Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: ebenfalls problem mit goingonearth

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 26.07.2011, 13:00   #1
vegaman
 
ebenfalls problem mit goingonearth - Standard

ebenfalls problem mit goingonearth



so. tach!

ich hatte ebenfalls das problem mit dem google redirect auf goingonearth (logs aus Malwarebytes sind angehängt). nachdem ich das nun soweit bereinigen konnte, bleibt noch drei dateien übrig, die als Spyware.Passwords.XGen erkannt wurden, zwar gelöscht werden, aber hartnäckig wiederkommen.


das ist die log von gestern. ich hab heute nochmal die datenbank aktualisiert und einen neuen scan gemacht. dieser blieb ergebnislos.

danke schonma'.

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Datenbank Version: 7276

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25.07.2011 23:29:36
mbam-log-2011-07-25 (23-29-36).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 315758
Laufzeit: 1 Stunde(n), 2 Minute(n), 56 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 6
Infizierte Registrierungswerte: 26
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 17

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBA123C3-A500-90BD-A820-04B53A2C8952} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\8DDYX0ZBPZ (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XMZH42I4GI (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> Value: WINID -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Value: idstrf -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Value: NoFolderOptions -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies (Backdoor.HMCPol.Gen) -> Value: Policies -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdater (Backdoor.Agent) -> Value: winupdater -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\8DDYX0ZBPZ (Trojan.FakeAlert.SA) -> Value: 8DDYX0ZBPZ -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12CFG214-K641-12SF-N85P (Trojan.SpyEyes) -> Value: 12CFG214-K641-12SF-N85P -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mqqyc (Trojan.Agent) -> Value: Mqqyc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlpsc (Trojan.Downloader.Gen) -> Value: Lvmciejlpsc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlprc (Trojan.Downloader.Gen) -> Value: Lvmciejlprc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlmc (Trojan.Downloader.Gen) -> Value: Lvmciejlmc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlo+ (Trojan.Downloader.Gen) -> Value: Lvmciejlo+ -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlqc (Trojan.Downloader.Gen) -> Value: Lvmciejlqc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlhb (Trojan.Downloader.Gen) -> Value: Lvmciejlhb -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mquxe (Trojan.Downloader) -> Value: Mquxe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4Y3Y0C3AZF7XXHYEUIHN (Trojan.SpyEyes) -> Value: 4Y3Y0C3AZF7XXHYEUIHN -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mqsuc (Trojan.Agent) -> Value: Mqsuc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlppf (Trojan.Downloader.Gen) -> Value: Lvmciejlppf -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqrMc (Trojan.Downloader) -> Value: MqrMc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlpe (Trojan.Agent) -> Value: Lvmciejlpe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlqvc (Trojan.Agent) -> Value: Lvmciejlqvc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mqqsc (Trojan.Downloader) -> Value: Mqqsc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlud (Trojan.Downloader.Gen) -> Value: Lvmciejlud -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Lvmciejlhkc (Trojan.Downloader.Gen) -> Value: Lvmciejlhkc -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Rxogetubetogum (Trojan.Agent.U) -> Value: Rxogetubetogum -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\XMZH42I4GI (Trojan.FakeAlert.SA) -> Value: XMZH42I4GI -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Users\dude\AppData\Local\winsvchost.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\dude\AppData\Local\wlan.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\dude\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\00NI1S1G\fun2[1].exe (Trojan.VirTool) -> Quarantined and deleted successfully.
c:\Users\dude\AppData\LocalLow\Sun\Java\deployment\cache\6.0\10\430ab8a-229dfef9 (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\dude\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\rkdviphc.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Windows\explorermgr.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Windows\Temp\AE67.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Windows\Temp\B9BD.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Windows\Temp\BF0A.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Windows\Temp\jpxtodljlmmuayth.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\program files\win\o.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\program files\win\p.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\jeljyxam\rkdviphc.exe (Spyware.Passwords.XGen) -> Delete on reboot.
c:\program files\protector suite ql\psqltraymgr.exe (Spyware.Passwords.XGen) -> Not selected for removal.
c:\program files\protector suite ql\upeksvrmgr.exe (Spyware.Passwords.XGen) -> Not selected for removal.
c:\program files\Samsung\AllShare\allsharemgr.exe (Spyware.Passwords.XGen) -> Not selected for removal.
c:\program files\Samsung\AllShare\allsharedms\wiselinkpromgr.exe (Spyware.Passwords.XGen) -> Not selected for removal.


----------------------

custom scan log vom otl...:

Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

1,99 Gb Total Physical Memory | 1,17 Gb Available Physical Memory | 58,54% Memory free
3,98 Gb Paging File | 3,04 Gb Available in Paging File | 76,36% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 203,59 Gb Total Space | 44,65 Gb Free Space | 21,93% Space Free | Partition Type: NTFS

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.07.25 23:49:51 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\dude\Downloads\OTL.exe
PRC - [2011.07.06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.05.24 13:44:40 | 007,237,024 | ---- | M] () -- C:\Programme\Samsung\AllShare\AllShareDMS\WiselinkPro.exe
PRC - [2011.05.24 13:44:34 | 000,428,088 | ---- | M] () -- C:\Programme\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe
PRC - [2011.05.24 13:42:54 | 000,250,768 | ---- | M] (Samsung) -- C:\Programme\Samsung\AllShare\AllShareAgent.exe
PRC - [2011.03.31 09:53:04 | 000,840,512 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Pro\DTAgent.exe
PRC - [2011.03.31 09:52:36 | 000,382,784 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2010.10.25 11:03:52 | 000,217,088 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2010.07.07 07:55:10 | 001,154,880 | ---- | M] (Ghisler Software GmbH) -- C:\Programme\totalcmd\TOTALCMD.EXE
PRC - [2009.07.14 03:17:29 | 000,673,048 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.07.14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2008.05.28 16:06:02 | 006,144,000 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.03.28 20:47:34 | 000,021,504 | ---- | M] (UPEK Inc.) -- C:\Programme\Protector Suite QL\upeksvr.exe
PRC - [2007.03.28 20:30:18 | 000,053,776 | ---- | M] (UPEK Inc.) -- C:\Programme\Protector Suite QL\psqltray.exe


========== Modules (SafeList) ==========

MOD - [2011.07.25 23:49:51 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\dude\Downloads\OTL.exe
MOD - [2009.07.14 03:15:42 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msacm32.dll
MOD - [2009.07.14 03:14:51 | 002,175,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\AppPatch\AcGenral.dll
MOD - [2009.07.14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011.07.06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.05.24 13:44:40 | 007,237,024 | ---- | M] () [Auto | Running] -- C:\Programme\Samsung\AllShare\AllShareDMS\WiselinkPro.exe -- (SamsungAllShare)
SRV - [2011.05.24 13:44:30 | 000,022,464 | ---- | M] (Samsung Electronics) [Auto | Stopped] -- C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer)
SRV - [2011.01.30 22:12:53 | 000,435,008 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2011.01.14 09:56:36 | 001,294,848 | ---- | M] (Synaptics, Inc.) [Disabled | Stopped] -- C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe -- (ScrybeUpdater)
SRV - [2010.10.25 11:03:52 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010.07.06 13:23:40 | 001,051,968 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010.01.21 18:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2009.08.26 21:09:40 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2011.07.06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.04.22 23:02:13 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010.10.25 11:03:52 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010.05.10 20:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.02.24 14:41:50 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010.02.17 20:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009.11.09 05:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009.07.14 00:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009.07.14 00:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2009.07.10 06:44:52 | 000,122,880 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
DRV - [2008.02.14 15:56:02 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007.04.11 10:40:14 | 000,046,592 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ESD7SK.sys -- (ESDCR)
DRV - [2007.04.11 10:40:10 | 000,063,488 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ESM7SK.sys -- (ESMCR)
DRV - [2007.04.11 10:40:06 | 000,067,584 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\EMS7SK.sys -- (EMSCR)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.belinea.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\dude\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\dude\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4C9C9FEF-64CD-44C6-B97B-5A6A1F986CBA}: C:\Users\dude\AppData\Local\{4C9C9FEF-64CD-44C6-B97B-5A6A1F986CBA}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.07.25 19:57:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.26 10:31:50 | 000,000,000 | ---D | M]

[2011.06.26 22:17:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dude\AppData\Roaming\mozilla\Extensions
[2011.06.26 22:17:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dude\AppData\Roaming\mozilla\Extensions\uploadr@flickr.com
[2011.07.07 18:18:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dude\AppData\Roaming\mozilla\Firefox\Profiles\kjia7it2.default\extensions
[2011.05.24 11:37:42 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.01.31 01:07:37 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011.01.31 01:07:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011.01.31 01:07:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011.07.25 19:57:45 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011.07.26 01:49:17 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [AllShareAgent] C:\Programme\Samsung\AllShare\AllShareAgent.exe (Samsung)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\jeljyxam\rkdviphc.exe) - C:\Programme\jeljyxam\rkdviphc.exe ()
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Users\dude\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\dude\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Scrybe.lnk - C:\Windows\Installer\{13061CAA-0284-4F9A-B460-3D4699575B35}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe - (Acresso Software Inc.)
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

Drivers32: msacm.avis - C:\Windows\System32\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011.07.26 09:59:23 | 000,000,000 | ---D | C] -- C:\Program Files\jeljyxam
[2011.07.26 01:58:14 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011.07.26 01:52:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.07.26 01:52:01 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.07.26 01:52:01 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Local\temp
[2011.07.26 01:35:18 | 000,000,000 | ---D | C] -- C:\Avenger
[2011.07.26 00:03:08 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.07.26 00:03:08 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.07.26 00:03:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.07.26 00:03:02 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.07.26 00:02:58 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.07.25 23:51:47 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.07.25 23:45:43 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.07.25 21:30:39 | 000,000,000 | ---D | C] -- C:\Windows\System32\AllShareUpload
[2011.07.25 19:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\aI00000CpDdC00000
[2011.07.25 18:48:16 | 000,000,000 | ---D | C] -- C:\Program Files\win
[2011.07.24 22:09:48 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Roaming\Apple Computer
[2011.07.24 22:09:48 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Local\Apple Computer
[2011.07.24 22:09:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.07.24 22:09:34 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2011.07.24 22:09:00 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.07.24 22:08:59 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.07.24 22:08:59 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011.07.24 22:07:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.07.24 22:07:37 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011.07.24 22:07:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011.07.24 22:07:14 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Local\Apple
[2011.07.24 22:07:02 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011.07.24 22:05:57 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011.07.24 22:05:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011.07.24 22:05:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011.07.19 15:42:54 | 000,000,000 | ---D | C] -- C:\Users\dude\Documents\My Videos
[2011.07.11 21:13:21 | 000,000,000 | ---D | C] -- C:\Users\dude\Documents\SelfMV
[2011.07.05 20:43:05 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011.06.30 21:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2011.06.26 22:24:41 | 000,000,000 | R--D | C] -- C:\Users\dude\Dropbox
[2011.06.26 22:22:13 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Roaming\Dropbox
[2011.06.26 22:17:58 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Roaming\Flickr
[2011.06.26 22:17:58 | 000,000,000 | ---D | C] -- C:\Users\dude\AppData\Local\Flickr
[2010.02.04 00:00:00 | 000,139,264 | ---- | C] ( ) -- C:\Windows\sipr3260.dll
[2009.09.11 14:04:46 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\dude\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011.07.26 10:06:44 | 000,012,912 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.07.26 10:06:44 | 000,012,912 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.07.26 10:04:50 | 000,699,274 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.07.26 10:04:50 | 000,654,552 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.07.26 10:04:50 | 000,148,478 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.07.26 10:04:50 | 000,121,424 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.07.26 09:58:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.07.26 09:58:47 | 1603,706,880 | -HS- | M] () -- C:\hiberfil.sys
[2011.07.26 01:49:17 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.07.26 01:17:41 | 699,797,720 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.07.25 20:41:36 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2011.07.25 20:24:51 | 000,011,323 | -H-- | M] () -- C:\treeinfo.wc
[2011.07.25 18:50:03 | 000,066,048 | RHS- | M] () -- C:\Windows\System32\NOISEU.dll
[2011.07.12 16:41:20 | 000,000,705 | ---- | M] () -- C:\Users\dude\Documents\+491704919319_Guten.vmg
[2011.07.06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.07.06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.07.05 20:43:15 | 000,001,990 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk

========== Files Created - No Company Name ==========

[2011.07.26 01:17:41 | 699,797,720 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.07.26 00:03:08 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.07.26 00:03:08 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.07.26 00:03:08 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.07.26 00:03:08 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.07.26 00:03:08 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.07.25 20:41:36 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.07.25 18:50:01 | 000,066,048 | RHS- | C] () -- C:\Windows\System32\NOISEU.dll
[2011.07.24 22:07:03 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011.07.12 16:41:20 | 000,000,705 | ---- | C] () -- C:\Users\dude\Documents\+491704919319_Guten.vmg
[2011.06.30 21:34:48 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2011.06.30 21:34:48 | 000,121,232 | ---- | C] () -- C:\Windows\System32\IScrNB.bmp
[2011.06.26 22:17:27 | 000,001,949 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flickr Uploadr.lnk
[2011.02.15 00:11:37 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011.02.02 13:01:00 | 000,006,656 | ---- | C] () -- C:\Users\dude\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.02.01 21:20:32 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2011.01.31 18:15:34 | 001,032,266 | ---- | C] () -- C:\Windows\System32\libmmd.dll
[2011.01.30 22:57:19 | 000,000,410 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.01.29 17:00:22 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.01.29 17:00:22 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.01.29 17:00:22 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.01.29 17:00:22 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2010.12.29 02:23:14 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010.12.19 02:47:03 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010.12.19 02:47:03 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.11.09 11:47:48 | 000,000,065 | ---- | C] () -- C:\Users\dude\AppData\Roaming\f54616158.bat
[2010.03.15 05:31:48 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010.03.14 18:16:09 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2010.01.01 19:12:42 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2010.01.01 19:12:42 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2010.01.01 19:12:42 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2009.10.14 19:23:33 | 000,021,628 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2009.09.23 12:16:08 | 002,050,952 | ---- | C] () -- C:\Windows\System32\igkrng400.bin
[2009.09.11 14:06:29 | 000,001,044 | ---- | C] () -- C:\Users\dude\AppData\Roaming\vso_ts_preview.xml
[2009.09.11 14:04:46 | 000,007,887 | ---- | C] () -- C:\Users\dude\AppData\Roaming\pcouffin.cat
[2009.09.11 14:04:46 | 000,001,144 | ---- | C] () -- C:\Users\dude\AppData\Roaming\pcouffin.inf
[2009.07.14 10:47:43 | 000,699,274 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,148,478 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 002,360,848 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,654,552 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,121,424 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 02:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.07.10 06:44:40 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009.04.01 20:46:08 | 000,017,928 | ---- | C] () -- C:\Windows\System32\X3DAudio1_2.dll
[2008.11.20 15:10:23 | 000,028,672 | ---- | C] () -- C:\Windows\System32\MFC_InstDrvDLL.dll
[2008.11.20 13:43:32 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2007.02.05 20:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI

========== LOP Check ==========

[2011.02.24 13:16:35 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\.minecraft
[2011.01.31 18:35:05 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Boilsoft
[2009.03.08 18:53:48 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DAEMON Tools
[2011.07.25 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DAEMON Tools Lite
[2011.07.25 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DAEMON Tools Pro
[2011.07.25 15:23:26 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Dropbox
[2011.07.26 10:44:49 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Facebook
[2011.06.26 22:17:58 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Flickr
[2010.03.20 20:12:54 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\GetRightToGo
[2011.01.31 01:21:20 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\GHISLER
[2011.05.30 22:08:20 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\gtk-2.0
[2011.01.31 01:21:20 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\ICQ
[2011.01.31 01:21:23 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\ImgBurn
[2011.04.24 18:37:46 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\ImTOO
[2011.01.31 01:21:51 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\OpenOffice.org
[2011.01.31 01:21:53 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\pokerth
[2011.01.31 01:21:53 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\runic games
[2011.07.25 15:28:51 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Samsung
[2011.01.31 01:50:51 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Synaptics
[2011.01.31 01:21:56 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\TuneUp Software
[2011.01.31 01:21:58 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Vso
[2011.02.02 13:25:19 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Win7codecs
[2011.01.31 01:21:58 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\X-Chat 2
[2011.03.21 12:40:12 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011.02.24 13:16:35 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\.minecraft
[2011.07.26 00:09:37 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Adobe
[2011.07.24 22:10:23 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Apple Computer
[2011.01.31 01:21:19 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\AVS4YOU
[2011.01.31 18:35:05 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Boilsoft
[2009.03.08 18:53:48 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DAEMON Tools
[2011.07.25 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DAEMON Tools Lite
[2011.07.25 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DAEMON Tools Pro
[2011.02.02 14:28:02 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\DivX
[2011.07.25 15:23:26 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Dropbox
[2011.03.22 15:44:48 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\dvdcss
[2011.07.26 10:44:49 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Facebook
[2011.06.26 22:17:58 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Flickr
[2010.03.20 20:12:54 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\GetRightToGo
[2011.01.31 01:21:20 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\GHISLER
[2011.05.30 22:08:20 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\gtk-2.0
[2011.01.31 01:21:20 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\ICQ
[2011.01.31 01:21:22 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Identities
[2011.01.31 01:21:23 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\ImgBurn
[2011.04.24 18:37:46 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\ImTOO
[2011.01.31 01:21:23 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Macromedia
[2011.01.31 01:21:40 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Malwarebytes
[2009.07.14 10:56:41 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Media Center Programs
[2011.07.25 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Media Player Classic
[2011.01.31 19:41:26 | 000,000,000 | --SD | M] -- C:\Users\dude\AppData\Roaming\Microsoft
[2011.01.31 01:21:50 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Move Networks
[2011.01.31 01:21:50 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Mozilla
[2011.01.31 01:21:51 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\OpenOffice.org
[2011.01.31 01:21:53 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\pokerth
[2011.01.31 01:21:53 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\runic games
[2011.07.25 15:28:51 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Samsung
[2011.05.15 22:00:55 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Skype
[2011.05.15 21:08:05 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\skypePM
[2011.01.31 01:21:56 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\SUPERAntiSpyware.com
[2011.01.31 01:50:51 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Synaptics
[2011.01.31 01:21:56 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\TuneUp Software
[2011.07.25 23:47:15 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Ventrilo
[2011.07.22 13:28:13 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\vlc
[2011.01.31 01:21:58 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Vso
[2011.02.02 13:25:19 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\Win7codecs
[2009.03.08 19:01:39 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\WinRAR
[2011.01.31 01:21:58 | 000,000,000 | ---D | M] -- C:\Users\dude\AppData\Roaming\X-Chat 2

< %APPDATA%\*.exe /s >
[2011.02.09 21:39:21 | 000,246,784 | ---- | M] () -- C:\Users\dude\AppData\Roaming\.minecraft\bin\name.exe
[2010.03.02 17:20:58 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\dude\AppData\Roaming\Facebook\uninstall.exe
[2010.03.12 14:53:25 | 000,144,053 | ---- | M] () -- C:\Users\dude\AppData\Roaming\Move Networks\uninstall.exe
[2010.02.11 21:31:38 | 000,097,216 | ---- | M] () -- C:\Users\dude\AppData\Roaming\Move Networks\ie_bin\MovePlayerUpgrade.exe

< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\ERDNT\cache\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 03:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2008.07.20 17:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\$WINDOWS.~Q\DATA\Windows\System32\drivers\iaStor.sys
[2008.07.20 17:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\OemDrv\IaStor.sys
[2008.07.20 17:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\drivers\iaStor.sys
[2008.07.20 17:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_b713da3dc2c70b47\iaStor.sys
[2008.07.20 17:44:44 | 000,324,120 | ---- | M] (Intel Corporation) MD5=707C1692214B1C290271067197F075F6 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_916ee8d64bb718d0\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\drivers\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\ERDNT\cache\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll

< MD5 for: USER32.DLL >
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\ERDNT\cache\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\System32\user32.dll
[2009.07.14 03:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=34B7E222E81FAFA885F0C5F2CFA56861 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll

< MD5 for: USERINIT.EXE >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WININIT.EXE >
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

< MD5 for: WINLOGON.EXE >
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\ERDNT\cache\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\System32\winlogon.exe
[2009.07.14 03:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WS2IFSL.SYS >
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 01:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2011.07.25 18:50:03 | 000,066,048 | RHS- | M] () Unable to obtain MD5 -- C:\Windows\system32\NOISEU.dll

< End of report >

Geändert von vegaman (26.07.2011 um 13:15 Uhr) Grund: custom scan log von otl angehängt.

Alt 26.07.2011, 14:22   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
ebenfalls problem mit goingonearth - Standard

ebenfalls problem mit goingonearth



Zitat:
[2011.07.26 00:03:08 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.07.26 00:03:08 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.07.26 00:03:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.07.26 00:03:02 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.07.26 00:02:58 | 000,000,000 | ---D | C] -- C:\Qoobox
Warum führst du CF ohne Anweisung aus und lässt dann noch das Log weg?
__________________

__________________

Antwort

Themen zu ebenfalls problem mit goingonearth
4d36e972-e325-11ce-bfc1-08002be10318, anti-malware, appdata, backdoor.agent, backdoor.hmcpol.gen, c:\windows\system32\rundll32.exe, dc3_fexec, google redirect, hijack.folderoptions, hijack.zones, malware.trace, nodrives, nvstor.sys, plug-in, poweriso, pum.hijack.regedit, spyware.passwords, spyware.passwords.xgen, start menu, trojan.agent, trojan.agent.u, trojan.downloader, trojan.downloader.gen, trojan.fakealert, trojan.fakealert.sa, trojan.spyeyes, trojan.virtool, wrapper




Ähnliche Themen: ebenfalls problem mit goingonearth


  1. ebenfalls Problem mit http://static.icmapp.com/blank2.html#....
    Log-Analyse und Auswertung - 27.01.2014 (19)
  2. Ebenfalls ein Problem mit dem Verschlüsselungstrojaner
    Log-Analyse und Auswertung - 04.05.2012 (1)
  3. Ebenfalls Problem mit "50 Euro Virus"
    Log-Analyse und Auswertung - 14.02.2012 (11)
  4. Goingonearth-Infektion
    Plagegeister aller Art und deren Bekämpfung - 25.08.2011 (39)
  5. Goingonearth Virus problem !
    Log-Analyse und Auswertung - 19.08.2011 (1)
  6. Goingonearth-Virus
    Plagegeister aller Art und deren Bekämpfung - 16.08.2011 (1)
  7. Goingonearth Problem
    Log-Analyse und Auswertung - 28.07.2011 (48)
  8. Goingonearth Problem
    Plagegeister aller Art und deren Bekämpfung - 21.07.2011 (23)
  9. Goingonearth und Sicherheitscenter deaktiviert
    Plagegeister aller Art und deren Bekämpfung - 09.07.2011 (8)
  10. Goingonearth Hijacker
    Log-Analyse und Auswertung - 01.07.2011 (14)
  11. Ebenfalls "Goingonearth" geschädigt!
    Plagegeister aller Art und deren Bekämpfung - 27.05.2011 (13)
  12. Ebenfalls "TR/Kazy.mekml.1" Problem
    Log-Analyse und Auswertung - 12.05.2011 (3)
  13. goingonearth malware Problem
    Plagegeister aller Art und deren Bekämpfung - 19.04.2011 (20)
  14. Ebenfalls problem mit google
    Log-Analyse und Auswertung - 14.12.2010 (13)
  15. Ebenfalls ein Problem mit TR/AGENT.GX.361
    Plagegeister aller Art und deren Bekämpfung - 17.06.2010 (3)
  16. Ebenfalls Problem mit: TR/Crypt.XPACK.Gen!
    Log-Analyse und Auswertung - 13.06.2009 (0)
  17. Hab ebenfalls ein Problem mit BDS/Agent.ay!!!!
    Plagegeister aller Art und deren Bekämpfung - 06.10.2004 (3)

Zum Thema ebenfalls problem mit goingonearth - so. tach! ich hatte ebenfalls das problem mit dem google redirect auf goingonearth (logs aus Malwarebytes sind angehängt). nachdem ich das nun soweit bereinigen konnte, bleibt noch drei dateien übrig, - ebenfalls problem mit goingonearth...
Archiv
Du betrachtest: ebenfalls problem mit goingonearth auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.