Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird (https://www.trojaner-board.de/111860-weisser-bildschirm-bitte-warten-waehrend-verbindung-hergestellt.html)

greggy 19.03.2012 16:50

Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird
 
Hallo zusammen,

also ich habe das Problem das wenn ich den Rechner starte, egal in welchem Modus, bekomme ich immer einen Weißen Bildschirm mit der Aufschrift "Bitte warten Sie während die Verbindung hergestellt wird".
Hab das Problem auch schon gesucht aber keine allgemein gültige Lösung gefunden.
Anbei das OTL Log.

Code:

OTL logfile created on: 3/19/2012 7:28:45 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
Windows 7 Professional  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 125.00 Gb Total Space | 84.50 Gb Free Space | 67.60% Space Free | Partition Type: NTFS
Drive D: | 107.88 Gb Total Space | 23.44 Gb Free Space | 21.73% Space Free | Partition Type: NTFS
Drive X: | 3.73 Gb Total Space | 3.33 Gb Free Space | 89.26% Space Free | Partition Type: FAT
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service)
SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield)
SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent)
SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr)
SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim)
SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService)
SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService)
SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr)
SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand] --  -- (FirehkMP)
DRV - File not found [Kernel | On_Demand] --  -- (Firehk)
DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp)
DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn)
DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog)
DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp)
DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter)
DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ)
DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm)
DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM)
DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM)
DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl)
DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr)
DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis)
DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum)
DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps)
DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard)
DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt)
DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R)
DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr)
DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It)
DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID)
DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV)
DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M]
 
[2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
 
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [7Rxb5FismTZydeX] C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.)
O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O20 - HKLM Winlogon: UserInit - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/19 16:07:56 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/03/19 03:15:04 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012/03/19 03:15:03 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012/03/19 03:15:00 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012/03/19 03:14:45 | 000,826,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2012/03/11 11:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\RavensburgerTipToi
[2012/03/11 11:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Ravensburger tiptoi
[2012/03/09 06:10:40 | 000,000,000 | ---D | C] -- C:\xmldm
[2012/02/29 09:53:53 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012/02/29 09:53:01 | 000,180,488 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2012/02/22 15:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc
[2012/02/22 15:47:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Shared
[2012/02/22 15:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Corporation
[2012/02/22 15:35:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/19 11:13:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/19 11:13:02 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini
[2012/03/19 11:09:55 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/19 08:45:59 | 000,000,074 | ---- | M] () -- C:\Windows\System32\settings.bin
[2012/03/19 08:40:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job
[2012/03/19 03:01:52 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/03/19 02:53:13 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job
[2012/03/19 02:50:13 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/03/19 02:50:13 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/03/19 02:50:13 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/19 02:50:13 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/05 16:25:03 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/02/29 09:53:46 | 000,180,488 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2012/02/22 16:10:56 | 000,476,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/02/22 15:47:55 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Reader for PC.lnk
[2012/02/22 15:47:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc
 
========== Files Created - No Company Name ==========
 
[2012/02/22 15:47:55 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Reader for PC.lnk
[2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp
[2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll
[2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe
[2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp
[2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat
[2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat
[2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini
[2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin
[2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll
[2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll
[2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll
[2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll
[2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll
[2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini
[2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI
[2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini
[2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll
[2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll
[2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll
[2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll
[2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll
[2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll
[2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll
[2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
 
========== LOP Check ==========
 
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications
[2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail
[2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom
[2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia
[2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount
[2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache
[2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi
[2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb
[2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip
[2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater
[2012/02/06 03:23:06 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
< End of report >

Vielen Dank schon einmal.

markusg 19.03.2012 16:59

hi,
auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort
rein:
Code:

:OTL
O20 - HKLM Winlogon: Shell - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O4 - HKLM..\Run: [7Rxb5FismTZydeX] C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
:Files
C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]

dieses speicherst du auf nem usb stick als fix.txt
nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist.
• Klicke nun bitte auf den Fix Button.
es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick.
wenn dies nicht funktioniert, bitte den fix manuell eintragen.
dann klicke erneut den fix buton. pc startet evtl. neu. wenn ja, nimm die cd aus dem laufwerk, windows sollte nun normal starten und die otl.txt öffnen,
log posten bitte.



falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus :)

greggy 19.03.2012 20:35

Vielen danke erst mal, der Rechner bootet wieder ganz normal.
Ich hoffe mal der Rest passt auch.

OTL Logfile:
Code:

OTL logfile created on: 3/19/2012 7:28:45 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
Windows 7 Professional  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 125.00 Gb Total Space | 84.50 Gb Free Space | 67.60% Space Free | Partition Type: NTFS
Drive D: | 107.88 Gb Total Space | 23.44 Gb Free Space | 21.73% Space Free | Partition Type: NTFS
Drive X: | 3.73 Gb Total Space | 3.33 Gb Free Space | 89.26% Space Free | Partition Type: FAT
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service)
SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield)
SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent)
SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr)
SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim)
SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService)
SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService)
SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr)
SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand] --  -- (FirehkMP)
DRV - File not found [Kernel | On_Demand] --  -- (Firehk)
DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp)
DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn)
DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog)
DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp)
DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter)
DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ)
DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm)
DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM)
DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM)
DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl)
DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr)
DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis)
DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum)
DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps)
DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard)
DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt)
DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R)
DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr)
DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It)
DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID)
DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV)
DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M]
 
[2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
 
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [7Rxb5FismTZydeX] C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.)
O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O20 - HKLM Winlogon: UserInit - (C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe) - C:\Users\EG011222\AppData\Roaming\k8rdift659c.exe (lyqU)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/19 16:07:56 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/03/19 03:15:04 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012/03/19 03:15:03 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012/03/19 03:15:00 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012/03/19 03:14:45 | 000,826,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2012/03/11 11:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\RavensburgerTipToi
[2012/03/11 11:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Ravensburger tiptoi
[2012/03/09 06:10:40 | 000,000,000 | ---D | C] -- C:\xmldm
[2012/02/29 09:53:53 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012/02/29 09:53:01 | 000,180,488 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2012/02/22 15:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc
[2012/02/22 15:47:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Shared
[2012/02/22 15:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony Corporation
[2012/02/22 15:35:02 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/19 11:13:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/19 11:13:02 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini
[2012/03/19 11:09:55 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/19 09:05:37 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/19 08:45:59 | 000,000,074 | ---- | M] () -- C:\Windows\System32\settings.bin
[2012/03/19 08:40:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job
[2012/03/19 03:01:52 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/03/19 02:53:13 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job
[2012/03/19 02:50:13 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/03/19 02:50:13 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/03/19 02:50:13 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/19 02:50:13 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/05 16:25:03 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/02/29 09:53:46 | 000,180,488 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2012/02/22 16:10:56 | 000,476,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/02/22 15:47:55 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Reader for PC.lnk
[2012/02/22 15:47:55 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc
 
========== Files Created - No Company Name ==========
 
[2012/02/22 15:47:55 | 000,002,029 | ---- | C] () -- C:\Users\Public\Desktop\Reader for PC.lnk
[2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp
[2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll
[2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe
[2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp
[2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat
[2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat
[2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini
[2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin
[2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll
[2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll
[2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll
[2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll
[2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll
[2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini
[2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI
[2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini
[2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll
[2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll
[2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll
[2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll
[2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll
[2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll
[2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll
[2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
 
========== LOP Check ==========
 
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications
[2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail
[2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom
[2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia
[2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount
[2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache
[2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi
[2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb
[2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip
[2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater
[2012/02/06 03:23:06 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
< End of report >

--- --- ---

[/CODE]

greggy 19.03.2012 20:50

Ich habe nun auch den Upload versucht, aber leider bekomm ich den "Link zum Thema im Forum" nicht hin. Habs mit dem Thema "Weißer Bildschirm - Bitte warten Sie während die Verbindung hergestellt wird" probiert, aber das scheint wohl nicht richtig zu sein?

markusg 19.03.2012 21:32

welches problem gibts da, link aus der adress zeile kopieren und dort einfügen. dann gehts

greggy 19.03.2012 22:37

Sorry finde die Beschreibung nicht ganz so klar. Hatte Sie auf jeden Fall falsch verstanden.
Nu is gut und das Ding ist oben.

markusg 20.03.2012 12:21

hi
bis wir fertig sind, wird nur auf den für die reinigung nötigen seiten gesurft, nirgendwo anders.
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.

Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
  • Besuche folgende Seite für Downloadlinks und Anweisungen für dieses
    Tool

    Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Hinweis:
    Gehe sicher das all deine Anti Virus und Anti Malware Programme abgeschalten sind, damit diese Combofix nicht bei der Arbeit stören.
  • Poste bitte die C:\Combofix.txt in deiner nächsten Antwort.


Alle Zeitangaben in WEZ +1. Es ist jetzt 04:26 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131