![]() |
Hallo, anbei der SystemLook.text. SystemLook 30.07.11 by jpshortstuff Log created at 17:29 on 16/01/2013 by Sabine Administrator - Elevation successful ========== filefind ========== Searching for "*iLivid*" C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.dat --a--c- 232 bytes [13:55 30/11/2011] [13:55 30/11/2011] F01CEA7CE4333EA3E84076BE00413309 C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.exe --a--c- 3001198 bytes [13:55 30/11/2011] [14:24 03/11/2011] 9C0D16DA08434A1BA63E274C0A54328D C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.lnk --a--c- 0 bytes [13:55 30/11/2011] [13:55 30/11/2011] D41D8CD98F00B204E9800998ECF8427E C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.msi --a--c- 265728 bytes [13:55 30/11/2011] [14:24 03/11/2011] A2D691886D299E9C9316220D43EA399E C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.par --a--c- 1555 bytes [13:55 30/11/2011] [13:55 30/11/2011] D6F4EA05715FD2DD2F0D57E654AFC7B9 C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.res --a--c- 2350911 bytes [13:55 30/11/2011] [14:24 03/11/2011] 6896755F9F046FEE43E6DEC89E721B78 C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.dat --a--c- 232 bytes [13:55 30/11/2011] [13:55 30/11/2011] F01CEA7CE4333EA3E84076BE00413309 C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.exe --a--c- 3001198 bytes [13:55 30/11/2011] [14:24 03/11/2011] 9C0D16DA08434A1BA63E274C0A54328D C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.lnk --a--c- 0 bytes [13:55 30/11/2011] [13:55 30/11/2011] D41D8CD98F00B204E9800998ECF8427E C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.msi --a--c- 265728 bytes [13:55 30/11/2011] [14:24 03/11/2011] A2D691886D299E9C9316220D43EA399E C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.par --a--c- 1555 bytes [13:55 30/11/2011] [13:55 30/11/2011] D6F4EA05715FD2DD2F0D57E654AFC7B9 C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.res --a--c- 2350911 bytes [13:55 30/11/2011] [14:24 03/11/2011] 6896755F9F046FEE43E6DEC89E721B78 C:\Users\Public\Desktop\iLivid Download Manager.lnk --a---- 873 bytes [13:55 30/11/2011] [13:55 30/11/2011] 98334F508B82101A5B2956F2695E959E C:\Users\Sabine\Downloads\iLividSetupV1(1).exe --a---- 2060760 bytes [13:54 30/11/2011] [13:54 30/11/2011] A3524B9D0A9BF6462B0A53F7335241D4 C:\Users\Sabine\Downloads\iLividSetupV1.exe --a---- 2060760 bytes [17:12 28/11/2011] [17:12 28/11/2011] A3524B9D0A9BF6462B0A53F7335241D4 Searching for "*Searchqu*" No files found. Searching for "*DataMngr*" No files found. Searching for "*SweetIM*" C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@home.sweetim[1].txt --a---- 416 bytes [16:01 09/01/2013] [16:02 09/01/2013] 79566709C84E1F70EECD268277A89ED6 Searching for "*Conduit*" C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll --a---- 1206160 bytes [21:32 09/08/2012] [21:32 09/08/2012] 309B2B1B22EE841E49F62C7A6FB55E46 C:\Users\Sabine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J0UXOV6Q\appsmetadata_toolbar_conduit-services_com[1].txt --a---- 1260 bytes [22:52 11/01/2013] [22:52 11/01/2013] 8631C5AB80CBD577FF8BA4C4BF3E81EF C:\Users\Sabine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J0UXOV6Q\translation_toolbar_conduit-services_com[1].txt --a---- 108056 bytes [22:52 11/01/2013] [22:52 11/01/2013] E9B17243769EE6FFBE574CFBDACABAE7 C:\Users\Sabine\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\0K2YQ2LT\facebook.conduitapps[1].xml --a---- 13 bytes [14:44 04/10/2012] [14:44 04/10/2012] C1DDEA3EF6BBEF3E7060A1A9AD89E4C5 C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\sabine@apps.conduit[1].txt --a---- 217 bytes [22:52 11/01/2013] [22:52 11/01/2013] 67975E6163D4F875674DABE181192A15 C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\sabine@services.apps.conduit[1].txt --a---- 226 bytes [22:52 11/01/2013] [22:52 11/01/2013] 6D0E70BDA6382CB507CD1CA9934FB311 C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\sabine@social.conduit[1].txt --a---- 219 bytes [22:52 11/01/2013] [22:52 11/01/2013] AB29B1170E7579CE9961C8C517BCBDAE C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@apps.conduit[1].txt --a---- 217 bytes [22:52 11/01/2013] [22:52 11/01/2013] EFAD7332731D3E85E8947AD28D8AA479 C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@search.conduit[1].txt --a---- 163 bytes [16:02 09/01/2013] [16:02 09/01/2013] A1BCD8AEB949784AC5323B79B8CF1EF7 C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@services.apps.conduit[1].txt --a---- 226 bytes [22:52 11/01/2013] [22:52 11/01/2013] 9CC507530F621EB30D86F0E81D57C065 C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@social.conduit[1].txt --a---- 219 bytes [22:52 11/01/2013] [22:52 11/01/2013] C0C1A3E25ACA95F0535CCBBE25220A33 Searching for "*softonic*" No files found. Searching for "Ask" No files found. ========== folderfind ========== Searching for "*iLivid*" No folders found. Searching for "*Searchqu*" No folders found. Searching for "*DataMngr*" No folders found. Searching for "*SweetIM*" No folders found. Searching for "*Conduit*" C:\Users\AppData\LocalLow\Conduit d------ [22:51 25/02/2011] Searching for "*softonic*" No folders found. Searching for "Ask" No folders found. ========== regfind ========== Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1(2).exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ilivid] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ilivid] @="URL:ilivid Player" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ilivid\shell\open\command] @=""C:\Program Files (x86)\iLivid\ilivid.exe" "%1"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160] "ProductName"="iLivid" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160\SourceList] "PackageName"="iLividSetupV1.msi" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Applications\iLividSetupV1(2).exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\ilivid] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\ilivid] @="URL:ilivid Player" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\ilivid\shell\open\command] @=""C:\Program Files (x86)\iLivid\ilivid.exe" "%1"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLivid\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D14257D02FF048419C2C3F7787732C8] "2B1E51D87B2D71A44BB42DDD5E894160"="C:\Program Files (x86)\iLivid\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6770AEB7E06F926409292E7BC2601EFE] "2B1E51D87B2D71A44BB42DDD5E894160"="01:\Software\ilivid\general\ReferrerID" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AC8629C735242C4C8DA212489E5DE11] "2B1E51D87B2D71A44BB42DDD5E894160"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLivid\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2B1E51D87B2D71A44BB42DDD5E894160\InstallProperties] "InstallLocation"="C:\Program Files (x86)\iLivid" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2B1E51D87B2D71A44BB42DDD5E894160\InstallProperties] "DisplayName"="iLivid" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Applications\iLividSetupV1(2).exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\ilivid] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\ilivid] @="URL:ilivid Player" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\ilivid\shell\open\command] @=""C:\Program Files (x86)\iLivid\ilivid.exe" "%1"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}] "InstallLocation"="C:\Program Files (x86)\iLivid" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}] "DisplayName"="iLivid" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}] "UninstallString"="C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}\iLividSetupV1.exe" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{80269624-336E-41BF-B278-32C270CA12B5}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{80269624-336E-41BF-B278-32C270CA12B5}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{80269624-336E-41BF-B278-32C270CA12B5}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_USERS\S-1-5-21-2719320216-1920363383-2196071213-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\iLivid] [HKEY_USERS\S-1-5-21-2719320216-1920363383-2196071213-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\C:\Program Files (x86)\iLivid] Searching for "Searchqu" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" Searching for "DataMngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{47A5D50F-ED54-4387-A3E3-3A4743253011}] "AppPath"="C:\PROGRA~2\WI371A~1\Datamngr\ToolBar" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{80269624-336E-41BF-B278-32C270CA12B5}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{80269624-336E-41BF-B278-32C270CA12B5}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{80269624-336E-41BF-B278-32C270CA12B5}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\dtUser.exe|Name=DTX broker|Edge=FALSE|" Searching for "SweetIM" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{27AD7445-03BD-49C4-BB5C-33881D70C31C}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\Sabine\Downloads\SweetImSetup.exe|Name=SweetIM Installer|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00B8E36E-BAA4-49CD-A7F2-EDCFAADD4E08}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\Sabine\Downloads\SweetImSetup.exe|Name=SweetIM Installer|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{27AD7445-03BD-49C4-BB5C-33881D70C31C}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\Sabine\Downloads\SweetImSetup.exe|Name=SweetIM Installer|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00B8E36E-BAA4-49CD-A7F2-EDCFAADD4E08}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\Sabine\Downloads\SweetImSetup.exe|Name=SweetIM Installer|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{27AD7445-03BD-49C4-BB5C-33881D70C31C}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\Sabine\Downloads\SweetImSetup.exe|Name=SweetIM Installer|Edge=FALSE|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00B8E36E-BAA4-49CD-A7F2-EDCFAADD4E08}"="v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\Sabine\Downloads\SweetImSetup.exe|Name=SweetIM Installer|Edge=FALSE|" Searching for "Conduit" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966] "AE48807DEC2E935419BD7466CCE1F5F5"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll" Searching for "softonic" [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] "C:\Users\Sabine\Downloads\SoftonicDownloader_fuer_izarc.exe"="ELEVATECREATEPROCESS" [HKEY_USERS\S-1-5-21-2719320216-1920363383-2196071213-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] "C:\Users\Sabine\Downloads\SoftonicDownloader_fuer_izarc.exe"="ELEVATECREATEPROCESS" Searching for "Ask Toolbar" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList] "PackageName"="Ask Toolbar.msi" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B355C356-3D0F-4A93-8ADE-89C7BEA37A53}] "Path"="\Scheduled Update for Ask Toolbar" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar] Searching for " " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{21C35C68-A6C5-4A75-8FFD-DB503CE6F67B}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{18CD34B7-7AA3-42b9-A303-5A729B2FF228}"> <Descriptor descriptorID="{ABE23B46-7F9F-495b-B4A9-87F41743727F}"/> <Descriptor descriptorID="{B54162A2-F67F-46dc-9ED5-F6067520EC94}"/> <Descriptor descriptorID="{7E0BC004-F80B-402d-A1FC-5FCDFF04DAB1}"/> <Descriptor descriptorID="{BE562A5F-2A80-4c28-9752-74C696E2ABAF}"/> </Rating> </Ratings>" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{DD05EAD9-FAA2-4A07-8AD3-FA36DC8F65C2}] "RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1"> <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{97D9239C-2BA3-4e1d-A710-B626DC4602A6}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> </Rating> <Rating ratingSystemID="{C705DCF4-6AFE-4f4f-BC51-21807E4E5CFB}" ratingID="{6948F4DF-FD98-41ea-979A-8364043D7FD6}"/> <Rating ratingSystemID="{5B39D1B8-ED49-4055-8A47-04B29A579AD6}" ratingID="{9AE7AC26-0F9A-4f59-A167-00E4F6C96E26}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> </Rating> <Rating ratingSystemID="{9AAFBACD-EAB9-4946-8BE8-C4D997927C81}" ratingID="{F7066480-67CC-4697-9B47-7E534B74089D}"> <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/> </R [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0001] "DriverDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0001] "FriendlyName"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0007] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0007] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0015] "DriverDesc"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0015] "FriendlyName"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0019] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0019] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1010289201039 0&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1010289201039 0&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1204181200206 2&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1204181200206 2&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#09021208F C1174&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#09021208F C1174&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_2.70# 000A270011A39AA4&0#] "DeviceDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_2.70# 000A270011A39AA4&0#] "FriendlyName"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_SONY&PROD_PRS-T1&REV_2001#148427501415694&0#] "DeviceDesc"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_SONY&PROD_PRS-T1&REV_2001#148427501415694&0#] "FriendlyName"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0001] "DriverDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0001] "FriendlyName"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0007] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0007] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0015] "DriverDesc"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0015] "FriendlyName"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0019] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0019] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1010289201039 0&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1010289201039 0&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1204181200206 2&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#1204181200206 2&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#09021208F C1174&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#09021208F C1174&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_2.70# 000A270011A39AA4&0#] "DeviceDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_2.70# 000A270011A39AA4&0#] "FriendlyName"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_SONY&PROD_PRS-T1&REV_2001#148427501415694&0#] "DeviceDesc"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_SONY&PROD_PRS-T1&REV_2001#148427501415694&0#] "FriendlyName"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0001] "DriverDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0001] "FriendlyName"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0007] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0007] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0015] "DriverDesc"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0015] "FriendlyName"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0019] "DriverDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0019] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#101028920 10390&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#101028920 10390&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#120418120 02062&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_#120418120 02062&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#09021 208FC1174&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#09021 208FC1174&0#] "FriendlyName"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_2 .70#000A270011A39AA4&0#] "DeviceDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_2 .70#000A270011A39AA4&0#] "FriendlyName"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_SONY&PROD_PRS-T1&REV_2001#148427501415694&0#] "DeviceDesc"="PRS-T1 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_SONY&PROD_PRS-T1&REV_2001#148427501415694&0#] "FriendlyName"="PRS-T1 " -= EOF =- Viele Grüsse, Sabine |
Servus, wir entfernen jetzt noch Reste und führen Kontrollsuchläufe durch: Schritt 1 Fixen mit OTL
Code: :OTL
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck
Bitte poste mit deiner nächsten Antwort
|
Hi, hier schon mal die Logdatei von OTL:OTL Logfile: Code: OTL logfile created on: 16.01.2013 20:53:10 - Run 2 mbam-log: Malwarebytes Anti-Malware (Test) 1.70.0.1100 Malwarebytes : Free anti-malware download Datenbank Version: v2013.01.16.08 Windows Vista Service Pack 1 x64 NTFS Internet Explorer 8.0.6001.19088 Sabine :: SABINES-PC [Administrator] Schutz: Aktiviert 16.01.2013 21:14:41 mbam-log-2013-01-16 (21-14-41).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 219095 Laufzeit: 2 Minute(n), 39 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6889 # api_version=3.0.2 # EOSSerial=de66397e9e639448b700251732d83f56 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-01-16 10:00:28 # local_time=2013-01-16 11:00:28 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode=1799 16775165 100 99 21239 223796918 9959 0 # compatibility_mode=5892 16776574 100 100 63948 195897534 0 0 # scanned=260478 # found=2 # cleaned=0 # scan_time=4053 C:\ProgramData\dsgsdgdsgdsgw.js JS/Agent.NID trojan B10B9733C8386028B2F356CB2E17E5B7ABD3CB53 I C:\Users\All Users\dsgsdgdsgdsgw.js JS/Agent.NID trojan B10B9733C8386028B2F356CB2E17E5B7ABD3CB53 I Und der letzte Text : Results of screen317's Security Check version 0.99.57 Windows Vista Service Pack 1 x64 (UAC is enabled) Out of date service pack!! Internet Explorer 8 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 JavaFX 2.1.1 Java(TM) 6 Update 29 Java 7 Update 9 Java version out of Date! Adobe Flash Player 11.5.502.146 Adobe Reader 10.1.5 Adobe Reader out of Date! Mozilla Firefox (4.0.1) Mozilla Thunderbird (3.1.7) Thunderbird out of Date! Google Chrome 23.0.1271.97 Google Chrome 24.0.1312.52 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe StarMoney 7.0 S-Edition ouservice StarMoneyOnlineUpdate.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
Servus, du hast meine Anleitung zu OTL nicht richtig gelesen. Ich wollte einen Fix sehen und keinen Scan! :stirn: Liest du auch das, was ich schreibe oder drückst du nur "irgendwas", worauf du gerade Bock hast :confused: Wir versuchen es nochmal... :) Fixen mit OTL
Code: :files
|
Hi, bitte entschuldige vielmals meinen Fehler. Natürlich lese ich Deine Anweisungen und drücke nicht irgendwas. Bisher hab ich doch alles immer nach Deinen Anweisungen gemacht - habe mich nur diesmal mit Scan und Fix verklickt. Also hier jetzt hoffentlich die richtige Datei: All processes killed ========== FILES ========== C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824} folder moved successfully. File\Folder C:\Users\All Users\{08E30618-5D06-461B-BBD3-4ADFB0810824} not found. C:\Users\Public\Desktop\iLivid Download Manager.lnk moved successfully. C:\Users\Sabine\Downloads\iLividSetupV1(1).exe moved successfully. C:\Users\Sabine\Downloads\iLividSetupV1.exe moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@home.sweetim[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\sabine@apps.conduit[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\sabine@services.apps.conduit[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\sabine@social.conduit[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@apps.conduit[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@search.conduit[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@services.apps.conduit[1].txt moved successfully. C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Cookies\Low\sabine@social.conduit[1].txt moved successfully. C:\Users\AppData\LocalLow\Conduit\Community Alerts\Log folder moved successfully. C:\Users\AppData\LocalLow\Conduit\Community Alerts folder moved successfully. C:\Users\AppData\LocalLow\Conduit folder moved successfully. C:\ProgramData\dsgsdgdsgdsgw.js moved successfully. File\Folder C:\Users\All Users\dsgsdgdsgdsgw.js not found. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{47A5D50F-ED54-4387-A3E3-3A4743253011}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47A5D50F-ED54-4387-A3E3-3A4743253011}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{80269624-336E-41BF-B278-32C270CA12B5} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80269624-336E-41BF-B278-32C270CA12B5}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A2D4C09-6BF7-46DC-9848-DBF839F7EFFE}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{27AD7445-03BD-49C4-BB5C-33881D70C31C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27AD7445-03BD-49C4-BB5C-33881D70C31C}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{00B8E36E-BAA4-49CD-A7F2-EDCFAADD4E08} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00B8E36E-BAA4-49CD-A7F2-EDCFAADD4E08}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\\C:\Users\Sabine\Downloads\SoftonicDownloader_fuer_izarc.exe deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B355C356-3D0F-4A93-8ADE-89C7BEA37A53}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B355C356-3D0F-4A93-8ADE-89C7BEA37A53}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\iLividSetupV1(2).exe\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ilivid\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Applications\iLividSetupV1(2).exe\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\ilivid\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: AppData ->Temp folder emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Sabine ->Temp folder emptied: 8343951 bytes ->Temporary Internet Files folder emptied: 302929039 bytes ->Java cache emptied: 3389594 bytes ->FireFox cache emptied: 138849366 bytes ->Google Chrome cache emptied: 406082925 bytes ->Flash cache emptied: 118811825 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 268442894 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 122584 bytes Total Files Cleaned = 1.189,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01172013_164036 Files\Folders moved on Reboot... File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UKT7V69D\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OBTMPYAH\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWTG0XA8\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C6AVC9EW\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Servus, gut gemacht. :abklatsch: Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Download und installiere als Erstes: Vista Service Pack 2 Internet Explorer 9 Schritt 1 Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Schritt 2 Deine Version von Adobe Flash Player ist veraltet. Bitte folge diesen Schritte, um Adobe Flash zu aktualisieren:
Schritt 3
Prüfe bitte auch (regelmässig) ob folgende Links fehlende Updates bei deinen Plugins zeigen: Schritt 4 Starte DeFogger und klicke auf Re-enable. Gegebenenfalls muss dein Rechner neu gestartet werden. Schritt 5 Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren. Windows-Taste + R drücke. Kopiere nun folgende Zeile in die Kommandozeile und klicke OK. Code: Combofix /Uninstall Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch aus dieser die Schädlinge verschwinden. Nun die eben deaktivierten Programme wieder aktivieren. Schritt 6 Downloade dir bitte delfix auf deinen Desktop.
Schritt 7 Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Super, vielen vielen vielen Dank schonmal bis hierhin. Klasse - ohne Deine Hilfe hätte ich das garantiert niemals geschafft. Ich werde die einzelnen Schritte heute im Laufe des Abends durchgehen und Dir eine Rückmeldung geben. Dicken Daumen hoch!!!!! Viele Grüsse, Sabine |
Hey Sabine, alles klar. Dann warte ich auf deine Rückmeldung. :) |
So, ich habe jetzt alle Hinweise und Schritte durchgearbeitet. Konnte ich gestern abend nicht alles schaffen. Nochmals vielen vielen Dank für deine Hilfe!!! Ich hoffe auf kein baldiges Wiedersehen, weiß aber jetzt im Falle des Falles wohin ich mich wenden kann :-) Ein schönes Wochenende und viele Grüsse, Sabine |
Ich bin froh, dass wir helfen konnten :abklatsch: Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 18:22 Uhr. |
Copyright ©2000-2025, Trojaner-Board