Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 05.12.2011, 00:31   #1
DPK
 
vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. - Standard

vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.



Hallo,

ich habe vor ca4 Tagen eine datei installiert und habe seither perfomanceprobleme. (rechner reagiert lagsamer als zuvor und verschiede spiele stützen aus unerfindlichen gründen ab. meist ohne Fehlermeldung)

ich habe win7 ultimate und verwende Avira (Avira findet nach einem vollständigem scan jedoch nichts.)

ich habe mich an die Anleitung gehalten und mit defogger meine vituellen CDlaufwerke deaktiviert und nicht wieder aktiviert.

nach 14 stunden musste ich meinen rechner abschalten aber gema war noch nicht ganz fertig.
gema war gerade beim ordner:
C:\Windows\winsxs als ich den rechner abschalten musste. ich habe das log vorher noch gespeichert.

gema meinte zudem das VC5SecS.exe vllt ein rootkick sein könnte.
Laut googlesuche gehört diese datei zu VitualCD, einem laufwerkemulationsprogramm das ich verwende.

mfg DPK

hier das OTL log:

OTL logfile created on: 03.12.2011 16:54:15 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\wind_of_pain\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy

3,25 Gb Total Physical Memory | 2,14 Gb Available Physical Memory | 65,90% Memory free
6,50 Gb Paging File | 5,41 Gb Available in Paging File | 83,33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 35,13 Gb Total Space | 4,55 Gb Free Space | 12,96% Space Free | Partition Type: NTFS
Drive D: | 461,04 Gb Total Space | 48,05 Gb Free Space | 10,42% Space Free | Partition Type: NTFS
Drive E: | 100,00 Gb Total Space | 3,90 Gb Free Space | 3,90% Space Free | Partition Type: NTFS
Drive F: | 7,77 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: PAINKEEPER | User Name: wind_of_pain | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\wind_of_pain\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (VC5SecS) -- C:\Program Files\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH)


========== Driver Services (SafeList) ==========

DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) -- C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (Mkd2kfNt) -- C:\Windows\System32\drivers\Mkd2kfNT.sys ()
DRV - (Mkd2Nadr) -- C:\Windows\System32\drivers\Mkd2Nadr.sys ()
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (vbev5mp) -- C:\Windows\System32\drivers\VBEV5MP.sys (H+H Software GmbH)
DRV - (tandpl) -- C:\Windows\System32\drivers\tandpl.sys ()
DRV - (enodpl) -- C:\Windows\System32\drivers\enodpl.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = my.daemon-search.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 78 7D 97 60 6F CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: firegestures@xuldev.org:1.6.3
FF - prefs.js..extensions.enabledItems: trackmenot@mrl.nyu.edu:0.6.723
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.2
FF - prefs.js..extensions.enabledItems: btpersonas@brandthunder.com:1.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.10 07:37:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.16 22:05:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.08.21 16:40:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions
[2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.11.29 11:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions
[2011.11.18 00:15:18 | 000,000,000 | ---D | M] ("Personas Interactive Theme Engine") -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions\btpersonas@brandthunder.com
[2011.02.27 01:22:06 | 000,002,071 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\absearch-search.xml
[2010.03.18 19:11:59 | 000,000,873 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\conduit.xml
[2011.02.18 22:01:35 | 000,002,059 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\daemon-search.xml
[2010.01.07 08:26:56 | 000,000,526 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\yahoo.xml
[2011.11.10 16:11:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.11.10 07:37:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.10 07:37:12 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.10 07:37:12 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.10 07:37:12 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.10 07:37:12 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.10 07:37:12 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.10 07:37:12 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2010.08.24 23:00:13 | 000,000,950 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 193.178.171.175 www.wienerlinien.at
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4E33D05-3FC0-499D-AF69-F6B5EE3D5DD1}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell - "" = AutoRun
O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell\AutoRun\command - "" = G:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {47B3BDBB-F2AE-4B55-95C8-921C25DB3B76} - .NET Framework
ActiveX: {49C187D7-91E1-459E-9759-2925384BD397} - .NET Framework
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5A604D2C-E968-429B-8327-62B5CE52126D} - .NET Framework
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {9793EDE2-499E-4A14-8220-523691D8F91B} - .NET Framework
ActiveX: {A59B76D1-5E3B-4893-BB7F-AF69B2570A73} - .NET Framework
ActiveX: {BFA2E378-31D9-4595-AFA9-CA19E610DC0F} - .NET Framework
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CE4BC71D-A88B-4943-BB3D-AF9C0E7D4387} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {FE600E50-2C69-46D5-ACAA-2B617006245C} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SetPointII.lnk - C:\Programme\Logitech\SetPoint II\SetPointII.exe - (Logitech Inc.)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip - - File not found
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DAEMON Tools Lite.lnk - C:\Programme\DAEMON Tools Lite\DTLite.exe - (DT Soft Ltd)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk - C:\Programme\Common Files\Logishrd\eReg\SetPoint\eReg.exe - (Leader Technologies/Logitech)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Mozilla Thunderbird.lnk - C:\Programme\Mozilla Thunderbird\thunderbird.exe - (Mozilla Messaging)
MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Skype.lnk - - File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: avgnt - hkey= - key= - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig - StartUpReg: Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - StartUpReg: StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: VC5Player - hkey= - key= - C:\Programme\HHVcdV5Sys\VC5Play.exe (H+H Software GmbH)
MsConfig - StartUpReg: WinampAgent - hkey= - key= - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
MsConfig - State: "startup" - 1

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011.12.03 16:23:50 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe
[2011.11.30 15:09:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\Neuer Ordner
[2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2011.11.29 19:42:59 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\backups
[2011.11.29 19:23:12 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\Uniblue
[2011.11.29 19:22:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011.11.29 19:15:17 | 000,939,368 | ---- | C] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx
[2011.11.29 19:14:27 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\PackageAware
[2011.11.12 01:37:28 | 002,339,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.11.05 13:30:47 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\uTorrent
[2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\uTorrent
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.03 16:50:19 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2011.12.03 16:49:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.03 16:49:14 | 2616,500,224 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.03 16:47:40 | 000,000,020 | ---- | M] () -- C:\Users\wind_of_pain\defogger_reenable
[2011.12.03 16:47:03 | 000,050,477 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe
[2011.12.03 16:23:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe
[2011.11.30 14:25:30 | 000,001,979 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank
[2011.11.19 07:39:05 | 000,694,232 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011.11.19 07:39:05 | 000,693,256 | ---- | M] () -- C:\Windows\System32\perfh00A.dat
[2011.11.19 07:39:05 | 000,690,994 | ---- | M] () -- C:\Windows\System32\perfh013.dat
[2011.11.19 07:39:05 | 000,689,528 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2011.11.19 07:39:05 | 000,688,910 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2011.11.19 07:39:05 | 000,679,144 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2011.11.19 07:39:05 | 000,675,760 | ---- | M] () -- C:\Windows\System32\perfh019.dat
[2011.11.19 07:39:05 | 000,663,606 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2011.11.19 07:39:05 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.19 07:39:05 | 000,631,982 | ---- | M] () -- C:\Windows\System32\perfh00E.dat
[2011.11.19 07:39:05 | 000,622,946 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.11.19 07:39:05 | 000,617,370 | ---- | M] () -- C:\Windows\System32\perfh01D.dat
[2011.11.19 07:39:05 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.19 07:39:05 | 000,610,004 | ---- | M] () -- C:\Windows\System32\perfh01F.dat
[2011.11.19 07:39:05 | 000,551,572 | ---- | M] () -- C:\Windows\System32\perfh008.dat
[2011.11.19 07:39:05 | 000,461,974 | ---- | M] () -- C:\Windows\System32\perfh006.dat
[2011.11.19 07:39:05 | 000,448,388 | ---- | M] () -- C:\Windows\System32\perfh014.dat
[2011.11.19 07:39:05 | 000,434,288 | ---- | M] () -- C:\Windows\System32\perfh001.dat
[2011.11.19 07:39:05 | 000,433,190 | ---- | M] () -- C:\Windows\System32\perfh00B.dat
[2011.11.19 07:39:05 | 000,399,538 | ---- | M] () -- C:\Windows\System32\perfh012.dat
[2011.11.19 07:39:05 | 000,388,320 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2011.11.19 07:39:05 | 000,377,672 | ---- | M] () -- C:\Windows\System32\prfh0404.dat
[2011.11.19 07:39:05 | 000,361,570 | ---- | M] () -- C:\Windows\System32\prfh0804.dat
[2011.11.19 07:39:05 | 000,353,324 | ---- | M] () -- C:\Windows\System32\perfh00D.dat
[2011.11.19 07:39:05 | 000,148,112 | ---- | M] () -- C:\Windows\System32\perfc00E.dat
[2011.11.19 07:39:05 | 000,136,864 | ---- | M] () -- C:\Windows\System32\perfc00A.dat
[2011.11.19 07:39:05 | 000,134,642 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2011.11.19 07:39:05 | 000,133,554 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2011.11.19 07:39:05 | 000,132,742 | ---- | M] () -- C:\Windows\System32\perfc013.dat
[2011.11.19 07:39:05 | 000,132,318 | ---- | M] () -- C:\Windows\System32\perfc019.dat
[2011.11.19 07:39:05 | 000,129,942 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011.11.19 07:39:05 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.19 07:39:05 | 000,127,896 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2011.11.19 07:39:05 | 000,126,946 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2011.11.19 07:39:05 | 000,123,542 | ---- | M] () -- C:\Windows\System32\perfc01D.dat
[2011.11.19 07:39:05 | 000,121,590 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.11.19 07:39:05 | 000,121,328 | ---- | M] () -- C:\Windows\System32\perfc01F.dat
[2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.19 07:39:05 | 000,104,478 | ---- | M] () -- C:\Windows\System32\perfc012.dat
[2011.11.19 07:39:05 | 000,104,050 | ---- | M] () -- C:\Windows\System32\prfc0804.dat
[2011.11.19 07:39:05 | 000,099,136 | ---- | M] () -- C:\Windows\System32\prfc0404.dat
[2011.11.19 07:39:05 | 000,089,238 | ---- | M] () -- C:\Windows\System32\perfc008.dat
[2011.11.19 07:39:05 | 000,081,950 | ---- | M] () -- C:\Windows\System32\perfc00B.dat
[2011.11.19 07:39:05 | 000,079,606 | ---- | M] () -- C:\Windows\System32\perfc006.dat
[2011.11.19 07:39:05 | 000,078,786 | ---- | M] () -- C:\Windows\System32\perfc001.dat
[2011.11.19 07:39:05 | 000,076,898 | ---- | M] () -- C:\Windows\System32\perfc014.dat
[2011.11.19 07:39:05 | 000,068,896 | ---- | M] () -- C:\Windows\System32\perfc00D.dat
[2011.11.18 08:54:56 | 004,157,452 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3
[2011.11.17 07:43:32 | 002,712,973 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3
[2011.11.12 09:23:29 | 000,289,720 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.07 09:26:14 | 000,939,368 | ---- | M] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx
[2011.11.06 12:32:25 | 001,169,064 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3
[2011.11.06 10:06:12 | 001,743,820 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.12.03 16:47:26 | 000,000,020 | ---- | C] () -- C:\Users\wind_of_pain\defogger_reenable
[2011.12.03 16:47:02 | 000,050,477 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe
[2011.11.30 11:06:42 | 000,001,979 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank
[2011.11.29 19:23:13 | 000,000,346 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job
[2011.11.18 08:48:00 | 004,157,452 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3
[2011.11.17 07:39:32 | 002,712,973 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3
[2011.11.06 12:30:48 | 001,169,064 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3
[2011.11.06 10:04:47 | 001,743,820 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3
[2011.10.20 06:42:23 | 000,007,621 | ---- | C] () -- C:\Users\wind_of_pain\AppData\Local\Resmon.ResmonCfg
[2011.09.14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011.08.26 15:34:14 | 000,239,869 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011.05.10 20:10:14 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011.03.31 18:03:33 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011.02.18 22:38:36 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.02.23 02:17:04 | 000,767,328 | ---- | C] () -- C:\Windows\System32\kdfinj.dll
[2010.02.23 02:12:44 | 000,131,072 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2kfNT.sys
[2010.02.23 02:12:44 | 000,079,104 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2Nadr.sys
[2010.02.19 14:36:01 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2010.02.14 18:11:19 | 000,007,552 | ---- | C] () -- C:\Windows\System32\drivers\enodpl.sys
[2010.02.14 18:11:19 | 000,004,736 | ---- | C] () -- C:\Windows\System32\drivers\tandpl.sys
[2010.01.17 03:09:12 | 000,388,320 | ---- | C] () -- C:\Windows\System32\perfh011.dat
[2010.01.17 03:09:12 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat
[2010.01.17 03:09:12 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc011.dat
[2010.01.17 03:09:12 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat
[2010.01.17 03:02:11 | 000,551,572 | ---- | C] () -- C:\Windows\System32\perfh008.dat
[2010.01.17 03:02:11 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat
[2010.01.17 03:02:11 | 000,089,238 | ---- | C] () -- C:\Windows\System32\perfc008.dat
[2010.01.17 03:02:11 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat
[2010.01.17 02:58:33 | 000,610,004 | ---- | C] () -- C:\Windows\System32\perfh01F.dat
[2010.01.17 02:58:33 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat
[2010.01.17 02:58:33 | 000,121,328 | ---- | C] () -- C:\Windows\System32\perfc01F.dat
[2010.01.17 02:58:33 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat
[2010.01.17 02:55:17 | 000,631,982 | ---- | C] () -- C:\Windows\System32\perfh00E.dat
[2010.01.17 02:55:17 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat
[2010.01.17 02:55:17 | 000,148,112 | ---- | C] () -- C:\Windows\System32\perfc00E.dat
[2010.01.17 02:55:17 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat
[2010.01.17 02:51:58 | 000,679,144 | ---- | C] () -- C:\Windows\System32\prfh0816.dat
[2010.01.17 02:51:58 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat
[2010.01.17 02:51:58 | 000,133,554 | ---- | C] () -- C:\Windows\System32\prfc0816.dat
[2010.01.17 02:51:58 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat
[2010.01.17 02:48:49 | 000,690,994 | ---- | C] () -- C:\Windows\System32\perfh013.dat
[2010.01.17 02:48:49 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat
[2010.01.17 02:48:49 | 000,132,742 | ---- | C] () -- C:\Windows\System32\perfc013.dat
[2010.01.17 02:48:49 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat
[2010.01.17 02:45:11 | 000,461,974 | ---- | C] () -- C:\Windows\System32\perfh006.dat
[2010.01.17 02:45:11 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat
[2010.01.17 02:45:11 | 000,079,606 | ---- | C] () -- C:\Windows\System32\perfc006.dat
[2010.01.17 02:45:11 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat
[2010.01.17 02:40:31 | 000,617,370 | ---- | C] () -- C:\Windows\System32\perfh01D.dat
[2010.01.17 02:40:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat
[2010.01.17 02:40:31 | 000,123,542 | ---- | C] () -- C:\Windows\System32\perfc01D.dat
[2010.01.17 02:40:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat
[2010.01.13 22:23:59 | 000,693,256 | ---- | C] () -- C:\Windows\System32\perfh00A.dat
[2010.01.13 22:23:59 | 000,689,528 | ---- | C] () -- C:\Windows\System32\perfh015.dat
[2010.01.13 22:23:59 | 000,675,760 | ---- | C] () -- C:\Windows\System32\perfh019.dat
[2010.01.13 22:23:59 | 000,663,606 | ---- | C] () -- C:\Windows\System32\prfh0416.dat
[2010.01.13 22:23:59 | 000,434,288 | ---- | C] () -- C:\Windows\System32\perfh001.dat
[2010.01.13 22:23:59 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat
[2010.01.13 22:23:59 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat
[2010.01.13 22:23:59 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat
[2010.01.13 22:23:59 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat
[2010.01.13 22:23:59 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat
[2010.01.13 22:23:59 | 000,136,864 | ---- | C] () -- C:\Windows\System32\perfc00A.dat
[2010.01.13 22:23:59 | 000,134,642 | ---- | C] () -- C:\Windows\System32\perfc015.dat
[2010.01.13 22:23:59 | 000,132,318 | ---- | C] () -- C:\Windows\System32\perfc019.dat
[2010.01.13 22:23:59 | 000,127,896 | ---- | C] () -- C:\Windows\System32\prfc0416.dat
[2010.01.13 22:23:59 | 000,078,786 | ---- | C] () -- C:\Windows\System32\perfc001.dat
[2010.01.13 22:23:59 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat
[2010.01.13 22:23:59 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat
[2010.01.13 22:23:59 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat
[2010.01.13 22:23:59 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat
[2010.01.13 22:23:59 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat
[2010.01.12 22:41:22 | 000,353,324 | ---- | C] () -- C:\Windows\System32\perfh00D.dat
[2010.01.12 22:41:22 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat
[2010.01.12 22:41:22 | 000,068,896 | ---- | C] () -- C:\Windows\System32\perfc00D.dat
[2010.01.12 22:41:22 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat
[2010.01.12 22:33:42 | 000,688,910 | ---- | C] () -- C:\Windows\System32\perfh010.dat
[2010.01.12 22:33:42 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat
[2010.01.12 22:33:42 | 000,126,946 | ---- | C] () -- C:\Windows\System32\perfc010.dat
[2010.01.12 22:33:42 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat
[2010.01.12 22:28:09 | 000,377,672 | ---- | C] () -- C:\Windows\System32\prfh0404.dat
[2010.01.12 22:28:09 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat
[2010.01.12 22:28:09 | 000,099,136 | ---- | C] () -- C:\Windows\System32\prfc0404.dat
[2010.01.12 22:28:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat
[2010.01.12 22:24:53 | 000,399,538 | ---- | C] () -- C:\Windows\System32\perfh012.dat
[2010.01.12 22:24:53 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat
[2010.01.12 22:24:53 | 000,104,478 | ---- | C] () -- C:\Windows\System32\perfc012.dat
[2010.01.12 22:24:53 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat
[2010.01.12 22:21:08 | 000,694,232 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2010.01.12 22:21:08 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2010.01.12 22:21:08 | 000,129,942 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2010.01.12 22:21:08 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2010.01.12 22:17:10 | 000,622,946 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2010.01.12 22:17:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2010.01.12 22:17:10 | 000,121,590 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2010.01.12 22:17:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2010.01.12 22:12:15 | 000,433,190 | ---- | C] () -- C:\Windows\System32\perfh00B.dat
[2010.01.12 22:12:15 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat
[2010.01.12 22:12:15 | 000,081,950 | ---- | C] () -- C:\Windows\System32\perfc00B.dat
[2010.01.12 22:12:15 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat
[2010.01.12 22:09:09 | 000,361,570 | ---- | C] () -- C:\Windows\System32\prfh0804.dat
[2010.01.12 22:09:09 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat
[2010.01.12 22:09:09 | 000,104,050 | ---- | C] () -- C:\Windows\System32\prfc0804.dat
[2010.01.12 22:09:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat
[2010.01.12 21:58:54 | 000,448,388 | ---- | C] () -- C:\Windows\System32\perfh014.dat
[2010.01.12 21:58:54 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat
[2010.01.12 21:58:54 | 000,076,898 | ---- | C] () -- C:\Windows\System32\perfc014.dat
[2010.01.12 21:58:54 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat
[2009.12.08 12:14:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.11.29 12:25:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.11.27 13:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009.07.14 09:47:43 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 09:47:43 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,289,720 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:55:09 | 000,587,776 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2004.08.13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[1997.11.17 17:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*. >
[2009.11.27 13:51:21 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.09.21 21:55:09 | 000,000,000 | ---D | M] -- C:\5301b5d6b61d5e9fd4431d67
[2011.07.06 14:14:32 | 000,000,000 | ---D | M] -- C:\ATI
[2009.11.27 13:36:56 | 000,000,000 | -HSD | M] -- C:\Boot
[2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2010.06.09 23:40:05 | 000,000,000 | ---D | M] -- C:\FrozenSynapse
[2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.11.29 19:47:31 | 000,000,000 | R--D | M] -- C:\Program Files
[2011.12.03 16:49:13 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Programme
[2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Recovery
[2011.12.03 16:58:07 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2009.11.27 13:51:09 | 000,000,000 | R--D | M] -- C:\Users
[2011.10.24 18:26:18 | 000,000,000 | ---D | M] -- C:\Windows

< %PROGRAMFILES%\*.exe >

< %LOCALAPPDATA%\*.exe >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.manifest /3 >


< MD5 for: AFD.SYS >
[2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\System32\drivers\afd.sys
[2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_d81220b5bf827af7\afd.sys
[2010.11.20 09:40:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=1151FD4FB0216CFED887BFDE29EBD516 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b\afd.sys
[2011.04.25 03:18:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=9EBBBA55060F786F0FCAA3893BFA2806 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_d9f97e05bca8003a\afd.sys
[2011.04.25 03:27:23 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C114AB7A1550D42EA1700FFD4179CF5A -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys
[2011.04.25 04:24:09 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C427F91A748CD342A2B3F9278D9FD6A5 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_da774a9ad5cea29e\afd.sys
[2009.07.14 00:12:38 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=DDC040FDB01EF1712A6B13E52AFB104C -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys

< MD5 for: EXPLORER.EXE >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: REGEDIT.EXE >
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe

< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WININIT.EXE >
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

< MD5 for: WINLOGON.EXE >
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-03 14:43:03

< End of report >

 

Themen zu vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.
adobe, antivir, autorun, avira, c:\windows\system32\rundll32.exe, defender, explorer, fehlermeldung, firefox, format, host.exe, installation, langs, log, logfile, microsoft, mozilla thunderbird, object, ordner, plug-in, programme, required, rundll, scan, sched.exe, secure, software, taskhost.exe, usb, virus, webcheck, windows, winlogon.exe, wmp




Ähnliche Themen: vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.


  1. Win 10 : Nach Download einer Datei massenhaft,leuchtende Werbung im Browser
    Log-Analyse und Auswertung - 26.08.2015 (4)
  2. Windows 8.1 gentec.gen virus nach öffnen einer datei
    Log-Analyse und Auswertung - 29.06.2015 (18)
  3. Windows 7 nach Installation einer Freeware infiziert
    Plagegeister aller Art und deren Bekämpfung - 06.07.2014 (39)
  4. Raving Reyven auf System nach Installation von Excel Datei
    Log-Analyse und Auswertung - 10.06.2014 (19)
  5. Vermutung: AppRound.us Virus nach Installation einer Freeware - VBates Funde
    Plagegeister aller Art und deren Bekämpfung - 17.03.2014 (9)
  6. BOO /TDss.O im Masterbootsektor gefunden nach Installation von Windows 7 auf einer zweiten internen Festplatte
    Plagegeister aller Art und deren Bekämpfung - 07.01.2014 (33)
  7. Windows XP: Trojaner tr/bankzone.a.4 nach Aufrufen einer Zip-Datei
    Log-Analyse und Auswertung - 28.08.2013 (7)
  8. Gmail erlaubt Anhängen einer "infizierten" Word-Datei nicht - evtl. Virus-Falschmeldung?
    Plagegeister aller Art und deren Bekämpfung - 14.05.2012 (2)
  9. PC startet nach dem ausführen einer .scr Datei nicht.
    Plagegeister aller Art und deren Bekämpfung - 14.10.2011 (1)
  10. Virus nach ausführen einer Datei, PC stürzt ab
    Plagegeister aller Art und deren Bekämpfung - 29.12.2010 (1)
  11. Laptop such nach einer Datei
    Plagegeister aller Art und deren Bekämpfung - 12.08.2010 (1)
  12. Vermute Virus in dieser Datei
    Plagegeister aller Art und deren Bekämpfung - 17.07.2010 (2)
  13. nach öffnen einer scr datei fehlermeldung in csrss.exe
    Plagegeister aller Art und deren Bekämpfung - 04.05.2010 (1)
  14. Nach Ausführung einer unseriösen Datei einen TrojanDownloader eingefangen
    Log-Analyse und Auswertung - 21.01.2009 (9)
  15. virus total fünde bei einer datei
    Plagegeister aller Art und deren Bekämpfung - 08.10.2008 (1)
  16. EScan zeigt Virus, aber nicht file-Quelle
    Plagegeister aller Art und deren Bekämpfung - 28.03.2005 (1)

Zum Thema vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. - Hallo, ich habe vor ca4 Tagen eine datei installiert und habe seither perfomanceprobleme. (rechner reagiert lagsamer als zuvor und verschiede spiele stützen aus unerfindlichen gründen ab. meist ohne Fehlermeldung) ich - vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle....
Archiv
Du betrachtest: vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.