Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner auf mein Netbook (https://www.trojaner-board.de/108404-trojaner-netbook.html)

farida 21.01.2012 18:02

Trojaner auf mein Netbook
 
Hallo ihr Liebe,ich habe mir auch diesen tollen Trojaner eingefangen.Wo man aufgefordert wir,50euro zu zahlen.Ich kann leider nicht neu formatieren,da es ein Netbook ist.Ich hab schon viele Einträge zu diesen Thema gelesen.Nur leider habe ich keine Ahnung von Computer und brauch eine Anleihtung für dumme :-).Kann mir bitte jemand helfen ich bin am verzweifeln.Es handelt sich um diese Trojaner:5036776-36e51215 TR/Ransom EI.64
4715619a2-fcc31af EXP/2011-3544.AU
0.61311149990808.exe TR(Ransom EI.64
dllhsts.exe TR/Ransom
Das sind echt ne menge.HILFE!!!danke

Larusso 22.01.2012 03:02

:hallo:

Mein Name ist Daniel und ich werde dir mit deinem Malware Relevanten Problemen helfen.

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen erst einmal durch. Sollte irgendetwas unklar sein, Frage bevor du beginnst.
  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.
  • Sollte ich auf diese, sowie allen weiteren Antworten, innerhalb von 3 Tagen keine Antwort von dir erhalten, werde ich das Thema aus meinen Abonnements löschen.
  • Nur Scanns durchführen zu denen Du von einem Helfer aufgefordert wirst und Installiere / Deinstalliere keine Software ohne Aufforderung.
  • Poste die Logfiles direkt in deinen Thread und nicht als Anhang, ausser du wurdest dazu aufgefordert. Erschwert mir das Auswerten.


Welches Betriebssystem ?
USB Stick zur Hand oder die Möglichkeit eine CD zu brennen ?

farida 22.01.2012 22:25

Hallo daniel,danke für deine schnelle Antwort und für deine Hilfe.Ich hab einen Stick zur Hand und nutze Windows.

farida 23.01.2012 00:27

Hi,ich habe vergessen zu schreiben,dass es windows 7 ist.lg

Larusso 23.01.2012 00:53

Downloade dir bitte Farbar's Recovery Scan Tool und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an Du musst das System nun in die System Reparatur Option booten.

Über den Boot Manager
  • Starte den Rechner neu auf.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu auf und starte von der CD
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !!
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument --> Datei --> Speichern unter und wähle Computer Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein. e:\frst.exe Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

farida 23.01.2012 19:46

Hallo Daniel,du schreibst ich soll die windows CD einlegen,aber zum einen ist das ein Netbook ohne CD Laufwerk und zum anderen habe ich keine CD zu diesem Netbook.

Larusso 23.01.2012 21:20

Wie wärs einfach mal den gesamten Text zu lesen ?

Zitat:

Über den Boot Manager

Starte den Rechner neu auf.
Während dem Hochfahren drücke mehrmals die F8 Taste
Wähle nun Computer reparieren.
Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".

farida 24.01.2012 18:23

Ok,hab es gelesen und verstanden.Werde es jetzt machen.

farida 24.01.2012 19:31

So das sollte ich dir posten.Ich hab den stick jetzt an ein anderen Laptop angeschlossen.ich hoffe,dass er ihn jetzt nicht auch infiziert?

Scan result of Farbars Recovery Tool (FRST written by farbar) Version: 24-01-2012
Ran by saliha at 2012-01-24 19:22:53
Running from E:\
(X86) OS Language: German Standard
Attention: Could not load system hive.FEHLER: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.

========================== Registry (Whitelisted) =============

HKLM\...\Winlogon: [Userinit] [x]
HKLM\...\Winlogon: [Shell]

================================ Services (Whitelisted) ==================


========================== Drivers (Whitelisted) =============


========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2012-01-24 19:13 - 2012-01-24 19:13 - 0000000 ____D C:\Users\saliha\AppData\Local\{F3A3CC18-9B76-4340-9DFE-0AAF063363B2}
2012-01-24 18:55 - 2012-01-24 18:55 - 0000000 ____D C:\Users\saliha\AppData\Local\{C024A112-19DF-499E-A1D8-664DF3CFAFB7}
2012-01-24 18:47 - 2012-01-24 18:47 - 0000000 ____D C:\Users\saliha\AppData\Local\{3CFDBB1F-B6DE-415A-A9DC-7BC69385941D}
2012-01-24 18:36 - 2012-01-24 19:22 - 0000000 ____D C:\FRST
2012-01-24 18:33 - 2012-01-24 18:33 - 0000000 ____D C:\Users\saliha\AppData\Local\{EB4B2084-1B22-4190-B560-97F857520599}
2012-01-23 00:23 - 2012-01-23 00:23 - 0000000 ____D C:\Users\saliha\AppData\Local\{CB4F5197-4E8A-492A-AF32-817E4E11F8FD}
2012-01-14 22:11 - 2012-01-14 22:11 - 0001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\Users\saliha\AppData\Roaming\Malwarebytes
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\Users\All Users\Malwarebytes
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\ProgramData\Malwarebytes
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-01-14 22:11 - 2011-12-10 15:24 - 0020464 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-01-14 22:04 - 2012-01-14 22:05 - 0000000 ____D C:\Users\saliha\Documents\antibotcd0112_chip[1]
2012-01-14 21:54 - 2012-01-14 21:54 - 0000000 ____D C:\Users\saliha\AppData\Local\{F27399F7-2B82-4377-89A9-A9CF6A39C5D3}
2012-01-14 21:54 - 2012-01-14 21:54 - 0000000 ____D C:\Users\saliha\AppData\Local\{A755919E-1172-4683-8572-6CFDAC9588EB}
2012-01-13 21:57 - 2012-01-14 21:52 - 0000000 ____D C:\1f46ce212972cb18796329d23666adad
2012-01-13 19:10 - 2012-01-13 19:10 - 0002033 ____A C:\Users\saliha\Desktop\Entfernen des Avira DE-Cleaners.lnk
2012-01-13 19:10 - 2012-01-13 19:10 - 0001962 ____A C:\Users\saliha\Desktop\Avira DE-Cleaner.lnk
2012-01-13 18:42 - 2012-01-13 18:42 - 0000000 ____D C:\Users\saliha\AppData\Local\{D507EAA4-93E1-4B99-9B79-6E1821D7C26C}
2012-01-13 18:42 - 2012-01-13 18:42 - 0000000 ____D C:\Users\saliha\AppData\Local\{04E23234-F08B-4205-8705-8C9FA4812F2C}
2012-01-12 20:24 - 2012-01-12 20:24 - 0000000 ____D C:\Users\saliha\AppData\Local\ElevatedDiagnostics
2012-01-12 20:00 - 2012-01-12 20:00 - 0000000 ____D C:\Program Files\PriceGong
2012-01-12 19:57 - 2012-01-12 19:57 - 0459568 ____A (SweetIM Technologies, Ltd.) C:\Users\saliha\Desktop\SweetImSetup.exe
2012-01-12 19:49 - 2012-01-24 19:18 - 1029112 ____A C:\Windows\ntbtlog.txt
2012-01-12 18:50 - 2012-01-12 18:50 - 0000000 ____D C:\Users\saliha\AppData\Roaming\Avira
2012-01-12 18:07 - 2012-01-12 18:07 - 0000000 ____D C:\Users\saliha\AppData\Local\{73D0459D-B613-4205-9565-F0FD453405F2}
2012-01-12 18:07 - 2012-01-12 18:07 - 0000000 ____D C:\Users\saliha\AppData\Local\{0E35760C-C11F-4C9B-9E5E-4062494B85CA}
2012-01-11 18:15 - 2011-11-19 15:06 - 0067072 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll
2012-01-11 18:15 - 2011-11-17 06:41 - 1288984 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2012-01-11 18:15 - 2011-10-26 05:28 - 1328640 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll
2012-01-11 18:15 - 2011-10-26 05:28 - 0514560 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-01-11 18:15 - 2011-10-14 05:42 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-01-11 18:08 - 2012-01-11 18:08 - 0000000 ____D C:\Users\saliha\AppData\Local\{989BC29A-656C-4761-8420-532B82E3D3CF}
2012-01-09 18:08 - 2012-01-09 18:08 - 0000000 ____D C:\Users\saliha\AppData\Local\{1D531BC1-DC24-4750-92A2-9E0745D4F484}
2012-01-09 17:15 - 2012-01-09 17:15 - 0000000 ____D C:\Users\saliha\AppData\Local\{B8C0C2F3-7F81-4B9C-A4A1-0417128EF064}
2012-01-08 13:25 - 2012-01-08 13:25 - 0000000 ____D C:\Users\saliha\AppData\Local\{9C682E12-26BD-44B5-97ED-37A5D42C8997}
2012-01-08 13:24 - 2012-01-08 13:25 - 0000000 ____D C:\Users\saliha\AppData\Local\{3C4E2D2B-DDB2-4CDF-8891-9B2AFAD762C5}
2012-01-08 12:22 - 2012-01-08 12:22 - 0000000 ____D C:\Users\saliha\AppData\Local\{6B21F5F9-5526-434A-869F-1A446F275A96}
2012-01-07 18:53 - 2012-01-07 18:53 - 0000000 ____D C:\Users\saliha\AppData\Local\{0BF5B351-D057-435A-843B-8D7ED79DDE0D}
2012-01-07 18:52 - 2012-01-07 18:53 - 0000000 ____D C:\Users\saliha\AppData\Local\{750667E9-9FC5-4112-9FC2-166FB146923F}
2011-12-31 21:32 - 2011-12-31 21:32 - 0000000 ____D C:\Users\saliha\AppData\Local\{A60C007F-B9D8-4834-81A7-5F4991AB101B}
2011-12-30 21:33 - 2011-12-30 21:33 - 0000000 ____D C:\Users\saliha\AppData\Local\{A5DF7854-B697-4892-8683-1A75E695E855}
2011-12-30 21:33 - 2011-12-30 21:33 - 0000000 ____D C:\Users\saliha\AppData\Local\{323FF4D1-2CB0-435A-A06E-3EF15C72936F}
2011-12-30 15:07 - 2011-12-30 15:07 - 0002310 ____A C:\Users\saliha\Documents\Mein Film.wlmp
2011-12-30 15:05 - 2011-12-30 15:05 - 0000000 ____D C:\Users\saliha\AppData\Local\{A1AA8B62-847B-49BD-9C1D-368AC7D0125E}
2011-12-30 14:58 - 2011-12-30 14:58 - 0000000 ____D C:\Users\saliha\AppData\Local\{64A7E85E-3C74-4A69-932C-50B2A299E04D}
2011-12-27 19:17 - 2011-12-27 19:24 - 0000000 ____D C:\Users\saliha\Documents\Youcam
2011-12-27 19:17 - 2011-12-27 19:17 - 0000000 ____D C:\Users\saliha\AppData\Roaming\CyberLink
2011-12-27 19:17 - 2011-12-27 19:17 - 0000000 ____D C:\Users\saliha\AppData\Local\CyberLink
2011-12-27 18:06 - 2011-12-27 18:06 - 0000000 ____D C:\Users\saliha\AppData\Local\{BA46FFFB-3D07-47CF-A941-695AF86BDE44}
2011-12-27 18:05 - 2011-12-27 18:06 - 0000000 ____D C:\Users\saliha\AppData\Local\{5FD07E8D-5F6E-4512-896A-9ECDB62263F5}

============ 3 Months Modified Files and Folders ===============

2012-01-24 19:22 - 2012-01-24 18:36 - 0000000 ____D C:\FRST
2012-01-24 19:18 - 2012-01-12 19:49 - 1029112 ____A C:\Windows\ntbtlog.txt
2012-01-24 19:16 - 2011-09-19 02:50 - 797581312 __ASH C:\hiberfil.sys
2012-01-24 19:15 - 2011-01-07 15:40 - 0000000 ____D C:\Users\All Users\BullGuard
2012-01-24 19:15 - 2011-01-07 15:40 - 0000000 ____D C:\ProgramData\BullGuard
2012-01-24 19:14 - 2011-09-19 01:51 - 0001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-01-24 19:13 - 2012-01-24 19:13 - 0000000 ____D C:\Users\saliha\AppData\Local\{F3A3CC18-9B76-4340-9DFE-0AAF063363B2}
2012-01-24 19:13 - 2011-09-19 01:51 - 0001094 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-01-24 19:13 - 2011-01-07 13:24 - 0000004 ____A C:\Users\All Users\RELED.INI
2012-01-24 19:13 - 2011-01-07 13:24 - 0000004 ____A C:\ProgramData\RELED.INI
2012-01-24 19:13 - 2011-01-07 13:22 - 0000035 ____A C:\Users\Public\Documents\AtherosServiceConfig.ini
2012-01-24 19:13 - 2009-07-14 05:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-01-24 19:13 - 2009-07-14 05:39 - 0033975 ____A C:\Windows\setupact.log
2012-01-24 19:03 - 2011-09-19 01:51 - 1474846 ____A C:\Windows\WindowsUpdate.log
2012-01-24 19:03 - 2009-07-14 05:34 - 0009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-01-24 19:03 - 2009-07-14 05:34 - 0009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-01-24 18:55 - 2012-01-24 18:55 - 0000000 ____D C:\Users\saliha\AppData\Local\{C024A112-19DF-499E-A1D8-664DF3CFAFB7}
2012-01-24 18:52 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\LogFiles
2012-01-24 18:47 - 2012-01-24 18:47 - 0000000 ____D C:\Users\saliha\AppData\Local\{3CFDBB1F-B6DE-415A-A9DC-7BC69385941D}
2012-01-24 18:37 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\config\TxR
2012-01-24 18:36 - 2011-01-07 08:42 - 0005414 ____A C:\Windows\System32\PerfStringBackup.INI
2012-01-24 18:33 - 2012-01-24 18:33 - 0000000 ____D C:\Users\saliha\AppData\Local\{EB4B2084-1B22-4190-B560-97F857520599}
2012-01-23 00:23 - 2012-01-23 00:23 - 0000000 ____D C:\Users\saliha\AppData\Local\{CB4F5197-4E8A-492A-AF32-817E4E11F8FD}
2012-01-14 22:11 - 2012-01-14 22:11 - 0001075 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\Users\saliha\AppData\Roaming\Malwarebytes
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\Users\All Users\Malwarebytes
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\ProgramData\Malwarebytes
2012-01-14 22:11 - 2012-01-14 22:11 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-01-14 22:05 - 2012-01-14 22:04 - 0000000 ____D C:\Users\saliha\Documents\antibotcd0112_chip[1]
2012-01-14 21:55 - 2011-09-21 16:46 - 0000000 ____D C:\Users\saliha\AppData\Local\Windows Live
2012-01-14 21:54 - 2012-01-14 21:54 - 0000000 ____D C:\Users\saliha\AppData\Local\{F27399F7-2B82-4377-89A9-A9CF6A39C5D3}
2012-01-14 21:54 - 2012-01-14 21:54 - 0000000 ____D C:\Users\saliha\AppData\Local\{A755919E-1172-4683-8572-6CFDAC9588EB}
2012-01-14 21:53 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\wfp
2012-01-14 21:52 - 2012-01-13 21:57 - 0000000 ____D C:\1f46ce212972cb18796329d23666adad
2012-01-14 21:52 - 2011-09-19 01:55 - 0000000 ____D C:\users\saliha
2012-01-14 21:52 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\DriverStore
2012-01-14 21:52 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\registration
2012-01-13 19:10 - 2012-01-13 19:10 - 0002033 ____A C:\Users\saliha\Desktop\Entfernen des Avira DE-Cleaners.lnk
2012-01-13 19:10 - 2012-01-13 19:10 - 0001962 ____A C:\Users\saliha\Desktop\Avira DE-Cleaner.lnk
2012-01-13 18:42 - 2012-01-13 18:42 - 0000000 ____D C:\Users\saliha\AppData\Local\{D507EAA4-93E1-4B99-9B79-6E1821D7C26C}
2012-01-13 18:42 - 2012-01-13 18:42 - 0000000 ____D C:\Users\saliha\AppData\Local\{04E23234-F08B-4205-8705-8C9FA4812F2C}
2012-01-12 20:24 - 2012-01-12 20:24 - 0000000 ____D C:\Users\saliha\AppData\Local\ElevatedDiagnostics
2012-01-12 20:00 - 2012-01-12 20:00 - 0000000 ____D C:\Program Files\PriceGong
2012-01-12 19:57 - 2012-01-12 19:57 - 0459568 ____A (SweetIM Technologies, Ltd.) C:\Users\saliha\Desktop\SweetImSetup.exe
2012-01-12 18:50 - 2012-01-12 18:50 - 0000000 ____D C:\Users\saliha\AppData\Roaming\Avira
2012-01-12 18:07 - 2012-01-12 18:07 - 0000000 ____D C:\Users\saliha\AppData\Local\{73D0459D-B613-4205-9565-F0FD453405F2}
2012-01-12 18:07 - 2012-01-12 18:07 - 0000000 ____D C:\Users\saliha\AppData\Local\{0E35760C-C11F-4C9B-9E5E-4062494B85CA}
2012-01-12 18:04 - 2011-09-20 15:06 - 0007198 ____A C:\Windows\PFRO.log
2012-01-11 18:08 - 2012-01-11 18:08 - 0000000 ____D C:\Users\saliha\AppData\Local\{989BC29A-656C-4761-8420-532B82E3D3CF}
2012-01-11 18:08 - 2011-09-21 16:45 - 0000000 ____D C:\Users\saliha\Tracing
2012-01-09 18:08 - 2012-01-09 18:08 - 0000000 ____D C:\Users\saliha\AppData\Local\{1D531BC1-DC24-4750-92A2-9E0745D4F484}
2012-01-09 17:15 - 2012-01-09 17:15 - 0000000 ____D C:\Users\saliha\AppData\Local\{B8C0C2F3-7F81-4B9C-A4A1-0417128EF064}
2012-01-08 13:25 - 2012-01-08 13:25 - 0000000 ____D C:\Users\saliha\AppData\Local\{9C682E12-26BD-44B5-97ED-37A5D42C8997}
2012-01-08 13:25 - 2012-01-08 13:24 - 0000000 ____D C:\Users\saliha\AppData\Local\{3C4E2D2B-DDB2-4CDF-8891-9B2AFAD762C5}
2012-01-08 12:22 - 2012-01-08 12:22 - 0000000 ____D C:\Users\saliha\AppData\Local\{6B21F5F9-5526-434A-869F-1A446F275A96}
2012-01-07 18:53 - 2012-01-07 18:53 - 0000000 ____D C:\Users\saliha\AppData\Local\{0BF5B351-D057-435A-843B-8D7ED79DDE0D}
2012-01-07 18:53 - 2012-01-07 18:52 - 0000000 ____D C:\Users\saliha\AppData\Local\{750667E9-9FC5-4112-9FC2-166FB146923F}
2011-12-31 22:10 - 2011-09-19 01:57 - 0000000 ____D C:\Users\saliha\Documents\Bluetooth Folder
2011-12-31 21:32 - 2011-12-31 21:32 - 0000000 ____D C:\Users\saliha\AppData\Local\{A60C007F-B9D8-4834-81A7-5F4991AB101B}
2011-12-30 21:33 - 2011-12-30 21:33 - 0000000 ____D C:\Users\saliha\AppData\Local\{A5DF7854-B697-4892-8683-1A75E695E855}
2011-12-30 21:33 - 2011-12-30 21:33 - 0000000 ____D C:\Users\saliha\AppData\Local\{323FF4D1-2CB0-435A-A06E-3EF15C72936F}
2011-12-30 15:07 - 2011-12-30 15:07 - 0002310 ____A C:\Users\saliha\Documents\Mein Film.wlmp
2011-12-30 15:05 - 2011-12-30 15:05 - 0000000 ____D C:\Users\saliha\AppData\Local\{A1AA8B62-847B-49BD-9C1D-368AC7D0125E}
2011-12-30 14:58 - 2011-12-30 14:58 - 0000000 ____D C:\Users\saliha\AppData\Local\{64A7E85E-3C74-4A69-932C-50B2A299E04D}
2011-12-27 19:24 - 2011-12-27 19:17 - 0000000 ____D C:\Users\saliha\Documents\Youcam
2011-12-27 19:19 - 2011-09-21 18:13 - 0000000 ____D C:\Users\saliha\AppData\Local\CrashDumps
2011-12-27 19:18 - 2011-01-07 15:13 - 0000000 ____D C:\Users\All Users\CyberLink
2011-12-27 19:18 - 2011-01-07 15:13 - 0000000 ____D C:\ProgramData\CyberLink
2011-12-27 19:17 - 2011-12-27 19:17 - 0000000 ____D C:\Users\saliha\AppData\Roaming\CyberLink
2011-12-27 19:17 - 2011-12-27 19:17 - 0000000 ____D C:\Users\saliha\AppData\Local\CyberLink
2011-12-27 19:14 - 2011-01-07 15:13 - 0000000 ____D C:\Program Files\CyberLink
2011-12-27 18:06 - 2011-12-27 18:06 - 0000000 ____D C:\Users\saliha\AppData\Local\{BA46FFFB-3D07-47CF-A941-695AF86BDE44}
2011-12-27 18:06 - 2011-12-27 18:05 - 0000000 ____D C:\Users\saliha\AppData\Local\{5FD07E8D-5F6E-4512-896A-9ECDB62263F5}
2011-12-24 18:56 - 2011-12-24 18:56 - 0000000 ____D C:\Users\saliha\AppData\Local\{E981D599-5907-49B5-9CD3-A931DE859BCE}
2011-12-24 18:56 - 2011-12-24 18:56 - 0000000 ____D C:\Users\saliha\AppData\Local\{16DF0B9F-DD52-47F9-BB78-7DB572520E93}
2011-12-24 15:59 - 2011-12-24 15:59 - 0000000 ____D C:\Users\saliha\AppData\Local\{414E87E0-AA1C-4A5B-AA01-041B4E13CAA7}
2011-12-21 13:02 - 2011-12-21 13:02 - 0000000 ____D C:\Users\saliha\AppData\Local\{5ECDA144-C411-44E5-B02C-F39AF1697713}
2011-12-21 13:02 - 2011-12-21 13:02 - 0000000 ____D C:\Users\saliha\AppData\Local\{0DE2E428-0E02-43C9-825B-D61F9718685A}
2011-12-17 15:37 - 2011-12-17 15:37 - 0000000 ____D C:\Users\saliha\AppData\Local\{43EAAF49-BB0B-4AFE-83B0-F5FCB45BA6AA}
2011-12-17 15:37 - 2011-12-17 15:36 - 0000000 ____D C:\Users\saliha\AppData\Local\{DCC69DB9-8779-4C8D-B52D-2AD2EC5FA718}
2011-12-17 15:35 - 2009-07-14 05:53 - 0032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2011-12-16 18:58 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\rescache
2011-12-16 17:45 - 2009-07-14 05:33 - 0269184 ____A C:\Windows\System32\FNTCACHE.DAT
2011-12-16 13:43 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\de-DE
2011-12-16 13:17 - 2011-12-16 13:16 - 0000000 ____D C:\Users\saliha\AppData\Local\{941704E3-9297-4AE4-8F0A-8A51B59FE13D}
2011-12-16 13:16 - 2011-12-16 13:16 - 0000000 ____D C:\Users\saliha\AppData\Local\{F93A3E15-B10E-44B3-8954-1A4C6EFB9D08}
2011-12-14 17:01 - 2011-12-14 17:01 - 0000000 ____D C:\Users\saliha\AppData\Local\{99558AFE-B930-4BB8-AB44-1AAC24F38DB2}
2011-12-14 17:01 - 2011-12-14 17:01 - 0000000 ____D C:\Users\saliha\AppData\Local\{650438B3-EB3C-4146-BA76-C22AC8F464B6}
2011-12-13 12:57 - 2011-12-13 12:56 - 0000000 ____D C:\Users\saliha\AppData\Local\{D6FC4799-4F83-4E7E-8749-E5FDFA4B86A3}
2011-12-13 12:56 - 2011-12-13 12:56 - 0000000 ____D C:\Users\saliha\AppData\Local\{7C18EFEF-7206-4EDA-8A92-3161E9384078}
2011-12-12 18:51 - 2011-12-12 18:51 - 0000000 ____D C:\Users\saliha\AppData\Local\{86B0168E-73EC-40A3-BD1A-717B4257EBB9}
2011-12-12 18:51 - 2011-12-12 18:51 - 0000000 ____D C:\Users\saliha\AppData\Local\{529A5C7A-3E17-44B6-9C4F-60DD430B566A}
2011-12-11 16:38 - 2011-12-11 16:38 - 0000000 ____D C:\Users\saliha\AppData\Local\{20083A5D-C189-486E-8BB4-2D15C18E8BB7}
2011-12-10 15:24 - 2012-01-14 22:11 - 0020464 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2011-12-09 13:32 - 2011-12-09 13:32 - 0000000 ____D C:\Users\saliha\AppData\Local\{11BC62B0-DD14-4998-9D3B-88EFA2C3B74A}
2011-12-09 13:32 - 2011-12-09 13:31 - 0000000 ____D C:\Users\saliha\AppData\Local\{D079650F-F05E-427E-A7C1-3CB94EA6C8A9}
2011-12-08 17:29 - 2011-12-08 17:28 - 0000000 ____D C:\Users\saliha\AppData\Local\{CDDEB7C2-A9EB-4A51-86FF-6C9F5417A6C3}
2011-12-08 17:28 - 2011-12-08 17:28 - 0000000 ____D C:\Users\saliha\AppData\Local\{077A2E39-A333-413E-AAD6-594B9C4BB3E1}
2011-12-05 13:16 - 2011-12-05 13:16 - 0000000 ____D C:\Users\saliha\AppData\Local\{0FE99463-2C7F-4EA7-8AE6-877B669E574B}
2011-12-05 13:16 - 2011-12-05 13:15 - 0000000 ____D C:\Users\saliha\AppData\Local\{7859EC40-C125-4A0B-8F1F-625FBEE4084F}
2011-12-02 16:54 - 2011-12-02 16:54 - 0000000 ____D C:\Users\saliha\AppData\Local\{07043F2D-F2A5-42F4-9F25-3E703B2C8287}
2011-12-02 16:53 - 2011-12-02 16:53 - 0000000 ____D C:\Users\saliha\AppData\Local\{6404611D-FB3D-4395-A786-EA12D9CD0E28}
2011-11-29 13:48 - 2011-11-29 13:48 - 0000000 ____D C:\Users\saliha\AppData\Local\{68566F0E-E75E-4EB1-8AE2-8686BC49C0DF}
2011-11-27 22:27 - 2011-11-27 22:27 - 0000000 ____D C:\Users\saliha\AppData\Local\{F0D11A7B-108D-4545-B76F-F71628C4C577}
2011-11-27 22:27 - 2011-11-27 22:27 - 0000000 ____D C:\Users\saliha\AppData\Local\{B49057A7-F6B2-479A-9C1E-86399C4F7533}
2011-11-26 17:10 - 2011-11-26 17:10 - 0000000 ____D C:\Users\saliha\AppData\Local\{D7EE7E7F-4AD6-4C03-9B2B-81906969B5FD}
2011-11-26 17:10 - 2011-11-26 17:10 - 0000000 ____D C:\Users\saliha\AppData\Local\{95CCD99C-CFF2-4262-8782-86978FC45575}
2011-11-25 23:02 - 2011-10-24 17:37 - 0000000 ____D C:\Users\saliha\AppData\Local\Microsoft Games
2011-11-25 22:27 - 2011-11-25 22:27 - 0000000 ____D C:\Users\saliha\AppData\Local\{730F32F1-843D-40B0-AA6F-BEA4D2E3F2EC}
2011-11-24 12:54 - 2011-11-24 12:53 - 0000000 ____D C:\Users\saliha\AppData\Local\{F0D8F908-101B-417B-9FAE-57C3CBAC5C9F}
2011-11-24 12:53 - 2011-11-24 12:53 - 0000000 ____D C:\Users\saliha\AppData\Local\{582F1CA6-0F9D-402E-9D00-5F0D83337449}
2011-11-24 05:23 - 2011-12-14 17:20 - 2340352 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2011-11-22 12:41 - 2011-11-22 12:40 - 0000000 ____D C:\Users\saliha\AppData\Local\{A42F7E31-59D7-490D-AE60-E26880F1CB07}
2011-11-22 12:40 - 2011-11-22 12:40 - 0000000 ____D C:\Users\saliha\AppData\Local\{EEEBF94D-9EDB-499A-9556-5231C49C3CA1}
2011-11-20 19:25 - 2011-11-20 19:25 - 0000000 ____D C:\Users\saliha\AppData\Local\{50394585-E040-4C1F-B60D-7116DC758526}
2011-11-20 19:25 - 2011-11-20 19:24 - 0000000 ____D C:\Users\saliha\AppData\Local\{4889ABB5-14C0-4012-A22F-11F3E68D3673}
2011-11-19 21:37 - 2011-11-19 21:37 - 0000000 ____D C:\Users\saliha\AppData\Local\{859CC8F8-29D6-4F78-88AC-7D2403521354}
2011-11-19 21:36 - 2011-11-19 21:36 - 0000000 ____D C:\Users\saliha\AppData\Local\{00BD1039-20DA-4422-9C08-F94F53829255}
2011-11-19 21:32 - 2011-11-19 21:32 - 0000000 ____D C:\Users\saliha\AppData\Local\{2CCD19D3-5264-4429-8AAC-32653A1517ED}
2011-11-19 21:28 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\NDF
2011-11-19 21:25 - 2011-11-19 21:25 - 0000000 ____D C:\Users\saliha\AppData\Local\{1A9B26A7-E876-4438-AA3B-FF3BD3A64067}
2011-11-19 15:06 - 2012-01-11 18:15 - 0067072 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll
2011-11-18 21:28 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\Microsoft.NET
2011-11-18 20:45 - 2011-11-18 20:45 - 0000000 ____D C:\Users\saliha\AppData\Local\{81F03172-D4D5-4537-8579-C09D626A23DE}
2011-11-18 20:45 - 2011-11-18 20:45 - 0000000 ____D C:\Users\saliha\AppData\Local\{025BE8B8-7F1B-4434-AC31-86089B6FFB4D}
2011-11-17 19:58 - 2011-11-17 19:58 - 0000000 ____D C:\Users\saliha\AppData\Local\{9EED3E49-0B89-41AD-B968-AC8D8B94E856}
2011-11-17 19:58 - 2011-11-17 19:57 - 0000000 ____D C:\Users\saliha\AppData\Local\{B8A0ADDC-489F-4D12-9EB7-0BC3102FD692}
2011-11-17 06:41 - 2012-01-11 18:15 - 1288984 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2011-11-16 20:30 - 2011-11-16 20:29 - 0000000 ____D C:\Users\saliha\AppData\Local\{4EDCE6B4-59B6-4345-A20F-184CC60865B1}
2011-11-16 20:29 - 2011-11-16 20:29 - 0000000 ____D C:\Users\saliha\AppData\Local\{69A8FEED-78F9-4E95-A357-8B99BCCEA2F5}
2011-11-15 20:22 - 2011-11-15 20:22 - 0000000 ____D C:\Users\saliha\AppData\Local\{C2779538-C215-4915-9A6A-B551D5999932}
2011-11-15 20:22 - 2011-11-15 20:22 - 0000000 ____D C:\Users\saliha\AppData\Local\{6B5299C8-291D-4346-BB3A-56A9B3FCFB1F}
2011-11-14 20:40 - 2011-11-14 20:40 - 0000000 ____D C:\Users\saliha\AppData\Local\{6EDFB4B1-70FD-4E15-B230-D37AD3F01693}
2011-11-14 20:39 - 2011-11-14 20:39 - 0000000 ____D C:\Users\saliha\AppData\Local\{ED1EE2CC-E767-4769-9B22-EDDE9C139215}
2011-11-14 13:20 - 2011-11-14 13:20 - 0000000 ____D C:\Users\saliha\AppData\Local\{9E4B7C8C-9275-4AA4-B469-333DE1946506}
2011-11-14 13:20 - 2011-11-14 13:20 - 0000000 ____D C:\Users\saliha\AppData\Local\{7A2F80A2-C1CA-40DF-91B8-E40C1D18DA17}
2011-11-13 20:15 - 2011-11-13 20:15 - 0000000 ____D C:\Users\saliha\AppData\Local\{51BDD3BC-26EE-49BA-BAEF-06BBDA43972D}
2011-11-13 12:21 - 2011-11-13 12:21 - 0000000 ____D C:\Users\saliha\AppData\Local\{9DC9EFB9-7AA6-4D8F-880A-0F2CBBF724E0}
2011-11-12 15:56 - 2011-11-12 15:55 - 0000000 ____D C:\Users\saliha\AppData\Local\{2B2FEED6-7106-41E6-A483-5FF2CC4069B4}
2011-11-12 15:55 - 2011-11-12 15:55 - 0000000 ____D C:\Users\saliha\AppData\Local\{B772ECDE-91B3-4A3B-98EC-5E3FF41E66DD}
2011-11-11 14:15 - 2009-07-14 03:37 - 0000000 ____D C:\Program Files\Common Files\System
2011-11-11 13:16 - 2011-11-11 13:16 - 0000000 ____D C:\Users\saliha\AppData\Local\{6DD14BC8-0E14-4A21-87A4-6A98692165F1}
2011-11-11 13:16 - 2011-11-11 13:16 - 0000000 ____D C:\Users\saliha\AppData\Local\{5D17E382-AE6F-4DDC-A709-7971261DA918}
2011-11-11 06:50 - 2011-12-14 17:20 - 10990080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-11-11 06:50 - 2011-12-14 17:20 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2011-11-10 11:41 - 2011-11-10 11:41 - 0000000 ____D C:\Users\saliha\AppData\Local\{8D68677F-BB5D-4E68-9820-56B57C9D7DE9}
2011-11-10 11:41 - 2011-11-10 11:41 - 0000000 ____D C:\Users\saliha\AppData\Local\{5B48BC9B-EBAF-4303-8046-BB77FBE65C86}
2011-11-08 12:58 - 2011-11-08 12:58 - 0000000 ____D C:\Users\saliha\AppData\Local\{E00A9A71-54FD-482C-AB67-4211E6A10A97}
2011-11-08 12:58 - 2011-11-08 12:57 - 0000000 ____D C:\Users\saliha\AppData\Local\{66EB0B9B-0A2F-4A70-AA8E-33AB20654D8D}
2011-11-07 13:14 - 2011-11-07 13:14 - 0000000 ____D C:\Users\saliha\AppData\Local\{0CC27395-D59B-4AB8-BBBA-D01420B76B1C}
2011-11-07 13:13 - 2011-11-07 13:13 - 0000000 ____D C:\Users\saliha\AppData\Local\{655B213F-FF31-40E6-9266-90D8B7BE65E0}
2011-11-05 20:14 - 2011-11-05 20:14 - 0000000 ____D C:\Users\saliha\AppData\Local\{EBE36C18-5C03-432B-8E3A-64F7C4528281}
2011-11-05 05:35 - 2011-12-14 17:20 - 1230336 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-11-05 05:35 - 2011-12-14 17:20 - 0981504 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-11-05 05:35 - 2011-12-14 17:20 - 0132096 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 5997568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 2072576 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0606208 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0599552 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0185856 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0067072 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0064512 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0048128 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-11-05 05:34 - 2011-12-14 17:20 - 0044544 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2011-11-05 05:33 - 2011-12-14 17:20 - 0381440 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2011-11-05 05:32 - 2011-12-14 17:20 - 0012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2011-11-05 05:30 - 2011-12-14 17:19 - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2011-11-05 04:28 - 2011-12-14 17:20 - 0386048 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2011-11-05 03:55 - 2011-12-14 17:20 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-11-04 13:49 - 2011-11-04 13:49 - 0000000 ____D C:\Users\saliha\AppData\Local\{EF5F6530-2D67-4D80-8D55-C8CBFA50B0FC}
2011-11-04 13:49 - 2011-11-04 13:48 - 0000000 ____D C:\Users\saliha\AppData\Local\{A3749E68-F361-4E6C-ABA2-5032CA1D5F88}
2011-11-03 20:27 - 2011-11-03 20:26 - 0000000 ____D C:\Users\saliha\AppData\Local\{C5F098A4-A2E3-4C35-913B-615B6B029D02}
2011-11-03 20:26 - 2011-11-03 20:26 - 0000000 ____D C:\Users\saliha\AppData\Local\{81921924-9BEF-45E0-A3C9-C00A4F930162}
2011-11-02 13:38 - 2011-11-02 13:38 - 0000000 ____D C:\Users\saliha\AppData\Local\{C2F741C5-59E7-4932-9452-F67C64D195AE}
2011-11-02 13:38 - 2011-11-02 13:38 - 0000000 ____D C:\Users\saliha\AppData\Local\{50F384FB-ED69-4EAD-AB28-C1FF7C3D7685}
2011-11-02 13:29 - 2011-11-02 13:29 - 0000000 ____D C:\Users\saliha\AppData\Local\{619692C6-BD3D-4750-B766-A55B697049F0}
2011-11-02 13:29 - 2011-11-02 13:28 - 0000000 ____D C:\Users\saliha\AppData\Local\{69CCE766-CB3B-4A6C-A7B8-5FF632F71241}
2011-11-01 08:04 - 2011-11-01 08:04 - 0000000 ____D C:\Users\saliha\AppData\Local\{E7DFBA66-BAB5-403D-9A79-1BC835E75673}
2011-10-31 16:12 - 2011-10-31 16:12 - 0000000 ____D C:\Users\saliha\AppData\Local\{15E32537-5AE8-44EA-B46B-5ABCE61C04A7}
2011-10-31 16:12 - 2011-10-31 16:11 - 0000000 ____D C:\Users\saliha\AppData\Local\{E7D5639C-2CAC-4D73-A290-3E6BD9837F4A}
2011-10-28 16:07 - 2011-10-28 16:06 - 0000000 ____D C:\Users\saliha\AppData\Local\{D8ED9AF2-BE7B-409B-B852-1D044DE2191C}
2011-10-28 16:06 - 2011-10-28 16:06 - 0000000 ____D C:\Users\saliha\AppData\Local\{5D7C3C49-B685-4E14-B5B3-CFAA5CA98D28}
2011-10-28 14:49 - 2011-10-28 14:49 - 0000000 ____D C:\Users\saliha\AppData\Local\{0CC605D8-E604-420B-8780-3D607F02770D}
2011-10-27 14:28 - 2011-10-27 14:27 - 0000000 ____D C:\Users\saliha\AppData\Local\{001CF2BA-E479-4B68-9816-DE93DD3E032A}
2011-10-27 14:27 - 2011-10-27 14:27 - 0000000 ____D C:\Users\saliha\AppData\Local\{E1F92E4A-E856-4786-8BE7-10F8581DFB4C}

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 21%
Total physical RAM: 1014.18 MB
Available physical RAM: 793.31 MB
Total Pagefile: 2038.18 MB
Available Pagefile: 1826.38 MB
Total Virtual: 2047.88 MB
Available Virtual: 1949.53 MB

======================= Partitions =========================

1 Drive c: (BOOT) (Fixed) (Total:191.78 GB) (Free:159.96 GB) NTFS
2 Drive d: (Recover) (Fixed) (Total:37.99 GB) (Free:26.11 GB) NTFS
3 Drive e: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT

Datentr„ger ### Status Gr”áe Frei Dyn GPT
--------------- ------------- ------- ------- --- ---
Datentr„ger 0 Online 232 GB 6144 KB
Datentr„ger 1 Online 961 MB 0 B

Datentr„gerpartitionierung wird beendet...


==========================================================

Last Boot: 2011-12-27 18:33

======================= End Of Log ==========================

Larusso 24.01.2012 20:45

Hm, ich seh da nichts.

Lassen wir mein Tool mal drüber, vl haben wir dann Glück.


Downloade dir bitte srep.exe und speichere diese auf einen USB Stick.
Wichtig: Nicht in einen Ordner speichern.
  • Starte den infizierten Rechner neu auf.
  • Während dem Hochfahren drücke mehrmals die F8 Taste. Danach solltest Du einige Optionen zur Auswahl haben. Navigiere mit den Pfeiltasten zu Abgesicherter Modus mit Eingabeaufforderung und drücke Enter
    ** Hinweis: Es kann sein, dass eine andere F Taste gedrückt werden muss, um in die Startoptionen zu kommen.
  • Logge dich nun in das infizierte Benutzerkonto ein.
  • Schließe den USB Stick an den infizierten Rechner an.
  • Nun ist etwas Handarbeit gefragt.
    • Du musst zuerst heraus finden, welchen Laufwerksbuchstaben der USB Stick hat.
    • Dazu gib bitte einfach E: ein und drücke Enter. Sollte folgende Meldung kommen.
      Zitat:

      Das System kann das angegeben Laufwerk nicht finden
      versuche einen anderen Laufwerksbuchstaben. ( zB F: )
  • Sobald Du den richtigen Laufwerksbuchstaben gefunden hast, gib folgendes ein und drücke Enter.
    start srep.exe
  • Drücke nun auf Scan.
  • Lass das Tool in Ruhe laufen. Der Rechner wird automatisch neu starten.
Auf deinen USB Stick befindet sich eine shell.txt. Bitte poste diese in deiner nächsten Antwort.

Hinweis: Es ist gut möglich, dass du bereits nach dem Scan wieder auf deinen Rechner zugreifen kannst.

farida 24.01.2012 20:52

Ok,wird gemacht.

farida 24.01.2012 21:07

So

WIN_7 X86
Running from E:\

HKLM\..\Winlogon; Shell = explorer.exe [ Microsoft Corporation ]
.
.
.
HKCU\..\Winlogon; Shell not found
.


[System Process]
System
smss.exe
csrss.exe
csrss.exe
wininit.exe
winlogon.exe
services.exe
lsass.exe
lsm.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
cmd.exe
conhost.exe
ctfmon.exe
srep.exe


HKLM\..\Run [IgfxTray] = C:\Windows\system32\igfxtray.exe
HKLM\..\Run [HotKeysCmds] = C:\Windows\system32\hkcmd.exe
HKLM\..\Run [Persistence] = C:\Windows\system32\igfxpers.exe
HKLM\..\Run [RtHDVCpl] = C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
HKLM\..\Run [FLxHCIm] = "C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe"
HKLM\..\Run [AtherosBtStack] = "C:\Program Files\Atheros\Bluetooth Suite\BtvStack.exe"
HKLM\..\Run [AthBtTray] = "C:\Program Files\Atheros\Bluetooth Suite\AthBtTray.exe"
HKLM\..\Run [fspuip] = %ProgramFiles%\FSP\fspuip.exe
HKLM\..\Run [Hotkey] = C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe
HKLM\..\Run [BullGuard] = "C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe" -boot
HKLM\..\Run [avgnt] = "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\..\Run [Malwarebytes' Anti-Malware] = "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

HKCU\..\Run [swg] = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKCU\..\Run [msnmsgr] = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

HKU\.DEFAULT\..\Winlogon; Shell =
HKU\S-1-5-19\..\Winlogon; Shell =
HKU\S-1-5-20\..\Winlogon; Shell =
HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\..\Winlogon; Shell =
HKU\S-1-5-21-3447485870-3442626122-2541432802-1000_Classes\..\Winlogon; Shell =
HKU\S-1-5-18\..\Winlogon; Shell =

HKU\S-1-5-19\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\..\Run [Sidebar] = %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\..\Run [swg] = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\..\Run [msnmsgr] = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

==== FINISH 24.01-21.05 ====

farida 24.01.2012 21:35

:dankeschoen:Ja es geht wieder juhuuuuuuuuuuuuuuu.Vielen lieben dank.Aber bin ich den Trojaner jetzt wirklich los?Wie kann ich mich am besten vor sowas schützen

Larusso 24.01.2012 21:43

Huch, magic ?

Auf deinem USB Stick sollte sich ein Ordner Infected befinden. Sieh mal bitte nach, ob der leer ist.


Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
%systemroot%\system32\*.manifest /3
/md5start
explorer.exe
regedit.exe
winlogon.exe
wininit.exe
userinit.exe
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Wenn der Scan beendet wurde, wird sich ein Textdokument öffnen.
  • Kopiere nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

farida 24.01.2012 21:53

Nein,der Ordner ist nicht leer.Da steht:hkcu Grösse 1KB und hklm 25KB.was ist das?

Larusso 24.01.2012 22:02

Kannst den Ordner löschen, poste mir die OTL Logfiles

farida 24.01.2012 22:13

Sag mal muss ich das jetzt machen oder kann ich das auch später machen?muss leider zu arbeit bin abreite im hotel und mein dienst beginnt um 23uhr.

farida 25.01.2012 00:18

Hi Daniel,hab das Notebook mit auf arbeit genommen und hab jetzt zeit.Ja kann und hab de Ordner gelösch.Ich hoffe,dass war richtig?Hab auch OTL herruntergeladen:Ich weiss nur nicht,was ich da in der Benutzerdefinierte Scan/Filxes hineinkopieren soll?

farida 25.01.2012 00:54

Ok ok hab es rausbekommen:rofl:und den quick scan durchgeführt.

farida 25.01.2012 00:56

Aber da öffnet sich kein Textdokument

farida 25.01.2012 01:00

OTL Logfile:
Code:

OTL logfile created on: 25.01.2012 00:41:01 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\saliha\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014,18 Mb Total Physical Memory | 471,31 Mb Available Physical Memory | 46,47% Memory free
1,99 Gb Paging File | 1,26 Gb Available in Paging File | 63,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,78 Gb Total Space | 160,75 Gb Free Space | 83,82% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 26,11 Gb Free Space | 68,71% Space Free | Partition Type: NTFS
Drive E: | 960,72 Mb Total Space | 957,78 Mb Free Space | 99,69% Space Free | Partition Type: FAT
 
Computer Name: SALIHA-PC | User Name: saliha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.24 23:37:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\saliha\Desktop\OTL.exe
PRC - [2011.12.24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.12.24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.04.21 06:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.21 06:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- c:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.03.28 19:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 19:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011.03.28 10:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft\BingBar\SeaPort.EXE
PRC - [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.01.07 12:06:25 | 000,233,936 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe
PRC - [2010.11.25 20:28:50 | 000,486,560 | ---- | M] (Atheros Communications) -- C:\Programme\Atheros\Bluetooth Suite\BtvStack.exe
PRC - [2010.11.25 20:28:44 | 000,302,240 | ---- | M] (Atheros Commnucations) -- C:\Programme\Atheros\Bluetooth Suite\AthBtTray.exe
PRC - [2010.11.25 20:28:42 | 000,056,480 | ---- | M] (Atheros Commnucations) -- C:\Programme\Atheros\Bluetooth Suite\AdminService.exe
PRC - [2010.11.19 16:25:40 | 000,033,792 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Programme\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe
PRC - [2010.10.20 14:23:26 | 000,821,664 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
PRC - [2010.10.08 13:53:38 | 000,348,160 | ---- | M] (Pegatron) -- C:\Programme\Pegatron\Hotkey\PHControl.exe
PRC - [2010.09.14 04:46:26 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010.09.14 04:46:16 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010.09.09 17:45:12 | 003,704,320 | ---- | M] (Sentelic Corporation) -- C:\Programme\FSP\FspUip.exe
PRC - [2010.05.24 15:44:48 | 000,151,552 | ---- | M] (Atheros) -- C:\Programme\Atheros\Ath_CoexAgent.exe
PRC - [2009.07.14 02:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.06.03 14:59:26 | 000,258,048 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\FastUserSwitching.exe
PRC - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010.09.24 17:04:00 | 000,053,248 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\WLANV.dll
MOD - [2010.09.09 17:44:02 | 000,066,048 | ---- | M] () -- C:\Programme\FSP\FspLib.dll
MOD - [2010.09.09 17:43:54 | 000,044,544 | ---- | M] () -- C:\Programme\FSP\KbdHook.dll
MOD - [2010.05.04 14:27:02 | 000,155,648 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\LCSwit.dll
MOD - [2009.10.28 16:15:36 | 000,053,248 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\TPS.dll
MOD - [2009.06.16 16:06:14 | 000,212,992 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\HKBD.dll
MOD - [2009.06.03 15:03:52 | 000,053,248 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\PEGAACPIDLL32.dll
MOD - [2009.06.03 14:59:26 | 000,258,048 | ---- | M] () -- C:\Programme\Pegatron\Hotkey\FastUserSwitching.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.12.24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.07.21 11:08:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.21 06:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.04.01 10:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.03.28 10:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010.11.25 20:28:42 | 000,056,480 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Programme\Atheros\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010.09.14 04:46:26 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010.09.14 04:46:16 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.05.24 15:44:48 | 000,151,552 | ---- | M] (Atheros) [Auto | Running] -- C:\Programme\Atheros\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.12.10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.07.21 11:11:12 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.21 11:11:11 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.11.25 20:29:00 | 000,239,776 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btfilter.sys -- (BtFilter)
DRV - [2010.11.25 20:29:00 | 000,141,088 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\btath_rcp.sys -- (BTATH_RCP)
DRV - [2010.11.25 20:28:58 | 000,258,720 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV - [2010.11.25 20:28:58 | 000,175,776 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\btath_hcrp.sys -- (BTATH_HCRP)
DRV - [2010.11.25 20:28:58 | 000,049,312 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV - [2010.11.25 20:28:58 | 000,034,976 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_flt.sys -- (AthBTPort)
DRV - [2010.11.25 20:28:58 | 000,024,736 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\btath_bus.sys -- (BTATH_BUS)
DRV - [2010.11.25 20:28:56 | 000,043,680 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\AthDfu.sys -- (ATHDFU)
DRV - [2010.11.19 16:25:40 | 000,174,080 | ---- | M] (Fresco Logic) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\FLxHCIc.sys -- (FLxHCIc) Fresco Logic xHCI (USB3)
DRV - [2010.11.19 16:25:40 | 000,038,400 | ---- | M] (Fresco Logic) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\FLxHCIh.sys -- (FLxHCIh) Fresco Logic xHCI (USB3)
DRV - [2010.10.28 20:07:44 | 000,027,632 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\clwvd.sys -- (clwvd)
DRV - [2010.09.14 04:46:26 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2010.09.14 04:46:22 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2010.09.14 04:46:18 | 000,194,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2010.09.14 04:46:14 | 000,577,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2010.09.09 17:48:36 | 000,055,808 | ---- | M] (Sentelic Corporation) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\fspad_wlh32.sys -- (fspad_wlh32)
DRV - [2010.07.08 01:02:14 | 001,801,216 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010.03.01 15:56:18 | 000,031,232 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AmUStor.sys -- (AmUStor)
DRV - [2009.10.08 16:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.06.09 20:30:42 | 000,016,456 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\ATKACPI.SYS -- (ACPIService)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI
IE - HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}: C:\Program Files\PriceGong\2.5.4\FF [2012.01.12 20:00:57 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Programme\PriceGong\2.5.4\PriceGongIE.dll (PriceGong)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Programme\Atheros\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-3447485870-3442626122-2541432802-1000\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AthBtTray] C:\Program Files\Atheros\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4 - HKLM..\Run: [AtherosBtStack] C:\Program Files\Atheros\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [FLxHCIm] C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe (Windows (R) Win 7 DDK provider)
O4 - HKLM..\Run: [fspuip] C:\Programme\FSP\FspUip.exe (Sentelic Corporation)
O4 - HKLM..\Run: [Hotkey] C:\Programme\Pegatron\Hotkey\FastUserSwitching.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\saliha\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay - eine der größten deutschen Shopping-Websites File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay - eine der größten deutschen Shopping-Websites File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Programme\Atheros\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77DE3EC2-C39E-4E8B-8E11-8AFABC812ACD}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E8CF0311-F9B5-4A3A-BEE9-D8C906E1C2F2}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.24 23:37:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\saliha\Desktop\OTL.exe
[2012.01.24 21:21:51 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{42F8AC1F-AE2A-48A5-A912-4B75357736B8}
[2012.01.24 21:21:23 | 000,000,000 | R--D | C] -- C:\Users\saliha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2012.01.24 21:07:20 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{18007C3A-5E3C-4619-9983-2473BB053C3B}
[2012.01.24 19:13:55 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{F3A3CC18-9B76-4340-9DFE-0AAF063363B2}
[2012.01.24 18:55:59 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{C024A112-19DF-499E-A1D8-664DF3CFAFB7}
[2012.01.24 18:47:09 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{3CFDBB1F-B6DE-415A-A9DC-7BC69385941D}
[2012.01.24 18:36:37 | 000,000,000 | ---D | C] -- C:\FRST
[2012.01.24 18:33:53 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{EB4B2084-1B22-4190-B560-97F857520599}
[2012.01.23 00:23:23 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{CB4F5197-4E8A-492A-AF32-817E4E11F8FD}
[2012.01.14 22:11:45 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Roaming\Malwarebytes
[2012.01.14 22:11:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.14 22:11:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.01.14 22:11:37 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.01.14 22:11:37 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.01.14 22:04:51 | 000,000,000 | ---D | C] -- C:\Users\saliha\Documents\antibotcd0112_chip[1]
[2012.01.14 21:54:43 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A755919E-1172-4683-8572-6CFDAC9588EB}
[2012.01.14 21:54:30 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{F27399F7-2B82-4377-89A9-A9CF6A39C5D3}
[2012.01.13 21:57:16 | 000,000,000 | ---D | C] -- C:\1f46ce212972cb18796329d23666adad
[2012.01.13 18:42:35 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{D507EAA4-93E1-4B99-9B79-6E1821D7C26C}
[2012.01.13 18:42:24 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{04E23234-F08B-4205-8705-8C9FA4812F2C}
[2012.01.12 20:24:38 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\ElevatedDiagnostics
[2012.01.12 20:00:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
[2012.01.12 20:00:57 | 000,000,000 | ---D | C] -- C:\Program Files\PriceGong
[2012.01.12 19:57:01 | 000,459,568 | ---- | C] (SweetIM Technologies, Ltd.) -- C:\Users\saliha\Desktop\SweetImSetup.exe
[2012.01.12 18:50:37 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Roaming\Avira
[2012.01.12 18:07:41 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{73D0459D-B613-4205-9565-F0FD453405F2}
[2012.01.12 18:07:28 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{0E35760C-C11F-4C9B-9E5E-4062494B85CA}
[2012.01.11 18:08:49 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{989BC29A-656C-4761-8420-532B82E3D3CF}
[2012.01.09 18:08:05 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{1D531BC1-DC24-4750-92A2-9E0745D4F484}
[2012.01.09 17:15:02 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{B8C0C2F3-7F81-4B9C-A4A1-0417128EF064}
[2012.01.08 13:25:12 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{9C682E12-26BD-44B5-97ED-37A5D42C8997}
[2012.01.08 13:24:48 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{3C4E2D2B-DDB2-4CDF-8891-9B2AFAD762C5}
[2012.01.08 12:22:05 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{6B21F5F9-5526-434A-869F-1A446F275A96}
[2012.01.07 18:53:19 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{0BF5B351-D057-435A-843B-8D7ED79DDE0D}
[2012.01.07 18:52:44 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{750667E9-9FC5-4112-9FC2-166FB146923F}
[2011.12.31 21:32:11 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A60C007F-B9D8-4834-81A7-5F4991AB101B}
[2011.12.30 21:33:40 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{323FF4D1-2CB0-435A-A06E-3EF15C72936F}
[2011.12.30 21:33:27 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A5DF7854-B697-4892-8683-1A75E695E855}
[2011.12.30 15:05:24 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A1AA8B62-847B-49BD-9C1D-368AC7D0125E}
[2011.12.30 14:58:56 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{64A7E85E-3C74-4A69-932C-50B2A299E04D}
[2011.12.27 19:17:55 | 000,000,000 | ---D | C] -- C:\Users\saliha\Documents\Youcam
[2011.12.27 19:17:50 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Roaming\CyberLink
[2011.12.27 19:17:48 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\CyberLink
[2011.12.27 18:06:04 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{BA46FFFB-3D07-47CF-A941-695AF86BDE44}
[2011.12.27 18:05:49 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{5FD07E8D-5F6E-4512-896A-9ECDB62263F5}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.25 00:44:47 | 000,000,004 | ---- | M] () -- C:\ProgramData\RELED.INI
[2012.01.25 00:14:01 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.24 23:37:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\saliha\Desktop\OTL.exe
[2012.01.24 21:34:24 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.24 21:34:24 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.24 21:21:21 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2012.01.24 21:21:13 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.24 21:20:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.24 21:20:52 | 797,581,312 | -HS- | M] () -- C:\hiberfil.sys
[2012.01.24 18:36:44 | 001,169,458 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.24 18:36:44 | 000,769,750 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.24 18:36:44 | 000,293,080 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.24 18:36:44 | 000,253,152 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.14 22:11:39 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.13 19:10:20 | 000,002,033 | ---- | M] () -- C:\Users\saliha\Desktop\Entfernen des Avira DE-Cleaners.lnk
[2012.01.13 19:10:20 | 000,001,962 | ---- | M] () -- C:\Users\saliha\Desktop\Avira DE-Cleaner.lnk
[2012.01.12 19:57:07 | 000,459,568 | ---- | M] (SweetIM Technologies, Ltd.) -- C:\Users\saliha\Desktop\SweetImSetup.exe
[2011.12.30 15:07:43 | 000,002,310 | ---- | M] () -- C:\Users\saliha\Documents\Mein Film.wlmp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.14 22:11:39 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.13 19:10:20 | 000,002,033 | ---- | C] () -- C:\Users\saliha\Desktop\Entfernen des Avira DE-Cleaners.lnk
[2012.01.13 19:10:20 | 000,001,962 | ---- | C] () -- C:\Users\saliha\Desktop\Avira DE-Cleaner.lnk
[2011.12.30 15:07:43 | 000,002,310 | ---- | C] () -- C:\Users\saliha\Documents\Mein Film.wlmp
[2011.01.07 13:24:31 | 000,000,004 | ---- | C] () -- C:\ProgramData\RELED.INI
[2011.01.07 13:16:26 | 000,246,804 | ---- | C] () -- C:\Windows\System32\AtherosBT.bin
[2011.01.07 13:13:01 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2010.12.17 08:45:41 | 000,016,456 | ---- | C] () -- C:\Windows\System32\drivers\ATKACPI.SYS
[2010.12.09 08:02:08 | 000,030,720 | --S- | C] () -- C:\Windows\System32\Install-Ambion.exe
[2010.11.25 20:20:54 | 000,246,804 | ---- | C] () -- C:\Windows\System32\drivers\AtherosBt.bin
[2009.07.14 09:47:43 | 001,169,458 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 09:47:43 | 000,293,080 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,269,184 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,769,750 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,253,152 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== LOP Check ==========
 
[2011.09.19 02:27:22 | 000,000,000 | ---D | M] -- C:\Users\saliha\AppData\Roaming\Ashampoo
[2011.09.21 18:12:46 | 000,000,000 | ---D | M] -- C:\Users\saliha\AppData\Roaming\DVDVideoSoft
[2011.09.21 18:11:20 | 000,000,000 | ---D | M] -- C:\Users\saliha\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.10.19 15:39:54 | 000,000,000 | ---D | M] -- C:\Users\saliha\AppData\Roaming\SoftGrid Client
[2011.09.28 19:44:14 | 000,000,000 | ---D | M] -- C:\Users\saliha\AppData\Roaming\TP
[2011.12.17 15:35:42 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2011.09.19 01:56:20 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2012.01.14 21:52:17 | 000,000,000 | ---D | M] -- C:\1f46ce212972cb18796329d23666adad
[2011.09.19 01:51:38 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.01.24 19:23:44 | 000,000,000 | ---D | M] -- C:\FRST
[2011.01.07 12:25:03 | 000,000,000 | ---D | M] -- C:\Intel
[2011.09.28 19:54:36 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.01.24 21:20:52 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.01.24 21:20:52 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2011.09.19 01:51:38 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.09.19 01:51:38 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.01.25 00:44:47 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.09.19 01:55:55 | 000,000,000 | R--D | M] -- C:\Users
[2012.01.14 21:53:03 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.manifest /3 >
 
 
< MD5 for: EXPLORER.EXE  >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
 
< MD5 for: REGEDIT.EXE  >
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-24 17:40:10
 
<          >

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 25.01.2012 00:41:01 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\saliha\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014,18 Mb Total Physical Memory | 471,31 Mb Available Physical Memory | 46,47% Memory free
1,99 Gb Paging File | 1,26 Gb Available in Paging File | 63,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,78 Gb Total Space | 160,75 Gb Free Space | 83,82% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 26,11 Gb Free Space | 68,71% Space Free | Partition Type: NTFS
Drive E: | 960,72 Mb Total Space | 957,78 Mb Free Space | 99,69% Space Free | Partition Type: FAT
 
Computer Name: SALIHA-PC | User Name: saliha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4
"_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02602409-9189-4567-BC07-562605243B69}" = Windows Live Remote Client Resources
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE
"{101A497C-7EF6-4001-834D-E5FA1C70FEFA}" = Bluetooth Win7 Suite
"{13709A29-963F-4C88-866F-132B12ABA40A}" = AM Usb Card Reader Driver
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros WLAN and Bluetooth Client Installation Program
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN
"{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A65A74A-5B6E-451A-92D8-50F1182BBE9A}" = Windows Live Remote Service Resources
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL
"{5A627DFB-EA4C-4FFA-B711-69E849FB40D8}" = Hotkey
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ACC4CD3-4BE8-4508-9C26-1DCE3EA867C8}" = AmbionWizard
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{81E1EABC-5496-4BC1-8F3F-5914939B28C6}" = Fresco Logic USB3.0 Host Controller
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-006D-0407-0000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR
"{AC76BA86-7AD7-1031-7B44-AA0000000001}" = Adobe Reader X - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw
"{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR
"{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}" = Finger Sensing Pad Driver
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AmUStor" = AM Usb Card Reader Driver
"Ashampoo Burning Studio_is1" = Ashampoo Burning Studio
"Ashampoo Photo Commander_is1" = Ashampoo Photo Commander
"Ashampoo Photo Optimizer_is1" = Ashampoo Photo Optimizer
"Ashampoo Snap_is1" = Ashampoo Snap
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"conduitEngine" = Conduit Engine
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.9.908
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"PriceGong" = PriceGong 2.5.4
"ST6UNST #1" = Instant-On Utilities v1.2
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 24.01.2012 16:19:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:19:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 16:21:16 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:21:16 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 16:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 17:04:08 | Computer Name = saliha-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912,
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850,
 Zeitstempel: 0x4e21132b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00006a12  ID des fehlerhaften
 Prozesses: 0x12dc  Startzeit der fehlerhaften Anwendung: 0x01ccdadb9a4f501c  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des
 fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: f44849d8-46ce-11e1-b287-485d6022d021
 
Error - 24.01.2012 18:44:30 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 177c    Startzeit:
 01ccdae8fa0ae97b    Endzeit: 16    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 ef86b685-46dc-11e1-b287-485d6022d021 
 
Error - 24.01.2012 18:53:58 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 153c    Startzeit:
 01ccdae9f0a209a0    Endzeit: 32    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 30f1b201-46de-11e1-b287-485d6022d021 
 
Error - 24.01.2012 19:48:11 | Computer Name = saliha-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912,
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850,
 Zeitstempel: 0x4e21132b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00006a12  ID des fehlerhaften
 Prozesses: 0x1348  Startzeit der fehlerhaften Anwendung: 0x01ccdaf2a0851182  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des
 fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: df0ce917-46e5-11e1-b287-485d6022d021
 
[ System Events ]
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Client Virtualization Handler" ist vom Dienst "Application
 Virtualization Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet
 wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  AFD  avipbb  BdSpy  cdrom  DfsC  discache  NetBIOS  NetBT  NovaShieldFilterDriver  NovaShieldTDIDriver
nsiproxy
Psched
rdbss
spldr
ssmdrv
tdx
vwififlt
Wanarpv6
WfpLwf
ws2ifsl
 
Error - 24.01.2012 16:07:10 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 24.01.2012 16:09:40 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 24.01.2012 16:21:41 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 24.01.2012 16:24:12 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 24.01.2012 17:29:38 | Computer Name = saliha-PC | Source = DCOM | ID = 10010
Description = OTL Extras logfile created on: 25.01.2012 00:41:01 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\saliha\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014,18 Mb Total Physical Memory | 471,31 Mb Available Physical Memory | 46,47% Memory free
1,99 Gb Paging File | 1,26 Gb Available in Paging File | 63,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,78 Gb Total Space | 160,75 Gb Free Space | 83,82% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 26,11 Gb Free Space | 68,71% Space Free | Partition Type: NTFS
Drive E: | 960,72 Mb Total Space | 957,78 Mb Free Space | 99,69% Space Free | Partition Type: FAT
 
Computer Name: SALIHA-PC | User Name: saliha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4
"_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02602409-9189-4567-BC07-562605243B69}" = Windows Live Remote Client Resources
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE
"{101A497C-7EF6-4001-834D-E5FA1C70FEFA}" = Bluetooth Win7 Suite
"{13709A29-963F-4C88-866F-132B12ABA40A}" = AM Usb Card Reader Driver
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros WLAN and Bluetooth Client Installation Program
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN
"{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A65A74A-5B6E-451A-92D8-50F1182BBE9A}" = Windows Live Remote Service Resources
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL
"{5A627DFB-EA4C-4FFA-B711-69E849FB40D8}" = Hotkey
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ACC4CD3-4BE8-4508-9C26-1DCE3EA867C8}" = AmbionWizard
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{81E1EABC-5496-4BC1-8F3F-5914939B28C6}" = Fresco Logic USB3.0 Host Controller
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-006D-0407-0000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR
"{AC76BA86-7AD7-1031-7B44-AA0000000001}" = Adobe Reader X - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw
"{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR
"{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}" = Finger Sensing Pad Driver
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AmUStor" = AM Usb Card Reader Driver
"Ashampoo Burning Studio_is1" = Ashampoo Burning Studio
"Ashampoo Photo Commander_is1" = Ashampoo Photo Commander
"Ashampoo Photo Optimizer_is1" = Ashampoo Photo Optimizer
"Ashampoo Snap_is1" = Ashampoo Snap
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"conduitEngine" = Conduit Engine
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.9.908
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"PriceGong" = PriceGong 2.5.4
"ST6UNST #1" = Instant-On Utilities v1.2
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 24.01.2012 16:19:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:19:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 16:21:16 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:21:16 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 16:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 17:04:08 | Computer Name = saliha-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912,
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850,
 Zeitstempel: 0x4e21132b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00006a12  ID des fehlerhaften
 Prozesses: 0x12dc  Startzeit der fehlerhaften Anwendung: 0x01ccdadb9a4f501c  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des
 fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: f44849d8-46ce-11e1-b287-485d6022d021
 
Error - 24.01.2012 18:44:30 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 177c    Startzeit:
 01ccdae8fa0ae97b    Endzeit: 16    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 ef86b685-46dc-11e1-b287-485d6022d021 
 
Error - 24.01.2012 18:53:58 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 153c    Startzeit:
 01ccdae9f0a209a0    Endzeit: 32    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 30f1b201-46de-11e1-b287-485d6022d021 
 
Error - 24.01.2012 19:48:11 | Computer Name = saliha-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912,
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850,
 Zeitstempel: 0x4e21132b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00006a12  ID des fehlerhaften
 Prozesses: 0x1348  Startzeit der fehlerhaften Anwendung: 0x01ccdaf2a0851182  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des
 fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: df0ce917-46e5-11e1-b287-485d6022d021
 
[ System Events ]
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Client Virtualization Handler" ist vom Dienst "Application
 Virtualization Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet
 wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  AFD  avipbb  BdSpy  cdrom  DfsC  discache  NetBIOS  NetBT  NovaShieldFilterDriver  NovaShieldTDIDriver
nsiproxy
Psched
rdbss
spldr
ssmdrv
tdx
vwififlt
Wanarpv6
WfpLwf
ws2ifsl
 
Error - 24.01.2012 16:07:10 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 24.01.2012 16:09:40 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 24.01.2012 16:21:41 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 24.01.2012 16:24:12 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 24.01.2012 17:29:38 | Computer Name = saliha-PC | Source = DCOM | ID = 10010
Description =
 
 
< End of report >

--- --- ---



< End of report >

farida 25.01.2012 01:08

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 25.01.2012 00:41:01 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\saliha\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014,18 Mb Total Physical Memory | 471,31 Mb Available Physical Memory | 46,47% Memory free
1,99 Gb Paging File | 1,26 Gb Available in Paging File | 63,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,78 Gb Total Space | 160,75 Gb Free Space | 83,82% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 26,11 Gb Free Space | 68,71% Space Free | Partition Type: NTFS
Drive E: | 960,72 Mb Total Space | 957,78 Mb Free Space | 99,69% Space Free | Partition Type: FAT
 
Computer Name: SALIHA-PC | User Name: saliha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4
"_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02602409-9189-4567-BC07-562605243B69}" = Windows Live Remote Client Resources
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE
"{101A497C-7EF6-4001-834D-E5FA1C70FEFA}" = Bluetooth Win7 Suite
"{13709A29-963F-4C88-866F-132B12ABA40A}" = AM Usb Card Reader Driver
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros WLAN and Bluetooth Client Installation Program
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN
"{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A65A74A-5B6E-451A-92D8-50F1182BBE9A}" = Windows Live Remote Service Resources
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL
"{5A627DFB-EA4C-4FFA-B711-69E849FB40D8}" = Hotkey
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ACC4CD3-4BE8-4508-9C26-1DCE3EA867C8}" = AmbionWizard
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{81E1EABC-5496-4BC1-8F3F-5914939B28C6}" = Fresco Logic USB3.0 Host Controller
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-006D-0407-0000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR
"{AC76BA86-7AD7-1031-7B44-AA0000000001}" = Adobe Reader X - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw
"{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR
"{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}" = Finger Sensing Pad Driver
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AmUStor" = AM Usb Card Reader Driver
"Ashampoo Burning Studio_is1" = Ashampoo Burning Studio
"Ashampoo Photo Commander_is1" = Ashampoo Photo Commander
"Ashampoo Photo Optimizer_is1" = Ashampoo Photo Optimizer
"Ashampoo Snap_is1" = Ashampoo Snap
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"conduitEngine" = Conduit Engine
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.9.908
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"PriceGong" = PriceGong 2.5.4
"ST6UNST #1" = Instant-On Utilities v1.2
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 24.01.2012 16:19:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:19:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 16:21:16 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:21:16 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 16:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description = Die Engine wurde verändert oder zerstört!  Fehlercode: 0xb
 
Error - 24.01.2012 16:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description = Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
 
Error - 24.01.2012 17:04:08 | Computer Name = saliha-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912,
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850,
 Zeitstempel: 0x4e21132b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00006a12  ID des fehlerhaften
 Prozesses: 0x12dc  Startzeit der fehlerhaften Anwendung: 0x01ccdadb9a4f501c  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des
 fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: f44849d8-46ce-11e1-b287-485d6022d021
 
Error - 24.01.2012 18:44:30 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 177c    Startzeit:
 01ccdae8fa0ae97b    Endzeit: 16    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 ef86b685-46dc-11e1-b287-485d6022d021 
 
Error - 24.01.2012 18:53:58 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 153c    Startzeit:
 01ccdae9f0a209a0    Endzeit: 32    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 30f1b201-46de-11e1-b287-485d6022d021 
 
Error - 24.01.2012 19:48:11 | Computer Name = saliha-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912,
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850,
 Zeitstempel: 0x4e21132b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00006a12  ID des fehlerhaften
 Prozesses: 0x1348  Startzeit der fehlerhaften Anwendung: 0x01ccdaf2a0851182  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des
 fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: df0ce917-46e5-11e1-b287-485d6022d021
 
[ System Events ]
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper
 und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst"
 abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Client Virtualization Handler" ist vom Dienst "Application
 Virtualization Client" abhängig, der aufgrund folgenden Fehlers nicht gestartet
 wurde:  %%1068
 
Error - 24.01.2012 15:56:56 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  AFD  avipbb  BdSpy  cdrom  DfsC  discache  NetBIOS  NetBT  NovaShieldFilterDriver  NovaShieldTDIDriver
nsiproxy
Psched
rdbss
spldr
ssmdrv
tdx
vwififlt
Wanarpv6
WfpLwf
ws2ifsl
 
Error - 24.01.2012 16:07:10 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 24.01.2012 16:09:40 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 24.01.2012 16:21:41 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 24.01.2012 16:24:12 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 24.01.2012 17:29:38 | Computer Name = saliha-PC | Source = DCOM | ID = 10010
Description =
 
 
< End of report >

--- --- ---
Tut mir echt leid aber ich habe grade echt viel um die ohren,umzug,arbeit und der computer.Ich hoffe du nimms mir das nicht übel

Larusso 25.01.2012 15:51

Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
Downloade dir bitte Combofix von einem dieser Downloadspiegel

Link 1
Link 2


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.



Bitte poste in deiner nächsten Antwort
Combofix.txt

farida 25.01.2012 19:14

Hallo Daniel,dass sollte ich dir posten:
Combofix Logfile:
Code:

ComboFix 12-01-23.02 - saliha 25.01.2012  18:37:10.1.2 - x86
Microsoft Windows 7 Starter  6.1.7600.0.1252.49.1031.18.1014.291 [GMT 1:00]
ausgeführt von:: c:\users\saliha\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Pegatron\Hotkey\FastUserSwitching.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-25 bis 2012-01-25  ))))))))))))))))))))))))))))))
.
.
2012-01-25 17:56 . 2012-01-25 17:57        --------        d-----w-        c:\users\saliha\AppData\Local\temp
2012-01-25 17:56 . 2012-01-25 17:56        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-24 17:36 . 2012-01-24 18:23        --------        d-----w-        C:\FRST
2012-01-14 21:11 . 2012-01-14 21:11        --------        d-----w-        c:\users\saliha\AppData\Roaming\Malwarebytes
2012-01-14 21:11 . 2012-01-14 21:11        --------        d-----w-        c:\programdata\Malwarebytes
2012-01-13 20:57 . 2012-01-14 20:52        --------        d-----w-        C:\1f46ce212972cb18796329d23666adad
2012-01-12 19:24 . 2012-01-12 19:24        --------        d-----w-        c:\users\saliha\AppData\Local\ElevatedDiagnostics
2012-01-12 19:00 . 2012-01-12 19:00        --------        d-----w-        c:\program files\PriceGong
2012-01-12 17:50 . 2012-01-12 17:50        --------        d-----w-        c:\users\saliha\AppData\Roaming\Avira
2012-01-11 17:15 . 2011-11-17 05:41        1288984        ----a-w-        c:\windows\system32\ntdll.dll
2012-01-11 17:15 . 2011-11-19 14:06        67072        ----a-w-        c:\windows\system32\packager.dll
2012-01-11 17:15 . 2011-10-26 04:28        1328640        ----a-w-        c:\windows\system32\quartz.dll
2012-01-11 17:15 . 2011-10-26 04:28        514560        ----a-w-        c:\windows\system32\qdvd.dll
2011-12-27 18:17 . 2011-12-27 18:17        --------        d-----w-        c:\users\saliha\AppData\Roaming\CyberLink
2011-12-27 18:17 . 2011-12-27 18:17        --------        d-----w-        c:\users\saliha\AppData\Local\CyberLink
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 04:23 . 2011-12-14 16:20        2340352        ----a-w-        c:\windows\system32\win32k.sys
2011-11-05 04:35 . 2011-12-14 16:20        981504        ----a-w-        c:\windows\system32\wininet.dll
2011-11-05 04:34 . 2011-12-14 16:20        44544        ----a-w-        c:\windows\system32\licmgr10.dll
2011-11-05 04:30 . 2011-12-14 16:19        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-11-05 03:28 . 2011-12-14 16:20        386048        ----a-w-        c:\windows\system32\html.iec
2011-11-05 02:55 . 2011-12-14 16:20        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54        175912        ----a-w-        c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2011-01-17 14:54        175912        ----a-w-        c:\program files\DVDVideoSoftTB\prxtbDVDV.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-09-19 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-23 150552]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-10-19 9755240]
"FLxHCIm"="c:\program files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [2010-11-19 33792]
"AtherosBtStack"="c:\program files\Atheros\Bluetooth Suite\BtvStack.exe" [2010-11-25 486560]
"AthBtTray"="c:\program files\Atheros\Bluetooth Suite\AthBtTray.exe" [2010-11-25 302240]
"fspuip"="c:\program files\FSP\fspuip.exe" [2010-09-09 3704320]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-19 136176]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2010-03-01 31232]
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\System32\Drivers\AthDfu.sys [2010-11-25 43680]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-19 136176]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\Atheros\Ath_CoexAgent.exe [2010-05-24 151552]
S2 AtherosSvc;AtherosSvc;c:\program files\Atheros\Bluetooth Suite\adminservice.exe [2010-11-25 56480]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
S3 ACPIService;ATK0100 ACPI SERVICE;c:\windows\system32\DRIVERS\ATKACPI.SYS [2009-06-09 16456]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2010-11-25 34976]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2010-11-25 258720]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2010-11-25 24736]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2010-11-25 175776]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2010-11-25 49312]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2010-11-25 141088]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2010-11-25 239776]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-10-28 27632]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [2010-11-19 174080]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [2010-11-19 38400]
S3 fspad_wlh32;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_wlh32;c:\windows\system32\DRIVERS\fspad_wlh32.sys [2010-09-09 55808]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2010-09-14 577384]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2010-09-14 194408]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2010-09-14 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2010-09-14 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-19 00:51]
.
2012-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-19 00:51]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
IE: Free YouTube to MP3 Converter - c:\users\saliha\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
TCP: DhcpNameServer = 192.168.1.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-BsScanner
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-01-25  19:05:52
ComboFix-quarantined-files.txt  2012-01-25 18:05
.
Vor Suchlauf: 8 Verzeichnis(se), 173.024.759.808 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 173.228.240.896 Bytes frei
.
- - End Of File - - 795B5D0A2FB2CC37AE773A174790AB82

--- --- ---

Larusso 26.01.2012 08:19

Deinstalliere bitte
Conduit Engine
DVDVideoSoftTB Toolbar
PriceGong 2.5.4



Aktualisiere bitte Malwarebytes und lass einen Quick Scan laufen. Entferne alle Funde und poste das Logfile hier.



Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 6 Update 30 ) herunter laden.
  • Wenn die installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Hacken gesetzt ist und klicke OK.
  • Klicke erneut OK.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte poste in deiner nächsten Antwort
MBAM Log
ESET log

farida 26.01.2012 19:24

Hallo Daniel,so das ist vom mbam:
Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.26.05

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
saliha :: SALIHA-PC [Administrator]

Schutz: Deaktiviert

26.01.2012 18:14:16
mbam-log-2012-01-26 (18-14-16).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 307464
Laufzeit: 1 Stunde(n), 3 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Program Files\InstantOnUtilities\InstantOnUtilities.exe (Spyware.Passwords) -> Erfolgreich gelöscht und in Quarantäne gestellt.
D:\TOOLS\Medion FastBoot\Utility\Support\InstantOnUtilities.exe (Spyware.Passwords) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

farida 26.01.2012 20:56

Leider,werde ich es heute nicht mehr schaffen,dir den ESET.log zu schicken.Das machen ich aber morgen,muss jetzt zu Arbeit.:dankeschoen:

farida 27.01.2012 20:14

Hallo Daniel,ich hab den ESET Scan durchlaufen lassen.Er zeigt an,no threats found und ich kann nur auf finish gehen

Larusso 27.01.2012 21:30

Gut so :)


Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 6 Update 30 ) herunter laden.
  • Wenn die installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Hacken gesetzt ist und klicke OK.
  • Klicke erneut OK.



Starte bitte OTL.exe.
Wähle unter
Extra Registrierung: Benutze Safe List und klicke auf den Scan Button.
Poste die OTL.txt und die Extras.txt hier in deinen Thread.


Berichte ob noch irgendwelche Probleme vorhanden sind.



Bitte poste in deiner nächsten Antwort
OTL.txt
Extras.txt

farida 27.01.2012 21:36

Ich hab mir doch die neuste Version von Java herruntergeladen und den scan durchgeführt.Soll ich jetzt,dass mit dem olt machen?

Larusso 27.01.2012 21:40

A sorry, hab ich übersehen. Ja mach mit OTL weiter :)

farida 27.01.2012 22:01

OTL Logfile:
Code:

OTL Extras logfile created on: 27.01.2012 21:48:26 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\saliha\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014,18 Mb Total Physical Memory | 382,31 Mb Available Physical Memory | 37,70% Memory free
1,99 Gb Paging File | 1,10 Gb Available in Paging File | 55,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,78 Gb Total Space | 160,25 Gb Free Space | 83,56% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 26,11 Gb Free Space | 68,71% Space Free | Partition Type: NTFS
 
Computer Name: SALIHA-PC | User Name: saliha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4
"_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02602409-9189-4567-BC07-562605243B69}" = Windows Live Remote Client Resources
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE
"{101A497C-7EF6-4001-834D-E5FA1C70FEFA}" = Bluetooth Win7 Suite
"{13709A29-963F-4C88-866F-132B12ABA40A}" = AM Usb Card Reader Driver
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java(TM) 6 Update 30
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros WLAN and Bluetooth Client Installation Program
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN
"{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A65A74A-5B6E-451A-92D8-50F1182BBE9A}" = Windows Live Remote Service Resources
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL
"{5A627DFB-EA4C-4FFA-B711-69E849FB40D8}" = Hotkey
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ACC4CD3-4BE8-4508-9C26-1DCE3EA867C8}" = AmbionWizard
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{81E1EABC-5496-4BC1-8F3F-5914939B28C6}" = Fresco Logic USB3.0 Host Controller
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-006D-0407-0000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR
"{AC76BA86-7AD7-1031-7B44-AA0000000001}" = Adobe Reader X - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw
"{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR
"{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}" = Finger Sensing Pad Driver
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AmUStor" = AM Usb Card Reader Driver
"Ashampoo Burning Studio_is1" = Ashampoo Burning Studio
"Ashampoo Photo Commander_is1" = Ashampoo Photo Commander
"Ashampoo Photo Optimizer_is1" = Ashampoo Photo Optimizer
"Ashampoo Snap_is1" = Ashampoo Snap
"Avira AntiVir Desktop" = Avira Free Antivirus
"ESET Online Scanner" = ESET Online Scanner v3
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.9.908
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"ST6UNST #1" = Instant-On Utilities v1.2
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 27.01.2012 12:06:12 | Computer Name = saliha-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren
 für Dienst "MSDTC Bridge 4.0.0.0" (MSDTC Bridge 4.0.0.0). Der Fehlercode ist das
 erste DWORD im Datenbereich.
 
Error - 27.01.2012 12:07:17 | Computer Name = saliha-PC | Source = MsiInstaller | ID = 10005
Description =
 
Error - 27.01.2012 12:07:40 | Computer Name = saliha-PC | Source = MsiInstaller | ID = 1023
Description =
 
Error - 27.01.2012 15:23:09 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description =
 
Error - 27.01.2012 15:23:09 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description =
 
Error - 27.01.2012 15:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description =
 
Error - 27.01.2012 15:28:52 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description =
 
Error - 27.01.2012 15:29:26 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4109
Description =
 
Error - 27.01.2012 15:29:26 | Computer Name = saliha-PC | Source = Avira AntiVir | ID = 4117
Description =
 
Error - 27.01.2012 16:48:07 | Computer Name = saliha-PC | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.31.0 kann nicht mehr unter Windows ausgeführt
 werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 1538    Startzeit:
 01ccdd34af92b8e2    Endzeit: 62    Anwendungspfad: C:\Users\saliha\Desktop\OTL.exe    Berichts-ID:
 2dd2f893-4928-11e1-beae-485d6022d021 
 
[ System Events ]
Error - 26.01.2012 14:32:10 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 26.01.2012 14:48:07 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 26.01.2012 14:50:37 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 27.01.2012 11:59:53 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 27.01.2012 12:02:23 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 27.01.2012 12:08:09 | Computer Name = saliha-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework
 4 unter Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server
 2008 x86 (KB2656351)
 
Error - 27.01.2012 15:38:15 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 27.01.2012 15:40:46 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
Error - 27.01.2012 16:14:32 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
  cdrom
 
Error - 27.01.2012 16:17:02 | Computer Name = saliha-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
 
 
< End of report >

--- --- ---
OTL Logfile:
Code:

OTL logfile created on: 27.01.2012 21:48:26 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\saliha\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1014,18 Mb Total Physical Memory | 382,31 Mb Available Physical Memory | 37,70% Memory free
1,99 Gb Paging File | 1,10 Gb Available in Paging File | 55,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,78 Gb Total Space | 160,25 Gb Free Space | 83,56% Space Free | Partition Type: NTFS
Drive D: | 37,99 Gb Total Space | 26,11 Gb Free Space | 68,71% Space Free | Partition Type: NTFS
 
Computer Name: SALIHA-PC | User Name: saliha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.24 23:37:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\saliha\Desktop\OTL.exe
PRC - [2011.12.15 15:00:00 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.12.15 14:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.12.15 14:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.12.15 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.11.05 05:38:00 | 000,673,048 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2011.08.23 21:20:18 | 000,887,976 | ---- | M] (Ask) -- C:\Programme\Ask.com\Updater\Updater.exe
PRC - [2011.07.16 05:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.05.13 15:03:34 | 004,283,256 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Messenger\msnmsgr.exe
PRC - [2011.05.13 13:49:42 | 000,025,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Contacts\wlcomm.exe
PRC - [2011.03.28 19:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011.03.28 19:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011.03.28 10:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft\BingBar\SeaPort.EXE
PRC - [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.25 20:28:50 | 000,486,560 | ---- | M] (Atheros Communications) -- C:\Programme\Atheros\Bluetooth Suite\BtvStack.exe
PRC - [2010.11.25 20:28:44 | 000,302,240 | ---- | M] (Atheros Commnucations) -- C:\Programme\Atheros\Bluetooth Suite\AthBtTray.exe
PRC - [2010.11.25 20:28:42 | 000,056,480 | ---- | M] (Atheros Commnucations) -- C:\Programme\Atheros\Bluetooth Suite\AdminService.exe
PRC - [2010.11.19 16:25:40 | 000,033,792 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Programme\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe
PRC - [2010.10.20 14:23:26 | 000,821,664 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
PRC - [2010.09.14 04:46:26 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010.09.14 04:46:16 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010.09.09 17:45:12 | 003,704,320 | ---- | M] (Sentelic Corporation) -- C:\Programme\FSP\FspUip.exe
PRC - [2010.05.24 15:44:48 | 000,151,552 | ---- | M] (Atheros) -- C:\Programme\Atheros\Ath_CoexAgent.exe
PRC - [2009.07.14 02:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010.09.09 17:44:02 | 000,066,048 | ---- | M] () -- C:\Programme\FSP\FspLib.dll
MOD - [2010.09.09 17:43:54 | 000,044,544 | ---- | M] () -- C:\Programme\FSP\KbdHook.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.12.15 14:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.12.15 14:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.01 10:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.03.28 10:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010.11.25 20:28:42 | 000,056,480 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Programme\Atheros\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010.09.14 04:46:26 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010.09.14 04:46:16 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.05.24 15:44:48 | 000,151,552 | ---- | M] (Atheros) [Auto | Running] -- C:\Programme\Atheros\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.07.24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.12.15 15:00:00 | 000,134,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.12.15 15:00:00 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.12.15 15:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.11.25 20:29:00 | 000,239,776 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btfilter.sys -- (BtFilter)
DRV - [2010.11.25 20:29:00 | 000,141,088 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\btath_rcp.sys -- (BTATH_RCP)
DRV - [2010.11.25 20:28:58 | 000,258,720 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV - [2010.11.25 20:28:58 | 000,175,776 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\btath_hcrp.sys -- (BTATH_HCRP)
DRV - [2010.11.25 20:28:58 | 000,049,312 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV - [2010.11.25 20:28:58 | 000,034,976 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_flt.sys -- (AthBTPort)
DRV - [2010.11.25 20:28:58 | 000,024,736 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\btath_bus.sys -- (BTATH_BUS)
DRV - [2010.11.25 20:28:56 | 000,043,680 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\AthDfu.sys -- (ATHDFU)
DRV - [2010.11.19 16:25:40 | 000,174,080 | ---- | M] (Fresco Logic) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\FLxHCIc.sys -- (FLxHCIc) Fresco Logic xHCI (USB3)
DRV - [2010.11.19 16:25:40 | 000,038,400 | ---- | M] (Fresco Logic) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\FLxHCIh.sys -- (FLxHCIh) Fresco Logic xHCI (USB3)
DRV - [2010.10.28 20:07:44 | 000,027,632 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\clwvd.sys -- (clwvd)
DRV - [2010.09.14 04:46:26 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2010.09.14 04:46:22 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2010.09.14 04:46:18 | 000,194,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2010.09.14 04:46:14 | 000,577,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2010.09.09 17:48:36 | 000,055,808 | ---- | M] (Sentelic Corporation) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\fspad_wlh32.sys -- (fspad_wlh32)
DRV - [2010.07.08 01:02:14 | 001,801,216 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010.06.17 14:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.03.01 15:56:18 | 000,031,232 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AmUStor.sys -- (AmUStor)
DRV - [2009.06.09 20:30:42 | 000,016,456 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\ATKACPI.SYS -- (ACPIService)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
 
 
 
O1 HOSTS File: ([2012.01.25 18:57:25 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Programme\Atheros\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [AthBtTray] C:\Program Files\Atheros\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4 - HKLM..\Run: [AtherosBtStack] C:\Program Files\Atheros\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [FLxHCIm] C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe (Windows (R) Win 7 DDK provider)
O4 - HKLM..\Run: [fspuip] C:\Programme\FSP\FspUip.exe (Sentelic Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\saliha\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programme\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Programme\Atheros\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77DE3EC2-C39E-4E8B-8E11-8AFABC812ACD}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E8CF0311-F9B5-4A3A-BEE9-D8C906E1C2F2}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.27 21:28:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.27 21:28:45 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.01.27 21:28:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.01.27 21:14:10 | 000,000,000 | R--D | C] -- C:\Users\saliha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2012.01.27 21:00:25 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Roaming\Avira
[2012.01.27 20:50:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.01.27 20:49:35 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012.01.27 20:49:31 | 000,134,856 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.01.27 20:49:31 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2012.01.27 20:49:31 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2012.01.27 20:49:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.01.27 20:49:25 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012.01.27 17:02:09 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{605E2FEC-B357-4156-90E1-54F61D6AC329}
[2012.01.27 17:00:02 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{61752167-445E-41E1-9FBA-6F74C3B62F01}
[2012.01.26 20:01:55 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.01.26 19:48:26 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2012.01.26 19:44:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.01.26 19:43:56 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.01.26 19:43:56 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.01.26 19:43:56 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.01.26 19:43:18 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.01.26 19:37:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask
[2012.01.26 18:37:28 | 000,910,112 | ---- | C] (Sun Microsystems, Inc.) -- C:\Users\saliha\Desktop\jxpiinstall.exe
[2012.01.26 18:06:35 | 010,847,608 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\saliha\Desktop\mbam-setup-1.60.0.1800.exe
[2012.01.26 17:56:08 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{ADE22BCE-4A88-4208-92D4-D037782584DC}
[2012.01.26 17:55:53 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{63A52A20-9D18-4B3D-B65B-7DCD5DD03B65}
[2012.01.25 19:06:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.01.25 19:05:56 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.01.25 19:05:56 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\temp
[2012.01.25 18:33:36 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.01.25 18:33:36 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.01.25 18:33:36 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.01.25 18:33:17 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012.01.25 18:33:01 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.01.25 18:30:22 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2012.01.25 18:30:21 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2012.01.25 18:29:39 | 004,388,468 | R--- | C] (Swearware) -- C:\Users\saliha\Desktop\ComboFix.exe
[2012.01.25 18:25:30 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{6A6396BD-0AE3-4F86-A71C-89A53A037576}
[2012.01.25 18:25:14 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{BE5FB36E-5E60-4636-9A4D-16C1698CC7D1}
[2012.01.25 00:47:44 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{289D93A2-AD33-4816-9943-938B4870DA1F}
[2012.01.25 00:47:30 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{35343A62-C925-452D-BFAA-BCB15E080F31}
[2012.01.24 23:37:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\saliha\Desktop\OTL.exe
[2012.01.24 21:21:51 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{42F8AC1F-AE2A-48A5-A912-4B75357736B8}
[2012.01.24 21:07:20 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{18007C3A-5E3C-4619-9983-2473BB053C3B}
[2012.01.24 19:13:55 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{F3A3CC18-9B76-4340-9DFE-0AAF063363B2}
[2012.01.24 18:55:59 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{C024A112-19DF-499E-A1D8-664DF3CFAFB7}
[2012.01.24 18:47:09 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{3CFDBB1F-B6DE-415A-A9DC-7BC69385941D}
[2012.01.24 18:36:37 | 000,000,000 | ---D | C] -- C:\FRST
[2012.01.24 18:33:53 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{EB4B2084-1B22-4190-B560-97F857520599}
[2012.01.23 00:23:23 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{CB4F5197-4E8A-492A-AF32-817E4E11F8FD}
[2012.01.14 22:11:45 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Roaming\Malwarebytes
[2012.01.14 22:11:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.01.14 22:04:51 | 000,000,000 | ---D | C] -- C:\Users\saliha\Documents\antibotcd0112_chip[1]
[2012.01.14 21:54:43 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A755919E-1172-4683-8572-6CFDAC9588EB}
[2012.01.14 21:54:30 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{F27399F7-2B82-4377-89A9-A9CF6A39C5D3}
[2012.01.13 21:57:16 | 000,000,000 | ---D | C] -- C:\1f46ce212972cb18796329d23666adad
[2012.01.13 18:42:35 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{D507EAA4-93E1-4B99-9B79-6E1821D7C26C}
[2012.01.13 18:42:24 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{04E23234-F08B-4205-8705-8C9FA4812F2C}
[2012.01.12 20:24:38 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\ElevatedDiagnostics
[2012.01.12 18:07:41 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{73D0459D-B613-4205-9565-F0FD453405F2}
[2012.01.12 18:07:28 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{0E35760C-C11F-4C9B-9E5E-4062494B85CA}
[2012.01.11 18:15:31 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012.01.11 18:15:29 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012.01.11 18:15:28 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012.01.11 18:08:49 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{989BC29A-656C-4761-8420-532B82E3D3CF}
[2012.01.09 18:08:05 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{1D531BC1-DC24-4750-92A2-9E0745D4F484}
[2012.01.09 17:15:02 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{B8C0C2F3-7F81-4B9C-A4A1-0417128EF064}
[2012.01.08 13:25:12 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{9C682E12-26BD-44B5-97ED-37A5D42C8997}
[2012.01.08 13:24:48 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{3C4E2D2B-DDB2-4CDF-8891-9B2AFAD762C5}
[2012.01.08 12:22:05 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{6B21F5F9-5526-434A-869F-1A446F275A96}
[2012.01.07 18:53:19 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{0BF5B351-D057-435A-843B-8D7ED79DDE0D}
[2012.01.07 18:52:44 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{750667E9-9FC5-4112-9FC2-166FB146923F}
[2011.12.31 21:32:11 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A60C007F-B9D8-4834-81A7-5F4991AB101B}
[2011.12.30 21:33:40 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{323FF4D1-2CB0-435A-A06E-3EF15C72936F}
[2011.12.30 21:33:27 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A5DF7854-B697-4892-8683-1A75E695E855}
[2011.12.30 15:05:24 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{A1AA8B62-847B-49BD-9C1D-368AC7D0125E}
[2011.12.30 14:58:56 | 000,000,000 | ---D | C] -- C:\Users\saliha\AppData\Local\{64A7E85E-3C74-4A69-932C-50B2A299E04D}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.27 21:28:52 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.27 21:24:17 | 010,847,608 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\saliha\Desktop\mbam-setup-1.60.0.1800.exe
[2012.01.27 21:22:11 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.27 21:22:11 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.27 21:14:05 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.27 21:13:58 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2012.01.27 21:13:50 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.27 21:13:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.27 21:13:34 | 797,581,312 | -HS- | M] () -- C:\hiberfil.sys
[2012.01.27 20:50:01 | 000,002,020 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.01.27 20:47:57 | 087,262,320 | ---- | M] () -- C:\Users\saliha\Desktop\avira_free_antivirus1200872_de.exe
[2012.01.26 19:43:23 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2012.01.26 19:43:23 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012.01.26 19:43:23 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012.01.26 19:43:23 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012.01.26 19:26:17 | 000,910,112 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\saliha\Desktop\jxpiinstall.exe
[2012.01.25 18:57:25 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012.01.25 18:29:52 | 004,388,468 | R--- | M] (Swearware) -- C:\Users\saliha\Desktop\ComboFix.exe
[2012.01.25 18:24:46 | 000,000,004 | ---- | M] () -- C:\ProgramData\RELED.INI
[2012.01.24 23:37:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\saliha\Desktop\OTL.exe
[2012.01.24 18:36:44 | 001,169,458 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.24 18:36:44 | 000,769,750 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.24 18:36:44 | 000,293,080 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.24 18:36:44 | 000,253,152 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.12.30 15:07:43 | 000,002,310 | ---- | M] () -- C:\Users\saliha\Documents\Mein Film.wlmp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.27 21:28:52 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.27 20:50:01 | 000,002,020 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.01.27 20:47:44 | 087,262,320 | ---- | C] () -- C:\Users\saliha\Desktop\avira_free_antivirus1200872_de.exe
[2012.01.25 18:33:36 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.01.25 18:33:36 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.01.25 18:33:36 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.01.25 18:33:36 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.01.25 18:33:36 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.12.30 15:07:43 | 000,002,310 | ---- | C] () -- C:\Users\saliha\Documents\Mein Film.wlmp
[2011.01.07 13:24:31 | 000,000,004 | ---- | C] () -- C:\ProgramData\RELED.INI
[2011.01.07 13:16:26 | 000,246,804 | ---- | C] () -- C:\Windows\System32\AtherosBT.bin
[2011.01.07 13:13:01 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2010.12.17 08:45:41 | 000,016,456 | ---- | C] () -- C:\Windows\System32\drivers\ATKACPI.SYS
[2010.12.09 08:02:08 | 000,030,720 | --S- | C] () -- C:\Windows\System32\Install-Ambion.exe
[2010.11.25 20:20:54 | 000,246,804 | ---- | C] () -- C:\Windows\System32\drivers\AtherosBt.bin
[2009.07.14 09:47:43 | 001,169,458 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 09:47:43 | 000,293,080 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,269,184 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,769,750 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,253,152 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat

< End of report >

--- --- ---

Der Computer reagiert manchmal nicht;wie zb beim scanen.Aber sonst ist er wie immer.

Larusso 28.01.2012 01:16

Code:

/md5start
ATKACPI.sys
/md5stop

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Nichts und danach den Scan Button.
  • Wenn der Scan beendet wurde, wird sich ein Textdokument öffnen.
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread

farida 28.01.2012 17:10

Hallo Daniel,ich hab die Otl.exe,als Adminstrator gestartet.Als ich,den Inhalt kopiren wollt kam die Meldung:Fehler auf dieser Seite.Ich hab es ein paar mal neu gestartet,aber immer die gleiche Meldung.Kann den Scan somit nicht durchführen.:schrei:

Larusso 29.01.2012 19:59

Scan mit SystemLook

Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop.

Download Mirror #1 - Download Mirror #2
  • Doppelklick auf die SystemLook.exe, um das Tool zu starten.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:

    :filefind
    ATKACPI.sys

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Wenn der Suchlauf beendet ist, wird sich Dein Editor mit den Ergebnissen öffnen, diese hier in den Thread posten.
  • Die Ergebnisse werden auf dem Desktop als SystemLook.txt gespeichert.

farida 30.01.2012 18:42

Ok,auch hier das gleiche Spiel.Wenn ich den Text,kopieren will heisst es Fehler auf der Seite.Das Netbook, ist sehr sehr langsam geworden und reagiert manchmal gar nicht,zb.wenn ich ein fenster schließen will.:confused:

Larusso 30.01.2012 21:17

Wie kopierst du den Text ?

farida 31.01.2012 20:59

Wie ich kopiere???So wie ich es immer gemacht habe,steht doch oben:alles kopieren.Und es hat immer funktioniert.Ansonsten,makiere ich das und dann kopieren.Es hat immer funktioniert aber leider jetzt nicht mehr.Warum????Und die meldung lautet Fehler auf der Seite.

farida 31.01.2012 21:06

Also,ich hab es nochmal versucht,und komisch komisch es hat funktioniert.So langsam,wird der pc mir unheimlich und sehr nervig!
SystemLook 30.07.11 by jpshortstuff
Log created at 21:01 on 31/01/2012 by saliha
Administrator - Elevation successful

========== filefind ==========

Searching for "ATKACPI.sys"
C:\Windows\System32\drivers\ATKACPI.SYS --a---- 16456 bytes [07:45 17/12/2010] [19:30 09/06/2009] C1C7EEF1A53A6B47323187A22559E553
C:\Windows\System32\DriverStore\FileRepository\osdacpi.inf_x86_neutral_e34d5f17c470a245\ATKACPI.SYS --a---- 16456 bytes [07:45 17/12/2010] [19:30 09/06/2009] C1C7EEF1A53A6B47323187A22559E553

Searching for " "
No files found.

-= EOF =-

Larusso 31.01.2012 21:09

Wenn du nicht immer so seltsam schreiben würdest, wo das Problem liegt, könnte ich dir wahrscheinlich helfen. Aber meine Glaskugel ist leider kaputt.

Liste mir alle Probleme auf, so das man sie auch versteht. Mit "er ist langsam" kann ich nichts anfangen. Was ist langsam, Startvorgang,.....

Je detailierter, desto besser.

farida 31.01.2012 21:22

Autsch,dass war nicht nett.Würdes du,mir schreiben das ich es detalierter beschreiben soll,hätte ich es sehr gerne getan!Wenn ich ein Program,starten will tut DER PC dies sehr langsam.Wenn ich ein Fenster,schließen möcht funktiniert das erst beim mehrmaligen versuch.Und wenn ich zb.ein Scan durchführen will,muss ich bis zu 5-6 auf Start klicken bis der Scan beginnt.Nochmalerweise steht dann da,dass der scan läuft diese Meldung fehlt auch.Ich hoffe,dass war detaliert genug.Sag mal bin ich den Trojaner jetzt endgültig los?Das würde mich intressieren???

Larusso 31.01.2012 21:57

War nicht böse gemeint, bin einfach nur etwas gestresst gerade.

Problem ist, ich sehe in den Logfiles nichts und ich weiß, dass srep eigentlich nichts löscht. Hab ich ja selber geschrieben :D

Sehen wir mal mit anderen Tools nach.



Downloade dir bitte dds ( von sUBs ) von einem der folgenden Downloadspiegel und speichere die Datei auf deinem Desktop.

dds.com
dds.scr
  • Schließe alle laufenden Programme.
  • Starte DDS mit Doppelklick.
  • Es wird 2 Logfiles erstellen.
    • dds.txt
    • attach.txt
  • Speichere beide Logfiles auf deinem Desktop
  • Poste beide Logfiles hier.



Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen.

Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und speichere das Logfile.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern ( Meistens C:\ )
    Als Beispiel: C:\TDSSKiller.<version_date_time>log.txt
Poste den Inhalt bitte hier in deinen Thread.



Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe
    Vista und Win7 User mit Rechtsklick "als Admininstartor starten"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. ( Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.



Bitte poste in deiner nächsten Antwort
dds.txt
attach.txt
TDSSKiller Log
aswMBR.txt

farida 01.02.2012 00:58

Ok,gestresst sein davon kann ich momentan ein Lied singen!
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514
Run by saliha at 0:29:00 on 2012-02-01
Microsoft Windows 7 Starter 6.1.7601.1.1252.49.1031.18.1014.341 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Atheros\Ath_CoexAgent.exe
C:\Program Files\Atheros\Bluetooth Suite\adminservice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Atheros\Bluetooth Suite\BtvStack.exe
C:\Program Files\Atheros\Bluetooth Suite\AthBtTray.exe
C:\Program Files\FSP\FspUip.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: CIESpeechBHO Class: {8d10f6c4-0e01-4bd4-8601-11ac1fdf8126} - c:\program files\atheros\bluetooth suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [FLxHCIm] "c:\program files\fresco logic inc\fresco logic usb3.0 host controller\host\FLxHCIm.exe"
mRun: [AtherosBtStack] "c:\program files\atheros\bluetooth suite\BtvStack.exe"
mRun: [AthBtTray] "c:\program files\atheros\bluetooth suite\AthBtTray.exe"
mRun: [fspuip] %ProgramFiles%\FSP\fspuip.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Free YouTube to MP3 Converter - c:\users\saliha\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - c:\program files\atheros\bluetooth suite\IEPlugIn.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{77DE3EC2-C39E-4E8B-8E11-8AFABC812ACD} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E8CF0311-F9B5-4A3A-BEE9-D8C906E1C2F2} : DhcpNameServer = 192.168.1.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-1-27 36000]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AntiVirSchedulerService;Avira Planer;c:\program files\avira\antivir desktop\sched.exe [2012-1-27 86224]
R2 AntiVirService;Avira Echtzeit Scanner;c:\program files\avira\antivir desktop\avguard.exe [2012-1-27 110032]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\atheros\Ath_CoexAgent.exe [2011-1-7 151552]
R2 AtherosSvc;AtherosSvc;c:\program files\atheros\bluetooth suite\AdminService.exe [2010-11-25 56480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-1-27 74640]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-10-20 821664]
R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2010-9-14 508264]
R3 ACPIService;ATK0100 ACPI SERVICE;c:\windows\system32\drivers\ATKACPI.SYS [2010-12-17 16456]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\drivers\btath_flt.sys [2010-11-25 34976]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2010-11-25 258720]
R3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\drivers\btath_bus.sys [2010-11-25 24736]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\drivers\btath_hcrp.sys [2010-11-25 175776]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\drivers\btath_lwflt.sys [2010-11-25 49312]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\drivers\btath_rcp.sys [2010-11-25 141088]
R3 BtFilter;BtFilter;c:\windows\system32\drivers\btfilter.sys [2010-11-25 239776]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\drivers\clwvd.sys [2010-10-28 27632]
R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\drivers\FLxHCIc.sys [2010-11-19 174080]
R3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\drivers\FLxHCIh.sys [2010-11-19 38400]
R3 fspad_wlh32;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_wlh32;c:\windows\system32\drivers\fspad_wlh32.sys [2010-12-17 55808]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-1-7 275048]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-9-14 577384]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-9-14 194408]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-9-14 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-9-14 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2010-9-14 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-19 136176]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.sys [2011-1-7 31232]
S3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\drivers\AthDfu.sys [2010-11-25 43680]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-4-1 183560]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-19 136176]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-9-26 52224]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-01-31 19:47:49 -------- d-----w- c:\users\saliha\appdata\local\{C1A7471D-4FE0-404A-8421-D59F7A166666}
2012-01-31 19:47:11 -------- d-----w- c:\users\saliha\appdata\local\{ED722A3F-8E6D-49A2-A03E-A431F088780E}
2012-01-30 17:28:47 -------- d-----w- c:\users\saliha\appdata\local\{336B0369-3EBE-41F6-9C0B-F3F2D63FCA50}
2012-01-30 17:28:31 -------- d-----w- c:\users\saliha\appdata\local\{70789DAF-490E-4A24-B5EF-F0D3B025DA29}
2012-01-28 21:53:37 -------- d-----w- c:\windows\system32\SPReview
2012-01-28 21:51:45 -------- d-----w- c:\windows\system32\EventProviders
2012-01-28 15:52:52 -------- d-----w- c:\users\saliha\appdata\local\{5BBE0F3E-FA08-486F-928E-07141326205B}
2012-01-28 15:52:28 -------- d-----w- c:\users\saliha\appdata\local\{8B123531-3AB8-420E-87E3-8D11C19AEB54}
2012-01-27 20:00:25 -------- d-----w- c:\users\saliha\appdata\roaming\Avira
2012-01-27 19:49:31 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-01-27 19:49:31 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-01-27 19:49:26 -------- d-----w- c:\programdata\Avira
2012-01-27 19:49:25 -------- d-----w- c:\program files\Avira
2012-01-27 16:02:09 -------- d-----w- c:\users\saliha\appdata\local\{605E2FEC-B357-4156-90E1-54F61D6AC329}
2012-01-27 16:00:02 -------- d-----w- c:\users\saliha\appdata\local\{61752167-445E-41E1-9FBA-6F74C3B62F01}
2012-01-26 18:48:26 -------- d-----w- c:\program files\Ask.com
2012-01-26 18:37:38 -------- d-----w- c:\programdata\Ask
2012-01-26 16:56:08 -------- d-----w- c:\users\saliha\appdata\local\{ADE22BCE-4A88-4208-92D4-D037782584DC}
2012-01-26 16:55:53 -------- d-----w- c:\users\saliha\appdata\local\{63A52A20-9D18-4B3D-B65B-7DCD5DD03B65}
2012-01-25 18:06:03 -------- d-sh--w- C:\$RECYCLE.BIN
2012-01-25 18:05:56 -------- d-----w- c:\users\saliha\appdata\local\temp
2012-01-25 17:33:36 98816 ----a-w- c:\windows\sed.exe
2012-01-25 17:33:36 518144 ----a-w- c:\windows\SWREG.exe
2012-01-25 17:33:36 256000 ----a-w- c:\windows\PEV.exe
2012-01-25 17:33:36 208896 ----a-w- c:\windows\MBR.exe
2012-01-25 17:30:24 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-25 17:30:24 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-25 17:30:23 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-25 17:30:23 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-25 17:30:22 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-25 17:30:22 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-25 17:30:22 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-25 17:30:22 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-25 17:30:22 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-25 17:30:22 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-25 17:25:30 -------- d-----w- c:\users\saliha\appdata\local\{6A6396BD-0AE3-4F86-A71C-89A53A037576}
2012-01-25 17:25:14 -------- d-----w- c:\users\saliha\appdata\local\{BE5FB36E-5E60-4636-9A4D-16C1698CC7D1}
2012-01-24 23:47:44 -------- d-----w- c:\users\saliha\appdata\local\{289D93A2-AD33-4816-9943-938B4870DA1F}
2012-01-24 23:47:30 -------- d-----w- c:\users\saliha\appdata\local\{35343A62-C925-452D-BFAA-BCB15E080F31}
2012-01-24 20:21:51 -------- d-----w- c:\users\saliha\appdata\local\{42F8AC1F-AE2A-48A5-A912-4B75357736B8}
2012-01-24 20:07:20 -------- d-----w- c:\users\saliha\appdata\local\{18007C3A-5E3C-4619-9983-2473BB053C3B}
2012-01-24 18:13:55 -------- d-----w- c:\users\saliha\appdata\local\{F3A3CC18-9B76-4340-9DFE-0AAF063363B2}
2012-01-24 17:55:59 -------- d-----w- c:\users\saliha\appdata\local\{C024A112-19DF-499E-A1D8-664DF3CFAFB7}
2012-01-24 17:47:09 -------- d-----w- c:\users\saliha\appdata\local\{3CFDBB1F-B6DE-415A-A9DC-7BC69385941D}
2012-01-24 17:36:37 -------- d-----w- C:\FRST
2012-01-24 17:33:53 -------- d-----w- c:\users\saliha\appdata\local\{EB4B2084-1B22-4190-B560-97F857520599}
2012-01-22 23:23:23 -------- d-----w- c:\users\saliha\appdata\local\{CB4F5197-4E8A-492A-AF32-817E4E11F8FD}
2012-01-14 21:11:45 -------- d-----w- c:\users\saliha\appdata\roaming\Malwarebytes
2012-01-14 21:11:38 -------- d-----w- c:\programdata\Malwarebytes
2012-01-14 20:54:43 -------- d-----w- c:\users\saliha\appdata\local\{A755919E-1172-4683-8572-6CFDAC9588EB}
2012-01-14 20:54:30 -------- d-----w- c:\users\saliha\appdata\local\{F27399F7-2B82-4377-89A9-A9CF6A39C5D3}
2012-01-13 20:57:16 -------- d-----w- C:\1f46ce212972cb18796329d23666adad
2012-01-13 17:42:35 -------- d-----w- c:\users\saliha\appdata\local\{D507EAA4-93E1-4B99-9B79-6E1821D7C26C}
2012-01-13 17:42:24 -------- d-----w- c:\users\saliha\appdata\local\{04E23234-F08B-4205-8705-8C9FA4812F2C}
2012-01-12 19:24:38 -------- d-----w- c:\users\saliha\appdata\local\ElevatedDiagnostics
2012-01-12 17:07:41 -------- d-----w- c:\users\saliha\appdata\local\{73D0459D-B613-4205-9565-F0FD453405F2}
2012-01-12 17:07:28 -------- d-----w- c:\users\saliha\appdata\local\{0E35760C-C11F-4C9B-9E5E-4062494B85CA}
2012-01-11 17:15:34 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 17:15:31 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 17:15:29 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 17:15:28 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 17:08:49 -------- d-----w- c:\users\saliha\appdata\local\{989BC29A-656C-4761-8420-532B82E3D3CF}
2012-01-09 17:08:05 -------- d-----w- c:\users\saliha\appdata\local\{1D531BC1-DC24-4750-92A2-9E0745D4F484}
2012-01-09 16:15:02 -------- d-----w- c:\users\saliha\appdata\local\{B8C0C2F3-7F81-4B9C-A4A1-0417128EF064}
2012-01-08 12:25:12 -------- d-----w- c:\users\saliha\appdata\local\{9C682E12-26BD-44B5-97ED-37A5D42C8997}
2012-01-08 12:24:48 -------- d-----w- c:\users\saliha\appdata\local\{3C4E2D2B-DDB2-4CDF-8891-9B2AFAD762C5}
2012-01-08 11:22:05 -------- d-----w- c:\users\saliha\appdata\local\{6B21F5F9-5526-434A-869F-1A446F275A96}
2012-01-07 17:53:19 -------- d-----w- c:\users\saliha\appdata\local\{0BF5B351-D057-435A-843B-8D7ED79DDE0D}
2012-01-07 17:52:44 -------- d-----w- c:\users\saliha\appdata\local\{750667E9-9FC5-4112-9FC2-166FB146923F}
.
==================== Find3M ====================
.
2012-01-28 22:45:56 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-01-26 18:43:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-24 04:25:27 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 04:35:00 981504 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 04:26:03 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 02:48:51 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 0:29:46,62 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Starter
Boot Device: \Device\HarddiskVolume1
Install Date: 19.09.2011 02:55:42
System Uptime: 01.02.2012 00:07:08 (0 hours ago)
.
Motherboard: Medion | | E122X
Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz | CPU 1 | 1667/167mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 192 GiB total, 168,731 GiB free.
D: is FIXED (NTFS) - 38 GiB total, 3,48 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP42: 28.01.2012 22:53:15 - Windows 7 Service Pack 1
RP43: 30.01.2012 18:28:58 - Windows-Sicherung
RP44: 31.01.2012 20:51:46 - Windows Update
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X - Deutsch
AM Usb Card Reader Driver
AmbionWizard
Ashampoo Burning Studio
Ashampoo Photo Commander
Ashampoo Photo Optimizer
Ashampoo Snap
Ask Toolbar
Ask Toolbar Updater
Atheros WLAN and Bluetooth Client Installation Program
Avira Free Antivirus
Bing Bar
Bluetooth Win7 Suite
CorelDRAW Essentials 4
CorelDRAW Essentials 4 - Content
CorelDRAW Essentials 4 - Draw
CorelDRAW Essentials 4 - Filters
CorelDRAW Essentials 4 - ICA
CorelDRAW Essentials 4 - IPM - No VBA
CorelDRAW Essentials 4 - Lang BR
CorelDRAW Essentials 4 - Lang DE
CorelDRAW Essentials 4 - Lang EN
CorelDRAW Essentials 4 - Lang ES
CorelDRAW Essentials 4 - Lang FR
CorelDRAW Essentials 4 - Lang IT
CorelDRAW Essentials 4 - Lang NL
CorelDRAW Essentials 4 - PHOTO-PAINT
CorelDRAW Essentials 4 - Windows Shell Extension
CyberLink PowerDVD 10
CyberLink YouCam
CyberLink YouPaint
D3DX10
Finger Sensing Pad Driver
Fresco Logic USB3.0 Host Controller
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Hotkey
Instant-On Utilities v1.2
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 30
Junk Mail filter update
Medion Home Cinema
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Office Klick-und-Los 2010
Microsoft Office Starter 2010 - Deutsch
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSVCRT
PlayReady PC Runtime x86
Realtek Ethernet Controller Driver For Windows 7
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX control for remote connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Encoder 9 Series
.
==== End Of File ===========================
aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-02-01 00:43:00
-----------------------------
00:43:00.389 OS Version: Windows 6.1.7601 Service Pack 1
00:43:00.389 Number of processors: 2 586 0x1C0A
00:43:00.389 ComputerName: SALIHA-PC UserName: saliha
00:43:01.278 Initialize success
00:44:55.580 AVAST engine defs: 12013100
00:46:34.484 The log file has been saved successfully to "C:\Users\saliha\Desktop\aswMBR.txt"

Zu TDSSkiller.exe kam die Meldung:no threats found.

Sag mal,kann ich die ganzen Programe und Logfiles wieder löschen,oder brauche ich die noch?Bitte beantworte mir die Fragen denn das tust du nie FRAGEN BEANTWORTEN:pfui:

Larusso 01.02.2012 17:16

Wenn mans genau nimmt. müsste ich hier garnichts tun.
Die Logfiles kommen jetzt weg. Ich seh da keine laufende Malware mehr, eventuell können dir die Leute im Windowsbereich helfen.



Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.

Windows-Taste + R drücke. Kopiere nun folgende Zeile in die Kommandozeile und klicke OK.
Code:

Combofix /Uninstall
http://larusso.trojaner-board.de/Images/CFuninstall.jpg

Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch aus dieser die Schädlinge verschwinden.

Nun die eben deaktivierten Programme wieder aktivieren.



Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.



Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.


Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

farida 02.02.2012 01:22

Hallo Daniel,ich habe,alles löschen können.Ich habe auch deine Tipps befolgt,und die Programe instaliert.Vielen lieben Dank für deine Hilfe!!!Ohne deine Hilfe,hätte ich es niemals geschaft.:dankeschoen: IHR SEIT ECHT EIN SUPER TEAM.:taenzer: Ich wünsche dir alles gute und wenig STRESS!:dankeschoen::applaus::daumenhoc mfg

Larusso 04.02.2012 05:02

Froh das wir helfen konnten :abklatsch:

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:59 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131