Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: neue INfektion: Trojan.Banker, Backdoor.Agent

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 04.08.2012, 21:54   #1
dk-jule
 
neue INfektion: Trojan.Banker, Backdoor.Agent - Standard

neue INfektion: Trojan.Banker, Backdoor.Agent



Hey,

leider gibt es auf dem PC meines Freundes (und meiner auch, aber dazu in nem neuen Thread) wieder einen Trojaner.

Win7, 64bit

Folgende Scans bereits durchgeführt:

Malwarebytes Quickscan Logfile:
Code:
ATTFilter
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.04.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
User :: SLOWY-LAPTOP [Administrator]

04.08.2012 22:32:21
mbam-log-2012-08-04 (22-34-26).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 193495
Laufzeit: 1 Minute(n), 52 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 4
HKCR\CLSID\{DD31495E-290C-41CF-8C66-7415383F82DE} (Trojan.Banker) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DD31495E-290C-41CF-8C66-7415383F82DE} (Trojan.Banker) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DD31495E-290C-41CF-8C66-7415383F82DE} (Trojan.Banker) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DD31495E-290C-41CF-8C66-7415383F82DE} (Trojan.Banker) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Userinit (Backdoor.Agent) -> Daten: C:\Users\User\AppData\Roaming\appconf32.exe -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\User\AppData\Roaming\AcroIEHelpe180.dll (Trojan.Banker) -> Keine Aktion durchgeführt.
C:\Users\User\AppData\Roaming\appconf32.exe (Backdoor.Agent) -> Keine Aktion durchgeführt.

(Ende)
         
OTL Logfile
Code:
ATTFilter
OTL logfile created on: 04.08.2012 22:46:13 - Run 3
OTL by OldTimer - Version 3.2.44.0     Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 58,98% Memory free
7,73 Gb Paging File | 5,63 Gb Available in Paging File | 72,84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596,07 Gb Total Space | 473,49 Gb Free Space | 79,44% Space Free | Partition Type: NTFS
 
Computer Name: SLOWY-LAPTOP | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Dell Products, LP.)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe (Synaptics, Inc.)
PRC - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Programme\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Windows\SysWOW64\TSTheme.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Users\User\AppData\Roaming\AcroIEHelpe180.dll ()
MOD - C:\Users\User\AppData\Roaming\BAcroIEHelpe180.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\06269663e6482bc4ceeb48c2a7d1ad34\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtGui4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtXmlPatterns4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtCore4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtScript4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\phonon4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\imageformats\qgif4.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (Mcx2Svc) -- C:\Windows\SysNative\Mcx2Svc.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (wltrysvc) -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Dell Inc.)
SRV:64bit: - (RemoteAccess) -- C:\Windows\SysNative\mprdim.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (DellDigitalDelivery) -- C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Dell Products, LP.)
SRV - (vToolbarUpdater11.2.0) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe ()
SRV - (AVGIDSAgent) -- C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avgfws) -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (ScrybeUpdater) -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe (Synaptics, Inc.)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (STacSV) -- C:\Programme\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (EvtEng) Intel(R) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (MyWiFiDHCPDNS) -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV - (RegSrvc) Intel(R) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (DockLoginService) -- C:\Programme\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (btwdins) -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (RemoteAccess) -- C:\Windows\SysWOW64\mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) -- C:\Programme\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (AVGIDSHA) -- C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) -- C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Avgrkx64) -- C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) -- C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgfwfd) -- C:\Windows\SysNative\drivers\avgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (udfs) -- C:\Windows\SysNative\drivers\udfs.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btusbflt) -- C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BcmVWL) -- C:\Windows\SysNative\drivers\bcmvwl64.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (crcdisk) -- C:\Windows\SysNative\drivers\crcdisk.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ws2ifsl) -- C:\Windows\SysNative\drivers\ws2ifsl.sys (Microsoft Corporation)
DRV:64bit: - (cdfs) -- C:\Windows\SysNative\drivers\cdfs.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            )
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) -- c:\Programme\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3A 6E E5 3E D1 3F CC 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_270.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012.07.10 13:00:33 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2012.07.13 18:57:22 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Programme\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Programme\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" File not found
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [Userinit] C:\Users\User\AppData\Roaming\appconf32.exe ()
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk =  File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{693F8FD7-10A0-4C49-AF3B-0C3A7DACDBFF}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.08.04 22:12:02 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{AB46652C-EA65-4D79-AA28-72943C71233C}
[2012.08.04 22:11:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{BE3ADB68-FF63-4ACA-B786-99DD561BE1FA}
[2012.08.04 21:00:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{638E877C-6AD0-4008-B129-EABF8BEE2B0B}
[2012.08.04 09:01:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell Digital Delivery
[2012.08.04 09:00:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5770D851-4C31-40D2-B6A4-5C4FC434DE78}
[2012.08.04 08:59:59 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{482C6958-56E9-48E6-9F41-4379A295A301}
[2012.08.03 10:21:29 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{6A06AB9E-331A-4522-936C-60E350A76813}
[2012.08.03 10:21:18 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DB296FC7-EC7B-4741-860F-E1CF43E7D541}
[2012.08.02 10:12:24 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DEA8AF22-064C-41E3-A122-9647DA8AC79F}
[2012.08.02 10:12:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FADB0AA8-F410-43DC-AC2B-621C8B0793DF}
[2012.08.01 11:15:45 | 000,000,000 | ---D | C] -- C:\xmldm
[2012.08.01 11:06:01 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{676A967A-9C65-46A3-BC37-F1936060DE8A}
[2012.07.31 22:40:40 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E9D76724-941D-4B0A-B130-30FF88988212}
[2012.07.31 22:40:29 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A0725F4B-02BF-40F4-902D-742F8E5A7C49}
[2012.07.31 10:40:02 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{551A2B62-DCB3-4E19-B4F7-B27594AE64DF}
[2012.07.31 10:39:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D7931B58-704D-4C94-84EC-A056AB59803D}
[2012.07.30 22:39:24 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CEFCB1FE-FB49-469E-9173-155BE137A779}
[2012.07.30 22:39:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DB105D57-2EE4-478C-9FBD-D5AEF0736185}
[2012.07.30 10:38:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{47B7116F-EEFD-43C1-A228-EF5F8C242166}
[2012.07.30 10:38:33 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C4C5424C-ADFF-4926-BCBF-64F0FE4CB492}
[2012.07.29 12:09:48 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5970AC8D-9E72-4D05-AC25-A2C953B4EC79}
[2012.07.29 12:09:37 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{82595588-F6D3-44DC-9AB2-5AB9F6CD8327}
[2012.07.28 20:26:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\UAs
[2012.07.28 20:25:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\xmldm
[2012.07.28 20:23:36 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\kock
[2012.07.28 15:27:41 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FC66868C-C7EF-4002-9E84-683A00D5295B}
[2012.07.28 15:27:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C33EA805-E9A7-4DC7-ACBD-521CC5AD41BE}
[2012.07.27 09:32:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A497F376-5FD0-4FD7-A15E-720C7B419296}
[2012.07.27 09:31:55 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{EB357A54-9B0B-4632-9820-496B870C86EF}
[2012.07.26 10:25:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D8F436FF-80BB-4D45-8D2F-F83F114011DA}
[2012.07.26 10:25:12 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{EE6C2552-9AF1-49E0-8CD5-60D5CC17614A}
[2012.07.25 11:01:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E33952D1-A29E-4075-BB6E-4779E70E211E}
[2012.07.25 11:01:27 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A1F1E2B9-FA44-4171-BC35-5018AA506E9B}
[2012.07.24 23:01:01 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DBE69918-DBC0-4F22-BB65-2376CA0E2C7B}
[2012.07.24 23:00:49 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{2189D8E1-56AC-40AF-BB97-5A76FDEADBCE}
[2012.07.24 11:00:22 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CCD67941-E996-4D1E-9EBC-14420295ABA5}
[2012.07.24 11:00:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{DC506B5A-67F7-41E6-8A61-661771F145A3}
[2012.07.23 22:35:46 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D419D51E-FB97-41B6-8C6C-67609CBE8C5E}
[2012.07.23 22:35:35 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{1FA0F094-8F59-413F-87CA-5F942FDDBC72}
[2012.07.23 10:35:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{3D07EF7D-1687-4B1E-B9C5-61AAA1209229}
[2012.07.23 10:34:56 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C6F93F43-6D83-47F8-9155-2F68A564124C}
[2012.07.22 11:24:55 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A7E12FC9-4239-4B7C-95CC-538FAC586D67}
[2012.07.22 11:24:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{4A463954-748B-4A1A-9C87-CE75BF84C901}
[2012.07.21 12:57:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B1E43BF0-FB04-463A-A421-9CFA4F6F1721}
[2012.07.21 12:57:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{241083AA-79D4-4461-99F7-9F7A2814A42B}
[2012.07.21 12:40:28 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{20F684E3-34DB-4EF6-951C-30A2D7A15166}
[2012.07.20 10:07:32 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E58D979F-D0CC-42AF-AE29-8D0552E93FD4}
[2012.07.20 10:07:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{15C4207A-896F-443B-A683-6300F9255003}
[2012.07.19 11:42:57 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{3AD60E7C-17FB-472D-8C50-22352E64582B}
[2012.07.19 11:42:46 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{8E050761-E99B-4155-9374-69005C3B3847}
[2012.07.18 06:42:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{935FDD9B-3A19-47CC-A1D0-CF212B21D61E}
[2012.07.18 06:41:59 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{AF6015ED-175E-48C1-B600-3E26341CB060}
[2012.07.17 10:39:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012.07.17 10:33:33 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{0469DC95-7E18-4C7A-A9F0-90C7B01F7019}
[2012.07.17 10:33:21 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{31DADC7B-AA80-469E-BFD2-ABCB8E5677BE}
[2012.07.16 10:51:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{73E360DB-9A85-4BF7-BD74-266DD997CF74}
[2012.07.16 10:51:31 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D4A02685-FBCD-4119-913E-FBF90D81086B}
[2012.07.15 11:14:08 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{367074D5-44C4-46CB-9689-2EF8A5453614}
[2012.07.15 11:13:54 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B7BBFE75-BA46-4D33-93C7-CB38455D02B5}
[2012.07.14 19:24:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012.07.14 19:24:02 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.07.14 19:23:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2012.07.14 19:09:06 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2012.07.14 15:57:28 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{2BCE95AF-1B78-4113-AC4E-F986B479FB84}
[2012.07.14 15:57:16 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C4AC76DF-E2F6-46BF-83B8-5CDCCB9A9ABC}
[2012.07.13 18:51:28 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.07.13 18:49:03 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{964715D6-65B7-4FDB-9E16-8B492318992D}
[2012.07.13 18:48:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{91CCBEFD-358B-4033-8E89-223940692B0F}
[2012.07.13 06:48:21 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{26651714-16BB-4173-9FCB-0AE96CB9C910}
[2012.07.13 06:48:08 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CE49802F-A090-4567-B8BB-0D5A58B3EBCA}
[2012.07.12 10:02:08 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{20ADF425-EAC4-4303-A80B-2B446E817FAD}
[2012.07.12 10:01:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{5B6CA96E-E643-4C33-9E20-D4E116B2F232}
[2012.07.11 21:54:54 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C8B95A33-3208-481F-9FE9-4F4140398967}
[2012.07.11 21:54:42 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{26453121-246D-4F3A-8E88-347BC44E85C5}
[2012.07.11 09:54:11 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{3E6F9226-5A97-4007-AB0E-06814BB57394}
[2012.07.11 09:53:58 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{162B079F-7B8A-47A7-96BF-265F9F56D182}
[2012.07.10 13:01:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\AVG2012
[2012.07.10 13:01:41 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\AVG Secure Search
[2012.07.10 13:01:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
[2012.07.10 13:01:12 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG
[2012.07.10 13:00:29 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012.07.10 13:00:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2012.07.10 13:00:29 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG
[2012.07.10 12:59:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2012.07.10 12:55:00 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.07.10 12:55:00 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012.07.10 10:26:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{35EA5617-BAC1-41BA-AAE9-B3775A1E7E3A}
[2012.07.10 10:26:20 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{0D2365B2-8AAC-49A8-ABCF-82CDF1DF0BD2}
[2012.07.09 10:10:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{86ED858F-AA0F-4DC1-8EF2-83400EE6F79F}
[2012.07.09 10:09:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{9A43464A-5421-47F2-91D1-E4B218558BD7}
[2012.07.08 18:52:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{EFDD85E3-368A-4B48-8DEF-38762DB4B754}
[2012.07.08 18:52:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{B6210202-6E5F-43C3-99EF-540D7158E7F5}
[2012.07.07 15:49:33 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2012.07.07 15:48:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2012.07.07 15:48:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.07.07 15:48:36 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.07.07 15:48:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.07 15:48:22 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.07 15:48:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.07 15:48:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.07 15:24:48 | 000,000,000 | -HSD | C] -- C:\found.000
[2012.07.07 12:25:20 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012.07.06 09:02:33 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{BD658276-142E-484F-A398-E8C5188B962E}
[2012.07.06 09:02:20 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{865127F8-C981-47F8-A24E-0D9FC3E197F9}
[2 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
[1 C:\Users\User\AppData\Roaming\*.tmp files -> C:\Users\User\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.08.04 22:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.08.04 22:35:38 | 000,000,017 | ---- | M] () -- C:\Users\User\AppData\Roaming\blckdom.res
[2012.08.04 22:18:04 | 000,014,208 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.04 22:18:04 | 000,014,208 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.04 22:13:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.08.04 22:11:05 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.08.04 22:10:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.04 22:10:48 | 3113,230,336 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.04 20:29:06 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012.08.04 16:21:17 | 102,971,474 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012.08.03 16:29:58 | 000,065,076 | ---- | M] () -- C:\Users\User\Desktop\Anschreiben.pdf
[2012.08.02 19:25:06 | 000,198,366 | ---- | M] () -- C:\Users\User\Desktop\Marktanalyse Polen.pdf
[2012.08.02 17:50:05 | 000,000,028 | ---- | M] () -- C:\Users\User\AppData\Roaming\urhtps.dat
[2012.08.01 21:38:26 | 000,175,760 | ---- | M] () -- C:\Users\User\AppData\Roaming\AcroIEHelpe180.dll
[2012.08.01 21:38:26 | 000,006,400 | ---- | M] () -- C:\Users\User\AppData\Roaming\BAcroIEHelpe180.dll
[2012.08.01 12:20:48 | 000,160,660 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012.07.31 15:11:38 | 000,006,400 | ---- | M] () -- C:\Users\User\AppData\Roaming\BAcroIEHelpe179.dll
[2012.07.30 18:43:28 | 000,039,143 | ---- | M] () -- C:\Users\User\Desktop\1.jpg
[2012.07.30 14:28:47 | 000,334,628 | ---- | M] () -- C:\Users\User\Desktop\Lebenslauf_Slowikow.pdf
[2012.07.25 14:47:17 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012.07.25 10:31:00 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012.07.23 12:02:50 | 001,847,671 | ---- | M] () -- C:\Users\User\Desktop\ekspertyzy_MozliwosciwykorzystaniaOZE2020.pdf
[2012.07.17 12:14:25 | 001,613,412 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.17 12:14:25 | 000,697,098 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.07.17 12:14:25 | 000,652,376 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.17 12:14:25 | 000,148,362 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.07.17 12:14:25 | 000,121,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.17 10:39:23 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012.07.15 18:39:52 | 000,068,691 | ---- | M] () -- C:\Users\User\Desktop\vinyl.jpg
[2012.07.14 19:24:56 | 000,001,954 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.07.14 19:24:02 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.07.14 00:16:16 | 000,624,883 | ---- | M] () -- C:\Users\User\Desktop\adwcleaner0.exe
[2012.07.13 22:26:51 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.07.13 19:06:43 | 000,001,982 | ---- | M] () -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012.07.13 18:57:22 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012.07.12 17:13:40 | 000,405,144 | ---- | M] (Newtonsoft) -- C:\Windows\SysWow64\Newtonsoft.Json.Net20.dll
[2012.07.11 13:11:14 | 000,435,512 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.10 13:01:12 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012.07.10 13:01:12 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012.07.10 13:01:12 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012.07.10 11:52:12 | 000,017,840 | ---- | M] () -- C:\Users\User\Desktop\faggotkuchen.jpg
[2012.07.09 11:11:14 | 000,022,710 | ---- | M] () -- C:\Users\User\Desktop\Allgemeine Geschäftsbedingungen.pdf
[2012.07.07 15:48:36 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
[1 C:\Users\User\AppData\Roaming\*.tmp files -> C:\Users\User\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.08.04 16:21:17 | 102,971,474 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012.08.03 16:29:58 | 000,065,076 | ---- | C] () -- C:\Users\User\Desktop\Anschreiben.pdf
[2012.08.02 19:25:05 | 000,198,366 | ---- | C] () -- C:\Users\User\Desktop\Marktanalyse Polen.pdf
[2012.08.01 21:38:26 | 000,175,760 | ---- | C] () -- C:\Users\User\AppData\Roaming\AcroIEHelpe180.dll
[2012.08.01 21:38:26 | 000,006,400 | ---- | C] () -- C:\Users\User\AppData\Roaming\BAcroIEHelpe180.dll
[2012.08.01 12:20:48 | 000,160,660 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012.07.31 15:11:38 | 000,006,400 | ---- | C] () -- C:\Users\User\AppData\Roaming\BAcroIEHelpe179.dll
[2012.07.30 18:43:28 | 000,039,143 | ---- | C] () -- C:\Users\User\Desktop\1.jpg
[2012.07.30 14:28:19 | 000,334,628 | ---- | C] () -- C:\Users\User\Desktop\Lebenslauf_Slowikow.pdf
[2012.07.30 10:42:21 | 000,000,028 | ---- | C] () -- C:\Users\User\AppData\Roaming\urhtps.dat
[2012.07.28 20:25:11 | 000,000,017 | ---- | C] () -- C:\Users\User\AppData\Roaming\blckdom.res
[2012.07.27 09:39:20 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.25 09:01:08 | 000,000,564 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012.07.23 12:02:50 | 001,847,671 | ---- | C] () -- C:\Users\User\Desktop\ekspertyzy_MozliwosciwykorzystaniaOZE2020.pdf
[2012.07.20 10:08:34 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.20 10:08:33 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.15 18:41:44 | 000,068,691 | ---- | C] () -- C:\Users\User\Desktop\vinyl.jpg
[2012.07.14 19:24:56 | 000,001,954 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.07.14 00:15:49 | 000,624,883 | ---- | C] () -- C:\Users\User\Desktop\adwcleaner0.exe
[2012.07.13 19:06:43 | 000,001,982 | ---- | C] () -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012.07.10 13:01:40 | 000,000,981 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012.07.10 13:01:12 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012.07.10 13:01:12 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012.07.10 13:01:12 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012.07.10 11:53:15 | 000,017,840 | ---- | C] () -- C:\Users\User\Desktop\faggotkuchen.jpg
[2012.07.09 10:59:24 | 000,022,710 | ---- | C] () -- C:\Users\User\Desktop\Allgemeine Geschäftsbedingungen.pdf
[2012.07.07 15:48:36 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.07 15:48:23 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2012.01.24 17:06:10 | 001,591,306 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.12.30 18:15:58 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2011.07.14 22:02:34 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.07.07 19:49:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.06.26 15:39:54 | 000,002,137 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.07.10 13:01:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG2012
[2012.07.14 19:22:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2012.02.16 12:10:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Pro
[2012.04.23 09:36:36 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Downloaded Installations
[2012.07.29 19:19:07 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DVDVideoSoft
[2012.06.03 13:14:39 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.07.28 20:23:36 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\kock
[2011.07.11 17:38:43 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\OpenOffice.org
[2012.02.16 12:41:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Origin
[2012.03.14 14:13:36 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PCDr
[2011.09.15 14:59:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SharePod
[2012.03.13 18:57:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Simfy
[2011.07.14 22:06:42 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Synaptics
[2012.01.26 12:33:39 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Titanium
[2011.12.31 00:58:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\tmp
[2012.08.01 15:00:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\UAs
[2011.07.12 20:28:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Windows Live Writer
[2012.01.24 16:44:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\WindSolutions
[2011.09.19 19:27:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Xilisoft
[2012.08.04 22:18:38 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\xmldm
[2012.07.25 10:31:00 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012.07.25 14:47:17 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012.07.03 15:41:31 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.08.04 20:29:06 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 

< End of report >
         

komischerweise ist es auf dem anderen laptop im haushalt ebenfalls drauf. allerdings habe ich es auf diesem nur gefunden, weil der andere zu erst die warnung brachte. daraufhin hab ich diesen laptop ebenfalls gescannt und bin fündig geworden..leider.


bitte um erneute hilfe!!
besten dank,
jule

Alt 06.08.2012, 19:31   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
neue INfektion: Trojan.Banker, Backdoor.Agent - Standard

neue INfektion: Trojan.Banker, Backdoor.Agent



Hab ich dich in dem anderen Strang über BankingTrojaner nicht ausreichend aufgeklärt?

Ich mein das ist wirklich gut, dass du bei Logs von anderen Rechnern einen neuen Strang aufmachst aber willst du diese Kisten wirklich bereinigen?
__________________

__________________

Alt 11.08.2012, 17:40   #3
dk-jule
 
neue INfektion: Trojan.Banker, Backdoor.Agent - Standard

neue INfektion: Trojan.Banker, Backdoor.Agent



da wir online banking betreiben werde ich windows mit dem recovery image neu aufspielen.
danke für deine hilfe auch im anderen thread! wenn alles sauber ist, gibts ne spende.

gruß,
jule
__________________

Alt 12.08.2012, 18:41   #4
dk-jule
 
neue INfektion: Trojan.Banker, Backdoor.Agent - Standard

neue INfektion: Trojan.Banker, Backdoor.Agent



hallo arne,

woher weiß ich, ob jetzt nach der Neuinstallation meines systems (via recovery image des laptop herstellers) alles wirklich in ordnung ist?
nützen die logfiles eines OTL und Malwarebytes Quick Scans, um zu gucken, ob da nun alles ok ist?

beste Grüße,
Jule

Antwort

Themen zu neue INfektion: Trojan.Banker, Backdoor.Agent
.dll, acroiehelpe180.dll, administrator, adobe, adwcleaner, autorun, avg, avg secure search, bacroiehelpe180.dll, bho, bonjour, browser, converter, document, explorer, firefox, flash player, format, google earth, helper, home, kaspersky, langs, logfile, mp3, plug-in, realtek, registry, secure search, software, vtoolbarupdater, warnung, wlan, wmi



Ähnliche Themen: neue INfektion: Trojan.Banker, Backdoor.Agent


  1. 2 Trojaner eingefangen durch E-Mail-Anhänge // Trojan-Banker.Win32.Agent.ubo und Trojan.Win32.Yakes.ghny
    Log-Analyse und Auswertung - 19.07.2015 (28)
  2. Infektion mit Trojan.Agent.SVR, SearchProtectA und anderes
    Log-Analyse und Auswertung - 03.10.2014 (13)
  3. Mailwarebytes meldet Infektion- Trojan.Agent...
    Log-Analyse und Auswertung - 18.12.2013 (5)
  4. Trojan.Agent und Backdoor.Agent eingefangen
    Plagegeister aller Art und deren Bekämpfung - 29.11.2013 (18)
  5. WinXp Trojan.Agent/Gen-Reputation Stolen.Data Trojan.Agent/Gen-DunDun Win32/Spy.Banker.YPK trojan
    Log-Analyse und Auswertung - 29.10.2013 (7)
  6. Nach Wiederherstellung Trojan.Banker und Backdoor.bot gefunden
    Log-Analyse und Auswertung - 13.10.2013 (29)
  7. Mehrere Trojaner (trojan.banker, trojan.agent), pup.funmoods
    Log-Analyse und Auswertung - 01.05.2013 (6)
  8. Trojan.Downloader, Trojan.Agent.VGENX, Trojan.Agent, PUP.Pantsoff.PasswordFinder, TR/spy.banker.gen5
    Log-Analyse und Auswertung - 27.10.2012 (1)
  9. Trojan.Banker, Trojan.Agent, Stolen.Data, Malware.Trace, was nun?
    Log-Analyse und Auswertung - 07.10.2012 (1)
  10. Trojaner Remover zeigt Trojan.Spy.Banker und ROOTKIT.AGENT
    Plagegeister aller Art und deren Bekämpfung - 25.07.2012 (1)
  11. Trojan.Agent, Backdoor.Agent, Trojan.Banker > 10 Trojaner auf einem PC
    Log-Analyse und Auswertung - 22.07.2012 (0)
  12. EXP/2008-5353.AO TR/Kazy.80527.3 Trojan.BT.Soft.Gen Trojan.Banker Trojan.Agent
    Plagegeister aller Art und deren Bekämpfung - 14.07.2012 (5)
  13. Trojan.Agent,Trojan.Banker,PUP.Blabbers .
    Plagegeister aller Art und deren Bekämpfung - 13.07.2012 (3)
  14. Trojan.Banker und Backdoor.Agent mit Malwarebytes entfernt - weitere Schritte nötig?
    Plagegeister aller Art und deren Bekämpfung - 19.06.2012 (3)
  15. Trojan.Banker, Trojan.Agent u.a.
    Plagegeister aller Art und deren Bekämpfung - 16.07.2009 (18)
  16. Win32.Banker.FS.Trojan.Spay.Agent.DA
    Log-Analyse und Auswertung - 21.02.2009 (5)
  17. Trojan.Banker.VB.0D9D0998 und Trojan-Dropper.Win32.Agent.wd
    Log-Analyse und Auswertung - 04.10.2005 (2)

Zum Thema neue INfektion: Trojan.Banker, Backdoor.Agent - Hey, leider gibt es auf dem PC meines Freundes (und meiner auch, aber dazu in nem neuen Thread) wieder einen Trojaner. Win7, 64bit Folgende Scans bereits durchgeführt: Malwarebytes Quickscan Logfile: - neue INfektion: Trojan.Banker, Backdoor.Agent...
Archiv
Du betrachtest: neue INfektion: Trojan.Banker, Backdoor.Agent auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.