![]() |
|
Log-Analyse und Auswertung: vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. Hallo, ich habe vor ca4 Tagen eine datei installiert und habe seither perfomanceprobleme. (rechner reagiert lagsamer als zuvor und verschiede spiele stützen aus unerfindlichen gründen ab. meist ohne Fehlermeldung) ich habe win7 ultimate und verwende Avira (Avira findet nach einem vollständigem scan jedoch nichts.) ich habe mich an die Anleitung gehalten und mit defogger meine vituellen CDlaufwerke deaktiviert und nicht wieder aktiviert. nach 14 stunden musste ich meinen rechner abschalten aber gema war noch nicht ganz fertig. gema war gerade beim ordner: C:\Windows\winsxs als ich den rechner abschalten musste. ich habe das log vorher noch gespeichert. gema meinte zudem das VC5SecS.exe vllt ein rootkick sein könnte. Laut googlesuche gehört diese datei zu VitualCD, einem laufwerkemulationsprogramm das ich verwende. mfg DPK hier das OTL log: OTL logfile created on: 03.12.2011 16:54:15 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\wind_of_pain\Desktop Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 3,25 Gb Total Physical Memory | 2,14 Gb Available Physical Memory | 65,90% Memory free 6,50 Gb Paging File | 5,41 Gb Available in Paging File | 83,33% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 35,13 Gb Total Space | 4,55 Gb Free Space | 12,96% Space Free | Partition Type: NTFS Drive D: | 461,04 Gb Total Space | 48,05 Gb Free Space | 10,42% Space Free | Partition Type: NTFS Drive E: | 100,00 Gb Total Space | 3,90 Gb Free Space | 3,90% Space Free | Partition Type: NTFS Drive F: | 7,77 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: PAINKEEPER | User Name: wind_of_pain | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\wind_of_pain\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited) PRC - C:\Windows\System32\atieclxx.exe (AMD) PRC - C:\Windows\System32\atiesrxx.exe (AMD) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Programme\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH) ========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation) SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (VC5SecS) -- C:\Program Files\HHVcdV5Sys\VC5SecS.exe (H+H Software GmbH) ========== Driver Services (SafeList) ========== DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.) DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation) DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) -- C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.) DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.) DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.) DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.) DRV - (Mkd2kfNt) -- C:\Windows\System32\drivers\Mkd2kfNT.sys () DRV - (Mkd2Nadr) -- C:\Windows\System32\drivers\Mkd2Nadr.sys () DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys () DRV - (vbev5mp) -- C:\Windows\System32\drivers\VBEV5MP.sys (H+H Software GmbH) DRV - (tandpl) -- C:\Windows\System32\drivers\tandpl.sys () DRV - (enodpl) -- C:\Windows\System32\drivers\enodpl.sys () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = my.daemon-search.com [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 78 7D 97 60 6F CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6 FF - prefs.js..extensions.enabledItems: firegestures@xuldev.org:1.6.3 FF - prefs.js..extensions.enabledItems: trackmenot@mrl.nyu.edu:0.6.723 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.2 FF - prefs.js..extensions.enabledItems: btpersonas@brandthunder.com:1.1.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.10 07:37:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.16 22:05:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.08.21 16:40:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions [2010.08.19 22:03:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011.11.29 11:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions [2011.11.18 00:15:18 | 000,000,000 | ---D | M] ("Personas Interactive Theme Engine") -- C:\Users\wind_of_pain\AppData\Roaming\mozilla\Firefox\Profiles\15e639cc.default\extensions\btpersonas@brandthunder.com [2011.02.27 01:22:06 | 000,002,071 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\absearch-search.xml [2010.03.18 19:11:59 | 000,000,873 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\conduit.xml [2011.02.18 22:01:35 | 000,002,059 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\daemon-search.xml [2010.01.07 08:26:56 | 000,000,526 | ---- | M] () -- C:\Users\wind_of_pain\AppData\Roaming\Mozilla\Firefox\Profiles\15e639cc.default\searchplugins\yahoo.xml [2011.11.10 16:11:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions () (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI () (No name found) -- C:\USERS\WIND_OF_PAIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\15E639CC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI [2011.11.10 07:37:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011.11.10 07:37:12 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.11.10 07:37:12 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.11.10 07:37:12 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.11.10 07:37:12 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.11.10 07:37:12 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.11.10 07:37:12 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.08.24 23:00:13 | 000,000,950 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 193.178.171.175 www.wienerlinien.at O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4E33D05-3FC0-499D-AF69-F6B5EE3D5DD1}: DhcpNameServer = 10.0.0.1 O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell - "" = AutoRun O33 - MountPoints2\{ad8fb8b6-dcda-11de-b995-002215fd5cbc}\Shell\AutoRun\command - "" = G:\SETUP.EXE O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {47B3BDBB-F2AE-4B55-95C8-921C25DB3B76} - .NET Framework ActiveX: {49C187D7-91E1-459E-9759-2925384BD397} - .NET Framework ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5A604D2C-E968-429B-8327-62B5CE52126D} - .NET Framework ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {9793EDE2-499E-4A14-8220-523691D8F91B} - .NET Framework ActiveX: {A59B76D1-5E3B-4893-BB7F-AF69B2570A73} - .NET Framework ActiveX: {BFA2E378-31D9-4595-AFA9-CA19E610DC0F} - .NET Framework ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CE4BC71D-A88B-4943-BB3D-AF9C0E7D4387} - .NET Framework ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {FE600E50-2C69-46D5-ACAA-2B617006245C} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SetPointII.lnk - C:\Programme\Logitech\SetPoint II\SetPointII.exe - (Logitech Inc.) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip - - File not found MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DAEMON Tools Lite.lnk - C:\Programme\DAEMON Tools Lite\DTLite.exe - (DT Soft Ltd) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk - C:\Programme\Common Files\Logishrd\eReg\SetPoint\eReg.exe - (Leader Technologies/Logitech) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Mozilla Thunderbird.lnk - C:\Programme\Mozilla Thunderbird\thunderbird.exe - (Mozilla Messaging) MsConfig - StartUpFolder: C:^Users^wind_of_pain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Skype.lnk - - File not found MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: avgnt - hkey= - key= - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig - StartUpReg: Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: VC5Player - hkey= - key= - C:\Programme\HHVcdV5Sys\VC5Play.exe (H+H Software GmbH) MsConfig - StartUpReg: WinampAgent - hkey= - key= - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.) MsConfig - State: "startup" - 1 CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.12.03 16:23:50 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe [2011.11.30 15:09:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\Neuer Ordner [2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue [2011.11.29 19:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue [2011.11.29 19:42:59 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\Desktop\backups [2011.11.29 19:23:12 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\Uniblue [2011.11.29 19:22:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} [2011.11.29 19:15:17 | 000,939,368 | ---- | C] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx [2011.11.29 19:14:27 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\PackageAware [2011.11.12 01:37:28 | 002,339,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.11.05 13:30:47 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent [2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Roaming\uTorrent [2011.11.05 13:29:13 | 000,000,000 | ---D | C] -- C:\Users\wind_of_pain\AppData\Local\uTorrent [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.12.03 16:55:25 | 000,019,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.12.03 16:50:19 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job [2011.12.03 16:49:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.12.03 16:49:14 | 2616,500,224 | -HS- | M] () -- C:\hiberfil.sys [2011.12.03 16:47:40 | 000,000,020 | ---- | M] () -- C:\Users\wind_of_pain\defogger_reenable [2011.12.03 16:47:03 | 000,050,477 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe [2011.12.03 16:23:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\wind_of_pain\Desktop\OTL.exe [2011.11.30 14:25:30 | 000,001,979 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank [2011.11.19 07:39:05 | 000,694,232 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2011.11.19 07:39:05 | 000,693,256 | ---- | M] () -- C:\Windows\System32\perfh00A.dat [2011.11.19 07:39:05 | 000,690,994 | ---- | M] () -- C:\Windows\System32\perfh013.dat [2011.11.19 07:39:05 | 000,689,528 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2011.11.19 07:39:05 | 000,688,910 | ---- | M] () -- C:\Windows\System32\perfh010.dat [2011.11.19 07:39:05 | 000,679,144 | ---- | M] () -- C:\Windows\System32\prfh0816.dat [2011.11.19 07:39:05 | 000,675,760 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2011.11.19 07:39:05 | 000,663,606 | ---- | M] () -- C:\Windows\System32\prfh0416.dat [2011.11.19 07:39:05 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.11.19 07:39:05 | 000,631,982 | ---- | M] () -- C:\Windows\System32\perfh00E.dat [2011.11.19 07:39:05 | 000,622,946 | ---- | M] () -- C:\Windows\System32\perfh005.dat [2011.11.19 07:39:05 | 000,617,370 | ---- | M] () -- C:\Windows\System32\perfh01D.dat [2011.11.19 07:39:05 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.11.19 07:39:05 | 000,610,004 | ---- | M] () -- C:\Windows\System32\perfh01F.dat [2011.11.19 07:39:05 | 000,551,572 | ---- | M] () -- C:\Windows\System32\perfh008.dat [2011.11.19 07:39:05 | 000,461,974 | ---- | M] () -- C:\Windows\System32\perfh006.dat [2011.11.19 07:39:05 | 000,448,388 | ---- | M] () -- C:\Windows\System32\perfh014.dat [2011.11.19 07:39:05 | 000,434,288 | ---- | M] () -- C:\Windows\System32\perfh001.dat [2011.11.19 07:39:05 | 000,433,190 | ---- | M] () -- C:\Windows\System32\perfh00B.dat [2011.11.19 07:39:05 | 000,399,538 | ---- | M] () -- C:\Windows\System32\perfh012.dat [2011.11.19 07:39:05 | 000,388,320 | ---- | M] () -- C:\Windows\System32\perfh011.dat [2011.11.19 07:39:05 | 000,377,672 | ---- | M] () -- C:\Windows\System32\prfh0404.dat [2011.11.19 07:39:05 | 000,361,570 | ---- | M] () -- C:\Windows\System32\prfh0804.dat [2011.11.19 07:39:05 | 000,353,324 | ---- | M] () -- C:\Windows\System32\perfh00D.dat [2011.11.19 07:39:05 | 000,148,112 | ---- | M] () -- C:\Windows\System32\perfc00E.dat [2011.11.19 07:39:05 | 000,136,864 | ---- | M] () -- C:\Windows\System32\perfc00A.dat [2011.11.19 07:39:05 | 000,134,642 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2011.11.19 07:39:05 | 000,133,554 | ---- | M] () -- C:\Windows\System32\prfc0816.dat [2011.11.19 07:39:05 | 000,132,742 | ---- | M] () -- C:\Windows\System32\perfc013.dat [2011.11.19 07:39:05 | 000,132,318 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2011.11.19 07:39:05 | 000,129,942 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2011.11.19 07:39:05 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.11.19 07:39:05 | 000,127,896 | ---- | M] () -- C:\Windows\System32\prfc0416.dat [2011.11.19 07:39:05 | 000,126,946 | ---- | M] () -- C:\Windows\System32\perfc010.dat [2011.11.19 07:39:05 | 000,123,542 | ---- | M] () -- C:\Windows\System32\perfc01D.dat [2011.11.19 07:39:05 | 000,121,590 | ---- | M] () -- C:\Windows\System32\perfc005.dat [2011.11.19 07:39:05 | 000,121,328 | ---- | M] () -- C:\Windows\System32\perfc01F.dat [2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc011.dat [2011.11.19 07:39:05 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.11.19 07:39:05 | 000,104,478 | ---- | M] () -- C:\Windows\System32\perfc012.dat [2011.11.19 07:39:05 | 000,104,050 | ---- | M] () -- C:\Windows\System32\prfc0804.dat [2011.11.19 07:39:05 | 000,099,136 | ---- | M] () -- C:\Windows\System32\prfc0404.dat [2011.11.19 07:39:05 | 000,089,238 | ---- | M] () -- C:\Windows\System32\perfc008.dat [2011.11.19 07:39:05 | 000,081,950 | ---- | M] () -- C:\Windows\System32\perfc00B.dat [2011.11.19 07:39:05 | 000,079,606 | ---- | M] () -- C:\Windows\System32\perfc006.dat [2011.11.19 07:39:05 | 000,078,786 | ---- | M] () -- C:\Windows\System32\perfc001.dat [2011.11.19 07:39:05 | 000,076,898 | ---- | M] () -- C:\Windows\System32\perfc014.dat [2011.11.19 07:39:05 | 000,068,896 | ---- | M] () -- C:\Windows\System32\perfc00D.dat [2011.11.18 08:54:56 | 004,157,452 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3 [2011.11.17 07:43:32 | 002,712,973 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3 [2011.11.12 09:23:29 | 000,289,720 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.11.07 09:26:14 | 000,939,368 | ---- | M] (Macromedia, Inc.) -- C:\Windows\System32\flash.ocx [2011.11.06 12:32:25 | 001,169,064 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3 [2011.11.06 10:06:12 | 001,743,820 | ---- | M] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3 [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.12.03 16:47:26 | 000,000,020 | ---- | C] () -- C:\Users\wind_of_pain\defogger_reenable [2011.12.03 16:47:02 | 000,050,477 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Defogger.exe [2011.11.30 11:06:42 | 000,001,979 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\HFv21.SC2Bank [2011.11.29 19:23:13 | 000,000,346 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job [2011.11.18 08:48:00 | 004,157,452 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate Part 2 (Beethoven) Moonlight Sonata.mp3 [2011.11.17 07:39:32 | 002,712,973 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Mondscheinsonate (Ludwig van Beethoven) Moonlight Sonata.mp3 [2011.11.06 12:30:48 | 001,169,064 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\My Little Pony - Rainbow Dash - Youre Gonna Go Far Kid.mp3 [2011.11.06 10:04:47 | 001,743,820 | ---- | C] () -- C:\Users\wind_of_pain\Desktop\Erasure - always.mp3 [2011.10.20 06:42:23 | 000,007,621 | ---- | C] () -- C:\Users\wind_of_pain\AppData\Local\Resmon.ResmonCfg [2011.09.14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll [2011.08.26 15:34:14 | 000,239,869 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2011.05.10 20:10:14 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat [2011.03.31 18:03:33 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini [2011.02.18 22:38:36 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib [2010.02.23 02:17:04 | 000,767,328 | ---- | C] () -- C:\Windows\System32\kdfinj.dll [2010.02.23 02:12:44 | 000,131,072 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2kfNT.sys [2010.02.23 02:12:44 | 000,079,104 | ---- | C] () -- C:\Windows\System32\drivers\Mkd2Nadr.sys [2010.02.19 14:36:01 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll [2010.02.14 18:11:19 | 000,007,552 | ---- | C] () -- C:\Windows\System32\drivers\enodpl.sys [2010.02.14 18:11:19 | 000,004,736 | ---- | C] () -- C:\Windows\System32\drivers\tandpl.sys [2010.01.17 03:09:12 | 000,388,320 | ---- | C] () -- C:\Windows\System32\perfh011.dat [2010.01.17 03:09:12 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat [2010.01.17 03:09:12 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc011.dat [2010.01.17 03:09:12 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat [2010.01.17 03:02:11 | 000,551,572 | ---- | C] () -- C:\Windows\System32\perfh008.dat [2010.01.17 03:02:11 | 000,369,984 | ---- | C] () -- C:\Windows\System32\perfi008.dat [2010.01.17 03:02:11 | 000,089,238 | ---- | C] () -- C:\Windows\System32\perfc008.dat [2010.01.17 03:02:11 | 000,045,182 | ---- | C] () -- C:\Windows\System32\perfd008.dat [2010.01.17 02:58:33 | 000,610,004 | ---- | C] () -- C:\Windows\System32\perfh01F.dat [2010.01.17 02:58:33 | 000,285,034 | ---- | C] () -- C:\Windows\System32\perfi01F.dat [2010.01.17 02:58:33 | 000,121,328 | ---- | C] () -- C:\Windows\System32\perfc01F.dat [2010.01.17 02:58:33 | 000,037,160 | ---- | C] () -- C:\Windows\System32\perfd01F.dat [2010.01.17 02:55:17 | 000,631,982 | ---- | C] () -- C:\Windows\System32\perfh00E.dat [2010.01.17 02:55:17 | 000,287,518 | ---- | C] () -- C:\Windows\System32\perfi00E.dat [2010.01.17 02:55:17 | 000,148,112 | ---- | C] () -- C:\Windows\System32\perfc00E.dat [2010.01.17 02:55:17 | 000,048,094 | ---- | C] () -- C:\Windows\System32\perfd00E.dat [2010.01.17 02:51:58 | 000,679,144 | ---- | C] () -- C:\Windows\System32\prfh0816.dat [2010.01.17 02:51:58 | 000,336,656 | ---- | C] () -- C:\Windows\System32\prfi0816.dat [2010.01.17 02:51:58 | 000,133,554 | ---- | C] () -- C:\Windows\System32\prfc0816.dat [2010.01.17 02:51:58 | 000,040,548 | ---- | C] () -- C:\Windows\System32\prfd0816.dat [2010.01.17 02:48:49 | 000,690,994 | ---- | C] () -- C:\Windows\System32\perfh013.dat [2010.01.17 02:48:49 | 000,341,322 | ---- | C] () -- C:\Windows\System32\perfi013.dat [2010.01.17 02:48:49 | 000,132,742 | ---- | C] () -- C:\Windows\System32\perfc013.dat [2010.01.17 02:48:49 | 000,043,068 | ---- | C] () -- C:\Windows\System32\perfd013.dat [2010.01.17 02:45:11 | 000,461,974 | ---- | C] () -- C:\Windows\System32\perfh006.dat [2010.01.17 02:45:11 | 000,306,636 | ---- | C] () -- C:\Windows\System32\perfi006.dat [2010.01.17 02:45:11 | 000,079,606 | ---- | C] () -- C:\Windows\System32\perfc006.dat [2010.01.17 02:45:11 | 000,039,236 | ---- | C] () -- C:\Windows\System32\perfd006.dat [2010.01.17 02:40:31 | 000,617,370 | ---- | C] () -- C:\Windows\System32\perfh01D.dat [2010.01.17 02:40:31 | 000,294,764 | ---- | C] () -- C:\Windows\System32\perfi01D.dat [2010.01.17 02:40:31 | 000,123,542 | ---- | C] () -- C:\Windows\System32\perfc01D.dat [2010.01.17 02:40:31 | 000,037,052 | ---- | C] () -- C:\Windows\System32\perfd01D.dat [2010.01.13 22:23:59 | 000,693,256 | ---- | C] () -- C:\Windows\System32\perfh00A.dat [2010.01.13 22:23:59 | 000,689,528 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2010.01.13 22:23:59 | 000,675,760 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2010.01.13 22:23:59 | 000,663,606 | ---- | C] () -- C:\Windows\System32\prfh0416.dat [2010.01.13 22:23:59 | 000,434,288 | ---- | C] () -- C:\Windows\System32\perfh001.dat [2010.01.13 22:23:59 | 000,341,432 | ---- | C] () -- C:\Windows\System32\perfi00A.dat [2010.01.13 22:23:59 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2010.01.13 22:23:59 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2010.01.13 22:23:59 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat [2010.01.13 22:23:59 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat [2010.01.13 22:23:59 | 000,136,864 | ---- | C] () -- C:\Windows\System32\perfc00A.dat [2010.01.13 22:23:59 | 000,134,642 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2010.01.13 22:23:59 | 000,132,318 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2010.01.13 22:23:59 | 000,127,896 | ---- | C] () -- C:\Windows\System32\prfc0416.dat [2010.01.13 22:23:59 | 000,078,786 | ---- | C] () -- C:\Windows\System32\perfc001.dat [2010.01.13 22:23:59 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat [2010.01.13 22:23:59 | 000,041,390 | ---- | C] () -- C:\Windows\System32\perfd00A.dat [2010.01.13 22:23:59 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2010.01.13 22:23:59 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2010.01.13 22:23:59 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat [2010.01.12 22:41:22 | 000,353,324 | ---- | C] () -- C:\Windows\System32\perfh00D.dat [2010.01.12 22:41:22 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat [2010.01.12 22:41:22 | 000,068,896 | ---- | C] () -- C:\Windows\System32\perfc00D.dat [2010.01.12 22:41:22 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat [2010.01.12 22:33:42 | 000,688,910 | ---- | C] () -- C:\Windows\System32\perfh010.dat [2010.01.12 22:33:42 | 000,335,478 | ---- | C] () -- C:\Windows\System32\perfi010.dat [2010.01.12 22:33:42 | 000,126,946 | ---- | C] () -- C:\Windows\System32\perfc010.dat [2010.01.12 22:33:42 | 000,037,534 | ---- | C] () -- C:\Windows\System32\perfd010.dat [2010.01.12 22:28:09 | 000,377,672 | ---- | C] () -- C:\Windows\System32\prfh0404.dat [2010.01.12 22:28:09 | 000,117,840 | ---- | C] () -- C:\Windows\System32\prfi0404.dat [2010.01.12 22:28:09 | 000,099,136 | ---- | C] () -- C:\Windows\System32\prfc0404.dat [2010.01.12 22:28:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0404.dat [2010.01.12 22:24:53 | 000,399,538 | ---- | C] () -- C:\Windows\System32\perfh012.dat [2010.01.12 22:24:53 | 000,157,694 | ---- | C] () -- C:\Windows\System32\perfi012.dat [2010.01.12 22:24:53 | 000,104,478 | ---- | C] () -- C:\Windows\System32\perfc012.dat [2010.01.12 22:24:53 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd012.dat [2010.01.12 22:21:08 | 000,694,232 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2010.01.12 22:21:08 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2010.01.12 22:21:08 | 000,129,942 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2010.01.12 22:21:08 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2010.01.12 22:17:10 | 000,622,946 | ---- | C] () -- C:\Windows\System32\perfh005.dat [2010.01.12 22:17:10 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat [2010.01.12 22:17:10 | 000,121,590 | ---- | C] () -- C:\Windows\System32\perfc005.dat [2010.01.12 22:17:10 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat [2010.01.12 22:12:15 | 000,433,190 | ---- | C] () -- C:\Windows\System32\perfh00B.dat [2010.01.12 22:12:15 | 000,279,790 | ---- | C] () -- C:\Windows\System32\perfi00B.dat [2010.01.12 22:12:15 | 000,081,950 | ---- | C] () -- C:\Windows\System32\perfc00B.dat [2010.01.12 22:12:15 | 000,038,258 | ---- | C] () -- C:\Windows\System32\perfd00B.dat [2010.01.12 22:09:09 | 000,361,570 | ---- | C] () -- C:\Windows\System32\prfh0804.dat [2010.01.12 22:09:09 | 000,111,310 | ---- | C] () -- C:\Windows\System32\prfi0804.dat [2010.01.12 22:09:09 | 000,104,050 | ---- | C] () -- C:\Windows\System32\prfc0804.dat [2010.01.12 22:09:09 | 000,031,548 | ---- | C] () -- C:\Windows\System32\prfd0804.dat [2010.01.12 21:58:54 | 000,448,388 | ---- | C] () -- C:\Windows\System32\perfh014.dat [2010.01.12 21:58:54 | 000,298,300 | ---- | C] () -- C:\Windows\System32\perfi014.dat [2010.01.12 21:58:54 | 000,076,898 | ---- | C] () -- C:\Windows\System32\perfc014.dat [2010.01.12 21:58:54 | 000,036,156 | ---- | C] () -- C:\Windows\System32\perfd014.dat [2009.12.08 12:14:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2009.11.29 12:25:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2009.11.27 13:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2009.07.14 09:47:43 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009.07.14 09:47:43 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 000,289,720 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 01:55:09 | 000,587,776 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll [2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2004.08.13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys [1997.11.17 17:13:16 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2009.11.27 13:51:21 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2011.09.21 21:55:09 | 000,000,000 | ---D | M] -- C:\5301b5d6b61d5e9fd4431d67 [2011.07.06 14:14:32 | 000,000,000 | ---D | M] -- C:\ATI [2009.11.27 13:36:56 | 000,000,000 | -HSD | M] -- C:\Boot [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2010.06.09 23:40:05 | 000,000,000 | ---D | M] -- C:\FrozenSynapse [2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs [2011.11.29 19:47:31 | 000,000,000 | R--D | M] -- C:\Program Files [2011.12.03 16:49:13 | 000,000,000 | -H-D | M] -- C:\ProgramData [2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Programme [2009.11.27 13:48:40 | 000,000,000 | -HSD | M] -- C:\Recovery [2011.12.03 16:58:07 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2009.11.27 13:51:09 | 000,000,000 | R--D | M] -- C:\Users [2011.10.24 18:26:18 | 000,000,000 | ---D | M] -- C:\Windows < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.manifest /3 > < MD5 for: AFD.SYS > [2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\System32\drivers\afd.sys [2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_d81220b5bf827af7\afd.sys [2010.11.20 09:40:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=1151FD4FB0216CFED887BFDE29EBD516 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b\afd.sys [2011.04.25 03:18:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=9EBBBA55060F786F0FCAA3893BFA2806 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_d9f97e05bca8003a\afd.sys [2011.04.25 03:27:23 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C114AB7A1550D42EA1700FFD4179CF5A -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys [2011.04.25 04:24:09 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C427F91A748CD342A2B3F9278D9FD6A5 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_da774a9ad5cea29e\afd.sys [2009.07.14 00:12:38 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=DDC040FDB01EF1712A6B13E52AFB104C -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys < MD5 for: EXPLORER.EXE > [2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe [2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe [2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe [2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe [2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe [2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe [2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe [2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe < MD5 for: REGEDIT.EXE > [2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe [2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe < MD5 for: USERINIT.EXE > [2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe [2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-03 14:43:03 < End of report > |
Themen zu vermute virus nach installation einer .exe datei aus nicht 100%sicherer Quelle. |
adobe, antivir, autorun, avira, c:\windows\system32\rundll32.exe, defender, explorer, fehlermeldung, firefox, format, host.exe, installation, langs, log, logfile, microsoft, mozilla thunderbird, object, ordner, plug-in, programme, required, rundll, scan, sched.exe, secure, software, taskhost.exe, usb, virus, webcheck, windows, winlogon.exe, wmp |