Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: BKA Trojaner Computer wurde gesperrt

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 08.08.2012, 13:17   #1
introplastic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



Hallo, habe mir gestern den BKA trojaner eingefangen. (siehe angehängte grafik)

Kann den laptop in sämtlichen modi starten (nur kommt bei normalem windows start eben direkt die sperrseite).
Habe bereits im "save with networking" modus defogger, otl und GMER laufen lassen. siehe logfiles.
Betriebssystem: win vista home premium

hoffe es kann mir jemand helfen, vielen dank schonmal für die mühe!

otl logfile

Code:
ATTFilter
OTL logfile created on: 08.08.2012 00:22:30 - Run 1
OTL by OldTimer - Version 3.2.56.0     Folder = C:\Users\Jonas\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,48 Gb Available Physical Memory | 82,63% Memory free
6,19 Gb Paging File | 5,88 Gb Available in Paging File | 94,94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 261,45 Gb Total Space | 9,17 Gb Free Space | 3,51% Space Free | Partition Type: NTFS
Drive H: | 30,29 Gb Total Space | 1,60 Gb Free Space | 5,30% Space Free | Partition Type: NTFS
 
Computer Name: JONAS-PC | User Name: Jonas | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.08.08 00:21:11 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Jonas\Desktop\OTL.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.01.21 04:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - File not found [Auto | Stopped] --  -- (0268391304585483mcinstcleanup)
SRV - [2012.08.08 00:09:44 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.01.20 13:42:40 | 000,329,168 | ---- | M] () [Auto | Stopped] -- C:\Programme\Verbindungsassistent\WTGService.exe -- (WTGService)
SRV - [2011.08.03 22:43:45 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto | Stopped] -- C:\Programme\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.04.20 10:50:46 | 000,792,976 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV - [2011.03.09 14:30:08 | 000,092,592 | ---- | M] (TomTom) [Disabled | Stopped] -- C:\Programme\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010.12.10 18:30:50 | 000,086,880 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.09.08 18:09:14 | 000,083,312 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper)
SRV - [2009.04.02 00:15:30 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2008.03.03 14:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programme\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.08.14 21:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Disabled | Stopped] -- C:\Programme\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2007.05.31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmnetadapter.sys -- (VMnetAdapter)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\\SystemRoot\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\igdkmd32.sys -- (igfx)
DRV - File not found [File_System | System | Stopped] -- system32\DRIVERS\AFSRedir.sys -- (AFSRedirector)
DRV - File not found [File_System | On_Demand | Stopped] -- system32\DRIVERS\AFSRedirLib.sys -- (AFSLibrary)
DRV - [2012.01.20 13:39:33 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2012.01.20 13:39:33 | 000,100,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewsercd.sys -- (ewsercd)
DRV - [2011.08.03 22:27:28 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva)
DRV - [2011.03.24 10:57:54 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2011.03.24 10:57:54 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2010.07.15 11:17:45 | 000,147,984 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2009.04.11 07:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2009.04.11 06:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2008.12.13 12:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008.02.23 02:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008.02.12 02:49:44 | 007,626,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008.02.06 02:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008.01.21 04:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2008.01.21 04:23:21 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\loop.sys -- (msloop)
DRV - [2007.12.17 03:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP)
DRV - [2007.12.14 06:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007.12.13 18:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall)
DRV - [2007.10.31 14:41:16 | 000,110,096 | ---- | M] (Kaspersky Lab) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\kl1.sys -- (kl1)
DRV - [2007.10.16 12:05:28 | 000,020,496 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2007.09.19 05:29:09 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32)
DRV - [2007.06.06 02:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony)
DRV - [2007.05.26 10:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2004.02.04 08:19:32 | 000,024,177 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2004.02.04 08:19:16 | 000,057,372 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2206084
IE - HKLM\..\SearchScopes\{F17154AC-2F13-4B6E-983B-2ECD80940F83}: "URL" = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.club-vaio.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.club-vaio.com/vbc
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {F17154AC-2F13-4B6E-983B-2ECD80940F83}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2206084
IE - HKCU\..\SearchScopes\{F17154AC-2F13-4B6E-983B-2ECD80940F83}: "URL" = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.9: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.08.08 00:09:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.28 17:06:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.05.28 17:06:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2010.11.18 14:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\mozilla\Extensions
[2010.07.05 22:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.07.29 17:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2010.11.18 14:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\mozilla\Extensions\uploadr@flickr.com
[2012.07.28 07:39:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\mozilla\Firefox\Profiles\fzjmzo64.default\extensions
[2010.07.07 23:45:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jonas\AppData\Roaming\mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.10.29 21:52:00 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jonas\AppData\Roaming\mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.02.11 23:16:51 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Users\Jonas\AppData\Roaming\mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}
[2012.07.28 07:39:41 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jonas\AppData\Roaming\mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2012.02.21 17:54:17 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Jonas\AppData\Roaming\mozilla\Firefox\Profiles\fzjmzo64.default\extensions\FoxdieGraphite@tanjihay.com
[2012.03.20 17:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.06.25 22:16:15 | 000,011,094 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\CSSEDITOR@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,005,285 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\EYEDROPPER@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,007,118 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FS@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,005,273 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FULLSCREEN@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,009,099 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\GFD@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,388,960 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-CS@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,387,240 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-DE@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,366,781 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-EN-US@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,339,956 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ES-ES@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,386,008 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FI@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,388,934 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FR@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,394,820 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HE@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,392,729 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HU@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,337,714 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-IT@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,416,549 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-JA@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,368,045 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-KO@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,380,550 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-NL@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,396,011 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-PL@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,383,592 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SL@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,418,980 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SR@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,418,463 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SV-SE@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,398,626 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-CN@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,398,347 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-TW@BLUEGRIFFON.ORG.XPI
[2012.06.25 22:16:15 | 000,015,163 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\MATHML@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,005,668 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SNIPPETS@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:15 | 000,659,648 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SVG-EDIT@GOOGLEGROUPS.COM.XPI
[2012.06.25 22:16:15 | 000,006,868 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TABLELAYOUT@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:16 | 000,016,878 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TEMPLATESMANAGER@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:16 | 000,014,431 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\THUMBNAILER@BLUEGRIFFON.COM.XPI
[2012.06.25 22:16:16 | 000,012,089 | ---- | M] () (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TIPOFTHEDAY@BLUEGRIFFON.COM.XPI
[2012.08.08 00:09:46 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.07.12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012.07.02 12:29:39 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.02 12:29:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.07.02 12:29:39 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.02 12:29:39 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.02 12:29:39 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.02 12:29:39 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.06.29 17:28:29 | 000,000,781 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       LOCALHOST
O1 - Hosts: ::1             LOCALHOST
O1 - Hosts: 10.254.254.253	AFS
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programme\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programme\Google BAE\BAE.dll (Your Company Name)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Snappy Fax Printer virtual printer agent] C:\Program Files\Snappy Fax Version 5\sfpagent.exe ()
O4 - HKCU..\Run: [mwgejhdgytlkjsb] C:\ProgramData\mwgejhdg.exe ()
O4 - HKCU..\Run: [Snappy Fax]  File not found
O4 - Startup: C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jonas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MIC279~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MIC279~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Statistik für Web-Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programme\Kaspersky Lab\Kaspersky Security Suite CBE\SCIEPlgn.dll (Kaspersky Lab)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{520B36B9-DF14-4CD8-B03A-041ED113C35F}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ECA3E94D-DBD3-42CA-A968-07313ACDE636}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\r3hook.dll) - C:\Programme\Kaspersky Lab\Kaspersky Security Suite CBE\r3hook.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Programme\Kaspersky Lab\Kaspersky Security Suite CBE\adialhk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) -  File not found
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: 
O24 - Desktop BackupWallPaper: 
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - H:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{45f70e5c-3e3b-11e1-930d-001a80f3c61d}\Shell - "" = AutoRun
O33 - MountPoints2\{45f70e5c-3e3b-11e1-930d-001a80f3c61d}\Shell\AutoRun\command - "" = I:\.\Autorun.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.08.08 00:21:05 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Jonas\Desktop\OTL.exe
[2012.08.07 18:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ztgcrqxmyuqrqqg
[2012.08.03 23:51:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snappy Fax Version 5
[2012.08.03 23:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Snappy Fax Version 5
[2012.08.03 23:50:58 | 000,000,000 | ---D | C] -- C:\Program Files\Snappy Fax Version 5
[2012.08.03 23:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Elevate Software
[2012.08.01 00:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012.08.01 00:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\IrfanView
[2012.08.01 00:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2012.07.29 01:09:10 | 002,369,456 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.CommandBars.v13.4.2.ocx
[2012.07.29 01:09:10 | 000,077,504 | ---- | C] (Michael Thummerer Software Design) -- C:\Windows\System32\mtScrollContainer.ocx
[2012.07.21 13:27:35 | 000,000,000 | ---D | C] -- C:\DIE_TUSCHS
[2012.07.10 21:07:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.08.08 00:25:54 | 000,628,422 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.08.08 00:25:54 | 000,596,052 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.08.08 00:25:54 | 000,126,278 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.08.08 00:25:54 | 000,103,868 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.08.08 00:21:11 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Jonas\Desktop\OTL.exe
[2012.08.08 00:19:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.08 00:17:51 | 000,000,176 | ---- | M] () -- C:\Users\Jonas\defogger_reenable
[2012.08.08 00:14:12 | 000,050,477 | ---- | M] () -- C:\Users\Jonas\Desktop\Defogger.exe
[2012.08.07 23:07:15 | 002,190,596 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx
[2012.08.07 23:07:14 | 237,518,880 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.dat
[2012.08.07 23:06:53 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.07 23:06:53 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.07 23:06:53 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.08.07 23:05:14 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.08.07 20:23:56 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.08.07 20:10:22 | 003,846,376 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.08.07 18:56:37 | 000,000,051 | ---- | M] () -- C:\ProgramData\wfixytpjmdpyflo
[2012.08.07 18:56:27 | 000,061,440 | ---- | M] () -- C:\ProgramData\mwgejhdg.exe
[2012.08.07 18:56:27 | 000,061,440 | ---- | M] () -- C:\Users\Jonas\0.48665953505403625.exe
[2012.08.06 23:12:34 | 000,041,472 | ---- | M] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.08.03 23:51:06 | 000,001,737 | ---- | M] () -- C:\Users\Jonas\Desktop\Snappy Fax Version 5.lnk
[2012.08.01 22:56:27 | 000,166,763 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001
[2012.08.01 00:06:36 | 000,001,687 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk
[2012.08.01 00:06:36 | 000,000,807 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView.lnk
[2012.07.28 07:30:38 | 310,824,085 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.07.11 14:22:17 | 000,000,206 | ---- | M] () -- C:\Windows\System32\MRT.INI
[2012.07.10 21:07:58 | 000,001,735 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.08.08 00:17:32 | 000,000,176 | ---- | C] () -- C:\Users\Jonas\defogger_reenable
[2012.08.08 00:14:12 | 000,050,477 | ---- | C] () -- C:\Users\Jonas\Desktop\Defogger.exe
[2012.08.07 18:56:37 | 000,061,440 | ---- | C] () -- C:\ProgramData\mwgejhdg.exe
[2012.08.07 18:56:29 | 000,000,051 | ---- | C] () -- C:\ProgramData\wfixytpjmdpyflo
[2012.08.07 18:56:27 | 000,061,440 | ---- | C] () -- C:\Users\Jonas\0.48665953505403625.exe
[2012.08.03 23:51:07 | 000,036,864 | ---- | C] () -- C:\Windows\System32\sfppm.dll
[2012.08.03 23:51:06 | 000,001,737 | ---- | C] () -- C:\Users\Jonas\Desktop\Snappy Fax Version 5.lnk
[2012.08.01 00:06:36 | 000,001,687 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk
[2012.08.01 00:06:36 | 000,000,807 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView.lnk
[2012.07.28 07:30:38 | 310,824,085 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012.07.10 21:07:58 | 000,001,735 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.06.29 17:15:27 | 000,000,600 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd
[2012.06.13 17:33:54 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2012.05.15 19:45:21 | 000,000,293 | ---- | C] () -- C:\Users\Jonas\Jonas - Verknüpfung.lnk
[2012.05.15 15:33:02 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.04.21 00:16:45 | 237,518,880 | -HS- | C] () -- C:\Windows\System32\drivers\fidbox.dat
[2012.02.12 02:01:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat
[2012.02.11 21:23:07 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012.02.11 21:23:00 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.02.11 21:22:49 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012.02.09 22:15:58 | 000,006,854 | RHS- | C] () -- C:\Windows\innova3.ini
[2012.01.31 20:37:33 | 000,000,196 | ---- | C] () -- C:\Windows\System32\ftdiun2k.ini
[2011.08.23 13:34:38 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.08.23 13:34:36 | 000,000,772 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011.08.10 07:18:00 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{72A5C72A-484F-44E4-A570-0EB5D6ED0F18}
[2011.08.10 07:07:04 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{80EA586A-7A9E-4E80-A54B-C062188EA15D}
[2011.07.02 15:02:54 | 000,180,609 | ---- | C] () -- C:\Users\Jonas\Abrechnung_Hofmann_Juni2011.pdf
[2011.06.30 12:38:21 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011.06.30 12:38:20 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011.06.30 12:38:14 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011.04.19 20:02:00 | 002,340,992 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2011.04.19 20:02:00 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2011.04.19 20:02:00 | 000,018,048 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2011.04.19 20:01:59 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2011.04.19 20:01:59 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2011.04.13 17:40:47 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2011.04.13 17:40:06 | 000,006,360 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2011.02.11 23:15:33 | 000,015,873 | ---- | C] () -- C:\Windows\System32\Inetde.dll
[2010.12.17 10:01:47 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI
[2010.12.02 13:51:55 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe
[2010.11.10 16:45:30 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.11.06 11:17:15 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2010.09.30 10:20:58 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010.09.30 10:20:58 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.08.18 22:24:04 | 000,002,738 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp DirectShow Decoder.dat
[2010.08.18 22:14:48 | 000,229,752 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2010.08.18 22:14:48 | 000,015,341 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2010.07.13 14:19:52 | 000,041,472 | ---- | C] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.05 19:08:29 | 000,001,356 | ---- | C] () -- C:\Users\Jonas\AppData\Local\d3d9caps.dat
[2010.07.05 19:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.dat
[2010.07.05 19:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001
 
========== LOP Check ==========
 
[2010.11.11 16:24:11 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\.purple
[2012.07.31 00:11:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\AllDup
[2011.11.27 00:52:17 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Audacity
[2011.04.15 21:54:03 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Azureus
[2011.07.13 11:46:46 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Blender Foundation
[2011.03.17 01:40:42 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\BOM
[2010.07.15 22:07:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Canon
[2011.05.05 11:22:48 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2010.07.17 18:13:28 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Crossword Compiler Deutsch 8
[2012.07.26 10:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
[2010.12.03 01:26:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DataCast
[2010.08.18 22:24:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\dBpoweramp
[2012.06.25 22:16:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Disruptive Innovations SARL
[2012.08.07 20:24:29 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Dropbox
[2012.03.19 08:34:06 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoft
[2011.04.04 23:12:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.11.18 14:12:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Flickr
[2010.11.26 11:58:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Free Sound Recorder
[2011.01.19 11:14:41 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\GetRightToGo
[2010.07.15 19:45:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Gutscheinmieze
[2011.09.29 22:22:59 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\HandBrake
[2011.01.16 18:28:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ICQ
[2011.10.20 00:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ImgBurn
[2012.02.09 22:15:54 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\innoplus
[2010.09.25 23:23:24 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\InterVideo
[2012.08.01 00:06:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\IrfanView
[2012.04.04 12:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\kompozer.net
[2010.09.29 20:23:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Leadertech
[2011.04.28 10:53:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\MAGIX
[2010.09.29 22:14:34 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OOo-dev
[2010.07.28 13:22:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OpenOffice.org
[2010.08.17 06:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PDF reDirect
[2010.07.15 23:17:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoFiltre
[2010.12.09 18:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoScape
[2010.07.17 17:13:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\pics
[2012.07.21 14:00:40 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\RipIt4Me
[2010.07.05 22:00:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Thunderbird
[2010.07.29 17:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TomTom
[2011.04.30 17:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TP
[2011.10.24 21:28:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\uTorrent
[2012.01.21 08:58:52 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Verbindungsassistent
[2011.06.30 12:42:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Video DVD Maker FREE
[2012.08.07 23:06:53 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >
         
gmer logfile

Code:
ATTFilter
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-08-08 11:13:22
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0000
Running: m7fro4k0.exe; Driver: C:\Users\Jonas\AppData\Local\Temp\kgloypow.sys


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                    
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                 0x00 0x00 0x00 0x00 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                 0
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                              0x8D 0x66 0xE9 0x28 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                 C:\Program Files\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                           
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                        0xA0 0x02 0x00 0x00 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                     0x5B 0x86 0x69 0x7A ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                      
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                0x6F 0xE8 0xEA 0xCC ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                     0x00 0x00 0x00 0x00 ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                     0
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                  0x15 0x21 0xC2 0x26 ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                     C:\Program Files\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)       
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                            0xA0 0x02 0x00 0x00 ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                         0x5B 0x86 0x69 0x7A ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)  
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                    0x6F 0xE8 0xEA 0xCC ...

---- EOF - GMER 1.0.15 ----
         
extras logfile

Code:
ATTFilter
OTL Extras logfile created on: 08.08.2012 00:22:30 - Run 1
OTL by OldTimer - Version 3.2.56.0     Folder = C:\Users\Jonas\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,48 Gb Available Physical Memory | 82,63% Memory free
6,19 Gb Paging File | 5,88 Gb Available in Paging File | 94,94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 261,45 Gb Total Space | 9,17 Gb Free Space | 3,51% Space Free | Partition Type: NTFS
Drive H: | 30,29 Gb Total Space | 1,60 Gb Free Space | 5,30% Space Free | Partition Type: NTFS
 
Computer Name: JONAS-PC | User Name: Jonas | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Value error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02CE2FCE-A358-4611-91EE-238B850385DA}" = lport=7001 | protocol=17 | dir=in | name=afs cachemanager callback (udp) | 
"{04DE179D-623F-486D-AAA0-F6D8DC0F5B98}" = rport=139 | protocol=6 | dir=out | app=system | 
"{103507A9-37B6-4BB2-86FF-80FEE522AD54}" = lport=7001 | protocol=17 | dir=in | app=c:\program files\openafs\client\program\afsd_service.exe | 
"{12E46B63-5CE4-460F-9349-F75801830C22}" = lport=138 | protocol=17 | dir=in | app=system | 
"{290F2AFB-75F4-4CE3-8031-B5E8587A6FDD}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{4DA8669C-E8E8-4FD0-9580-63F1E1FB6572}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{5BAB61A2-80F3-4BCD-9EB1-0BFC35FEDDED}" = lport=137 | protocol=17 | dir=in | app=system | 
"{5DB7F2E5-F139-4F64-B453-58A09FC99EC2}" = rport=138 | protocol=17 | dir=out | app=system | 
"{64BD9A85-A3B3-484F-A977-FD7D17FD4F13}" = rport=445 | protocol=6 | dir=out | app=system | 
"{66263D89-DE24-4F12-ABEE-7D889749BF8B}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{778B0F76-5704-4FB6-A852-EC9DA5793A16}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{7D744048-185F-4297-A300-CEF3FE8FD92C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{7F263977-6E8D-4258-8F0A-D8E248FF2399}" = lport=139 | protocol=6 | dir=in | app=system | 
"{903E8EB2-C8D5-4D9C-8F36-ADEE7DE0C934}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{AAE8D7D0-D63F-4A7F-89B3-E23128F1FBA6}" = rport=137 | protocol=17 | dir=out | app=system | 
"{D017A58F-8B03-420C-B60F-DFAF9CD1F2A1}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{E398F7AC-EF04-4D77-8E1E-4655A5184C6E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | 
"{F0922728-1DF6-4379-A8C0-2AC75FF8EA26}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 | 
"{F83AE574-FB56-412E-8FC0-E09606995E9A}" = lport=445 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04B9A431-A7EF-4204-8718-2D65B6B727CC}" = protocol=17 | dir=in | app=c:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe | 
"{05110A86-8433-4E67-980D-6A75CE647CD8}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{0606EDC9-15F9-4620-94AA-03B917FD32F5}" = protocol=17 | dir=in | app=c:\program files\dsl connection manager\dslconmanconfig.exe | 
"{0BFC14D2-7AA0-4246-BA1C-9CC75B1FB22B}" = protocol=6 | dir=in | app=c:\program files\dsl connection manager\dslconmanconfig.exe | 
"{0CFA8880-86D1-4763-BD31-8AD0B3EBE267}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{105150C3-5038-4C8F-97F6-936D08B881D3}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{10A48E1A-6E50-44B1-9C2A-BD0B47EB5BB9}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{126F7C9D-099F-4DDF-99DF-03E09CCD907C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{21E1B092-A601-43B0-8CB2-72D9F2825197}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{26152CC0-94E1-4C71-BFCA-B70701A5000F}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{26B691CD-C79E-4D8F-BBDB-AFBD92C3094A}" = protocol=17 | dir=in | app=c:\program files\dsl connection manager\dslcoman.exe | 
"{27515C78-5C8D-474C-A462-DFA6775C9414}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{27F6C574-A9E0-4A7E-A34C-7DD5A3F47C5F}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | 
"{2B23C51D-BC28-46B3-9A3F-B5C5067AC5C5}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | 
"{37E7F1C0-599D-4306-B306-8C0CAFEC6882}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{3C1E9D8E-237B-4E64-9C4B-8C643BAF1620}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{3D4AE764-06DE-459A-BC9E-3E30981ABB64}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{5401A1A5-2AE3-4FB0-B035-7A0840CFDA3A}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{55505C8F-D508-4EB3-B827-9C20FE2849B5}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{55D0AD7A-21D0-40FF-B740-48B62D290775}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{5C8A8C7F-F1A3-4BE1-AA17-42A915449F26}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{629AF91D-1CCC-4EC5-ADD4-1B1AB3198C38}" = protocol=6 | dir=in | app=c:\program files\google\google talk\googletalk.exe | 
"{6586AE3E-341C-4F4C-B73C-A478E4726CC8}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{6773716E-31BE-4D72-BA8F-C1DC9420F26C}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{747E324B-01AA-4AE9-A534-AB9184E5AC37}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{7A0EC007-DD1B-4619-B352-5DE0663C6BA9}" = protocol=6 | dir=in | app=c:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\dedicated\xr_3da.exe | 
"{7BB35231-A7DC-4ED8-9113-05FFF609877F}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{81549C0D-B1C5-4088-AABD-6D46148D94A4}" = protocol=6 | dir=in | app=c:\users\jonas\appdata\roaming\dropbox\bin\dropbox.exe | 
"{897D1FAB-D329-4E1A-B801-2820B580A301}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{8BBC15EC-5EED-4E4A-9DBA-2D5151F36A2B}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | 
"{936AF1BF-CAA0-4AD2-A04A-98E9CCAA0029}" = protocol=17 | dir=in | app=c:\program files\google\google talk\googletalk.exe | 
"{93ADA0FA-15E5-4204-8AE7-1A6FEA759081}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{99AE31E7-EB48-43DE-B370-9D624B282098}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe | 
"{9C15B845-0CE6-4193-B7A6-75DC63191523}" = protocol=17 | dir=in | app=c:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe | 
"{A74F2B0B-1DA5-4D61-B36F-38552512562F}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{AC50894D-E799-4CD3-B2EB-520B22673C3A}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{B1777DE5-0747-4776-B8A9-AC1F7903513F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{B6394046-9CB9-42EB-851D-198E58857416}" = protocol=6 | dir=in | app=c:\program files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\xr_3da.exe | 
"{B808DE45-FCCB-492C-BBCA-8C1C4D7AE372}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{BD06232F-BDF4-40DB-83F5-A13A47337893}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | 
"{BD20FC71-7C25-4134-AFCB-EA1E0B6073C9}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{BD2FE750-C3F3-4BCA-9180-65720E396B8A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{BF2D2D6E-E7AC-452C-BC32-A5FD19A1D56A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{BFEE1D0A-27A0-4724-961F-E41636F7AEB5}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{C1F717E7-9C69-4BB3-B607-A75CF89AD72D}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{C450A36D-80AE-4277-9445-D65BAC91B624}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{C475B2B7-4641-41DE-ABCD-5B3C25DED743}" = protocol=17 | dir=in | app=c:\users\jonas\appdata\roaming\dropbox\bin\dropbox.exe | 
"{C48BB211-59AD-44BA-88FD-60B6379BC941}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{C88F36A6-84FF-4F05-811C-25F805370749}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{CA50882D-F93F-4D18-B883-BBBF907B148A}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe | 
"{D0CE0B58-DCA3-440B-A4E9-2976362742D8}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{D0EB79DA-5364-410B-A7CC-0E3B1B046FB2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{E0A46DBD-F42B-4BDB-8059-1D5F4D9DEB9A}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{E51AB22B-77E5-4854-8CAD-AFC85CC264C6}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{EBE01D48-1E1D-484B-B4F5-0E6EDDC72862}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{ED92DF8E-8C27-438E-BAC0-3896D15D4331}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{EE9DEE16-2FF5-4264-9622-3C74BA60C211}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{F27F0194-374B-40B6-BED6-61258C8378B2}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{F2AEAE62-47EE-4635-8C1D-451032E01C29}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | 
"{F33616D9-7265-46AB-A889-023D7689ABA1}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | 
"{FE9799A1-D088-436D-AE34-919D3D9A93D7}" = protocol=6 | dir=in | app=c:\program files\dsl connection manager\dslcoman.exe | 
"TCP Query User{09D3A87E-63F6-4D09-8801-733D177D444B}C:\program files\novalogic\delta force black hawk down\dfbhd.exe" = protocol=6 | dir=in | app=c:\program files\novalogic\delta force black hawk down\dfbhd.exe | 
"TCP Query User{20B5B32F-51D5-4E12-851C-247EAC08491D}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"TCP Query User{225FA105-E286-4CA9-850E-50C007655E7D}C:\program files\chapura\chapura syncmanager\syncmgr.exe" = protocol=6 | dir=in | app=c:\program files\chapura\chapura syncmanager\syncmgr.exe | 
"TCP Query User{26E7B576-A2D0-4742-85AB-A886D803D332}C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\ghost recon advanced warfighter\graw.exe | 
"TCP Query User{2E890FD2-DE32-417B-8DC9-44F1AB031B70}C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\ghost recon advanced warfighter\graw.exe | 
"TCP Query User{44D300DD-CC24-4F88-B9B3-F848744DB92A}C:\program files\novalogic\delta force black hawk down\dfbhd.exe" = protocol=6 | dir=in | app=c:\program files\novalogic\delta force black hawk down\dfbhd.exe | 
"TCP Query User{570B970B-8B63-4307-8F71-F2C81FD81443}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"TCP Query User{5896246E-5BF6-4644-B98E-ACD8E763C019}C:\program files\ea games\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 1942\bf1942.exe | 
"TCP Query User{A29AA45B-6109-4D35-BBB5-3949EB1D0909}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | 
"TCP Query User{D09DA7E5-5C37-4B61-BAD1-892EC69FCBD3}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"TCP Query User{E9D0C941-995D-43EF-B43D-CCF4FB5C4A55}C:\users\jonas\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\jonas\appdata\roaming\dropbox\bin\dropbox.exe | 
"UDP Query User{088D3F28-A983-4127-BDC3-C3085243620D}C:\users\jonas\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\jonas\appdata\roaming\dropbox\bin\dropbox.exe | 
"UDP Query User{3D8BEB5F-5D20-48D7-A5A5-11EECA78D900}C:\program files\chapura\chapura syncmanager\syncmgr.exe" = protocol=17 | dir=in | app=c:\program files\chapura\chapura syncmanager\syncmgr.exe | 
"UDP Query User{41E3BA88-452C-43F6-AEB6-6E43EFE450A1}C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\ghost recon advanced warfighter\graw.exe | 
"UDP Query User{6B91F267-881D-43AF-842F-B1E066F37432}C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\ghost recon advanced warfighter\graw.exe | 
"UDP Query User{78565176-96E7-42D8-9383-829E39839E03}C:\program files\ea games\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 1942\bf1942.exe | 
"UDP Query User{9D7AB4D4-E918-43D2-9AE2-69B23DB3C5E7}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"UDP Query User{B74F1F9F-EC2B-4394-8D5B-BDFDCEC4BE24}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"UDP Query User{D0106423-EF64-44BB-BB6A-99F157EF5F6E}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | 
"UDP Query User{DD9F81CC-010C-4CA5-9880-5AC9148E54E5}C:\program files\novalogic\delta force black hawk down\dfbhd.exe" = protocol=17 | dir=in | app=c:\program files\novalogic\delta force black hawk down\dfbhd.exe | 
"UDP Query User{DF5C67B4-A023-4BE2-96DD-3CE3F54E99BA}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"UDP Query User{E78B2A2F-179B-47B2-AF33-41BD0B4014CC}C:\program files\novalogic\delta force black hawk down\dfbhd.exe" = protocol=17 | dir=in | app=c:\program files\novalogic\delta force black hawk down\dfbhd.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0819B21B-E958-438C-B06C-5A54C98833E9}" = DSL Connection Manager
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1153700F-C007-4EC7-B04A-7C14D1E6E3DD}" = OOo-dev 3.4
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{12D0BE8D-538C-4AB1-86DE-C540308F50DA}" = VAIO Content Metadata Manager Settings
"{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}" = VAIO Launcher
"{18510937-0146-417B-95D8-14706649C384}" = VAIO Content Metadata Manager Settings
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{23825B69-36DF-4DAD-9CFD-118D11D80F16}" = VAIO Content Folder Setting
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{27A2ABE9-E4C4-45DD-B9A8-CEEEE380E7E1}" = VAIO Content Metadata Intelligent Analyzing Manager
"{291FB4BF-EEC7-4CF9-8469-F39ED1DBC4D8}" = VAIO Content Metadata XML Interface Library
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{44257960-C5CC-45BA-8E83-524E4A0F3FD5}" = Cisco AnyConnect VPN Client
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5BEE8F1F-BD32-4553-8107-500439E43BD7}" = VAIO Update
"{5C5EE8F2-0B38-4C13-AE4E-A87A237FE718}" = 
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6873B7BE-1D71-4672-93D0-CC0959695CB1}" = OOo-dev 3.4 Language Pack (German)
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77555CD4-FBF8-415E-B5D0-39CB79497E0A}" = MAGIX Speed burnR (MSI)
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79872596-B887-E700-8D56-CADBC78BA5DE}" = Adobe Download Assistant
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C404084-C5A6-42FF-B731-0BAC79A6E134}" = VAIO Original Funktion Einstellungen
"{802889F8-6AF5-45A5-9764-CA5B999E50FC}" = VAIO Power Management
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FE54D21-8254-4CCF-AEE0-066496AE43F4}" = Delta Force - Black Hawk Down
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile-Gerätecenter
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95229EF6-F4A1-413A-BA50-668311FAFE19}" = VAIO Original Function Settings
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" = 
"{9A0CEF36-483A-4EAE-99B8-0E5767FFD161}_is1" = Snappy Fax Version 5
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C71059E-6DDD-4958-9251-7A5F865B6BA0}" = VAIO Content Metadata Intelligent Analyzing Manager
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{A33E457B-5369-481F-8B53-71108AE2EB5B}" = Roxio Easy Media Creator 10 LJ
"{A3563827-B0DB-44DC-B037-15CC4E5E692F}" = VAIO Content Metadata XML Interface Library
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{A9015334-10BE-4D64-A776-203336EFE806}_is1" = BlueGriffon version 1.5.2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch
"{AC76BA86-7AD7-5670-0000-800000000003}" = Korean Fonts Support For Adobe Reader 8
"{AEA6A4C2-7C4E-48F9-A770-879DE2EDEE1B}" = OpenMG Secure Module 5.4.00
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BF962E1B-D17A-4713-A100-6531A132D83D}_is1" = Foto-Mosaik-Edda Standard V5.8.0
"{C0482AA0-9CDF-49B4-9B39-551FD1A7A7E6}" = VAIO Movie Story 1.5 Upgrade
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" = VAIO Event Service
"{C774410D-3EF9-4DE7-AC01-332613163ECF}" = Kaspersky Security Suite CBE
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DEBA60A3-7CDE-48D7-993D-7C68663AEE68}" = VAIO Content Metadata Intelligent Analyzing Manager
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}" = Need for Speed™ Undercover
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile-Gerätecenter: Treiberupdate
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F46E21DF-5BE1-48E2-8390-5EEA8B25E36A}" = Microsoft SQL Server Native Client
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" = 
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FDE96E86-7780-431C-92F7-679C6A7CEC51}" = Microsoft SQL Server VSS Writer
"{FE51662F-D8F6-43B5-99D9-D4894AF00F83}" = Roxio Easy Media Creator Home
"7-Zip" = 7-Zip 4.65
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AllDup_is1" = AllDup 3.4.8
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"AudibleManager" = AudibleManager
"AVS Audio Converter 6.1_is1" = AVS Audio Converter version 6.1
"AVS Audio Converter 6.2_is1" = AVS Audio Converter version 6.2
"AVS Audio Editor 5.2_is1" = AVS Audio Editor version 5.2
"AVS Audio Recorder 3.9_is1" = AVS Audio Recorder version 3.9
"AVS Disc Creator_is1" = AVS Disc Creator version 3.5
"AVS DVD Authoring_is1" = AVS DVD Authoring
"AVS DVD Copy_is1" = AVS DVD Copy version 4.1.1
"AVS Media Player_is1" = AVS Media Player 3.1
"AVS Registry Cleaner 1.1_is1" = AVS Registry Cleaner version 1.1
"AVS Ringtone Maker 1.6_is1" = AVS Ringtone Maker version 1.6
"AVS SystemInfo_is1" = AVS System Info
"AVS TV Recorder_is1" = AVS TV Recorder 2.1.2
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor 4_is1" = AVS Video Editor 4 4.2.1.166
"AVS Video Recorder_is1" = AVS Video Recorder 2.4 (Service Version)
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"AVSCoverEditor_AVS4YOU_is1" = AVS Cover Editor 1.3.1.96 (AVS4YOU)
"Biet-O-Matic v2.14.8" = Biet-O-Matic v2.14.8
"Canon MP560 series Benutzerregistrierung" = Canon MP560 series Benutzerregistrierung
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"DAEMON Tools Lite" = DAEMON Tools Lite
"dBpoweramp DirectShow Decoder" = dBpoweramp DirectShow Decoder
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"dt icon module" = 
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink DE_is1" = DVD Shrink 3.2 deutsch (DeCSS-frei)
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 8.0.1 Home Edition
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"EXMARaLDA_is1" = EXMARaLDA 1.7
"Free Studio_is1" = Free Studio version 5.2.1
"Free WAV to MP3 Converter" = Free WAV to MP3 Converter
"FTDICOMM" = FTDI USB Serial Converter Drivers
"gtfirstboot Setting Request" = 
"ifolor-Designer" = ifolor Designer
"ImgBurn" = ImgBurn
"InstallShield_{AEA6A4C2-7C4E-48F9-A770-879DE2EDEE1B}" = OpenMG Secure Module 5.4.00
"InstallWIX_{C774410D-3EF9-4DE7-AC01-332613163ECF}" = Kaspersky Security Suite CBE
"IrfanView" = IrfanView (remove only)
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.2.0 (Full)
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"MFU Module" = 
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de)
"Mozilla Thunderbird 10.0.2 (x86 de)" = Mozilla Thunderbird 10.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"NVIDIA Drivers" = NVIDIA Drivers
"PDF reDirect" = PDF reDirect (remove only)
"PhotoScape" = PhotoScape
"Pidgin" = Pidgin
"S.T.A.L.K.E.R. - Shadow of Chernobyl_is1" = S.T.A.L.K.E.R. - Shadow of Chernobyl
"SKTools Lite" = SKTools Lite
"SPB Backup" = SPB Backup
"SPB Backup_is1" = SPB Backup 2.1.0
"TCPMP" = TCPMP
"TomTom HOME" = TomTom HOME 2.8.1.2218
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"VAIO Help and Support" = 
"VAIO_My Club VAIO" = My Club VAIO
"VCDS-Lite  1.1" = VCDS-Lite 1.1
"Verbindungsassistent" = Verbindungsassistent
"VLC media player" = VLC media player 1.1.9
"Winamp" = Winamp
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.46-1
"winscp3_is1" = WinSCP 4.3.8
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"PhotoFiltre" = PhotoFiltre
"Winamp Detect" = Winamp Erkennungs-Plug-in
"WinSetupFromUSB" = WinSetupFromUSB
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 17.07.2012 07:56:39 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 17.07.2012 07:56:39 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5725
 
Error - 17.07.2012 07:56:39 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5725
 
Error - 17.07.2012 07:59:12 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 17.07.2012 07:59:12 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 159215
 
Error - 17.07.2012 07:59:12 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 159215
 
Error - 17.07.2012 07:59:14 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 17.07.2012 07:59:14 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 160712
 
Error - 17.07.2012 07:59:14 | Computer Name = Jonas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 160712
 
Error - 17.07.2012 12:57:38 | Computer Name = Jonas-PC | Source = System Restore | ID = 8193
Description = 
 
[ Cisco AnyConnect VPN Client Events ]
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CMainThread::applyHostConfigForNoVpn File: .\MainThread.cpp
Line:
 7639 Invoked Function: CHostConfigMgr::DeterminePublicInterface Return Code: -33161196
 (0xFE060014) Description: ROUTEMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CMainThread::OnTimerExpired File: .\MainThread.cpp Line: 4287
Invoked
 Function: CMainThread::applyHostConfigForNoVpn Return Code: -33161196 (0xFE060014)
Description:
 ROUTEMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CIPv4ChangeRouteHelper::FindBestRoute File: .\IPv4ChangeRouteHelper.cpp
Line:
 2423 Invoked Function: CIPv4RouteTable::FindMatchingRoute Return Code: -33095647 
(0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CRouteMgr::UpdatePublicAddress File: .\RouteMgr.cpp Line: 
2190 Invoked Function: CChangeRouteTable::FindBestRouteInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CIPv4ChangeRouteHelper::FindBestRoute File: .\IPv4ChangeRouteHelper.cpp
Line:
 2423 Invoked Function: CIPv4RouteTable::FindMatchingRoute Return Code: -33095647 
(0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CRouteMgr::UpdatePublicAddress File: .\RouteMgr.cpp Line: 
2190 Invoked Function: CChangeRouteTable::FindBestRouteInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CNetEnvironment::testNetwork File: .\NetEnvironment.cpp Line:
 644 Invoked Function: CHostConfigMgr::DeterminePublicInterface Return Code: -33161196
 (0xFE060014) Description: ROUTEMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CNetEnvironment::TestNetEnv File: .\NetEnvironment.cpp Line:
 190 Invoked Function: CNetEnvironment::testNetwork Return Code: -33161196 (0xFE060014)
Description:
 ROUTEMGR_ERROR_PUBLIC_ADDRESS_UNAVAILABLE 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CIPv4ChangeRouteHelper::FindBestRoute File: .\IPv4ChangeRouteHelper.cpp
Line:
 2423 Invoked Function: CIPv4RouteTable::FindMatchingRoute Return Code: -33095647 
(0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 23.07.2012 16:56:47 | Computer Name = Jonas-PC | Source = vpnagent | ID = 67108866
Description = Function: CRouteMgr::UpdatePublicAddress File: .\RouteMgr.cpp Line: 
2190 Invoked Function: CChangeRouteTable::FindBestRouteInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
[ System Events ]
Error - 07.08.2012 18:10:33 | Computer Name = Jonas-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 07.08.2012 18:18:05 | Computer Name = Jonas-PC | Source = DCOM | ID = 10010
Description = 
 
Error - 07.08.2012 18:19:31 | Computer Name = Jonas-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 07.08.2012 18:19:39 | Computer Name = Jonas-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 07.08.2012 18:19:41 | Computer Name = Jonas-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 07.08.2012 18:19:49 | Computer Name = Jonas-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 07.08.2012 18:19:50 | Computer Name = Jonas-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 07.08.2012 18:20:01 | Computer Name = Jonas-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 07.08.2012 18:20:01 | Computer Name = Jonas-PC | Source = Service Control Manager | ID = 7026
Description = 
 
Error - 07.08.2012 18:21:16 | Computer Name = Jonas-PC | Source = Service Control Manager | ID = 7001
Description = 
 
 
< End of report >
         
Miniaturansicht angehängter Grafiken
BKA Trojaner Computer wurde gesperrt-bka.jpg  

Alt 08.08.2012, 13:26   #2
markusg
/// Malware-holic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:
ATTFilter
:OTL
O4 - HKCU..\Run: [mwgejhdgytlkjsb] C:\ProgramData\mwgejhdg.exe ()
[2012.08.07 18:56:37 | 000,000,051 | ---- | M] () -- C:\ProgramData\wfixytpjmdpyflo
[2012.08.07 18:56:27 | 000,061,440 | ---- | M] () -- C:\Users\Jonas\0.48665953505403625.exe
 :Files
C:\ProgramData\mwgejhdg.exe
:Commands
[Reboot]
         


• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus


für eine weitere analyse benötige ich mal folgendes.
c:\Users\name\AppData\LocalLow\Sun\Java\Deployment\cache
dort rechtsklick auf den ordner cache, diesen mit winrar oder einem anderen programm packen, und im upload channel hochladen bitte
Trojaner-Board Upload Channel
wenn dies erledigt ist, bittemelden.
__________________

__________________

Alt 08.08.2012, 13:56   #3
introplastic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



hallo,

habe die cache.zip hochgeladen. ebenso die movedfiles.zip.

habe allerdings nachdem ich otl mit dem script habe laufen lassen und der neustart (in den normalen modus) fällig war, keine text datei finden können. wie nennt die sich und wo ist die abgelegt?
__________________

Alt 08.08.2012, 17:36   #4
markusg
/// Malware-holic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



hi
danke
die finde ich dann im upload
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.
Downloade dir bitte Combofix von einem dieser Downloadspiegel

Link 1
Link 2


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 08.08.2012, 21:01   #5
introplastic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



so, combofix ausgeführt und rechner neugestartet - keine fehlermeldung...

muss ich jetzt noch was tun?

hier die combofix.txt:

Code:
ATTFilter
ComboFix 12-08-08.01 - Jonas 08.08.2012  20:34:27.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.49.1031.18.3070.1821 [GMT 2:00]
ausgeführt von:: c:\users\Jonas\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\timerintray
c:\windows\iun6002.exe
c:\windows\security\Database\tmp.edb
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\Thumbs.db
c:\windows\system32\WanPacket.dll
c:\windows\unin0407.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-07-08 bis 2012-08-08  ))))))))))))))))))))))))))))))
.
.
2012-08-08 18:46 . 2012-08-08 18:46	--------	d-----w-	c:\users\Jonas\AppData\Local\temp
2012-08-08 18:46 . 2012-08-08 18:46	--------	d-----w-	c:\users\Default\AppData\Local\temp
2012-08-08 11:41 . 2012-08-08 11:46	--------	d-----w-	C:\_OTL
2012-08-07 16:56 . 2012-08-07 16:56	--------	d-----w-	c:\programdata\ztgcrqxmyuqrqqg
2012-08-07 16:25 . 2012-06-29 08:44	6891424	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{EA5F442B-954B-43D1-9F0D-A12D06662446}\mpengine.dll
2012-08-03 21:51 . 2009-10-05 17:41	36864	----a-w-	c:\windows\system32\sfppm.dll
2012-08-03 21:50 . 2012-08-03 21:51	--------	d-----w-	c:\program files\Snappy Fax Version 5
2012-08-03 21:50 . 2012-08-03 21:50	--------	d-----w-	c:\users\Jonas\AppData\Local\Snappy Fax Version 5
2012-08-03 21:50 . 2012-08-03 21:50	--------	d-----w-	c:\users\Jonas\AppData\Local\Elevate Software
2012-07-31 22:06 . 2012-07-31 22:06	--------	d-----w-	c:\users\Jonas\AppData\Roaming\IrfanView
2012-07-31 22:06 . 2012-07-31 22:06	--------	d-----w-	c:\program files\IrfanView
2012-07-28 23:09 . 2010-10-13 04:42	2369456	----a-w-	c:\windows\system32\Codejock.CommandBars.v13.4.2.ocx
2012-07-28 23:09 . 2009-10-12 22:01	77504	----a-w-	c:\windows\system32\mtScrollContainer.ocx
2012-07-21 11:27 . 2012-07-21 12:00	--------	d-----w-	C:\DIE_TUSCHS
2012-07-11 12:22 . 2012-06-13 13:40	2047488	----a-w-	c:\windows\system32\win32k.sys
2012-07-11 12:18 . 2012-06-05 16:47	708608	----a-w-	c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 12:18 . 2012-06-05 16:47	1401856	----a-w-	c:\windows\system32\msxml6.dll
2012-07-11 12:18 . 2012-06-05 16:47	1248768	----a-w-	c:\windows\system32\msxml3.dll
2012-07-11 12:18 . 2012-06-04 15:26	440704	----a-w-	c:\windows\system32\drivers\ksecdd.sys
2012-07-11 12:18 . 2012-06-02 00:04	278528	----a-w-	c:\windows\system32\schannel.dll
2012-07-11 12:18 . 2012-06-02 00:03	204288	----a-w-	c:\windows\system32\ncrypt.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-28 05:32 . 2012-04-10 20:48	426184	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2012-07-28 05:32 . 2011-05-16 10:21	70344	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-10 19:07 . 2010-09-29 18:29	477240	----a-w-	c:\windows\system32\drivers\sptd.sys
2012-06-02 22:19 . 2012-06-29 14:47	53784	----a-w-	c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-29 14:47	45080	----a-w-	c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-29 14:46	35864	----a-w-	c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-29 14:46	577048	----a-w-	c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-29 14:47	1933848	----a-w-	c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-29 14:47	2422272	----a-w-	c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-29 14:46	88576	----a-w-	c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-29 14:46	171904	----a-w-	c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-29 14:46	33792	----a-w-	c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2010-07-15 17:32	237072	------w-	c:\windows\system32\MpSigStub.exe
2012-08-07 22:09 . 2012-01-20 08:35	136672	----a-w-	c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12	94208	----a-w-	c:\users\Jonas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12	94208	----a-w-	c:\users\Jonas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12	94208	----a-w-	c:\users\Jonas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
"Snappy Fax Printer virtual printer agent"="c:\program files\Snappy Fax Version 5\sfpagent.exe" [2009-10-05 94208]
.
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Jonas\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 19:05	98304	----a-w-	c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\r3hook.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Jonas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Jonas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OOo-dev 3.3.lnk]
path=c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OOo-dev 3.3.lnk
backup=c:\windows\pss\OOo-dev 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55	937920	----a-w-	c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2008-02-23 00:38	122880	----a-w-	c:\program files\Apoint\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-05-30 18:06	59280	----a-w-	c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
2008-05-01 13:33	221184	----a-w-	c:\program files\Kaspersky Lab\Kaspersky Security Suite CBE\avp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-03-24 02:00	1983816	----a-w-	c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40	767312	----a-w-	c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2012-04-17 15:19	3671872	----a-w-	c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2009-05-19 15:11	136544	----a-w-	c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
2007-11-21 11:38	311296	----a-w-	c:\program files\Sony\ISB Utility\ISBMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-06-07 17:33	421776	----a-w-	c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-02-12 00:47	8497696	----a-w-	c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-02-12 00:47	81920	----a-w-	c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2008-02-12 00:50	86016	----a-w-	c:\windows\System32\nvsvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-18 18:56	421888	----a-w-	c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-01-23 00:11	4718592	----a-w-	c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2008-01-23 00:11	1826816	----a-w-	c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 12:06	254696	----a-w-	c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2011-03-09 12:30	247728	----a-w-	c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-07-12 16:32	74752	----a-w-	c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23	1008184	----a-w-	c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
2007-05-31 08:21	648072	----a-w-	c:\windows\WindowsMobile\wmdc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R2 0268391304585483mcinstcleanup;0268391304585483mcinstcleanup; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	FontCache
bthsvcs	REG_MULTI_SZ   	BthServ
WindowsMobile	REG_MULTI_SZ   	wcescomm rapimgr
LocalServiceRestricted	REG_MULTI_SZ   	WcesComm RapiMgr
.
Inhalt des "geplante Tasks" Ordners
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-06 10:25]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-06 10:25]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.club-vaio.com/vbc
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MIC279~1\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MIC279~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2206084&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2206084&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{9d81af43-de53-48d0-a199-42c2a226b24c} - (no file)
WebBrowser-{9D81AF43-DE53-48D0-A199-42C2A226B24C} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
HKCU-Run-Snappy Fax - (no file)
MSConfigStartUp-3813FB3FDA73C74D - c:\judhfkashfi\judhfkashfi.exe
MSConfigStartUp-HotKeysCmds - c:\windows\system32\hkcmd.exe
MSConfigStartUp-IgfxTray - c:\windows\system32\igfxtray.exe
MSConfigStartUp-MarketingTools - c:\program files\Sony\Marketing Tools\MarketingTools.exe
MSConfigStartUp-Persistence - c:\windows\system32\igfxpers.exe
MSConfigStartUp-Prime95 - c:\users\Jonas\Downloads\p95v2511\prime95.exe
AddRemove-Uninstall_is1 - c:\program files\Common Files\DVDVideoSoft\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-08-08 20:46
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2775964904-2318342985-3309343633-1003\Software\SecuROM\License information*]
"datasecu"=hex:9a,85,31,37,9c,f8,a3,45,14,57,07,2c,b0,78,e0,0b,09,4c,6f,b6,c5,
   29,a5,08,76,da,7e,48,a1,8f,ca,4f,11,55,83,a3,0a,b7,e6,cc,a6,38,4a,94,d1,9e,\
"rkeysecu"=hex:b9,04,84,cf,bc,f7,f3,e8,79,e5,f6,b7,c2,2b,06,23
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(744)
c:\progra~1\KASPER~1\KASPER~1\r3hook.dll
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\windows\system32\WLDAP32.dll
.
- - - - - - - > 'lsass.exe'(680)
c:\progra~1\KASPER~1\KASPER~1\r3hook.dll
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\program files\Kaspersky Lab\Kaspersky Security Suite CBE\dnsq.dll
.
Zeit der Fertigstellung: 2012-08-08  20:49:13
ComboFix-quarantined-files.txt  2012-08-08 18:48
.
Vor Suchlauf: 6.216.096.768 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 10.262.711.296 Bytes frei
.
- - End Of File - - 0939E3A51A36383B0A4F33821F7DDF24
         


Alt 14.08.2012, 19:52   #6
markusg
/// Malware-holic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



hi



malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.
__________________
--> BKA Trojaner Computer wurde gesperrt

Alt 14.08.2012, 22:35   #7
introplastic
 
BKA Trojaner Computer wurde gesperrt - Standard

BKA Trojaner Computer wurde gesperrt



habe die letzte anweisung hier gerade erst gelesen, leider kam ich nicht mehr dazu Malwarebytes zu downloaden usw da ich mittlerweile unter dem gvu trojaner leide, wie in meinem anderen thread zu sehen...

Antwort

Themen zu BKA Trojaner Computer wurde gesperrt
7-zip, bho, bka trojaner, black, bonjour, codejock software, computer, converter, dsl, error, failed, firefox, flash player, format, gesperrt, google earth, grand theft auto, home, jdownloader, kaspersky, mozilla, mp3, realtek, registry, registry cleaner, rundll, scan, security, server, sperrseite, starten, svchost.exe, trojaner, ukash, vista, visual studio, windows



Ähnliche Themen: BKA Trojaner Computer wurde gesperrt


  1. Bitte dringende Hilfe! GVU-Trojaner: Ihr Computer wurde von der GVU gesperrt
    Plagegeister aller Art und deren Bekämpfung - 28.04.2013 (25)
  2. GVU Trojaner, Computer wurde gesperrt, Ausschalten des PCs
    Plagegeister aller Art und deren Bekämpfung - 02.01.2013 (5)
  3. Trojaner /Ihr Computer wurde gesperrt
    Log-Analyse und Auswertung - 29.12.2012 (17)
  4. GVU-Trojaner - Ihr Computer wurde gesperrt
    Plagegeister aller Art und deren Bekämpfung - 20.12.2012 (2)
  5. Polizei-Trojaner Österreich - Ihr Computer wurde gesperrt...
    Log-Analyse und Auswertung - 13.12.2012 (17)
  6. Trojaner: GVU - Ihr Computer wurde gesperrt / 100 € zahlen / Zugriff auf ebcam
    Plagegeister aller Art und deren Bekämpfung - 06.12.2012 (4)
  7. Bundestrojaner Variante: "Ihr Computer wurde gesperrt"; " Ihr Computer wurde durch das Speichern der autom. Informationskontrolle gesperrt"
    Log-Analyse und Auswertung - 25.11.2012 (10)
  8. Ihr Computer wurde gesperrt ... Trojaner Trojan.Ransom.Gen
    Plagegeister aller Art und deren Bekämpfung - 23.10.2012 (7)
  9. Trojaner Ihr Computer wurde automatisch gesperrt
    Plagegeister aller Art und deren Bekämpfung - 18.10.2012 (23)
  10. Trojaner: Ihr Computer wurde gesperrt Bundespolizei Ukash
    Plagegeister aller Art und deren Bekämpfung - 05.10.2012 (10)
  11. Ihr Computer wurde gesperrt - Polizei Trojaner
    Plagegeister aller Art und deren Bekämpfung - 10.09.2012 (1)
  12. Ihr Computer wurde gesperrt - Bundespolizei Trojaner
    Log-Analyse und Auswertung - 21.08.2012 (10)
  13. GUV Trojaner - Windows 7 64 Bit. Computer wurde gesperrt
    Plagegeister aller Art und deren Bekämpfung - 06.08.2012 (12)
  14. Trojaner: Bundeskriminalamt - Ihr Computer wurde gesperrt!
    Plagegeister aller Art und deren Bekämpfung - 02.07.2012 (9)
  15. ihr computer wurde von der gvu gesperrt trojaner auf Netbook
    Plagegeister aller Art und deren Bekämpfung - 10.06.2012 (1)
  16. POLIZEI - Ihr Computer wurde gesperrt - 100 Euro Trojaner
    Log-Analyse und Auswertung - 06.06.2012 (3)
  17. Ukash-Trojaner, Computer wurde gesperrt
    Plagegeister aller Art und deren Bekämpfung - 02.04.2012 (28)

Zum Thema BKA Trojaner Computer wurde gesperrt - Hallo, habe mir gestern den BKA trojaner eingefangen. (siehe angehängte grafik) Kann den laptop in sämtlichen modi starten (nur kommt bei normalem windows start eben direkt die sperrseite). Habe bereits - BKA Trojaner Computer wurde gesperrt...
Archiv
Du betrachtest: BKA Trojaner Computer wurde gesperrt auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.