![]() |
| |||||||
Log-Analyse und Auswertung: Mail vom Telekom Abuse-Team / Wichtige Sicherheitswarnung zu ihrem InternetzugangWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #1 |
| | Mail vom Telekom Abuse-Team / Wichtige Sicherheitswarnung zu ihrem Internetzugang Hallo Trojaner-Board-Team, ich habe gestern eine Mail vom Telekom Abuse-Team bekommen in dem es heißt: "wir schreiben Ihnen heute aus einem unerfreulichen Grund, denn wir haben Hinweise erhalten, dass von Ihrem Anschluss unerwünschte Zugriffe auf fremde Rechner erfolgt sind ("Hacking"). Das bedeutet konkret: Unbekannte Personen nutzen möglicherweise Ihren Internet-Zugang missbräuchlich. Eventuell sind diesen auch bereits Passwörter, Kreditkarten-, Bank- und sonstige Daten bekannt! Es besteht kein Zweifel daran, dass Ihr Internet-Zugang die Quelle ist, denn bei jeder Einwahl ins Internet wird Ihrem Router eine IP-Adresse zugewiesen. Wir haben verlässlich ermittelt, dass die genannte IP-Adresse zu dem Zeitpunkt Ihrer Zugangsnummer zugeordnet war". Ich bin jetzt natürlich sehr verunsichert und möchte Ihre Hilfe in Anspruch nehmen. Der Rechner wird ausschliesslich von mir benutzt und als Antivirensoftware habe ich Norton Internet Security von der Telekom (als Sicherheitspaket im Vertrag) installiert. Hier die gewünschten Auszüge der Scans: MBAM Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.65.1.1000 www.malwarebytes.org Datenbank Version: v2012.11.20.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Markgräfler 2012 :: MARKGRÄFLER2012 [Administrator] Schutz: Aktiviert 20.11.2012 11:23:24 mbam-log-2012-11-20 (13-04-58) Malwarescan.txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 525282 Laufzeit: 1 Stunde(n), 29 Minute(n), 26 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCR\CLSID\{312BFDCE-A901-4203-B4F2-ADCB957D1887} (Trojan.Agent) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 6 D:\Backup alter PC C\windows\Dokumente und Einstellungen\markgraefler\Desktop\RemoveWGA.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt. F:\Backup alter PC C+D\Backup alter PC C\windows\Dokumente und Einstellungen\markgraefler\Desktop\RemoveWGA.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt. C:\ProgramData\Windows\ccdxmmde.dat (Malware.Trace) -> Keine Aktion durchgeführt. C:\ProgramData\Windows\drss.dat (Malware.Trace) -> Keine Aktion durchgeführt. C:\ProgramData\Windows\msseedir.dll (Trojan.Agent) -> Keine Aktion durchgeführt. C:\ProgramData\Windows\xessmsxe.dat (Malware.Trace) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter OTL Extras logfile created on: 20.11.2012 13:25:13 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Markgräfler 2012\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,98 Gb Total Physical Memory | 2,16 Gb Available Physical Memory | 54,32% Memory free
7,97 Gb Paging File | 5,97 Gb Available in Paging File | 74,99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 159,90 Gb Total Space | 118,10 Gb Free Space | 73,86% Space Free | Partition Type: NTFS
Drive D: | 305,76 Gb Total Space | 275,74 Gb Free Space | 90,18% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 298,97 Gb Free Space | 64,19% Space Free | Partition Type: NTFS
Computer Name: MARKGRÄFLER2012 | User Name: Markgräfler 2012 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{056135B6-EBF1-40D8-ABC6-E9D656C56862}" = lport=445 | protocol=6 | dir=in | app=system |
"{0FDD6C46-404B-4AD1-8046-3C023A22498E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{10E32BD4-703D-4FB8-B8AA-1F8FA0E4899A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{16B56973-0688-4BB8-9864-E204BBECE589}" = lport=139 | protocol=6 | dir=in | app=system |
"{20CEA9A0-FB12-4DA9-BDE3-F89429D57396}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{24F1F2D7-043B-4BA5-876D-98F2A357642D}" = rport=445 | protocol=6 | dir=out | app=system |
"{42F38DD4-B3E4-4BC7-930C-8705A5293161}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4BF47541-DD56-434A-A201-78CF38BE9CE6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52FCBDD1-FB60-4D3A-AC14-FCBF02D072CF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{693921CA-2323-4283-91BB-8E41491EEB22}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{703731A9-5934-497A-A611-DFB63DB83183}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{77A632AC-5A72-4588-8D08-15BF8093C33A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7A59E5BB-CA55-41F4-A570-9AB87DA3809B}" = lport=137 | protocol=17 | dir=in | app=system |
"{882CD634-D919-4373-A708-0AD6609FC369}" = lport=10243 | protocol=6 | dir=in | app=system |
"{925212EA-04A4-45A3-8214-9C451B65D255}" = lport=2869 | protocol=6 | dir=in | app=system |
"{929220FF-B905-43E0-8078-535B379EECD6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B4822530-791D-4F56-96FC-991654607AAB}" = rport=138 | protocol=17 | dir=out | app=system |
"{C43181F3-6541-4E02-8841-65EC2A301919}" = rport=139 | protocol=6 | dir=out | app=system |
"{C96EA3BF-2531-400F-A8AD-76FACD02F102}" = rport=137 | protocol=17 | dir=out | app=system |
"{DF5E8CCA-7D42-4F32-B88E-8EFE7C4807C9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EE4A7CE5-7445-451E-9192-3B8836F1FABE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F0669238-9EE4-40B4-9063-BF68370EB580}" = lport=138 | protocol=17 | dir=in | app=system |
"{F62F0A93-AA86-44B1-A419-A9956C460BC3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F2F55B-537E-4079-906C-18D05AB2595C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{12C2C0E7-AEF6-48C5-9799-A3E151F6A3AC}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{13CBD5A4-289E-4398-8225-A7474AF18876}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{289263DC-6668-4681-847A-CC259630BF04}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3033B2AD-14BE-4899-8E79-5104380416E9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3499F45D-ED6F-4606-8CD9-37D92FA23661}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{40B4C050-42D0-4DFB-AFE9-AC62FC3063CA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{470C886F-C5A0-40CE-AA57-FCC8198ED1C2}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{49D9D650-DAFB-4D7E-9463-B1CB7728C28E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4C1D05BA-1B59-411B-9A0B-043D5B747BFA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4CFA2624-0D77-43E2-B664-405CF09BF6FA}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{51D06682-116B-4BE6-B3BC-1B11A44F8E21}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{57E5B0F5-A123-4690-A10B-9CD435268D07}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5C688C5A-1FD6-4467-A17D-8DE0C8654DB2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{691BD366-44DA-4BBC-A5CF-C668FD881C76}" = protocol=6 | dir=out | app=system |
"{6F36E621-7DC4-40BF-83D5-EE522FC9B2FA}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe |
"{71E16824-4179-42B7-BC8E-F5EE70FB8E46}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8CAC2EEB-C545-4168-9C1A-28B7C10B80AF}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9C2489E8-EF50-4B45-9504-920C8080D76B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AB6BFEB9-8E3E-4688-9410-E18789D248DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B41895E4-E8DC-4F3C-A4A2-006F3F0CB08E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CC9D5D0A-5DC7-4018-901B-F99AD4403C32}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{CFAE8F0E-B87D-4ECF-A2C2-BE44597AD7BE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{ED2536BE-BD60-4188-8777-0A5BACB4567C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FBDECE32-315F-4D33-AEF3-738AE1EF4AAE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.16.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.61.3
"GIMP-2_is1" = GIMP 2.8.2
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Toolbar3 x64_is1" = Toolbar 3.0 der Telekom x64
"VLC media player" = VLC media player 2.0.2
"Windows7FirewallControl_is1" = Windows7FirewallControl (x64) 5.0.0.15
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 9
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
"{295C31E5-3F91-498E-9623-DA24D2FA2B6A}" = T-Online WLAN-Access Finder
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2F672AB6-053A-4F23-855F-F57F7BFBA163}_is1" = WGA Remover version 1.2
"{3B35725F-C623-4A1E-B5CC-99C0868679E3}" = Smart 6 B11.0824.1
"{3B983EFD-6E37-4AD9-9A7D-8C83E61674F7}" = Splashtop Connect IE
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{41E496B5-47F4-11D6-9BBB-00E0987BB2CD}" = ZSMC USB PC Camera
"{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B11.0823.1
"{45D49CA7-D7D8-4659-B35A-EBD98C30AF28}" = Splashtop Connect for Firefox
"{48D082B9-18F6-4426-AFAC-8B6A3E7021B1}" = Brother MFL-Pro Suite MFC-250C
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{675F86A8-E093-4002-87D5-915CC2C45571}" = DES 2.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.8.0
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{B1275E23-717A-4D52-997A-1AD1E24BC7F3}" = T-Online 6.0
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS
"{C75FAD21-EC08-42F3-92D6-C9C0AB355345}" = AutoGreen B10.1021.1
"{D4C7DAB9-6623-4D86-9B9A-C9F8903BA4D2}" = MediaImpression 2.0 for PENTAX
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{DADC7AB0-E554-4705-9F6A-83EA82ED708E}" = Realtek Ethernet Diagnostic Utility
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 9
"InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B11.0823.1
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}" = AutoGreen B10.1021.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
"Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MySSID_is1" = Vtune 7.22
"NIS" = Norton Internet Security
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Toolbar3_is1" = Toolbar 3.0 der Telekom
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 16.11.2012 08:10:35 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 16.11.2012 13:00:01 | Computer Name = Markgräfler2012 | Source = Windows Backup | ID = 4103
Description =
Error - 17.11.2012 05:00:53 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 17.11.2012 08:52:30 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 17.11.2012 09:39:29 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 18.11.2012 08:32:53 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 19.11.2012 04:48:58 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 19.11.2012 09:54:27 | Computer Name = Markgräfler2012 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 16.0.2.4680,
Zeitstempel: 0x50882871 Name des fehlerhaften Moduls: msvcrt.dll, Version: 7.0.7601.17744,
Zeitstempel: 0x4eeaf722 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000a05b ID des fehlerhaften
Prozesses: 0x1230 Startzeit der fehlerhaften Anwendung: 0x01cdc63358dc2c8e Pfad der
fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Pfad
des fehlerhaften Moduls: C:\Windows\syswow64\msvcrt.dll Berichtskennung: a196ebe0-3250-11e2-b718-902b34186949
Error - 20.11.2012 04:53:59 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
Error - 20.11.2012 08:09:52 | Computer Name = Markgräfler2012 | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 09.11.2012 10:35:32 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 09.11.2012 13:32:03 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 13.11.2012 08:33:16 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 14.11.2012 13:37:35 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 15.11.2012 11:59:53 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 15.11.2012 12:15:19 | Computer Name = Markgräfler2012 | Source = volsnap | ID = 393230
Description = Die Schattenkopien von Volume "H:" wurden aufgrund eines E/A-Fehlers
auf Volume "H:" abgebrochen.
Error - 18.11.2012 09:33:48 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 19.11.2012 10:16:58 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 19.11.2012 13:51:14 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error - 20.11.2012 06:30:37 | Computer Name = Markgräfler2012 | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
< End of report >
Code:
ATTFilter @BIOS GIGABYTE 24.08.2012 2.12 Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 09.10.2012 6,00MB 11.4.402.287 Adobe Flash Player 11 Plugin Adobe Systems Incorporated 12.11.2012 6,00MB 11.5.502.110 Adobe Reader X (10.1.4) - Deutsch Adobe Systems Incorporated 11.10.2012 121MB 10.1.4 Apple Application Support Apple Inc. 29.08.2012 61,0MB 2.1.7 Apple Software Update Apple Inc. 29.08.2012 2,38MB 2.1.3.127 AutoGreen B10.1021.1 GIGABYTE 24.08.2012 4,77MB 1.00.0000 Brother MFL-Pro Suite MFC-250C Brother Industries, Ltd. 25.09.2012 1.0.1.0 CCleaner Piriform 24.10.2012 3.24 CPUID CPU-Z 1.61.3 24.08.2012 3,16MB CyberLink Media Suite 9 CyberLink Corp. 24.08.2012 33,0MB 9.0.2608 CyberLink PowerDVD 9 CyberLink Corp. 24.08.2012 164MB 9.0.3518.02 DES 2.0 Gigabyte 24.08.2012 1.00.0000 DHTML Editing Component Microsoft Corporation 22.10.2012 554KB 6.02.0001 Easy Tune 6 B11.0823.1 GIGABYTE 24.08.2012 34,5MB 1.00.0000 GIMP 2.8.2 The GIMP Team 03.09.2012 234MB 2.8.2 Google Chrome Google Inc. 24.09.2012 23.0.1271.64 Intel(R) Control Center Intel Corporation 24.08.2012 1.2.1.1007 Intel(R) Management Engine Components Intel Corporation 24.08.2012 7.0.0.1118 Intel(R) Rapid Storage Technology Intel Corporation 24.08.2012 10.6.0.1002 Java 7 Update 9 Oracle 05.09.2012 128MB 7.0.90 Malwarebytes Anti-Malware Version 1.65.1.1000 Malwarebytes Corporation 20.11.2012 19,4MB 1.65.1.1000 MediaImpression 2.0 for PENTAX ArcSoft 03.09.2012 178MB 2.0.63.826 Microsoft .NET Framework 4 Client Profile Microsoft Corporation 28.08.2012 38,8MB 4.0.30319 Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 28.08.2012 2,93MB 4.0.30319 Microsoft Office Home and Student 2010 Microsoft Corporation 27.08.2012 14.0.6029.1000 Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 27.08.2012 300KB 8.0.56336 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 24.08.2012 788KB 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 28.08.2012 788KB 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 24.08.2012 596KB 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 28.08.2012 600KB 9.0.30729.6161 Mozilla Firefox 16.0.2 (x86 de) Mozilla 29.10.2012 38,5MB 16.0.2 Mozilla Maintenance Service Mozilla 29.10.2012 329KB 16.0.2 Norton Internet Security Symantec Corporation 15.11.2012 20.2.0.19 NVIDIA 3D Vision Controller-Treiber 301.42 NVIDIA Corporation 24.08.2012 301.42 NVIDIA 3D Vision Treiber 306.97 NVIDIA Corporation 18.11.2012 306.97 NVIDIA Grafiktreiber 306.97 NVIDIA Corporation 18.11.2012 306.97 NVIDIA HD-Audiotreiber 1.3.16.0 NVIDIA Corporation 24.08.2012 1.3.16.0 NVIDIA PhysX-Systemsoftware 9.12.0213 NVIDIA Corporation 24.08.2012 9.12.0213 NVIDIA Update 1.8.15 NVIDIA Corporation 24.08.2012 1.8.15 ON_OFF Charge B11.0110.1 GIGABYTE 24.08.2012 1.00.0001 PDF24 Creator 4.8.0 PDF24.org 29.08.2012 33,9MB QuickTime Apple Inc. 29.08.2012 73,2MB 7.72.80.56 Realtek Ethernet Controller Driver Realtek 24.08.2012 7.46.531.2011 Realtek Ethernet Diagnostic Utility Realtek 24.08.2012 1.00.0000 Realtek High Definition Audio Driver Realtek Semiconductor Corp. 24.08.2012 6.0.1.6423 Skype™ 5.10 Skype Technologies S.A. 29.08.2012 19,4MB 5.10.116 Smart 6 B11.0824.1 GIGABYTE 24.08.2012 1.00.0000 Splashtop Connect for Firefox Splashtop Inc. 24.08.2012 1.1.8.4 Splashtop Connect IE Splashtop Inc. 24.08.2012 1.1.13.1 T-Online 6.0 22.10.2012 T-Online WLAN-Access Finder 22.10.2012 Toolbar 3.0 der Telekom Deutsche Telekom AG 22.10.2012 9,92MB 3.0.2 (2) Toolbar 3.0 der Telekom x64 Deutsche Telekom AG 22.10.2012 11,9MB 3.0.2 (3) VLC media player 2.0.2 VideoLAN 29.08.2012 2.0.2 Vtune 7.22 24.08.2012 11,2MB WGA Remover version 1.2 WGAREMOVER 25.09.2012 1,55MB 1.2 Windows7FirewallControl (x64) 5.0.0.15 Sphinx Software 27.08.2012 5.0.0.15 WinRAR 4.20 (64-Bit) win.rar GmbH 15.11.2012 4.20.0 ZSMC USB PC Camera 15.11.2012 Geändert von Markgräfler (20.11.2012 um 14:15 Uhr) |
| Themen zu Mail vom Telekom Abuse-Team / Wichtige Sicherheitswarnung zu ihrem Internetzugang |
| abuse-team, administrator, anschluss, anti-malware, autostart, code, cpu-z, dateien, desktop, explorer, install.exe, karte, mail, malwarebytes, norton, norton internet security, nvidia update, passwörter, personen, rechner, router, security, sicherheitswarnung, software, speicher, telekom, test, trojan.agent, version |