Punkt 1:
Alle aufgelisteten programme deinstalliert, bis auf dieses "Free Ride Games", das findet Windows nicht (mehr).
Punkt 2:
Hier das Logfile:
Code:
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKEY_USERS\S-1-5-21-4129386300-1563012868-1195755936-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKU\S-1-5-21-4129386300-1563012868-1195755936-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Prefs.js: "41.158.128.221" removed from network.proxy.autoconfig_url
Prefs.js: "203.42.246.231" removed from network.proxy.backup.ftp
Prefs.js: 80 removed from network.proxy.backup.ftp_port
Prefs.js: "203.42.246.231" removed from network.proxy.backup.socks
Prefs.js: 80 removed from network.proxy.backup.socks_port
Prefs.js: "203.42.246.231" removed from network.proxy.backup.ssl
Prefs.js: 80 removed from network.proxy.backup.ssl_port
Prefs.js: "203.42.246.231" removed from network.proxy.ftp
Prefs.js: 80 removed from network.proxy.ftp_port
Prefs.js: "203.42.246.231" removed from network.proxy.http
Prefs.js: 80 removed from network.proxy.http_port
Prefs.js: true removed from network.proxy.share_proxy_settings
Prefs.js: "203.42.246.231" removed from network.proxy.socks
Prefs.js: 80 removed from network.proxy.socks_port
Prefs.js: 4 removed from network.proxy.socks_version
Prefs.js: "203.42.246.231" removed from network.proxy.ssl
Prefs.js: 80 removed from network.proxy.ssl_port
Prefs.js: 4 removed from network.proxy.type
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IntelTBRunOnce not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\Exetender deleted successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Exetender not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\Exetender deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\Exetender deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Starting removal of ActiveX control {6A060448-60F9-11D5-A6CD-0002B31F7455}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A060448-60F9-11D5-A6CD-0002B31F7455}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\ not found.
========== SERVICES/DRIVERS ==========
Service SANDRA stopped successfully!
Service SANDRA deleted successfully!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{474247E7-C1A2-4DB6-94C6-34057EE8B231} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{474247E7-C1A2-4DB6-94C6-34057EE8B231}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Henrik\Desktop\cmd.bat deleted successfully.
C:\Users\Henrik\Desktop\cmd.txt deleted successfully.
File\Folder C:\Program Files\SiSoftware not found.
C:\Users\Henrik\AppData\Local\{03F80C2B-1C92-4111-A4BA-F4F36EAE20E6} folder moved successfully.
C:\Users\Henrik\AppData\Local\{0508B13E-801D-4332-A9B5-278A03BB9532} folder moved successfully.
C:\Users\Henrik\AppData\Local\{05509D7C-E595-4DCE-8C5A-E83448F6805B} folder moved successfully.
C:\Users\Henrik\AppData\Local\{0A0252E6-33D1-4F21-8A05-C246198A53B5} folder moved successfully.
C:\Users\Henrik\AppData\Local\{18EC2FAA-E9A3-4526-9E7D-FA34D59B3B77} folder moved successfully.
C:\Users\Henrik\AppData\Local\{2A1D60F1-4CF0-4F06-BB74-D29FB5475B34} folder moved successfully.
C:\Users\Henrik\AppData\Local\{46D5EA60-B174-4F9A-8685-85D7A6E28131} folder moved successfully.
C:\Users\Henrik\AppData\Local\{6A91F7D0-FD96-46CF-9F12-93E25B9F184A} folder moved successfully.
C:\Users\Henrik\AppData\Local\{87E46065-61E3-4269-ADFB-426CB4815040} folder moved successfully.
C:\Users\Henrik\AppData\Local\{8DEFACEF-D58D-4FEE-8486-E7D688585B97} folder moved successfully.
C:\Users\Henrik\AppData\Local\{8EC8CF35-846E-4A11-8EBC-F91EA693563F} folder moved successfully.
C:\Users\Henrik\AppData\Local\{950868E3-6E4F-4079-90A1-BF289DB49F30} folder moved successfully.
C:\Users\Henrik\AppData\Local\{A817C2A6-E494-49F1-AC8E-303151C66C7C} folder moved successfully.
C:\Users\Henrik\AppData\Local\{B0C2BE79-850B-417C-8101-285575C479CC} folder moved successfully.
C:\Users\Henrik\AppData\Local\{BAEE3015-412A-4AD2-97DE-DC21419439D7} folder moved successfully.
C:\Users\Henrik\AppData\Local\{DC949629-5C57-4D1C-9C0A-487A091D43C1} folder moved successfully.
C:\Users\Henrik\AppData\Local\{DEC5B175-D9FF-4DD7-A84B-3A373EB6D43C} folder moved successfully.
C:\Users\Henrik\AppData\Local\{E0763661-E080-4F30-A633-4136185EA882} folder moved successfully.
C:\Users\Henrik\AppData\Local\{E1458AFF-3AB0-4F0F-8924-6F37068DEA7A} folder moved successfully.
C:\Users\Henrik\AppData\Local\{E673AE14-718C-46AC-B983-42D27CABA78F} folder moved successfully.
C:\Users\Henrik\AppData\Roaming\BitTorrent\ie folder moved successfully.
C:\Users\Henrik\AppData\Roaming\BitTorrent\dlimagecache folder moved successfully.
C:\Users\Henrik\AppData\Roaming\BitTorrent\apps folder moved successfully.
C:\Users\Henrik\AppData\Roaming\BitTorrent folder moved successfully.
C:\Windows\SysNative\ehefrau - video-nackt,hure,nutte,gefickt,wife,ehefrau,hure und mutter,nutte,bitch,germany,sau,ficken,fuck,100%,real,sperm,sperma,sau,heimlich,bilder,pics,echt,beine,strapse,nylon,legs,married,049.jpg.lnk moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\lib\jqplot folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\lib\datejs folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\lib folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\PageManager folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\Page folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\DT folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo\css folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\MediaInfo folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite\IconsCache folder moved successfully.
C:\Users\Henrik\AppData\Roaming\DAEMON Tools Lite folder moved successfully.
File\Folder C:\Program Files (x86)\Free Ride Games not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Henrik
->Temp folder emptied: 4104638 bytes
->Temporary Internet Files folder emptied: 1541674 bytes
->Java cache emptied: 1728470 bytes
->FireFox cache emptied: 51911123 bytes
->Google Chrome cache emptied: 1905008 bytes
->Flash cache emptied: 1058 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: UpdatusUser.MILA
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 1619120 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 24882 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50568 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 639 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 60,00 mb
OTL by OldTimer - Version 3.2.48.0 log created on 06162012_181236
Files\Folders moved on Reboot...
C:\Users\Henrik\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\_avast_\Webshlock.txt not found!
Registry entries deleted on Reboot...
Punkt 3:
Erledigt.
Punkt 4:
Überprüft und sie ist nicht schädlich.
Punkt 5:
Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 18:19 on 16/06/2012 by Henrik
Administrator - Elevation successful
========== dir ==========
C:\Windows\de - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 107888 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\en - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 106864 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\el - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 107888 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\es - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 107376 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\fr - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 107376 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\he - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 106352 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\it - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 106864 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\nl - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 107376 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\ru - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 106864 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Windows\ar - Parameters: "/s"
---Files---
WLXPGSS.SCR.mui --a---- 106352 bytes [16:45 08/03/2012] [16:45 08/03/2012]
No folders found.
C:\Users\Henrik\AppData\Roaming\.mono - Parameters: "/s"
---Files---
None found.
C:\Users\Henrik\AppData\Roaming\.mono\certs d------ [17:42 07/06/2012]
C:\Users\Henrik\AppData\Roaming\.mono\certs\CA d------ [17:42 07/06/2012]
C:\Users\Henrik\AppData\Roaming\.mono\certs\Trust d------ [17:42 07/06/2012]
C:\ProgramData\.mono - Parameters: "/s"
---Files---
None found.
C:\ProgramData\.mono\certs d------ [17:42 07/06/2012]
C:\ProgramData\.mono\certs\Trust d------ [17:42 07/06/2012]
C:\Users\Henrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\discreet - Parameters: "/s"
---Files---
None found.
C:\Users\Henrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\discreet\gmax d------ [21:55 27/05/2012]
gmax.lnk --a---- 610 bytes [21:55 27/05/2012] [21:55 27/05/2012]
-= EOF =-
Punkt 6:
Es handelt sich um einen ASUS K53SV SX690V mit einer vorinstallierten Version von Windows 7 Home Premium (auf dem neuestem Stand).
aswMBR:
Code:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-06-16 18:20:54
-----------------------------
18:20:54.836 OS Version: Windows x64 6.1.7601 Service Pack 1
18:20:54.836 Number of processors: 4 586 0x2A07
18:20:54.836 ComputerName: MILA UserName:
18:20:56.287 Initialize success
18:20:56.411 AVAST engine defs: 12061600
18:23:20.551 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:23:20.551 Disk 0 Vendor: Hitachi_ JE3O Size: 476940MB BusType: 3
18:23:20.598 Disk 0 MBR read successfully
18:23:20.598 Disk 0 MBR scan
18:23:20.598 Disk 0 Windows 7 default MBR code
18:23:20.614 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048
18:23:20.629 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 246336 MB offset 52430848
18:23:20.661 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 205001 MB offset 556926976
18:23:20.707 Disk 0 scanning C:\Windows\system32\drivers
18:23:42.017 Service scanning
18:24:07.273 Modules scanning
18:24:07.289 Disk 0 trace - called modules:
18:24:07.320 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
18:24:07.336 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009a10060]
18:24:07.336 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007b00e40]
18:24:07.351 5 ACPI.sys[fffff88000f9a7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007e04050]
18:24:08.428 AVAST engine scan C:\Windows
18:24:21.891 AVAST engine scan C:\Windows\system32
18:26:55.410 AVAST engine scan C:\Windows\system32\drivers
18:27:03.991 AVAST engine scan C:\Users\Henrik
18:34:18.872 AVAST engine scan C:\ProgramData
18:36:06.562 Scan finished successfully
18:40:42.304 Disk 0 MBR has been saved successfully to "C:\Users\Henrik\Desktop\MBR.dat"
18:40:42.320 The log file has been saved successfully to "C:\Users\Henrik\Desktop\aswMBR.txt"