|
Log-Analyse und Auswertung: Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern...Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.04.2011, 09:25 | #1 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... ... Daten verloren. Dieser Fehler kann durch einen Ausfall der Hardware verursacht werden. Guetn Morgen zusammen, dieser Fehlermeldung erscheint, wie zig andere noch während des Betriebs meines Laptops. Ich denke ich hab mri wie viele auch den TR/Kazy.mekml.1 eingefangen. Hier mal meine OTL.TXT: OTL logfile created on: 22.04.2011 10:04:16 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Danny\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19048) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,88 Gb Total Space | 62,18 Gb Free Space | 55,57% Space Free | Partition Type: NTFS Drive D: | 111,00 Gb Total Space | 110,91 Gb Free Space | 99,92% Space Free | Partition Type: NTFS Computer Name: DANNY-PC | User Name: Danny | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Danny\Downloads\OTL(2).exe (OldTimer Tools) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\ProgramData\MRtPNAFMRSnT.exe (WinTrust) PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) PRC - C:\Programme\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) PRC - C:\Programme\Logitech\Logitech Vid\Vid.exe (Logitech Inc.) PRC - C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) PRC - C:\Programme\Logitech\Logitech WebCam Software\LWS.exe () PRC - C:\Programme\Common Files\logishrd\LQCVFX\COCIManager.exe () PRC - C:\Programme\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Windows\System32\conime.exe (Microsoft Corporation) PRC - C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics) PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.) PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.) PRC - C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) PRC - C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ========== Modules (SafeList) ========== MOD - C:\Users\Danny\Downloads\OTL(2).exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (LVPrcSrv) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.) SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) SRV - (EvtEng) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) SRV - (RegSrvc) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) SRV - (Samsung Update Plus) -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe () SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\Windows\System32\drivers\LV302V32.SYS (Logitech Inc.) DRV - (LVPr2Mon) -- C:\Windows\System32\drivers\LVPr2Mon.sys () DRV - (DgiVecp) -- C:\Windows\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.) DRV - (SSPORT) -- C:\Windows\System32\drivers\SSPORT.SYS (Samsung Electronics) DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation) DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.) DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems) DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC A3 E3 2E 3D 05 CA 01 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/" FF - prefs.js..extensions.enabledItems: autopager@mozilla.org:0.6.2.4 FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.24 02:15:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.24 02:15:30 | 000,000,000 | ---D | M] [2009.07.06 22:29:21 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Danny\AppData\Roaming\mozilla\Extensions [2011.04.21 23:42:14 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions [2011.04.21 19:27:30 | 000,000,000 | -H-D | M] (Session Manager) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} [2011.04.21 21:30:24 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011.04.21 21:30:24 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2011.04.21 21:30:24 | 000,000,000 | -H-D | M] ("ICQ Toolbar") -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011.04.21 19:27:15 | 000,000,000 | -H-D | M] ("CoolPreviews") -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [2011.04.21 19:27:19 | 000,000,000 | -H-D | M] (DownThemAll!) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} [2010.07.14 11:20:15 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011.04.21 19:27:24 | 000,000,000 | -H-D | M] (FoxTab) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [2011.04.21 19:27:14 | 000,000,000 | -H-D | M] ("AutoPager") -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\autopager@mozilla.org [2011.04.21 21:30:24 | 000,000,000 | -H-D | M] (Move Media Player) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\moveplayer@movenetworks.com [2011.04.21 19:27:31 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Danny\AppData\Roaming\mozilla\Firefox\Profiles\qyb470lw.default\extensions\staged-xpis [2011.04.16 15:59:02 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-1.xml [2010.07.14 11:19:30 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-10.xml [2010.07.22 23:58:58 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-11.xml [2010.07.24 20:38:38 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-12.xml [2010.09.09 09:23:49 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-13.xml [2010.09.17 12:38:53 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-14.xml [2010.10.21 20:01:01 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-15.xml [2010.10.29 18:55:42 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-16.xml [2010.12.12 23:26:51 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-17.xml [2011.03.02 19:27:22 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-18.xml [2011.03.16 10:51:48 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-19.xml [2009.09.11 07:46:28 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-2.xml [2011.03.24 02:15:41 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-20.xml [2011.04.18 01:29:00 | 000,000,950 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-21.xml [2009.10.29 07:44:30 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-3.xml [2009.11.08 10:27:08 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-4.xml [2009.12.17 07:51:59 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-5.xml [2010.01.07 19:01:53 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-6.xml [2010.03.04 18:56:40 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-7.xml [2010.04.02 08:49:49 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-8.xml [2010.06.24 17:58:11 | 000,000,961 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin-9.xml [2010.05.12 17:40:48 | 000,001,042 | -H-- | M] () -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\searchplugins\icqplugin.xml [2011.03.11 20:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2009.07.06 22:30:47 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Programme\Mozilla Firefox\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2009.07.06 22:30:39 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Programme\Mozilla Firefox\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} [2009.07.06 22:30:59 | 000,000,000 | ---D | M] (Session Manager) -- C:\Programme\Mozilla Firefox\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} [2009.07.06 22:31:00 | 000,000,000 | ---D | M] (Site Launcher) -- C:\Programme\Mozilla Firefox\extensions\{20291fcc-1471-46c8-8213-5911f5ce6d67} [2009.07.06 22:31:02 | 000,000,000 | ---D | M] ("Split Browser") -- C:\Programme\Mozilla Firefox\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d} [2009.07.06 22:30:54 | 000,000,000 | ---D | M] (Minimap Addon) -- C:\Programme\Mozilla Firefox\extensions\{398e77b8-2304-11dc-8314-0800200c9a66} [2009.07.19 21:58:25 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2010.05.13 10:20:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.09.07 17:14:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2011.03.11 20:20:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2009.07.06 22:30:41 | 000,000,000 | ---D | M] ("CoolPreviews") -- C:\Programme\Mozilla Firefox\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [2009.07.06 22:30:37 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Programme\Mozilla Firefox\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3} [2009.07.06 22:30:43 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Programme\Mozilla Firefox\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} [2009.07.06 22:30:48 | 000,000,000 | ---D | M] (FoxTab) -- C:\Programme\Mozilla Firefox\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [2009.07.06 22:30:50 | 000,000,000 | ---D | M] (GooglePreview) -- C:\Programme\Mozilla Firefox\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6} [2009.07.06 22:30:35 | 000,000,000 | ---D | M] ("AutoPager") -- C:\Programme\Mozilla Firefox\extensions\autopager@mozilla.org [2009.07.06 22:29:22 | 000,000,000 | ---D | M] ("COMPUTER BILD Fox Config Helper") -- C:\Programme\Mozilla Firefox\extensions\cbsf-config@com.extensions.mattiasschlenker.de [2009.07.06 22:30:56 | 000,000,000 | ---D | M] (Personal Menu) -- C:\Programme\Mozilla Firefox\extensions\CompactMenuCE@Merci.chao [2009.07.06 22:30:51 | 000,000,000 | ---D | M] (Lazarus: Form Recovery) -- C:\Programme\Mozilla Firefox\extensions\lazarus@interclue.com [2009.07.06 22:30:34 | 000,000,000 | ---D | M] ("Metaswitcher") -- C:\Programme\Mozilla Firefox\extensions\metaswitcher@com.extensions.mattiasschlenker.de [2009.07.06 22:30:57 | 000,000,000 | ---D | M] (printpdf) -- C:\Programme\Mozilla Firefox\extensions\printpdf@pavlov.net [2009.07.06 22:29:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\cbsf-config@com.extensions.mattiasschlenker.de\chrome [2009.07.06 22:29:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\cbsf-config@com.extensions.mattiasschlenker.de\defaults [2009.07.06 22:30:33 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\metaswitcher@com.extensions.mattiasschlenker.de\chrome [2009.07.06 22:30:33 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\metaswitcher@com.extensions.mattiasschlenker.de\defaults [2009.07.06 22:30:22 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [2009.09.27 20:23:29 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [2009.12.09 08:39:09 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2010.03.30 18:40:05 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [2010.05.13 10:20:10 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.09.07 17:14:15 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2011.03.11 20:20:35 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll [2010.07.14 11:18:50 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.07.14 11:18:50 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2010.07.14 11:18:50 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.07.14 11:18:50 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.07.14 11:18:50 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [ICQ] File not found O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Logitech Vid\vid.exe (Logitech Inc.) O4 - HKCU..\Run: [MRtPNAFMRSnT] C:\ProgramData\MRtPNAFMRSnT.exe (WinTrust) O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} hxxp://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab (PhotoPickConvert Class) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img34.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img34.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.04.22 09:36:26 | 000,201,288 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys [2011.04.22 09:36:26 | 000,125,728 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\Mpfp.sys [2011.04.22 09:36:26 | 000,079,304 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys [2011.04.22 09:36:26 | 000,040,488 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfesmfk.sys [2011.04.22 09:36:26 | 000,035,240 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys [2011.04.22 09:36:26 | 000,033,800 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdk.sys [2011.04.22 09:36:25 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vsp1cln.exe [2011.04.22 09:36:24 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmProv.dll [2011.04.22 09:36:24 | 000,001,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmCl.dll [2011.04.22 09:36:20 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll [2011.04.21 19:39:25 | 000,000,000 | -H-D | C] -- C:\Users\Danny\AppData\Roaming\Avira [2011.04.21 18:51:27 | 000,000,000 | -H-D | C] -- C:\Users\Danny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery [2011.04.21 08:27:06 | 000,569,344 | -H-- | C] (WinTrust) -- C:\ProgramData\MRtPNAFMRSnT.exe [2011.04.17 23:27:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.4 [2011.04.17 23:26:33 | 000,000,000 | -H-D | C] -- C:\Programme\ICQ7.4 [2011.04.13 08:21:04 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2011.04.13 08:21:03 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll [2011.04.13 08:20:58 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011.04.13 08:20:58 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2011.04.13 08:20:58 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.04.13 08:20:58 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.04.13 08:20:57 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.04.13 08:20:56 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011.04.13 08:20:56 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.04.13 08:20:56 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.04.13 08:20:56 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011.04.13 08:20:56 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.04.13 08:20:56 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.04.13 08:20:56 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.04.13 08:20:56 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.04.13 08:20:56 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.04.13 08:20:56 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.04.13 08:20:56 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011.04.13 08:20:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.04.13 08:20:53 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll [2011.04.13 08:20:53 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll [2011.04.13 08:20:50 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe [2011.04.13 08:20:49 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.04.13 08:20:46 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2011.04.13 08:20:46 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2011.03.23 20:16:27 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2011.03.23 20:16:27 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2010.08.25 19:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll ========== Files - Modified Within 30 Days ========== [2011.04.22 09:54:22 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.04.22 09:54:22 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.04.22 09:54:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.04.22 09:54:12 | 3179,921,408 | -HS- | M] () -- C:\hiberfil.sys [2011.04.22 09:52:13 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2011.04.22 09:16:57 | 000,370,752 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.04.21 21:22:07 | 000,685,712 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.04.21 21:22:07 | 000,642,704 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.04.21 21:22:07 | 000,149,980 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.04.21 21:22:07 | 000,121,592 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.04.21 19:40:40 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011.04.21 18:51:29 | 000,000,583 | -H-- | M] () -- C:\Users\Danny\Desktop\Windows Recovery.lnk [2011.04.21 18:51:29 | 000,000,104 | -H-- | M] () -- C:\ProgramData\~33414920 [2011.04.21 18:51:28 | 000,000,120 | -H-- | M] () -- C:\ProgramData\~33414920r [2011.04.21 18:51:06 | 000,000,336 | -H-- | M] () -- C:\ProgramData\33414920 [2011.04.21 08:27:06 | 000,569,344 | -H-- | M] (WinTrust) -- C:\ProgramData\MRtPNAFMRSnT.exe [2011.04.18 02:16:13 | 000,000,680 | -H-- | M] () -- C:\Users\Danny\AppData\Local\d3d9caps.dat [2011.04.17 23:27:16 | 000,001,609 | ---- | M] () -- C:\Users\Public\Desktop\ICQ7.4.lnk ========== Files Created - No Company Name ========== [2011.04.21 18:51:29 | 000,000,583 | -H-- | C] () -- C:\Users\Danny\Desktop\Windows Recovery.lnk [2011.04.21 18:51:28 | 000,000,120 | -H-- | C] () -- C:\ProgramData\~33414920r [2011.04.21 18:51:28 | 000,000,104 | -H-- | C] () -- C:\ProgramData\~33414920 [2011.04.21 18:51:06 | 000,000,336 | -H-- | C] () -- C:\ProgramData\33414920 [2011.04.17 23:27:16 | 000,001,609 | ---- | C] () -- C:\Users\Public\Desktop\ICQ7.4.lnk [2011.01.22 13:46:50 | 000,028,160 | ---- | C] () -- C:\Windows\System32\odbccr33.dll [2010.08.25 20:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin [2010.08.25 20:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin [2010.08.25 20:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin [2010.08.25 19:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2010.08.25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2010.08.25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll [2009.12.04 23:27:22 | 000,022,723 | ---- | C] () -- C:\Windows\System32\SSGR3l3.dll [2009.08.18 20:10:40 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.08.18 20:10:40 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009.07.13 22:27:14 | 000,022,016 | -H-- | C] () -- C:\Users\Danny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.07.06 20:34:06 | 000,000,680 | -H-- | C] () -- C:\Users\Danny\AppData\Local\d3d9caps.dat [2009.05.08 10:13:04 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll [2009.04.30 22:39:36 | 000,082,289 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [2009.04.30 16:00:12 | 000,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys [2008.12.12 03:40:56 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v5016.dll [2008.10.10 04:51:01 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2008.10.09 13:48:44 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2008.10.09 13:18:24 | 000,307,200 | ---- | C] () -- C:\Windows\SetDisplayResolution.exe [2008.10.09 13:17:30 | 000,000,135 | R--- | C] () -- C:\Windows\System32\lngEng.ini [2008.10.09 13:17:30 | 000,000,117 | ---- | C] () -- C:\Windows\System32\lngKor.ini [2008.10.09 13:01:16 | 000,040,960 | ---- | C] () -- C:\Windows\System32\IhDEV.exe [2008.10.09 13:01:16 | 000,024,576 | ---- | C] () -- C:\Windows\System32\IhINF.exe [2008.10.09 13:01:00 | 000,002,134 | ---- | C] () -- C:\Windows\HotFixList.ini [2008.10.09 11:05:55 | 000,685,712 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.10.09 11:05:55 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.10.09 11:05:55 | 000,149,980 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.10.09 11:05:55 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2008.10.09 10:55:55 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2008.02.09 18:03:07 | 000,024,576 | ---- | C] () -- C:\Windows\System32\drivers\Marker.exe [2007.02.26 09:49:12 | 006,139,774 | ---- | C] () -- C:\Windows\imagine digital freedom.dat [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 14:47:37 | 000,370,752 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:33:01 | 000,642,704 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 12:33:01 | 000,121,592 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2001.11.14 05:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll ========== LOP Check ========== [2011.04.21 21:30:23 | 000,000,000 | -H-D | M] -- C:\Users\Danny\AppData\Roaming\Facebook [2011.04.17 23:30:02 | 000,000,000 | -H-D | M] -- C:\Users\Danny\AppData\Roaming\ICQ [2011.04.22 09:52:17 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > und die Extras.Txt: OTL Extras logfile created on: 22.04.2011 10:04:16 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Danny\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19048) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,88 Gb Total Space | 62,18 Gb Free Space | 55,57% Space Free | Partition Type: NTFS Drive D: | 111,00 Gb Total Space | 110,91 Gb Free Space | 99,92% Space Free | Partition Type: NTFS Computer Name: DANNY-PC | User Name: Danny | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0A23C05F-1595-4FF7-9BEA-42F5C4D72C32}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{1B2497C2-9244-4CE8-A7C7-51FE7E92B2A5}" = rport=139 | protocol=6 | dir=out | app=system | "{4A2B3146-08CE-40B8-BDF4-85836A8148BB}" = rport=445 | protocol=6 | dir=out | app=system | "{50C73B9D-C87F-49A7-8C66-51513B24B85A}" = rport=138 | protocol=17 | dir=out | app=system | "{5E182C44-84CC-4D3C-BF28-EE7C73C7B247}" = lport=139 | protocol=6 | dir=in | app=system | "{663AC32B-516A-418A-B91D-030082CDB9ED}" = rport=137 | protocol=17 | dir=out | app=system | "{68121BFD-7B52-43F1-B027-08CB466590EA}" = lport=138 | protocol=17 | dir=in | app=system | "{7602E6F3-3FA1-4A49-95F0-B7356C6FE12A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{77F9C8D6-8731-4178-9F50-1D16ABF5BAA1}" = lport=445 | protocol=6 | dir=in | app=system | "{9579937C-32C8-4487-A866-FFFE49DB6BBE}" = lport=2869 | protocol=6 | dir=in | app=system | "{AB8A0AF9-A2F0-45A1-918D-876154EE2847}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{F09ACBD6-A8A7-4FE8-881F-F24D647B4812}" = lport=137 | protocol=17 | dir=in | app=system | "{F760D1E4-0B50-4E51-B7A6-EB686E3976EF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0EE7E187-9703-4952-8EF0-0BC0B02162A5}" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe | "{2AC2C132-9B9F-4942-9D09-E4B4256681EB}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{39C3A882-2EDD-4D76-9299-C7CAA9486F02}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{3E740CEA-7484-441D-A42B-E8D40E8BF3DA}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{42E683B6-A520-4892-8BD2-702A0EB06066}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{45EBA1B9-2477-4D2F-890C-A8CA5FA35B89}" = protocol=17 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe | "{50588E77-DD6D-450A-9875-8C9EB901007B}" = dir=in | app=c:\program files\itunes\itunes.exe | "{528D7B23-F431-41F6-A248-0FB428419777}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{53FD283E-421D-453D-9F54-18E0ECDAED04}" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe | "{5D666D41-F1BF-4EAB-8D3B-D2CDAE94E02C}" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe | "{5FE3AD94-BD6D-4842-BE16-36EFA16D4037}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{632A9688-1050-41AB-900A-64945B8C4B7B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{7B942282-C231-4B4E-B8FC-FF173651B04E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{A5A85013-690F-492F-ACFC-1B3BEEB47671}" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe | "{ACB7ADF4-05B7-437C-B0E5-891CB854BF5D}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{B090C11E-09C2-45C4-B55A-7326D3D3C9C2}" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe | "{B48A66D2-FC0B-4F1B-A130-227C8B9BD017}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{BA7A9EDA-9D0E-4FFC-A9E8-2FE4DA8AFBA5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C7319186-B876-4048-84F6-2E2A55E6FC31}" = protocol=6 | dir=in | app=d:\world of warcraft\wow-3.2.0-dede-downloader.exe | "{D7C5A336-3B19-40ED-80F3-83E32BFBDE19}" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe | "{D8AFF2AA-96D0-4EB3-8837-B6198175FC13}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{DA7DD00D-18C6-4240-807B-D844DB8BA9C1}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe | "{DF531C25-0293-4150-A2F4-22972CD45FA3}" = protocol=17 | dir=in | app=d:\world of warcraft\wow-3.2.0-dede-downloader.exe | "{F2275757-FA18-4CE6-93C5-CFE1A04B7064}" = protocol=6 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe | "TCP Query User{28C134BF-529B-49B9-BF50-59BFB30D5722}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{3A2B7533-1ADA-44C6-9972-6CC0C8ABAA83}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{7E7FA24D-6B45-497D-943B-1FEAA00041B5}D:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.exe | "TCP Query User{94CEBB50-1937-424A-A345-AC4F7D68233D}C:\users\danny\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\danny\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe | "TCP Query User{D020D3FF-C1FF-4BE2-8055-FBF419D82AAF}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{F5DAC3B9-54EC-42E3-903C-9412FC390894}C:\program files\logitech\logitech vid\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe | "UDP Query User{150B4DCA-6E6E-44C9-9D7C-F189D408883C}D:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.exe | "UDP Query User{3CBA7CD2-6474-4428-B142-B4BC867B5BAC}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{603E37DF-F479-4CF9-BB4B-EF39026F569D}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{823A2E07-CEBA-4805-92F1-1925FF5A59C8}C:\program files\logitech\logitech vid\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe | "UDP Query User{C2EEA8E8-AECD-4E9D-AF5F-57E56DAFC4DA}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{E65AD741-5D71-4312-A809-653C5875B5D7}C:\users\danny\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\danny\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1 "{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.6300 "{04830D0F-F980-4EC0-89F1-594F2FD2A1B5}" = ElsterFormular 2008/2009 "{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) "{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID-Anmelde-Assistent "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution III "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 24 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor "{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4cb9f93c-9edc-4be9-ae61-af128ddbecfa}" = Business Contact Manager für Outlook 2007 SP2 "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid "{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager "{70AA9B4F-64F7-4B0D-ADD8-05802D61AF72}" = Windows Live Toolbar "{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera "{71A51B59-E7D3-11DB-A386-005056C00008}" = Namuga 1.3M Webcam "{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}" = ICQ7.4 "{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8E106A57-A17E-431D-B48F-175E42EB9F74}" = imagine digital freedom - Samsung "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007 "{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95120000-0122-0407-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes "{AC76BA86-7AD7-1031-7B44-A81200000003}" = Adobe Reader 8.1.2 - Deutsch "{AC96671C-2001-432C-9826-5266D84EF1DC}" = Logitech Webcam Software "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{AED53CDF-1046-4C6B-B5E2-C195125ECDA0}" = Intel(R) PROSet/Wireless WiFi-Software "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F46E21DF-5BE1-48E2-8390-5EEA8B25E36A}" = Microsoft SQL Server Native Client "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{FDE96E86-7780-431C-92F7-679C6A7CEC51}" = Microsoft SQL Server VSS Writer "{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Agere Systems Soft Modem" = Agere Systems HDA Modem "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Business Contact Manager" = Business Contact Manager für Outlook 2007 SP2 "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "HDMI" = Intel(R) Graphics Media Accelerator Driver "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ICQToolbar" = ICQ Toolbar "InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16) "NVIDIA Drivers" = NVIDIA Drivers "Picasa 3" = Picasa 3 "PROHYBRIDR" = 2007 Microsoft Office system "ProInst" = Intel PROSet Wireless "Samsung SCX-4100 Series" = Samsung SCX-4100 Series "SynTPDeinstKey" = Synaptics Pointing Device Driver "Tony Hawk's Pro Skater 2 Demo" = Tony Hawk's Pro Skater 2 Demo "WinLiveSuite_Wave3" = Windows Live Essentials ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Facebook Plug-In" = Facebook Plug-In "Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 15.12.2010 22:00:54 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1845118 Error - 15.12.2010 22:00:54 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1845118 Error - 15.12.2010 22:00:55 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 15.12.2010 22:00:55 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1846132 Error - 15.12.2010 22:00:55 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1846132 Error - 15.12.2010 22:00:56 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 15.12.2010 22:00:56 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1847146 Error - 15.12.2010 22:00:56 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1847146 Error - 15.12.2010 22:00:57 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 15.12.2010 22:00:57 | Computer Name = Danny-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1848160 [ System Events ] Error - 22.04.2011 03:18:31 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7001 Description = Error - 22.04.2011 03:18:31 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7000 Description = Error - 22.04.2011 03:18:31 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7000 Description = Error - 22.04.2011 03:22:48 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7022 Description = Error - 22.04.2011 03:28:04 | Computer Name = Danny-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 22.04.2011 03:56:02 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7001 Description = Error - 22.04.2011 03:56:02 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7000 Description = Error - 22.04.2011 03:56:02 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7000 Description = Error - 22.04.2011 04:00:03 | Computer Name = Danny-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 22.04.2011 04:00:36 | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7022 Description = < End of report > Da ich nichts damit anfangen kann, meine ganzen Dateien auf dem Lapi verschwunden sind bitte ich um HIIILLFFFEEE Vielen Dank schonmal und lG Danny |
22.04.2011, 09:36 | #2 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... • Starte bitte die OTL.exe
__________________• Kopiere nun das Folgende in die Textbox. :OTL PRC - C:\ProgramData\MRtPNAFMRSnT.exe (WinTrust) O4 - HKCU..\Run: [MRtPNAFMRSnT] C:\ProgramData\MRtPNAFMRSnT.exe (WinTrust) :Files C:\ProgramData\MRtPNAFMRSnT.exe C:\Users\Danny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery C:\Users\Danny\Desktop\Windows Recovery.lnk C:\ProgramData\~33414920 C:\ProgramData\~33414920r C:\ProgramData\33414920 :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. öffne computer, öffne C: dann _OTL dort rechtsklick auf moved files wähle zu moved files.rar oder zip hinzufügen. das archiv nach anleitung hochladen: http://www.trojaner-board.de/54791-a...ner-board.html
__________________ |
22.04.2011, 09:45 | #3 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Hier noch der mbam-log von alwarebytes:
__________________Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6417 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19048 22.04.2011 10:43:42 mbam-log-2011-04-22 (10-43-42).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 154473 Laufzeit: 3 Minute(n), 46 Sekunde(n) Infizierte Speicherprozesse: 1 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 2 Infizierte Speicherprozesse: c:\programdata\mrtpnafmrsnt.exe (Trojan.FakeAlert) -> 2808 -> Unloaded process successfully. Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MRtPNAFMRSnT (Trojan.FakeAlert) -> Value: MRtPNAFMRSnT -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\programdata\mrtpnafmrsnt.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Danny\AppData\Local\Temp\tmpF0AE.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. |
22.04.2011, 09:46 | #4 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... bitte führe nur die von mir genannten schritte aus, danke.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
22.04.2011, 10:15 | #5 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Entschuldige hab das paralell gemacht. Das hier ist nun nach dem Neustart erschienen: All processes killed ========== OTL ========== No active process named MRtPNAFMRSnT.exe was found! Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MRtPNAFMRSnT not found. File C:\ProgramData\MRtPNAFMRSnT.exe not found. ========== FILES ========== File\Folder C:\ProgramData\MRtPNAFMRSnT.exe not found. File\Folder C:\Users\Danny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery not found. File\Folder C:\Users\Danny\Desktop\Windows Recovery.lnk not found. File\Folder C:\ProgramData\~33414920 not found. File\Folder C:\ProgramData\~33414920r not found. File\Folder C:\ProgramData\33414920 not found. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Danny ->Flash cache emptied: 456 bytes User: Default User: Default User User: Public Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Danny ->Temp folder emptied: 37467 bytes ->Temporary Internet Files folder emptied: 85570237 bytes ->Java cache emptied: 50858503 bytes ->FireFox cache emptied: 128267636 bytes ->Flash cache emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 31453382 bytes RecycleBin emptied: 13057031 bytes Total Files Cleaned = 295,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04222011_111046 Files\Folders moved on Reboot... File\Folder C:\Windows\temp\logishrd\LVPrcInj03.dll not found! Registry entries deleted on Reboot... |
22.04.2011, 10:19 | #6 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... 1. unhide: http://filepony.de/download-unhide/ doppelklicken dateien werden sichtbar. 2. malwarebytes updaten, vollständiger scan, log posten
__________________ --> Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... |
22.04.2011, 10:42 | #7 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes Datenbank Version: 6418 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19048 22.04.2011 11:30:37 mbam-log-2011-04-22 (11-30-37).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 153438 Laufzeit: 3 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
22.04.2011, 11:45 | #8 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... bitte erstelle und poste ein combofix log. Ein Leitfaden und Tutorium zur Nutzung von ComboFix
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
22.04.2011, 13:05 | #9 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Combofix Logfile: Code:
ATTFilter ComboFix 11-04-21.04 - Danny 22.04.2011 13:28:16.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3032.2140 [GMT 2:00] ausgeführt von:: c:\users\Danny\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . Infizierte Kopie von c:\windows\system32\drivers\volsnap.sys wurde gefunden und desinfiziert Kopie von - Kitty had a snack :p wurde wiederhergestellt . ((((((((((((((((((((((( Dateien erstellt von 2011-03-22 bis 2011-04-22 )))))))))))))))))))))))))))))) . . 2011-04-22 11:35 . 2011-04-22 11:35 -------- d-----w- c:\users\Danny\AppData\Local\temp 2011-04-22 11:35 . 2011-04-22 11:35 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-04-22 08:55 . 2011-04-22 08:55 -------- d-----w- C:\_OTL 2011-04-22 08:28 . 2011-04-22 08:28 -------- d-----w- c:\users\Danny\AppData\Roaming\Malwarebytes 2011-04-22 08:28 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-22 08:28 . 2011-04-22 08:28 -------- d-----w- c:\programdata\Malwarebytes 2011-04-22 08:28 . 2011-04-22 08:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-04-22 07:37 . 2011-04-22 07:37 -------- d-----w- c:\windows\system32\wbem\en-US 2011-04-22 07:36 . 2007-07-24 03:02 33800 ----a-w- c:\windows\system32\drivers\mferkdk.sys 2011-04-22 07:36 . 2007-07-23 22:40 79304 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2011-04-22 07:36 . 2007-07-21 00:08 40488 ----a-w- c:\windows\system32\drivers\mfesmfk.sys 2011-04-22 07:36 . 2007-07-21 00:08 35240 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2011-04-22 07:36 . 2007-07-21 00:08 201288 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2011-04-22 07:36 . 2007-07-13 00:21 125728 ----a-w- c:\windows\system32\drivers\Mpfp.sys 2011-04-22 07:36 . 2008-01-21 02:23 599552 ----a-w- c:\windows\system32\vsp1cln.exe 2011-04-22 07:36 . 2008-01-21 02:24 54784 ----a-w- c:\windows\system32\WsmProv.dll 2011-04-22 07:36 . 2008-01-21 02:24 1536 ----a-w- c:\windows\system32\WsmCl.dll 2011-04-22 07:36 . 2008-01-21 02:24 78336 ----a-w- c:\windows\system32\ieencode.dll 2011-04-21 17:39 . 2011-04-21 17:39 -------- d-----w- c:\users\Danny\AppData\Roaming\Avira 2011-04-19 18:07 . 2011-04-11 07:04 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{054E6E04-041B-4318-927D-3F3E8FF2FFF5}\mpengine.dll 2011-04-17 21:26 . 2011-04-21 19:30 -------- d-----w- c:\program files\ICQ7.4 2011-04-13 06:21 . 2011-02-16 14:02 292864 ----a-w- c:\windows\system32\atmfd.dll 2011-04-13 06:21 . 2011-02-16 16:16 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-03-23 18:16 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-23 18:16 . 2011-02-22 13:33 1068544 ----a-w- c:\windows\system32\DWrite.dll 2011-03-23 18:16 . 2011-02-22 13:33 797696 ----a-w- c:\windows\system32\FntCache.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-21 17:40 . 2009-07-17 21:39 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-02-02 20:40 . 2010-05-13 08:20 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-02-02 16:11 . 2009-10-03 07:45 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-01-22 11:46 . 2011-01-22 11:46 28160 ----a-w- c:\windows\system32\odbccr33.dll 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-17 2289664] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] "Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-06-02 5451536] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-26 13548064] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-26 92704] "RtHDVCpl"="RtHDVCpl.exe" [2008-04-17 6111232] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256] "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 ADDMEM;ADDMEM;c:\users\ADMINI~1\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [x] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-08-05 44576] R3 VMC302;Vimicro Camera Service VMC302;c:\windows\system32\Drivers\VMC302.sys [x] R3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [x] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-01-10 135336] S2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\system32\DRIVERS\kmdfmemio.sys [2007-05-23 13312] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-03-02 5120] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-03-17 08:56 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://start.icq.com/ uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe FF - ProfilePath - c:\users\Danny\AppData\Roaming\Mozilla\Firefox\Profiles\qyb470lw.default\ FF - prefs.js: browser.search.selectedEngine - ICQ Search FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/ FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: AutoPager: autopager@mozilla.org - c:\program files\Mozilla Firefox\extensions\autopager@mozilla.org FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: AutoPager: autopager@mozilla.org - %profile%\extensions\autopager@mozilla.org FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com FF - user.js: yahoo.homepage.dontask - true . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-ICQ - c:\progra~1\ICQ6.5\ICQ.exe AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Danny\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2011-04-22 13:35 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . Zeit der Fertigstellung: 2011-04-22 13:37:28 ComboFix-quarantined-files.txt 2011-04-22 11:37 . Vor Suchlauf: 12 Verzeichnis(se), 68.607.004.672 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 69.058.715.648 Bytes frei . - - End Of File - - 69CBE5D7B07EF44EF5291235EB4954E7 |
22.04.2011, 13:23 | #10 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... machst du onlinebanking /einkäufe oder sonst was wichtiges mit diesem pc?
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
22.04.2011, 16:14 | #11 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Nein, nur ein bißle surfen, mehr nicht. |
22.04.2011, 16:23 | #12 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... wie läuft das system jetzt? lade den CCleaner slim: Piriform - Builds falls der CCleaner bereits instaliert, überspringen. instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
22.04.2011, 17:16 | #13 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Bin echt unsicher mit der Liste, vor allem das was sich wichtig anhört, ich aber nicht kenne :-) Lapi läuft übrigens prima!! 2007 Microsoft Office system Microsoft Corporation 12.07.2009 514MB 12.0.6425.1000 Activation Assistant for the 2007 Microsoft Office suites Microsoft Corporation 30.06.2009 13,5MB Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 05.07.2009 10.0.22.87 notwendig Adobe Flash Player 10 Plugin Adobe Systems Incorporated 19.03.2011 10.2.152.32 notwendig Adobe Reader 8.1.2 - Deutsch Adobe Systems Incorporated 08.10.2008 99,6MB 8.1.2 notwendig Agere Systems HDA Modem Agere Systems 08.10.2008 unbekant Apple Application Support Apple Inc. 01.02.2011 52,7MB 1.4.1 unbekannt Apple Mobile Device Support Apple Inc. 01.02.2011 21,7MB 3.3.1.3 unbekannt Apple Software Update Apple Inc. 07.09.2009 2,16MB 2.1.1.116 unbekannt Atheros WLAN Client 30.06.2009 1,02MB 1.00.000 notwendig(?) Avira AntiVir Personal - Free Antivirus Avira GmbH 20.04.2011 71,5MB 10.0.0.635 notwendig Bonjour Apple Inc. 18.10.2010 0,76MB 2.0.3.0 unbekannt Business Contact Manager für Outlook 2007 SP2 Microsoft Corporation 05.07.2009 31,4MB 3.0.8619.1 unnötig CCleaner Piriform 21.04.2011 3,60MB 3.05 notwendig CyberLink DVD Suite CyberLink Corp. 30.06.2009 9,64MB 5.0.2403 unbekannt CyberLink Power2Go CyberLink Corp. 30.06.2009 52,4MB 5.0.3825 unbekannt DivX Codec DivX, Inc. 03.08.2009 1,31MB 6.8.5 notwendig DivX Converter DivX, Inc. 03.08.2009 45,3MB 7.1.0 notwendig DivX Player DivX, Inc. 03.08.2009 8,43MB 7.2.0 notwendig DivX Plus DirectShow Filters DivX, Inc. 03.08.2009 1,58MB notwendig DivX Web Player DivX,Inc. 03.08.2009 3,45MB 1.5.0 notwendig Easy Battery Manager Samsung 30.06.2009 7,89MB 3.2.1.7 unbekannt Easy Display Manager Samsung 08.10.2008 11,4MB 2.0.0.0 unbekannt Easy Network Manager 3.0 Ihr Firmenname 08.10.2008 36,9MB 3.0.0.0 unbekannt Easy SpeedUp Manager 30.06.2009 3,69MB 2.0.1.3 unbekannt ElsterFormular 2008/2009 Steuerverwaltung des Bundes und der Länder 23.01.2010 154,4MB 10.3.2.0 unnötig Facebook Plug-In Facebook, Inc. 12.06.2010 5,46MB unbekannt ICQ Toolbar ICQ 18.07.2009 3.0.0 unnötig ICQ7.4 ICQ 16.04.2011 47,2MB 7.4 notwendig imagine digital freedom - Samsung Samsung Electronics Co. Ltd., 08.10.2008 7,50MB 1.0.2.2 unbekannt Intel(R) Graphics Media Accelerator Driver Intel Corporation 30.06.2009 unbekannt Intel(R) PROSet/Wireless WiFi-Software Intel(R) Corporation 08.10.2008 78,3MB 12.00.4000 unbekannt Intel® Matrix Storage Manager Intel Corporation 30.06.2009 0,79MB unbekannt iTunes Apple Inc. 01.02.2011 144,7MB 10.1.2.17 unbekannt Java(TM) 6 Update 24 Sun Microsystems, Inc. 05.07.2009 97,5MB 6.0.240 notwendig LabelPrint CyberLink Corp. 30.06.2009 106,4MB .2406 unbekannt LightScribe System Software 1.12.37.1 LightScribe 08.10.2008 20,9MB 1.12.37.1 unbekannt Logitech Vid Logitech Inc. 07.07.2009 38,4MB 1.01.1015 notwendig Logitech Webcam Software Logitech Inc. 07.07.2009 44,3MB 12.00.1280 notwendig Malwarebytes' Anti-Malware Malwarebytes Corporation 21.04.2011 4,80MB notwendig Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft Corporation 12.07.2009 37,0MB notwendig Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 05.07.2009 37,0MB notwendig Microsoft .NET Framework 4 Client Profile Microsoft Corporation 23.06.2010 120,3MB 4.0.30319 notwendig Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 23.06.2010 24,5MB 4.0.30319 notwendig Microsoft Office 2003 Web Components Microsoft Corporation 15.09.2010 11.0.8003.0 notwendig Microsoft Office 2007 Primary Interop Assemblies Microsoft Corporation 13.04.2011 12.0.4518.1014 notwendig Microsoft Office Home and Student 2007 Microsoft Corporation 21.08.2009 566MB 12.0.6425.1000 notwendig Microsoft Office Live Add-in 1.5 Microsoft Corporation 23.06.2010 0,49MB 2.0.4024.1 notwendig Microsoft Office Outlook Connector Microsoft Corporation 02.10.2009 6,13MB 12.0.6423.1000 notwendig Microsoft Office Small Business Connectivity Components Microsoft Corporation 08.10.2008 0,15MB 2.0.7024.0 notwendig Microsoft Silverlight Microsoft Corporation 20.04.2011 4.0.60310.0 notwendig Microsoft SQL Server 2005 Microsoft Corporation 08.10.2008 54,1MB notwendig Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 05.07.2009 1,74MB 3.1.0000 notwendig Microsoft SQL Server Native Client Microsoft Corporation 14.03.2011 2,63MB 9.00.5000.00 notwendig Microsoft SQL Server VSS Writer Microsoft Corporation 14.03.2011 0,68MB 9.00.5000.00 notwendig Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Corporation 01.02.2011 0,61MB 1.0.1215.0 notwendig Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Corporation 01.02.2011 1,45MB 1.0.1215.0 notwendig Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Corporation 29.07.2009 0,19MB 9.0.30729.4148 notwendig Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Corporation 13.04.2011 0,58MB 9.0.30729.5570 notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 16.07.2009 0,58MB 9.0.30729 notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 23.03.2010 0,58MB 9.0.30729.4148 notwendig Mozilla Firefox (3.6.16) Mozilla 23.03.2011 42,1MB 3.6.16 (de) notwendig Namuga 1.3M Webcam Vimicro Corporation 08.10.2008 1,86MB 1.00.0000 unbekannt NVIDIA Drivers 30.06.2009 notwendig Picasa 3 Google, Inc. 16.12.2010 65,6MB 3.8 notwendig PowerDirector CyberLink Corp. 30.06.2009 129,4MB 5.0.3927 unbekannt PowerDVD CyberLink Corp. 30.06.2009 114,4MB 7.0.3118.0 notwendig PowerProducer CyberLink Corp. 30.06.2009 298MB 085120(3.7)_Vista_SSPC unbekannt QuickTime Apple Inc. 01.02.2011 73,7MB 7.69.80.9 notwendig Realtek High Definition Audio Driver Realtek Semiconductor Corp. 08.10.2008 11,4MB 6.0.1.5605 unbekannt Samsung Magic Doctor Samsung Electronics Co., LTD 30.06.2009 15,7MB 5.0 unbekannt Samsung Recovery Solution III Samsung 08.10.2008 36,5MB 3.0.0.6 unbekannt Samsung SCX-4100 Series 03.12.2009 19,2MB notwendig Samsung Update Plus Samsung Electronics Co., LTD 08.10.2008 5,78MB 1.3.0.11 unbekannt Synaptics Pointing Device Driver Synaptics 08.10.2008 13,6MB 10.1.2.0 unbekannt Tony Hawk's Pro Skater 2 Demo 05.07.2010 38,0MB unbekannt Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) Microsoft Corporation 14.03.2011 30,6MB 9.00.5000.00 unbekannt User Guide 30.06.2009 214MB 1.0 unbekannt Vimicro UVC Camera Vimicro Corporation 08.10.2008 2,15MB 1.00.0000 unbekannt WIDCOMM Bluetooth Software 6.0.1.6300 WIDCOMM, Inc. 08.10.2008 35,5MB 6.0.1.6300 unbekannt Windows Live Essentials Microsoft Corporation 02.02.2011 92,0MB 14.0.8117.0416 notwendig Windows Live ID-Anmelde-Assistent Microsoft Corporation 23.06.2010 4,69MB 6.500.3165.0 notwendig Windows Live Sync Microsoft Corporation 16.12.2010 2,80MB 14.0.8117.416 notwendig Windows Live-Uploadtool Microsoft Corporation 05.07.2009 0,22MB 14.0.8014.1029 notwendig Windows Media Player Firefox Plugin Microsoft Corp 28.08.2009 0,29MB 1.0.0.8 notwendig |
22.04.2011, 17:25 | #14 |
/// Malware-holic | Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... deinstaliere Adobe Reader 8.1.2 updaten: Adobe - Adobe Reader herunterladen - Alle Versionen haken bei mcafee security scan raus öffne den adobe reader, bearbeiten, voreinstellungen, javascript, dort den haken raus, internet, ebenfalls alle haken raus. so werden keine pdfs mehr automatisch geladen und es kann dir kein schadcode mehr auf diese weise untergeschoben werden. unter allgemein, nur zertifizierte zusatzmodule verwenden anhaken. unter update, auf instalieren stellen. klicke übernehmen /ok deinstaliere. Bonjour Business Contact Manager CyberLink beide Easy Battery Manager Easy Display Manager Easy SpeedUp ElsterFormular ICQ Toolbar iTunes zum musik laden falls unnötig weg, mit den apple einträgen. LabelPrint LightScribe Microsoft Silverlight nutzt du das, falls nein weg Microsoft SQL Server nutzt du den, falls nein weg Mozilla Firefox öffnen hillfe update, version 4 instalieren Namuga PowerDirector PowerDVD PowerProducer Samsung Magic Tony Hawk's Unterstützungsdateien Vimicro bereinige mit dem ccleaner.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
22.04.2011, 18:19 | #15 |
| Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... Ok, alle Schritte erledigt. Hab ichs nun überstanden?? |
Themen zu Windows konnte alle Daten fur die Datei \\System32\\496A8300 nicht speichern... |
antivir, avgntflt.sys, avira, betriebs, bho, bonjour, desktop, error, excel.exe, extras.txt, fehler, firefox, flash player, helper, home, install.exe, langs, location, logfile, lws.exe, microsoft office 2003, microsoft office word, mozilla, nvlddmkm.sys, object, office 2007, oldtimer, otl.txt, picasa, plug-in, realtek, registry, saver, scan, sched.exe, searchplugins, security, security update, senden, server, shell32.dll, software, start menu, svchost.exe, system, vista, windows |