![]() |
|
Log-Analyse und Auswertung: Bundespolizei TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Bundespolizei Trojaner Servus, hab hier den Laptop von einem Bekannten mit dem Bundespolizei-Trojaner. Hab schon die AntiVir Security Disc drüber laufen lassen die auch was gefunden hat, der Trojaner bleibt aber. Hier die Logs von OTL: Code:
ATTFilter OTL logfile created on: 4/13/2011 12:41:48 PM - Run OTLPE by OldTimer - Version 3.1.46.0 Folder = X:\Programs\OTLPE 64bit-Windows 7 Home Premium (Version = 6.1.7600) - Type = System Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 92.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 14.65 Gb Total Space | 8.19 Gb Free Space | 55.90% Space Free | Partition Type: NTFS Drive E: | 451.07 Gb Total Space | 365.96 Gb Free Space | 81.13% Space Free | Partition Type: NTFS Drive F: | 998.02 Mb Total Space | 21.80 Mb Free Space | 2.18% Space Free | Partition Type: FAT32 Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010/02/25 20:03:00 | 000,244,736 | ---- | M] (IDT, Inc.) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\stacsv64.exe -- (STacSV) SRV:64bit: - [2009/07/16 21:06:22 | 000,033,280 | ---- | M] () [Auto] -- E:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc) SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009/06/25 06:48:28 | 000,203,264 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2009/06/09 10:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto] -- E:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService) SRV:64bit: - [2009/03/02 20:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe -- (AESTFilters) SRV - [2011/03/18 12:45:15 | 000,269,480 | ---- | M] (Avira GmbH) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010/11/02 11:43:26 | 000,135,336 | ---- | M] (Avira GmbH) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2010/04/05 15:55:01 | 000,116,104 | ---- | M] () [Auto] -- E:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC) SRV - [2010/03/18 08:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/11 12:53:00 | 000,660,800 | ---- | M] (SoftThinks) [Auto] -- E:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService) SRV - [2010/01/15 08:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand] -- E:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009/06/05 20:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand] -- E:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService) SRV - [2009/06/04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R) SRV - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto] -- E:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) ========== Driver Services (SafeList) ========== DRV:64bit: - [2010/12/10 12:36:34 | 000,083,120 | ---- | M] (Avira GmbH) [File_System | Auto] -- E:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV:64bit: - [2010/09/28 10:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2010/09/22 19:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fssfltr.sys -- (fssfltr) DRV:64bit: - [2010/03/02 07:35:01 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System] -- E:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV:64bit: - [2010/02/25 20:03:00 | 000,505,856 | ---- | M] (IDT, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\stwrt64.sys -- (STHDA) DRV:64bit: - [2009/12/26 03:41:32 | 000,280,624 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV:64bit: - [2009/09/28 03:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\yk62x64.sys -- (yukonw7) DRV:64bit: - [2009/07/16 21:06:20 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY) DRV:64bit: - [2009/07/16 21:06:16 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BCMWL664.SYS -- (BCM43XX) DRV:64bit: - [2009/07/09 04:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- E:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2009/06/25 07:24:30 | 006,036,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV:64bit: - [2009/06/15 14:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt) DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/05/08 04:15:18 | 000,215,552 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:64bit: - [2006/11/01 12:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- E:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\Jakob_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8 IE - HKU\Jakob_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050 IE - HKU\Jakob_ON_E\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - Reg Error: Key error. File not found IE - HKU\Jakob_ON_E\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found IE - HKU\Jakob_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Jakob_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Web Search..." FF - prefs.js..browser.search.defaultthis.engineName: "Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.0.14 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0 FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2 FF - prefs.js..extensions.enabledItems: 5 FF - prefs.js..extensions.enabledItems: 3 FF - prefs.js..extensions.enabledItems: 1 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2 FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2 FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.9.1.14019 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&q=" [2010/05/11 16:17:16 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Extensions [2011/04/11 15:58:53 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions [2010/08/22 09:01:52 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2010/08/22 09:01:52 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2010/12/20 06:53:54 | 000,000,000 | ---D | M] (softonic-de3 Community Toolbar) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} [2010/12/20 06:53:53 | 000,000,000 | ---D | M] (Conduit Engine) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\engine@conduit.com [2010/12/11 11:08:29 | 000,000,000 | ---D | M] (TVU Web Player) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\firefox@tvunetworks.com [2011/01/10 17:35:16 | 000,000,000 | ---D | M] (Ask Toolbar) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\toolbar@ask.com [2010/12/11 11:14:56 | 000,000,000 | ---D | M] (vShare) -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\extensions\vshare@toolbar [2010/08/22 09:32:04 | 000,000,873 | ---- | M] () -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\searchplugins\conduit.xml [2010/12/11 11:15:24 | 000,001,583 | ---- | M] () -- E:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\e7hxi0f6.default\searchplugins\web-search.xml [2011/04/11 08:39:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions [2010/05/11 16:28:02 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C} File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\ENGINE@CONDUIT.COM File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\FIREFOX@TVUNETWORKS.COM File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\TOOLBAR@ASK.COM File not found (No name found) -- C:\USERS\JAKOB\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7HXI0F6.DEFAULT\EXTENSIONS\VSHARE@TOOLBAR [2010/04/12 11:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll [2010/08/24 11:34:02 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010/08/24 11:34:02 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-de.xml [2010/08/24 11:34:02 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010/08/24 11:34:02 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010/08/24 11:34:02 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - E:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - E:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - E:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - E:\Program Files (x86)\softonic-de3\tbsoft.dll (Conduit Ltd.) O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - E:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - E:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - E:\Program Files (x86)\softonic-de3\tbsoft.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\Jakob_ON_E\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKU\Jakob_ON_E\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKU\Jakob_ON_E\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - E:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.) O3 - HKU\Jakob_ON_E\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - E:\Program Files (x86)\softonic-de3\tbsoft.dll (Conduit Ltd.) O3 - HKU\Jakob_ON_E\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] E:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.) O4:64bit: - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4:64bit: - HKLM..\Run: [QuickSet] E:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) O4:64bit: - HKLM..\Run: [SysTrayApp] E:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [avgnt] E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CanonSolutionMenuEx] E:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) O4 - HKU\Jakob_ON_E..\Run: [{9178238A-3194-2B60-EAE8-5F23AA5BD1C2}] E:\Users\Jakob\AppData\Roaming\Umyb\syxii.exe (Elpxet Xnqklkjrw) O4 - HKU\Jakob_ON_E..\Run: [EA Core] File not found O4 - HKU\Jakob_ON_E..\Run: [msnmsgr] File not found O4 - HKU\Jakob_ON_E..\Run: [Octoshape Streaming Services] E:\Users\Jakob\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS) O4 - HKU\LocalService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\NetworkService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [Launcher] E:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe (Softthinks) O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] File not found O4 - Startup: E:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk () O4 - Startup: E:\Users\Jakob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\Jakob_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - E:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - E:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13:64bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKU\Jakob_ON_E Winlogon: Shell - (C:\Users\Jakob\AppData\Local\Temp\0.9833726678399152.exe) - E:\Users\Jakob\AppData\Local\Temp\0.9833726678399152.exe (XMRLPUSVBHO) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - File not found - -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011/04/06 14:43:37 | 000,000,000 | ---D | C] -- E:\Users\Jakob\Desktop\attachment-Dateien [2011/04/05 10:50:38 | 000,000,000 | ---D | C] -- E:\5ec103496c0cc79e1b8768d426475f [2011/04/05 10:46:44 | 000,000,000 | ---D | C] -- E:\Users\Jakob\Desktop\Schule [1 E:\Users\Jakob\Desktop\*.tmp files -> E:\Users\Jakob\Desktop\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/04/12 17:49:20 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat [2011/04/12 17:46:06 | 000,668,442 | ---- | M] () -- E:\Windows\System32\perfh007.dat [2011/04/12 17:46:06 | 000,628,236 | ---- | M] () -- E:\Windows\System32\perfh009.dat [2011/04/12 17:46:06 | 000,137,408 | ---- | M] () -- E:\Windows\System32\perfc007.dat [2011/04/12 17:46:06 | 000,112,022 | ---- | M] () -- E:\Windows\System32\perfc009.dat [2011/04/12 17:41:41 | 3218,358,272 | -HS- | M] () -- E:\hiberfil.sys [2011/04/12 16:55:27 | 000,014,016 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/04/12 16:55:27 | 000,014,016 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/04/12 16:49:29 | 000,343,752 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT [2011/04/06 14:43:37 | 000,000,823 | ---- | M] () -- E:\Users\Jakob\Desktop\attachment.htm [2011/03/17 17:33:09 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [1 E:\Users\Jakob\Desktop\*.tmp files -> E:\Users\Jakob\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/04/06 14:43:36 | 000,000,823 | ---- | C] () -- E:\Users\Jakob\Desktop\attachment.htm [2011/03/06 09:45:00 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat [2011/02/27 18:48:47 | 000,000,536 | ---- | C] () -- E:\Windows\MyHeritage.INI [2011/02/27 18:46:26 | 000,454,656 | ---- | C] () -- E:\Windows\SysWow64\PaintX.dll [2010/12/03 13:39:19 | 000,110,940 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat [2010/07/02 15:49:35 | 000,009,728 | ---- | C] () -- E:\Users\Jakob\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/04/24 16:18:41 | 000,000,075 | RHS- | C] () -- E:\Windows\CT4CET.bin [2010/04/24 08:27:00 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin [2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat [2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT [2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat [2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin [2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- E:\Windows\SysWow64\DShowRdpFilter.dll [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll [2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2010/05/11 15:38:54 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data [2011/01/17 12:41:23 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonBJ [2011/01/17 12:56:03 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonEPP [2011/01/19 14:25:26 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJEPPEX [2011/01/17 12:56:03 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJEPPEX2 [2011/01/17 12:45:43 | 000,000,000 | ---D | M] -- E:\ProgramData\CanonIJMSetup [2011/01/17 12:56:03 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJMyPrinter [2011/04/01 13:30:29 | 000,000,000 | ---D | M] -- E:\ProgramData\CanonIJPLM [2011/01/17 12:56:04 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJSolutionMenuEX [2011/01/17 12:43:34 | 000,000,000 | ---D | M] -- E:\ProgramData\CanonIJWSpt [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents [2010/05/11 15:38:54 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente [2010/06/23 08:45:29 | 000,000,000 | ---D | M] -- E:\ProgramData\Electronic Arts [2010/05/11 15:38:54 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites [2011/02/27 18:54:22 | 000,000,000 | ---D | M] -- E:\ProgramData\MyHeritage [2010/04/24 16:05:47 | 000,000,000 | ---D | M] -- E:\ProgramData\PCDr [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu [2010/05/11 15:38:54 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü [2010/04/24 16:05:49 | 000,000,000 | ---D | M] -- E:\ProgramData\SupportSoft [2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates [2010/04/24 16:21:43 | 000,000,000 | ---D | M] -- E:\ProgramData\Uninstall [2010/05/11 15:38:54 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen [2010/04/24 16:03:02 | 000,000,000 | ---D | M] -- E:\ProgramData\WildTangent [2010/05/12 06:19:32 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2010/04/24 16:22:28 | 000,000,000 | -H-D | M] -- E:\ProgramData\{D19C2D22-6043-47E7-B400-83A351841204} [2011/03/04 16:04:01 | 000,032,640 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > convidis |
Themen zu Bundespolizei Trojaner |
antivir, avgntflt.sys, avira, bho, bonjour, bundespolizei trojaner, canon, defender, desktop, error, explorer, explorer.exe, firefox, format, home, location, logfile, microsoft, mozilla, neu, oldtimer, plug-in, realtek, reatogo, registry, scan, sched.exe, searchplugins, security, security scan, software, start menu, syswow64, trojane, trojaner, webcheck, winlogon, wlan |