|
Plagegeister aller Art und deren Bekämpfung: Google verlinkt auf falsche Seite(trotz formatierung)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.01.2011, 21:16 | #1 |
| Google verlinkt auf falsche Seite(trotz formatierung) Hallo Leute, wenn ich bei google etwas suche, dann werde ich manchmal an ganz andere Seiten verlinkt. Einmal war es eine Erotikseite und mehrere male eine ganz komische Seite (mit irgendwelchen Scripts denke ich). Bei der letzteren Seite öffnet sich dann auch der acrobat reader. Einmal bekam ich ne Fehlermeldung von Antivir aber jetzt kommt auch keine Meldung. Nach der Formatierung klappt alles wunderbar, bis ich die Google suche benutze. Danach hat der Laptop probleme beim Starten(Windows startet normal aber die Hintergrundbeleuchtung bleibt aus oder Windows startet und ich sehe nur die Maus und der Hintergund ist Schwarz, also keine Desktopsymbole und auch keine Leiste unten) Habe Windows Vista und benutze den Internet Explorer Brauche dringend euren Rat. |
03.01.2011, 21:35 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google verlinkt auf falsche Seite(trotz formatierung) Hallo und
__________________Hast du rein zufällig einen Router? Ja? Welches Modell genau, welcher Firmwarestand? Wurde da das Passwort für die browserbasierte Einstellung des Routers geändert?
__________________ |
04.01.2011, 03:44 | #3 |
| Google verlinkt auf falsche Seite(trotz formatierung) Hallo cosinus,
__________________erstmal Danke für die schnelle Antwort. Ja ich benutze einen router, nämlich die easy-box mit der Firmware 20.02.022 (13.02.2010-00:05:02). Auf meinem Pc läuft alles wunderbar nur eben auf dem laptop nicht. Also von dem Passwort für die browserbasierte Einstellung hab ich leider keine Ahnung. |
04.01.2011, 11:51 | #4 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ | Google verlinkt auf falsche Seite(trotz formatierung)Zitat:
Zitat:
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ Logfiles bitte immer in CODE-Tags posten |
04.01.2011, 13:48 | #5 |
| Google verlinkt auf falsche Seite(trotz formatierung) Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 5455 Windows 6.0.6000 Internet Explorer 7.0.6000.16473 04.01.2011 13:03:23 mbam-log-2011-01-04 (13-03-23).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 185007 Laufzeit: 17 Minute(n), 30 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
04.01.2011, 13:49 | #6 |
| Google verlinkt auf falsche Seite(trotz formatierung) OTL Logfile: Code:
ATTFilter OTL logfile created on: 04.01.2011 13:32:01 - Run 1 OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\Mine\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16473) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 61,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 75,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,69 Gb Total Space | 96,95 Gb Free Space | 86,80% Space Free | Partition Type: NTFS Drive D: | 111,43 Gb Total Space | 94,30 Gb Free Space | 84,62% Space Free | Partition Type: NTFS Computer Name: MINE-PC | User Name: Mine | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Mine\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Users\Mine\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.) PRC - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer) PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.) PRC - C:\Programme\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Programme\Internet Explorer\ieuser.exe (Microsoft Corporation) PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Windows\PLFSetL.exe (sonix) PRC - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe () PRC - C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.) PRC - C:\Acer\Empowering Technology\eAudio\eAudio.exe (CyberLink) PRC - C:\Programme\Acer Arcade Deluxe\Play Movie\PMVService.exe (CyberLink Corp.) PRC - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe (HiTRSUT) PRC - C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (HiTRUST) PRC - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.) PRC - C:\Acer\ALaunch\ALaunchSvc.exe () PRC - C:\Acer\Mobility Center\MobilityService.exe () PRC - C:\Windows\explorer.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\Mine\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe File not found SRV - (WMIService) -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (eSettingsService) -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe () SRV - (eNet Service) -- C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.) SRV - (eDataSecurity Service) -- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe (HiTRSUT) SRV - (eLockService) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.) SRV - (ALaunchService) -- C:\Acer\ALaunch\ALaunchSvc.exe () SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe () ========== Driver Services (SafeList) ========== DRV - (UIUSys) -- C:\Windows\System32\DRIVERS\UIUSYS.SYS File not found DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\System32\drivers\snp2uvc.sys () DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.) DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation) DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.) DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.) DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.) DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.) DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.) DRV - (PSDNServ) -- C:\Windows\system32\drivers\PSDNServ.sys (HiTRUST) DRV - (psdvdisk) -- C:\Windows\system32\drivers\psdvdisk.sys (HiTRUST) DRV - (PSDFilter) -- C:\Windows\system32\DRIVERS\psdfilter.sys (HiTRUST) DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC) DRV - (int15) -- C:\Windows\System32\drivers\int15.sys () DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC) DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC) DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) -- C:\Programme\Acer Arcade Deluxe\Play Movie\000.fcl (Cyberlink Corp.) DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.) DRV - (DritekPortIO) -- C:\Programme\Launch Manager\DPortIO.sys (Dritek System Inc.) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.intl.acer.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.intl.acer.yahoo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = hxxp://de.rd.yahoo.com/customize/ycomp/defaults/sp/*hxxp://de.yahoo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.intl.acer.yahoo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\System32\ActiveToolBand.dll (HiTRUST) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar mit Pop-Up-Blocker) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [eAudio] C:\Acer\Empowering Technology\eAudio\eAudio.exe (CyberLink) O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (HiTRUST) O4 - HKLM..\Run: [eRecoveryService] File not found O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe (CyberLink Corp.) O4 - HKLM..\Run: [PLFSetL] C:\Windows\PLFSetL.exe (sonix) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd File not found O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== File not found -- C:\Windows\System32\Acer.exe [2011.01.04 13:30:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mine\Desktop\OTL.exe [2011.01.04 12:37:05 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2011.01.04 11:19:23 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Roaming\Malwarebytes [2011.01.04 11:18:19 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011.01.04 11:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.01.04 11:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.01.04 11:18:15 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.01.04 11:18:15 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2011.01.03 07:59:00 | 000,199,440 | ---- | C] (Dritek System Inc.) -- C:\Windows\UNINST32.EXE [2011.01.03 07:59:00 | 000,021,264 | ---- | C] (Dritek System Inc.) -- C:\Windows\System32\drivers\DKbFltr.sys [2011.01.03 07:58:57 | 006,844,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll [2011.01.03 07:58:57 | 003,620,864 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvvitvsr.dll [2011.01.03 07:58:57 | 003,395,584 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvvitvs.dll [2011.01.03 07:58:57 | 002,379,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwssr.dll [2011.01.03 07:58:57 | 002,113,536 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwss.dll [2011.01.03 07:58:57 | 001,410,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll [2011.01.03 07:58:57 | 000,356,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvuninst.exe [2011.01.03 07:58:57 | 000,356,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvudisp.exe [2011.01.03 07:58:57 | 000,217,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\oemdspif.dll [2011.01.03 07:58:57 | 000,086,016 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll [2011.01.03 07:58:56 | 007,137,984 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys [2011.01.03 07:58:56 | 003,235,840 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgamesr.dll [2011.01.03 07:58:56 | 003,145,728 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgames.dll [2011.01.03 07:58:56 | 002,854,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmoblsr.dll [2011.01.03 07:58:56 | 000,958,464 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmobls.dll [2011.01.03 07:58:56 | 000,458,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmccssr.dll [2011.01.03 07:58:56 | 000,307,200 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvexpbar.dll [2011.01.03 07:58:56 | 000,229,376 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmccs.dll [2011.01.03 07:58:56 | 000,188,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmccss.dll [2011.01.03 07:58:56 | 000,081,920 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll [2011.01.03 07:58:56 | 000,067,584 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhotkey.dll [2011.01.03 07:58:56 | 000,045,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmccsrs.dll [2011.01.03 07:58:55 | 006,074,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdisps.dll [2011.01.03 07:58:55 | 005,427,200 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispsr.dll [2011.01.03 07:58:55 | 004,763,648 | ---- | C] (NVidia Corporation) -- C:\Windows\System32\nvd3dum.dll [2011.01.03 07:58:55 | 001,069,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcpluir.dll [2011.01.03 07:58:55 | 000,815,104 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcplui.exe [2011.01.03 07:58:54 | 008,433,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll [2011.01.03 07:58:54 | 001,062,304 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvmfdx32.sys [2011.01.03 07:58:54 | 000,344,064 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll [2011.01.03 07:58:54 | 000,201,728 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\fdco1.dll [2011.01.03 07:58:54 | 000,143,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcolor.exe [2011.01.03 07:58:54 | 000,073,728 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.cpl [2011.01.03 07:58:54 | 000,037,888 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvconrm.dll [2011.01.03 07:58:54 | 000,037,376 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcod.dll [2011.01.03 07:58:47 | 017,100,352 | ---- | C] (Macrovision Corporation) -- C:\Windows\eRy.exe [2011.01.03 07:58:42 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\devcon.exe [2011.01.02 22:37:02 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Local\PlayMovie [2011.01.02 22:35:30 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Roaming\InstallShield [2011.01.02 22:34:48 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2011.01.02 22:32:05 | 000,368,640 | ---- | C] (Acer Inc.) -- C:\Windows\System32\CheckD2DSystem.exe [2011.01.02 22:32:05 | 000,327,680 | ---- | C] (Acer Inc.) -- C:\Windows\System32\Remove_eRecovery.exe [2011.01.02 22:32:05 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe [2011.01.02 22:31:12 | 000,000,000 | ---D | C] -- C:\Programme\Apoint2K [2011.01.02 22:29:55 | 000,000,000 | ---D | C] -- C:\Programme\SUYIN [2011.01.02 22:29:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crystal Eye webcam [2011.01.02 22:29:55 | 000,000,000 | ---D | C] -- C:\Programme\ACER Crystal Eye webcam [2011.01.02 22:28:40 | 000,286,720 | ---- | C] (Sonix) -- C:\Windows\System32\vsnp2uvc.dll [2011.01.02 22:28:40 | 000,094,208 | ---- | C] (sonix) -- C:\Windows\PLFSetL.exe [2011.01.02 22:28:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\x64 [2011.01.02 22:28:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\x64 [2011.01.02 22:28:40 | 000,000,000 | ---D | C] -- C:\Windows\SUYIN NB Cam [2011.01.02 22:28:39 | 000,172,032 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll [2011.01.02 22:28:39 | 000,094,208 | ---- | C] (sonix) -- C:\Windows\System32\PLFSetL.exe [2011.01.02 22:28:39 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll [2011.01.02 22:28:39 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\snp2uvc [2011.01.02 22:27:24 | 003,217,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSAT.exe [2011.01.02 22:27:24 | 000,386,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSATAPI.dll [2011.01.02 22:22:28 | 000,185,776 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll [2011.01.02 22:22:27 | 004,669,440 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe [2011.01.02 22:22:27 | 002,048,000 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll [2011.01.02 22:22:27 | 001,841,312 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RTKVHDA.sys [2011.01.02 22:22:27 | 001,826,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SkyTel.exe [2011.01.02 22:22:27 | 000,563,712 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll [2011.01.02 22:22:27 | 000,532,480 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl [2011.01.02 22:22:27 | 000,126,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\maxxaudioapo.dll [2011.01.02 22:22:27 | 000,017,408 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInst.dll [2011.01.02 22:21:36 | 000,040,960 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\junction.exe [2011.01.02 22:21:11 | 001,706,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll [2011.01.02 22:20:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Launch Manager [2011.01.02 22:20:05 | 000,000,000 | ---D | C] -- C:\Programme\Launch Manager [2011.01.02 22:19:53 | 000,000,000 | -H-D | C] -- C:\Users\Mine\AppData\Local\acer eNM [2011.01.02 22:19:22 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2011.01.02 22:19:18 | 000,000,000 | R--D | C] -- C:\Users\Mine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011.01.02 22:19:18 | 000,000,000 | R--D | C] -- C:\Users\Mine\Searches [2011.01.02 22:19:18 | 000,000,000 | R--D | C] -- C:\Users\Mine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011.01.02 22:19:10 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Roaming\Identities [2011.01.02 22:19:08 | 000,000,000 | R--D | C] -- C:\Users\Mine\Contacts [2011.01.02 22:19:07 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Local\VirtualStore [2011.01.02 22:18:54 | 056,349,822 | ---- | C] (Macromedia, Inc.) -- C:\Windows\System32\acer.exe [2011.01.02 22:18:53 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Roaming\Macromedia [2011.01.02 22:18:53 | 000,000,000 | ---D | C] -- C:\Programme\Acer Inc [2011.01.02 22:18:52 | 000,000,000 | ---D | C] -- C:\Windows\ACER [2011.01.02 22:18:37 | 000,000,000 | ---D | C] -- C:\Programme\Yahoo! [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Vorlagen [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\AppData\Local\Verlauf [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\AppData\Local\Temporary Internet Files [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Startmenü [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\SendTo [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Recent [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Netzwerkumgebung [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Lokale Einstellungen [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Documents\Eigene Videos [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Documents\Eigene Musik [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Eigene Dateien [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Documents\Eigene Bilder [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Druckumgebung [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Cookies [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\AppData\Local\Anwendungsdaten [2011.01.02 22:18:27 | 000,000,000 | -HSD | C] -- C:\Users\Mine\Anwendungsdaten [2011.01.02 22:18:26 | 000,000,000 | --SD | C] -- C:\Users\Mine\AppData\Roaming\Microsoft [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Videos [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Saved Games [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Pictures [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Music [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Links [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Favorites [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Downloads [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Documents [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\Desktop [2011.01.02 22:18:26 | 000,000,000 | R--D | C] -- C:\Users\Mine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011.01.02 22:18:26 | 000,000,000 | -H-D | C] -- C:\Users\Mine\AppData [2011.01.02 22:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Local\Temp [2011.01.02 22:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Local\Microsoft [2011.01.02 22:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mine\AppData\Roaming\Media Center Programs [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\Programme [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\Programme\Gemeinsame Dateien [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2011.01.02 22:15:25 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2011.01.02 22:05:20 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2007.07.28 18:02:42 | 000,045,056 | ---- | C] ( ) -- C:\Windows\PLFSet.dll [2007.07.28 10:24:55 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll ========== Files - Modified Within 30 Days ========== [2011.01.04 13:30:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mine\Desktop\OTL.exe [2011.01.04 12:49:09 | 000,641,344 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.01.04 12:49:09 | 000,610,142 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.01.04 12:49:09 | 000,116,706 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.01.04 12:49:09 | 000,103,924 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.01.04 12:45:16 | 000,027,240 | ---- | M] () -- C:\Users\Mine\AppData\Roaming\nvModes.001 [2011.01.04 12:44:34 | 000,027,240 | ---- | M] () -- C:\Users\Mine\AppData\Roaming\nvModes.dat [2011.01.04 12:44:21 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.01.04 12:44:21 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.01.04 12:44:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.01.04 12:44:02 | 2146,340,864 | -HS- | M] () -- C:\hiberfil.sys [2011.01.04 12:34:42 | 273,024,774 | ---- | M] () -- C:\Windows\MEMORY.DMP [2011.01.04 11:18:19 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.01.04 11:17:14 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdFs_01_00_00.Wdf [2011.01.03 07:58:47 | 000,000,003 | ---- | M] () -- C:\Windows\AFirst.cmd [2011.01.02 22:53:18 | 000,000,104 | ---- | M] () -- C:\Users\Mine\Desktop\Internet Explorer.lnk [2011.01.02 22:31:56 | 000,000,305 | ---- | M] () -- C:\Windows\Alaunch.ini [2011.01.02 22:31:25 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_Apfiltr_01005.Wdf [2011.01.02 22:29:55 | 000,001,583 | ---- | M] () -- C:\Users\Public\Desktop\Acer Crystal Eye webcam.lnk [2011.01.02 22:27:24 | 003,217,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WinSAT.exe [2011.01.02 22:27:24 | 000,386,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WinSATAPI.dll [2011.01.02 22:24:43 | 000,001,818 | ---- | M] () -- C:\Users\Public\Desktop\Empowering Technology.lnk [2011.01.02 22:22:30 | 000,319,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\DIFxAPI.dll [2011.01.02 22:20:23 | 000,000,000 | ---- | M] () -- C:\Windows\SETUP.INI [2011.01.02 22:20:07 | 000,000,083 | ---- | M] () -- C:\Windows\LManager.UNI [2011.01.02 22:18:36 | 000,001,252 | ---- | M] () -- C:\Windows\CLEANUP.CMD [2010.12.20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.12.20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2011.01.04 11:18:19 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.01.03 19:27:47 | 000,027,240 | ---- | C] () -- C:\Users\Mine\AppData\Roaming\nvModes.001 [2011.01.03 19:27:46 | 000,027,240 | ---- | C] () -- C:\Users\Mine\AppData\Roaming\nvModes.dat [2011.01.03 07:58:55 | 000,006,193 | ---- | C] () -- C:\Windows\System32\nvdisp.nvu [2011.01.03 07:58:54 | 000,111,787 | ---- | C] () -- C:\Windows\System32\nvapps.xml [2011.01.03 07:58:47 | 000,000,003 | ---- | C] () -- C:\Windows\AFirst.cmd [2011.01.03 07:58:42 | 000,001,252 | ---- | C] () -- C:\Windows\CLEANUP.CMD [2011.01.03 07:58:42 | 000,000,397 | ---- | C] () -- C:\Windows\MSSEC_RB.CMD [2011.01.03 07:58:42 | 000,000,387 | ---- | C] () -- C:\Windows\MSSFT_RB.CMD [2011.01.03 07:58:42 | 000,000,336 | ---- | C] () -- C:\Windows\ACERTOURREMINDERRUN.REG [2011.01.03 07:58:42 | 000,000,294 | ---- | C] () -- C:\Windows\offline.reg [2011.01.03 07:58:42 | 000,000,155 | ---- | C] () -- C:\Windows\IR.reg [2011.01.03 07:58:42 | 000,000,092 | ---- | C] () -- C:\Windows\CLEANUP.INI [2011.01.03 07:58:42 | 000,000,030 | ---- | C] () -- C:\Windows\SETPANEL.INI [2011.01.02 22:53:18 | 000,000,104 | ---- | C] () -- C:\Users\Mine\Desktop\Internet Explorer.lnk [2011.01.02 22:34:29 | 273,024,774 | ---- | C] () -- C:\Windows\MEMORY.DMP [2011.01.02 22:32:06 | 000,000,552 | ---- | C] () -- C:\Windows\System32\setup.iss [2011.01.02 22:32:05 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe [2011.01.02 22:31:25 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_Apfiltr_01005.Wdf [2011.01.02 22:29:55 | 000,001,583 | ---- | C] () -- C:\Users\Public\Desktop\Acer Crystal Eye webcam.lnk [2011.01.02 22:28:40 | 001,792,640 | ---- | C] () -- C:\Windows\System32\drivers\x64\snp2uvc.sys [2011.01.02 22:28:40 | 000,035,072 | ---- | C] () -- C:\Windows\System32\drivers\x64\sncduvc.sys [2011.01.02 22:28:39 | 001,749,376 | ---- | C] () -- C:\Windows\System32\snp2uvc.sys [2011.01.02 22:28:39 | 000,028,032 | ---- | C] () -- C:\Windows\System32\sncduvc.sys [2011.01.02 22:28:39 | 000,016,005 | ---- | C] () -- C:\Windows\System32\snp2uvc.cat [2011.01.02 22:28:39 | 000,014,818 | ---- | C] () -- C:\Windows\System32\snp2uvc.inf [2011.01.02 22:28:39 | 000,000,131 | ---- | C] () -- C:\Windows\System32\PidList.ini [2011.01.02 22:28:39 | 000,000,131 | ---- | C] () -- C:\Windows\PidList.ini [2011.01.02 22:20:23 | 000,000,000 | ---- | C] () -- C:\Windows\SETUP.INI [2011.01.02 22:20:07 | 000,000,083 | ---- | C] () -- C:\Windows\LManager.UNI [2011.01.02 22:19:01 | 083,554,304 | ---- | C] () -- C:\Windows\System32\acer.scr [2011.01.02 22:07:16 | 2146,340,864 | -HS- | C] () -- C:\hiberfil.sys [2007.07.28 20:54:24 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll [2007.07.28 18:03:11 | 000,000,305 | ---- | C] () -- C:\Windows\Alaunch.ini [2007.07.28 18:02:42 | 001,749,376 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys [2007.07.28 18:02:42 | 000,028,032 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys [2007.07.28 10:38:36 | 000,076,584 | ---- | C] () -- C:\Windows\System32\drivers\int15.sys [2007.07.28 10:38:36 | 000,015,656 | ---- | C] () -- C:\Windows\System32\drivers\int15_64.sys [2007.07.28 10:37:48 | 000,065,536 | ---- | C] () -- C:\Windows\System32\NATTraversal.dll [2007.07.28 10:24:52 | 000,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll [2007.07.28 09:35:23 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll [2007.07.28 09:32:12 | 000,000,775 | ---- | C] () -- C:\Windows\RtDefLvl.ini [2007.04.25 15:33:22 | 000,266,240 | ---- | C] () -- C:\Windows\System32\NotesExtmngr.dll [2007.04.25 15:32:50 | 000,204,800 | ---- | C] () -- C:\Windows\System32\NotesActnMenu.dll [2007.04.25 15:32:46 | 000,086,016 | ---- | C] () -- C:\Windows\System32\MSNSpook.dll [2007.04.25 15:31:00 | 000,028,672 | ---- | C] () -- C:\Windows\System32\BatchCrypto.dll [2007.04.25 15:30:52 | 000,073,728 | ---- | C] () -- C:\Windows\System32\APISlice.dll [2007.04.25 15:30:44 | 000,063,488 | ---- | C] () -- C:\Windows\System32\ShowErrMsg.dll [2006.12.25 14:44:48 | 000,022,016 | ---- | C] () -- C:\Windows\System32\MailFormat_U.dll [2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2001.12.26 15:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll [2001.09.03 22:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll [2001.07.30 15:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll [2001.07.23 21:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll < End of report > |
04.01.2011, 13:50 | #7 |
| Google verlinkt auf falsche Seite(trotz formatierung) OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 04.01.2011 13:32:01 - Run 1 OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\Mine\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16473) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 61,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 75,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,69 Gb Total Space | 96,95 Gb Free Space | 86,80% Space Free | Partition Type: NTFS Drive D: | 111,43 Gb Total Space | 94,30 Gb Free Space | 84,62% Space Free | Partition Type: NTFS Computer Name: MINE-PC | User Name: Mine | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{443FD6FC-DF16-48F8-87D9-1559431AB8B3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{5DF5BC70-F7DC-425A-ABAE-2FC40B06B02D}" = dir=in | app=c:\program files\acer arcade deluxe\play movie\playmovie.exe | "{9813433C-19D2-4C2B-A1CB-ED550897727A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{ABD333AC-86BE-4ED9-B1F6-886CED34F64E}" = dir=in | app=c:\program files\acer arcade deluxe\dv wizard\dv wizard.exe | "{BA1D7486-D878-43F4-82B8-B80465158EF5}" = dir=in | app=c:\program files\acer arcade deluxe\dvdivine\dvdivine.exe | "{C8EE00CE-7B28-452D-84AC-6CD0ACBF9D18}" = dir=in | app=c:\program files\acer arcade deluxe\videomagician\videomagician.exe | "{D033DA20-65D1-4A19-80D9-462792854C0E}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe | "{DFD9D1FE-158C-4A91-B12B-D2868D03C8B0}" = dir=in | app=c:\program files\acer arcade deluxe\play movie\pmvservice.exe | "{EF6DB405-C6E4-4BCC-9BBC-986FFE4DA449}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In "{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye Webcam Video Class Camera "{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works "{57265292-228A-41FA-9AEC-4620CBCC2739}" = Acer eAudio Management "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{67ADE9AF-5CD9-4089-8825-55DE4B366799}" = NTI Backup NOW! 4.7 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111263673}" = Treasures of the Deep "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111271497}" = Mystery Case Files - Prime Suspects "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111310630}" = Big Kahuna Reef 2 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111473353}" = Dynasty "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11170417}" = Luxor 2 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111730193}" = Star Defender 3 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112179547}" = Mystery Case Files Ravenhearst "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{94389919-B0AA-4882-9BE8-9F0B004ECA35}" = Acer Tour "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver "{AA047D7C-5E7C-4878-B75C-77589151B563}" = Acer Crystal Eye webcam "{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0 "{AEEAE013-92F1-4515-B278-139F1A692A36}" = Acer eDataSecurity Management "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer 3.72 "{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management "{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1 "{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management "{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Deluxe "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker "LManager" = Launch Manager "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "NVIDIA Drivers" = NVIDIA Drivers "ShockwaveFlash" = Adobe Flash Player 9 ActiveX "Yahoo! Companion" = Yahoo! Toolbar mit Pop-Up-Blocker "Yahoo! Toolbar" = Yahoo! Toolbar ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 03.01.2011 14:31:40 | Computer Name = Mine-PC | Source = WerSvc | ID = 5007 Description = Error - 03.01.2011 15:13:49 | Computer Name = Mine-PC | Source = System Restore | ID = 8193 Description = Error - 03.01.2011 15:13:49 | Computer Name = Mine-PC | Source = System Restore | ID = 8210 Description = Error - 03.01.2011 17:00:40 | Computer Name = Mine-PC | Source = Application Hang | ID = 1002 Description = Programm AcerTour.exe, Version 2.0.1003.0 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: a14 Anfangszeit: 01cbab73decdf983 Zeitpunkt der Beendigung: 18 Error - 03.01.2011 17:08:02 | Computer Name = Mine-PC | Source = WerSvc | ID = 5007 Description = Error - 03.01.2011 17:46:04 | Computer Name = Mine-PC | Source = System Restore | ID = 8193 Description = Error - 03.01.2011 17:46:04 | Computer Name = Mine-PC | Source = System Restore | ID = 8210 Description = Error - 04.01.2011 06:16:50 | Computer Name = Mine-PC | Source = WerSvc | ID = 5007 Description = Error - 04.01.2011 07:38:09 | Computer Name = Mine-PC | Source = WerSvc | ID = 5007 Description = Error - 04.01.2011 07:49:09 | Computer Name = Mine-PC | Source = WerSvc | ID = 5007 Description = [ System Events ] Error - 03.01.2011 17:03:08 | Computer Name = Mine-PC | Source = ACPI | ID = 327686 Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz 12, Funktion 0. Wenden Sie sich an den Systemhersteller, um technische Unterstützung zu erhalten. Error - 03.01.2011 17:03:08 | Computer Name = Mine-PC | Source = ACPI | ID = 327686 Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz 13, Funktion 0. Wenden Sie sich an den Systemhersteller, um technische Unterstützung zu erhalten. Error - 03.01.2011 17:03:42 | Computer Name = Mine-PC | Source = Service Control Manager | ID = 7000 Description = Error - 04.01.2011 06:15:22 | Computer Name = Mine-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am 04.01.2011 um 00:50:38 unerwartet heruntergefahren. Error - 04.01.2011 07:27:45 | Computer Name = Mine-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am 04.01.2011 um 12:26:01 unerwartet heruntergefahren. Error - 04.01.2011 07:27:57 | Computer Name = Mine-PC | Source = Service Control Manager | ID = 7000 Description = Error - 04.01.2011 07:34:56 | Computer Name = Mine-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am 04.01.2011 um 12:33:14 unerwartet heruntergefahren. Error - 04.01.2011 07:35:14 | Computer Name = Mine-PC | Source = Service Control Manager | ID = 7000 Description = Error - 04.01.2011 07:42:58 | Computer Name = Mine-PC | Source = Service Control Manager | ID = 7024 Description = Error - 04.01.2011 07:44:26 | Computer Name = Mine-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > |
04.01.2011, 14:16 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google verlinkt auf falsche Seite(trotz formatierung) Gibt es noch weitere Logs von Malwarebytes? Wenn ja bitte alle posten, die in Malwarebytes im Reiter Logdateien sichtbar sind.
__________________ Logfiles bitte immer in CODE-Tags posten |
04.01.2011, 16:08 | #9 |
| Google verlinkt auf falsche Seite(trotz formatierung) Leider gibt es keine anderen Logs. Ich muss noch hinzufügen das ich das Gerät vor dem Scan formatiert hatte, also ich habe die Google Suche noch nicht benutzt. Und zur zeit gibt es auch kein problem, aber ich befürchte das ich den virus bekommen könnte wenn ich auf google etwas suche. Soll ich denn einmal die Suche benutzen und dann nochmal scannen? PS: Windows update geht auch nicht Fehlercode: 80072EFE Tut mir wirklich leid für die Umstände die ich bereite |
04.01.2011, 19:18 | #10 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Google verlinkt auf falsche Seite(trotz formatierung) Wenn du formatiert hast, sind die Schädlinge geschichte. Zitat:
Bzw. Google mal mit entsprechender Fehlermeldung füttern.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Google verlinkt auf falsche Seite(trotz formatierung) |
acrobat, antivir, beim starten, dringend, euren, falsche, falsche seite, fehlermeldung, formatierung, google, internet, keine desktopsymbole, komische, laptop, leute, maus, probleme, probleme beim starten, seite, seiten, starten, startet, suche, trotz, vista, windows, windows vista, öffnet |