Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Bundestrojaner sperrt Win7

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 25.06.2012, 10:35   #1
greggy
 
Bundestrojaner sperrt Win7 - Standard

Bundestrojaner sperrt Win7



Hallo,

also ich habe mir einen Bundestrojaner eingefangen der beim Hochfahren von Win7 den Rechner sperrt.
Kann mir jemand helfen das Ding wieder los zu werden?
Die OTL Disk hätte ich nach lesen der anderen Beiträge schon mal erstellt. Aber was jetz? Einfach den Scan laufen lassen und die Log posten?
Vielen Dank schon mal.

Alt 25.06.2012, 11:56   #2
Chris4You
 
Bundestrojaner sperrt Win7 - Standard

Bundestrojaner sperrt Win7



Hi,

ja (und beten das nichts verschlüsselt wurde ;o)...

chris
__________________

__________________

Alt 25.06.2012, 12:25   #3
greggy
 
Bundestrojaner sperrt Win7 - Standard

Bundestrojaner sperrt Win7



Hi,

Also beten tue ich jetzt schon seit einigen Stunden ;-)
Unten also jetzt der die Log Datei. Ich hoffe das passt so.

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 6/25/2012 5:15:54 PM - Run 
OTLPE by OldTimer - Version 3.1.48.0     Folder = X:\Programs\OTLPE
Windows 7 Professional  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 125.00 Gb Total Space | 84.65 Gb Free Space | 67.72% Space Free | Partition Type: NTFS
Drive F: | 107.88 Gb Total Space | 14.16 Gb Free Space | 13.13% Space Free | Partition Type: NTFS
Drive X: | 3.73 Gb Total Space | 2.83 Gb Free Space | 75.94% Space Free | Partition Type: FAT
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto] --  -- (z525bus)
SRV - File not found [Auto] --  -- (yats32)
SRV - File not found [Auto] --  -- (WmXlCore)
SRV - File not found [Auto] --  -- (WimFltr)
SRV - File not found [Auto] --  -- (wcontrol)
SRV - File not found [Auto] --  -- (vzupsvc)
SRV - File not found [Auto] --  -- (USBVCD)
SRV - File not found [Auto] --  -- (usbbus)
SRV - File not found [Auto] --  -- (tvichw32)
SRV - File not found [Auto] --  -- (TUWinStylerThemeSvc)
SRV - File not found [Auto] --  -- (transbaseservice)
SRV - File not found [Auto] --  -- (TPM)
SRV - File not found [Auto] --  -- (tosrfec)
SRV - File not found [Auto] --  -- (tbiosdrv)
SRV - File not found [Auto] --  -- (symmpi)
SRV - File not found [Auto] --  -- (swupdtmr)
SRV - File not found [Auto] --  -- (steamdvr)
SRV - File not found [Auto] --  -- (spcstb)
SRV - File not found [Auto] --  -- (SNPSTD3)
SRV - File not found [Auto] --  -- (Slpsvdr)
SRV - File not found [Auto] --  -- (SiRemFil)
SRV - File not found [Auto] --  -- (sgeclient)
SRV - File not found [Auto] --  -- (ser2pl)
SRV - File not found [Auto] --  -- (sbhooksvc)
SRV - File not found [Auto] --  -- (rkhdrv31)
SRV - File not found [Auto] --  -- (RecAgent)
SRV - File not found [Auto] --  -- (radiosvr)
SRV - File not found [Auto] --  -- (pshost)
SRV - File not found [Auto] --  -- (pelmouse)
SRV - File not found [Auto] --  -- (pdlncbas)
SRV - File not found [Auto] --  -- (ovepstatusengine)
SRV - File not found [Auto] --  -- (NWSIPX32)
SRV - File not found [Auto] --  -- (nv4)
SRV - File not found [Auto] --  -- (ntservice1)
SRV - File not found [Auto] --  -- (nsm1mdm)
SRV - File not found [Auto] --  -- (npfmntor)
SRV - File not found [Auto] --  -- (nmsaccess)
SRV - File not found [Auto] --  -- (nalntservice)
SRV - File not found [Auto] --  -- (mxssvr)
SRV - File not found [Auto] --  -- (mr7910)
SRV - File not found [Auto] --  -- (lyncusbserv)
SRV - File not found [Auto] --  -- (lvckap)
SRV - File not found [Auto] --  -- (ltmodem5)
SRV - File not found [Auto] --  -- (konfig)
SRV - File not found [Auto] --  -- (issvc)
SRV - File not found [Auto] --  -- (issm)
SRV - File not found [Auto] --  -- (ipinip)
SRV - File not found [Auto] --  -- (ipahelper.exe)
SRV - File not found [Auto] --  -- (ICAM3NT5)
SRV - File not found [Auto] --  -- (iap)
SRV - File not found [Auto] --  -- (i2omgmt)
SRV - File not found [Auto] --  -- (hpn)
SRV - File not found [Auto] --  -- (eSettingsService)
SRV - File not found [Auto] --  -- (enxpsvr)
SRV - File not found [Auto] --  -- (enxpsvc)
SRV - File not found [Auto] --  -- (digirefresh)
SRV - File not found [Auto] --  -- (digictrl)
SRV - File not found [Auto] --  -- (dbustrcm)
SRV - File not found [Auto] --  -- (cqmghost)
SRV - File not found [Auto] --  -- (com0com)
SRV - File not found [Auto] --  -- (clisvc)
SRV - File not found [Auto] --  -- (Cam5603D)
SRV - File not found [Auto] --  -- (cachemanxp)
SRV - File not found [Auto] --  -- (btnhnd)
SRV - File not found [Auto] --  -- (bcoreusb)
SRV - File not found [Auto] --  -- (BCMTPM)
SRV - File not found [Auto] --  -- (basfipm)
SRV - File not found [Auto] --  -- (avidsdmservice)
SRV - File not found [Auto] --  -- (aliadwdm)
SRV - File not found [Auto] --  -- (AffinegyService)
SRV - File not found [Auto] --  -- (aexnsclient)
SRV - File not found [Auto] --  -- (adpu160m)
SRV - File not found [Auto] --  -- (AcronisOSSReinstallSvc)
SRV - [2012/05/21 19:24:57 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service)
SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield)
SRV - [2011/09/29 10:44:32 | 002,498,560 | ---- | M] () [Auto] -- C:\Program Files\McAfee\EEGo\EegoService.exe -- (McAfee EEGo)
SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent)
SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr)
SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim)
SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService)
SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService)
SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr)
SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand] --  -- (FirehkMP)
DRV - File not found [Kernel | On_Demand] --  -- (Firehk)
DRV - [2011/11/01 05:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 05:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 05:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 05:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp)
DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn)
DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog)
DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp)
DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter)
DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ)
DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm)
DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM)
DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM)
DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl)
DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr)
DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis)
DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum)
DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps)
DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard)
DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt)
DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R)
DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr)
DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It)
DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID)
DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV)
DRV - [2007/01/24 10:27:54 | 000,039,704 | ---- | M] (Belcarra Technologies) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rcblan.sys -- (RemoteControl-USBLAN)
DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://mywikis.tycoelectronics.com/cm/wiki/?id=10294
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy
 
IE - HKU\EG005689_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://mywikis.tycoelectronics.com/cm/wiki/?id=10294
IE - HKU\EG005689_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy
 
IE - HKU\EG011222_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\EG011222_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://myte.tycoelectronics.com/portal/server.pt?PageID=0&parentname=Login&parentid=1&CommunityID=256&space=CommunityPage&control=SetCommunity&cached=false&in_hi_userid=104876
IE - HKU\EG011222_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\EG011222_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy
 
 
 
IE - HKU\SMSAccess_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M]
 
[2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
 
Hosts file not found
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\EG011222_ON_C\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKU\EG011222_ON_C\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [dcmsvc] C:\Program Files\dcmsvc\dcmsvc.exe ()
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.)
O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
O4 - HKU\EG011222_ON_C..\Run: []  File not found
O4 - HKU\EG011222_ON_C..\Run: [7Rxb5FismTZydeX]  File not found
O4 - HKU\EG011222_ON_C..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKU\EG011222_ON_C..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O4 - HKU\EG011222_ON_C..\Run: [X1FileMonitor.exe] C:\Program Files\X1\X1FileMonitor.exe ()
O4 - HKU\LocalService_ON_C..\Run: [Sidebar]  File not found
O4 - HKU\NetworkService_ON_C..\Run: [Sidebar]  File not found
O4 - HKU\SMSAccess_ON_C..\Run: [Sidebar]  File not found
O4 - HKU\EG005689_ON_C..\RunOnce: [SetupRevertTELogo] C:\Apps\TECApps\SetupRevertTELogo.exe ()
O4 - HKU\EG011222_ON_C..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe (Adobe Systems Incorporated)
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\SMSAccess_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPhoneExplorer.lnk ()
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Office Keyboard.exe ()
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warner Bros.lnk ()
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\X1 System Tray.lnk ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\EG005689_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\EG005689_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\EG011222_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\SMSAccess_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000044 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000045 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000046 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000047 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000048 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000049 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000050 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000051 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000052 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000053 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000054 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000055 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000056 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000057 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000058 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000059 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000060 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000061 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000062 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000063 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000064 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000065 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000066 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000067 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000068 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000069 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000070 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000071 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000072 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000073 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000074 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000075 -  File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKU\EG011222_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ecojink: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll -  File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1dab4fdb-6116-11e0-839c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1dab4fdb-6116-11e0-839c-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/06/25 04:47:38 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\NPE
[2012/06/24 20:26:57 | 000,000,000 | ---D | C] -- C:\NPE
[2012/06/24 20:26:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2012/06/24 19:06:19 | 000,000,000 | ---D | C] -- C:\NBRT
[2012/06/22 13:11:24 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/06/22 09:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\egvixvcletcqitf
[2012/06/21 20:03:26 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\Mozilla
[2012/06/21 09:06:42 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1F484A5F-3B4F-4B28-BEDF-E27115B582F5}
[2012/06/21 09:06:20 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{40128DC9-A673-4F4C-8993-82A501B5C9B4}
[2012/06/20 05:15:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{89FBBE95-9710-4104-9ED3-B337ACFE728A}
[2012/06/20 05:15:30 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{0B6D5AC8-7D22-4FF4-900B-F7898B4A3976}
[2012/06/20 02:24:00 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B94F1FFE-CFB8-4DA4-890B-9C97863D79FF}
[2012/06/20 02:19:03 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{D829BDE5-7A5F-4874-8835-D1398A74577B}
[2012/06/20 02:15:08 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{81659A2B-17B2-4F6F-AA2A-3E02A62BD734}
[2012/06/19 04:26:11 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B6C49E82-062F-496A-8ECC-5E5C606CACCE}
[2012/06/19 04:25:54 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{39CF9DA7-9F42-44FB-920C-E117251DEB5B}
[2012/06/19 02:54:39 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\.salesforce.com
[2012/06/19 02:54:37 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\salesforce.com
[2012/06/19 02:54:37 | 000,000,000 | ---D | C] -- C:\ProgramData\salesforce.com
[2012/06/19 02:52:24 | 000,000,000 | ---D | C] -- C:\Program Files\salesforce.com
[2012/06/18 05:12:43 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{72C8C4AE-44DC-4533-ACE5-D06A04A2379C}
[2012/06/17 06:42:52 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1D2A4A4E-B3D2-4AA9-9F87-C92511618ADC}
[2012/06/14 04:54:30 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{43F24588-D02C-4408-A6A5-0061ECDE2FF5}
[2012/06/14 04:20:48 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{041B35CC-6060-4C69-B7AA-6EC9C05854FD}
[2012/06/13 08:31:55 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{9458F21D-65AB-43BB-BC37-A91E4F54704C}
[2012/06/13 08:31:35 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{3F0F1BF6-A91B-4498-8373-0F9C7A548612}
[2012/06/13 08:07:55 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{10EA408A-F370-4D9D-B534-EE878AE683DB}
[2012/06/11 15:07:48 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{468BB37E-322C-4546-8DB5-CADF6FE816E8}
[2012/06/10 13:48:45 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{5781FDF2-A01C-4504-870B-A570E9CC24CB}
[2012/06/07 17:04:06 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{4193B25C-65F4-4451-B1C3-A220E23DEF27}
[2012/06/05 14:42:27 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{BD37A6E8-51C3-4B7F-8F51-CBEAE17D439F}
[2012/06/05 14:42:06 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{8250949A-A41A-49E6-BC2A-27589F896F6B}
[2012/06/03 09:21:33 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{157D3603-8789-452C-81AE-295C1176437E}
[2012/06/03 09:21:10 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{7A901744-F987-46E4-9864-F644E5E55C65}
[2012/06/02 14:50:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{AE5993DB-7119-4200-BEBD-5ACA400074F9}
[2012/06/01 05:15:21 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B729E639-C1AE-4261-915A-2933B3FD62DA}
[2012/06/01 04:50:44 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{02628924-0716-41F2-94ED-D12EA2B0C627}
[2012/05/30 03:41:56 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{DEA7767A-0FD8-4056-9A81-4DE6A151096F}
[2012/05/30 03:41:42 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B0478902-55DB-499B-B4DB-91E865B52374}
[2012/05/29 16:13:09 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{344BF6F8-DD81-48DE-B707-F97D6739A941}
[2012/05/29 02:30:58 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{C1839AB4-0F1D-4673-9F34-33D8C929F41B}
[2012/05/29 02:27:35 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{28645085-0D13-4ACB-BFD6-B968E004D3CD}
[2012/05/28 18:49:22 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{C50E0260-1456-4DB3-8725-AA147D68F1F1}
[2012/05/28 18:11:54 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{62026264-D041-4062-9BAA-B5CA7EFA13A0}
[2012/05/28 17:53:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{755B7984-437E-43E7-9AA3-D7718774A4CE}
[2012/05/28 17:06:32 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{F8627BBB-A9C5-44DC-9B01-B0481E84C516}
[2012/05/28 17:03:09 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1DB5DBC7-D1DA-41F4-A35A-24458644E564}
[2012/05/28 14:13:37 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{A110C5EC-813F-4B66-A94B-E338D5C42F4B}
[2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe
[2007/08/13 11:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\EG011222\AppData\Local\CDRip.dll
[2007/01/18 15:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\EG011222\AppData\Local\No23 Recorder.exe
[2006/12/11 13:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\EG011222\AppData\Local\basscd.dll
[2006/12/11 13:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\EG011222\AppData\Local\bass.dll
[1 C:\Users\EG011222\AppData\Roaming\*.tmp files -> C:\Users\EG011222\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/06/25 10:09:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/25 10:09:30 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 10:09:30 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 10:08:59 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini
[2012/06/25 10:08:18 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/25 10:06:18 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/25 09:48:35 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/06/25 09:48:35 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/06/25 09:48:35 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/25 09:48:35 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/25 09:45:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job
[2012/06/25 06:44:13 | 000,000,298 | ---- | M] () -- C:\ProgramData\SMRResults300.dat
[2012/06/25 04:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/24 10:45:08 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_trash_log.cmd
[2012/06/24 07:53:50 | 000,003,600 | ---- | M] () -- C:\bootsqm.dat
[2012/06/24 06:14:19 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/24 00:45:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job
[2012/06/22 09:44:25 | 000,000,052 | ---- | M] () -- C:\ProgramData\kwztyvvcmhovudt
[2012/06/22 09:44:19 | 000,061,440 | ---- | M] () -- C:\ProgramData\tddanntg.exe
[2012/06/22 09:44:19 | 000,061,440 | ---- | M] () -- C:\ProgramData\ohpfgkae.exe
[2012/06/21 09:25:58 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/06/20 07:33:35 | 000,061,666 | ---- | M] () -- C:\Users\EG011222\Desktop\TGV Buchungsbestätigung.pdf
[2012/06/20 07:26:14 | 000,106,366 | ---- | M] () -- C:\Users\EG011222\Desktop\LE_MANS_GARE-CHARLES_DE_GAULLE_2_TGV_20-06-12.pdf
[2012/06/20 02:22:13 | 000,002,486 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012/06/19 02:41:58 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/06/19 02:41:47 | 000,023,745 | ---- | M] () -- C:\Users\EG011222\AppData\Roaming\Microsoft Excel.ADR
[2012/06/17 06:50:56 | 000,021,504 | ---- | M] () -- C:\Windows\jestertb.dll
[1 C:\Users\EG011222\AppData\Roaming\*.tmp files -> C:\Users\EG011222\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/06/25 06:44:13 | 000,000,298 | ---- | C] () -- C:\ProgramData\SMRResults300.dat
[2012/06/24 07:53:50 | 000,003,600 | ---- | C] () -- C:\bootsqm.dat
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\tddanntg.exe
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\ohpfgkae.exe
[2012/06/22 09:44:20 | 000,000,052 | ---- | C] () -- C:\ProgramData\kwztyvvcmhovudt
[2012/06/20 07:33:34 | 000,061,666 | ---- | C] () -- C:\Users\EG011222\Desktop\TGV Buchungsbestätigung.pdf
[2012/06/20 07:26:14 | 000,106,366 | ---- | C] () -- C:\Users\EG011222\Desktop\LE_MANS_GARE-CHARLES_DE_GAULLE_2_TGV_20-06-12.pdf
[2012/06/17 06:50:56 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll
[2012/04/09 04:47:24 | 000,001,497 | ---- | C] () -- C:\Users\EG011222\AppData\Local\RecConfig.xml
[2012/03/15 05:30:20 | 000,005,624 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\BAcroIEHelpe087.dll
[2012/03/14 05:38:45 | 000,005,624 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\BAcroIEHelpe086.dll
[2012/03/13 09:02:59 | 000,003,584 | ---- | C] () -- C:\Users\EG011222\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/18 08:31:25 | 000,007,667 | ---- | C] () -- C:\Users\EG011222\AppData\Local\Resmon.ResmonCfg
[2011/11/07 18:38:45 | 000,000,008 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\pij8405e9rx3klvv.dat
[2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp
[2011/09/05 09:32:47 | 000,023,745 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\Microsoft Excel.ADR
[2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll
[2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe
[2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp
[2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat
[2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat
[2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini
[2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin
[2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll
[2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll
[2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll
[2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll
[2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll
[2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini
[2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI
[2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini
[2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll
[2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll
[2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll
[2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll
[2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll
[2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll
[2007/08/13 11:46:00 | 000,155,136 | ---- | C] () -- C:\Users\EG011222\AppData\Local\lame_enc.dll
[2006/10/25 19:06:48 | 000,064,000 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbisenc.dll
[2006/10/25 19:06:48 | 000,019,456 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbisfile.dll
[2006/10/25 19:06:46 | 000,143,872 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbis.dll
[2006/10/25 19:06:36 | 000,015,872 | ---- | C] () -- C:\Users\EG011222\AppData\Local\ogg.dll
[2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll
[2005/08/23 16:34:06 | 000,029,184 | ---- | C] () -- C:\Users\EG011222\AppData\Local\no23xwrapper.dll
[2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
 
========== LOP Check ==========
 
[2011/04/07 09:37:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ICAClient
[2011/04/08 04:54:30 | 000,000,000 | ---D | M] -- C:\Users\EG005689\AppData\Roaming\ICAClient
[2011/04/15 06:15:03 | 000,000,000 | ---D | M] -- C:\Users\EG005689\AppData\Roaming\Vodafone
[2012/06/20 09:38:19 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\.oit
[2012/06/19 02:54:39 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\.salesforce.com
[2011/12/22 16:29:23 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\1&1 Mail & Media GmbH
[2012/01/20 09:11:39 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Aventail
[2012/04/09 06:52:49 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1
[2012/04/20 15:34:22 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\DVDVideoSoft
[2011/12/23 16:59:09 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/06/07 09:25:44 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Foxit
[2011/06/07 09:25:45 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Foxit Software
[2011/04/08 05:41:08 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\ICAClient
[2012/05/24 12:24:37 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\inkscape
[2012/05/02 12:03:23 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Itsth
[2012/03/05 03:32:05 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\kock
[2011/04/29 05:03:34 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Leadertech
[2012/05/28 14:31:53 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\MyPhoneExplorer
[2012/02/06 06:15:40 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia
[2011/05/31 19:05:49 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia Ovi Suite
[2012/02/06 06:17:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia Suite
[2011/05/31 19:05:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\PC Suite
[2012/03/11 11:31:48 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\RavensburgerTipToi
[2012/06/19 02:54:37 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\salesforce.com
[2011/04/28 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\SAP
[2012/03/13 16:17:14 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\UAs
[2011/04/08 06:05:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Vodafone
[2011/04/28 15:50:10 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Vodafone Mobile Connect
[2012/03/13 16:17:57 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\xmldm
[2012/05/22 13:49:52 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\XnView
[2011/12/23 16:54:22 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Youtube Downloader HD
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications
[2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail
[2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom
[2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2012/06/22 09:44:24 | 000,000,000 | ---D | M] -- C:\ProgramData\egvixvcletcqitf
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia
[2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount
[2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache
[2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi
[2012/06/19 02:54:37 | 000,000,000 | ---D | M] -- C:\ProgramData\salesforce.com
[2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2012/05/02 12:51:41 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb
[2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2012/05/17 14:50:32 | 000,000,000 | ---D | M] -- C:\ProgramData\Windows
[2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip
[2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater
[2012/05/07 04:12:47 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9FF7C773
< End of report >
         
--- --- ---

[/CODE]
__________________

Alt 25.06.2012, 13:47   #4
Chris4You
 
Bundestrojaner sperrt Win7 - Standard

Bundestrojaner sperrt Win7



Hi,

Script auf USB-Stick kopieren, von OTL-Disk booten, rüberkopieren und wie folgt verfahren:

By teh way: Du hast die Enterpriseedition (McAfee) im Einsatz, ist das ein Firmenrechner (auch die Cloudlösung spricht dafür)... Dann muß sich eigentlich der Sysadmin darum kümmern...

Fix für OTL:
  • Doppelklick auf die OTL.exe, um das Programm auszuführen.
  • Vista/Win7-User bitte per Rechtsklick und "Ausführen als Administrator" starten.
  • Kopiere den Inhalt der folgenden Codebox komplett in die OTL-Box unter "Custom Scan/Fixes"

Code:
ATTFilter
:OTL
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O4 - HKU\EG011222_ON_C..\Run: []  File not found
O4 - HKU\EG011222_ON_C..\Run: [7Rxb5FismTZydeX]  File not found
O4 - HKU\EG011222_ON_C..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O20 - Winlogon\Notify\ecojink: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll -  File not found
[2012/06/25 04:47:38 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\NPE
[2012/06/22 09:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\egvixvcletcqitf
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\tddanntg.exe
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\ohpfgkae.exe
[2012/06/22 09:44:20 | 000,000,052 | ---- | C] () -- C:\ProgramData\kwztyvvcmhovudt
[2012/06/17 06:50:56 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll
[2012/06/22 09:44:24 | 000,000,000 | ---D | M] -- C:\ProgramData\egvixvcletcqitf
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9FF7C773

:Commands
[emptytemp]
[resethosts]
[createrestorepoint]
[Reboot]
         
  • Den roten Run Fixes! Button anklicken.
  • Bitte alles aus dem Ergebnisfenster (Results) herauskopieren.
  • Eine Kopie eines OTL-Fix-Logs wird in einer Textdatei in folgendem Ordner gespeichert:
  • %systemroot%\_OTL

Der Rechner sollte jetzt wieder booten...

Malwarebytes Antimalware (MAM)
Anleitung&Download hier: http://www.trojaner-board.de/51187-m...i-malware.html
Falls der Download nicht klappt, bitte hierüber eine generische Version runterladen:
http://filepony.de/download-chameleon/
Danach bitte update der Signaturdateien (Reiter "Aktualisierungen" -> Suche nach Aktualisierungen")
Fullscan und alles bereinigen lassen! Log posten.

chris
__________________
Don't bring me down
Vor dem posten beachten!
Spenden
(Wer spenden will, kann sich gerne melden )

Alt 25.06.2012, 14:27   #5
greggy
 
Bundestrojaner sperrt Win7 - Standard

Bundestrojaner sperrt Win7



Hi,

also erst mal vielen Dank für die Hilfe. Ich kann zumindest mal wieder hochfahren.
Das mit dem Firmenrechner ist nicht ganz richtig. Das ist ein ehemaliger Rechner meiner Firma. Den hab ich so wie er jetzt ist gekauft.
Das es da eine Cloudlösung gibt ist mir noch nicht einmal bekannt ;-)

Ist das nur allgemein oder soll ich auch das LOG von Malwarebytes posten?

greggy


Alt 25.06.2012, 17:52   #6
Chris4You
 
Bundestrojaner sperrt Win7 - Standard

Bundestrojaner sperrt Win7



Hi,

bitte beide Logs posten... (OTL, MAM)...

chris
__________________
--> Bundestrojaner sperrt Win7

Antwort

Themen zu Bundestrojaner sperrt Win7
andere, anderen, beiträge, bundes, bundestrojaner, bundestrojaner eingefangen, einfach, eingefangen, erstell, gefangen, gen, hochfahren, laufe, laufen, log, poste, posten, rechner, scan, sperrt, win, win7



Ähnliche Themen: Bundestrojaner sperrt Win7


  1. Win7, Google Chrome, Einblendungen ähnlich Bundestrojaner
    Log-Analyse und Auswertung - 11.11.2015 (9)
  2. Bundestrojaner sperrt alle zugänge zur GUI (Windows 7)
    Plagegeister aller Art und deren Bekämpfung - 26.11.2014 (3)
  3. Provider sperrt Internetzugang nach Spamversand (Befall unter Win7 Home Prem x64?)
    Plagegeister aller Art und deren Bekämpfung - 04.07.2014 (15)
  4. Div. Bluescreens bei Win7 und Win7-Installation nach durchgeb. Netzteil
    Alles rund um Windows - 24.11.2013 (8)
  5. Bundestrojaner (noch?) auf Win7 32bit-Rechner nach ESET-Bereinigug?
    Log-Analyse und Auswertung - 09.11.2013 (11)
  6. Win7, Bundestrojaner eingefangen, nicht im Admin-Nutzer - Wie vorgehen?
    Plagegeister aller Art und deren Bekämpfung - 09.10.2013 (13)
  7. GVU / Bundestrojaner auf Win7-PC (Standrechner)
    Log-Analyse und Auswertung - 28.07.2013 (11)
  8. GVU Trojaner mit webcambild sperrt win7
    Log-Analyse und Auswertung - 27.06.2013 (1)
  9. Bundestrojaner sperrt Laptop
    Plagegeister aller Art und deren Bekämpfung - 13.03.2013 (23)
  10. WIN7 GVU-Virus sperrt den PC
    Plagegeister aller Art und deren Bekämpfung - 16.01.2013 (1)
  11. Bundestrojaner auf WIN7 / 64bit System
    Log-Analyse und Auswertung - 06.10.2012 (15)
  12. GVU Bundestrojaner mit Webcam - Win7
    Log-Analyse und Auswertung - 20.07.2012 (17)
  13. UKash/Bundestrojaner sperrt System
    Log-Analyse und Auswertung - 02.04.2012 (1)
  14. Bundestrojaner auf win7 64 Bit System
    Log-Analyse und Auswertung - 24.03.2012 (3)
  15. Bundestrojaner win7 64 bit
    Plagegeister aller Art und deren Bekämpfung - 20.03.2012 (19)
  16. Bundestrojaner entfernen Win7 64bit Standardbenutzer-Account befallen
    Plagegeister aller Art und deren Bekämpfung - 27.10.2011 (22)
  17. Bundestrojaner sperrt meinen Computer
    Log-Analyse und Auswertung - 19.08.2011 (23)

Zum Thema Bundestrojaner sperrt Win7 - Hallo, also ich habe mir einen Bundestrojaner eingefangen der beim Hochfahren von Win7 den Rechner sperrt. Kann mir jemand helfen das Ding wieder los zu werden? Die OTL Disk hätte - Bundestrojaner sperrt Win7...
Archiv
Du betrachtest: Bundestrojaner sperrt Win7 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.