|
Log-Analyse und Auswertung: PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehrWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.08.2010, 16:45 | #1 |
| PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Entschuldigung das ich erst jetzt antworten kann, aber beruflich war ich extrem eingespannt. Nur das Problem ist immer noch geblieben und wird im Moment sogar schlimmer: Zusätzlich funktioniert die Funkmaus und die Tastatur zum Teil nicht mehr... Dann lässt sich der PC auch erst nach mindestens 3 Versuchen starten. HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:35:48, on 11.08.2010 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16385) Boot mode: Normal Running processes: E:\Windows\system32\taskhost.exe E:\Windows\system32\Dwm.exe E:\Windows\Explorer.EXE E:\Program Files\Avira\AntiVir Desktop\avgnt.exe E:\Windows\WindowsMobile\wmdc.exe E:\Program Files\Microsoft IntelliPoint\ipoint.exe E:\Program Files\Common Files\Java\Java Update\jusched.exe E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe E:\Program Files\DAEMON Tools Lite\DTLite.exe E:\Program Files\Mozilla Firefox\firefox.exe E:\Program Files\Windows Live\Mail\wlmail.exe E:\Program Files\Windows Live\Contacts\wlcomm.exe E:\Users\Rolf\Downloads\HiJackThis204.exe E:\Program Files\Mozilla Firefox\plugin-container.exe E:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - E:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - E:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - E:\Program Files\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [avgnt] "E:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe O4 - HKLM\..\Run: [IntelliPoint] "E:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\RunOnce: [SpeedUpMyPC] "E:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe" delay 20000 O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O4 - Global Startup: Sinus 1054 data WLAN Manager.lnk = E:\Program Files\DT\Sinus 1054 data\Wifiusb.exe O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: An OneNote s&enden - res://E:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://E:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000 O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - E:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - E:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: @E:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll O9 - Extra 'Tools' menuitem: @E:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programs\PartyGaming\PartyCasino\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programs\PartyGaming\PartyCasino\RunApp.exe (file missing) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O10 - Unknown file in Winsock LSP: d:\nvidia\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - E:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - E:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - E:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe O23 - Service: Google Update Service (gupdate1cab870c98ceb00) (gupdate1cab870c98ceb00) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - E:\Windows\system32\nvvsvc.exe O23 - Service: Steam Client Service - Valve Corporation - E:\Program Files\Common Files\Steam\SteamService.exe -- End of file - 8784 bytes |
13.08.2010, 13:56 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Hallo und
__________________Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
13.08.2010, 17:55 | #3 |
| PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Hoffe Du kannst hiermit was anfangen. Schon jetzt vielen Dank!
__________________Ok, hier das Log vom Malwarebytes Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4052 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 13.08.2010 18:50:12 mbam-log-2010-08-13 (18-50-12).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Durchsuchte Objekte: 372114 Laufzeit: 3 Stunde(n), 19 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) Und hier nun der OLT LogOTL Logfile: Code:
ATTFilter OTL logfile created on: 13.08.2010 18:51:33 - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = E:\Users\Rolf\Downloads Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 50,00% Memory free 9,00 Gb Paging File | 7,00 Gb Available in Paging File | 80,00% Paging File free Paging file location(s): [Binary data over 100 bytes] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files Drive C: | 186,30 Gb Total Space | 7,50 Gb Free Space | 4,03% Space Free | Partition Type: NTFS Drive D: | 48,83 Gb Total Space | 19,51 Gb Free Space | 39,97% Space Free | Partition Type: NTFS Drive E: | 27,85 Gb Total Space | 3,15 Gb Free Space | 11,33% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ROLF-PC Current User Name: Rolf Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2010.08.13 15:20:53 | 000,574,976 | ---- | M] (OldTimer Tools) -- E:\Users\Rolf\Downloads\OTL.exe PRC - [2010.07.28 17:38:56 | 000,032,768 | ---- | M] () -- C:\Casino\Bwin Casino\browserhost.exe PRC - [2010.07.28 17:38:55 | 000,047,104 | ---- | M] () -- C:\Casino\Bwin Casino\casino.exe PRC - [2010.07.25 12:54:03 | 000,014,808 | ---- | M] (Mozilla Corporation) -- E:\Program Files\Mozilla Firefox\plugin-container.exe PRC - [2010.07.25 12:53:58 | 000,910,296 | ---- | M] (Mozilla Corporation) -- E:\Program Files\Mozilla Firefox\firefox.exe PRC - [2010.04.29 15:39:32 | 001,090,952 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe PRC - [2010.04.20 20:36:27 | 000,267,432 | ---- | M] (Avira GmbH) -- E:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2010.04.01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- E:\Program Files\DAEMON Tools Lite\DTLite.exe PRC - [2010.03.02 10:28:23 | 000,282,792 | ---- | M] (Avira GmbH) -- E:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2010.02.24 09:28:01 | 000,135,336 | ---- | M] (Avira GmbH) -- E:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- E:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- E:\Windows\explorer.exe PRC - [2009.09.30 20:58:42 | 000,026,464 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Windows Live\Contacts\wlcomm.exe PRC - [2009.09.26 05:28:22 | 004,639,136 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE PRC - [2009.08.10 15:59:50 | 000,178,720 | ---- | M] () -- D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe PRC - [2009.08.10 15:59:48 | 000,387,616 | ---- | M] () -- D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe PRC - [2009.07.26 17:44:14 | 000,112,464 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Windows Live\Mail\wlmail.exe PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\taskhost.exe PRC - [2009.07.14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\conhost.exe ========== Modules (SafeList) ========== MOD - [2010.08.13 15:20:53 | 000,574,976 | ---- | M] (OldTimer Tools) -- E:\Users\Rolf\Downloads\OTL.exe MOD - [2009.07.14 03:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\sspicli.dll MOD - [2009.07.14 03:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\sechost.dll MOD - [2009.07.14 03:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\samcli.dll MOD - [2009.07.14 03:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\profapi.dll MOD - [2009.07.14 03:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\netutils.dll MOD - [2009.07.14 03:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\KernelBase.dll MOD - [2009.07.14 03:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\dwmapi.dll MOD - [2009.07.14 03:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\devobj.dll MOD - [2009.07.14 03:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\cryptbase.dll MOD - [2009.07.14 03:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\cfgmgr32.dll MOD - [2009.07.14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\msscript.ocx MOD - [2009.07.14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- E:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - [2010.04.20 20:36:27 | 000,267,432 | ---- | M] (Avira GmbH) [Auto | Running] -- E:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010.04.10 17:05:58 | 000,266,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.02.24 09:28:01 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- E:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2009.09.26 05:28:22 | 004,639,136 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- E:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2009.08.24 22:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- E:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe -- (DfSdkS) SRV - [2009.08.10 15:59:50 | 000,178,720 | ---- | M] () [Auto | Running] -- D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp) SRV - [2009.08.10 15:59:48 | 000,387,616 | ---- | M] () [Auto | Running] -- D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) SRV - [2009.08.05 23:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc) SRV - [2009.07.14 03:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\wwansvc.dll -- (WwanSvc) SRV - [2009.07.14 03:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\wbiosrvc.dll -- (WbioSrvc) SRV - [2009.07.14 03:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Windows\System32\umpo.dll -- (Power) SRV - [2009.07.14 03:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Windows\System32\themeservice.dll -- (Themes) SRV - [2009.07.14 03:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\sppuinotify.dll -- (sppuinotify) SRV - [2009.07.14 03:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- E:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper) SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- E:\Windows\System32\pnrpsvc.dll -- (PNRPsvc) SRV - [2009.07.14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- E:\Windows\System32\pnrpsvc.dll -- (p2pimsvc) SRV - [2009.07.14 03:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- E:\Windows\System32\provsvc.dll -- (HomeGroupProvider) SRV - [2009.07.14 03:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg) SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.07.14 03:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- E:\Windows\System32\ListSvc.dll -- (HomeGroupListener) SRV - [2009.07.14 03:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\FntCache.dll -- (FontCache) SRV - [2009.07.14 03:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Windows\System32\dhcpcore.dll -- (Dhcp) SRV - [2009.07.14 03:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\defragsvc.dll -- (defragsvc) SRV - [2009.07.14 03:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- E:\Windows\System32\bdesvc.dll -- (BDESVC) SRV - [2009.07.14 03:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX-Installer (AxInstSV) SRV - [2009.07.14 03:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\appidsvc.dll -- (AppIDSvc) SRV - [2009.07.14 03:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- E:\Windows\System32\sppsvc.exe -- (sppsvc) SRV - [2009.05.19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort) SRV - [2008.12.22 11:52:16 | 000,104,944 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- E:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2007.05.31 17:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007.05.31 17:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- E:\Windows\System32\PCANDIS4.SYS -- (PCANDIS4) DRV - File not found [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy) DRV - [2010.04.03 22:55:32 | 011,573,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2010.03.01 09:05:19 | 000,124,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- E:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2010.02.27 20:29:25 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- E:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2010.02.27 20:29:25 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- E:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2010.02.27 20:16:17 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- E:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2010.02.16 13:24:01 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- E:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2009.12.18 00:25:12 | 000,026,024 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- E:\Windows\System32\drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV - [2009.12.11 09:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg) DRV - [2009.11.11 17:23:46 | 000,030,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\point32k.sys -- (Point32) DRV - [2009.11.04 20:13:10 | 000,294,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- E:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm) DRV - [2009.11.04 20:13:10 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\vpcusb.sys -- (vpcusb) DRV - [2009.11.04 20:13:10 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- E:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr) DRV - [2009.11.04 20:13:09 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\vpchbus.sys -- (vpcbus) DRV - [2009.11.04 03:59:00 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB) DRV - [2009.08.09 23:25:56 | 000,029,696 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\VClone.sys -- (VClone) DRV - [2009.08.05 23:48:42 | 000,054,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\fssfltr.sys -- (fssfltr) DRV - [2009.07.30 17:12:54 | 000,287,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvmf6232.sys -- (NVNET) DRV - [2009.07.14 03:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide) DRV - [2009.07.14 03:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci) DRV - [2009.07.14 03:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx) DRV - [2009.07.14 03:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs) DRV - [2009.07.14 03:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320) DRV - [2009.07.14 03:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas) DRV - [2009.07.14 03:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata) DRV - [2009.07.14 03:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\arc.sys -- (arc) DRV - [2009.07.14 03:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- E:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata) DRV - [2009.07.14 03:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\aliide.sys -- (aliide) DRV - [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor) DRV - [2009.07.14 03:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid) DRV - [2009.07.14 03:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960) DRV - [2009.07.14 03:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS) DRV - [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV) DRV - [2009.07.14 03:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR) DRV - [2009.07.14 03:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI) DRV - [2009.07.14 03:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC) DRV - [2009.07.14 03:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2) DRV - [2009.07.14 03:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp) DRV - [2009.07.14 03:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\megasas.sys -- (megasas) DRV - [2009.07.14 03:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy) DRV - [2009.07.14 03:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor) DRV - [2009.07.14 03:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx) DRV - [2009.07.14 03:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD) DRV - [2009.07.14 03:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- E:\Windows\System32\drivers\fsdepends.sys -- (FsDepends) DRV - [2009.07.14 03:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid) DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus) DRV - [2009.07.14 03:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp) DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt) DRV - [2009.07.14 03:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot) DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- E:\Windows\System32\drivers\wimmount.sys -- (WIMMount) DRV - [2009.07.14 03:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\viaide.sys -- (viaide) DRV - [2009.07.14 03:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300) DRV - [2009.07.14 03:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\rdyboost.sys -- (rdyboost) DRV - [2009.07.14 03:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx) DRV - [2009.07.14 03:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4) DRV - [2009.07.14 03:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\pcw.sys -- (pcw) DRV - [2009.07.14 03:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2) DRV - [2009.07.14 03:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor) DRV - [2009.07.14 03:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\Drivers\cng.sys -- (CNG) DRV - [2009.07.14 02:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM) DRV - [2009.07.14 02:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\rdpbus.sys -- (rdpbus) DRV - [2009.07.14 02:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- E:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP) DRV - [2009.07.14 01:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2) DRV - [2009.07.14 01:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- E:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf) DRV - [2009.07.14 01:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\ndiscap.sys -- (NdisCap) DRV - [2009.07.14 01:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\vwifibus.sys -- (vwifibus) DRV - [2009.07.14 01:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\1394ohci.sys -- (1394ohci) DRV - [2009.07.14 01:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\umpass.sys -- (UmPass) DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\winusb.sys -- (WINUSB) DRV - [2009.07.14 01:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf) DRV - [2009.07.14 01:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig) DRV - [2009.07.14 01:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus) DRV - [2009.07.14 01:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\drivers\appid.sys -- (AppID) DRV - [2009.07.14 01:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- E:\Windows\System32\drivers\scfilter.sys -- (scfilter) DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap) DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID) DRV - [2009.07.14 01:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- E:\Windows\System32\drivers\discache.sys -- (discache) DRV - [2009.07.14 01:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt) DRV - [2009.07.14 01:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi) DRV - [2009.07.14 01:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\amdppm.sys -- (AmdPPM) DRV - [2009.07.14 00:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2009.07.14 00:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm) DRV - [2009.07.14 00:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer) DRV - [2009.07.14 00:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm) DRV - [2009.07.14 00:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo) DRV - [2009.07.14 00:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp) DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD) DRV - [2009.07.14 00:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x) DRV - [2009.07.14 00:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv) DRV - [2009.07.14 00:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv) DRV - [2009.06.29 00:36:36 | 000,017,920 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvsmu.sys -- (nvsmu) DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- E:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.05.09 02:14:20 | 000,014,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nuidfltr.sys -- (NuidFltr) DRV - [2009.02.13 12:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- E:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2007.11.13 23:48:46 | 000,071,720 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- E:\Windows\system32\DRIVERS\pnp680.sys -- (Pnp680) DRV - [2005.10.19 09:20:30 | 000,357,792 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\PRISMA02.sys -- (PRISM_A02) DRV - [2004.08.13 10:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C0 E3 6E 52 D0 B7 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Winamp Search" FF - prefs.js..browser.search.defaulturl: "hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..keyword.URL: "hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" FF - user.js..browser.search.openintab: false FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2010.07.25 12:54:08 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2010.08.06 23:34:27 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.1\extensions\\Components: E:\Program Files\Mozilla Thunderbird\components [2010.08.10 11:11:21 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.1\extensions\\Plugins: E:\Program Files\Mozilla Thunderbird\plugins [2010.08.10 11:11:22 | 000,000,000 | ---D | M] -- E:\Users\Rolf\AppData\Roaming\mozilla\Extensions [2010.08.10 11:11:22 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Rolf\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010.07.25 12:58:16 | 000,000,000 | ---D | M] -- E:\Users\Rolf\AppData\Roaming\mozilla\Firefox\Profiles\woju0099.default\extensions [2010.03.16 23:40:04 | 000,001,196 | ---- | M] () -- E:\Users\Rolf\AppData\Roaming\Mozilla\FireFox\Profiles\woju0099.default\searchplugins\winamp-search.xml [2010.08.12 20:21:34 | 000,000,000 | ---D | M] -- E:\Program Files\Mozilla Firefox\extensions [2010.05.23 12:58:01 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010.05.23 12:57:42 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll [2010.07.12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- E:\Program Files\Mozilla Firefox\plugins\npwachk.dll [2010.01.16 03:15:29 | 000,001,392 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.01.16 03:15:29 | 000,002,344 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml [2010.01.16 03:15:29 | 000,006,805 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.01.16 03:15:29 | 000,001,178 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.01.16 03:15:29 | 000,001,105 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.04.06 23:25:25 | 000,385,990 | R--- | M]) - E:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.123fporn.info O1 - Hosts: 13311 more lines... O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - E:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - E:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - E:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - E:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O4 - HKLM..\Run: [avgnt] E:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [NWEReboot] File not found O4 - HKCU..\Run: [DAEMON Tools Lite] E:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: An OneNote s&enden - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O8 - Extra context menu item: Nach Microsoft E&xel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - E:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - E:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: @E:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @E:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programs\PartyGaming\PartyCasino\RunApp.exe File not found O9 - Extra 'Tools' menuitem : PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Programs\PartyGaming\PartyCasino\RunApp.exe File not found O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - D:\nvidia\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - E:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - E:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - E:\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O30 - LSA: Security Packages - (pku2u) - E:\Windows\System32\pku2u.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.12.12 13:31:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{3e642e21-7b90-11df-9949-0003c983c6a3}\Shell - "" = AutoRun O33 - MountPoints2\{3e642e21-7b90-11df-9949-0003c983c6a3}\Shell\AutoRun\command - "" = K:\AutoStart.exe -- File not found O33 - MountPoints2\{a402ce27-23cc-11df-af89-0003c983c6a3}\Shell - "" = AutoRun O33 - MountPoints2\{a402ce27-23cc-11df-af89-0003c983c6a3}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.08.11 17:44:11 | 000,197,632 | ---- | C] (Intel(R) Corporation) -- E:\Windows\System32\ir32_32.dll [2010.08.11 17:44:11 | 000,082,944 | ---- | C] (Radius Inc.) -- E:\Windows\System32\iccvid.dll [2010.08.11 17:44:11 | 000,037,376 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\rtutils.dll [2010.08.11 17:44:09 | 003,955,080 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntkrnlpa.exe [2010.08.11 17:44:08 | 003,899,784 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntoskrnl.exe [2010.08.11 17:43:59 | 001,638,912 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb [2010.08.11 17:43:59 | 000,606,208 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mstime.dll [2010.08.11 17:43:59 | 000,381,440 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iedkcs32.dll [2010.08.11 17:43:59 | 000,185,856 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iepeers.dll [2010.08.11 17:43:59 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll [2010.08.11 17:43:59 | 000,064,512 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeedsbs.dll [2010.08.11 17:43:59 | 000,048,128 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll [2010.08.11 17:43:59 | 000,012,800 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeedssync.exe [2010.08.11 17:43:08 | 002,326,016 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys [2010.08.10 11:11:15 | 000,000,000 | ---D | C] -- E:\Users\Rolf\AppData\Roaming\Thunderbird [2010.08.10 11:11:15 | 000,000,000 | ---D | C] -- E:\Users\Rolf\AppData\Local\Thunderbird [2010.08.06 23:08:26 | 000,880,912 | ---- | C] (Microsoft Corporation) -- E:\Windows\WM8EUTIL.exe [2010.08.06 23:08:26 | 000,000,000 | ---D | C] -- E:\Program Files\CD Audio MP3 Converter [2010.08.06 23:03:14 | 000,000,000 | ---D | C] -- E:\Users\Rolf\Documents\AltoMP3 [2010.08.06 23:03:13 | 000,000,000 | ---D | C] -- E:\ProgramData\TEMP [2010.07.29 18:37:33 | 000,000,000 | ---D | C] -- E:\Users\Rolf\Documents\Neuer Ordner [2010.07.24 12:03:15 | 000,000,000 | ---D | C] -- E:\ProgramData\FarmFrenzy3_Arctica [2010.07.24 12:01:50 | 000,000,000 | ---D | C] -- E:\Windows\System32\Adobe [2010.07.23 18:34:45 | 000,000,000 | ---D | C] -- E:\ProgramData\HoverBee Studios [2010.07.23 18:30:41 | 000,000,000 | ---D | C] -- E:\Users\Rolf\AppData\Roaming\Settlement. Colossus [2010.07.17 15:44:20 | 000,000,000 | -HSD | C] -- E:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} [2010.07.17 00:35:42 | 000,093,504 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\QTW16DEL.EXE [2010.07.17 00:35:19 | 000,017,536 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\VIEWENU.DLL [2010.07.17 00:35:19 | 000,016,928 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\PLAYENU.DLL [2010.07.17 00:35:14 | 000,061,568 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\VIEWER.EXE [2010.07.17 00:35:10 | 000,074,496 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\PLAYER.EXE [2010.07.17 00:35:00 | 000,259,280 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTW16.CPL [2010.07.17 00:35:00 | 000,005,520 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\TSENG.QTC [2010.07.17 00:34:56 | 000,007,440 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\ATIVIDEO.QTC [2010.07.17 00:34:56 | 000,005,264 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\CIRRUS.QTC [2010.07.17 00:34:51 | 000,031,952 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\DHIO_DH.QTC [2010.07.17 00:34:51 | 000,004,176 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTNOTIFY.EXE [2010.07.17 00:34:47 | 000,027,152 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTVHDW.QTC [2010.07.17 00:34:47 | 000,008,304 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTHNDLR.DLL [2010.07.17 00:34:42 | 000,073,712 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTOLE.DLL [2010.07.17 00:34:37 | 000,029,280 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTMOVIE.VBX [2010.07.17 00:34:37 | 000,015,232 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTPIC.VBX [2010.07.17 00:34:33 | 000,039,936 | R--- | C] (Intel(R) Corporation) -- E:\Windows\System\QTIYVU9.QTC [2010.07.17 00:34:33 | 000,011,152 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\REELMGIC.QTC [2010.07.17 00:34:28 | 000,064,432 | R--- | C] (Intel(R) Corporation) -- E:\Windows\System\IV32QT16.QTC [2010.07.17 00:34:23 | 000,058,544 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTRT21.QTC [2010.07.17 00:34:23 | 000,028,912 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTJPEG.QTC [2010.07.17 00:34:19 | 000,165,264 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTSMC.QTC [2010.07.17 00:34:14 | 000,201,088 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTRPZA.QTC [2010.07.17 00:34:10 | 000,093,376 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTRLE.QTC [2010.07.17 00:34:10 | 000,007,952 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTRAW.QTC [2010.07.17 00:34:05 | 000,429,424 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTIM.DLL [2010.07.17 00:34:00 | 000,312,640 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTCVID.QTC [2010.07.17 00:33:56 | 000,024,096 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\NAVG.QTC [2010.07.17 00:33:51 | 000,111,664 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QCMC.QTC [2010.07.17 00:33:47 | 000,014,544 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTIMCMGR.DLL [2010.07.17 00:33:47 | 000,004,320 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\MCIQTENU.DLL [2010.07.17 00:33:42 | 000,043,504 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\MCIQTW.DRV [2010.07.17 00:33:42 | 000,007,488 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\System\QTOLD.QTC [2010.07.17 00:33:37 | 002,037,248 | R--- | C] (Apple Computer, Inc.) -- E:\Windows\QTINSTAL.EXE [2010.07.16 22:42:07 | 000,000,000 | ---D | C] -- E:\Program Files\MultiLingua [2010.07.16 19:51:59 | 000,000,000 | ---D | C] -- E:\Program Files\Uniblue [2010.07.16 19:48:32 | 014,890,280 | ---- | C] (Uniblue Systems Ltd ) -- E:\Users\Rolf\Desktop\powersuite.exe [2010.07.16 19:26:55 | 000,000,000 | ---D | C] -- E:\ProgramData\Uniblue [2010.07.16 19:15:15 | 000,000,000 | ---D | C] -- E:\Users\Rolf\AppData\Roaming\Uniblue [2010.07.16 15:49:11 | 000,000,000 | ---D | C] -- E:\Program Files\Cheatbook 12.2009 ========== Files - Modified Within 30 Days ========== [2010.08.13 18:53:30 | 006,815,744 | -HS- | M] () -- E:\Users\Rolf\NTUSER.DAT [2010.08.13 18:48:07 | 000,001,096 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010.08.13 14:53:28 | 000,023,552 | ---- | M] () -- E:\Users\Rolf\Documents\Arbeitszeugnis Rolf 1.doc [2010.08.13 12:41:09 | 000,013,536 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.08.13 12:41:09 | 000,013,536 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.08.13 12:32:35 | 000,001,092 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010.08.13 12:32:26 | 000,000,006 | -H-- | M] () -- E:\Windows\tasks\SA.DAT [2010.08.13 12:32:19 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat [2010.08.13 12:32:09 | 2415,267,840 | -HS- | M] () -- E:\hiberfil.sys [2010.08.12 23:29:35 | 003,215,533 | -H-- | M] () -- E:\Users\Rolf\AppData\Local\IconCache.db [2010.08.11 22:48:52 | 000,002,290 | ---- | M] () -- E:\Users\Public\Desktop\Google Chrome.lnk [2010.08.11 17:56:37 | 000,429,256 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT [2010.08.10 19:30:43 | 000,173,280 | ---- | M] () -- E:\Users\Rolf\Documents\Mappe1.pdf [2010.08.10 11:11:22 | 000,000,000 | ---- | M] () -- E:\Windows\nsreg.dat [2010.08.06 23:34:28 | 000,000,666 | ---- | M] () -- E:\Users\Public\Desktop\Winamp.lnk [2010.08.06 23:08:28 | 000,000,966 | ---- | M] () -- E:\Users\Rolf\Desktop\CD Audio MP3 Converter.lnk [2010.07.29 16:26:58 | 001,507,106 | ---- | M] () -- E:\Windows\System32\PerfStringBackup.INI [2010.07.29 16:26:58 | 000,659,312 | ---- | M] () -- E:\Windows\System32\perfh007.dat [2010.07.29 16:26:58 | 000,619,252 | ---- | M] () -- E:\Windows\System32\perfh009.dat [2010.07.29 16:26:58 | 000,131,444 | ---- | M] () -- E:\Windows\System32\perfc007.dat [2010.07.29 16:26:58 | 000,107,572 | ---- | M] () -- E:\Windows\System32\perfc009.dat [2010.07.29 08:30:49 | 000,197,632 | ---- | M] (Intel(R) Corporation) -- E:\Windows\System32\ir32_32.dll [2010.07.29 08:30:34 | 000,082,944 | ---- | M] (Radius Inc.) -- E:\Windows\System32\iccvid.dll [2010.07.17 18:12:56 | 000,000,057 | ---- | M] () -- E:\Windows\QTW.INI [2010.07.17 15:28:13 | 000,114,792 | ---- | M] () -- E:\Users\Rolf\AppData\Local\GDIPFONTCACHEV1.DAT [2010.07.17 00:35:52 | 000,000,030 | ---- | M] () -- E:\Windows\RESULT.QTW [2010.07.17 00:35:42 | 000,000,550 | ---- | M] () -- E:\Windows\WININI.QTW [2010.07.17 00:35:42 | 000,000,219 | ---- | M] () -- E:\Windows\SYSINI.QTW [2010.07.16 22:42:20 | 000,000,277 | ---- | M] () -- E:\Windows\inform.ini [2010.07.16 22:41:16 | 000,000,764 | ---- | M] () -- E:\Users\Rolf\Desktop\CCleaner.lnk [2010.07.16 19:51:55 | 000,000,732 | ---- | M] () -- E:\Users\Public\Desktop\PowerSuite.lnk [2010.07.16 19:48:58 | 014,890,280 | ---- | M] (Uniblue Systems Ltd ) -- E:\Users\Rolf\Desktop\powersuite.exe [2010.07.16 15:49:13 | 000,001,036 | ---- | M] () -- E:\Users\Rolf\Desktop\Cheatbook 12.2009.lnk [2010.07.16 15:49:12 | 000,000,550 | ---- | M] () -- E:\Windows\win.ini ========== Files Created - No Company Name ========== [2010.08.13 14:53:27 | 000,023,552 | ---- | C] () -- E:\Users\Rolf\Documents\Arbeitszeugnis Rolf 1.doc [2010.08.10 19:30:40 | 000,173,280 | ---- | C] () -- E:\Users\Rolf\Documents\Mappe1.pdf [2010.08.10 11:11:22 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat [2010.08.06 23:08:28 | 000,000,966 | ---- | C] () -- E:\Users\Rolf\Desktop\CD Audio MP3 Converter.lnk [2010.07.17 00:35:42 | 000,000,550 | ---- | C] () -- E:\Windows\WININI.QTW [2010.07.17 00:35:42 | 000,000,219 | ---- | C] () -- E:\Windows\SYSINI.QTW [2010.07.17 00:35:42 | 000,000,057 | ---- | C] () -- E:\Windows\QTW.INI [2010.07.17 00:35:38 | 000,036,412 | R--- | C] () -- E:\Windows\VIEWENU.HLP [2010.07.17 00:35:33 | 000,067,415 | R--- | C] () -- E:\Windows\PLAYENU.HLP [2010.07.17 00:35:28 | 000,881,787 | R--- | C] () -- E:\Windows\SAMPLE.MOV [2010.07.17 00:35:23 | 000,043,875 | R--- | C] () -- E:\Windows\MCENU.HLP [2010.07.17 00:35:14 | 000,010,112 | R--- | C] () -- E:\Windows\READ_QTW.WRI [2010.07.17 00:35:05 | 000,175,135 | R--- | C] () -- E:\Windows\System\QTWCP.HLP [2010.07.16 22:42:33 | 000,000,030 | ---- | C] () -- E:\Windows\RESULT.QTW [2010.07.16 22:42:20 | 000,000,277 | ---- | C] () -- E:\Windows\inform.ini [2010.07.16 22:41:16 | 000,000,764 | ---- | C] () -- E:\Users\Rolf\Desktop\CCleaner.lnk [2010.07.16 19:51:55 | 000,000,732 | ---- | C] () -- E:\Users\Public\Desktop\PowerSuite.lnk [2010.07.16 15:49:13 | 000,001,036 | ---- | C] () -- E:\Users\Rolf\Desktop\Cheatbook 12.2009.lnk [2010.03.16 20:47:02 | 000,819,200 | ---- | C] () -- E:\Windows\System32\xvidcore.dll [2010.03.16 20:47:01 | 000,180,224 | ---- | C] () -- E:\Windows\System32\xvidvfw.dll [2010.03.16 20:42:43 | 000,116,224 | ---- | C] () -- E:\Windows\System32\pdfcmnnt.dll [2010.03.07 19:55:29 | 000,000,066 | ---- | C] () -- E:\Windows\Ulead32.ini [2010.02.27 20:29:25 | 000,281,760 | ---- | C] () -- E:\Windows\System32\drivers\atksgt.sys [2010.02.27 20:29:25 | 000,025,888 | ---- | C] () -- E:\Windows\System32\drivers\lirsgt.sys [2010.02.27 20:16:17 | 000,691,696 | ---- | C] () -- E:\Windows\System32\drivers\sptd.sys [2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- E:\Windows\System32\BthpanContextHandler.dll [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\System32\BWContextHandler.dll [2008.10.07 10:13:30 | 000,197,912 | ---- | C] () -- E:\Windows\System32\physxcudart_20.dll [2008.10.07 10:13:22 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelTraditionalChinese.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelSwedish.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelSpanish.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelSimplifiedChinese.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelPortugese.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelKorean.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelJapanese.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelGerman.dll [2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- E:\Windows\System32\AgCPanelFrench.dll [2004.08.13 10:56:20 | 000,005,810 | ---- | C] () -- E:\Windows\System32\drivers\ASACPI.sys [2002.10.06 20:42:57 | 000,237,568 | ---- | C] () -- E:\Windows\System32\OggDS.dll [2002.10.05 01:04:25 | 000,921,600 | ---- | C] () -- E:\Windows\System32\vorbisenc.dll [2002.10.05 01:04:24 | 000,188,416 | ---- | C] () -- E:\Windows\System32\vorbis.dll [2002.10.05 01:04:17 | 000,045,056 | ---- | C] () -- E:\Windows\System32\ogg.dll < End of report > |
13.08.2010, 18:03 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehrZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
13.08.2010, 22:31 | #5 |
| PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Ok noch einmal jetzt das neueste Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4425 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 13.08.2010 23:11:06 mbam-log-2010-08-13 (23-11-06).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Durchsuchte Objekte: 388584 Laufzeit: 3 Stunde(n), 19 Minute(n), 35 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
14.08.2010, 17:14 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Das ist alles unauffällig. Beachte zum langsamen PC mal diesen Artikel => http://www.trojaner-board.de/71631-p...samer-tun.html
__________________ --> PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr |
20.08.2010, 11:40 | #7 |
| PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Seit eben ca. 2 Stunden her, spielt der PC komplett verrückt. Auf einmal zeige der PC heute morgen folgende Meldung: Kritischer Fehler. Windows 7 wird in einer Minute neu gestartet. Beim Neustart zeigt er diverse Meldungen bezüglich Antivir vonwegen nicht aktiviert, mit Virus soundso infected, aber alles so schnell nacheinander, daß eine genaue Angabe sogut wie unmöglich ist. Außerdem läuft ein Programm mit dem Namen Security Scan welches sich in der kurzen Zeit nicht abschalten, bzw nachvollziehen lässt. Wer weiß Rat? Habe bereits einen Antivirenscan im Abgesicherten Modus durchgeführt und keine Fehler finden können. |
21.08.2010, 10:31 | #8 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehrZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
21.08.2010, 10:57 | #9 |
| PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr Ist schon Ok. War Virus mit dem Namen ilzda. Mir wurde aber schon durch Markus G geholfen. Vielen Dank |
22.08.2010, 18:50 | #10 | |
Administrator /// technical service | PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr hier gehts weiter: http://www.trojaner-board.de/89767-e...inute-neu.html Zitat:
|
Themen zu PC wird immer langsamer - Funkmaus und die Tastatur funktionieren zum Teil nicht mehr |
plug-in, speedupmypc |