Hallo cosinus,
vielen Dank für deine Antwort!
Ich habe jetzt mal alles gemacht was du geschrieben hast, funnktioniert auch alles 1A.
Allerdings ist damit der Virus ja trotzdem noch auf der Festplatte und ich würde jeden PC damit infizieren, sobald ich die HDD einstecke?
Ich bin die Schritte durchgegangen die gemacht werden sollen wenn man ein Thread erstellt. Hier sind mal dazu die log-files. OTL:
OTL Logfile: Code:
OTL logfile created on: 26.11.2012 19:30:44 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,93 Gb Total Physical Memory | 1,84 Gb Available Physical Memory | 63,05% Memory free
5,85 Gb Paging File | 4,62 Gb Available in Paging File | 78,94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298,08 Gb Total Space | 158,22 Gb Free Space | 53,08% Space Free | Partition Type: NTFS
Drive F: | 2,97 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: FUJITSU | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.11.26 19:30:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads\OTL.exe
PRC - [2012.10.28 20:38:10 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.09.07 19:26:23 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.09.07 19:26:19 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.09.07 19:26:13 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.09.07 19:26:13 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.09.06 12:12:20 | 000,162,408 | ---- | M] (Geek Software GmbH) -- C:\Program Files\PDF24\pdf24.exe
PRC - [2012.08.27 05:21:12 | 026,924,984 | ---- | M] (Dropbox, Inc.) -- C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012.08.20 18:37:58 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.03.23 15:55:44 | 007,351,760 | ---- | M] (QIP) -- C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\qip.exe
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.11.01 16:04:50 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.11.01 16:04:44 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.09.26 01:44:56 | 000,036,864 | ---- | M] (Dassault Systemes) -- C:\Program Files\Dassault Systemes\B20\intel_a\code\bin\CATSysDemon.exe
PRC - [2006.07.12 16:43:28 | 000,090,112 | ---- | M] (FUJITSU LIMITED) -- C:\Programme\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
========== Modules (No Company Name) ==========
MOD - [2012.10.28 20:38:09 | 002,295,264 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.03.23 15:56:04 | 000,957,392 | ---- | M] () -- C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\Protos\Social\Social.dll
MOD - [2012.03.23 15:56:00 | 001,641,936 | ---- | M] () -- C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\Protos\MRA\MRA.dll
MOD - [2012.03.23 15:56:00 | 000,049,104 | ---- | M] () -- C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\Protos\MRA\pics.dll
MOD - [2012.03.23 15:55:56 | 002,524,112 | ---- | M] () -- C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\Protos\InfICQ\InfICQ.dll
MOD - [2012.03.23 15:55:54 | 000,130,000 | ---- | M] () -- C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\Plugins\Win7Helper\Win7Helper.dll
MOD - [2012.01.10 20:12:12 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll
========== Services (SafeList) ==========
SRV - [2012.10.28 20:38:09 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.07 19:26:19 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.09.07 19:26:13 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.07.27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2009.11.01 16:04:50 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009.11.01 16:04:44 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009.09.26 01:44:56 | 000,036,864 | ---- | M] (Dassault Systemes) [Auto | Running] -- C:\Program Files\Dassault Systemes\B20\intel_a\code\bin\CATSysDemon.exe -- (BBDemon)
SRV - [2009.07.14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RtsUCcid.sys -- (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (RtsUIR)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2012.09.22 13:55:44 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012.09.07 19:26:23 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.09.07 19:26:23 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.09.07 19:26:23 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.06.17 14:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.11.06 11:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009.11.01 16:04:44 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2007.04.24 17:52:10 | 000,016,688 | ---- | M] (IBM) [Kernel | System | Running] -- C:\Windows\System32\drivers\LUMDriver.sys -- (LUMDriver)
DRV - [2006.11.01 18:59:24 | 000,005,632 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fuj02e3.sys -- (FUJ02E3)
DRV - [2006.11.01 18:20:28 | 000,005,888 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fuj02b1.sys -- (FUJ02B1)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D2 5F 0D 04 45 BF CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.28 20:38:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.10.28 20:38:10 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012.09.21 12:09:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions
[2012.11.24 13:45:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\tult9ajn.default\extensions
[2012.11.24 13:45:34 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\tult9ajn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.10.28 20:38:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.10.28 20:38:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.10.28 20:38:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.10.28 20:38:10 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.09.06 03:07:37 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.06 03:07:37 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.09.06 03:07:37 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.09.06 03:07:37 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.09.06 03:07:37 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.09.06 03:07:37 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Admin\AppData\Local\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Admin\AppData\Local\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Admin\AppData\Local\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java(TM) Platform SE 6 U37 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Admin\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Google Mail = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [IndicatorUtility] C:\Programme\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKCU..\Run: [Infium] C:\Program Files\jeak.de\QIP 2012 Jeak-Edition\qip.exe (QIP)
O4 - Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{185516C8-46DF-471B-B15F-2003CFC09F12}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27514C3B-0225-4693-A3BC-4675FCE0D094}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.07.15 20:39:51 | 000,000,122 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{015be092-03d5-11e2-a745-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{015be092-03d5-11e2-a745-806e6f6e6963}\Shell\AutoRun\command - "" = D:\start.exe
O33 - MountPoints2\{015be092-03d5-11e2-a745-806e6f6e6963}\Shell\option1\command - "" = D:\deskupdate\DeskUpdate.exe
O33 - MountPoints2\{015be092-03d5-11e2-a745-806e6f6e6963}\Shell\support\command - "" = D:\deskupdate\support.bat
O33 - MountPoints2\{a447bcc9-049f-11e2-b903-e0ca94afd7d9}\Shell - "" = AutoRun
O33 - MountPoints2\{a447bcc9-049f-11e2-b903-e0ca94afd7d9}\Shell\AutoRun\command - "" = F:\sources\sperr32.exe -- [2009.07.15 20:39:51 | 000,123,472 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.11.17 16:50:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.11.17 16:46:49 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\x-formation
[2012.11.17 16:46:49 | 000,000,000 | ---D | C] -- C:\ProgramData\x-formation
[2012.11.17 16:46:48 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\altair
[2012.11.17 16:46:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Altair
[2012.11.13 14:37:07 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\uni
[2012.11.10 12:18:39 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012.11.07 16:53:10 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\Peter der Assi
[2012.11.02 23:42:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Diagnostics
[2012.10.29 21:45:31 | 000,000,000 | ---D | C] -- C:\Swsetup
[2012.10.28 20:38:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
========== Files - Modified Within 30 Days ==========
[2012.11.26 19:29:52 | 000,000,156 | ---- | M] () -- C:\Users\Admin\defogger_reenable
[2012.11.26 19:26:52 | 000,014,752 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.26 19:26:52 | 000,014,752 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.26 19:19:42 | 000,000,388 | ---- | M] () -- C:\Windows\tasks\QIPdater 2012.job
[2012.11.26 19:19:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.26 19:19:17 | 2356,584,448 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.26 13:02:14 | 000,000,806 | ---- | M] () -- C:\Users\Admin\Desktop\DrWeb.csv
[2012.11.26 12:05:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2066243063-1105699576-1169010081-1000UA.job
[2012.11.25 11:44:01 | 000,003,584 | ---- | M] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.11.24 15:05:00 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2066243063-1105699576-1169010081-1000Core.job
[2012.11.17 17:12:33 | 000,305,880 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.11.17 16:53:45 | 000,696,870 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.11.17 16:53:45 | 000,652,148 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.11.17 16:53:45 | 000,148,134 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.11.17 16:53:45 | 000,121,080 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.11.17 16:51:32 | 000,002,603 | ---- | M] () -- C:\Users\Admin\Documents\command.cmf
[2012.11.12 14:00:49 | 000,017,558 | ---- | M] () -- C:\Users\Admin\Desktop\PB_KAZ_KtoNr_0726057708_10-11-2012_0301.pdf
[2012.11.12 11:57:27 | 000,238,928 | ---- | M] () -- C:\Users\Admin\Desktop\fotobuch.jpg
[2012.11.10 17:40:38 | 001,001,282 | ---- | M] () -- C:\Users\Admin\Desktop\e3.png
[2012.11.10 12:18:08 | 371,964,956 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.11.08 16:57:40 | 000,002,752 | ---- | M] () -- C:\Users\Admin\Desktop\porsche-schriftzug_274x21px.jpg
[2012.11.08 16:49:07 | 000,028,439 | ---- | M] () -- C:\Users\Admin\Desktop\GT.jpg
[2012.11.08 14:39:27 | 000,015,743 | ---- | M] () -- C:\Users\Admin\Desktop\PB_KAZ_KtoNr_0726057708_13-10-2012_0953-1.pdf
[2012.11.03 22:38:09 | 000,034,901 | ---- | M] () -- C:\Users\Admin\Desktop\Konto_502656-Auszug_2012_010.pdf.pdf
[2012.11.03 17:57:46 | 000,023,030 | ---- | M] () -- C:\Users\Admin\Desktop\Finanzreport_Nr.09_vom_01.11.2012064305-1.pdf
[2012.11.03 12:25:07 | 000,034,620 | ---- | M] () -- C:\Users\Admin\Desktop\Kontoauszug_63218003__Nr.010_vom_01.11.2012_20121103122452.pdf
[2012.11.03 12:24:46 | 000,028,545 | ---- | M] () -- C:\Users\Admin\Desktop\Kontoauszug_63218607__Nr.010_vom_01.11.2012_20121103122430.pdf
[2012.10.29 23:10:21 | 000,086,924 | ---- | M] () -- C:\Users\Admin\Desktop\81X0gYpIPPL._AA1500_.jpg
[2012.10.29 18:18:41 | 000,094,255 | ---- | M] () -- C:\Users\Admin\Desktop\Klettern.jpg
========== Files Created - No Company Name ==========
[2012.11.26 19:29:51 | 000,000,156 | ---- | C] () -- C:\Users\Admin\defogger_reenable
[2012.11.25 11:44:01 | 000,003,584 | ---- | C] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.11.17 16:48:10 | 000,002,603 | ---- | C] () -- C:\Users\Admin\Documents\command.cmf
[2012.11.17 16:44:51 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012.11.17 16:44:09 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012.11.16 18:30:40 | 000,000,806 | ---- | C] () -- C:\Users\Admin\Desktop\DrWeb.csv
[2012.11.12 14:00:49 | 000,017,558 | ---- | C] () -- C:\Users\Admin\Desktop\PB_KAZ_KtoNr_0726057708_10-11-2012_0301.pdf
[2012.11.12 11:57:27 | 000,238,928 | ---- | C] () -- C:\Users\Admin\Desktop\fotobuch.jpg
[2012.11.10 17:40:37 | 001,001,282 | ---- | C] () -- C:\Users\Admin\Desktop\e3.png
[2012.11.10 12:18:08 | 371,964,956 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.11.08 16:57:40 | 000,002,752 | ---- | C] () -- C:\Users\Admin\Desktop\porsche-schriftzug_274x21px.jpg
[2012.11.08 16:49:07 | 000,028,439 | ---- | C] () -- C:\Users\Admin\Desktop\GT.jpg
[2012.11.08 14:39:27 | 000,015,743 | ---- | C] () -- C:\Users\Admin\Desktop\PB_KAZ_KtoNr_0726057708_13-10-2012_0953-1.pdf
[2012.11.03 22:38:09 | 000,034,901 | ---- | C] () -- C:\Users\Admin\Desktop\Konto_502656-Auszug_2012_010.pdf.pdf
[2012.11.03 17:57:46 | 000,023,030 | ---- | C] () -- C:\Users\Admin\Desktop\Finanzreport_Nr.09_vom_01.11.2012064305-1.pdf
[2012.11.03 12:25:07 | 000,034,620 | ---- | C] () -- C:\Users\Admin\Desktop\Kontoauszug_63218003__Nr.010_vom_01.11.2012_20121103122452.pdf
[2012.11.03 12:24:45 | 000,028,545 | ---- | C] () -- C:\Users\Admin\Desktop\Kontoauszug_63218607__Nr.010_vom_01.11.2012_20121103122430.pdf
[2012.10.29 23:10:21 | 000,086,924 | ---- | C] () -- C:\Users\Admin\Desktop\81X0gYpIPPL._AA1500_.jpg
[2012.10.29 18:18:41 | 000,094,255 | ---- | C] () -- C:\Users\Admin\Desktop\Klettern.jpg
[2012.09.22 19:35:54 | 000,016,975 | ---- | C] () -- C:\Users\Admin\candy.jpg
[2012.09.22 14:25:12 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012.09.22 14:05:00 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.09.21 11:53:42 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat
[2012.01.10 21:17:08 | 000,128,204 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2012.01.10 21:17:04 | 000,105,608 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2012.01.10 21:17:02 | 000,867,020 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2012.01.10 20:29:54 | 013,904,384 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll
[2012.01.10 20:14:34 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012.01.10 20:12:34 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2012.01.10 20:12:12 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.09.28 14:26:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited
[2012.09.22 13:59:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
[2012.09.23 09:51:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DassaultSystemes
[2012.11.26 19:19:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Dropbox
[2012.09.21 13:54:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\IrfanView
[2012.09.21 14:37:59 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\jeak.de
[2012.09.21 14:02:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QIP
[2012.09.23 16:19:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Windows Live Writer
[2012.11.17 16:46:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\x-formation
========== Purity Check ==========
< End of report > --- --- --- Extras:
OTL Logfile: Code:
OTL Extras logfile created on: 26.11.2012 19:30:44 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,93 Gb Total Physical Memory | 1,84 Gb Available Physical Memory | 63,05% Memory free
5,85 Gb Paging File | 4,62 Gb Available in Paging File | 78,94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298,08 Gb Total Space | 158,22 Gb Free Space | 53,08% Space Free | Partition Type: NTFS
Drive F: | 2,97 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: FUJITSU | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CCA81ED-7F38-4219-9B45-50ABBFA4A987}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0E031089-1F23-4B30-8BE9-A12514B812C0}" = rport=445 | protocol=6 | dir=out | app=system |
"{1AB6F99F-B55A-4EF7-A820-B25020303EC5}" = rport=139 | protocol=6 | dir=out | app=system |
"{20071828-4703-40D1-9FA4-A6D2E117BABE}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{2659FDA5-DD56-49FF-B58F-9A03C3E4A5A9}" = rport=138 | protocol=17 | dir=out | app=system |
"{3A2AAA46-E1F0-4EE4-A578-0B19DBBC2819}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3E1B4502-6FA0-463B-9252-0C0D3505987E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{43F50730-C456-4135-98A0-FDED2ACEB48F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{51AE98EF-6B3A-42C5-A016-D8A04BA91E77}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{64D3804C-1094-41C5-8CB6-9AC530782EBC}" = lport=445 | protocol=6 | dir=in | app=system |
"{67AE0AF0-9DEC-4E61-89E9-4B8A82298AB2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{75159396-C8B9-426F-8FF0-F010F0FEB800}" = lport=10243 | protocol=6 | dir=in | app=system |
"{75A787EC-D187-4480-8B6C-30C722673A3C}" = lport=139 | protocol=6 | dir=in | app=system |
"{7D61E6DC-F70A-4643-95B8-4862878337BA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{86C0F8B4-B1B9-4528-84E9-7588E596BAB9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{9EA49F75-3506-45AF-9B20-56FEF572BCDD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AB96E35D-4E80-4B48-B53E-EA3248EA4EF8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{ADBB765B-542B-4418-A79E-83AB89457C77}" = rport=10243 | protocol=6 | dir=out | app=system |
"{B2FC5747-9912-4CBF-8D58-10776E5C586C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{BF3A242A-E0DE-47D5-A546-C09D0D41A61F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D4DDA857-9104-434F-9667-3D3622F90992}" = lport=137 | protocol=17 | dir=in | app=system |
"{DB1A60ED-4766-4841-A09E-7C65ECF09AD3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC6FD45C-9E27-49DA-B5BB-E9B7CB279DF2}" = lport=138 | protocol=17 | dir=in | app=system |
"{E356F9AE-55EE-4FB0-A3D2-4E8BFCBE31DF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EC9914E1-538F-438A-A354-51D5A42B801D}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{F3A00202-41C2-4C6D-8975-A021D11937FE}" = rport=137 | protocol=17 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05669E49-4C38-4F20-8772-BE3F96267D36}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0CB681E8-D7F2-4C36-A6E6-6DCE73A3AB16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0E438CD4-6177-4041-BC7D-427C95460D7F}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{10A3AAAF-DE10-49A5-9C03-AB9D8ED3B1CA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{24EAECE1-D8BA-4970-B353-22234D3FEF39}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2AADFBFD-5F03-4EEA-8895-5FB93F7BF0E7}" = dir=in | app=c:\program files\jeak.de\qip 2012 jeak-edition\qip.exe |
"{46CB2368-F55A-4A3C-8885-A5A5AEE591BC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{60673D87-8578-4825-B971-4945A7A3B55C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{72143582-5766-41C2-9AE5-EFBDA9419D83}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7BCF1BAA-B0DD-4718-9668-A32C66DACBC7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9404C740-8056-4FF7-8F95-DE6120728CFB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{998B6097-B41C-4D0E-ADE3-1A7BA55E3FF0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AC1263D2-E9E3-4874-B8C4-C47978F33ABD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AFD2EFE8-627E-443F-BAB9-0FE0E22E8BB9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BBDDF7D4-5A5C-4F37-94E4-2CD87B6DD9ED}" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"{C79F760F-9162-4C2A-AAB5-B28F8AFCD85D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D419DA42-FE29-4355-89F6-97D0BC3CF95B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D489FC88-EF72-4EE0-AFE9-1FE6CECC70C4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E5E6F58F-E0C8-42CB-91A6-493458ECFDFD}" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"{E84604DF-857F-4F8A-8FFE-5AB654C9008C}" = protocol=6 | dir=out | app=system |
"TCP Query User{05943D45-F61D-4614-A509-D62CA01B90F0}C:\program files\dassault systemes\b20\intel_a\code\bin\cnext.exe" = protocol=6 | dir=in | app=c:\program files\dassault systemes\b20\intel_a\code\bin\cnext.exe |
"TCP Query User{784970EC-4841-46D2-93B0-DE6C800E8C02}C:\program files\dassault systemes\b20\intel_a\code\bin\orbixd.exe" = protocol=6 | dir=in | app=c:\program files\dassault systemes\b20\intel_a\code\bin\orbixd.exe |
"TCP Query User{7A2C674B-9314-4530-A64D-DB2699BCF4AE}C:\spiele\blobby volley\volley.exe" = protocol=6 | dir=in | app=c:\spiele\blobby volley\volley.exe |
"TCP Query User{AE2842A7-0654-473F-AF05-4E4A7C86A897}C:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{0410531C-413C-4A7B-B809-FAE5515C83B1}C:\program files\dassault systemes\b20\intel_a\code\bin\orbixd.exe" = protocol=17 | dir=in | app=c:\program files\dassault systemes\b20\intel_a\code\bin\orbixd.exe |
"UDP Query User{49A769DB-8D90-41F8-8D4A-6321551349C4}C:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{6B32386C-0428-4631-ADCD-3C597AA3C2A2}C:\program files\dassault systemes\b20\intel_a\code\bin\cnext.exe" = protocol=17 | dir=in | app=c:\program files\dassault systemes\b20\intel_a\code\bin\cnext.exe |
"UDP Query User{CA215497-3730-4F73-989E-07D730954CC0}C:\spiele\blobby volley\volley.exe" = protocol=17 | dir=in | app=c:\spiele\blobby volley\volley.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{15F3A6F5-06AE-4332-AE3E-21CD0416827A}" = Windows Live Mail
"{1B947146-366B-42CD-86D5-219993CE3EE2}" = Windows Live MIME IFilter
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java(TM) 6 Update 37
"{2FBC78B6-125F-4E8C-8B18-2D7A3C2FD306}" = QIP 2012 7221 Jeak-Edition
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6DE6837F-F3A3-40FF-9F5C-A0B95948E32D}" = Dassault Systemes Software Prerequisites x86
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.9.0
"{8256F87F-8554-4457-8C3D-3F3324697D9F}" = Windows Live ID Sign-in Assistant
"{8913AC02-67B8-4B52-91B2-BBA7B9C265B5}" = Windows Live Writer Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A13D16C5-38A9-4D96-9647-59FCCAB12A85}" = Visual Basic for Applications (R) Core - English
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack
"{BA0CC975-682B-4678-A35C-05E607F36387}" = Fujitsu Hotkey Utility
"{BD8A0C60-1AEB-11D6-B8E1-00025521AE60}" = VBA (3821b)
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FB97C283-1F3C-42D4-AE01-ADC1DC12F774}" = Visual Basic for Applications (R) Core
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Altair HyperWorks 11.0.0.39 (Local 32-bit)" = Altair HyperWorks 11.0.0.39 (Local 32-bit)
"Avira AntiVir Desktop" = Avira Free Antivirus
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dassault Systemes B20_0" = Dassault Systemes Software B20
"InstallShield_{BA0CC975-682B-4678-A35C-05E607F36387}" = Fujitsu Hotkey Utility
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"QIP 2012 7221 Jeak-Edition 4.0.7221" = QIP 2012 7221 Jeak-Edition
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 2.0.3
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.20 (32-Bit)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 29.10.2012 13:17:12 | Computer Name = Fujitsu | Source = VSS | ID = 8194
Description =
Error - 29.10.2012 13:18:39 | Computer Name = Fujitsu | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Die Anwendung oder der Dienst "Windows Search" konnte nicht heruntergefahren
werden.
Error - 29.10.2012 13:21:31 | Computer Name = Fujitsu | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Die Anwendung oder der Dienst "Microsoft Windows Search Filter Host"
konnte nicht heruntergefahren werden.
Error - 29.10.2012 13:21:36 | Computer Name = Fujitsu | Source = Application Error | ID = 1000
Error - 29.10.2012 13:28:09 | Computer Name = Fujitsu | Source = VSS | ID = 8194
Description =
Error - 29.10.2012 13:29:21 | Computer Name = Fujitsu | Source = Microsoft-Windows-RestartManager
| ID = 10006
Description = Die Anwendung oder der Dienst "Windows Live Mail" konnte nicht heruntergefahren werden.
Error - 29.10.2012 13:29:33 | Computer Name = Fujitsu | Source = Microsoft-Windows-RestartManager
| ID = 10006
Description = Die Anwendung oder der Dienst "Windows Search" konnte nicht heruntergefahren werden.
Error - 05.11.2012 06:12:58 | Computer Name = Fujitsu | Source = Application Hang
| ID = 1002
Description = Programm firefox.exe, Version 16.0.2.4680 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1318
Startzeit: 01cdbb394941a220
Endzeit: 37
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 5d6ea3ff-2731-11e2-8ba7-e0ca94afd7d9
Error - 07.11.2012 14:34:48 | Computer Name = Fujitsu | Source = Application Hang
| ID = 1002
Description = Programm NOTEPAD.EXE, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 300
Startzeit: 01cdbd1674bd02da
Endzeit: 5
Anwendungspfad: C:\Windows\system32\NOTEPAD.EXE
Berichts-ID: bdd29e8a-2909-11e2-87eb-e0ca94afd7d9
Error - 10.11.2012 12:40:19 | Computer Name = Fujitsu | Source = Application Hang
| ID = 1002
Description = Programm firefox.exe, Version 16.0.2.4680 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 5bc
Startzeit: 01cdbf3736e76fc2
Endzeit: 102
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 4afdac3a-2b55-11e2-ad12-e0ca94afd7d9
Error - 11.11.2012 13:07:58 | Computer Name = Fujitsu | Source = Application Error
| ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 16.0.2.4680, Zeitstempel: 0x50882871
Name des fehlerhaften Moduls: xul.dll, Version: 16.0.2.4680, Zeitstempel: 0x508827d6
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00130ef7
ID des fehlerhaften Prozesses: 0x1260
Startzeit der fehlerhaften Anwendung: 0x01cdbffb43599fc4
Pfad der fehlerhaften Anwendung: C:\Program Files\Mozilla Firefox\firefox.exe
Pfad des fehlerhaften Moduls: C:\Program Files\Mozilla Firefox\xul.dll
Berichtskennung: 56e09248-2c22-11e2-a136-e0ca94afd7d9
Error encountered while reading event logs.
< End of report > --- --- --- Gmer:
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-11-26 20:41:25
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.01.0
Running: f57i6c57.exe; Driver: C:\Users\Admin\AppData\Local\Temp\fwldypod.sys
---- System - GMER 1.0.15 ----
SSDT 935C9386 ZwCreateSection
SSDT 935C9390 ZwRequestWaitReplyPort
SSDT 935C938B ZwSetContextThread
SSDT 935C9395 ZwSetSecurityObject
SSDT 935C939A ZwSystemDebugControl
SSDT 935C9327 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82C86A49 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CC04D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 82CC762C 4 Bytes [86, 93, 5C, 93]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 82CC7988 4 Bytes [90, 93, 5C, 93] {NOP ; XCHG EBX, EAX; POP ESP; XCHG EBX, EAX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1597 82CC79CC 4 Bytes [8B, 93, 5C, 93]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1613 82CC7A48 4 Bytes [95, 93, 5C, 93] {XCHG EBP, EAX; XCHG EBX, EAX; POP ESP; XCHG EBX, EAX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1667 82CC7A9C 4 Bytes [9A, 93, 5C, 93]
.text ...
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 AC8D6000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 AC8D6123 629 Bytes [15, 8D, AC, FE, 05, 34, 15, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 AC8D6399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F AC8D63FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B AC8D64AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e0ca94afd7d9
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e0ca94afd7d9 (not active ControlSet)
---- EOF - GMER 1.0.15 ---- --- --- --- |