|
Plagegeister aller Art und deren Bekämpfung: Blackscreen + "Lags" Was tunWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.12.2011, 00:33 | #1 |
| Blackscreen + "Lags" Was tun Blackscreen & "Lags" Guten Abend, da ich mein Problem nicht definitiv einer "Problemzone" zuordnen kann, hoffe ich ihr könnt mir trotzdessen helfen. Das Problem begann vor mittlerweile 1 1/2 Wochen in Form eines "Standbildes" + BIOS-Sound( dieses Biepen, durchgehend). Nach dem Neustart des Rechners, wurde durch den Monitor eine "Kein Signal" Meldung angezeigt. Nachdem Austauschen des Monitors wurde zumindest das Bild erst mal wieder dargestellt. Allerdings eröffnete sich mir da schon das nächste Problem: Das Bild wurde extrem fehlerhaft dargestellt. Zudem konnte ich die Bildtiefe auf nicht mehr als 4Bit einstellen. Die Graka wurde nicht erkannt, DirectX angeblich nicht vorhanden. Ansonsten funktionierte das System reibungslos. Daraufhin reinigte ich den Rechner und tauschte die Grafikkarte aus. Wie erhofft wurde das Bild fehlerfrei angezeigt, die Graka erkannt und DirectX wieder vorhanden. Jetzt zum aktuellen Problem: Wird der Rechner gestartet wechselt der Monitor nachdem Booten in ein "Blackscreen" bei dem die Maus gesteuert werden kann. Das dauert ca. 10 sec. an danach geht der Startvorgang normal von statten. Doch schon bei der Darstellung des Windowslogos "hängt" der Desktop kurze Zeit. Bin ich dan angemeldet wird jede Aktion von Verzögerungen begleitet. Aus Mangel an Worten bezeichne ich das jetz mal als "Lag". Der Dektop ist eingefroren und ich kann nichts machen. Ab udn an wird das auch von dem BIOS Sound begleitet(durchgehendes Biepen) "Lags" dauern 2-20sec. Filme/Programmstarts/Texteingabe etc. ist schwer bis gar nicht möglich auf Grund dieser Verzögerungen. Hoffe die Anamnese hilft erst mal weiter... Systeminformationen: Windows Vista Home Premium 32bit / SP2 Motherboard ID 07/17/2007-SiS-671-2A7IGG01C-00 Motherboard Hersteller PACKARD BELL BV GA-T671MG CPU Name: Intel Core 2 Duo CPU E4500 2.20GHz Grafikkarte: GeForce GT 520 Treiber:nvd3dum (8.17.12.7533),nvwgf2um,nvwgf2um 2 GB Arbeitsspeicher Ähm ja falls ihr noch weitere Infos braucht sagts einfach, ich versuch mein Bestes. Ich habe im I-Net schon mal einige Infos zusammengetragen und daraufhin das hier geladen/ausgeführt: Ad-Aware, Avira, SpyBot, Malwarebytes' Anti-Malware. CPU Stable Test, Wise Registry Cleaner, Memtest(Noch nicht durchgeführt), HiJackThis, RSIT, Defogger, OTL. Logs pinn ich ma gleich mit dran. Hoffe auf rasche Antwort. Mr.Tencendur Mh...kurioser weise kann ich keine Dateianhänge mitsenden da ich nicht eingeloggt bin -.- ...Egal wie oft ich mich einlogge es wid immer nur wieder neu das Einloggfenster geladen..ichversuchs weiterhin. Gerade noch gesehen das ich die OTL.txt datei direkt hier rein posten soll.OTL Logfile: Code:
ATTFilter OTL logfile created on: 21.12.2011 22:45:41 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\***\Desktop\SystemControl Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 62,10% Memory free 4,23 Gb Paging File | 3,39 Gb Available in Paging File | 80,17% Paging File free Paging file location(s): c:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 290,09 Gb Total Space | 18,24 Gb Free Space | 6,29% Space Free | Partition Type: NTFS Drive G: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ***-PC | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.12.21 22:33:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\SystemControl\OTL.exe PRC - [2011.12.15 20:06:44 | 000,127,040 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ7.7\ICQ.exe PRC - [2011.07.15 11:19:17 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2011.05.25 08:25:02 | 000,839,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2011.05.25 08:24:56 | 000,373,864 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2011.05.25 08:24:45 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe PRC - [2011.05.04 14:40:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2010.12.11 08:57:11 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2010.09.23 12:08:48 | 000,604,416 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe PRC - [2010.05.08 12:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe PRC - [2010.05.08 12:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2009.10.02 22:32:51 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2009.04.11 07:28:15 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.03.05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PRC - [2009.01.26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe PRC - [2007.05.10 16:10:00 | 004,468,736 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2007.03.29 14:41:26 | 000,222,128 | ---- | M] (Macrovision Corporation) -- C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe ========== Modules (No Company Name) ========== MOD - [2009.02.27 15:39:29 | 000,019,968 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ========== Win32 Services (SafeList) ========== SRV - [2011.10.28 19:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) [On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2011.07.15 11:19:17 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.05.25 08:24:45 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2011.05.04 14:40:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2010.09.23 12:08:48 | 000,604,416 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc) SRV - [2010.09.23 12:08:45 | 000,361,216 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag) SRV - [2010.09.22 21:30:44 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010.05.08 12:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe) SRV - [2009.04.27 13:21:36 | 000,028,928 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp) SRV - [2009.01.26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService) SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) ========== Driver Services (SafeList) ========== DRV - [2011.10.28 19:35:26 | 000,015,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer) DRV - [2011.07.15 11:19:20 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011.07.15 11:19:20 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.05.25 08:24:42 | 010,589,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2010.09.22 20:35:47 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2010.07.05 13:17:50 | 000,015,172 | ---- | M] (Prassi Technology) [Kernel | Boot | Running] -- C:\Windows\system32\Drivers\PzWDM.sys -- (PzWDM) DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2009.06.22 18:17:20 | 000,103,680 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cm_ser.sys -- (cm_ser) DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2007.01.23 10:01:00 | 000,050,176 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - user.js..browser.search.selectedEngine: "Search the web" FF - user.js..browser.search.order.1: "Search the web" FF - user.js..browser.search.defaultenginename: "Search the web" FF - user.js..keyword.URL: "hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.) [2010.08.10 13:43:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2011.12.17 04:17:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions [2008.04.23 18:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2011.12.15 20:11:15 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011.12.17 04:17:32 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\plugin@yontoo.com [2008.04.23 18:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\TEMP [2011.11.12 00:52:02 | 000,000,000 | ---D | M] (toolplugin) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\welcome@toolmin.com [2011.03.30 14:14:34 | 000,001,042 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\d066qnlp.default\searchplugins\icqplugin.xml [2008.04.25 23:01:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2008.04.23 05:15:39 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\PACKARDBELL@PARTNERS.MOZILLA.COM File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\TALKBACK@MOZILLA.ORG [2006.11.09 14:20:40 | 002,111,096 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll O1 HOSTS File: ([2011.05.21 19:11:47 | 000,419,912 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 14490 more lines... O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-89AF-189327213627} - No CLSID value found. O3 - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-974869382-2840092170-1439893959-1002..\Run: [ICQ] C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-974869382-2840092170-1439893959-1002..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) O4 - HKU\S-1-5-21-974869382-2840092170-1439893959-1002..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-21-974869382-2840092170-1439893959-1005..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O7 - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.225 193.189.244.206 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E86F415-C3A2-455A-A5CC-DF4AC4F6B014}: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59E6236C-16CB-4123-BF94-C8B796D681CC}: DhcpNameServer = 193.189.244.225 193.189.244.206 O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\***\Desktop\All in one\Bilddaz,Picz\PICT0001.JPG O24 - Desktop BackupWallPaper: C:\Users\***\Desktop\All in one\Bilddaz,Picz\PICT0001.JPG O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2010.10.17 13:11:37 | 000,000,000 | ---D | M] - C:\Autorun -- [ NTFS ] O32 - AutoRun File - [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () - G:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2008.03.10 01:34:52 | 000,000,047 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{0c0bffb0-6023-11de-aa2e-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{0c0bffb0-6023-11de-aa2e-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{13768b13-2968-11e0-94d8-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{13768b13-2968-11e0-94d8-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{13768b7a-2968-11e0-94d8-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{13768b7a-2968-11e0-94d8-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{14754a21-2a75-11e1-bc50-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{14754a21-2a75-11e1-bc50-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () O33 - MountPoints2\{2012c120-c682-11df-a6d4-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{2012c120-c682-11df-a6d4-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () O33 - MountPoints2\{20166a92-dd3c-11df-ad74-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{20166a92-dd3c-11df-ad74-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{20166aab-dd3c-11df-ad74-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{20166aab-dd3c-11df-ad74-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{25a4f93e-2969-11e0-bba8-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{25a4f93e-2969-11e0-bba8-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{25a4f969-2969-11e0-bba8-001e101fb681}\Shell - "" = AutoRun O33 - MountPoints2\{25a4f969-2969-11e0-bba8-001e101fb681}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{25f5a8f6-9432-11df-ad51-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{25f5a8f6-9432-11df-ad51-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O33 - MountPoints2\{293597f3-5463-11e0-91c3-001e101fe5e1}\Shell - "" = AutoRun O33 - MountPoints2\{293597f3-5463-11e0-91c3-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{4a9b08dd-2971-11e0-bc76-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{4a9b08dd-2971-11e0-bc76-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{59caa7f0-3129-11e0-8609-001e101f9743}\Shell - "" = AutoRun O33 - MountPoints2\{59caa7f0-3129-11e0-8609-001e101f9743}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{60424ec3-5f4d-11de-933b-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{60424ec3-5f4d-11de-933b-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{60424f0d-5f4d-11de-933b-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{60424f0d-5f4d-11de-933b-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{64ba5e91-6f12-11e0-81a6-001e101f0f46}\Shell - "" = AutoRun O33 - MountPoints2\{64ba5e91-6f12-11e0-81a6-001e101f0f46}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{6ee3536d-4b7e-11dd-b3df-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{6ee3536d-4b7e-11dd-b3df-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe O33 - MountPoints2\{71cf97f3-e055-11df-ae7e-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{71cf97f3-e055-11df-ae7e-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{71cf9836-e055-11df-ae7e-001e101f8aaa}\Shell - "" = AutoRun O33 - MountPoints2\{71cf9836-e055-11df-ae7e-001e101f8aaa}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{7ba3d2df-0d13-11e0-8370-001e101f859f}\Shell - "" = AutoRun O33 - MountPoints2\{7ba3d2df-0d13-11e0-8370-001e101f859f}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{82023bc2-10ee-11dd-96c6-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{82023bc2-10ee-11dd-96c6-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autoplay.exe O33 - MountPoints2\{94ba9646-10f3-11dd-b740-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{94ba9646-10f3-11dd-b740-001a4ddcbf24}\Shell\AutoRun\command - "" = J:\StartVMCLite.exe O33 - MountPoints2\{94ba964d-10f3-11dd-b740-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{94ba964d-10f3-11dd-b740-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe O33 - MountPoints2\{9f659e65-3217-11e0-a044-001e101f82a7}\Shell - "" = AutoRun O33 - MountPoints2\{9f659e65-3217-11e0-a044-001e101f82a7}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{bea039e2-f50c-11df-8cbe-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{bea039e2-f50c-11df-8cbe-001e101f82a0}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c8ec4f0c-4df2-11dd-b643-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{c8ec4f0c-4df2-11dd-b643-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe O33 - MountPoints2\{cc5b4193-6e53-11e0-8e8b-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{cc5b4193-6e53-11e0-8e8b-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{ccb0ae2d-2a7b-11e1-8c51-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{ccb0ae2d-2a7b-11e1-8c51-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () O33 - MountPoints2\{de6263c2-1f5b-11e1-86af-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{de6263c2-1f5b-11e1-86af-001a4ddcbf24}\Shell\AutoRun\command - "" = Iomega Encryption Utility.exe O33 - MountPoints2\{f814b44e-606b-11e0-bc16-001e101f50a4}\Shell - "" = AutoRun O33 - MountPoints2\{f814b44e-606b-11e0-bc16-001e101f50a4}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Installer.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (lsdelete) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.12.19 21:00:08 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Macrovision [2011.12.19 20:15:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner [2011.12.19 20:15:03 | 000,069,504 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jucdcacm.sys [2011.12.19 20:15:03 | 000,063,616 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jubusenum.sys [2011.12.19 20:15:03 | 000,046,336 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jucdcecm.sys [2011.12.19 20:15:03 | 000,025,088 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_juextctrl.sys [2011.12.19 20:14:56 | 000,861,696 | ---- | C] (DiBcom SA) -- C:\Windows\System32\drivers\mod7700.sys [2011.12.19 20:14:56 | 000,116,736 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbnet.sys [2011.12.19 20:14:56 | 000,105,984 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys [2011.12.19 20:14:56 | 000,023,424 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys [2011.12.19 20:14:56 | 000,011,136 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_usbenumfilter.sys [2011.12.19 20:14:48 | 000,101,504 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_hwusbdev.sys [2011.12.18 03:17:12 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\vlc [2011.12.17 17:22:34 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Wise Registry Cleaner [2011.12.17 17:21:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner [2011.12.17 17:10:51 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\PackageAware [2011.12.17 06:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro [2011.12.17 06:33:40 | 000,000,000 | ---D | C] -- C:\rsit [2011.12.17 04:20:31 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2011.12.17 04:19:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.12.17 04:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.12.17 04:18:54 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.12.17 04:17:17 | 000,000,000 | ---D | C] -- C:\Program Files\Yontoo Layers Runtime [2011.12.17 04:16:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2011.12.17 04:14:00 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\***\Desktop\mbam-setup-1.51.2.1300.exe [2011.12.17 02:49:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys [2011.12.17 00:04:12 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\SystemControl [2011.12.16 21:05:58 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Macromedia [2011.12.16 05:04:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III [2011.12.16 02:51:43 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2011.12.16 02:51:25 | 002,560,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll [2011.12.16 02:51:25 | 000,066,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll [2011.12.16 02:51:13 | 003,693,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll [2011.12.16 02:51:13 | 002,557,544 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll [2011.12.16 02:51:13 | 000,111,208 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll [2011.12.16 02:51:09 | 000,543,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll [2011.12.16 02:49:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation [2011.12.16 02:44:32 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll [2011.12.16 02:44:31 | 016,456,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll [2011.12.16 02:44:31 | 010,589,800 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys [2011.12.16 02:44:31 | 006,555,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll [2011.12.16 02:44:31 | 000,899,688 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco3220150.dll [2011.12.16 02:44:31 | 000,865,896 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco322090.dll [2011.12.16 02:44:30 | 013,011,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll [2011.12.16 02:44:30 | 011,992,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll [2011.12.16 02:44:30 | 005,301,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll [2011.12.16 02:44:30 | 002,804,328 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll [2011.12.16 02:44:30 | 002,082,408 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll [2011.12.16 02:44:29 | 002,335,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll [2011.12.16 02:44:29 | 000,012,392 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvBridge.kmd [2011.12.16 01:52:28 | 000,000,000 | ---D | C] -- C:\MFT 3777 [2011.12.15 20:40:40 | 000,000,000 | ---D | C] -- C:\Windows\pss [2011.12.15 20:11:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.7 [2011.12.15 20:05:50 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.7 [2011.12.15 06:18:15 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2011.12.15 05:54:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft [2011.12.15 05:54:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2011.12.15 05:54:27 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft [2011.12.14 19:17:02 | 000,000,000 | R--D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011.12.14 17:56:51 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011.12.14 17:56:49 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2011.12.14 17:56:49 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011.12.14 17:56:48 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2011.12.14 17:56:47 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011.12.14 17:56:41 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011.12.14 17:49:44 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2011.12.14 17:49:42 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.12.14 17:49:39 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2011.12.14 17:49:39 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2011.12.14 17:49:29 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2011.12.14 17:49:18 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2011.12.14 17:08:44 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll [2011.12.14 17:08:44 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll [2011.12.14 17:08:44 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll [2011.12.14 17:08:43 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll [2011.12.14 17:08:43 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll [2011.12.14 17:08:43 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll [2011.12.14 17:08:42 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll [2011.12.14 17:08:42 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll [2011.12.14 17:08:41 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll [2011.12.14 17:08:41 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll [2011.12.14 17:08:41 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll [2011.12.14 17:08:41 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll [2011.12.13 21:52:26 | 000,000,000 | ---D | C] -- C:\Program Files\MSI Afterburner [2011.12.13 21:13:23 | 000,941,160 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco322090.dll [2011.12.13 21:13:20 | 000,837,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco322040.dll [2011.12.11 21:10:02 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011.12.11 00:19:44 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2011.12.11 00:19:44 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2011.12.11 00:19:44 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2011.12.11 00:19:44 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2011.12.11 00:19:43 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2011.12.11 00:19:43 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2011.12.11 00:19:43 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.12.11 00:19:43 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2011.12.11 00:19:43 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2011.12.11 00:19:43 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.12.11 00:19:43 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.12.11 00:19:43 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.12.11 00:19:43 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2011.12.11 00:19:43 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.12.11 00:19:42 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.12.11 00:19:42 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.12.11 00:19:42 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2011.12.11 00:19:42 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2011.12.11 00:19:42 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.12.11 00:19:42 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2011.12.11 00:19:42 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2011.12.11 00:19:42 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.12.11 00:19:41 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2011.12.11 00:19:41 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2011.12.11 00:19:41 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2011.12.11 00:19:41 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.12.11 00:19:41 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2011.12.11 00:19:41 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2011.12.11 00:19:41 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.12.11 00:19:41 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2011.12.11 00:19:41 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.12.11 00:18:44 | 000,979,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll [2011.12.11 00:18:44 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll [2011.12.11 00:18:44 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll [2011.12.11 00:18:44 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll [2011.12.11 00:18:43 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll [2011.12.11 00:18:43 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll [2011.12.11 00:18:43 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll [2011.12.11 00:18:41 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe [2011.12.11 00:18:41 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2011.12.11 00:18:41 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll [2011.12.11 00:18:41 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll [2011.12.11 00:18:41 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll [2011.11.25 18:28:21 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\PALIM PALIM [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.21 23:00:03 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\1-Click Maintenance.job [2011.12.21 22:50:57 | 007,551,736 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.12.21 22:50:57 | 002,699,728 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.12.21 22:50:57 | 002,338,372 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.12.21 22:50:57 | 002,116,380 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.12.21 22:40:51 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.12.21 22:40:50 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.12.21 22:39:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.12.21 22:38:55 | 000,000,020 | ---- | M] () -- C:\Users\***\defogger_reenable [2011.12.19 20:32:33 | 000,000,680 | ---- | M] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2011.12.19 20:15:40 | 000,000,839 | ---- | M] () -- C:\Users\Public\Desktop\Mobile Partner.lnk [2011.12.17 04:15:47 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\***\Desktop\mbam-setup-1.51.2.1300.exe [2011.12.17 02:49:25 | 000,000,726 | ---- | M] () -- C:\Users\***\Desktop\EVEREST Home Edition.lnk [2011.12.16 05:06:28 | 000,000,925 | ---- | M] () -- C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk [2011.12.15 20:11:57 | 000,001,572 | ---- | M] () -- C:\Users\Public\Desktop\ICQ7.7.lnk [2011.12.15 06:18:14 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2011.12.15 06:17:44 | 000,016,432 | ---- | M] () -- C:\Windows\System32\lsdelete.exe [2011.12.15 04:55:59 | 000,001,100 | ---- | M] () -- C:\Users\***\AppData\Local\d3d8caps.dat [2011.12.14 18:08:18 | 002,346,928 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.12.14 18:02:04 | 000,184,320 | -H-- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.12.11 22:59:51 | 000,001,594 | ---- | M] () -- C:\Users\***\Desktop\config.ini [2011.12.11 00:19:50 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat [2011.12.11 00:19:50 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat [2011.12.11 00:19:44 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2011.12.11 00:19:44 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2011.12.11 00:19:44 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2011.12.11 00:19:44 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2011.12.11 00:19:43 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2011.12.11 00:19:43 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2011.12.11 00:19:43 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.12.11 00:19:43 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2011.12.11 00:19:43 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2011.12.11 00:19:43 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.12.11 00:19:43 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.12.11 00:19:43 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.12.11 00:19:43 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2011.12.11 00:19:43 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2011.12.11 00:19:43 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.12.11 00:19:42 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.12.11 00:19:42 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.12.11 00:19:42 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2011.12.11 00:19:42 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2011.12.11 00:19:42 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.12.11 00:19:42 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2011.12.11 00:19:42 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2011.12.11 00:19:42 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.12.11 00:19:41 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2011.12.11 00:19:41 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2011.12.11 00:19:41 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2011.12.11 00:19:41 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.12.11 00:19:41 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2011.12.11 00:19:41 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2011.12.11 00:19:41 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.12.11 00:19:41 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2011.12.11 00:19:41 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.12.11 00:18:44 | 000,979,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll [2011.12.11 00:18:44 | 000,357,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll [2011.12.11 00:18:44 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll [2011.12.11 00:18:44 | 000,261,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll [2011.12.11 00:18:43 | 002,873,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mf.dll [2011.12.11 00:18:43 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll [2011.12.11 00:18:43 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll [2011.12.11 00:18:41 | 000,667,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe [2011.12.11 00:18:41 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2011.12.11 00:18:41 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll [2011.12.11 00:18:41 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll [2011.12.11 00:18:41 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll [2011.11.27 14:28:23 | 000,000,000 | ---- | M] () -- C:\Windows\System32\Access.dat [2011.11.26 16:20:09 | 000,001,940 | ---- | M] () -- C:\Users\***\Desktop\Spybot - Search & Destroy.lnk [2011.11.23 14:37:27 | 002,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.12.21 22:37:21 | 000,000,020 | ---- | C] () -- C:\Users\***\defogger_reenable [2011.12.19 20:15:40 | 000,000,839 | ---- | C] () -- C:\Users\Public\Desktop\Mobile Partner.lnk [2011.12.17 02:49:25 | 000,000,726 | ---- | C] () -- C:\Users\***\Desktop\EVEREST Home Edition.lnk [2011.12.16 05:04:09 | 000,000,925 | ---- | C] () -- C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk [2011.12.16 02:44:31 | 000,004,364 | ---- | C] () -- C:\Windows\System32\nvinfo.pb [2011.12.15 20:11:57 | 000,001,572 | ---- | C] () -- C:\Users\Public\Desktop\ICQ7.7.lnk [2011.12.15 13:44:20 | 000,016,432 | ---- | C] () -- C:\Windows\System32\lsdelete.exe [2011.12.11 22:59:51 | 000,001,594 | ---- | C] () -- C:\Users\***\Desktop\config.ini [2011.12.11 00:29:59 | 000,000,912 | ---- | C] () -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011.12.11 00:19:43 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2011.11.26 16:20:09 | 000,001,940 | ---- | C] () -- C:\Users\***\Desktop\Spybot - Search & Destroy.lnk [2011.05.20 22:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2011.05.10 03:00:19 | 000,000,610 | ---- | C] () -- C:\Windows\System32\wun32.dll [2010.11.01 07:01:35 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat [2010.10.21 19:18:56 | 000,000,680 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat [2010.09.23 11:34:08 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010.09.23 11:34:08 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010.07.05 13:17:47 | 000,091,923 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2010.07.05 13:17:47 | 000,076,956 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2010.07.05 13:17:47 | 000,039,121 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2010.07.05 13:17:47 | 000,027,965 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_JP.dat [2009.06.22 18:57:55 | 000,000,000 | ---- | C] () -- C:\Windows\System32\WoW-3.0.3.9183-to-3.0.8.9464-deDE-patch.exe.part [2009.06.22 18:57:23 | 000,000,000 | ---- | C] () -- C:\Windows\System32\WoW-3.0.8.9464-to-3.0.8.9506-deDE-patch.exe.part [2009.04.23 03:25:55 | 000,000,000 | ---- | C] () -- C:\Windows\iPlayer.INI [2008.11.11 07:03:00 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2008.07.06 21:35:22 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll [2008.07.06 21:35:22 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll [2008.07.06 21:35:22 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll [2008.06.27 00:45:54 | 000,001,100 | ---- | C] () -- C:\Users\***\AppData\Local\d3d8caps.dat [2008.05.25 21:06:37 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll [2008.05.09 02:36:50 | 000,000,442 | ---- | C] () -- C:\Windows\SIERRA.INI [2008.04.23 18:25:30 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys [2008.04.23 18:13:09 | 000,000,403 | ---- | C] () -- C:\Windows\ODBC.INI [2008.04.23 14:36:10 | 007,551,736 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.04.23 14:36:10 | 002,338,372 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.04.23 14:36:10 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.04.23 14:36:10 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2008.04.23 08:27:22 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll [2008.04.23 06:06:26 | 000,184,320 | -H-- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.04.23 05:52:18 | 000,000,094 | -H-- | C] () -- C:\Users\***\AppData\Local\fusioncache.dat [2007.02.13 08:48:38 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini [2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 13:47:37 | 002,346,928 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 11:33:01 | 002,699,728 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 11:33:01 | 002,116,380 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [1999.04.30 01:00:00 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL [1997.06.14 12:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll < End of report > Geändert von Tencendur (22.12.2011 um 00:59 Uhr) |
22.12.2011, 08:22 | #2 | ||||
/// Helfer-Team | Blackscreen + "Lags" Was tun Hallo und Herzlich Willkommen!
__________________Bevor wir unsere Zusammenarbeit beginnen, [Bitte Vollständig lesen]: Zitat:
Hast du in der letzten Zeit:
Für Vista und Win7: Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen! 1. Zitat:
meiner Meinung nach bietet nicht mehr ausreichenden Schutz gegen "moderne Malwarearten"... 2. Zitat:
Code:
ATTFilter :OTL IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-974869382-2840092170-1439893959-1002\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found FF - prefs.js..browser.startup.homepage: "http://start.icq.com/" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - user.js..browser.search.selectedEngine: "Search the web" FF - user.js..browser.search.order.1: "Search the web" FF - user.js..browser.search.defaultenginename: "Search the web" FF - user.js..keyword.URL: "http://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-89AF-189327213627} - No CLSID value found. O4 - HKLM..\Run: [] File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010.10.17 13:11:37 | 000,000,000 | ---D | M] - C:\Autorun -- [ NTFS ] O32 - AutoRun File - [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () - G:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2008.03.10 01:34:52 | 000,000,047 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{0c0bffb0-6023-11de-aa2e-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{0c0bffb0-6023-11de-aa2e-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{13768b13-2968-11e0-94d8-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{13768b13-2968-11e0-94d8-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{13768b7a-2968-11e0-94d8-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{13768b7a-2968-11e0-94d8-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{14754a21-2a75-11e1-bc50-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{14754a21-2a75-11e1-bc50-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () O33 - MountPoints2\{2012c120-c682-11df-a6d4-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{2012c120-c682-11df-a6d4-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () O33 - MountPoints2\{20166a92-dd3c-11df-ad74-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{20166a92-dd3c-11df-ad74-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{20166aab-dd3c-11df-ad74-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{20166aab-dd3c-11df-ad74-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{25a4f93e-2969-11e0-bba8-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{25a4f93e-2969-11e0-bba8-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{25a4f969-2969-11e0-bba8-001e101fb681}\Shell - "" = AutoRun O33 - MountPoints2\{25a4f969-2969-11e0-bba8-001e101fb681}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{25f5a8f6-9432-11df-ad51-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{25f5a8f6-9432-11df-ad51-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O33 - MountPoints2\{293597f3-5463-11e0-91c3-001e101fe5e1}\Shell - "" = AutoRun O33 - MountPoints2\{293597f3-5463-11e0-91c3-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{4a9b08dd-2971-11e0-bc76-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{4a9b08dd-2971-11e0-bc76-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{59caa7f0-3129-11e0-8609-001e101f9743}\Shell - "" = AutoRun O33 - MountPoints2\{59caa7f0-3129-11e0-8609-001e101f9743}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{60424ec3-5f4d-11de-933b-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{60424ec3-5f4d-11de-933b-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{60424f0d-5f4d-11de-933b-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{60424f0d-5f4d-11de-933b-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{64ba5e91-6f12-11e0-81a6-001e101f0f46}\Shell - "" = AutoRun O33 - MountPoints2\{64ba5e91-6f12-11e0-81a6-001e101f0f46}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{6ee3536d-4b7e-11dd-b3df-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{6ee3536d-4b7e-11dd-b3df-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe O33 - MountPoints2\{71cf97f3-e055-11df-ae7e-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{71cf97f3-e055-11df-ae7e-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{71cf9836-e055-11df-ae7e-001e101f8aaa}\Shell - "" = AutoRun O33 - MountPoints2\{71cf9836-e055-11df-ae7e-001e101f8aaa}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{7ba3d2df-0d13-11e0-8370-001e101f859f}\Shell - "" = AutoRun O33 - MountPoints2\{7ba3d2df-0d13-11e0-8370-001e101f859f}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{82023bc2-10ee-11dd-96c6-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{82023bc2-10ee-11dd-96c6-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autoplay.exe O33 - MountPoints2\{94ba9646-10f3-11dd-b740-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{94ba9646-10f3-11dd-b740-001a4ddcbf24}\Shell\AutoRun\command - "" = J:\StartVMCLite.exe O33 - MountPoints2\{94ba964d-10f3-11dd-b740-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{94ba964d-10f3-11dd-b740-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe O33 - MountPoints2\{9f659e65-3217-11e0-a044-001e101f82a7}\Shell - "" = AutoRun O33 - MountPoints2\{9f659e65-3217-11e0-a044-001e101f82a7}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{bea039e2-f50c-11df-8cbe-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{bea039e2-f50c-11df-8cbe-001e101f82a0}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{c8ec4f0c-4df2-11dd-b643-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{c8ec4f0c-4df2-11dd-b643-001a4ddcbf24}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe O33 - MountPoints2\{cc5b4193-6e53-11e0-8e8b-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{cc5b4193-6e53-11e0-8e8b-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{ccb0ae2d-2a7b-11e1-8c51-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{ccb0ae2d-2a7b-11e1-8c51-001a4ddcbf24}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.05.08 20:48:36 | 000,126,976 | R--- | M] () O33 - MountPoints2\{de6263c2-1f5b-11e1-86af-001a4ddcbf24}\Shell - "" = AutoRun O33 - MountPoints2\{de6263c2-1f5b-11e1-86af-001a4ddcbf24}\Shell\AutoRun\command - "" = Iomega Encryption Utility.exe O33 - MountPoints2\{f814b44e-606b-11e0-bc16-001e101f50a4}\Shell - "" = AutoRun O33 - MountPoints2\{f814b44e-606b-11e0-bc16-001e101f50a4}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Installer.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a :Commands [purity] [emptytemp] [resethosts]
3. Lade Dir Malwarebytes Anti-Malware von→ malwarebytes.org
4. Ich würde gerne noch all deine installierten Programme sehen: Lade dir das Tool CCleaner herunter → Download installieren (Software-Lizenzvereinbarung lesen, falls angeboten wird "Füge CCleaner Yahoo! Toolbar hinzu" abwählen)→ starten→ Sprache → Deutsch auswählen dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..." wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein 5. erneut einen Scan mit OTL:
6. läuft unter XP, Vista mit (32Bit) und Windows 7 (32Bit) Achtung!: WENN GMER NICHT AUSGEFÜHRT WERDEN KANN ODER PROBMLEME VERURSACHT, fahre mit dem nächsten Punkt fort!- Es ist NICHT sinnvoll einen zweiten Versuch zu starten! Um einen tieferen Einblick in dein System, um eine mögliche Infektion mit einem Rootkit/Info v.wikipedia.org) aufzuspüren, werden wir ein Tool - Gmer - einsetzen :
** keine Verbindung zu einem Netzwerk und Internet - WLAN nicht vergessen Wenn der Scan beendet ist, bitte alle Programme und Tools wieder aktivieren! Anleitung:-> GMER - Rootkit Scanner 7. Kontrolle mit MBR -t, ob Master Boot Record in Ordnung ist (MBR-Rootkit) Mit dem folgenden Tool prüfen wir, ob sich etwas Schädliches im Master Boot Record eingenistet hat.
Zitat:
kira
__________________ |
23.12.2011, 13:08 | #3 |
| Blackscreen + "Lags" Was tun Hallo und danke für die Antwort,
__________________Ich habe lediglich den GrakaTreiber installiert - keine externene Medien angeschlossen und keine Viren erkannt. Hier die Logs: Alle installierten Programme Code:
ATTFilter 7-Zip 9.20 21.12.2011 3,54MB Acrobat.com Adobe Systems Incorporated 21.09.2010 1,70MB 1.2.443 Ad-Aware Lavasoft Limited 14.12.2011 31,6MB 9.6.0 Adobe AIR Adobe Systems Inc. 21.09.2010 1.1.0.5790 Adobe Creative Suite 4 Master Collection Adobe Systems Incorporated 21.09.2010 4.0 Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 22.09.2010 2,95MB 10.1.85.3 Adobe Flash Player 10 Plugin Adobe Systems Incorporated 23.06.2011 2,95MB 10.3.181.26 Avira AntiVir Personal - Free Antivirus Avira GmbH 14.07.2011 90,7MB 10.2.0.696 CCleaner Piriform 21.12.2011 4,22MB 3.14 Dawn Of War THQ 16.10.2010 1.670MB 1.40 Dawn of War - Dark Crusade THQ 07.10.2010 4.268MB 1.00.0000 Dawn of War - Soulstorm THQ 16.10.2010 5.315MB 1.00.0000 Dawn of War - Tyranid Mod v0.45SS "Team Super Ninja" 29.07.2011 5.536MB "0.45SS" EVE Online (remove only) CCP Games Ltd. 15.10.2011 8.893MB EVEREST Home Edition v2.20 Lavalys Inc 16.12.2011 10,6MB 2.20 Firefox 22.04.2008 Flash Player 9 Internet Explorer 22.04.2008 1,49MB HDRegDE Acxiom 22.04.2008 2,04MB 2.0.0 ICQ7.7 ICQ 14.12.2011 60,4MB 7.7 Malwarebytes' Anti-Malware Version 1.51.2.1300 Malwarebytes Corporation 16.12.2011 7,08MB 1.51.2.1300 Microsoft .NET Framework 1.1 10.07.2008 Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft Corporation 22.09.2010 37,0MB Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 02.08.2009 27,8MB Microsoft .NET Framework 4 Client Profile Microsoft Corporation 22.09.2010 120,3MB 4.0.30319 Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 22.09.2010 24,5MB 4.0.30319 Microsoft Office Enterprise 2007 Microsoft Corporation 22.09.2010 375MB 12.0.6425.1000 Microsoft SQL Server Compact 4.0 ENU Microsoft Corporation 09.09.2011 11,0MB 4.0.8482.1 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 27.10.2011 0,58MB 9.0.30729 Mobile Partner Huawei Technologies Co.,Ltd 18.12.2011 43,1MB 11.302.09.04.382 Norton 360 2007 22.04.2008 NVIDIA Grafiktreiber 275.33 NVIDIA Corporation 15.12.2011 40,9MB 275.33 NVIDIA PhysX-Systemsoftware 9.10.0514 NVIDIA Corporation 15.12.2011 73,3MB 9.10.0514 NVIDIA Update 1.3.5 NVIDIA Corporation 15.12.2011 6,37MB 1.3.5 Opera 11.60 Opera Software ASA 12.12.2011 35,0MB 11.60.1185 Packard Bell LCD Test 22.04.2008 74,3MB Packard Bell Updator 22.04.2008 74,3MB Picasa2 22.04.2008 Realtek HD Audio V6.0.1.5413 22.04.2008 Shockwave player 10 22.04.2008 Skype 2.5.2.151 22.04.2008 14,4MB Skype™ 5.3 Skype Technologies S.A. 15.05.2011 16,5MB 5.3.111 TeamSpeak 3 Client TeamSpeak Systems GmbH 27.10.2011 29,4MB TuneUp Utilities 2009 TuneUp Software 22.09.2010 8.0.3100.31 VLC media player 1.1.4 VideoLAN 21.09.2010 76,7MB 1.1.4 Warcraft III Blizzard Entertainment 15.12.2011 1.444MB Warcraft III 16.12.2011 WinRAR 22.04.2008 3,66MB Wise Registry Cleaner 6.14 WiseCleaner.com, Inc. 16.12.2011 2,86MB Yontoo Layers Runtime 1.10.01 Yontoo LLC 16.12.2011 0,19MB 1.10.01 OTL: Code:
ATTFilter OTL logfile created on: 22.12.2011 12:23:51 - Run 2 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\sascha\Desktop\SystemControl\OTL Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,12 Gb Available Physical Memory | 56,06% Memory free 4,24 Gb Paging File | 3,28 Gb Available in Paging File | 77,31% Paging File free Paging file location(s): c:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 290,09 Gb Total Space | 18,59 Gb Free Space | 6,41% Space Free | Partition Type: NTFS Drive F: | 20,49 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: SASCHA-PC | User Name: sascha | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days ========== Processes (SafeList) ========== PRC - [2011.12.21 22:33:51 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\sascha\Desktop\SystemControl\OTL\OTL.exe PRC - [2011.12.15 20:06:44 | 000,127,040 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ7.7\ICQ.exe PRC - [2011.12.13 11:04:16 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2011.07.15 11:19:17 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2011.05.25 08:25:02 | 000,839,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2011.05.25 08:24:56 | 000,373,864 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2011.05.25 08:24:45 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe PRC - [2011.05.04 14:40:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2010.12.11 08:57:11 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2010.09.23 12:08:48 | 000,604,416 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe PRC - [2010.05.08 12:48:36 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe PRC - [2010.05.08 12:48:26 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2009.10.02 22:32:51 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2007.05.10 16:10:00 | 004,468,736 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe ========== Modules (No Company Name) ========== MOD - [2011.06.24 15:17:28 | 006,271,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll MOD - [2009.12.10 11:52:38 | 000,192,512 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll MOD - [2009.12.10 11:51:36 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll MOD - [2009.12.10 11:40:20 | 000,991,232 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll MOD - [2009.09.19 11:21:06 | 000,139,264 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoPlugin.dll MOD - [2009.06.19 15:10:46 | 000,143,360 | ---- | M] () -- C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll MOD - [2009.06.19 15:10:22 | 000,159,744 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSPlugin.dll MOD - [2009.06.18 10:56:10 | 000,032,768 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll MOD - [2009.06.18 10:54:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Mobile Partner\ConfigFilePlugin.dll MOD - [2009.06.18 10:48:24 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll MOD - [2009.05.25 13:09:40 | 000,114,688 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceOperate.dll MOD - [2009.05.23 11:02:28 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\DetectDev.dll MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files\Mobile Partner\atcomm.dll MOD - [2009.02.27 15:39:29 | 000,019,968 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU MOD - [2007.09.20 17:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2007.08.23 16:39:30 | 000,014,848 | ---- | M] () -- C:\Program Files\Mobile Partner\isaputrace.dll MOD - [2007.07.31 15:50:04 | 000,090,112 | ---- | M] () -- C:\Program Files\Mobile Partner\FileManager.dll ========== Win32 Services (SafeList) ========== SRV - [2011.10.28 19:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) [On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2011.07.15 11:19:17 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2011.05.25 08:24:45 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2011.05.04 14:40:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2010.09.23 12:08:48 | 000,604,416 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc) SRV - [2010.09.23 12:08:45 | 000,361,216 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag) SRV - [2010.09.22 21:30:44 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010.05.08 12:48:36 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe) SRV - [2009.04.27 13:21:36 | 000,028,928 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp) SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) ========== Driver Services (SafeList) ========== DRV - [2011.10.28 19:35:26 | 000,015,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer) DRV - [2011.07.15 11:19:20 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011.07.15 11:19:20 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.05.25 08:24:42 | 010,589,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2010.09.22 20:35:47 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2010.07.05 13:17:50 | 000,015,172 | ---- | M] (Prassi Technology) [Kernel | Boot | Running] -- C:\Windows\system32\Drivers\PzWDM.sys -- (PzWDM) DRV - [2010.04.09 15:24:12 | 000,063,616 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV - [2010.03.25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2010.03.20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - [2010.03.20 10:28:12 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2009.06.22 18:17:20 | 000,103,680 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cm_ser.sys -- (cm_ser) DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2007.01.23 10:01:00 | 000,050,176 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.defaultenginename: "" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) [2010.08.10 13:43:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sascha\AppData\Roaming\mozilla\Extensions [2011.12.17 04:17:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sascha\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions [2008.04.23 18:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sascha\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2011.12.15 20:11:15 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\sascha\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011.12.17 04:17:32 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Users\sascha\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\plugin@yontoo.com [2008.04.23 18:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sascha\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\TEMP [2011.11.12 00:52:02 | 000,000,000 | ---D | M] (toolplugin) -- C:\Users\sascha\AppData\Roaming\mozilla\Firefox\Profiles\d066qnlp.default\extensions\welcome@toolmin.com [2011.03.30 14:14:34 | 000,001,042 | ---- | M] () -- C:\Users\sascha\AppData\Roaming\Mozilla\Firefox\Profiles\d066qnlp.default\searchplugins\icqplugin.xml [2008.04.25 23:01:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2008.04.23 05:15:39 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\PACKARDBELL@PARTNERS.MOZILLA.COM File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\TALKBACK@MOZILLA.ORG [2006.11.09 14:20:40 | 002,111,096 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll O1 HOSTS File: ([2011.12.22 11:58:53 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe File not found O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.189.244.225 193.189.244.206 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E86F415-C3A2-455A-A5CC-DF4AC4F6B014}: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{59E6236C-16CB-4123-BF94-C8B796D681CC}: DhcpNameServer = 193.189.244.225 193.189.244.206 O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\sascha\Desktop\All in one\Bilddaz,Picz\PICT0001.JPG O24 - Desktop BackupWallPaper: C:\Users\sascha\Desktop\All in one\Bilddaz,Picz\PICT0001.JPG O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2010.10.17 13:11:37 | 000,000,000 | ---D | M] - C:\Autorun -- [ NTFS ] O33 - MountPoints2\{07ade3cf-2a72-11e1-bb41-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{07ade3cf-2a72-11e1-bb41-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (lsdelete) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 14 Days ========== [2011.12.22 12:19:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011.12.22 11:55:22 | 000,000,000 | ---D | C] -- C:\_OTL [2011.12.22 08:46:38 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Roaming\InstallShield [2011.12.22 01:18:44 | 000,100,864 | ---- | C] (GMER) -- C:\fwriqpog.sys [2011.12.22 00:52:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip [2011.12.22 00:52:37 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2011.12.19 21:00:08 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Roaming\Macrovision [2011.12.19 20:15:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner [2011.12.19 20:15:03 | 000,069,504 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jucdcacm.sys [2011.12.19 20:15:03 | 000,063,616 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jubusenum.sys [2011.12.19 20:15:03 | 000,046,336 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jucdcecm.sys [2011.12.19 20:15:03 | 000,025,088 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_juextctrl.sys [2011.12.19 20:14:56 | 000,861,696 | ---- | C] (DiBcom SA) -- C:\Windows\System32\drivers\mod7700.sys [2011.12.19 20:14:56 | 000,116,736 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbnet.sys [2011.12.19 20:14:56 | 000,105,984 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys [2011.12.19 20:14:56 | 000,023,424 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys [2011.12.19 20:14:56 | 000,011,136 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_usbenumfilter.sys [2011.12.19 20:14:48 | 000,101,504 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_hwusbdev.sys [2011.12.18 03:17:12 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Roaming\vlc [2011.12.17 17:22:34 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Roaming\Wise Registry Cleaner [2011.12.17 17:21:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner [2011.12.17 17:10:51 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Local\PackageAware [2011.12.17 06:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro [2011.12.17 06:33:40 | 000,000,000 | ---D | C] -- C:\rsit [2011.12.17 04:20:31 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Roaming\Malwarebytes [2011.12.17 04:19:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.12.17 04:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.12.17 04:18:54 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.12.17 04:17:17 | 000,000,000 | ---D | C] -- C:\Program Files\Yontoo Layers Runtime [2011.12.17 04:16:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2011.12.17 04:14:00 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\sascha\Desktop\mbam-setup-1.51.2.1300.exe [2011.12.17 02:49:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys [2011.12.17 00:04:12 | 000,000,000 | ---D | C] -- C:\Users\sascha\Desktop\SystemControl [2011.12.16 21:05:58 | 000,000,000 | ---D | C] -- C:\Users\sascha\AppData\Roaming\Macromedia [2011.12.16 05:04:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III [2011.12.16 02:51:43 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2011.12.16 02:51:25 | 002,560,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll [2011.12.16 02:51:25 | 000,066,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll [2011.12.16 02:51:13 | 003,693,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll [2011.12.16 02:51:13 | 002,557,544 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll [2011.12.16 02:51:13 | 000,111,208 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll [2011.12.16 02:51:09 | 000,543,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll [2011.12.16 02:49:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation [2011.12.16 02:44:32 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll [2011.12.16 02:44:31 | 016,456,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll [2011.12.16 02:44:31 | 010,589,800 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys [2011.12.16 02:44:31 | 006,555,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll [2011.12.16 02:44:31 | 000,899,688 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco3220150.dll [2011.12.16 02:44:31 | 000,865,896 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco322090.dll [2011.12.16 02:44:30 | 013,011,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll [2011.12.16 02:44:30 | 011,992,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll [2011.12.16 02:44:30 | 005,301,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll [2011.12.16 02:44:30 | 002,804,328 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll [2011.12.16 02:44:30 | 002,082,408 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll [2011.12.16 02:44:29 | 002,335,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll [2011.12.16 02:44:29 | 000,012,392 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvBridge.kmd [2011.12.16 01:52:28 | 000,000,000 | ---D | C] -- C:\MFT 3777 [2011.12.15 20:40:40 | 000,000,000 | ---D | C] -- C:\Windows\pss [2011.12.15 20:11:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.7 [2011.12.15 20:05:50 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.7 [2011.12.15 06:18:15 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2011.12.15 05:54:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft [2011.12.15 05:54:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2011.12.15 05:54:27 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft [2011.12.14 19:17:02 | 000,000,000 | R--D | C] -- C:\Users\sascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011.12.14 17:56:51 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011.12.14 17:56:49 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2011.12.14 17:56:49 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011.12.14 17:56:48 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2011.12.14 17:56:47 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011.12.14 17:56:41 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011.12.14 17:49:44 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2011.12.14 17:49:42 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.12.14 17:49:39 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2011.12.14 17:49:39 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2011.12.14 17:49:29 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2011.12.14 17:49:18 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2011.12.14 17:08:44 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll [2011.12.14 17:08:44 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll [2011.12.14 17:08:44 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll [2011.12.14 17:08:43 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll [2011.12.14 17:08:43 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll [2011.12.14 17:08:43 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll [2011.12.14 17:08:42 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll [2011.12.14 17:08:42 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll [2011.12.14 17:08:41 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll [2011.12.14 17:08:41 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll [2011.12.14 17:08:41 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll [2011.12.14 17:08:41 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll [2011.12.13 21:52:26 | 000,000,000 | ---D | C] -- C:\Program Files\MSI Afterburner [2011.12.13 21:13:23 | 000,941,160 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco322090.dll [2011.12.13 21:13:20 | 000,837,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco322040.dll [2011.12.11 21:10:02 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011.12.11 00:19:44 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2011.12.11 00:19:44 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2011.12.11 00:19:44 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2011.12.11 00:19:44 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2011.12.11 00:19:43 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2011.12.11 00:19:43 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2011.12.11 00:19:43 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.12.11 00:19:43 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2011.12.11 00:19:43 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2011.12.11 00:19:43 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.12.11 00:19:43 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.12.11 00:19:43 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.12.11 00:19:43 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2011.12.11 00:19:43 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.12.11 00:19:42 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.12.11 00:19:42 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.12.11 00:19:42 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2011.12.11 00:19:42 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2011.12.11 00:19:42 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.12.11 00:19:42 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2011.12.11 00:19:42 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2011.12.11 00:19:42 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.12.11 00:19:41 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2011.12.11 00:19:41 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2011.12.11 00:19:41 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2011.12.11 00:19:41 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.12.11 00:19:41 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2011.12.11 00:19:41 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2011.12.11 00:19:41 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.12.11 00:19:41 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2011.12.11 00:19:41 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.12.11 00:18:44 | 000,979,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll [2011.12.11 00:18:44 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll [2011.12.11 00:18:44 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll [2011.12.11 00:18:44 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll [2011.12.11 00:18:43 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll [2011.12.11 00:18:43 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll [2011.12.11 00:18:43 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll [2011.12.11 00:18:41 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe [2011.12.11 00:18:41 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2011.12.11 00:18:41 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll [2011.12.11 00:18:41 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll [2011.12.11 00:18:41 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll ========== Files - Modified Within 14 Days ========== [2011.12.22 12:09:26 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\1-Click Maintenance.job [2011.12.22 12:08:36 | 007,613,096 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.12.22 12:08:36 | 002,718,448 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.12.22 12:08:36 | 002,358,020 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.12.22 12:08:36 | 002,134,332 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.12.22 12:01:31 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.12.22 12:01:30 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.12.22 12:00:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.12.22 11:58:53 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts [2011.12.22 01:18:44 | 000,100,864 | ---- | M] (GMER) -- C:\fwriqpog.sys [2011.12.22 01:12:21 | 209,332,762 | ---- | M] () -- C:\Windows\MEMORY.DMP [2011.12.21 22:38:55 | 000,000,020 | ---- | M] () -- C:\Users\sascha\defogger_reenable [2011.12.19 20:32:33 | 000,000,680 | ---- | M] () -- C:\Users\sascha\AppData\Local\d3d9caps.dat [2011.12.19 20:15:40 | 000,000,839 | ---- | M] () -- C:\Users\Public\Desktop\Mobile Partner.lnk [2011.12.17 04:15:47 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\sascha\Desktop\mbam-setup-1.51.2.1300.exe [2011.12.17 02:49:25 | 000,000,726 | ---- | M] () -- C:\Users\sascha\Desktop\EVEREST Home Edition.lnk [2011.12.16 05:06:28 | 000,000,925 | ---- | M] () -- C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk [2011.12.15 20:11:57 | 000,001,572 | ---- | M] () -- C:\Users\Public\Desktop\ICQ7.7.lnk [2011.12.15 06:18:14 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2011.12.15 06:17:44 | 000,016,432 | ---- | M] () -- C:\Windows\System32\lsdelete.exe [2011.12.15 04:55:59 | 000,001,100 | ---- | M] () -- C:\Users\sascha\AppData\Local\d3d8caps.dat [2011.12.14 18:08:18 | 002,346,928 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.12.14 18:02:04 | 000,184,320 | -H-- | M] () -- C:\Users\sascha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.12.11 22:59:51 | 000,001,594 | ---- | M] () -- C:\Users\sascha\Desktop\config.ini [2011.12.11 00:19:50 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat [2011.12.11 00:19:50 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat [2011.12.11 00:19:44 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2011.12.11 00:19:44 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2011.12.11 00:19:44 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2011.12.11 00:19:44 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2011.12.11 00:19:43 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2011.12.11 00:19:43 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2011.12.11 00:19:43 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.12.11 00:19:43 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2011.12.11 00:19:43 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2011.12.11 00:19:43 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.12.11 00:19:43 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.12.11 00:19:43 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.12.11 00:19:43 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2011.12.11 00:19:43 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2011.12.11 00:19:43 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.12.11 00:19:42 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.12.11 00:19:42 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.12.11 00:19:42 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2011.12.11 00:19:42 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2011.12.11 00:19:42 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.12.11 00:19:42 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2011.12.11 00:19:42 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2011.12.11 00:19:42 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.12.11 00:19:41 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2011.12.11 00:19:41 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2011.12.11 00:19:41 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2011.12.11 00:19:41 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.12.11 00:19:41 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2011.12.11 00:19:41 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2011.12.11 00:19:41 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.12.11 00:19:41 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2011.12.11 00:19:41 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.12.11 00:18:44 | 000,979,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll [2011.12.11 00:18:44 | 000,357,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll [2011.12.11 00:18:44 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll [2011.12.11 00:18:44 | 000,261,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll [2011.12.11 00:18:43 | 002,873,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mf.dll [2011.12.11 00:18:43 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll [2011.12.11 00:18:43 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll [2011.12.11 00:18:41 | 000,667,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe [2011.12.11 00:18:41 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll [2011.12.11 00:18:41 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll [2011.12.11 00:18:41 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll [2011.12.11 00:18:41 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll ========== Files Created - No Company Name ========== [2011.12.22 01:12:21 | 209,332,762 | ---- | C] () -- C:\Windows\MEMORY.DMP [2011.12.21 22:37:21 | 000,000,020 | ---- | C] () -- C:\Users\sascha\defogger_reenable [2011.12.19 20:15:40 | 000,000,839 | ---- | C] () -- C:\Users\Public\Desktop\Mobile Partner.lnk [2011.12.17 02:49:25 | 000,000,726 | ---- | C] () -- C:\Users\sascha\Desktop\EVEREST Home Edition.lnk [2011.12.16 05:04:09 | 000,000,925 | ---- | C] () -- C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk [2011.12.16 02:44:31 | 000,004,364 | ---- | C] () -- C:\Windows\System32\nvinfo.pb [2011.12.15 20:11:57 | 000,001,572 | ---- | C] () -- C:\Users\Public\Desktop\ICQ7.7.lnk [2011.12.15 13:44:20 | 000,016,432 | ---- | C] () -- C:\Windows\System32\lsdelete.exe [2011.12.11 22:59:51 | 000,001,594 | ---- | C] () -- C:\Users\sascha\Desktop\config.ini [2011.12.11 00:29:59 | 000,000,912 | ---- | C] () -- C:\Users\sascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011.12.11 00:19:43 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2011.05.20 22:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2011.05.10 03:00:19 | 000,000,610 | ---- | C] () -- C:\Windows\System32\wun32.dll [2010.11.01 07:01:35 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat [2010.10.21 19:18:56 | 000,000,680 | ---- | C] () -- C:\Users\sascha\AppData\Local\d3d9caps.dat [2010.09.23 11:34:08 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010.09.23 11:34:08 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010.07.05 13:17:47 | 000,091,923 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2010.07.05 13:17:47 | 000,076,956 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2010.07.05 13:17:47 | 000,039,121 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2010.07.05 13:17:47 | 000,027,965 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_JP.dat [2009.06.22 18:57:55 | 000,000,000 | ---- | C] () -- C:\Windows\System32\WoW-3.0.3.9183-to-3.0.8.9464-deDE-patch.exe.part [2009.06.22 18:57:23 | 000,000,000 | ---- | C] () -- C:\Windows\System32\WoW-3.0.8.9464-to-3.0.8.9506-deDE-patch.exe.part [2009.04.23 03:25:55 | 000,000,000 | ---- | C] () -- C:\Windows\iPlayer.INI [2008.11.11 07:03:00 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2008.07.06 21:35:22 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll [2008.07.06 21:35:22 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll [2008.07.06 21:35:22 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll [2008.06.27 00:45:54 | 000,001,100 | ---- | C] () -- C:\Users\sascha\AppData\Local\d3d8caps.dat [2008.05.25 21:06:37 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll [2008.05.09 02:36:50 | 000,000,442 | ---- | C] () -- C:\Windows\SIERRA.INI [2008.04.23 18:25:30 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys [2008.04.23 18:13:09 | 000,000,403 | ---- | C] () -- C:\Windows\ODBC.INI [2008.04.23 14:36:10 | 007,613,096 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.04.23 14:36:10 | 002,358,020 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.04.23 14:36:10 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.04.23 14:36:10 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2008.04.23 08:27:22 | 000,021,504 | ---- | C] () -- C:\Windows\jestertb.dll [2008.04.23 06:06:26 | 000,184,320 | -H-- | C] () -- C:\Users\sascha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.04.23 05:52:18 | 000,000,094 | -H-- | C] () -- C:\Users\sascha\AppData\Local\fusioncache.dat [2007.02.13 08:48:38 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini [2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 13:47:37 | 002,346,928 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 11:33:01 | 002,718,448 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 11:33:01 | 002,134,332 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [1999.04.30 01:00:00 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL [1997.06.14 12:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll ========== LOP Check ========== [2011.09.14 15:22:25 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\EveHQ [2011.10.25 15:13:39 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\EVEMon [2011.12.21 22:36:03 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\ICQ [2011.02.10 20:46:26 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\Opera [2008.04.23 06:04:03 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\Packard Bell [2011.12.15 13:44:17 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\toolplugin [2011.10.28 15:14:10 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\TS3Client [2011.10.28 15:14:21 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\ts3overlay [2010.09.23 12:07:31 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\TuneUp Software [2011.12.17 17:34:19 | 000,000,000 | ---D | M] -- C:\Users\sascha\AppData\Roaming\Wise Registry Cleaner [2011.12.22 12:09:26 | 000,000,508 | ---- | M] () -- C:\Windows\Tasks\1-Click Maintenance.job [2011.12.22 11:59:34 | 000,032,586 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 22:37 on 21/12/2011 (***) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... Unable to read sptd.sys SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- MbAm: [CODE]info.txtRSIT Logfile: Code:
ATTFilter logfile of random's system information tool 1.09 2011-12-21 23:28:20 ======Uninstall list====== -->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF} -->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF} -->MsiExec.exe /I{0D330013-4A99-46D6-83C6-2C959C68DBFF} -->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87} -->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0} -->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048} -->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA} -->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82} -->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0410-0000-0000000FF1CE} /uninstall {322296D4-1EAE-4030-9FBC-D2787EB25FA2} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0407-0000-0000000FF1CE} /uninstall {26454C26-D259-4543-AA60-3189E09C5F76} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B} 32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA} Acrobat.com-->msiexec /qb /x {C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B} Acrobat.com-->MsiExec.exe /I{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B} Ad-Aware-->MsiExec.exe /X{E43196CF-182A-4D9E-9CE7-69616DBEE3B0} Adobe Acrobat 9 Pro - English, Français, Deutsch-->msiexec /I {AC76BA86-1033-F400-7760-000000000004} Adobe After Effects CS4 Third Party Content-->MsiExec.exe /I{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E} Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E} Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8} Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0} Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191} Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02} Adobe Color EU Recommended Settings CS4-->MsiExec.exe /I{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1} Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F} Adobe Color NA Extra Settings CS4-->MsiExec.exe /I{098A2A49-7CF3-4F08-A38D-FB879117152A} Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D} Adobe Creative Suite 4 Master Collection-->C:\Program Files\Common Files\Adobe\Installers\5445c5ddd9a5c69582d3c1e2bba18f7\Setup.exe --uninstall=1 Adobe Creative Suite 4 Master Collection-->MsiExec.exe /I{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C} Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF} Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683} Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A} Adobe Dreamweaver CS4-->MsiExec.exe /I{30C8AA56-4088-426F-91D1-0EDFD3A25678} Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C} Adobe Encore CS4 Codecs-->MsiExec.exe /I{FB2A5FCC-B81B-48C2-A009-7804694D83E9} Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5} Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972} Adobe Fireworks CS4-->MsiExec.exe /I{428FDF9F-E010-4C4C-A8BB-156960AFCA1C} Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -maintain activex Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10t_Plugin.exe -maintain plugin Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794} Adobe Illustrator CS4-->MsiExec.exe /I{87532CAB-7932-4F84-8937-823337622807} Adobe InDesign CS4 Application Feature Set Files (Roman)-->MsiExec.exe /I{2BAF2B96-7560-48B4-87D4-10178DDBE217} Adobe InDesign CS4 Common Base Files-->MsiExec.exe /I{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C} Adobe InDesign CS4 Icon Handler-->MsiExec.exe /I{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1} Adobe InDesign CS4-->MsiExec.exe /I{1DCA3EAA-6EB5-4563-A970-EA14D75037BA} Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67} Adobe Media Encoder CS4 Exporter-->MsiExec.exe /I{561968FD-56A1-49FD-9ED0-F55482C7C5BC} Adobe Media Encoder CS4 Importer-->MsiExec.exe /I{8186FF34-D389-4B7E-9A2F-C197585BCFBD} Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A} Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353} Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD} Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494} Adobe Premiere Pro CS4 Third Party Content-->MsiExec.exe /I{C938BE91-3BB5-4B84-9EF6-88F0505D0038} Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA} Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7} Adobe Setup-->MsiExec.exe /I{E8EE9410-8AC4-4F43-A626-DDECA75C79F3} Adobe SGM CS4-->MsiExec.exe /I{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B} Adobe Shockwave Player-->MsiExec.exe /X{A7DB362E-16DC-4E29-8A34-E74381E00B5B} Adobe SING CS4-->MsiExec.exe /I{4A52555C-032A-4083-BDD9-6A85ABFB39A8} Adobe Soundbooth CS4 Codecs-->MsiExec.exe /I{52232EF4-CC12-4C21-ABCF-ADB79618302D} Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230} Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755} Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF} Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739} AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4} AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4} Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D} Dawn of War - Dark Crusade-->C:\Program Files\InstallShield Installation Information\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}\setup.exe -runfromtemp -l0x0007 -removeonly Dawn of War - Soulstorm-->"C:\Program Files\InstallShield Installation Information\{20533183-D42D-4261-A125-956736FBEA8C}\setup.exe" -runfromtemp -l0x0007 -removeonly Dawn of War - Tyranid Mod v0.45SS-->"C:\Games\Dawn of War - Soulstrom\TyranidsUninstall.exe" Dawn Of War-->MsiExec.exe /X{83F12F73-D52E-40C0-93B1-463C311C4E17} EVE Online (remove only)-->C:\Program Files\CCP\EVE\Uninstall.exe EVEREST Home Edition v2.20-->"C:\Users\***\Desktop\SystemControl\EVEREST Home Edition\unins000.exe" Firefox-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *FirefoxDE* Flash Player 9 Internet Explorer-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Flashplayer* GearDrvs-->MsiExec.exe /I{206FD69B-F9FE-4164-81BD-D52552BC9C23} HDRegDE-->MsiExec.exe /I{D359B12F-9B1A-46FD-B70C-F507B5B11590} Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT="" ICQ7.7-->"C:\Program Files\InstallShield Installation Information\{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243} Malwarebytes' Anti-Malware Version 1.51.2.1300-->"C:\Users\***\Desktop\SystemControl\Malwarebytes' Anti-Malware\unins000.exe" Microsoft .NET Framework 1.1 Security Update (KB2572067)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp" Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp" Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 3.5 Language Pack SP1 - DEU-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - deu\setup.exe Microsoft .NET Framework 3.5 Language Pack SP1 - deu-->MsiExec.exe /I{052FDD78-A6EA-3187-8386-C82F4CA3A929} Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} Microsoft .NET Framework 4 Client Profile DEU Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1031 /parameterfolder ClientLP Microsoft .NET Framework 4 Client Profile DEU Language Pack-->MsiExec.exe /X{F750C986-5310-3A5A-95F8-4EC71C8AC01C} Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6} Microsoft Office Access MUI (German) 2007-->MsiExec.exe /X{90120000-0015-0407-0000-0000000FF1CE} Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE} Microsoft Office Excel MUI (German) 2007-->MsiExec.exe /X{90120000-0016-0407-0000-0000000FF1CE} Microsoft Office Groove MUI (German) 2007-->MsiExec.exe /X{90120000-00BA-0407-0000-0000000FF1CE} Microsoft Office InfoPath MUI (German) 2007-->MsiExec.exe /X{90120000-0044-0407-0000-0000000FF1CE} Microsoft Office OneNote MUI (German) 2007-->MsiExec.exe /X{90120000-00A1-0407-0000-0000000FF1CE} Microsoft Office Outlook MUI (German) 2007-->MsiExec.exe /X{90120000-001A-0407-0000-0000000FF1CE} Microsoft Office PowerPoint MUI (German) 2007-->MsiExec.exe /X{90120000-0018-0407-0000-0000000FF1CE} Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE} Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE} Microsoft Office Proof (Italian) 2007-->MsiExec.exe /X{90120000-001F-0410-0000-0000000FF1CE} Microsoft Office Proofing (German) 2007-->MsiExec.exe /X{90120000-002C-0407-0000-0000000FF1CE} Microsoft Office Publisher MUI (German) 2007-->MsiExec.exe /X{90120000-0019-0407-0000-0000000FF1CE} Microsoft Office Shared MUI (German) 2007-->MsiExec.exe /X{90120000-006E-0407-0000-0000000FF1CE} Microsoft Office Word MUI (German) 2007-->MsiExec.exe /X{90120000-001B-0407-0000-0000000FF1CE} Microsoft SQL Server Compact 4.0 ENU-->MsiExec.exe /X{2F141715-E144-48C0-8562-D193B7AB85BC} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475} Mobile Partner-->C:\Program Files\Mobile Partner\uninst.exe Norton 360 2007-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *N360_2007_DE* NVIDIA Grafiktreiber 275.33-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.2\NVI2.DLL",UninstallPackage Display.Driver NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF} NVIDIA PhysX-Systemsoftware 9.10.0514-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.2\NVI2.DLL",UninstallPackage Display.PhysX NVIDIA Update 1.3.5-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.2\NVI2.DLL",UninstallPackage Display.Update Opera 11.60-->"C:\Program Files\Opera\Opera.exe" /uninstall Packard Bell LCD Test-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *LCDTest* Packard Bell Updator-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Updator* PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9} Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8} Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe" Picasa2-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Picasa_2* Realtek HD Audio V6.0.1.5413-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AUDIO_REALTEK* Realtek High Definition Audio Driver-->RtlUpd.exe -r -m Roxio Creator 9 LE-->MsiExec.exe /I{B7FB0C86-41A4-4402-9A33-912C462042A0} Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08} Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73} Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT="" Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7E97AB83-C1FE-38DE-B848-877E0A4BD81E} /parameterfolder Client Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {DB31DEDD-BF95-31E7-A9B7-5480561CEFF3} /parameterfolder Client Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780} Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D} Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C} Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050} Shockwave player 10-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Shockwave* Skype 2.5.2.151-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *SKYPE* Skype™ 5.3-->MsiExec.exe /X{5335DADB-34BA-4AE8-A519-648D78498846} Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe" Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434} TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe" TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357} Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT="" Update for Microsoft .NET Framework 4 Client Profile (KB2468871)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Client Update for Microsoft .NET Framework 4 Client Profile (KB2533523)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Client Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462} Update for Outlook 2007 Junk Email Filter (kb970012)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {DC4A962B-9EC2-469C-BC9C-87312ADAEE81} VC80CRTRedist - 8.0.50727.6195-->MsiExec.exe /I{933B4015-4618-4716-A828-5289FC03165F} VLC media player 1.1.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe Warcraft III-->C:\Program Files\Common Files\Blizzard Entertainment\Warcraft III\Uninstall.exe WinRAR-->C:\Program Files\WinRAR\uninstall.exe Wise Registry Cleaner 6.14-->"C:\Users\***\Desktop\SystemControl\Wise Registry Cleaner\unins000.exe" Yontoo Layers Runtime 1.10.01-->C:\PROGRA~2\TARMAI~1\{889DF~1\Setup.exe /remove /q0 ======Hosts File====== 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com ======Security center information====== AS: Spybot - Search and Destroy (outdated) ======System event log====== Computer Name: ***-PC Event Code: 4386 Message: Windows-Wartung erforderte einen Neustart, um das Update 2507938-26_neutral_PACKAGE aus Paket KB2507938(Security Update) in den Status Installation angefordert(Install Requested) setzen zu können. Record Number: 284903 Source Name: Microsoft-Windows-Servicing Time Written: 20110807232424.000000-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: ***-PC Event Code: 4386 Message: Windows-Wartung erforderte einen Neustart, um das Update 2507938-25_neutral_PACKAGE aus Paket KB2507938(Security Update) in den Status Installation angefordert(Install Requested) setzen zu können. Record Number: 284902 Source Name: Microsoft-Windows-Servicing Time Written: 20110807232424.000000-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: ***-PC Event Code: 4376 Message: Windows-Wartung erforderte einen Neustart, um das Paket KB2507938(Security Update) in den Status Installation angefordert(Install Requested) setzen zu können. Record Number: 284901 Source Name: Microsoft-Windows-Servicing Time Written: 20110807232424.000000-000 Event Type: Warnung User: NT-AUTORITÄT\SYSTEM Computer Name: ***-PC Event Code: 4386 Message: Windows-Wartung erforderte einen Neustart, um das Update 2507938-9_neutral_GDR aus Paket KB2507938(Security Update) in den Status Installation angefordert(Install Requested) setzen zu können. Record Number: 284900 Source Name: Microsoft-Windows-Servicing Time Written: 20110807232424.000000-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: ***-PC Event Code: 4386 Message: Windows-Wartung erforderte einen Neustart, um das Update 2507938-7_neutral_GDR aus Paket KB2507938(Security Update) in den Status Installation angefordert(Install Requested) setzen zu können. Record Number: 284899 Source Name: Microsoft-Windows-Servicing Time Written: 20110807232424.000000-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM =====Application event log===== Computer Name: ***-PC Event Code: 1040 Message: Windows Installer-Transaktion wird gestartet: {098727E1-775A-4450-B573-3F441F1CA243}. Clientprozess-ID: 1424. Record Number: 57610 Source Name: MsiInstaller Time Written: 20100923141909.000000-000 Event Type: Informationen User: ***-PC\*** Computer Name: ***-PC Event Code: 1042 Message: Windows Installer-Transaktion wird beendet: {B29AD377-CC12-490A-A480-1452337C618D}. Clientprozess-ID: 1424. Record Number: 57609 Source Name: MsiInstaller Time Written: 20100923141908.000000-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: ***-PC Event Code: 1035 Message: Das Produkt wurde durch Windows Installer neu konfiguriert. Produktname: Connect. Produktversion: 1.0.0.1. Produktsprache: 0. Erfolg- bzw. Fehlerstatus der neuen Konfiguration: 0. Record Number: 57608 Source Name: MsiInstaller Time Written: 20100923141908.000000-000 Event Type: Informationen User: ***-PC\*** Computer Name: ***-PC Event Code: 11728 Message: Product: Connect -- Die Konfiguration wurde abgeschlossen. Record Number: 57607 Source Name: MsiInstaller Time Written: 20100923141908.000000-000 Event Type: Informationen User: ***-PC\*** Computer Name: ***-PC Event Code: 1040 Message: Windows Installer-Transaktion wird gestartet: {B29AD377-CC12-490A-A480-1452337C618D}. Clientprozess-ID: 1424. Record Number: 57606 Source Name: MsiInstaller Time Written: 20100923141900.000000-000 Event Type: Informationen User: ***-PC\*** =====Security event log===== Computer Name: ***-PC Event Code: 5033 Message: Der Windows-Firewalltreiber wurde erfolgreich gestartet. Record Number: 79326 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20101209143143.983839-000 Event Type: Überwachung erfolgreich User: Computer Name: ***-PC Event Code: 4672 Message: Einer neuen Anmeldung wurden besondere Rechte zugewiesen. Antragsteller: Sicherheits-ID: S-1-5-18 Kontoname: SYSTEM Kontodomäne: NT-AUTORITÄT Anmelde-ID: 0x3e7 Berechtigungen: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege Record Number: 79325 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20101209143143.549839-000 Event Type: Überwachung erfolgreich User: Computer Name: ***-PC Event Code: 4624 Message: Ein Konto wurde erfolgreich angemeldet. Antragsteller: Sicherheits-ID: S-1-5-18 Kontoname: ***-PC$ Kontodomäne: WORKGROUP Anmelde-ID: 0x3e7 Anmeldetyp: 5 Neue Anmeldung: Sicherheits-ID: S-1-5-18 Kontoname: SYSTEM Kontodomäne: NT-AUTORITÄT Anmelde-ID: 0x3e7 Anmelde-GUID: {00000000-0000-0000-0000-000000000000} Prozessinformationen: Prozess-ID: 0x2d4 Prozessname: C:\Windows\System32\services.exe Netzwerkinformationen: Arbeitsstationsname: Quellnetzwerkadresse: - Quellport: - Detaillierte Authentifizierungsinformationen: Anmeldeprozess: Advapi Authentifizierungspaket: Negotiate Übertragene Dienste: - Paketname (nur NTLM): - Schlüssellänge: 0 Dieses Ereignis wird beim Erstellen einer Anmeldesitzung generiert. Es wird auf dem Computer generiert, auf den zugegriffen wurde. Die Antragstellerfelder geben das Konto auf dem lokalen System an, von dem die Anmeldung angefordert wurde. Dies ist meistens ein Dienst wie der Serverdienst oder ein lokaler Prozess wie "Winlogon.exe" oder "Services.exe". Das Anmeldetypfeld gibt den jeweiligen Anmeldetyp an. Die häufigsten Typen sind 2 (interaktiv) und 3 (Netzwerk). Die Felder für die neue Anmeldung geben das Konto an, für das die Anmeldung erstellt wurde, d. h. das angemeldete Konto. Die Netzwerkfelder geben die Quelle einer Remoteanmeldeanforderung an. der Arbeitsstationsname ist nicht immer verfügbar und kann in manchen Fällen leer bleiben. Die Felder für die Authentifizierungsinformationen enthalten detaillierte Informationen zu dieser speziellen Anmeldeanforderung. - Die Anmelde-GUID ist ein eindeutiger Bezeichner, der verwendet werden kann, um dieses Ereignis mit einem KDC-Ereignis zu korrelieren. - Die übertragenen Dienste geben an, welche Zwischendienste an der Anmeldeanforderung beteiligt waren. - Der Paketname gibt das in den NTLM-Protokollen verwendete Unterprotokoll an. - Die Schlüssellänge gibt die Länge des generierten Sitzungsschlüssels an. Wenn kein Sitzungsschlüssel angefordert wurde, ist dieser Wert 0. Record Number: 79324 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20101209143143.549839-000 Event Type: Überwachung erfolgreich User: Computer Name: ***-PC Event Code: 4648 Message: Anmeldeversuch mit expliziten Anmeldeinformationen. Antragsteller: Sicherheits-ID: S-1-5-18 Kontoname: ***-PC$ Kontodomäne: WORKGROUP Anmelde-ID: 0x3e7 Anmelde-GUID: {00000000-0000-0000-0000-000000000000} Konto, dessen Anmeldeinformationen verwendet wurden: Kontoname: SYSTEM Kontodomäne: NT-AUTORITÄT Anmelde-GUID: {00000000-0000-0000-0000-000000000000} Zielserver: Zielservername: localhost Weitere Informationen: localhost Prozessinformationen: Prozess-ID: 0x2d4 Prozessname: C:\Windows\System32\services.exe Netzwerkinformationen: Netzwerkadresse: - Port: - Dieses Ereignis wird bei einem Anmeldeversuch durch einen Prozess generiert, wenn ausdrücklich die Anmeldeinformationen des Kontos angegeben werden. Dies ist normalerweise der Fall in Batch-Konfigurationen, z. B. bei geplanten Aufgaben oder wenn der Befehl "runas" verwendet wird. Record Number: 79323 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20101209143143.549839-000 Event Type: Überwachung erfolgreich User: Computer Name: ***-PC Event Code: 4672 Message: Einer neuen Anmeldung wurden besondere Rechte zugewiesen. Antragsteller: Sicherheits-ID: S-1-5-18 Kontoname: SYSTEM Kontodomäne: NT-AUTORITÄT Anmelde-ID: 0x3e7 Berechtigungen: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege Record Number: 79322 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20101209143140.316236-000 Event Type: Überwachung erfolgreich User: ======Environment variables====== "CLASSPATH"=.; "ComSpec"=%SystemRoot%\system32\cmd.exe "FP_NO_HOST_CHECK"=NO "NUMBER_OF_PROCESSORS"=2 "OS"=Windows_NT "Path"=C:\Program Files\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\ "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel "PROCESSOR_LEVEL"=6 "PROCESSOR_REVISION"=0f0d "PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\ "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\ "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "USERNAME"=SYSTEM "windir"=%SystemRoot% -----------------EOF----------------- so ...hoff das hilft |
24.12.2011, 07:07 | #4 | ||
/// Helfer-Team | Blackscreen + "Lags" Was tun 1. Du hast deinen Rechner mit zwei Anti-Viren-Programmen generell `geschwächt`: Zitat:
Nur eine Firewall sowie ein Antiviren Programm verwenden, welche sich immer auf dem aktuellsten Stand befinden sollten! Mehr AV Programme bedeutet nicht mehr Sicherheit!Die Scanner behindern sich gegenseitig (bei beiden den On-Access Scan aktiviert bzw laufen ständig im Hintergrund) und ein Systemcrash kann die Folge sein oder im schlechtesten fall, kannst Du über eine komplette Neuinstallation freuen! Deinstalliere also eines der AV-Programme und lass nur noch eins auf deinem PC laufen. Zitat:
► Removal Tools oder Deinstallationsanleitungen für diverse Antiviren Software : -> Removal Tools oder Deinstallationsanleitungen für diverse Antiviren Software ► AV Deinstallations Hinweise also Entscheide Dich für NUR einen Virenscanner und benutze diesen regelmäßig! 2. erneut einen Scan mit OTL:
3. Ich würde gerne noch all deine installierten Programme sehen: CCleaner starten... dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..." wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
Themen zu Blackscreen + "Lags" Was tun |
avira, booten, desktop, eingefroren, erkannt, geforce, gen, grafikkarte, hijack, hijackthis, home, hängt, i-net, malwarebytes, maus, meldung, monitor, neustart, nicht erkannt, nicht mehr, nicht möglich, nvlddmkm.sys, packard bell, problem, registry, registry cleaner, safer networking, search the web, senden, spybot, system, tarma, vista, yontoo |