![]() |
|
Plagegeister aller Art und deren Bekämpfung: Antimalware Doctor eingefangen - Malwarebytes hängt sich aufWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() ![]() | ![]() Antimalware Doctor eingefangen - Malwarebytes hängt sich auf Hallo liebes Forum, gestern Abend habe ich mir auch den Antimalware Doctor eingefangen. Nachdem ich zahlreiche Foren durchstöbert habe, habe ich die Anweisungen hier aus dem Forum befolgt, rkill auszuführen und dann Malwarebytes durchlaufen zu lassen. rkill ließ sich auch ohne Probleme ausführen, allerdings hängt sich Malwarebytes auf. Das Programm ist hängen geblieben bei: "Durchsuche zur Zeit: C:\Program Files\Movie Maker\OmdProject.dll" bei einem Scan mit AntiVir, den ich vorher im abgesicherten Modus durchgeführt habe, hat sich das Programm ebenfalls beim Durchsuchen dieses Ordners aufgehängt. Gleichzeitig erscheint ein Dialog-Fenster mit dem Titel "Security Warning Application cannot be executed. the file crashreporter.exe is infected. Do you want to activate your antivirus software now?" Das ist, wie ich annehme, eine Meldung vom Antimalware Doctor, oder?! Schlißen kann ich das nicht. Der Task-Manager lässt sich ebenfall nicht aufrufen. Wenn ich das probiere, wird der Bildschrim nach einer Zeit schwarz und es erscheint noch eine weitere Meldung: "Fehler beim Erstellen des Sicherheitsoptionen-Dialogfeldes Fehler-Sicherheitsoptionen" Nichts hilft, außer das Drücken des Netzschalters. Kann mir jemand weiterhelfen? ok, ich habe gerade eine quick scan mit Malwarebytes durchgeführt. das ging. Ich hab die Anweisungen befolgt und die infizierten Dateien löschen lassen. Wie im Forum beschrieben poste ich jetzt mal den Bericht. Wird jemand da schlau raus und kann mir sagen, wie ich weiter vorgehen soll? Herzlichen Dank schon mal im Voraus! Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4488 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 27.08.2010 16:11:05 mbam-log-2010-08-27 (16-11-05).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 139559 Laufzeit: 6 Minute(n), 15 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 2 Infizierte Registrierungswerte: 9 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 9 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmxnwersao.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xwarcemson.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\newsecureapp70700.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*upd_debug.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*upd_debug.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cngfuawj (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nfljvkga (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gdukhsmn (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\whxvarjy (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Users\***\AppData\Local\Temp\cmxnwersao.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Local\Temp\xwarcemson.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Roaming\C57572CD1FEB9F1B2EAB4009BCD77F4C\newsecureapp70700.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Roaming\C57572CD1FEB9F1B2EAB4009BCD77F4C\upd_debug.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Local\Windows\winhelp.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Local\naspbrjkh\tlvhgwxshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Local\gneocswlw\tlmmfgfshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Local\qbvoclkep\tshpkcwshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. C:\Users\***\AppData\Local\lbmnculnq\tkkcaicshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. ...einen Systemscan mit OTL habe ich nun ebenfalls durchgeführt. Die log-File hänge ich hier ebenfalls an:OTL Logfile: Code:
ATTFilter OTL logfile created on: 27.08.2010 16:24:06 - Run 1 OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\***\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 116,44 Gb Total Space | 21,82 Gb Free Space | 18,74% Space Free | Partition Type: NTFS Drive D: | 106,68 Gb Total Space | 2,33 Gb Free Space | 2,18% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 7,40 Gb Total Space | 6,34 Gb Free Space | 85,67% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HÄNZ-PC Current User Name: *** Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\***\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) PRC - C:\Program Files\pdf24\pdf24.exe (Geek Software GmbH) PRC - C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe () PRC - C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Windows\ASScrPro.exe () PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor) PRC - D:\Tobit ClipInc\Server\ClipInc-Server.exe () PRC - C:\Program files\P4G\BatteryLife.exe (ATK) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.) PRC - C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS) PRC - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) PRC - C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS) PRC - C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (ASUS) PRC - C:\Program Files\ASUS\Splendid\ACMON.exe (ATK) PRC - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) PRC - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.) PRC - C:\Program Files\ASUS\ATK Hotkey\WDC.exe () PRC - C:\Windows\System32\conime.exe (Microsoft Corporation) PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe () PRC - C:\Program Files\ASUS\ASUS Live Update\ALU.exe () PRC - C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe () PRC - C:\Program Files\ATKOSD2\ATKOSD2.exe () PRC - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe () PRC - C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe () PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe () PRC - C:\Program Files\Wireless Console 2\wcourier.exe () PRC - C:\Windows\System32\ACEngSvr.exe (ASUSTeK) ========== Modules (SafeList) ========== MOD - C:\Users\***\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (GoogleDesktopManager-051210-111108) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) SRV - (Radio.fx) -- C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe () SRV - (Application Updater) -- C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (ClipInc001) -- D:\Tobit ClipInc\Server\ClipInc-Server.exe () SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.) SRV - (ADSMService) -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.) SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (ASLDRService) -- C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe () SRV - (ATKGFNEXSrv) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe () SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation) ========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (CVPNDRVA) -- C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.) DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\System32\drivers\snp2uvc.sys () DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (DNE) -- C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.) DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation) DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.) DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation) DRV - (AsDsm) -- C:\Windows\System32\drivers\AsDsm.sys (Windows (R) Codename Longhorn DDK provider) DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC) DRV - (ASMMAP) -- C:\Program Files\ATKGFNEX\ASMMAP.sys () DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation ) DRV - (kbfiltr) -- C:\Windows\System32\drivers\kbfiltr.sys ( ) DRV - (CVirtA) -- C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.) DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ATK0100) DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.) DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = iGoogle IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = iGoogle IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522 ========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398" FF - prefs.js..browser.startup.homepage: "www.tagesschau.de" FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2 FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198 FF - HKLM\software\mozilla\Mozilla Firefox 3.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.09 09:52:47 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.03 12:40:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.07.09 09:52:47 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2009.07.09 00:48:56 | 000,000,000 | ---D | M] -- C:\Users\Hänz\AppData\Roaming\mozilla\Extensions [2009.07.09 00:48:56 | 000,000,000 | ---D | M] -- C:\Users\Hänz\AppData\Roaming\mozilla\Firefox\Profiles\uorrjzqe.default\extensions [2010.07.19 10:50:01 | 000,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2010.07.19 10:49:57 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2009.06.24 14:37:42 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2009.06.24 14:37:42 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2009.06.24 14:37:42 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2009.06.24 14:37:42 | 000,000,986 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2009.06.24 14:37:42 | 000,000,801 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll File not found O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll File not found O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe () O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe () O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ATKOSD2\ATKOSD2.exe () O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) O4 - HKLM..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe () O4 - HKLM..\Run: [ Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NeroCheck] C:\Windows\System32\\NeroCheck.exe () O4 - HKLM..\Run: [P2Go_Menu] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\RunOnce: [*hostcacheadm.exe] C:\Users\Hänz\hostcacheadm.exe () O4 - Startup: C:\Users\Hänz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Hänz\AppData\Roaming\Dropbox\bin\Dropbox.exe () O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet) O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {00000130-9980-0010-8000-00AA00389B71} hxxp://codecs.microsoft.com/codecs/i386/ACELPACM.CAB (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL (Google) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Users\Hänz\Desktop\PresseLive\rise_against_tim_mcilrath_2_2.JPG O24 - Desktop BackupWallPaper: C:\Users\Hänz\Desktop\PresseLive\rise_against_tim_mcilrath_2_2.JPG O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{3f7803a7-9e31-11df-8ef7-00248c454e09}\Shell - "" = AutoRun O33 - MountPoints2\{3f7803a7-9e31-11df-8ef7-00248c454e09}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found O33 - MountPoints2\{b9ffb112-2e99-11df-9ea0-00248c454e09}\Shell - "" = AutoRun O33 - MountPoints2\{b9ffb112-2e99-11df-9ea0-00248c454e09}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O33 - MountPoints2\{c0a31e53-a6e1-11df-9da2-00248c454e09}\Shell - "" = AutoRun O33 - MountPoints2\{c0a31e53-a6e1-11df-9da2-00248c454e09}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.08.27 16:22:11 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2010.08.27 13:50:01 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2010.08.27 13:49:51 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.08.27 13:49:49 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.08.27 13:49:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.08.27 13:49:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010.08.27 13:48:10 | 006,153,648 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\***\Desktop\mbam-setup.exe [2010.08.27 00:09:06 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\lbmnculnq [2010.08.27 00:09:04 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\qbvoclkep [2010.08.27 00:08:57 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\gneocswlw [2010.08.27 00:08:54 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\naspbrjkh [2010.08.27 00:08:45 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Windows [2010.08.27 00:08:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Windows Server [2010.08.27 00:08:11 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\C57572CD1FEB9F1B2EAB4009BCD77F4C [2010.08.24 15:26:34 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\HDRVersuche [2010.08.24 15:22:02 | 000,000,000 | ---D | C] -- C:\Users\***\LuminanceHDR [2010.08.24 15:21:53 | 000,000,000 | ---D | C] -- C:\Program Files\Luminance HDR [2010.08.24 15:19:15 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\luminance-hdr_2.0.0 [2010.08.23 16:05:22 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Rakaa -- Crown Of Thorns [Decon, 2010] [2010.08.17 13:02:37 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Marvin und Ball [2010.08.11 21:17:35 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\(Ambient, Electronic) Clubroot - II - MMX - 2010, MP3, 320 kbps [mikkisays.net] [2010.08.03 18:35:04 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\DPP Tutorial [2010.07.30 01:03:26 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\ISL [2010.07.30 01:02:55 | 000,000,000 | ---D | C] -- C:\Program Files\ISL [2010.07.30 01:00:39 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations [2008.07.23 01:56:59 | 000,176,128 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll [2007.01.24 05:08:39 | 000,005,632 | ---- | C] ( ) -- C:\Windows\System32\drivers\kbfiltr.sys ========== Files - Modified Within 30 Days ========== [2010.08.27 16:25:43 | 002,097,152 | -HS- | M] () -- C:\Users\***\NTUSER.DAT [2010.08.27 16:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2010.08.27 16:12:29 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.08.27 16:12:29 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.08.27 16:12:25 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.08.27 16:12:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.08.27 16:12:18 | 3212,042,240 | -HS- | M] () -- C:\hiberfil.sys [2010.08.27 16:11:28 | 000,524,288 | -HS- | M] () -- C:\Users\Hänz\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms [2010.08.27 16:11:28 | 000,065,536 | -HS- | M] () -- C:\Users\Hänz\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2010.08.27 16:11:27 | 001,457,229 | -H-- | M] () -- C:\Users\Hänz\AppData\Local\IconCache.db [2010.08.27 16:11:05 | 000,154,112 | ---- | M] () -- C:\Users\Hänz\hostcacheadm.exe [2010.08.27 16:00:27 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe [2010.08.27 15:37:58 | 000,000,680 | ---- | M] () -- C:\Users\Hänz\AppData\Local\d3d9caps.dat [2010.08.27 14:46:36 | 000,000,825 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.27 13:48:10 | 006,153,648 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Hänz\Desktop\mbam-setup.exe [2010.08.27 13:42:58 | 000,363,520 | ---- | M] () -- C:\Users\Hänz\Desktop\rkill.com [2010.08.26 23:58:57 | 003,835,678 | ---- | M] () -- C:\Users\Hänz\Desktop\Erdmöbel - Nah bei dir.mp3 [2010.08.26 15:51:26 | 002,571,776 | ---- | M] () -- C:\Users\Hänz\Desktop\100825_Nowbakht_6_Korrekturen von Hänz Kapitel 4_26_08_2010.doc [2010.08.26 15:30:23 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F98472F7-C93A-43A1-A35B-ABC61E9D366F}.job [2010.08.26 14:35:57 | 000,028,672 | ---- | M] () -- C:\Users\Hänz\Desktop\MZ Geigle Sandbaumhüter.doc [2010.08.26 11:46:01 | 000,163,987 | ---- | M] () -- C:\Users\Hänz\.recently-used.xbel [2010.08.24 15:21:58 | 000,000,789 | ---- | M] () -- C:\Users\Public\Desktop\Luminance HDR.lnk [2010.08.24 15:18:51 | 002,450,689 | ---- | M] () -- C:\Users\Hänz\Desktop\luminance-hdr_2.0.0.tar.gz [2010.08.24 01:42:50 | 000,070,144 | ---- | M] () -- C:\Users\Hänz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.08.23 16:09:37 | 109,940,472 | ---- | M] () -- C:\Users\Hänz\Desktop\Mit -- Nanonotes [V2, 2010].zip [2010.08.23 16:08:45 | 067,260,254 | ---- | M] () -- C:\Users\Hänz\Desktop\Matthew Dear -- Black City [Ghostly, 2010].zip [2010.08.23 16:04:55 | 101,569,962 | ---- | M] () -- C:\Users\Hänz\Desktop\Oriol -- Night And Day [Planet Mu, 2010].zip [2010.08.23 15:58:37 | 000,107,697 | ---- | M] () -- C:\Users\Hänz\Desktop\Ernst-Moritz-Arndt-Universi....pdf [2010.08.23 12:40:55 | 000,108,013 | ---- | M] () -- C:\Users\Hänz\Desktop\PR Den Haag D 15. September oder 1. Oktober 2010.pdf [2010.08.16 18:27:40 | 001,418,806 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2010.08.16 18:27:40 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.08.16 18:27:40 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.08.16 18:27:40 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.08.16 18:27:40 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.08.03 20:08:34 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Digital Photo Professional.lnk [2010.07.29 15:54:14 | 000,524,288 | -HS- | M] () -- C:\Users\Hänz\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms ========== Files Created - No Company Name ========== [2010.08.27 16:11:05 | 000,154,112 | ---- | C] () -- C:\Users\Hänz\hostcacheadm.exe [2010.08.27 16:00:01 | 3212,042,240 | -HS- | C] () -- C:\hiberfil.sys [2010.08.27 13:49:53 | 000,000,825 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.27 13:42:57 | 000,363,520 | ---- | C] () -- C:\Users\Hänz\Desktop\rkill.com [2010.08.27 00:48:02 | 000,000,680 | ---- | C] () -- C:\Users\Hänz\AppData\Local\d3d9caps.dat [2010.08.26 23:58:34 | 003,835,678 | ---- | C] () -- C:\Users\Hänz\Desktop\Erdmöbel - Nah bei dir.mp3 [2010.08.26 15:51:25 | 002,571,776 | ---- | C] () -- C:\Users\Hänz\Desktop\100825_Nowbakht_6_Korrekturen von Hänz Kapitel 4_26_08_2010.doc [2010.08.26 14:12:47 | 000,028,672 | ---- | C] () -- C:\Users\Hänz\Desktop\MZ Geigle Sandbaumhüter.doc [2010.08.26 11:46:01 | 000,163,987 | ---- | C] () -- C:\Users\Hänz\.recently-used.xbel [2010.08.24 15:21:58 | 000,000,789 | ---- | C] () -- C:\Users\Public\Desktop\Luminance HDR.lnk [2010.08.24 15:18:50 | 002,450,689 | ---- | C] () -- C:\Users\Hänz\Desktop\luminance-hdr_2.0.0.tar.gz [2010.08.23 16:05:15 | 067,260,254 | ---- | C] () -- C:\Users\Hänz\Desktop\Matthew Dear -- Black City [Ghostly, 2010].zip [2010.08.23 16:05:09 | 109,940,472 | ---- | C] () -- C:\Users\Hänz\Desktop\Mit -- Nanonotes [V2, 2010].zip [2010.08.23 16:00:31 | 101,569,962 | ---- | C] () -- C:\Users\Hänz\Desktop\Oriol -- Night And Day [Planet Mu, 2010].zip [2010.08.23 15:58:36 | 000,107,697 | ---- | C] () -- C:\Users\Hänz\Desktop\Ernst-Moritz-Arndt-Universi....pdf [2010.08.23 12:40:55 | 000,108,013 | ---- | C] () -- C:\Users\Hänz\Desktop\PR Den Haag D 15. September oder 1. Oktober 2010.pdf [2010.07.13 18:08:45 | 000,004,096 | -H-- | C] () -- C:\Users\Hänz\AppData\Local\keyfile3.drm [2010.02.11 13:19:37 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2010.02.06 12:37:11 | 000,000,055 | ---- | C] () -- C:\Windows\cryavitowmv.ini [2009.07.15 17:22:18 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini [2009.07.14 09:27:15 | 000,070,144 | ---- | C] () -- C:\Users\Hänz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.07.10 13:14:16 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2009.07.09 16:48:42 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2009.07.09 15:05:01 | 000,554,496 | ---- | C] () -- C:\Windows\System32\dvmsg.dll [2009.02.24 05:11:42 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll [2009.02.24 04:57:52 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll [2008.08.29 14:58:26 | 000,197,408 | ---- | C] () -- C:\Windows\System32\vpnapi.dll [2008.07.23 01:59:59 | 001,772,544 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys [2008.07.23 01:57:59 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini [2008.07.23 01:56:59 | 000,028,160 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys [2008.04.16 12:43:39 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.03.08 12:57:59 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2003.02.20 17:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI [2002.08.31 07:00:00 | 000,001,770 | -H-- | C] () -- C:\Windows\System32\msisl$.dll < End of report > ...und hier die zweite log-File:OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 27.08.2010 16:24:06 - Run 1 OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Hänz\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 116,44 Gb Total Space | 21,82 Gb Free Space | 18,74% Space Free | Partition Type: NTFS Drive D: | 106,68 Gb Total Space | 2,33 Gb Free Space | 2,18% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 7,40 Gb Total Space | 6,34 Gb Free Space | 85,67% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HÄNZ-PC Current User Name: Hänz Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02A24FD3-63BA-473D-9E1F-6DEE7FA6D6B3}" = protocol=17 | dir=in | app=c:\program files\tobit radio.fx\server\rfx-server.exe | "{12D83608-9499-4D25-B82D-C2A2272984AD}" = protocol=6 | dir=in | app=c:\users\hänz\appdata\roaming\dropbox\bin\dropbox.exe | "{3E829DBA-3451-4C0B-904D-AF2EC93DA4B4}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{5F1A3EE9-5DA9-40EF-9FD1-E430C5AEEBAA}" = protocol=6 | dir=in | app=c:\program files\tobit radio.fx\server\rfx-server.exe | "{8E1D4E5B-6544-4B36-96F4-E5FCF81B3D14}" = protocol=17 | dir=in | app=c:\users\hänz\appdata\roaming\dropbox\bin\dropbox.exe | "{8EEA962B-64D2-4825-AC5E-AA785A8BF3FC}" = protocol=17 | dir=in | app=d:\tobit clipinc\player\clipinc-player.exe | "{95538F67-CE87-424F-A8BE-14E0D8AD2AFF}" = protocol=17 | dir=in | app=c:\program files\tobit radio.fx\client\rfx-client.exe | "{99C01370-2B8B-445B-BE8A-23E5476FB364}" = protocol=6 | dir=in | app=d:\tobit clipinc\player\clipinc-player.exe | "{AE46B3AC-86EC-4CCE-AB30-16229870D5B6}" = protocol=6 | dir=in | app=c:\program files\tobit radio.fx\client\rfx-client.exe | "{B5AD102A-4F1E-4741-9C1D-C332FB3CAE76}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{BF97F3B6-734B-40C7-A850-760A5912E769}" = protocol=17 | dir=in | app=d:\tobit clipinc\server\clipinc-server.exe | "{C01EFC9C-D178-4B1E-A5E9-C29280D544D1}" = protocol=6 | dir=in | app=d:\tobit clipinc\server\clipinc-server.exe | "{CD2670B6-71BA-40F7-B855-0BF399CD4D61}" = protocol=6 | dir=in | app=d:\tobit clipinc\player\radiorecorder.exe | "{E0C385FA-BA8E-449B-A72E-5B040C348D52}" = protocol=17 | dir=in | app=d:\tobit clipinc\player\radiorecorder.exe | "{FC7783CF-3C7E-4830-838F-F8E25424C099}" = dir=in | app=c:\program files\skype\phone\skype.exe | "TCP Query User{608F1311-9097-431F-8E68-6E771070BBC1}C:\program files\zattoo\zattood.exe" = protocol=6 | dir=in | app=c:\program files\zattoo\zattood.exe | "TCP Query User{90467992-E63B-43BC-B991-77F5D8B63EFF}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe | "TCP Query User{AA713469-2D09-4011-821C-631348A8C48D}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{21D590A2-E299-44D3-BE86-02E450F778A8}C:\program files\zattoo\zattood.exe" = protocol=17 | dir=in | app=c:\program files\zattoo\zattood.exe | "UDP Query User{ADE99BA1-BDE6-4D89-9D3E-BF4B590447C4}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe | "UDP Query User{F7D27824-49B3-4036-AD36-860EE7A08CD4}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology "{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1 "{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}" = ASUS Data Security Manager "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3 "{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module "{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}" = Cisco Systems VPN Client 5.0.04.0300 "{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2 "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.03 "{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}" = ATKOSD2 "{62CF8923-31DC-4285-A23C-17CE5AA6A679}" = Express Gate "{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{7020FC34-6E04-4858-924D-354B28CB2402}_is1" = Luminance HDR 2.0.0 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey "{80557F5B-A54A-4700-8E19-8E4DA16508A5}" = SILKYPIX Developer Studio 3.0G "{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator "{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module "{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2 "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid "{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame "{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom "{AC76BA86-7AD7-1031-7B44-A81200000003}" = Adobe Reader 8.1.2 - Deutsch "{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}" = Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service "{DC905847-D537-427F-BF91-47CC7ACCDE58}" = ASUS FancyStart "{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash "{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update "{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver "Audacity_is1" = Audacity 1.2.6 "Audiograbber" = Audiograbber 1.83 SE "Audiograbber-Lame" = Audiograbber Lame-MP3-Plugin "AVI To WMV Converter_is1" = AVI To WMV Converter 1.00 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "DPP" = Canon Utilities Digital Photo Professional 3.8 "EOS Utility" = Canon Utilities EOS Utility "Google Desktop" = Google Desktop "GPL Ghostscript 8.70" = GPL Ghostscript 8.70 "GSview 4.9" = GSview 4.9 "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "InstallShield_{80557F5B-A54A-4700-8E19-8E4DA16508A5}" = SILKYPIX Developer Studio 3.0G "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "MozBackup" = MozBackup 1.4.9 "Mozilla Firefox (3.5)" = Mozilla Firefox (3.5) "Mozilla Thunderbird (2.0.0.24)" = Mozilla Thunderbird (2.0.0.24) "Neat Image_is1" = Neat Image v6 Demo (with plug-in) "PhotoStitch" = Canon Utilities PhotoStitch "Picasa2" = Picasa 2 "SynTPDeinstKey" = Synaptics Pointing Device Driver "TBBackup (Testversion)_is1" = TBBackup - Thunderbird Datensicherung (Testversion) "Tobit ClipInc Server" = WDR RadioRecorder "Tobit Radio.fx Server 1" = WDR RadioRecorder "TVWiz" = Intel(R) TV Wizard "USB 2.0 UVC 1.3M WebCam" = USB 2.0 UVC 1.3M WebCam "VLC media player" = VLC media player 1.0.0 "WinGimp-2.0_is1" = GIMP 2.6.7 "WinRAR archiver" = WinRAR "Zattoo" = Zattoo 3.3.4 Beta ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 20.08.2010 19:34:57 | Computer Name = Hänz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 20.08.2010 19:36:01 | Computer Name = Hänz-PC | Source = WinMgmt | ID = 10 Description = Error - 20.08.2010 19:40:00 | Computer Name = Hänz-PC | Source = Application Hang | ID = 1002 Description = Programm Explorer.EXE, Version 6.0.6001.18164 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 6c4 Anfangszeit: 01cb40c03922d311 Zeitpunkt der Beendigung: 97 Error - 21.08.2010 07:02:21 | Computer Name = Hänz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 21.08.2010 07:03:29 | Computer Name = Hänz-PC | Source = WinMgmt | ID = 10 Description = Error - 21.08.2010 19:07:04 | Computer Name = Hänz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 21.08.2010 19:08:12 | Computer Name = Hänz-PC | Source = WinMgmt | ID = 10 Description = Error - 21.08.2010 20:11:12 | Computer Name = Hänz-PC | Source = Application Hang | ID = 1002 Description = Programm Explorer.EXE, Version 6.0.6001.18164 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 660 Anfangszeit: 01cb41858138aa2c Zeitpunkt der Beendigung: 93 Error - 22.08.2010 06:10:12 | Computer Name = Hänz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 22.08.2010 06:11:26 | Computer Name = Hänz-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 27.08.2010 08:57:16 | Computer Name = Hänz-PC | Source = Service Control Manager | ID = 7001 Description = Error - 27.08.2010 08:57:16 | Computer Name = Hänz-PC | Source = Service Control Manager | ID = 7026 Description = Error - 27.08.2010 08:57:16 | Computer Name = Hänz-PC | Source = Service Control Manager | ID = 7001 Description = Error - 27.08.2010 08:57:16 | Computer Name = Hänz-PC | Source = Service Control Manager | ID = 7001 Description = Error - 27.08.2010 08:57:16 | Computer Name = Hänz-PC | Source = Service Control Manager | ID = 7001 Description = Error - 27.08.2010 08:57:16 | Computer Name = Hänz-PC | Source = Service Control Manager | ID = 7001 Description = Error - 27.08.2010 10:00:06 | Computer Name = Hänz-PC | Source = HTTP | ID = 15016 Description = Error - 27.08.2010 10:00:46 | Computer Name = Hänz-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 27.08.2010 10:12:25 | Computer Name = Hänz-PC | Source = HTTP | ID = 15016 Description = Error - 27.08.2010 10:13:01 | Computer Name = Hänz-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = < End of report > UPDATE: ...also, ich habe jetzt nochmal einen vollständigen Scan mit Malwarebytes ausprobiert, aber keine Chance - das Programm bleibt immer bei der "OmdProject.dll" hängen - die gehört zum Movie Maker und ist anscheinend harmlos, das Programm kann aber nicht deinstalliert werden. Das einzige, was ich also machen kann, ist ein Quick Scan mit Malwarebytes. Das funktioniert, allerdings findet der jedes Mal, wenn ich den Scan durchführe, wieder neue infizierte Dateien. Ein Komplettscan mit SUPERAntiSpyware hat überhaupt nicht funktioniert - Rechner hat sich aufgehängt, ging gar nichts mehr. Beim Start von Windows erscheint immer rechts unten an der Symbolleiste ein Infofenster, in dem steht, dass einige Autostartprogramme, die für den Start eine Berechtigung brauchen, von Windows geblockt werden. Ist das auch eine Mitteilung vom Antimalware Doctor? Bitte sagt mir, wie ich weiter vorgehen soll. Ich habe soweit alles über das Problem gelesen, was hier im Forum und auf anderen Seiten steht. Ich würde ja auch gerne auf eigene Faust versuchen, das Problem zu beheben, aber hier im Forum wird immer darauf hingewiesen, dass man unbedingt den Anweisungen der Profis folgen soll, und da ich leider nur sehr begrenzte Ahnung hab, lass ich das dann lieber. Also, bitte helft mir irgendwie weiter! Vielen Dank, Johannes Ich hänge hier jetzt nochmal die log-Datei vom letzten QuickScan an: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4490 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 27.08.2010 19:35:52 mbam-log-2010-08-27 (19-35-52).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 134454 Laufzeit: 4 Minute(n), 59 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 2 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*auditressvc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*auditressvc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Program Files\auditressvc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. |
Themen zu Antimalware Doctor eingefangen - Malwarebytes hängt sich auf |
.dll, abgesicherten, acroiehelper.dll, antimalware, antivir, antivirus, audacity, audiograbber, aufrufe, avgntflt.sys, black, canon, components, corp./icp, ebenfalls, eingefangen, fehler, files, firefox.exe, foren, forum, gen, gfnexsrv.exe, home premium, hängen, hängt, iastor.sys, install.exe, intranet, local\temp, location, log-datei, malwarebytes, malwarebytes hängt, meldung, modus, mozilla thunderbird, not, nvstor.sys, oldtimer, otl logfile, otl.exe, pdfforge toolbar, picasa, plug-in, probleme, programdata, programm, rkill, rogue.antimalwaredoctor, saver, scan, sched.exe, schwarz, searchplugins, security, shell32.dll, skype.exe, software, spigot, spyware.passwords.xgen, start menu, start von windows, studio, task-manager, usb 2.0, vlc media player, windows geblockt, winhelp.exe |