010.01.18 11:43:00 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\TMP [2010.10.07 18:22:17 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\uTorrent [2010.10.13 10:23:06 | 000,031,798 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2010.10.12 18:39:32 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Adobe [2010.05.02 15:30:30 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Apple Computer [2010.10.12 23:58:42 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Audacity [2010.09.04 11:11:49 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\BE931B4CFB1CEE9643432EEA35D0ED34 [2010.01.28 14:54:40 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\DAEMON Tools Pro [2010.03.10 19:31:21 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\DivX [2010.08.02 21:43:10 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Evyt [2010.06.27 12:18:38 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Facebook [2010.02.01 22:01:08 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\GrabPro [2010.02.02 18:25:03 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\HP [2010.01.18 11:28:38 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Identities [2010.10.04 02:39:15 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Iphi [2010.01.27 18:46:58 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Macromedia [2010.10.13 10:08:16 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Malwarebytes [2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Media Center Programs [2010.08.14 14:37:03 | 000,000,000 | --SD | M] -- C:\Users\Test\AppData\Roaming\Microsoft [2010.08.05 12:23:35 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Miugix [2010.02.01 14:54:49 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Mozilla [2010.10.13 13:51:34 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Orbit [2010.10.05 12:26:18 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Poim [2010.09.10 23:47:00 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Real [2010.10.12 18:23:10 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Skype [2010.10.12 17:45:53 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\skypePM [2010.08.15 11:15:21 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Systweak [2010.01.18 11:43:00 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\TMP [2010.10.07 18:22:17 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\uTorrent < %APPDATA%\*.exe /s > [2007.10.29 07:23:14 | 000,017,408 | ---- | M] () -- C:\Users\Test\AppData\Roaming\Facebook\facebook.exe [2010.06.27 12:18:38 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\Test\AppData\Roaming\Facebook\uninstall.exe [2008.05.29 02:03:08 | 000,037,176 | ---- | M] () -- C:\Users\Test\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2010.08.14 14:37:03 | 000,110,080 | R--- | M] () -- C:\Users\Test\AppData\Roaming\Microsoft\Installer\{95431C66-CF9A-4913-BFFF-6050785AFB65}\IconD7F16134.exe [2010.08.14 14:37:03 | 000,110,080 | R--- | M] () -- C:\Users\Test\AppData\Roaming\Microsoft\Installer\{95431C66-CF9A-4913-BFFF-6050785AFB65}\IconF7A21AF7.exe [2007.12.30 06:01:18 | 000,307,200 | ---- | M] (Simon Tatham) -- C:\Users\Test\AppData\Roaming\Mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe [2007.12.30 06:01:18 | 000,172,032 | ---- | M] (Simon Tatham) -- C:\Users\Test\AppData\Roaming\Mozilla\Firefox\Profiles\9t8nou9e.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys [2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys [2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys [2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys < MD5 for: AHCIX86S.SYS > [2007.12.19 19:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) MD5=0DEE2B628D4C6E23285BB91EFFDABFDE -- C:\Windows\System32\drivers\ahcix86s.sys [2007.12.19 19:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) MD5=0DEE2B628D4C6E23285BB91EFFDABFDE -- C:\Windows\System32\DriverStore\FileRepository\ahcix86s.inf_71554ba4\ahcix86s.sys < MD5 for: ATAPI.SYS > [2008.04.23 12:43:22 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\drivers\atapi.sys [2008.04.23 12:43:22 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys [2008.04.23 12:43:22 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys [2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys [2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys [2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [2008.04.23 12:43:22 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys < MD5 for: CNGAUDIT.DLL > [2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll [2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll < MD5 for: EXPLORER.EXE > [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe [2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\explorer.exe [2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe [2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe [2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe [2008.01.21 04:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe < MD5 for: IASTOR.SYS > [2007.04.25 13:17:36 | 000,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 -- C:\fsc.tmp\1016640\Winall\Driver\iaStor.sys [2007.04.25 13:17:36 | 000,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 -- C:\fsc.tmp\1016656\iaStor.sys [2007.04.25 13:17:36 | 000,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 -- C:\Programme\Intel\Intel Matrix Storage Manager\driver\iaStor.sys [2007.04.25 13:17:36 | 000,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 -- C:\Windows\System32\drivers\iaStor.sys [2007.04.25 13:17:36 | 000,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_b92fa6ec\iaStor.sys [2007.04.25 13:18:12 | 000,537,368 | ---- | M] (Intel Corporation) MD5=6E9BEDAEFA5A3F86CECF40F4963F3021 -- C:\fsc.tmp\1016640\Winall\Driver64\IaStor.sys [2007.04.25 13:18:12 | 000,537,368 | ---- | M] (Intel Corporation) MD5=6E9BEDAEFA5A3F86CECF40F4963F3021 -- C:\Programme\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys < MD5 for: IASTORV.SYS > [2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys [2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys [2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys [2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys < MD5 for: NETLOGON.DLL > [2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\System32\netlogon.dll [2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll < MD5 for: NVSTOR.SYS > [2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys [2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys [2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys < MD5 for: NVSTOR32.SYS > [2007.10.31 12:23:00 | 000,115,744 | ---- | M] (NVIDIA Corporation) MD5=9D2BD672C0461185D6EA1AE8BD3AE3F4 -- C:\Windows\System32\drivers\nvstor32.sys [2007.10.31 12:23:00 | 000,115,744 | ---- | M] (NVIDIA Corporation) MD5=9D2BD672C0461185D6EA1AE8BD3AE3F4 -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_04bc6797\nvstor32.sys < MD5 for: SCECLI.DLL > [2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\System32\scecli.dll [2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll < MD5 for: USER32.DLL > [2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll [2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll < MD5 for: USERINIT.EXE > [2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe [2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe < MD5 for: WINLOGON.EXE > [2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\System32\winlogon.exe [2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe < MD5 for: WS2IFSL.SYS > [2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys [2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > [2010.01.28 14:16:16 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\Windows\System32\drivers\sptd.sys < %systemroot%\System32\config\*.sav > [2008.01.21 05:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV [2008.01.21 05:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV [2008.01.21 05:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV [2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV [2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2009.03.08 13:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll [2009.03.08 13:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll [2008.01.21 04:24:11 | 001,386,496 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\msvbvm60.dll [2008.01.21 04:24:42 | 000,242,744 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll [2008.01.21 04:24:38 | 000,225,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < > < End of report > Extras.Txt OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 13.10.2010 14:04:49 - Run 1 OTL by OldTimer - Version 3.2.15.2 Folder = C:\Downloads Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 29,00% Memory free 6,00 Gb Paging File | 4,00 Gb Available in Paging File | 63,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 298,09 Gb Total Space | 184,88 Gb Free Space | 62,02% Space Free | Partition Type: NTFS Computer Name: TEST-PC | User Name: Test | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2577750887-1694976949-513453921-1000\SOFTWARE\Classes\<extension>] .exe [@ = exefile] -- Reg Error: Key error. File not found .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2577750887-1694976949-513453921-1000] "EnableNotifications" = 0 "EnableNotificationsRef" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitdm.exe" = C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com) "C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitnet.exe" = C:\Users\Test\Desktop\Musik\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{8D60807F-EA1A-4E22-9920-7ED14BD13F96}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 | "{8FA8564C-DB04-4E46-BF99-54F54E6C6FAF}" = lport=2869 | protocol=6 | dir=in | app=system | "{DA4BB859-C10D-4D5F-B3D6-761838855E2C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{F1E8D59C-A4A2-4C20-9152-4A3830B35AAF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00EA053C-989B-460B-9F28-657BA70CC84A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{0F5C1446-2ED6-42B1-BB8A-ABEDBD07B72B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{2C8BD266-FAD4-4D5D-B7EE-0A9DC81F560B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{3080CFED-DD9E-4787-8045-93DF5E766B71}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{310A627D-DA2B-4B74-B803-385589BBAE4B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{49B47EF0-A5D5-4557-A56E-E937D2127432}" = protocol=17 | dir=in | app=c:\users\test\appdata\roaming\facebook\facebook.exe | "{4FD2FAFA-DFE4-4F1A-9C05-8D914F9D6D63}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{5E6EFAA5-CCB2-4215-8C81-1CFC2815976E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{70F6B5F3-2797-47F4-A13C-4910FF8C7B16}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{7217D24E-35F2-4162-80C4-C517D7683114}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{735D7C6E-F380-471B-8AA8-0FA2F7A2747F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{82047081-FAD1-4E9B-ACCA-678B2CD8F118}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{8B625306-D9B3-4217-AB8A-814A0B9D3C11}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{AA584C16-2A1F-493A-AB86-4C403D4E6B75}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{ABB25DB1-B128-4F58-B04B-D2063A0B3B66}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{B04B3850-C499-4759-9252-07C3A27C8ECE}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{CADC87A6-6E70-4B0B-AF75-7630C9C8E348}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{D33BB319-A6D8-4998-BB23-222D25D54827}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{D7D69E15-C74D-4C52-91B3-AA4F38580EFF}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{D9CA35F3-A5E7-4774-82B8-69802E4C8F51}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{E799237E-F162-4A93-8B98-237A3498C347}" = protocol=6 | dir=in | app=c:\users\test\appdata\roaming\facebook\facebook.exe | "{E88A9029-96AC-4C38-ADB1-99FFA9797C2C}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{EBDCA8A9-52BB-4D14-87E2-51962D8C9AA2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{EFD41243-2A3E-44F3-BE21-F66B8CD8FECA}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{FAAB171F-27E3-4B02-96DE-7F4226ECDC0F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "TCP Query User{30C20616-281D-4B1A-A639-A4D4ED761D7F}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe | "TCP Query User{6B356ABD-FA03-4434-9AB2-2DC54FAA7C30}C:\users\test\documents\downloads\keygen.ultraiso.9.3.1.2633.exe" = protocol=6 | dir=in | app=c:\users\test\documents\downloads\keygen.ultraiso.9.3.1.2633.exe | "TCP Query User{83605DF3-8156-4726-8368-9D4BC0923B66}C:\users\test\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\test\appdata\local\google\chrome\application\chrome.exe | "TCP Query User{96AD869D-4F7B-49F3-BBE8-F208BED37E82}C:\users\test\desktop\musik\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\users\test\desktop\musik\orbitdownloader\orbitnet.exe | "TCP Query User{BEF6DD67-B503-458B-B963-32EDC84180D5}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{D3E778BE-980B-4964-ABEA-6B57EF0FF303}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{199FFFBA-9583-43C2-B3F1-CA36AF04B87A}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | "UDP Query User{35B80CC5-702B-4D9C-A8DD-3E56E620CE83}C:\users\test\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\test\appdata\local\google\chrome\application\chrome.exe | "UDP Query User{417F703B-F79B-4353-A74C-3F02ADE17EC3}C:\users\test\desktop\musik\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\users\test\desktop\musik\orbitdownloader\orbitnet.exe | "UDP Query User{682E16F7-EA3C-45F3-885A-E05CFE2B1BD9}C:\users\test\documents\downloads\keygen.ultraiso.9.3.1.2633.exe" = protocol=17 | dir=in | app=c:\users\test\documents\downloads\keygen.ultraiso.9.3.1.2633.exe | "UDP Query User{BC9F481B-57C9-403A-8223-5BFBD1F4694C}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{D83115C7-8852-4675-82B5-A3AC39BDC7EE}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3 "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center "{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{0FE6B77F-54CD-45ED-BB64-A99477B0A8F1}" = 5600 "{10140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 14 "{10140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 14 "{10140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 14 "{10140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 14 "{10140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 14 "{10140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 14 "{10140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 14 "{10140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 14 "{10140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 14 "{10140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 14 "{10140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 14 "{10140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 14 "{10140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 14 "{10140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 14 "{10140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 14 "{10140000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 14 "{10140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 14 "{10140000-011A-0000-0000-0000000FF1CE}" = Microsoft Office Send-a-Smile "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2605461E-AB2E-49F5-8A16-64B7F3595030}" = 5600Trb "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18 "{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3 "{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor "{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4 "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3 "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3 "{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7DCBC3D8-8954-491D-A1B9-8C61C563B004}" = 5600_Help "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3 "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3 "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Turbo Memory und Intel® Matrix Storage Manager "{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95431C66-CF9A-4913-BFFF-6050785AFB65}" = SpyHunter "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch "{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3 "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter "{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3 - Deutsch "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0 "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2 "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{C716522C-3731-4667-8579-40B098294500}" = Toolbox "{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport "{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9-Reihe "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3 "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext "{E8A602BF-C276-4DB2-A9FF-B4C30EA1CB7C}_is1" = iDump (Freeware) Build:31 "{EAFEF30E-3789-49C7-A6D9-77C12E005BAC}" = Safari "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3 "Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4 "Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode) "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CCleaner" = CCleaner "CNXT_AUDIO_HDA" = Conexant HD Audio "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "Digitale Bibliothek 3" = Digitale Bibliothek 3 "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "ENTERPRISE" = Microsoft Office Enterprise 2007 "Free ISO Creator (by minidvdsoft)_is1" = Free ISO Creator version 2.8 "Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.2 "HDMI" = Intel(R) Graphics Media Accelerator Driver "HijackThis" = HijackThis 2.0.2 "Hotkey Utility_is1" = Hotkey Utility "HP Imaging Device Functions" = HP Imaging Device Functions 8.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0 "HPExtendedCapabilities" = HP Customer Participation Program 8.0 "HPOCR" = HP OCR Software 8.0 "KLiteCodecPack_is1" = K-Lite Codec Pack 6.4.0 (Full) "LAME for Audacity_is1" = LAME v3.98.2 for Audacity "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Marvell Miniport Driver" = Marvell Miniport Driver "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.2pre)" = Mozilla Firefox (3.6.2pre) "Native Instruments Controller Editor" = Native Instruments Controller Editor "Native Instruments Service Center" = Native Instruments Service Center "Native Instruments Traktor" = Native Instruments Traktor "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 (Technical Preview) "Orbit_is1" = Orbit Downloader "RealPlayer 12.0" = RealPlayer "SynTPDeinstKey" = Synaptics Pointing Device Driver "UltraISO_is1" = UltraISO Premium V9.35 "uTorrent" = µTorrent "Windows Media Encoder 9" = Windows Media Encoder 9-Reihe "WinLiveSuite_Wave3" = Windows Live Essentials ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-2577750887-1694976949-513453921-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Facebook Plug-In" = Facebook Plug-In "Google Chrome" = Google Chrome ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 13.10.2010 03:59:39 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 25520266 Error - 13.10.2010 03:59:39 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 25520266 Error - 13.10.2010 03:59:40 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 13.10.2010 03:59:40 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 25521468 Error - 13.10.2010 03:59:40 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 25521468 Error - 13.10.2010 03:59:41 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 13.10.2010 03:59:41 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 25522856 Error - 13.10.2010 03:59:41 | Computer Name = Test-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 25522856 Error - 13.10.2010 04:25:49 | Computer Name = Test-PC | Source = WinMgmt | ID = 10 Description = Error - 13.10.2010 05:36:04 | Computer Name = Test-PC | Source = Application Error | ID = 1000 Description = Fehlerhafte Anwendung iexplore.exe, Version 8.0.6001.18904, Zeitstempel 0x4b835fec, fehlerhaftes Modul urlmon.dll, Version 8.0.6001.18904, Zeitstempel 0x4b837808, Ausnahmecode 0xc0000005, Fehleroffset 0x000294fe, Prozess-ID 0x1424, Anwendungsstartzeit 01cb6ab996320f7b. [ System Events ] Error - 01.07.2010 09:09:58 | Computer Name = Test-PC | Source = HTTP | ID = 15016 Description = Error - 01.07.2010 09:10:55 | Computer Name = Test-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 01.07.2010 09:11:11 | Computer Name = Test-PC | Source = Service Control Manager | ID = 7000 Description = Error - 05.07.2010 06:28:45 | Computer Name = Test-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am 05.07.2010 um 02:47:59 unerwartet heruntergefahren. Error - 05.07.2010 06:28:48 | Computer Name = Test-PC | Source = HTTP | ID = 15016 Description = Error - 05.07.2010 06:30:12 | Computer Name = Test-PC | Source = Service Control Manager | ID = 7000 Description = Error - 05.07.2010 06:31:15 | Computer Name = Test-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 02.08.2010 15:40:14 | Computer Name = Test-PC | Source = HTTP | ID = 15016 Description = Error - 02.08.2010 15:40:53 | Computer Name = Test-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 02.08.2010 15:41:35 | Computer Name = Test-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > |
13.10.2010, 13:26 | #4 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse ok musst du noch daten sichern?^ |
13.10.2010, 13:29 | #5 |
| 20 Tan Trojaner - SparkasseEmm, ja ungefähr zwölf Jahre Daten (Dokumente, Bilder etc.) und Emails. Geht bei so einer Neubespielung die ganze Software verloren? (bin ich 20 Minuten wieder da) |
13.10.2010, 13:34 | #6 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse ja geht sie. naja sorry wenn man so viele daten hatt, hat man davon auch nen backup auf ner externen daten quelle, was machst du denn, wenn deine festplatte mal kaputt ist? |
13.10.2010, 14:11 | #7 | |
| 20 Tan Trojaner - SparkasseZitat:
Aber das kann man doch überprüfen? Vielen Dank übrigens. |
13.10.2010, 14:13 | #8 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse also das ist kein file infektor, du kannst also alless rüber ziehen was du brauchst. |
13.10.2010, 14:17 | #9 | |
| 20 Tan Trojaner - SparkasseZitat:
Ok super. Und wie wird neubespielt? Ich habe nämlich keine Installations Dd für Vista bekommen, sondern nur eine Recovery DVD selbser erstellt. Und wie kann ich meine Emails eigentlich sichern, ist das überhaupt möglich? Sind bei Outlook. |
13.10.2010, 14:44 | #10 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse erst mal outlook Outlook 2000, 2002, 2003, 2007 und 2010 Daten sichern [Backup] probier mal obs klappt |
13.10.2010, 15:52 | #11 | |
| 20 Tan Trojaner - SparkasseZitat:
Outlook backup bin ich gerade dabei. Die Daten sind jetzt auf der externen Festplatte. Ich denke ich bin in 15 Minuten soweit |
13.10.2010, 16:02 | #12 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse das ist doch schon mal was :-) dann lege die cd ein die du erstellt hast, die backup cd und starte von dieser cd neu. der pc sollte von der cd aus starten, wenn nicht, gehe ins boot menü und wähle dort die cd aus, sollte bei neustart f11 oder f12 sein dann wirst du durch die schritte geführt, evtl. musst du erst formatieren, dann windows aufspielen, je mach dem was angezeigt wird. dann, wenn das fertig ist, instaliere alle treiber etc. dann gehts sofort los mit windows updates. 1. servicepack2: Downloaddetails: Windows Server 2008 Service Pack 2 und Windows Vista Service Pack 2 - Five Language Standalone (KB948465) internet explorer 8 Internet Explorer 8: Startseite dann besuche die windows update seite, spiele wichtige updates auf, unter einstellungen schaue das automatische updates aktiev sind und automatisch instaliert werden. dann gehts weiter: 2. dep aktivieren: dep für alle prozesse: Datenausführungsverhinderung (DEP) • "Datenausführungsverhinderung für alle Programme und Dienste mit Ausnahme der ausgewählten einschalten:". wenn es zu problemen kommen sollte, kann man die betroffenen prozesse aus der Überwachung entfernen. 3. sehop aktivieren: SEHOP aktivieren: Aktivieren von SEHOP (Structured Exception Handling Overwrite Protection) in Windows-Betriebssystemen klicke auf "Feature automatisch aktivieren" und folge den anweisungen dieser tipp, gilt auch für windows 7 4. einer der sichersten browser ist opera. http://de.opera.com/download/ in den letzten jahren lag er was die sicherheit angeht weit vor den großen wie dem internet explorer und dem firefox. mit diesem tool lässt sich ein werbeblocker laden Opera AdBlock Configurator - Freeware - DE - Download.CHIP.eu zusätzlich kannst du das auch manuell erledigen, falls mal etwas nicht geblockt wird: http://my.opera.com/computerbase/blo...ung-blockieren 5. avira genaustens nach anleitung instalieren: http://www.trojaner-board.de/54192-a...tellungen.html die einzige abweichung unter konfiguration, guard, autostart, haken raus nehmen. 6. um das surfen sicherer zu machen, würde ich Sandboxie empfehlen. Download: drop.io (als pdf) hier noch ein paar zusatzeinstellungen, nicht verunsichern lassen, wenn ihr das programm instaliert habt, werden sie klar. den direkten datei zugriff bitte auf opera beschrenken, bei Internetzugriff: opera.exe öffne dann sandboxie, dann oben im menü auf sandbox klickem, wähle deine sandbox aus und klicke dann auf sandboxeinstellung. dort auf anwendung, webbrowser, andere dort auf direkten zugriff auf opera bookmarks erlauben. dann auf hinzufügen und ok. somit kannst du deine lesezeichen auch in der sandbox dauerhaft abspeichern. wenn du mit dem programm gut auskommst, ist ne lizenz zu empfehlen. 1. es gibt dann noch ein paar mehr funktionen. 2. kommt nach nem monat die anzeige, dass das programm freeware ist, die verschwindet erst nach ner zeit, find ich n bissel nerfig. 3. ist die lizenz lebenslang gültig, kostenpunkt rund 30 €, und du kannst sie auf allen pcs in deinem haushalt einsetzen. 7. autorun deaktivieren: über diesen weg werden sehr häufig schaddateien verbreitet, schalte die funktion also ab. Tipparchiv - Autorun/Autoplay gezielt für Laufwerkstypen oder -buchstaben abschalten - WinTotal.de usb sticks, festplatten etc, sollte man mit panda vaccine impfen: ANTIMALWARE: Panda USB Vaccine - Download FREE - PANDA SECURITY so holt man sich keine infektionen ins haus, wenn man mal die festplatte etc verleit. hake an: hake an: run panda usb vaccine automatically when computer boots automatically vaccine any new insert usb key enable ntfs file suport 8. updates: Updates sind für dein system genauso wichtig, wie ein antivirenscanner. Sehr häufig gelangen schädlinge nur aufs system, weil der user veraltete software nutzt. instaliere die folgenden update checker. Secunia: http://www.trojaner-board.de/83959-s...ector-psi.html und file hippo update checker: FileHippo.com Update Checker - FileHippo.com das file Hippo Symbol wird im infobereich neben der uhr auftauchen, mache bitte nen rechtsklick darauf, wähle settings, results, setze einen haken bei "hide beta updates" klicke ok. dann doppelklicke file hippo, eine Internetseite wird geöffnet, auf der dier die aktuellsten updates gezeigt werden, diese downloaden und instalieren. Beide programme sollten im autostart bleiben, und sobald eines der programme updates anzeigt sollten diese umgehend instaliert werden. 9. regelmäßige Backups des systems sind sehr wichtig, du weist nie, ob deine festplatte mal kaputt geht. Acronis True Image 2011 - Festplatten-Backup-Software, Datei-Backup und Disk Imaging, Wiederherstellung von Anwendungseinstellungen, Backup von Musik, Videos, Fotos und Outlook-Mails außerdem kannst du, bei neuerlichem malware befall das system zurücksetzen. Das Backup sollte möglichst auf eine externe festplatte etc emacht werden, nicht auf die selbe, wo sich die zu sichernden daten befinden. Von sehr wichtigen Daten könnte man noch eine zusätzliche Sicherung auf dvds/cds erstellen, dazu könnte man auch wiederbeschreibbare verwenden (rws) falls die sammlung mal erneuert werden soll. 10. passwörter endern. bitte surfe ab sofort nur noch unter sandboxie, mit klick auf "sandboxed web browser" wenn dir der opera nicht zusagen sollte, gib doch bitte bescheid, damit ich die anleitung für Sandboxie anpassen kann und noch nützliche tools für den ff posten kann. allgemein: - nutze keine toolbars, die verlangsamen den browser, sind nur ein zusatzrisiko, können daten ausspähen. - nutze keine tuning programme, sind nutzlos. - keine illegalen downloads!! keine streaming seiten wie kino.to, die verbreiten malware. |
13.10.2010, 16:32 | #13 |
| 20 Tan Trojaner - Sparkasse Ich habe nun über Office 2010 die pst Dateien gespeichert, er fragte mich aber nach keinem Ort. Nun finde ich die Dateien nicht, hast du eine Ahnung wo er die gespeichert haben könnte. Ich weiß auch nicht wie er sie benannt hat. |
13.10.2010, 16:33 | #14 |
/// Malware-holic | 20 Tan Trojaner - Sparkasse sorry ich nutze leider kein office 2010 machs doch einfach noch mal und schau ob man den ort manuell festlegen kann |
13.10.2010, 16:37 | #15 | |
| 20 Tan Trojaner - SparkasseZitat:
Ja gut ich habe mir jetzt deine Anleitung ausgedruckt und werde versuchen mich da durchzuschlagen. Ich danke dir recht herzlich. Habt ihr ein Spendenkonto oder etwas in der Art? |
Themen zu 20 Tan Trojaner - Sparkasse |
20 tan, 20 tan trojaner, adobe, advanced system protector, antivir, antivir guard, avg, avgntflt.sys, avira, bho, bonjour, browser, components, corp./icp, desktop, document, downloader, enigma, excel, excel.exe, explorer, google, hijack, home premium, iastor.sys, internet, internet explorer, location, musik, nvstor.sys, object, oldtimer, otl.exe, plug-in, programdata, rogue.securitysuite, rundll, searchplugins, service pack 1, software, sptd.sys, spyhunter 4, system, systweak, tan, tan trojaner, trojaner, vista, windows |