|
Plagegeister aller Art und deren Bekämpfung: Vierenfund : Win32:Cycbot-KI[Trj] bei Avast!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.09.2011, 22:54 | #1 |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Hallo Leute, Habe folgendes Problem: Habe vorhin eine meiner Wöchentlichen Avast! Virenprüfungen gemacht und habe dabei auf meinem Speicher mehrmals den Trojaner : Win32:Cycbot-KI gefunden. Das Komische daran war die angegeben anwendungen hatten zu 90% was mit Gaming und Gaming-Hardware zu tun (Steam.exe,pnkbstra.exe,...) ebenfalls was mich auch verdammt gewundert hat war das dort eine :" avastui.exe und eine avastsvc.exe zu finden waren. Hinter allen ergebnissen fand sich ein "(Kernel32.dll)". Ich weis aber auch nicht was das zu bedeuten hat. Hab natürlich erstmal n bisschen rum gegoogelt und da hieß es dann, nachdem ich :"virus im Ram" eingegeben hab, (glaubich sogar bei euch im Forum) das die meisten "vieren" sich beim booten mit starten oder beim Herunterfahren "verloren" gehen. Also hab ich eben n ReBoot gemacht und nochmal Avast! über den Speicher laufen lassen, immer noch die selben ergebnisse, zu finden waren immer noch avastui.exe und von den vorher gefunden Anwendungen eben nur die die Mitgestartet sind. Nun meine Frage, wie solll ich Vorgehen oder ist das ganze nur ein Fehler von Avast ? (Zusatz: Meine Hardware: ("Eigenbau") AMD Phenom II X4 955/Black Edition (3,2Ghz) Corsair DIMM 8GB DDR3-1333 Kit XFX Readon HD6870 Gigabyte 880GA-UD3H Aerocool E85M 550W Seagate 2 TB) Bedanke mich schonmal fürs Durchlesen. Mfg Benni *EDIT* Sollte noch dazu sagen das ich morgen (Montag : 17.09.11) frühestens ab 18Uhr wieder an den PC wende Also nich wundern wenn kein post von mir kommt... Geändert von BenniDE (25.09.2011 um 23:03 Uhr) |
26.09.2011, 12:43 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast!Zitat:
__________________ |
26.09.2011, 17:48 | #3 |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! [IMG]<script src='hxxp://img33.imageshack.us/shareable/?i=avastprotokoll.png&p=tl' type='text/javascript'></script><noscript></noscript>/[/IMG]
__________________Das ist das Avast! Protokoll von gestern abend. Habe eben nochmal eine Überprüfung gemacht (von Systemlaufwerk und Speicher) dieses mal aber zu meiner Überaschung, kein Fund! Mich verwundert das ganze einbisschen. Hoffe mal das Avast Protokoll reicht zur Fehleranalyse Mfg Benni |
26.09.2011, 19:41 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
26.09.2011, 21:44 | #5 | |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Log Datei von Malewarebytes : Zitat:
werde jetzt noch den ESET online scanner benutzen und den COD 4 Level hack Löschen weil ich den sowieso nicht mehr brauch Mfg Benni |
27.09.2011, 11:00 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast!Zitat:
Du weiß schon, dass du mit diesen Hacks ein dauerhaftes Banning riskierst?
__________________ --> Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! |
27.09.2011, 12:38 | #7 |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Benutz das ding eh nichtmehr seitdem ichs mir in Steam gekauft hab. Und wie siehts jetzt aus , denkt ihr/du das das wirklich nur ein Fehler von Avast war? (ESET läuft noch im hintergrund) |
27.09.2011, 14:15 | #8 |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! ESET sagt das es nichts gefunden hat , deswegen geh ich mal davon aus das ich den log auch nicht mehr posten muss ... Danke für die Hilfe ... Mfg Benni |
27.09.2011, 14:55 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! CustomScan mit OTL Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
27.09.2011, 16:18 | #10 |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Der angeforderte OTl.txt inhalt : OTL Logfile: Code:
ATTFilter OTL logfile created on: 27.09.2011 16:37:22 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Benjamin\Downloads 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 8,00 Gb Total Physical Memory | 6,27 Gb Available Physical Memory | 78,45% Memory free 15,99 Gb Paging File | 14,00 Gb Available in Paging File | 87,51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 244,04 Gb Total Space | 129,16 Gb Free Space | 52,93% Space Free | Partition Type: NTFS Drive F: | 3,73 Gb Total Space | 3,47 Gb Free Space | 93,15% Space Free | Partition Type: FAT32 Computer Name: BENNIPC | User Name: Benjamin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.09.27 16:35:28 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Benjamin\Downloads\OTL.exe PRC - [2011.09.06 22:45:30 | 003,722,416 | ---- | M] (AVAST Software) -- C:\Programme\Avast\AvastUI.exe PRC - [2011.09.06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Programme\Avast\AvastSvc.exe PRC - [2011.08.31 01:19:28 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2011.06.21 11:14:38 | 000,207,872 | ---- | M] () -- B:\Games\Random Stuff\G15-Applets\LCRSirReal\LCDSirReal\LCDSirReal.exe PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011.04.29 21:16:08 | 001,677,096 | ---- | M] (ClanServers Hosting LLC) -- B:\Games\GameTracker\GSInGameService.exe PRC - [2010.09.01 06:26:04 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe PRC - [2010.08.03 09:43:02 | 000,522,824 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech\GamePanel Software\Applets\LCDMedia.exe PRC - [2010.04.14 16:03:46 | 000,275,832 | ---- | M] (Advanced Micro Devices, Inc.) -- B:\Programme\AMD\Fusion Utility for Desktop\FusionUtility2Service.exe PRC - [2010.04.14 16:03:46 | 000,140,160 | ---- | M] (Advanced Micro Devices) -- C:\Program Files (x86)\AMD\Reservation Manager\AMD Reservation Manager.exe ========== Modules (No Company Name) ========== MOD - [2011.06.21 11:14:38 | 000,207,872 | ---- | M] () -- B:\Games\Random Stuff\G15-Applets\LCRSirReal\LCDSirReal\LCDSirReal.exe ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011.09.06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:64bit: - [2011.07.28 23:35:34 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV - [2011.09.22 13:06:40 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011.08.31 01:19:28 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2011.08.08 12:37:10 | 000,168,864 | ---- | M] () [Auto | Running] -- C:\Programme\Common Files\WireHelpSvc.exe -- (WireHelpSvc) SRV - [2011.08.04 14:34:48 | 002,329,480 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- B:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2011.07.28 17:43:58 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service) SRV - [2011.06.08 13:02:00 | 000,633,856 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.04.29 21:16:08 | 001,677,096 | ---- | M] (ClanServers Hosting LLC) [Auto | Running] -- B:\Games\GameTracker\GSInGameService.exe -- (GS In-Game Service) SRV - [2010.04.14 16:03:46 | 000,275,832 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- B:\Programme\AMD\Fusion Utility for Desktop\FusionUtility2Service.exe -- (AMD FusionUtility Service) SRV - [2010.04.14 16:03:46 | 000,140,160 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Program Files (x86)\AMD\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager) SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011.09.06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:64bit: - [2011.09.06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:64bit: - [2011.09.06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:64bit: - [2011.09.06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr) DRV:64bit: - [2011.09.06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:64bit: - [2011.09.06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:64bit: - [2011.08.15 14:32:10 | 000,146,736 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp) DRV:64bit: - [2011.08.09 23:59:07 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:64bit: - [2011.08.08 12:37:02 | 000,161,184 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC) DRV:64bit: - [2011.07.29 00:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2011.07.28 22:54:10 | 000,309,248 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2011.06.07 00:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2011.05.28 00:34:20 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:64bit: - [2011.05.28 00:34:19 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:64bit: - [2011.05.18 10:14:22 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt) DRV:64bit: - [2011.05.18 10:14:20 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev) DRV:64bit: - [2011.05.18 10:14:16 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc) DRV:64bit: - [2011.05.18 10:14:12 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd) DRV:64bit: - [2011.04.18 12:11:38 | 000,025,528 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ESLvnic.sys -- (ESLvnic1) DRV:64bit: - [2011.01.13 13:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2010.12.14 05:54:12 | 000,058,472 | R--- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (TEAM) Realtek Virtual Miniport Driver for Teaming (NDIS 6.0) DRV:64bit: - [2010.12.14 05:54:12 | 000,058,472 | R--- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (RTTEAMPT) Realtek Teaming Protocol Driver (NDIS 6.0) DRV:64bit: - [2010.12.14 05:54:12 | 000,027,136 | R--- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RtNdPt60.sys -- (RtNdPt60) DRV:64bit: - [2010.12.14 05:54:12 | 000,024,064 | R--- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtVlan60.sys -- (VLAN) Realtek Virtual Miniport Driver for VLAN (NDIS 6.2) DRV:64bit: - [2010.12.14 05:54:12 | 000,024,064 | R--- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtVlan60.sys -- (RTVLANPT) Realtek Vlan Protocol Driver (NDIS 6.2) DRV:64bit: - [2010.05.25 05:07:58 | 000,253,728 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService) DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64) DRV:64bit: - [2009.11.23 17:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid) DRV:64bit: - [2009.11.23 17:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum) DRV:64bit: - [2009.09.16 08:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle) DRV:64bit: - [2009.08.21 01:52:10 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21) DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009.07.14 02:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser) DRV:64bit: - [2009.06.17 09:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt) DRV:64bit: - [2009.06.17 09:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt) DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi) DRV:64bit: - [2008.08.28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd) DRV:64bit: - [2006.02.23 11:18:50 | 000,038,912 | ---- | M] (AMD, Inc.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\AmdTools64.sys -- (AmdTools) DRV - [2011.06.24 06:31:02 | 000,055,424 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01) DRV - [2011.05.26 03:20:58 | 000,030,528 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\GVTDrv64.sys -- (GVTDrv64) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 54 D8 E9 19 45 1B CC 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "google.com" FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) FF - HKLM\Software\MozillaPlugins\Adobe Reader: B:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Avast\WebRep\FF [2011.09.14 22:31:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.09.07 00:09:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: B:\Programme\Mozilla Thunderbird\components [2011.08.18 14:00:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: B:\Programme\Mozilla Thunderbird\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011.08.26 20:04:33 | 000,000,000 | ---D | M] [2011.05.26 21:42:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benjamin\AppData\Roaming\mozilla\Extensions [2011.05.26 21:42:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benjamin\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011.07.02 16:26:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benjamin\AppData\Roaming\mozilla\Firefox\Profiles\ogt3nigd.default\extensions [2011.05.28 14:24:44 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Benjamin\AppData\Roaming\mozilla\Firefox\Profiles\ogt3nigd.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011.08.05 16:54:10 | 000,004,140 | ---- | M] () -- C:\Users\Benjamin\AppData\Roaming\Mozilla\Firefox\Profiles\ogt3nigd.default\searchplugins\youtube.xml [2011.08.22 00:57:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2011.09.21 12:58:32 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011.07.03 12:07:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011.06.13 14:38:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011.06.25 13:15:04 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files (x86)\mozilla firefox\extensions\quickstores@quickstores.de [2011.09.14 22:31:57 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST\WEBREP\FF () (No name found) -- C:\USERS\BENJAMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\OGT3NIGD.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI [2011.09.07 00:09:03 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\Avast\aswWebRepIE64.dll (AVAST Software) O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Avast\aswWebRepIE.dll (AVAST Software) O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation) O4 - HKLM..\Run: [avast] C:\Program Files\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [DAEMON Tools Lite] B:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup File not found O4 - HKLM..\RunOnce: [GBTUpd] C:\Program Files (x86)\GIGABYTE\UpdManager\PreRun.exe (PreRun) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Benjamin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Benjamin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Free YouTube Download - C:\Users\Benjamin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Benjamin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.10.10.254 10.10.10.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54FF7843-3361-4EF4-B766-E70B23685877}: DhcpNameServer = 10.10.10.254 10.10.10.1 O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{a241f8f3-c2d2-11e0-9ae6-00ff01000001}\Shell - "" = AutoRun O33 - MountPoints2\{a241f8f3-c2d2-11e0-9ae6-00ff01000001}\Shell\AutoRun\command - "" = E:\setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* MsConfig:64bit - StartUpFolder: C:^Users^Benjamin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk - B:\Programme\OpenOffice.org 3\program\quickstart.exe - () MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: AdobeCS5.5ServiceManager - hkey= - key= - File not found MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - B:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig:64bit - StartUpReg: ESL Wire - hkey= - key= - B:\Games\EslWire\wire.exe (Turtle Entertainment GmbH) MsConfig:64bit - StartUpReg: KPeerNexonEU - hkey= - key= - C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.) MsConfig:64bit - StartUpReg: LogMeIn Hamachi Ui - hkey= - key= - B:\Programme\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) MsConfig:64bit - StartUpReg: NokiaMServer - hkey= - key= - C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia) MsConfig:64bit - StartUpReg: NokiaOviSuite2 - hkey= - key= - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia) MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - B:\Programme\QuickTime\QTTask.exe (Apple Inc.) MsConfig:64bit - StartUpReg: RGSC - hkey= - key= - File not found MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig:64bit - StartUpReg: Steam - hkey= - key= - B:\Games\Steam\steam.exe (Valve Corporation) MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig:64bit - StartUpReg: SwitchBoard - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) MsConfig:64bit - State: "startup" - Reg Error: Key error. SafeBootMin:64bit: AppMgmt - Service SafeBootMin:64bit: Base - Driver Group SafeBootMin:64bit: Boot Bus Extender - Driver Group SafeBootMin:64bit: Boot file system - Driver Group SafeBootMin:64bit: File system - Driver Group SafeBootMin:64bit: Filter - Driver Group SafeBootMin:64bit: HelpSvc - Service SafeBootMin:64bit: PCI Configuration - Driver Group SafeBootMin:64bit: PNP Filter - Driver Group SafeBootMin:64bit: Primary disk - Driver Group SafeBootMin:64bit: sacsvr - Service SafeBootMin:64bit: SCSI Class - Driver Group SafeBootMin:64bit: System Bus Extender - Driver Group SafeBootMin:64bit: vmms - Service SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:64bit: AppMgmt - Service SafeBootNet:64bit: Base - Driver Group SafeBootNet:64bit: Boot Bus Extender - Driver Group SafeBootNet:64bit: Boot file system - Driver Group SafeBootNet:64bit: File system - Driver Group SafeBootNet:64bit: Filter - Driver Group SafeBootNet:64bit: HelpSvc - Service SafeBootNet:64bit: Messenger - Service SafeBootNet:64bit: NDIS Wrapper - Driver Group SafeBootNet:64bit: NetBIOSGroup - Driver Group SafeBootNet:64bit: NetDDEGroup - Driver Group SafeBootNet:64bit: Network - Driver Group SafeBootNet:64bit: NetworkProvider - Driver Group SafeBootNet:64bit: PCI Configuration - Driver Group SafeBootNet:64bit: PNP Filter - Driver Group SafeBootNet:64bit: PNP_TDI - Driver Group SafeBootNet:64bit: Primary disk - Driver Group SafeBootNet:64bit: rdsessmgr - Service SafeBootNet:64bit: sacsvr - Service SafeBootNet:64bit: SCSI Class - Driver Group SafeBootNet:64bit: Streams Drivers - Driver Group SafeBootNet:64bit: System Bus Extender - Driver Group SafeBootNet:64bit: TDI - Driver Group SafeBootNet:64bit: vmms - Service SafeBootNet:64bit: WudfUsbccidDriver - Driver SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: Hamachi2Svc - B:\Programme\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L) Drivers32:64bit: VIDC.HFYU - huffyuv.dll (Disappearing Inc.) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L) Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.09.26 22:48:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET [2011.09.26 20:51:19 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\AppData\Roaming\Malwarebytes [2011.09.26 20:51:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.09.26 20:51:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.09.26 20:51:05 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011.09.26 20:51:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011.09.15 13:36:04 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\Documents\FIFA 12 [2011.09.15 12:25:58 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\VirtualBox VMs [2011.09.15 12:25:38 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\.VirtualBox [2011.09.15 12:01:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox [2011.09.09 12:46:42 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1 [2011.09.07 14:45:27 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield [2011.09.07 14:45:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE [2011.09.07 14:35:07 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM [2011.09.07 14:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2011.09.07 14:34:56 | 000,369,864 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64H.dll [2011.09.07 14:34:56 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64H.dll [2011.09.07 14:34:56 | 000,095,432 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64H.dll [2011.09.07 14:34:56 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64H.dll [2011.09.07 14:34:55 | 000,307,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RH3DHT64.dll [2011.09.07 14:34:55 | 000,307,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RH3DAA64.dll [2011.09.07 14:34:51 | 002,580,824 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll [2011.09.07 14:34:50 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll [2011.09.07 14:34:50 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll [2011.09.07 14:34:50 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll [2011.09.07 14:34:50 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll [2011.09.07 14:34:43 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll [2011.09.07 14:34:43 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll [2011.09.07 14:34:43 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll [2011.09.07 14:34:43 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll [2011.09.07 14:34:42 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll [2011.09.07 14:34:42 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll [2011.09.07 14:34:35 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll [2011.09.07 14:34:35 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll [2011.09.07 14:34:27 | 001,937,312 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll [2011.09.07 14:34:20 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp [2011.08.30 17:19:17 | 000,000,000 | -HSD | C] -- C:\Windows\ftpcache [2011.08.29 19:45:31 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\AppData\Roaming\Kalypso Media [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.09.27 13:34:16 | 000,030,272 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.09.27 13:34:15 | 000,030,272 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.09.27 13:31:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.09.26 22:45:31 | 2145,546,239 | -HS- | M] () -- C:\hiberfil.sys [2011.09.26 21:15:36 | 000,018,216 | ---- | M] () -- C:\Users\Benjamin\Desktop\Nachrichten Präsentation.odt [2011.09.26 20:51:08 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.09.26 18:45:07 | 000,087,615 | ---- | M] () -- C:\Users\Benjamin\Desktop\Avast - Protokoll.png [2011.09.25 17:57:46 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2011.09.25 17:57:46 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2011.09.25 15:01:45 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2011.09.21 12:28:37 | 000,466,520 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2011.09.21 12:28:36 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2011.09.18 22:06:50 | 001,612,504 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011.09.18 22:06:50 | 000,696,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2011.09.18 22:06:50 | 000,651,946 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011.09.18 22:06:50 | 000,147,924 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2011.09.18 22:06:50 | 000,120,878 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011.09.14 22:31:59 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2011.09.09 20:12:39 | 034,720,926 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 4 - 1.wav [2011.09.09 20:12:39 | 000,135,688 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 4 - 1.sfk [2011.09.09 20:09:19 | 001,392,018 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 3 - 2.wav [2011.09.09 20:09:19 | 000,005,496 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 3 - 2.sfk [2011.09.09 20:08:31 | 018,931,446 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 3 - 1.wav [2011.09.09 20:08:31 | 000,074,008 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 3 - 1.sfk [2011.09.08 23:04:00 | 103,298,810 | ---- | M] () -- C:\Users\Benjamin\Documents\Commtry.wav [2011.09.08 23:04:00 | 000,403,568 | ---- | M] () -- C:\Users\Benjamin\Documents\Commtry.sfk [2011.09.08 22:42:45 | 000,385,198 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 13.wav [2011.09.08 22:42:45 | 000,001,560 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 13.sfk [2011.09.08 22:42:35 | 000,363,162 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 12.wav [2011.09.08 22:42:35 | 000,001,480 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 12.sfk [2011.09.08 22:39:55 | 001,157,718 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 11.wav [2011.09.08 22:39:55 | 000,004,576 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 11.sfk [2011.09.08 22:38:10 | 000,865,658 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 10.wav [2011.09.08 22:38:10 | 000,003,440 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 10.sfk [2011.09.08 22:37:43 | 000,836,254 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 9.wav [2011.09.08 22:37:43 | 000,003,328 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 9.sfk [2011.09.08 22:37:19 | 001,244,702 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 8.wav [2011.09.08 22:37:19 | 000,004,920 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 8.sfk [2011.09.07 18:23:42 | 003,382,558 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 5 - 1.wav [2011.09.07 18:23:42 | 000,013,272 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 5 - 1.sfk [2011.09.07 14:43:41 | 000,000,010 | ---- | M] () -- C:\Windows\GSetup.ini [2011.09.07 01:28:15 | 000,614,154 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 7.wav [2011.09.07 01:28:15 | 000,002,456 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 7.sfk [2011.09.07 01:26:04 | 001,068,326 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 2 - 1.wav [2011.09.07 01:26:04 | 000,004,232 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 2 - 1.sfk [2011.09.07 01:23:31 | 000,649,594 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 6.wav [2011.09.07 01:23:31 | 000,002,592 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 6.sfk [2011.09.07 01:22:48 | 000,460,050 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 5.wav [2011.09.07 01:22:48 | 000,001,856 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 5.sfk [2011.09.07 01:22:28 | 000,962,574 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 4.wav [2011.09.07 01:22:28 | 000,003,816 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 4.sfk [2011.09.07 01:21:56 | 003,307,806 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 3.wav [2011.09.07 01:21:56 | 000,012,976 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 3.sfk [2011.09.06 22:45:29 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe [2011.09.06 22:45:29 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2011.09.06 22:45:17 | 000,254,400 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2011.09.06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2011.09.06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2011.09.06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys [2011.09.06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys [2011.09.06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2011.09.06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys [2011.09.06 13:08:04 | 003,629,434 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 2.wav [2011.09.06 13:08:04 | 000,014,232 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 2.sfk [2011.09.05 20:22:31 | 022,729,294 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 1.wav [2011.09.05 20:22:31 | 000,088,840 | ---- | M] () -- C:\Users\Benjamin\Documents\Track 1 - 1.sfk [2011.09.04 21:42:10 | 000,062,556 | ---- | M] () -- C:\Users\Benjamin\Documents\ts3_clientui-win32-14642-2011-09-04 21_42_09.818939.dmp [2011.09.02 01:39:47 | 000,012,574 | ---- | M] () -- C:\Users\Benjamin\.recently-used.xbel [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011.08.31 01:19:28 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe [2011.08.30 17:36:05 | 000,682,280 | ---- | M] () -- C:\Windows\SysWow64\pbsvc.exe [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.09.26 20:51:08 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.09.26 20:01:24 | 000,018,216 | ---- | C] () -- C:\Users\Benjamin\Desktop\Nachrichten Präsentation.odt [2011.09.26 18:45:07 | 000,087,615 | ---- | C] () -- C:\Users\Benjamin\Desktop\Avast - Protokoll.png [2011.09.09 20:12:39 | 000,135,688 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 4 - 1.sfk [2011.09.09 20:09:22 | 034,720,926 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 4 - 1.wav [2011.09.09 20:09:19 | 000,005,496 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 3 - 2.sfk [2011.09.09 20:08:31 | 001,392,018 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 3 - 2.wav [2011.09.09 20:08:31 | 000,074,008 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 3 - 1.sfk [2011.09.09 20:06:43 | 018,931,446 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 3 - 1.wav [2011.09.08 23:04:00 | 000,403,568 | ---- | C] () -- C:\Users\Benjamin\Documents\Commtry.sfk [2011.09.08 22:42:45 | 103,298,810 | ---- | C] () -- C:\Users\Benjamin\Documents\Commtry.wav [2011.09.08 22:42:45 | 000,001,560 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 13.sfk [2011.09.08 22:42:35 | 000,385,198 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 13.wav [2011.09.08 22:42:35 | 000,001,480 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 12.sfk [2011.09.08 22:39:55 | 000,363,162 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 12.wav [2011.09.08 22:39:55 | 000,004,576 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 11.sfk [2011.09.08 22:38:10 | 001,157,718 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 11.wav [2011.09.08 22:38:10 | 000,003,440 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 10.sfk [2011.09.08 22:37:43 | 000,865,658 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 10.wav [2011.09.08 22:37:43 | 000,003,328 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 9.sfk [2011.09.08 22:37:19 | 000,836,254 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 9.wav [2011.09.08 22:37:19 | 000,004,920 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 8.sfk [2011.09.08 22:37:11 | 001,244,702 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 8.wav [2011.09.07 18:23:42 | 000,013,272 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 5 - 1.sfk [2011.09.07 18:23:21 | 003,382,558 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 5 - 1.wav [2011.09.07 14:33:43 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2011.09.07 01:28:15 | 000,002,456 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 7.sfk [2011.09.07 01:28:10 | 000,614,154 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 7.wav [2011.09.07 01:26:04 | 000,004,232 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 2 - 1.sfk [2011.09.07 01:25:56 | 001,068,326 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 2 - 1.wav [2011.09.07 01:23:31 | 000,002,592 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 6.sfk [2011.09.07 01:22:48 | 000,649,594 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 6.wav [2011.09.07 01:22:48 | 000,001,856 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 5.sfk [2011.09.07 01:22:28 | 000,460,050 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 5.wav [2011.09.07 01:22:28 | 000,003,816 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 4.sfk [2011.09.07 01:21:56 | 000,962,574 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 4.wav [2011.09.07 01:21:56 | 000,012,976 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 3.sfk [2011.09.07 01:21:36 | 003,307,806 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 3.wav [2011.09.06 13:08:04 | 000,014,232 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 2.sfk [2011.09.06 13:07:42 | 003,629,434 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 2.wav [2011.09.05 20:22:31 | 000,088,840 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 1.sfk [2011.09.05 20:20:20 | 022,729,294 | ---- | C] () -- C:\Users\Benjamin\Documents\Track 1 - 1.wav [2011.09.04 21:42:09 | 000,062,556 | ---- | C] () -- C:\Users\Benjamin\Documents\ts3_clientui-win32-14642-2011-09-04 21_42_09.818939.dmp [2011.09.02 01:39:47 | 000,012,574 | ---- | C] () -- C:\Users\Benjamin\.recently-used.xbel [2011.07.17 23:54:02 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll [2011.07.10 12:54:44 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2011.07.10 12:54:43 | 000,682,280 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe [2011.07.10 12:54:43 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2011.07.05 16:29:12 | 001,574,468 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011.07.05 13:33:47 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe [2011.05.28 09:59:27 | 000,000,317 | ---- | C] () -- C:\Windows\game.ini [2011.05.27 05:03:13 | 000,007,596 | ---- | C] () -- C:\Users\Benjamin\AppData\Local\Resmon.ResmonCfg [2011.05.26 21:45:47 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011.05.26 03:50:33 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011.05.26 03:20:58 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2011.03.17 19:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2010.05.27 00:30:15 | 000,528,896 | ---- | C] () -- C:\Windows\SysWow64\RegisterDialog.dll [2009.08.27 09:04:12 | 000,207,400 | R--- | C] () -- C:\Windows\GSetup.exe [2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2011.09.18 14:55:01 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\.minecraft [2011.06.14 12:28:02 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2011.05.27 23:01:47 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\DAEMON Tools Lite [2011.09.18 02:09:57 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\DVDVideoSoft [2011.05.28 14:24:43 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\DVDVideoSoftIEHelpers [2011.08.26 12:08:30 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\GameRanger [2011.07.06 21:47:45 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\GameTracker [2011.09.02 01:39:47 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\gtk-2.0 [2011.08.01 12:36:59 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\ImgBurn [2011.08.29 19:45:31 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Kalypso Media [2011.08.03 15:43:47 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Leadertech [2011.06.07 18:42:23 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\MAXON [2011.08.26 20:08:39 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Nokia [2011.08.26 20:08:39 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Nokia Ovi Suite [2011.07.03 12:08:45 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\OpenOffice.org [2011.08.15 08:53:07 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Origin [2011.08.26 20:06:49 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\PC Suite [2011.05.27 00:35:36 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Publish Providers [2011.07.02 21:46:05 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Sony [2011.06.27 16:30:48 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Sony Creative Software [2011.06.12 13:31:52 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\TeamViewer [2011.05.26 21:42:55 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Thunderbird [2011.08.22 00:57:37 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\TS3Client [2011.08.22 00:57:37 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\ts3overlay [2011.08.04 17:45:58 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Tunngle [2011.09.09 12:46:42 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1 [2011.05.28 00:36:34 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Ubisoft [2011.09.27 06:44:35 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2011.09.18 14:55:01 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\.minecraft [2011.08.08 23:15:14 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Adobe [2011.05.27 21:14:58 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\ATI [2011.06.14 12:28:02 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2011.05.27 23:01:47 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\DAEMON Tools Lite [2011.07.24 17:01:46 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\dvdcss [2011.09.18 02:09:57 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\DVDVideoSoft [2011.05.28 14:24:43 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\DVDVideoSoftIEHelpers [2011.08.26 12:08:30 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\GameRanger [2011.07.06 21:47:45 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\GameTracker [2011.09.02 01:39:47 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\gtk-2.0 [2011.05.26 03:06:07 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Identities [2011.08.01 12:36:59 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\ImgBurn [2011.08.29 19:45:31 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Kalypso Media [2011.08.03 15:43:47 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Leadertech [2011.05.26 03:58:26 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Macromedia [2011.09.26 20:51:19 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Malwarebytes [2011.06.07 18:42:23 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\MAXON [2009.07.14 20:18:18 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Media Center Programs [2011.07.29 13:13:35 | 000,000,000 | --SD | M] -- C:\Users\Benjamin\AppData\Roaming\Microsoft [2011.05.26 03:52:53 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Mozilla [2011.05.27 00:25:30 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\NCH Software [2011.08.26 20:08:39 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Nokia [2011.08.26 20:08:39 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Nokia Ovi Suite [2011.07.03 12:08:45 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\OpenOffice.org [2011.08.15 08:53:07 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Origin [2011.08.26 20:06:49 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\PC Suite [2011.05.27 00:35:36 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Publish Providers [2011.06.12 13:31:00 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\SecuROM [2011.09.27 16:36:55 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Skype [2011.06.19 13:09:31 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\skypePM [2011.07.02 21:46:05 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Sony [2011.06.27 16:30:48 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Sony Creative Software [2011.06.12 13:31:52 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\TeamViewer [2011.05.26 21:42:55 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Thunderbird [2011.08.22 00:57:37 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\TS3Client [2011.08.22 00:57:37 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\ts3overlay [2011.08.04 17:45:58 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Tunngle [2011.09.09 12:46:42 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1 [2011.05.28 00:36:34 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Ubisoft [2011.08.22 00:57:37 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\vlc [2011.05.26 05:18:46 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\WinRAR < %APPDATA%\*.exe /s > [2011.09.18 14:54:09 | 001,050,355 | ---- | M] () -- C:\Users\Benjamin\AppData\Roaming\.minecraft\mcpatcher-2.1.1.exe [2011.08.16 16:42:01 | 001,449,696 | ---- | M] (GameRanger Technologies) -- C:\Users\Benjamin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe [2011.06.14 12:27:23 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Benjamin\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2011.07.21 15:49:21 | 000,010,134 | R--- | M] () -- C:\Users\Benjamin\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS > [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: IASTORV.SYS > [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys [2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys < MD5 for: NETLOGON.DLL > [2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll [2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll [2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll < MD5 for: NVSTOR.SYS > [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys [2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys < MD5 for: SCECLI.DLL > [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll [2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll [2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll [2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll < MD5 for: USER32.DLL > [2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll [2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll [2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll < MD5 for: USERINIT.EXE > [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe [2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe [2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe [2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe [2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe [2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe [2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe [2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe [2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2010.09.01 06:29:28 | 011,406,848 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\wmp.dll [4 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < End of report > Mfg Benni |
27.09.2011, 18:49 | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{a241f8f3-c2d2-11e0-9ae6-00ff01000001}\Shell - "" = AutoRun O33 - MountPoints2\{a241f8f3-c2d2-11e0-9ae6-00ff01000001}\Shell\AutoRun\command - "" = E:\setup.exe :Commands [emptytemp] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten |
27.09.2011, 19:03 | #12 | |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Hier das Logfile von OTL : Zitat:
Mfg Benni |
27.09.2011, 19:40 | #13 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen!
__________________ Logfiles bitte immer in CODE-Tags posten |
27.09.2011, 19:43 | #14 | |
| Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Der Report - Sagt meiner meinung nach aus das nichts mehr vorliegt oder ? und auf verknüpfungen sowie Eigene Dokumente kann ich noch zugreifen. Zitat:
Mfg Benni |
27.09.2011, 19:50 | #15 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Vierenfund : Win32:Cycbot-KI[Trj] bei Avast! |
.dll, anwendungen, avast, avast!, booten, ebenfalls, edition, fehler, folge, forum, frage, fund, herunterfahren, komische, leute, problem, ram, reboot, rum, speicher, starten, trojaner, vieren, virus, win, win32, win32:cycbot-ki[trj] |