UNSOLVED

Airseb

updated

16 years ago

A

Airseb

12 Posts

0

3102

August 24th, 2010 13:00

Firefox Popups and windows update error 80072EFE

Hi,

I have a similar problem as another user of this forum regarding poping up new tabs with random webpages in firefox and windows update error 80072EFE. Before I ran several anti malware programs i also had this online norton antivirus message.
I appreciate any help, and thanks in advance!


Here is the Hijack log

 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:03:25, on 24.08.2010
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
E:\Programme\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\PixArt\PAC7311\Monitor.exe
E:\Programme\Bamboo Dock\BambooCore.exe
E:\Programme\DAEMON Tools Lite\DTLite.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\S. Manna\Downloads\HiJackThis204(2).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Programme\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Programme\Java\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Programme\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [avgnt] "E:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "E:\Programme\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [PAC7311_Monitor] C:\Windows\PixArt\PAC7311\Monitor.exe
O4 - HKLM\..\Run: [BambooCore] e:\Programme\Bamboo Dock\BambooCore.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Programme\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe -update plugin
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\S. Manna\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/xhtml+xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: application/xhtml+xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: AGI Data Update Service for STK 9 (AgDataUpdateSvc9) - Analytical Graphics, Inc. - E:\Programme\AGI\STK 9\bin\AgDataUpdateSvc9.exe
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - E:\Programme\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Programme\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - E:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe

--
End of file - 9468 bytes

  • Bugbatter

    4 Apprentice

    20487 Posts

    596

    0

    Posted September 4th, 2010 06:00

    Welcome. Thank you for using Dell Community Forums.

    I am reviewing your log. In the meantime, you can help me by addressing the following:

    * Have you have posted this issue on another forum? If so, please provide a link to the topic.

    * If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.

    * If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE.

    * If you are using any P2P (file sharing) programs, please remove them before we clean your computer.  The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE.    

    * Some CD Emulators use a hidden driver which can be seen as a rootkit, and can also interfere with a correct read of the state of the machine by our tools.

    Please uninstall the following software before  performing any of the pre-posting scans. It can be re-installed once your helper has determined the cleaning process is complete.
    The following should be uninstalled via the Control Panel:
    Daemon Tools and Daemon Tools Lite
    Alcohol 120% and 52%
    AstroBurn
    StarBurn

    For a complete uninstall, and so our tools may run unhindered, please also follow the steps on DuplexSecure's page for uninstalling the SPTD driver which these emulators use.
    http://www.duplexsecure.com/en/faq
    Scroll down to:
    Quote:
    Q: How can I remove SPTD driver on 32-bit OS?


    Follow the instructions.
    Quote:
    Q: How can I remove SPTD driver on 32-bit OS?

    A: To remove SPTD, simply download SPTD setup file "SPTDinst-v162-x86.exe" for Windows 2000/XP/2003/Vista (32-bit) [911,856 bytes] and execute it.
    In dialog that appears press "Uninstall" button and then SPTD will remove itself from your Windows installation.

    * If this computer belongs to someone else, do you have authority to apply the fixes we will use?

    * After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.

    * During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.

    * We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

    I look forward to your reply so we can begin cleaning.

    No Reply within 3 days will result in this topic being closed, and I will remove it from my subscriptions. If you require more time, please let me know.

    Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.

     

  • Airseb

    12 Posts

    596

    0

    Posted September 5th, 2010 16:00

    Hi Ive done everything you did write above except the system restore function. Except my optical drive there are no HD appearing in the window for selecting the drive for the stored windows state. Furthermore there are no drives (except optical) listed in the Drive Administration (I dont know the respective englisch name for german "Datenträgerverwaltung" - its the window where you create and modify partitions in windows 7)

    However, Im ready to go, and thanks in advance.

     

  • Bugbatter

    4 Apprentice

    20487 Posts

    596

    0

    Posted September 5th, 2010 17:00


    We need to see some additional information about what is happening in your machine.

    • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explanation about the tool.
    • Click Yes at the prompt for Optional Scan.
    • When done, DDS will open two (2) logs

    1. DDS.txt
    2. Attach.txt

    • Save both reports to your desktop.
    • Copy/paste both logs to your reply on the forum. Do not attach them.
    • Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.

  • Bugbatter

    4 Apprentice

    20487 Posts

    596

    0

    Posted September 5th, 2010 18:00

    I see that you have Malwarebytes' Anti-Malware installed. Please update, run a scan and post the log.

    • If you encounter any problems while downloading the updates,

    manually download them from here
    and just double-click on mbam-rules.exe to install.
    Alternatively, you can update through MBAM's interface from a clean computer,
    copy the definitions (rules.ref) located in
    C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
    Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.

    On the Scanner tab:

    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top.
    It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully.
    Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:

    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report along with a fresh HijackThis log into your next reply and exit MBAM.

    Note:-- If MBAM encounters a file that is difficult to remove,
    you may be asked to reboot your computer so it can proceed with the disinfection process.
    Regardless if prompted to restart the computer or not, please do so immediately.
    Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

    -- MBAM may make changes to your registry as part of its disinfection routine.
    If you're using other security programs that detect registry changes (like Spybot's Teatimer),
    they may interfere with the fix or alert you after scanning with MBAM.
    Please disable such programs until disinfection is complete or permit them to allow the changes.

     

    **If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from HERE

  • Airseb

    12 Posts

    596

    0

    Posted September 5th, 2010 18:00


    DDS (Ver_10-03-17.01) - NTFSx86 
    Run by S. Manna at  2:04:15,15 on 06.09.2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows 7 Professional   6.1.7600.0.1252.49.1031.18.2038.1048 [GMT 2:00]


    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    E:\Programme\Avira\AntiVir Desktop\avguard.exe
    E:\Programme\Avira\AntiVir Desktop\avshadow.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\LEXBCES.EXE
    C:\Windows\System32\LEXPPS.EXE
    E:\Programme\Avira\AntiVir Desktop\sched.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\aestsrv.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\FsUsbExService.Exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\PSIService.exe
    C:\Windows\system32\STacSV.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\Pen_Tablet.exe
    C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
    E:\Programme\Avira\AntiVir Desktop\avgnt.exe
    C:\Windows\PixArt\PAC7311\Monitor.exe
    E:\Programme\Bamboo Dock\BambooCore.exe
    C:\Windows\system32\WTablet\Pen_TabletUser.exe
    C:\Program Files\Cursor Attention\CursorAttention.exe
    C:\Windows\system32\Pen_Tablet.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Windows\System32\spoolsv.exe
    E:\Programme\Nero\Nero 7\Nero Toolkit\DriveSpeed.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    c:\program files\windows defender\MpCmdRun.exe
    C:\Users\S. Manna\Downloads\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\mobsync.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uInternet Settings,ProxyOverride = *.local
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
    BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\programme\java\bin\jp2ssv.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
    EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
    mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
    mRun: [avgnt] "e:\programme\avira\antivir desktop\avgnt.exe" /min
    mRun: [PAC7311_Monitor] c:\windows\pixart\pac7311\Monitor.exe
    mRun: [BambooCore] e:\programme\bamboo dock\BambooCore.exe
    mRun: [NPSStartup]
    StartupFolder: c:\users\s6fa1~1.man\appdata\roaming\micros~1\windows\startm~1\programs\startup\cursor~1.lnk - c:\program files\cursor attention\CursorAttention.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: An vorhandene PDF-Datei anfügen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: Free YouTube to Mp3 Converter - c:\users\s. manna\appdata\roaming\dvdvideosoftiehelpers\youtubetomp3.htm
    IE: In Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
    IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Linkziel in Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    Filter: application/xhtml+xml - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Filter: application/xhtml+xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Filter: application/xhtml+xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\s6fa1~1.man\appdata\roaming\mozilla\firefox\profiles\g2dqhpym.default\
    FF - prefs.js: browser.search.selectedEngine - Wikipedia (de)
    FF - prefs.js: browser.startup.homepage - www.google.de
    FF - component: e:\programme\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
    FF - plugin: c:\windows\system32\wat\npWatWeb.dll
    FF - plugin: e:\programme\itunes\mozilla plugins\npitunes.dll
    FF - plugin: e:\programme\java\bin\new_plugin\npdeployJava1.dll
    FF - plugin: e:\programme\java\bin\new_plugin\npjp2.dll
    FF - HiddenExtension: Java Console: No Registry Reference - e:\programme\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    e:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    e:\programme\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency",   1600);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.proxy.type",                  5);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
    e:\programme\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
    e:\programme\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    e:\programme\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    e:\programme\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug",            false);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight",       2);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize",       1);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight",   25);
    e:\programme\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight",     5);
    e:\programme\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    e:\programme\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    e:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    e:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    e:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    e:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
    e:\programme\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    e:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    e:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    e:\programme\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    e:\programme\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2010-5-13 73728]
    R2 AntiVirSchedulerService;Avira AntiVir Planer;e:\programme\avira\antivir desktop\sched.exe [2010-5-14 135336]
    R2 AntiVirService;Avira AntiVir Guard;e:\programme\avira\antivir desktop\avguard.exe [2010-5-14 267432]
    R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-5-14 60936]
    R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-8-14 233472]
    R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2010-7-5 1373480]
    R3 b57nd60x;Broadcom NetXtreme-Gigabit-Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
    R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-14 36608]
    R3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
    S3 AgDataUpdateSvc9;AGI Data Update Service for STK 9;e:\programme\agi\stk 9\bin\AgDataUpdateSvc9.exe [2010-5-7 54728]
    S3 PAC7311;Trust WB-3400T Webcam;c:\windows\system32\drivers\PA707UCM.SYS [2007-3-14 449024]
    S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-8-14 90112]
    S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-8-14 14976]
    S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-8-14 121856]
    S3 StorSvc;Speicherdienst;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
    S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-12 1343400]

    ============== File Associations ===============

    .txt=

    =============== Created Last 30 ================

    2010-08-29 23:49:47    0    d-----w-    c:\users\s6fa1~1.man\appdata\roaming\PTC
    2010-08-29 13:18:16    0    d-----w-    c:\program files\Cursor Attention
    2010-08-29 12:51:07    0    d-----w-    C:\WTablet
    2010-08-27 14:25:35    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-27 14:25:33    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
    2010-08-27 14:25:33    0    d-----w-    c:\program files\Malwarebytes' Anti-Malware
    2010-08-26 11:55:41    0    d-----w-    c:\users\s. manna\Neuer Ordner
    2010-08-18 21:06:02    0    d-----w-    c:\users\s6fa1~1.man\appdata\roaming\mplayer
    2010-08-14 12:03:43    0    d-----w-    c:\programdata\PC Suite
    2010-08-14 12:00:52    90624    ----a-w-    c:\windows\system32\nmwcdcls.dll
    2010-08-14 12:00:52    0    d-----w-    c:\program files\Samsung
    2010-08-14 12:00:48    21632    ----a-w-    c:\windows\system32\drivers\pccsmcfd.sys
    2010-08-14 12:00:19    90112    ----a-w-    c:\windows\system32\drivers\ss_bbus.sys
    2010-08-14 12:00:19    14976    ----a-w-    c:\windows\system32\drivers\ss_bmdfl.sys
    2010-08-14 12:00:19    121856    ----a-w-    c:\windows\system32\drivers\ss_bmdm.sys
    2010-08-14 12:00:19    12160    ----a-w-    c:\windows\system32\drivers\ss_bwhnt.sys
    2010-08-14 12:00:19    12160    ----a-w-    c:\windows\system32\drivers\ss_bwh.sys
    2010-08-14 12:00:19    12160    ----a-w-    c:\windows\system32\drivers\ss_bcmnt.sys
    2010-08-14 12:00:19    12160    ----a-w-    c:\windows\system32\drivers\ss_bcm.sys
    2010-08-14 11:59:03    0    d-----w-    c:\windows\system32\Samsung_USB_Drivers
    2010-08-14 11:58:45    36608    ----a-w-    c:\windows\system32\FsUsbExDisk.Sys
    2010-08-14 11:58:45    233472    ----a-w-    c:\windows\system32\FsUsbExService.Exe
    2010-08-14 11:58:45    110592    ----a-w-    c:\windows\system32\FsUsbExDevice.Dll
    2010-08-14 11:58:21    0    d-----w-    c:\users\s6fa1~1.man\appdata\roaming\Samsung
    2010-08-14 11:57:59    0    d-----w-    c:\program files\MarkAny
    2010-08-14 11:57:57    0    d-----w-    c:\program files\PC Connectivity Solution
    2010-08-13 16:05:36    0    d-----w-    c:\program files\Design Science
    2010-08-13 16:05:22    0    d-----w-    c:\programdata\AGI
    2010-08-13 16:05:22    0    d-----w-    c:\program files\AGI
    2010-08-13 16:04:10    140488    ----a-w-    c:\windows\system32\comdlg32.ocx
    2010-08-12 15:07:39    0    d-----w-    c:\users\s6fa1~1.man\appdata\roaming\.matplotlib
    2010-08-09 15:18:43    0    d-----w-    c:\users\s6fa1~1.man\appdata\roaming\.anki

    ==================== Find3M  ====================

    2010-09-05 22:25:13    647376    ----a-w-    c:\windows\system32\perfh007.dat
    2010-09-05 22:25:13    127404    ----a-w-    c:\windows\system32\perfc007.dat
    2010-08-05 18:25:55    73494    ----a-w-    c:\windows\War3Unin.dat
    2010-08-05 16:31:48    2829    ----a-w-    c:\windows\War3Unin.pif
    2010-08-05 16:31:48    139264    ----a-w-    c:\windows\War3Unin.exe
    2010-06-13 13:53:28    23692    ----a-w-    c:\windows\hpqins15.dat
    2010-06-08 15:35:19    737280    ----a-w-    c:\windows\iun6002.exe
    2009-07-14 08:47:32    38104    ----a-w-    c:\windows\inf\perflib\0407\perfd.dat
    2009-07-14 08:47:32    38104    ----a-w-    c:\windows\inf\perflib\0407\perfc.dat
    2009-07-14 08:47:32    295922    ----a-w-    c:\windows\inf\perflib\0407\perfi.dat
    2009-07-14 08:47:32    295922    ----a-w-    c:\windows\inf\perflib\0407\perfh.dat
    2009-07-14 04:41:57    174    --sha-w-    c:\program files\desktop.ini
    2009-07-14 00:34:40    291294    ----a-w-    c:\windows\inf\perflib\0000\perfi.dat
    2009-07-14 00:34:40    291294    ----a-w-    c:\windows\inf\perflib\0000\perfh.dat
    2009-07-14 00:34:38    31548    ----a-w-    c:\windows\inf\perflib\0000\perfd.dat
    2009-07-14 00:34:38    31548    ----a-w-    c:\windows\inf\perflib\0000\perfc.dat
    2009-06-10 21:26:35    9633792    --sha-r-    c:\windows\fonts\StaticCache.dat
    2010-05-17 09:31:36    16384    --sha-w-    c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
    2010-05-17 09:31:36    32768    --sha-w-    c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
    2010-05-17 09:31:36    16384    --sha-w-    c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
    2010-05-17 09:31:36    245760    --sha-w-    c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
    2009-07-14 01:14:45    396800    --sha-w-    c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

    ============= FINISH:  2:05:44,64 ===============

  • Airseb

    12 Posts

    596

    0

    Posted September 5th, 2010 18:00


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows 7 Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 12.05.2010 21:24:49
    System Uptime: 09.05.2010 21:59:03 (2861 hours ago)

    Motherboard: Dell Inc. |  | 0N6705
    Processor: Intel(R) Core(TM)2 Duo CPU     T5250  @ 1.50GHz | Microprocessor | 1500/166mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 24 GiB total, 5,742 GiB free.
    D: is FIXED (NTFS) - 0 GiB total, 0,07 GiB free.
    E: is FIXED (NTFS) - 98 GiB total, 66,324 GiB free.
    F: is FIXED (NTFS) - 176 GiB total, 13,402 GiB free.
    G: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    32 Bit HP CIO Components Installer
    Acrobat.com
    Adobe AIR
    Adobe Encore CS4 Codecs
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Media Encoder CS4 Exporter
    Adobe Media Encoder CS4 Importer
    Adobe Media Player
    Adobe Premiere Pro CS4 Third Party Content
    Adobe Setup
    Adobe Soundbooth CS4 Codecs
    AGI License Manager
    Anki
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Audacity 1.2.6
    Avira AntiVir Personal - Free Antivirus
    Bamboo Dock
    Bamboo Dock 3.3
    Bonjour
    BufferChm
    CamStudio
    Codec Pack - All In 1 6.0.3.0
    Condor: The Competition Soaring Simulator 1.1.0
    Copy
    CoreAVC Professional Edition (remove only)
    Corel Painter X
    Cursor Attention
    Dell AIO Printer A920
    Dell Driver Download Manager
    Destinations
    DeviceDiscovery
    DJ_AIO_06_F2400_SW_Min
    EasternAlps Scenery 2.0
    ElsterFormular
    F2400
    Fax-Lösungen
    Free Audio CD Burner version 1.4
    Free YouTube to MP3 Converter version 3.7
    FreeTrack v2.2.0.279
    GPBaseService2
    Haali Media Splitter
    HP Customer Participation Program 13.0
    HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
    HP Imaging Device Functions 13.0
    HP Print Projects 1.0
    HP Smart Web Printing 4.60
    HP Solution Center 13.0
    HP Update
    HPPhotoGadget
    hpPrintProjects
    HPProductAssistant
    hpWLPGInstaller
    ImageMixer 3 SE Ver.3
    IrfanView (remove only)
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 20
    Laptop Integrated Webcam Driver (1.04.01.1011) 
    Live 8.0.4
    Malwarebytes' Anti-Malware
    MarketResearch
    Mathcad 15 F000
    MathPlayer
    Microsoft Camcorder
    Microsoft Primary Interoperability Assemblies 2005
    Microsoft Silverlight
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Mozilla Firefox (3.6.8)
    neroxml
    PC Connectivity Solution
    QuickTime
    SAMSUNG Mobile Composite Device Software
    Samsung Mobile Modem Device Software
    SAMSUNG Mobile Modem Driver Set
    Samsung Mobile phone USB driver Drive Software
    SAMSUNG Mobile USB Modem 1.0 Software
    SAMSUNG Mobile USB Modem Software
    Samsung New PC Studio
    Samsung New PC Studio USB Driver Installer
    SAMSUNG USB Mobile Device Software
    SamsungConnectivityCableDriver
    Scan
    SeaTools for Windows
    SigmaTel Audio
    Skype Toolbars
    Skype™ 4.2
    SmartWebPrinting
    SolutionCenter
    Status
    Stifttablett
    STK 9
    System Requirements Lab for Intel
    Toolbox
    TrayApp
    Trust WB-3400T Webcam
    Uninstall 1.0.0.1
    VLC media player 1.0.5
    Warcraft III
    Warcraft III: All Products
    WebReg
    Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
    WinRAR
    XviD Video Codec (remove only)

    ==== End Of File ===========================

  • Airseb

    12 Posts

    596

    0

    Posted September 6th, 2010 05:00

    I tried to do the scan several times but it always stops at a the same file in the windows temp directory and is not able to move on. i tried to reinstall MBAM and also deactivate my Antivir during the scan process but it didnt help. i used MBAM before i opened the thread here and it worked then. it found a few JAVA. malware and i removed them into quarantine. after i scanned again to be sure, and it found 0 infected objects.

     

     

  • Bugbatter

    4 Apprentice

    20487 Posts

    596

    0

    Posted September 6th, 2010 07:00

    It appears that your system is not a 64-bit Windows 7, therefore we can run Combofix.
    If you are not sure of whether you are running a 32-bit or a 64-bit version of Microsoft Windows 7:
    * Try right-clicking on the Computer icon on the Desktop and selecting Properties from the popup context menu.
      In the System Type it should say whether it is a 32-bit or a 64-bit operating system. If it is NOT 64-bit we are okay with ComboFix.





    Please visit this webpage for download links, and instructions for running ComboFix (If you have a prior copy of Combofix, delete it now!) :

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Please login as Administrator. Do not attempt to simply run ComboFix with Admin Approval Mode. Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <-- Important



    Double click on ComboFix.exe & follow the prompts.

    • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.




    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:





    Click on Yes, to continue scanning for malware.

    When finished, it will produce a log for you.
    Please include the C:\ComboFix.txt in your next reply for further review.











     

    Notes:

    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

    2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

    3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

    4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.

    5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    * Additional information on A/V control HERE. * ComboFix is not intended for use with servers.



  • Airseb

    12 Posts

    596

    0

    Posted September 7th, 2010 14:00

    Hi,

     

    While Running combofix there was the message that rootkit activity was detected and a restart is nececcassary. after the scan completed and the "logfile will be displayed soon" there was an error message saying that a certain registry entry could not be deleted. I dont remember exactly what this message was saying. Anyway, combofix seamed to fix something, Windows updates are possible now, the harddrives are displayed correctly, until now there were no redirects in firefox and MBAM could perform a full scan with no infections found. Can you tell what the problem was, or what kind of infections i had to deal with, and were was it from? Is it possible that data was being stolen?

    And: thanks for now, of what I can see now, you really helped me!

    here is the Combofix logfile:

     

    ComboFix 10-09-07.01 - S. Manna 07.09.2010  21:52:16.1.2 - x86
    Microsoft Windows 7 Professional   6.1.7600.0.1252.49.1031.18.2038.1143 [GMT 2:00]
    ausgeführt von:: c:\users\S. Manna\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    Infizierte Kopie von c:\windows\system32\drivers\rdyboost.sys wurde gefunden und desinfiziert
    Kopie von - Kitty had a snack :p wurde wiederhergestellt
    .
    (((((((((((((((((((((((   Dateien erstellt von 2010-08-07 bis 2010-09-07  ))))))))))))))))))))))))))))))
    .

    2010-09-07 20:04 . 2010-09-07 20:04    --------    d-----w-    c:\users\S. Manna\AppData\Local\temp
    2010-09-06 10:39 . 2010-04-29 13:39    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
    2010-09-06 10:39 . 2010-04-29 13:39    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
    2010-08-29 23:49 . 2010-08-29 23:49    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\PTC
    2010-08-29 23:49 . 2010-08-29 23:49    --------    d-----w-    c:\users\S. Manna\AppData\Local\Mathsoft
    2010-08-29 23:49 . 2010-08-29 23:49    --------    d-----w-    c:\users\S. Manna\AppData\Local\Parametric_Technology_Cor
    2010-08-29 13:18 . 2010-08-29 13:18    --------    d-----w-    c:\users\S. Manna\AppData\Local\Kenrick_Mock
    2010-08-29 13:18 . 2010-08-29 13:18    --------    d-----w-    c:\program files\Cursor Attention
    2010-08-29 12:51 . 2010-09-02 21:00    --------    d-----w-    C:\WTablet
    2010-08-27 14:25 . 2010-09-06 10:39    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
    2010-08-26 11:55 . 2010-08-26 11:55    --------    d-----w-    c:\users\S. Manna\Neuer Ordner
    2010-08-18 21:06 . 2010-08-18 21:06    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\mplayer
    2010-08-14 12:04 . 2010-08-14 12:04    69632    ----a-w-    c:\users\S. Manna\AppData\Roaming\Samsung\New PC Studio\DriverChecker.exe
    2010-08-14 12:03 . 2010-08-14 12:03    --------    d-----w-    c:\programdata\PC Suite
    2010-08-14 12:03 . 2010-08-14 12:03    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\PC Suite
    2010-08-14 12:03 . 2010-08-14 12:03    786432    ----a-w-    c:\users\S. Manna\AppData\Roaming\Samsung\New PC Studio\LiveUpdate\Setup_For_Full_Update_IH2_7.exe
    2010-08-14 12:00 . 2010-08-14 12:00    --------    d-----w-    c:\program files\Samsung
    2010-08-14 12:00 . 2007-05-02 14:31    90624    ----a-w-    c:\windows\system32\nmwcdcls.dll
    2010-08-14 12:00 . 2010-08-14 12:00    --------    d-----w-    c:\program files\DIFX
    2010-08-14 12:00 . 2007-09-17 13:53    21632    ----a-w-    c:\windows\system32\drivers\pccsmcfd.sys
    2010-08-14 12:00 . 2009-03-20 08:01    90112    ----a-w-    c:\windows\system32\drivers\ss_bbus.sys
    2010-08-13 16:05 . 2010-08-13 16:05    --------    d-----w-    c:\program files\Design Science
    2010-08-13 16:05 . 2010-08-13 16:05    --------    d-----w-    c:\users\S6FA1~1~MAN
    2010-08-13 16:05 . 2010-08-13 16:05    --------    d-----w-    c:\users\S. Manna\AppData\Local\AGI
    2010-08-13 16:05 . 2010-08-13 16:06    --------    d-----w-    c:\programdata\AGI
    2010-08-13 16:05 . 2010-08-13 16:05    --------    d-----w-    c:\program files\AGI
    2010-08-12 19:59 . 2010-08-12 19:59    --------    d-----w-    c:\users\Maggie\Eigene Dateien
    2010-08-12 19:59 . 2010-08-12 19:59    --------    d-----w-    c:\users\Maggie
    2010-08-12 15:07 . 2010-08-12 15:07    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\.matplotlib
    2010-08-09 15:18 . 2010-08-20 16:24    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\.anki

    .
    ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-09-07 19:56 . 2009-07-14 08:47    647376    ----a-w-    c:\windows\system32\perfh007.dat
    2010-09-07 19:56 . 2009-07-14 08:47    127404    ----a-w-    c:\windows\system32\perfc007.dat
    2010-09-07 19:51 . 2010-07-05 21:34    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\WTablet
    2010-09-06 10:39 . 2010-07-09 12:51    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\Malwarebytes
    2010-09-06 10:39 . 2010-07-09 12:51    --------    d-----w-    c:\programdata\Malwarebytes
    2010-09-05 22:43 . 2010-05-13 08:58    109784    ----a-w-    c:\users\S. Manna\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-09-05 22:19 . 2010-05-13 16:00    --------    d-----w-    c:\programdata\Nero
    2010-09-05 22:05 . 2010-05-15 09:05    --------    d-----w-    c:\program files\Common Files\Adobe
    2010-09-05 20:27 . 2010-05-14 11:47    --------    d-----w-    c:\programdata\Microsoft Help
    2010-09-05 20:27 . 2010-05-14 11:48    --------    d-----w-    c:\program files\Microsoft Visual Studio 8
    2010-09-05 20:23 . 2009-07-14 04:52    --------    d-----w-    c:\program files\MSBuild
    2010-09-05 20:18 . 2010-05-13 09:02    --------    d--h--w-    c:\program files\InstallShield Installation Information
    2010-08-30 12:59 . 2010-05-13 15:03    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\uTorrent
    2010-08-27 19:49 . 2010-05-28 15:47    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\Skype
    2010-08-27 14:33 . 2010-05-28 15:52    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\skypePM
    2010-08-14 12:00 . 2010-08-14 11:57    --------    d-----w-    c:\program files\PC Connectivity Solution
    2010-08-14 11:58 . 2010-08-14 11:58    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\Samsung
    2010-08-14 11:57 . 2010-08-14 11:57    --------    d-----w-    c:\program files\MarkAny
    2010-08-05 18:25 . 2010-08-05 16:23    73494    ----a-w-    c:\windows\War3Unin.dat
    2010-08-05 16:31 . 2010-08-05 16:23    2829    ----a-w-    c:\windows\War3Unin.pif
    2010-08-05 16:31 . 2010-08-05 16:23    139264    ----a-w-    c:\windows\War3Unin.exe
    2010-07-30 23:07 . 2010-06-08 13:16    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\Ahead
    2010-07-28 13:33 . 2010-07-28 13:33    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\Mathsoft
    2010-07-28 13:21 . 2010-07-28 13:21    --------    d-----w-    c:\program files\Mathcad
    2010-07-28 11:35 . 2010-05-14 12:27    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\vlc
    2010-07-27 22:46 . 2010-07-27 22:46    --------    d-----w-    c:\users\S. Manna\AppData\Roaming\DVDVideoSoftIEHelpers
    2010-07-27 22:46 . 2010-07-27 22:45    --------    d-----w-    c:\program files\Common Files\DVDVideoSoft
    2010-07-27 22:45 . 2010-07-27 22:45    --------    d-----w-    c:\program files\DVDVideoSoft
    2010-06-13 13:53 . 2010-06-12 17:38    23692    ----a-w-    c:\windows\hpqins15.dat
    2009-06-10 21:26 . 2009-07-14 02:04    9633792    --sha-r-    c:\windows\Fonts\StaticCache.dat
    2009-07-14 01:14 . 2009-07-13 23:42    396800    --sha-w-    c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    .

    ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe" [2010-06-24 231888]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
    "avgnt"="e:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
    "PAC7311_Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
    "BambooCore"="e:\programme\Bamboo Dock\BambooCore.exe" [2010-06-25 609424]

    c:\users\S. Manna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    CursorAttention.lnk - c:\program files\Cursor Attention\CursorAttention.exe [2008-6-20 43008]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor Ver.3.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.3.lnk
    backup=c:\windows\pss\ImageMixer 3 SE Camera Monitor Ver.3.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
    2006-11-03 15:09    312200    ----a-w-    c:\program files\Dell PC Fax\fm3032.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    2010-06-09 18:55    49208    ----a-w-    c:\program files\HP\HP Software Update\hpwuschd2.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-04-28 13:06    142120    ----a-w-    e:\programme\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
    2007-05-09 15:01    36864    ----a-w-    c:\windows\OEM02Mon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-03-17 19:53    421888    ----a-w-    c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2010-02-18 09:43    248040    ----a-w-    c:\program files\Common Files\Java\Java Update\jusched.exe

    R3 AgDataUpdateSvc9;AGI Data Update Service for STK 9;e:\programme\AGI\STK 9\bin\AgDataUpdateSvc9.exe [2010-05-06 54728]
    R3 PAC7311;Trust WB-3400T Webcam;c:\windows\system32\DRIVERS\PA707UCM.SYS [2007-03-14 449024]
    R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
    R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
    R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
    R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-12 1343400]
    R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys
    S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
    S2 AntiVirSchedulerService;Avira AntiVir Planer;e:\programme\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
    S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
    S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2007-09-07 1373480]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
    S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12    REG_MULTI_SZ       Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt    REG_MULTI_SZ       hpqcxs08 hpqddsvc
    .
    .
    ------- Zusätzlicher Suchlauf -------
    .
    uInternet Settings,ProxyOverride = *.local
    IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Free YouTube to Mp3 Converter - c:\users\S. Manna\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
    IE: In Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    FF - ProfilePath - c:\users\S. Manna\AppData\Roaming\Mozilla\Firefox\Profiles\g2dqhpym.default\
    FF - prefs.js: browser.search.selectedEngine - Wikipedia (de)
    FF - prefs.js: browser.startup.homepage - www.google.de
    FF - component: e:\programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
    FF - plugin: c:\windows\system32\Wat\npWatWeb.dll
    FF - plugin: e:\programme\iTunes\Mozilla Plugins\npitunes.dll
    FF - plugin: e:\programme\Java\bin\new_plugin\npdeployJava1.dll
    FF - plugin: e:\programme\Java\bin\new_plugin\npjp2.dll

    ---- FIREFOX Richtlinien ----
    e:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    e:\programme\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    e:\programme\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .
    .
    ------- Dateityp-Verknüpfung -------
    .
    .txt=
    .
    - - - - Entfernte verwaiste Registrierungseinträge - - - -

    HKLM-Run-NPSStartup - (no file)
    MSConfigStartUp-Acrobat Assistant 8 - e:\programme\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
    MSConfigStartUp-Adobe_ID0ENQBO - c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
    MSConfigStartUp-Dell AIO Printer A920 - c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
    MSConfigStartUp-GrooveMonitor - c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
    MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
    AddRemove-_{91CABF8F-A81C-4CB0-A1B0-D55B25F1B150} - e:\programme\Corel\Corel Painter X\MSILauncher {91CABF8F-A81C-4CB0-A1B0-D55B25F1B150}


    .
    --------------------- Gesperrte Registrierungsschluessel ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Zeit der Fertigstellung: 2010-09-07  22:08:16
    ComboFix-quarantined-files.txt  2010-09-07 20:08

    Vor Suchlauf: 6.089.523.200 Bytes frei
    Nach Suchlauf: 6.099.197.952 Bytes frei

    - - End Of File - - 8E51F420DD1DBA2688C26CF10CBD5A8E

  • Bugbatter

    4 Apprentice

    20487 Posts

    455

    0

    Posted September 7th, 2010 16:00

    I don't read German well, but it appears that you had a rootkit infecting a system file. The file was disinfected and restored because there was a backup on the system, thanks to ComboFix. Please run an online virus scan by Kaspersky from HERE.

    • 1. At the main page. Press on " Accept". After reading the contents.
      2. At the next window Select Update. Allow the Database to update.
      Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
      3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete.
      4. Select Scan Report.
      5. If any threats were found they will appear in the report
      6. Select "Save error report as"
      Then in the file name just type in kaspersky
      Under "save as type" select text .txt
      Save it to your Desktop.


    Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
    If that report looks good and everything is running well, we'll update Java, remove our tools, reset System Restore, and you'll be good to go, so let me know how things are running when your return.