Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Bundestrojaner sperrt Win7 (https://www.trojaner-board.de/117927-bundestrojaner-sperrt-win7.html)

greggy 25.06.2012 09:35

Bundestrojaner sperrt Win7
 
Hallo,

also ich habe mir einen Bundestrojaner eingefangen der beim Hochfahren von Win7 den Rechner sperrt.
Kann mir jemand helfen das Ding wieder los zu werden?
Die OTL Disk hätte ich nach lesen der anderen Beiträge schon mal erstellt. Aber was jetz? Einfach den Scan laufen lassen und die Log posten?
Vielen Dank schon mal.

Chris4You 25.06.2012 10:56

Hi,

ja (und beten das nichts verschlüsselt wurde ;o)...

chris

greggy 25.06.2012 11:25

Hi,

Also beten tue ich jetzt schon seit einigen Stunden ;-)
Unten also jetzt der die Log Datei. Ich hoffe das passt so.

OTL Logfile:
Code:

OTL logfile created on: 6/25/2012 5:15:54 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
Windows 7 Professional  (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 125.00 Gb Total Space | 84.65 Gb Free Space | 67.72% Space Free | Partition Type: NTFS
Drive F: | 107.88 Gb Total Space | 14.16 Gb Free Space | 13.13% Space Free | Partition Type: NTFS
Drive X: | 3.73 Gb Total Space | 2.83 Gb Free Space | 75.94% Space Free | Partition Type: FAT
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto] --  -- (z525bus)
SRV - File not found [Auto] --  -- (yats32)
SRV - File not found [Auto] --  -- (WmXlCore)
SRV - File not found [Auto] --  -- (WimFltr)
SRV - File not found [Auto] --  -- (wcontrol)
SRV - File not found [Auto] --  -- (vzupsvc)
SRV - File not found [Auto] --  -- (USBVCD)
SRV - File not found [Auto] --  -- (usbbus)
SRV - File not found [Auto] --  -- (tvichw32)
SRV - File not found [Auto] --  -- (TUWinStylerThemeSvc)
SRV - File not found [Auto] --  -- (transbaseservice)
SRV - File not found [Auto] --  -- (TPM)
SRV - File not found [Auto] --  -- (tosrfec)
SRV - File not found [Auto] --  -- (tbiosdrv)
SRV - File not found [Auto] --  -- (symmpi)
SRV - File not found [Auto] --  -- (swupdtmr)
SRV - File not found [Auto] --  -- (steamdvr)
SRV - File not found [Auto] --  -- (spcstb)
SRV - File not found [Auto] --  -- (SNPSTD3)
SRV - File not found [Auto] --  -- (Slpsvdr)
SRV - File not found [Auto] --  -- (SiRemFil)
SRV - File not found [Auto] --  -- (sgeclient)
SRV - File not found [Auto] --  -- (ser2pl)
SRV - File not found [Auto] --  -- (sbhooksvc)
SRV - File not found [Auto] --  -- (rkhdrv31)
SRV - File not found [Auto] --  -- (RecAgent)
SRV - File not found [Auto] --  -- (radiosvr)
SRV - File not found [Auto] --  -- (pshost)
SRV - File not found [Auto] --  -- (pelmouse)
SRV - File not found [Auto] --  -- (pdlncbas)
SRV - File not found [Auto] --  -- (ovepstatusengine)
SRV - File not found [Auto] --  -- (NWSIPX32)
SRV - File not found [Auto] --  -- (nv4)
SRV - File not found [Auto] --  -- (ntservice1)
SRV - File not found [Auto] --  -- (nsm1mdm)
SRV - File not found [Auto] --  -- (npfmntor)
SRV - File not found [Auto] --  -- (nmsaccess)
SRV - File not found [Auto] --  -- (nalntservice)
SRV - File not found [Auto] --  -- (mxssvr)
SRV - File not found [Auto] --  -- (mr7910)
SRV - File not found [Auto] --  -- (lyncusbserv)
SRV - File not found [Auto] --  -- (lvckap)
SRV - File not found [Auto] --  -- (ltmodem5)
SRV - File not found [Auto] --  -- (konfig)
SRV - File not found [Auto] --  -- (issvc)
SRV - File not found [Auto] --  -- (issm)
SRV - File not found [Auto] --  -- (ipinip)
SRV - File not found [Auto] --  -- (ipahelper.exe)
SRV - File not found [Auto] --  -- (ICAM3NT5)
SRV - File not found [Auto] --  -- (iap)
SRV - File not found [Auto] --  -- (i2omgmt)
SRV - File not found [Auto] --  -- (hpn)
SRV - File not found [Auto] --  -- (eSettingsService)
SRV - File not found [Auto] --  -- (enxpsvr)
SRV - File not found [Auto] --  -- (enxpsvc)
SRV - File not found [Auto] --  -- (digirefresh)
SRV - File not found [Auto] --  -- (digictrl)
SRV - File not found [Auto] --  -- (dbustrcm)
SRV - File not found [Auto] --  -- (cqmghost)
SRV - File not found [Auto] --  -- (com0com)
SRV - File not found [Auto] --  -- (clisvc)
SRV - File not found [Auto] --  -- (Cam5603D)
SRV - File not found [Auto] --  -- (cachemanxp)
SRV - File not found [Auto] --  -- (btnhnd)
SRV - File not found [Auto] --  -- (bcoreusb)
SRV - File not found [Auto] --  -- (BCMTPM)
SRV - File not found [Auto] --  -- (basfipm)
SRV - File not found [Auto] --  -- (avidsdmservice)
SRV - File not found [Auto] --  -- (aliadwdm)
SRV - File not found [Auto] --  -- (AffinegyService)
SRV - File not found [Auto] --  -- (aexnsclient)
SRV - File not found [Auto] --  -- (adpu160m)
SRV - File not found [Auto] --  -- (AcronisOSSReinstallSvc)
SRV - [2012/05/21 19:24:57 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/01/04 08:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/11/17 17:12:44 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe -- (Sony SCSI Helper Service)
SRV - [2011/11/15 11:06:00 | 000,132,672 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2011/10/06 08:18:48 | 000,148,520 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/10/06 08:15:46 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield)
SRV - [2011/09/29 10:44:32 | 002,498,560 | ---- | M] () [Auto] -- C:\Program Files\McAfee\EEGo\EegoService.exe -- (McAfee EEGo)
SRV - [2011/09/12 16:16:54 | 000,488,824 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe -- (enterceptAgent)
SRV - [2011/09/12 16:16:54 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2011/06/06 07:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/17 21:48:10 | 000,290,472 | ---- | M] (Aventail Corporation) [Auto] -- C:\Windows\System32\ngvpnmgr.exe -- (NgVpnMgr)
SRV - [2011/01/12 15:46:36 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2010/12/13 08:37:46 | 000,135,536 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2010/11/29 05:23:16 | 000,019,456 | ---- | M] (Tyco Electronics Corporation) [Auto] -- C:\Program Files\TECnim\TECnim_service.exe -- (TECnim)
SRV - [2010/10/28 06:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010/06/09 11:38:30 | 000,463,912 | R--- | M] (Ericsson AB) [Auto] -- C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe -- (WMCoreService)
SRV - [2010/03/24 19:32:16 | 000,009,216 | ---- | M] (Vodafone) [Auto] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2010/03/23 18:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/23 18:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/01/10 06:01:26 | 000,060,928 | ---- | M] () [Auto] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService)
SRV - [2010/01/08 09:55:16 | 000,628,000 | ---- | M] (Broadcom Corporation.) [Auto] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/17 21:00:00 | 000,764,768 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2009/09/17 21:00:00 | 000,246,624 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\CCM\TSManager.exe -- (smstsmgr)
SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2006/06/18 08:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand] --  -- (FirehkMP)
DRV - File not found [Kernel | On_Demand] --  -- (Firehk)
DRV - [2011/11/01 05:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 05:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 05:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 05:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/10/06 18:37:36 | 000,039,336 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\FireNfcp.sys -- (FireNfcp)
DRV - [2011/10/06 08:18:54 | 000,165,416 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/10/06 08:18:02 | 000,087,392 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/10/06 08:17:32 | 000,463,912 | ---- | M] (McAfee, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/10/06 08:16:58 | 000,059,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/10/06 08:16:48 | 000,180,328 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/10/06 08:16:28 | 000,120,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/09/12 16:16:54 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/09/12 16:16:54 | 000,145,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2011/09/12 16:16:54 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/05/17 21:11:52 | 000,081,480 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngvpn.sys -- (NgVpn)
DRV - [2011/05/17 21:11:52 | 000,027,208 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nglog.sys -- (NgLog)
DRV - [2011/05/17 21:11:52 | 000,025,160 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngwfp.sys -- (NgWfp)
DRV - [2011/05/17 21:11:52 | 000,023,112 | ---- | M] (Aventail Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ngfilter.sys -- (NgFilter)
DRV - [2010/07/14 06:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010/06/21 15:59:30 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/05/25 10:03:14 | 000,229,928 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WwanUsbMp.sys -- (WwanUsbServ)
DRV - [2010/04/27 04:02:48 | 000,405,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3Mdm.sys -- (Mbm3Mdm)
DRV - [2010/04/27 04:02:48 | 000,388,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3DevMt.sys -- (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM)
DRV - [2010/04/27 04:02:48 | 000,329,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3CBus.sys -- (Mbm3CBus) Dell Wireless HSPA Mini-Card Device (WDM)
DRV - [2010/04/27 04:02:48 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Mbm3mdfl.sys -- (Mbm3mdfl)
DRV - [2010/03/11 03:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2010/03/11 03:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2010/03/03 05:30:26 | 000,026,152 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanussf.sys -- (ecnssndisfltr)
DRV - [2010/03/03 05:30:24 | 000,023,592 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wwanuss.sys -- (ecnssndis)
DRV - [2010/03/01 12:35:24 | 000,061,952 | ---- | M] (Vodafone) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum)
DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/03 13:36:36 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/01/25 14:18:08 | 000,082,984 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554gps.sys -- (d554gps)
DRV - [2010/01/25 14:17:20 | 000,047,744 | ---- | M] (Ericsson AB) [Kernel | On_Demand] -- C:\Windows\System32\drivers\d554scard.sys -- (d554scard)
DRV - [2010/01/18 01:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/01/18 01:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- C:\Windows\System32\drivers\stdfltn.sys -- (stdflt)
DRV - [2009/12/10 09:36:54 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R)
DRV - [2009/11/03 11:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/09/17 21:00:00 | 000,020,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\CCM\PrepDrv.sys -- (prepdrvr)
DRV - [2009/07/13 21:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 21:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 21:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) Gigaset ISDN (Call It)
DRV - [2009/07/13 19:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 19:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/05/28 11:39:44 | 000,021,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID)
DRV - [2008/08/26 04:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/06/04 08:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV)
DRV - [2007/01/24 10:27:54 | 000,039,704 | ---- | M] (Belcarra Technologies) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rcblan.sys -- (RemoteControl-USBLAN)
DRV - [2004/06/26 07:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto] -- C:\Windows\System32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004/06/26 07:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vncdrv.sys -- (vncdrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://mywikis.tycoelectronics.com/cm/wiki/?id=10294
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy
 
IE - HKU\EG005689_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://mywikis.tycoelectronics.com/cm/wiki/?id=10294
IE - HKU\EG005689_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\EG005689_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy
 
IE - HKU\EG011222_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\EG011222_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://myte.tycoelectronics.com/portal/server.pt?PageID=0&parentname=Login&parentid=1&CommunityID=256&space=CommunityPage&control=SetCommunity&cached=false&in_hi_userid=104876
IE - HKU\EG011222_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\EG011222_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://proxy.tycoelectronics.com/auto.proxy
 
 
 
IE - HKU\SMSAccess_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2011/04/08 05:57:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/29 18:13:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/02/06 06:14:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/06 06:14:37 | 000,000,000 | ---D | M]
 
[2011/07/21 08:09:28 | 000,032,040 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
 
Hosts file not found
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120103195851.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\EG011222_ON_C\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKU\EG011222_ON_C\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [dcmsvc] C:\Program Files\dcmsvc\dcmsvc.exe ()
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.)
O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O4 - HKLM..\Run: [Tyco_BGinfo] C:\Program Files\bginfo\Bginfo.exe (Sysinternals)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
O4 - HKU\EG011222_ON_C..\Run: []  File not found
O4 - HKU\EG011222_ON_C..\Run: [7Rxb5FismTZydeX]  File not found
O4 - HKU\EG011222_ON_C..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKU\EG011222_ON_C..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O4 - HKU\EG011222_ON_C..\Run: [X1FileMonitor.exe] C:\Program Files\X1\X1FileMonitor.exe ()
O4 - HKU\LocalService_ON_C..\Run: [Sidebar]  File not found
O4 - HKU\NetworkService_ON_C..\Run: [Sidebar]  File not found
O4 - HKU\SMSAccess_ON_C..\Run: [Sidebar]  File not found
O4 - HKU\EG005689_ON_C..\RunOnce: [SetupRevertTELogo] C:\Apps\TECApps\SetupRevertTELogo.exe ()
O4 - HKU\EG011222_ON_C..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe (Adobe Systems Incorporated)
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\SMSAccess_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPhoneExplorer.lnk ()
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Office Keyboard.exe ()
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warner Bros.lnk ()
O4 - Startup: C:\Users\EG011222\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\X1 System Tray.lnk ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DefaultLogonDomain = TycoElectronics
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\EG005689_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\EG005689_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\EG011222_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\SMSAccess_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000044 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000045 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000046 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000047 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000048 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000049 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000050 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000051 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000052 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000053 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000054 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000055 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000056 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000057 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000058 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000059 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000060 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000061 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000062 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000063 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000064 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000065 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000066 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000067 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000068 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000069 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000070 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000071 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000072 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000073 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000074 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000075 -  File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = de.tycoelectronics.com
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP, Walldorf)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKU\EG011222_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ecojink: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll -  File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1dab4fdb-6116-11e0-839c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1dab4fdb-6116-11e0-839c-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/06/25 04:47:38 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\NPE
[2012/06/24 20:26:57 | 000,000,000 | ---D | C] -- C:\NPE
[2012/06/24 20:26:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2012/06/24 19:06:19 | 000,000,000 | ---D | C] -- C:\NBRT
[2012/06/22 13:11:24 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/06/22 09:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\egvixvcletcqitf
[2012/06/21 20:03:26 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\Mozilla
[2012/06/21 09:06:42 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1F484A5F-3B4F-4B28-BEDF-E27115B582F5}
[2012/06/21 09:06:20 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{40128DC9-A673-4F4C-8993-82A501B5C9B4}
[2012/06/20 05:15:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{89FBBE95-9710-4104-9ED3-B337ACFE728A}
[2012/06/20 05:15:30 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{0B6D5AC8-7D22-4FF4-900B-F7898B4A3976}
[2012/06/20 02:24:00 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B94F1FFE-CFB8-4DA4-890B-9C97863D79FF}
[2012/06/20 02:19:03 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{D829BDE5-7A5F-4874-8835-D1398A74577B}
[2012/06/20 02:15:08 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{81659A2B-17B2-4F6F-AA2A-3E02A62BD734}
[2012/06/19 04:26:11 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B6C49E82-062F-496A-8ECC-5E5C606CACCE}
[2012/06/19 04:25:54 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{39CF9DA7-9F42-44FB-920C-E117251DEB5B}
[2012/06/19 02:54:39 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\.salesforce.com
[2012/06/19 02:54:37 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Roaming\salesforce.com
[2012/06/19 02:54:37 | 000,000,000 | ---D | C] -- C:\ProgramData\salesforce.com
[2012/06/19 02:52:24 | 000,000,000 | ---D | C] -- C:\Program Files\salesforce.com
[2012/06/18 05:12:43 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{72C8C4AE-44DC-4533-ACE5-D06A04A2379C}
[2012/06/17 06:42:52 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1D2A4A4E-B3D2-4AA9-9F87-C92511618ADC}
[2012/06/14 04:54:30 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{43F24588-D02C-4408-A6A5-0061ECDE2FF5}
[2012/06/14 04:20:48 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{041B35CC-6060-4C69-B7AA-6EC9C05854FD}
[2012/06/13 08:31:55 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{9458F21D-65AB-43BB-BC37-A91E4F54704C}
[2012/06/13 08:31:35 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{3F0F1BF6-A91B-4498-8373-0F9C7A548612}
[2012/06/13 08:07:55 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{10EA408A-F370-4D9D-B534-EE878AE683DB}
[2012/06/11 15:07:48 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{468BB37E-322C-4546-8DB5-CADF6FE816E8}
[2012/06/10 13:48:45 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{5781FDF2-A01C-4504-870B-A570E9CC24CB}
[2012/06/07 17:04:06 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{4193B25C-65F4-4451-B1C3-A220E23DEF27}
[2012/06/05 14:42:27 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{BD37A6E8-51C3-4B7F-8F51-CBEAE17D439F}
[2012/06/05 14:42:06 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{8250949A-A41A-49E6-BC2A-27589F896F6B}
[2012/06/03 09:21:33 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{157D3603-8789-452C-81AE-295C1176437E}
[2012/06/03 09:21:10 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{7A901744-F987-46E4-9864-F644E5E55C65}
[2012/06/02 14:50:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{AE5993DB-7119-4200-BEBD-5ACA400074F9}
[2012/06/01 05:15:21 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B729E639-C1AE-4261-915A-2933B3FD62DA}
[2012/06/01 04:50:44 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{02628924-0716-41F2-94ED-D12EA2B0C627}
[2012/05/30 03:41:56 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{DEA7767A-0FD8-4056-9A81-4DE6A151096F}
[2012/05/30 03:41:42 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{B0478902-55DB-499B-B4DB-91E865B52374}
[2012/05/29 16:13:09 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{344BF6F8-DD81-48DE-B707-F97D6739A941}
[2012/05/29 02:30:58 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{C1839AB4-0F1D-4673-9F34-33D8C929F41B}
[2012/05/29 02:27:35 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{28645085-0D13-4ACB-BFD6-B968E004D3CD}
[2012/05/28 18:49:22 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{C50E0260-1456-4DB3-8725-AA147D68F1F1}
[2012/05/28 18:11:54 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{62026264-D041-4062-9BAA-B5CA7EFA13A0}
[2012/05/28 17:53:50 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{755B7984-437E-43E7-9AA3-D7718774A4CE}
[2012/05/28 17:06:32 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{F8627BBB-A9C5-44DC-9B01-B0481E84C516}
[2012/05/28 17:03:09 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{1DB5DBC7-D1DA-41F4-A35A-24458644E564}
[2012/05/28 14:13:37 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\{A110C5EC-813F-4B66-A94B-E338D5C42F4B}
[2011/04/07 09:22:49 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2010/07/28 08:27:20 | 000,105,984 | ---- | C] (Tyco Electronics Corporation) -- C:\Program Files\TECmdv_3.0.4.exe
[2007/08/13 11:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\EG011222\AppData\Local\CDRip.dll
[2007/01/18 15:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\EG011222\AppData\Local\No23 Recorder.exe
[2006/12/11 13:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\EG011222\AppData\Local\basscd.dll
[2006/12/11 13:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\EG011222\AppData\Local\bass.dll
[1 C:\Users\EG011222\AppData\Roaming\*.tmp files -> C:\Users\EG011222\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/06/25 10:09:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/25 10:09:30 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 10:09:30 | 000,014,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 10:08:59 | 000,000,462 | ---- | M] () -- C:\Windows\SMSCFG.ini
[2012/06/25 10:08:18 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/25 10:06:18 | 2760,241,152 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/25 09:48:35 | 000,649,374 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/06/25 09:48:35 | 000,128,156 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/06/25 09:48:35 | 000,007,188 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/25 09:48:35 | 000,004,936 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/25 09:45:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003UA.job
[2012/06/25 06:44:13 | 000,000,298 | ---- | M] () -- C:\ProgramData\SMRResults300.dat
[2012/06/25 04:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/24 10:45:08 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_trash_log.cmd
[2012/06/24 07:53:50 | 000,003,600 | ---- | M] () -- C:\bootsqm.dat
[2012/06/24 06:14:19 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/24 00:45:00 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-725345543-78003Core.job
[2012/06/22 09:44:25 | 000,000,052 | ---- | M] () -- C:\ProgramData\kwztyvvcmhovudt
[2012/06/22 09:44:19 | 000,061,440 | ---- | M] () -- C:\ProgramData\tddanntg.exe
[2012/06/22 09:44:19 | 000,061,440 | ---- | M] () -- C:\ProgramData\ohpfgkae.exe
[2012/06/21 09:25:58 | 000,013,068 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/06/20 07:33:35 | 000,061,666 | ---- | M] () -- C:\Users\EG011222\Desktop\TGV Buchungsbestätigung.pdf
[2012/06/20 07:26:14 | 000,106,366 | ---- | M] () -- C:\Users\EG011222\Desktop\LE_MANS_GARE-CHARLES_DE_GAULLE_2_TGV_20-06-12.pdf
[2012/06/20 02:22:13 | 000,002,486 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012/06/19 02:41:58 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/06/19 02:41:47 | 000,023,745 | ---- | M] () -- C:\Users\EG011222\AppData\Roaming\Microsoft Excel.ADR
[2012/06/17 06:50:56 | 000,021,504 | ---- | M] () -- C:\Windows\jestertb.dll
[1 C:\Users\EG011222\AppData\Roaming\*.tmp files -> C:\Users\EG011222\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/06/25 06:44:13 | 000,000,298 | ---- | C] () -- C:\ProgramData\SMRResults300.dat
[2012/06/24 07:53:50 | 000,003,600 | ---- | C] () -- C:\bootsqm.dat
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\tddanntg.exe
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\ohpfgkae.exe
[2012/06/22 09:44:20 | 000,000,052 | ---- | C] () -- C:\ProgramData\kwztyvvcmhovudt
[2012/06/20 07:33:34 | 000,061,666 | ---- | C] () -- C:\Users\EG011222\Desktop\TGV Buchungsbestätigung.pdf
[2012/06/20 07:26:14 | 000,106,366 | ---- | C] () -- C:\Users\EG011222\Desktop\LE_MANS_GARE-CHARLES_DE_GAULLE_2_TGV_20-06-12.pdf
[2012/06/17 06:50:56 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll
[2012/04/09 04:47:24 | 000,001,497 | ---- | C] () -- C:\Users\EG011222\AppData\Local\RecConfig.xml
[2012/03/15 05:30:20 | 000,005,624 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\BAcroIEHelpe087.dll
[2012/03/14 05:38:45 | 000,005,624 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\BAcroIEHelpe086.dll
[2012/03/13 09:02:59 | 000,003,584 | ---- | C] () -- C:\Users\EG011222\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/18 08:31:25 | 000,007,667 | ---- | C] () -- C:\Users\EG011222\AppData\Local\Resmon.ResmonCfg
[2011/11/07 18:38:45 | 000,000,008 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\pij8405e9rx3klvv.dat
[2011/09/29 18:08:35 | 000,262,624 | ---- | C] () -- C:\Windows\hpwins23.dat.temp
[2011/09/05 09:32:47 | 000,023,745 | ---- | C] () -- C:\Users\EG011222\AppData\Roaming\Microsoft Excel.ADR
[2011/05/17 21:51:12 | 000,127,144 | ---- | C] () -- C:\Windows\ngmsi.dll
[2011/05/17 21:50:04 | 000,015,016 | ---- | C] () -- C:\Windows\ngutil.exe
[2011/04/30 23:08:13 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp
[2011/04/30 11:59:06 | 000,262,715 | ---- | C] () -- C:\Windows\hpwins23.dat
[2011/04/30 11:59:06 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat
[2011/04/28 01:45:27 | 000,091,154 | ---- | C] () -- C:\Windows\System32\CcmFramework.ini
[2011/04/28 00:49:54 | 000,000,074 | ---- | C] () -- C:\Windows\System32\settings.bin
[2011/04/15 02:26:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011/04/08 07:02:44 | 001,064,960 | ---- | C] () -- C:\Windows\System32\h5krnl32.dll
[2011/04/08 07:02:44 | 000,188,928 | ---- | C] () -- C:\Windows\System32\h5icon32.dll
[2011/04/08 07:02:44 | 000,175,616 | ---- | C] () -- C:\Windows\System32\h5menu32.dll
[2011/04/08 07:02:44 | 000,095,744 | ---- | C] () -- C:\Windows\System32\h5rtf32.dll
[2011/04/08 07:02:44 | 000,051,200 | ---- | C] () -- C:\Windows\System32\h5tool32.dll
[2011/04/08 05:41:39 | 000,000,462 | ---- | C] () -- C:\Windows\SMSCFG.ini
[2011/04/08 05:06:59 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/04/08 01:07:21 | 000,065,784 | ---- | C] () -- C:\Windows\SAPLOGON.INI
[2011/04/08 01:07:21 | 000,002,555 | ---- | C] () -- C:\Windows\sapmsg.ini
[2011/04/07 09:23:23 | 000,012,288 | ---- | C] () -- C:\Windows\EvtMessage.dll
[2011/04/07 09:22:50 | 000,870,560 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2011/04/07 09:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2011/04/07 09:22:50 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2011/04/07 09:22:49 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2011/04/07 09:22:48 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2011/04/07 09:22:48 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2011/04/07 09:16:02 | 000,308,624 | ---- | C] () -- C:\Windows\System32\brcmbsp.dll
[2011/04/07 09:16:02 | 000,206,216 | ---- | C] () -- C:\Windows\System32\bipbsp.dll
[2011/04/07 09:14:59 | 000,080,368 | ---- | C] () -- C:\Windows\System32\pbadrvdll.dll
[2011/04/07 09:05:22 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2011/04/07 08:59:46 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2011/04/07 08:59:19 | 000,013,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/03/15 13:15:34 | 000,156,430 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009/07/14 04:50:01 | 000,649,374 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009/07/14 04:50:01 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009/07/14 04:50:01 | 000,128,156 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009/07/14 04:50:01 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,476,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:48 | 000,007,188 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,004,936 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/09 09:47:02 | 000,013,824 | ---- | C] () -- C:\Windows\System32\CallSimReader.dll
[2009/04/09 09:46:02 | 000,055,808 | ---- | C] () -- C:\Windows\System32\SimReader.dll
[2007/08/13 11:46:00 | 000,155,136 | ---- | C] () -- C:\Users\EG011222\AppData\Local\lame_enc.dll
[2006/10/25 19:06:48 | 000,064,000 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbisenc.dll
[2006/10/25 19:06:48 | 000,019,456 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbisfile.dll
[2006/10/25 19:06:46 | 000,143,872 | ---- | C] () -- C:\Users\EG011222\AppData\Local\vorbis.dll
[2006/10/25 19:06:36 | 000,015,872 | ---- | C] () -- C:\Users\EG011222\AppData\Local\ogg.dll
[2006/06/30 06:58:44 | 000,176,128 | ---- | C] () -- C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 06:58:44 | 000,126,976 | ---- | C] () -- C:\Windows\System32\bioapi100.dll
[2005/08/23 16:34:06 | 000,029,184 | ---- | C] () -- C:\Users\EG011222\AppData\Local\no23xwrapper.dll
[2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
 
========== LOP Check ==========
 
[2011/04/07 09:37:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ICAClient
[2011/04/08 04:54:30 | 000,000,000 | ---D | M] -- C:\Users\EG005689\AppData\Roaming\ICAClient
[2011/04/15 06:15:03 | 000,000,000 | ---D | M] -- C:\Users\EG005689\AppData\Roaming\Vodafone
[2012/06/20 09:38:19 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\.oit
[2012/06/19 02:54:39 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\.salesforce.com
[2011/12/22 16:29:23 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\1&1 Mail & Media GmbH
[2012/01/20 09:11:39 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Aventail
[2012/04/09 06:52:49 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1
[2012/04/20 15:34:22 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\DVDVideoSoft
[2011/12/23 16:59:09 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/06/07 09:25:44 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Foxit
[2011/06/07 09:25:45 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Foxit Software
[2011/04/08 05:41:08 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\ICAClient
[2012/05/24 12:24:37 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\inkscape
[2012/05/02 12:03:23 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Itsth
[2012/03/05 03:32:05 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\kock
[2011/04/29 05:03:34 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Leadertech
[2012/05/28 14:31:53 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\MyPhoneExplorer
[2012/02/06 06:15:40 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia
[2011/05/31 19:05:49 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia Ovi Suite
[2012/02/06 06:17:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Nokia Suite
[2011/05/31 19:05:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\PC Suite
[2012/03/11 11:31:48 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\RavensburgerTipToi
[2012/06/19 02:54:37 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\salesforce.com
[2011/04/28 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\SAP
[2012/03/13 16:17:14 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\UAs
[2011/04/08 06:05:00 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Vodafone
[2011/04/28 15:50:10 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Vodafone Mobile Connect
[2012/03/13 16:17:57 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\xmldm
[2012/05/22 13:49:52 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\XnView
[2011/12/23 16:54:22 | 000,000,000 | ---D | M] -- C:\Users\EG011222\AppData\Roaming\Youtube Downloader HD
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/06/15 09:11:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Applications
[2012/01/20 09:23:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Aventail
[2011/04/07 09:15:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Broadcom
[2011/04/07 09:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\Citrix
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2012/06/22 09:44:24 | 000,000,000 | ---D | M] -- C:\ProgramData\egvixvcletcqitf
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/02/06 06:14:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia
[2011/05/31 18:52:40 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaAccount
[2012/03/13 03:12:26 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache
[2011/05/31 19:03:09 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2012/03/11 11:32:00 | 000,000,000 | ---D | M] -- C:\ProgramData\RavensburgerTipToi
[2012/06/19 02:54:37 | 000,000,000 | ---D | M] -- C:\ProgramData\salesforce.com
[2011/04/08 01:07:21 | 000,000,000 | ---D | M] -- C:\ProgramData\SAP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2012/05/02 12:51:41 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/04/08 05:45:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2011/12/22 16:29:24 | 000,000,000 | ---D | M] -- C:\ProgramData\UUdb
[2011/04/28 15:49:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone
[2011/04/07 08:59:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2012/05/17 14:50:32 | 000,000,000 | ---D | M] -- C:\ProgramData\Windows
[2011/04/08 01:33:33 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip
[2011/04/08 05:32:03 | 000,000,000 | ---D | M] -- C:\ProgramData\X1 Updater
[2012/05/07 04:12:47 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9FF7C773
< End of report >

--- --- ---

[/CODE]

Chris4You 25.06.2012 12:47

Hi,

Script auf USB-Stick kopieren, von OTL-Disk booten, rüberkopieren und wie folgt verfahren:

By teh way: Du hast die Enterpriseedition (McAfee) im Einsatz, ist das ein Firmenrechner (auch die Cloudlösung spricht dafür)... Dann muß sich eigentlich der Sysadmin darum kümmern...

Fix für OTL:
  • Doppelklick auf die OTL.exe, um das Programm auszuführen.
  • Vista/Win7-User bitte per Rechtsklick und "Ausführen als Administrator" starten.
  • Kopiere den Inhalt der folgenden Codebox komplett in die OTL-Box unter "Custom Scan/Fixes"
http://oldtimer.geekstogo.com/OTL/OTL_Main_Tutorial.gif
Code:


:OTL
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O4 - HKU\EG011222_ON_C..\Run: []  File not found
O4 - HKU\EG011222_ON_C..\Run: [7Rxb5FismTZydeX]  File not found
O4 - HKU\EG011222_ON_C..\Run: [tddanntgfyjjyof] C:\ProgramData\tddanntg.exe ()
O20 - Winlogon\Notify\ecojink: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll -  File not found
[2012/06/25 04:47:38 | 000,000,000 | ---D | C] -- C:\Users\EG011222\AppData\Local\NPE
[2012/06/22 09:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\egvixvcletcqitf
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\tddanntg.exe
[2012/06/22 09:44:25 | 000,061,440 | ---- | C] () -- C:\ProgramData\ohpfgkae.exe
[2012/06/22 09:44:20 | 000,000,052 | ---- | C] () -- C:\ProgramData\kwztyvvcmhovudt
[2012/06/17 06:50:56 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll
[2012/06/22 09:44:24 | 000,000,000 | ---D | M] -- C:\ProgramData\egvixvcletcqitf
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:9FF7C773

:Commands
[emptytemp]
[resethosts]
[createrestorepoint]
[Reboot]

  • Den roten Run Fixes! Button anklicken.
  • Bitte alles aus dem Ergebnisfenster (Results) herauskopieren.
  • Eine Kopie eines OTL-Fix-Logs wird in einer Textdatei in folgendem Ordner gespeichert:
  • %systemroot%\_OTL

Der Rechner sollte jetzt wieder booten...

Malwarebytes Antimalware (MAM)
Anleitung&Download hier: http://www.trojaner-board.de/51187-m...i-malware.html
Falls der Download nicht klappt, bitte hierüber eine generische Version runterladen:
http://filepony.de/download-chameleon/
Danach bitte update der Signaturdateien (Reiter "Aktualisierungen" -> Suche nach Aktualisierungen")
Fullscan und alles bereinigen lassen! Log posten.

chris

greggy 25.06.2012 13:27

Hi,

also erst mal vielen Dank für die Hilfe. Ich kann zumindest mal wieder hochfahren.
Das mit dem Firmenrechner ist nicht ganz richtig. Das ist ein ehemaliger Rechner meiner Firma. Den hab ich so wie er jetzt ist gekauft.
Das es da eine Cloudlösung gibt ist mir noch nicht einmal bekannt ;-)

Ist das nur allgemein oder soll ich auch das LOG von Malwarebytes posten?

greggy

Chris4You 25.06.2012 16:52

Hi,

bitte beide Logs posten... (OTL, MAM)...

chris


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131