![]() |
|
Log-Analyse und Auswertung: GVU Trojaner mit WebCam: TR/Rogue.kdv.683070 und EXP/2012-0507.CZ.3Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() GVU Trojaner mit WebCam: TR/Rogue.kdv.683070 und EXP/2012-0507.CZ.3 Hallo zusammen, ich habe mir einen GVU Trojaner eingefangen: 2 mal bisher kam beim Surfen mit Firefox 14.0.1 unter Win7 ein auf "offiziell" gemachter Fullscreen mit dem Text "Ihr Computer wurde aus einem oder mehreren Gründen gesperrt." und mehreren Paragraphen und der Aufforderung Strafe zu zahlen, sowie ner kleinen WebCam in der Ecke, die die eigene (Laptop-)Cam abgreift. Hat mir beim ersten Mal schon nen ganz schönen Schreck eingejagt. Weil ich das Fenster nicht schließen könnte (Alt+Tab, Alt+F4, Strg+Alt+Entf oder ähnliches ging nicht), hab ich auf den Powerknopf gedrückt, aber anstatt runterzufahren, ging das Fenster weg, und ich konnte den PC weiter benutzen. Gleiches heute, als es zum 2. Mal auftrat. Ich benutze Avira und Comodo-Firewall. Gestern und heute hat Avira folgendes gefunden: Code:
ATTFilter Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\V.class Status: Infiziert Quarantäne-Objekt: 56bca853.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.38.86 Meldung: EXP/2012-0507.CZ.3 Datum/Uhrzeit: 01.08.2012, 12:22 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 54184ebe.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.38.86 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 01.08.2012, 10:54 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 551548d1.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.38.86 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 01.08.2012, 10:23 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 4d825fba.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.38.86 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 01.08.2012, 10:23 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 55023ced.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.38.06 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 30.07.2012, 16:14 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 4d952b06.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.38.06 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 30.07.2012, 16:14 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 4ee8285e.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.37.246 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 30.07.2012, 16:09 Typ: Datei Quelle: C:\Users\Jasper\AppData\Local\Temp\g7i0ol_kaz.exe Status: Infiziert Quarantäne-Objekt: 567f3fa5.qua Wiederhergestellt: NEIN Zu Avira hochgeladen: NEIN Betriebssystem: Windows XP/VISTA Workstation/Windows 7 Suchengine: 8.02.10.120 Virendefinitionsdatei: 7.11.37.246 Meldung: TR/Rogue.kdv.683070 Datum/Uhrzeit: 30.07.2012, 16:09 Unabhängig davon, dass ich natürlich grundsätzlich diesen Virus gerne loswerden möchte, ist das Hauptproblem: -> Ich schreib grad an meiner Bachelor-Arbeit und muss die in zwei Wochen fertig haben und nicht grade viel Spielraum in meinem Zeitplan. Deshalb wäre im Falle einer notwendigen Formatierung vor allem die Datensicherung ein Problem. Mein letztes, mir per Mail geschicktes Back-Up ist schon ziemlich alt :/ Ich hab Malwarebytes, OTL, Defogger und GMER bereits durchlaufen lassen (siehe Logfiles), aber leider in dieser Reihenfolge! Habe erst nach Malwarebytes und OTL gesehen, dass man emulierte Laufwerke mit Defogger vorher deaktivieren sollte. Vielleicht hab ich ja Glück und es ist hier kein großes Problem, grade Malwarebytes hat für den Scan lange gebraucht (über 2 Stunden). Hoffe, ich hab keine wichtigen Infos vergessen. Der OTL.txt Code ist direkt im Codefenster und die anderen Logfiles gepackt als Anhang. Wär super, wenn ihr mir irgendwie helfen könntet! ![]() ![]() Vielen, vielen Dank schonmal!! OTL.txt: Code:
ATTFilter OTL logfile created on: 01.08.2012 16:53:06 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Jasper\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,97 Gb Total Physical Memory | 1,53 Gb Available Physical Memory | 51,71% Memory free 5,93 Gb Paging File | 4,12 Gb Available in Paging File | 69,53% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 103,65 Gb Total Space | 47,77 Gb Free Space | 46,09% Space Free | Partition Type: NTFS Drive D: | 347,01 Gb Total Space | 264,72 Gb Free Space | 76,28% Space Free | Partition Type: NTFS Computer Name: JASPER-PC | User Name: Jasper | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Jasper\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia) PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia) PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia) PRC - C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia) PRC - C:\ProgramData\GameXN\GameXNGO.exe (EasyBits Software AS) PRC - C:\Users\Jasper\AppData\Roaming\BrowserCompanion\tcbhn.exe () PRC - C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (Yuna Software) PRC - C:\Program Files\MSN Plus! Live\PlusService.exe (Yuna Software) PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files\Stickies\stickies.exe (Zhorn Software) PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Program Files\COMODO Internet Security\COMODO\COMODO Internet Security\cfp.exe (COMODO) PRC - C:\Program Files\COMODO Internet Security\COMODO\COMODO Internet Security\cmdagent.exe (COMODO) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Windows\System32\hasplms.exe (SafeNet Inc.) PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe () PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) PRC - C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (SEC) PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics) PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.) PRC - C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe () PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) PRC - C:\Users\Jasper\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS) PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) ========== Modules (No Company Name) ========== MOD - C:\Program Files\Mozilla Firefox\mozjs.dll () MOD - C:\Program Files\Nokia\Nokia Suite\phonon4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtXmlPatterns4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtXml4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtWebKit4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtScript4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtSql4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtNetwork4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtOpenGL4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtGui4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtMultimediaKit1.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtDeclarative4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\QtCore4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\imageformats\qjpeg4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\imageformats\qico4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\imageformats\qgif4.dll () MOD - C:\Program Files\Nokia\Nokia Suite\NService.dll () MOD - C:\Program Files\Nokia\Nokia Suite\CommonUpdateChecker.dll () MOD - C:\Program Files\Nokia\Nokia Suite\ssoengine.dll () MOD - C:\Program Files\Nokia\Nokia Suite\securestorage.dll () MOD - C:\Program Files\Nokia\Nokia Suite\mediaservice\dsengine.dll () MOD - C:\Users\Jasper\AppData\Roaming\BrowserCompanion\tcbhn.exe () MOD - C:\Program Files\Stickies\shook70.dll () MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll () MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe () MOD - C:\Program Files\Notepad++\NppShell_04.dll () MOD - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe () MOD - C:\Program Files\Samsung\Samsung Update Plus\HMXML.dll () MOD - C:\Program Files\WinRAR\rarext.dll () MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll () ========== Win32 Services (SafeList) ========== SRV - (SBSDWSCService) -- C:\Program Files\Spybot File not found SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (MsgPlusService) -- C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (Yuna Software) SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies) SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation) SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (cmdAgent) -- C:\Program Files\COMODO Internet Security\COMODO\COMODO Internet Security\cmdagent.exe (COMODO) SRV - (hasplms) -- C:\Windows\System32\hasplms.exe (SafeNet Inc.) SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.) SRV - (OberonGameConsoleService) -- C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe () SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (UsbserFilt) -- system32\DRIVERS\usbser_lowerfltj.sys File not found DRV - (upperdev) -- system32\DRIVERS\usbser_lowerflt.sys File not found DRV - (a6zh7qig) -- File not found DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia) DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH) DRV - (inspect) -- C:\Windows\System32\drivers\inspect.sys (COMODO) DRV - (cmdHlp) -- C:\Windows\System32\drivers\cmdhlp.sys (COMODO) DRV - (cmdGuard) -- C:\Windows\System32\drivers\cmdGuard.sys (COMODO) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (aksfridge) -- C:\Windows\System32\drivers\aksfridge.sys (SafeNet Inc.) DRV - (akshasp) -- C:\Windows\System32\drivers\akshasp.sys (Aladdin Knowledge Systems Ltd.) DRV - (hardlock) -- C:\Windows\System32\drivers\hardlock.sys (SafeNet Inc.) DRV - (aksusb) -- C:\Windows\System32\drivers\aksusb.sys (Aladdin Knowledge Systems Ltd.) DRV - (akshhl) -- C:\Windows\System32\drivers\akshhl.sys (Aladdin Knowledge Systems Ltd.) DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys () DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (CVPNDRVA) -- C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.) DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation) DRV - (DNE) -- C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.) DRV - (CVirtA) -- C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.) DRV - (zntport) -- C:\Windows\System32\drivers\ZNTPORT.SYS (Zeal SoftStudio) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn IE - HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn IE - HKU\S-1-5-21-771618654-3341757510-301361698-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKU\S-1-5-21-771618654-3341757510-301361698-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-771618654-3341757510-301361698-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-771618654-3341757510-301361698-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.tagesschau.de" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5 FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.732 FF - prefs.js..extensions.enabledItems: yyginstantplay@yoyogames.com:1.1.0.24 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: YoutubeDownloader@PeterOlayev.com:1.5 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Jasper\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Jasper\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.06.25 20:34:39 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.02.16 14:45:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.07.30 18:47:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.04.17 11:28:26 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Programme\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.04.17 11:28:26 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.07.11 22:29:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.07.30 18:47:16 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.04.17 11:28:26 | 000,000,000 | ---D | M] [2011.03.29 09:52:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jasper\AppData\Roaming\mozilla\Extensions [2011.03.29 09:52:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jasper\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012.07.25 21:05:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jasper\AppData\Roaming\mozilla\Firefox\Profiles\24uxsnwp.default\extensions [2012.04.01 18:41:20 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Jasper\AppData\Roaming\mozilla\Firefox\Profiles\24uxsnwp.default\extensions\bbrs_002@blabbers.com [2012.06.29 15:18:22 | 000,000,000 | ---D | M] (Online Games Downloader) -- C:\Users\Jasper\AppData\Roaming\mozilla\Firefox\Profiles\24uxsnwp.default\extensions\onlinegamesdownloader@gamesdownloader.net [2012.04.11 14:30:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2012.04.11 14:30:51 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012.02.16 14:45:35 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 [2011.12.09 20:34:37 | 000,026,866 | ---- | M] () (No name found) -- C:\USERS\JASPER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\24UXSNWP.DEFAULT\EXTENSIONS\{322E833A-A7D4-4277-97C6-334FA1622D6A}.XPI [2012.02.12 21:40:10 | 000,709,293 | ---- | M] () (No name found) -- C:\USERS\JASPER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\24UXSNWP.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI [2012.07.30 18:47:16 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.02.23 16:52:08 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.07.03 00:54:27 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.07.03 00:54:27 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.07.03 00:54:27 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.07.03 00:54:27 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.03 00:54:27 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.03 00:54:27 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml Hosts file not found O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com) O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (Flash Catcher) - {3AF255C7-8742-4B96-8971-1268EEE04974} - C:\Program Files\Online Games Downloader\SWFCatcher.dll (VTools) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-771618654-3341757510-301361698-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO Internet Security\COMODO\COMODO Internet Security\cfp.exe (COMODO) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [MessengerPlusForSkypeService] C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (Yuna Software) O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [PlusService] C:\Program Files\MSN Plus! Live\PlusService.exe (Yuna Software) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\S-1-5-21-771618654-3341757510-301361698-1000..\Run: [] File not found O4 - HKU\S-1-5-21-771618654-3341757510-301361698-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-771618654-3341757510-301361698-1000..\Run: [GameXN GO] C:\ProgramData\GameXN\GameXNGO.exe (EasyBits Software AS) O4 - HKU\S-1-5-21-771618654-3341757510-301361698-1000..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) O4 - HKU\S-1-5-21-771618654-3341757510-301361698-1000..\Run: [Octoshape Streaming Services] C:\Users\Jasper\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS) O4 - HKU\S-1-5-21-771618654-3341757510-301361698-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = File not found O4 - Startup: C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk = C:\Users\Jasper\AppData\Roaming\BrowserCompanion\tcbhn.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com) O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 129.206.100.126 129.206.210.127 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FC1B6C9-FD68-4014-ACF2-46670090018B}: DhcpNameServer = 129.206.100.126 129.206.210.127 O18 - Protocol\Handler\base64 - No CLSID value found O18 - Protocol\Handler\chrome - No CLSID value found O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\prox - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{738d9abd-b296-11df-b990-00245422984c}\Shell - "" = AutoRun O33 - MountPoints2\{738d9abd-b296-11df-b990-00245422984c}\Shell\AutoRun\command - "" = H:\_AUTORUN\AUTORUN.EXE O33 - MountPoints2\{738d9abd-b296-11df-b990-00245422984c}\Shell\readme\command - "" = notepad Liesmich.txt O33 - MountPoints2\{91de49eb-ac7c-11df-8308-00245422984c}\Shell - "" = AutoRun O33 - MountPoints2\{91de49eb-ac7c-11df-8308-00245422984c}\Shell\AutoRun\command - "" = G:\autorun.exe O33 - MountPoints2\{91de49eb-ac7c-11df-8308-00245422984c}\Shell\directx\command - "" = G:\DirectX\DXSETUP.exe O33 - MountPoints2\{91de49eb-ac7c-11df-8308-00245422984c}\Shell\install\command - "" = G:\setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.08.01 12:01:10 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\Jasper\Desktop\OTL.exe [2012.08.01 11:57:53 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Roaming\Malwarebytes [2012.08.01 11:57:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.08.01 11:57:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.08.01 11:57:42 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys [2012.08.01 11:57:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012.08.01 10:36:26 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Local\FreePDF_XP [2012.08.01 10:35:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreePDF [2012.08.01 10:34:59 | 000,000,000 | ---D | C] -- C:\Program Files\FreePDF_XP [2012.08.01 10:34:59 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Roaming\FreePDF [2012.08.01 10:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ghostscript [2012.08.01 10:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\gs [2012.08.01 10:28:58 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Local\OpenFreelyEditTemp [2012.08.01 10:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack [2012.08.01 10:20:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open Freely [2012.08.01 10:20:29 | 000,000,000 | ---D | C] -- C:\Program Files\Open Freely [2012.08.01 10:11:42 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Local\DolphinFutures [2012.07.14 18:17:38 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Local\NokiaAccount [2012.07.12 08:24:02 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Roaming\Avira [2012.07.12 08:23:55 | 000,000,000 | ---D | C] -- C:\Users\Jasper\AppData\Local\Nokia [2012.07.12 08:23:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia [2012.07.12 08:23:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Nokia [2012.07.12 08:22:26 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution [2012.07.12 08:20:13 | 000,000,000 | ---D | C] -- C:\ProgramData\NokiaInstallerCache [2012.07.12 08:18:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.07.12 08:18:33 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\ssmdrv.sys [2012.07.12 08:18:32 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avipbb.sys [2012.07.12 08:18:32 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avgntflt.sys [2012.07.12 08:18:32 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avkmgr.sys [2012.07.12 08:18:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.07.12 08:18:26 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.07.11 23:03:41 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys [2012.07.11 22:43:08 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ncrypt.dll [2012.07.11 22:43:07 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msxml3r.dll [2012.07.11 22:43:05 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\cdosys.dll ========== Files - Modified Within 30 Days ========== [2012.08.01 16:54:24 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.08.01 16:54:24 | 000,014,736 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.08.01 16:46:53 | 000,001,094 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2012.08.01 16:46:39 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2012.08.01 16:46:31 | 2388,086,784 | -HS- | M] () -- C:\hiberfil.sys [2012.08.01 16:20:17 | 000,001,098 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2012.08.01 12:01:12 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Jasper\Desktop\OTL.exe [2012.08.01 10:47:48 | 004,503,728 | ---- | M] () -- C:\ProgramData\zak_lo0i7g.pad [2012.08.01 10:39:04 | 000,046,377 | ---- | M] () -- C:\Users\Jasper\Desktop\Fragebogen Anforderungen von Computerspielen.pdf [2012.08.01 09:53:41 | 000,083,325 | ---- | M] () -- C:\Users\Jasper\Desktop\page4.xps [2012.07.31 20:48:26 | 000,002,208 | -H-- | M] () -- C:\Users\Jasper\Documents\Default.rdp [2012.07.18 17:01:26 | 002,097,558 | ---- | M] () -- C:\Users\Jasper\EM.jar [2012.07.14 18:19:04 | 000,721,984 | ---- | M] () -- C:\windows\System32\perfh007.dat [2012.07.14 18:19:04 | 000,671,864 | ---- | M] () -- C:\windows\System32\perfh009.dat [2012.07.14 18:19:04 | 000,158,676 | ---- | M] () -- C:\windows\System32\perfc007.dat [2012.07.14 18:19:04 | 000,128,316 | ---- | M] () -- C:\windows\System32\perfc009.dat [2012.07.12 08:09:59 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\System32\FlashPlayerApp.exe [2012.07.12 08:09:59 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\System32\FlashPlayerCPLApp.cpl [2012.07.12 08:08:08 | 000,432,560 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2012.08.01 10:39:03 | 000,046,377 | ---- | C] () -- C:\Users\Jasper\Desktop\Fragebogen Anforderungen von Computerspielen.pdf [2012.08.01 10:35:00 | 000,116,224 | ---- | C] () -- C:\windows\System32\redmonnt.dll [2012.08.01 10:35:00 | 000,045,056 | ---- | C] () -- C:\windows\System32\unredmon.exe [2012.08.01 10:20:45 | 000,165,376 | ---- | C] () -- C:\windows\System32\unrar.dll [2012.08.01 09:53:39 | 000,083,325 | ---- | C] () -- C:\Users\Jasper\Desktop\page4.xps [2012.07.28 11:50:36 | 004,503,728 | ---- | C] () -- C:\ProgramData\zak_lo0i7g.pad [2012.07.18 17:01:18 | 002,097,558 | ---- | C] () -- C:\Users\Jasper\EM.jar [2012.05.08 09:32:07 | 000,000,094 | ---- | C] () -- C:\Users\Jasper\AppData\Local\fusioncache.dat [2012.04.13 15:43:33 | 000,001,473 | ---- | C] () -- C:\Users\Jasper\.recently-used.xbel [2012.04.04 13:50:50 | 000,131,917 | ---- | C] () -- C:\windows\unstall.exe [2012.03.25 16:49:47 | 000,000,994 | ---- | C] () -- C:\Users\Jasper\endnote-citations.enw [2010.09.09 14:33:45 | 000,073,728 | ---- | C] () -- C:\windows\System32\RtNicProp32.dll [2010.09.01 12:13:38 | 000,000,027 | ---- | C] () -- C:\windows\BRPP2KA.INI [2010.08.01 20:48:09 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010.07.29 16:39:21 | 000,000,837 | ---- | C] () -- C:\Users\Jasper\AppData\Local\ikonudowubu.dll [2010.06.25 20:46:41 | 000,013,824 | ---- | C] () -- C:\Users\Jasper\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.12.25 07:58:59 | 000,007,605 | ---- | C] () -- C:\Users\Jasper\AppData\Local\Resmon.ResmonCfg [2009.12.25 02:08:21 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe ========== LOP Check ========== [2012.02.23 13:43:11 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Dropbox [2012.02.23 13:34:58 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\PC Suite [2012.02.23 13:43:40 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\stickies [2012.02.23 13:38:24 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Thunderbird [2010.06.13 17:45:11 | 000,000,000 | -HSD | M] -- C:\Users\Jasper\AppData\Roaming\.# [2011.02.07 14:39:57 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\.minecraft [2012.01.29 16:03:25 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Allen Institute [2012.08.01 16:47:50 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\BrowserCompanion [2011.12.21 18:48:41 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2011.07.13 10:07:43 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2010.08.20 19:10:26 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\DAEMON Tools Lite [2012.02.23 13:30:06 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Dropbox [2011.12.24 19:43:37 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\EAC [2011.11.27 14:26:41 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\EndNote [2010.09.04 02:36:25 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\FreeFLVConverter [2012.08.01 10:34:59 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\FreePDF [2009.12.25 03:00:50 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\GameConsole [2012.08.01 16:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\go [2009.12.25 03:02:06 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Go Go Gourmet [2010.06.08 16:22:36 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\GrabPro [2012.04.13 15:43:33 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\gtk-2.0 [2010.01.02 16:48:51 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\ICQ [2010.09.04 02:17:29 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\ManyCam [2010.06.27 12:27:13 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Nokia [2011.08.16 13:37:43 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Notepad++ [2010.05.19 10:45:52 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Octoshape [2012.06.29 15:18:22 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Online Games Downloader [2010.02.21 20:28:14 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\OpenOffice.org [2012.07.20 18:19:21 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Orbit [2010.06.25 20:36:50 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\PC Suite [2010.05.09 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\PlayFirst [2011.11.22 20:46:19 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Pst [2012.08.01 16:47:50 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\stickies [2011.03.29 09:52:43 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Thunderbird [2011.01.26 20:37:55 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Unity [2010.01.05 03:44:51 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Windows Live Writer [2010.05.09 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Jasper\AppData\Roaming\Zylom [2011.10.01 13:32:49 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:5C5A503E @Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:A42A9F39 @Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4CF61E54 @Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:ABE89FFE @Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:E1F04E8D < End of report > |
Themen zu GVU Trojaner mit WebCam: TR/Rogue.kdv.683070 und EXP/2012-0507.CZ.3 |
adobe, antivir, autorun, avira, bho, bonjour, computer, datensicherung, defender, explorer, firefox, gebraucht, google earth, gvu trojaner, helper, home, loswerden, mozilla, online games, plug-in, problem, registry, safer networking, scan, security, software, super, taskhost.exe, taskmanager, tcbhn.exe, temp, trojaner, virus |