Windows Xp *BKA*-Trojaner Hallo !
hab diesen bloeden verschluesselungstrojaner...
nach dem booten per CD gibt OTLP dieses Scan-file aus
wer weiss rat ?
danke schon mal fuer die hilfe ! Code:
OTL logfile created on: 9/12/2013 4:12:32 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
511.00 Mb Total Physical Memory | 253.00 Mb Available Physical Memory | 50.00% Memory free
459.00 Mb Paging File | 291.00 Mb Available in Paging File | 63.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 149.04 Gb Total Space | 66.82 Gb Free Space | 44.83% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 1 Day
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - [2013/09/10 19:48:26 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/09/01 13:15:40 | 000,042,504 | ---- | M] (COMPANYVERS_NAME) [Auto] -- C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe -- (VideoDownloadConverter_4zService)
SRV - [2013/04/04 08:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 08:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2009/12/31 04:17:24 | 000,012,640 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Auto] -- C:\Programme\Aladdin\eToken\PKIClient\x32\eTSrv.exe -- (eTSrv)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto] -- C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (RT2500)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - [2013/09/12 08:28:25 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2013/04/04 08:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009/01/05 15:55:54 | 000,017,480 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/07/29 10:40:04 | 000,048,296 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\aksifdh.sys -- (AKSIFDH)
DRV - [2008/04/13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/06/13 12:11:10 | 000,025,136 | ---- | M] (America Online) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\atwpkt2.sys -- (ATWPKT2)
DRV - [2005/02/08 17:01:27 | 000,008,552 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2005/01/22 16:07:41 | 000,008,864 | ---- | M] () [Kernel | Auto] -- C:\WINDOWS\system32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2003/01/10 17:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2002/12/26 23:41:00 | 000,026,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS -- (viaagp1)
DRV - [2001/08/17 09:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001/08/17 08:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)
DRV - [2000/07/23 19:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto] -- C:\WINDOWS\System32\drivers\BrPar.sys -- (BrPar)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\user_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\WindowsXP_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\WindowsXP_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKU\WindowsXP_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.tb.ask.com/index.jhtml?n=77DE8857&p2=^HJ^xdm382^YYA^de&ptb=849EBFD9-1815-4E90-B949-FC447C37D84C&si=pconverter
IE - HKU\WindowsXP_ON_C\..\URLSearchHook: {93a3111f-4f74-4ed8-895e-d9708497629e} - Reg Error: Key error. File not found
IE - HKU\WindowsXP_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin: C:\Programme\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2013/01/06 10:41:14 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Toolbar BHO) - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Search Assistant BHO) - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)
O3 - HKLM\..\Toolbar: (VideoDownloadConverter) - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKU\user_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\user_ON_C\..\Toolbar\WebBrowser: (no name) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No CLSID value found.
O3 - HKU\user_ON_C\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKU\WindowsXP_ON_C\..\Toolbar\WebBrowser: (VideoDownloadConverter) - {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark)
O3 - HKU\WindowsXP_ON_C\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Advanced System Protector_startup] C:\Programme\Advanced System Protector\AdvancedSystemProtector.exe (Systweak)
O4 - HKLM..\Run: [AOLDialer] C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe (AOL LLC)
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [eTMonitor] C:\Programme\Aladdin\eToken\PKIClient\x32\PKIMonitor.exe (Aladdin Knowledge Systems, Ltd.)
O4 - HKLM..\Run: [HostManager] C:\Programme\Gemeinsame Dateien\aol\1175031853\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PSDrvCheck] C:\WINDOWS\system32\PSDrvCheck.exe ()
O4 - HKLM..\Run: [VideoDownloadConverter Search Scope Monitor] C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zSrchMn.exe (MindSpark)
O4 - HKLM..\Run: [VideoDownloadConverter_4z Browser Plugin Loader] C:\Programme\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe (VER_COMPANY_NAME)
O4 - HKU\user_ON_C..\Run: [aOXoJlZQ] C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\ApplicationHistory\YyqhtxXX.exe ()
O4 - HKU\WindowsXP_ON_C..\Run: [aOXoJlZQ] C:\Dokumente und Einstellungen\WindowsXP\Lokale Einstellungen\Anwendungsdaten\Adobe\GZxcFNhY.exe ()
O4 - HKU\WindowsXP_ON_C..\Run: [RDReminder] C:\Programme\RegClean Pro\RegCleanPro.exe (Systweak Inc)
O4 - HKU\WindowsXP_ON_C..\Run: [WEB.DE Application {sync-000021}] C:\Dokumente und Einstellungen\WindowsXP\Lokale Einstellungen\Anwendungsdaten\WEB.DE Application {sync-000021}\webde_onlinespeicher.exe (1&1 Mail & Media GmbH)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\user\Startmenü\Programme\Autostart\SHaibdeL.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\WindowsXP\Startmenü\Programme\Autostart\SHaibdeL.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\user_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\WindowsXP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\WindowsXP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\WindowsXP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\WindowsXP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350211576234 (WUWebControl Class)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab (GameHouse Games Player)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DED4846F-31AF-4185-870A-19BE187A3B8F} hxxp://www.yukonenergy.ca/WebSurveillance.cab (WebFormX Control)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Programme\Adobe\GZxcFNhY.exe) - C:\Programme\Adobe\GZxcFNhY.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 1 Day ==========
[2013/09/12 07:42:55 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Systweak
[2013/09/12 07:41:18 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/09/12 07:40:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\lfcXVrJD
[2013/09/12 05:26:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\WindowsXP\Lokale Einstellungen\Anwendungsdaten\lfcXVrJD
[2013/09/12 05:26:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\WindowsXP\Lokale Einstellungen\Anwendungsdaten\dYfsueyB
[2012/10/15 16:55:33 | 000,763,448 | ---- | C] (Google Inc.) -- C:\Programme\ChromeSetup.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\*.tmp -> ]
========== Files - Modified Within 1 Day ==========
[2013/09/12 08:28:25 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/09/12 08:26:09 | 000,000,080 | ---- | M] () -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\mbam.context.scan
[2013/09/12 08:22:32 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/09/12 08:22:21 | 000,001,366 | ---- | M] () -- C:\Dokumente und Einstellungen\WindowsXP\Desktop\Registry kostenlos entrümpeln!.lnk
[2013/09/12 08:21:39 | 000,004,452 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2013/09/12 08:21:37 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/12 08:21:28 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/09/12 08:21:26 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2013/09/12 07:38:00 | 000,001,096 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/12 06:48:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/12 05:30:33 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RegClean Pro_UPDATES.job
[2013/09/12 05:25:44 | 000,146,432 | --S- | M] () -- C:\Dokumente und Einstellungen\WindowsXP\Startmenü\Programme\Autostart\SHaibdeL.exe
[2013/09/12 05:25:44 | 000,146,432 | --S- | M] () -- C:\Dokumente und Einstellungen\user\Startmenü\Programme\Autostart\SHaibdeL.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/12 08:26:09 | 000,000,080 | ---- | C] () -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\mbam.context.scan
[2013/09/12 07:40:46 | 000,146,432 | --S- | C] () -- C:\Dokumente und Einstellungen\user\Startmenü\Programme\Autostart\SHaibdeL.exe
[2013/09/12 05:26:06 | 000,146,432 | --S- | C] () -- C:\Dokumente und Einstellungen\WindowsXP\Startmenü\Programme\Autostart\SHaibdeL.exe
[2013/09/01 13:22:52 | 000,017,136 | ---- | C] () -- C:\WINDOWS\System32\sasnative32.exe
[2013/08/05 03:57:09 | 000,097,464 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2013/07/16 03:16:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2013/01/06 09:57:36 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013/01/06 09:57:36 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013/01/06 09:57:36 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013/01/06 09:57:36 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013/01/06 09:57:36 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/10/23 05:30:50 | 000,076,341 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\odozzgbrbiotagi
[2012/02/16 09:28:12 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/10/31 18:04:28 | 000,005,120 | ---- | C] () -- C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/11 13:09:13 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/01/11 12:08:59 | 000,000,141 | ---- | C] () -- C:\WINDOWS\BRVIDEO.INI
[2010/01/11 12:08:59 | 000,000,023 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2010/01/11 12:08:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2010/01/11 12:08:56 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP.DLL
[2010/01/11 12:08:54 | 000,008,981 | ---- | C] () -- C:\WINDOWS\HL-2030.INI
[2010/01/11 12:08:46 | 000,000,432 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/01/11 12:08:46 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\BD2030.DAT
[2009/11/09 13:36:32 | 000,000,900 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/13 13:25:55 | 000,000,057 | ---- | C] () -- C:\WINDOWS\DcmLtbox-WS.ini
[2009/01/05 15:46:08 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2007/09/27 01:24:08 | 000,000,137 | ---- | C] () -- C:\Dokumente und Einstellungen\user\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/09/26 07:08:23 | 000,000,142 | ---- | C] () -- C:\Dokumente und Einstellungen\WindowsXP\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/09/26 06:56:55 | 000,109,403 | ---- | C] () -- C:\WINDOWS\hpiins04.dat
[2007/09/26 06:56:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpimdl04.dat
[2006/08/06 05:52:52 | 000,078,336 | ---- | C] () -- C:\Dokumente und Einstellungen\WindowsXP\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/15 07:44:25 | 000,029,184 | ---- | C] () -- C:\WINDOWS\HTMLRUN.EXE
[2005/11/26 11:13:32 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\IWUninstall.exe
[2005/11/26 11:12:54 | 000,396,800 | ---- | C] () -- C:\WINDOWS\System32\PSDrvCheck.exe
[2005/10/17 17:38:15 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT
[2005/10/17 17:35:28 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDEC46Euro.ini
[2005/09/28 11:50:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\distlib.ini
[2005/09/22 15:44:26 | 000,065,536 | ---- | C] () -- C:\WINDOWS\IFinst27.exe
[2005/04/09 18:47:18 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005/04/09 12:57:59 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\wztmscs.dll
[2005/04/07 09:54:31 | 000,000,078 | ---- | C] () -- C:\WINDOWS\SLAY.INI
[2005/03/07 10:10:33 | 007,741,336 | ---- | C] () -- C:\Programme\DivX521XP2K.exe
[2005/02/11 14:55:04 | 000,051,712 | ---- | C] () -- C:\WINDOWS\System32\sp_init.dll
[2005/02/11 14:55:04 | 000,048,640 | ---- | C] () -- C:\WINDOWS\System32\virtual_keyboard.dll
[2005/02/11 14:55:04 | 000,048,128 | ---- | C] () -- C:\WINDOWS\System32\vo_env.dll
[2005/02/11 14:55:04 | 000,031,744 | ---- | C] () -- C:\WINDOWS\System32\vo_hook.dll
[2005/02/11 14:54:44 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\shellses.dll
[2005/02/08 17:02:50 | 000,000,725 | ---- | C] () -- C:\WINDOWS\aolback.exe.lnk
[2005/02/08 16:59:58 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2005/02/08 15:21:24 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2005/01/25 13:10:02 | 000,000,241 | ---- | C] () -- C:\WINDOWS\CSPLAYER.INI
[2005/01/25 12:51:31 | 000,063,488 | ---- | C] () -- C:\WINDOWS\xobglu16.dll
[2005/01/25 12:51:31 | 000,034,628 | ---- | C] () -- C:\WINDOWS\xobglu32.dll
[2005/01/25 12:50:20 | 000,000,569 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2005/01/25 10:22:47 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.WindowsXP.ini
[2005/01/22 16:07:41 | 000,008,864 | ---- | C] () -- C:\WINDOWS\System32\drivers\CDAC15BA.SYS
[2005/01/22 16:04:31 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2005/01/22 15:56:31 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2005/01/22 15:56:31 | 000,003,136 | ---- | C] () -- C:\WINDOWS\Ade001.bin
[2005/01/22 15:56:31 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\epDPE.ini
[2005/01/22 15:55:12 | 000,030,605 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2005/01/22 15:55:12 | 000,027,030 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2005/01/22 15:55:12 | 000,000,022 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2005/01/22 15:54:05 | 000,064,000 | ---- | C] () -- C:\WINDOWS\System32\esfw41.bin
[2005/01/22 15:52:54 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE P242580GD.ini
[2005/01/06 17:24:50 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/01/06 17:18:42 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/01/06 17:11:30 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/01/06 17:10:31 | 000,153,976 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/01/06 10:56:04 | 000,000,403 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/01/06 10:35:31 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2005/01/06 10:35:31 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2005/01/06 10:35:30 | 000,000,010 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2005/01/06 10:35:25 | 000,266,240 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2005/01/06 10:35:25 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2005/01/06 10:34:09 | 000,002,598 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2005/01/06 10:34:08 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2004/10/26 18:39:05 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/08/03 19:12:38 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/02 08:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/04/23 09:02:10 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.exe
[2003/02/18 12:26:28 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2001/08/23 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/18 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/18 06:00:00 | 000,527,562 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2001/08/18 06:00:00 | 000,502,772 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/18 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/18 06:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2001/08/18 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/18 06:00:00 | 000,105,656 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2001/08/18 06:00:00 | 000,088,296 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/18 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/18 06:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2001/08/18 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/18 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2000/04/18 07:02:00 | 000,000,110 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT
[1999/04/29 18:00:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2005/11/22 17:13:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\user\Anwendungsdaten\EPSON
[2013/09/12 07:42:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\user\Anwendungsdaten\Systweak
[2012/10/11 14:34:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\1&1 Mail & Media GmbH
[2012/10/18 20:47:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Aprob
[2005/03/02 13:34:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\EPSON
[2008/05/26 12:45:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\FocusDVD
[2010/07/04 09:35:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\GARMIN
[2012/10/24 03:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Oqavme
[2012/10/23 05:31:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Siday
[2005/01/22 16:05:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Smart Panel
[2005/11/26 11:20:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Steinberg
[2013/09/01 13:23:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Systweak
[2013/09/01 13:17:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\VideoDownloadConverter_4z
[2009/04/22 03:53:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\WindowsXP\Anwendungsdaten\Zylom
[2012/10/11 14:34:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DesktopIcons
[2010/01/29 10:33:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\GameHouse
[2012/05/31 19:21:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\mggolveontrrsqw
[2012/10/23 05:31:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\pzyeqhzedvrsdtu
[2013/09/01 13:22:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Systweak
[2005/10/17 17:39:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UDL
[2006/02/17 15:10:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Zylom
[2013/09/11 09:02:34 | 000,000,264 | ---- | M] () -- C:\WINDOWS\Tasks\RegClean Pro_DEFAULT.job
[2013/09/12 05:30:33 | 000,000,272 | ---- | M] () -- C:\WINDOWS\Tasks\RegClean Pro_UPDATES.job
========== Purity Check ==========
< End of report > |