|
Log-Analyse und Auswertung: Windows 7 blockiert, 50€Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.12.2011, 20:54 | #1 |
| Windows 7 blockiert, 50€ Nabend selbes Problem wie viele hier. Im Anhang die Dateien. gruss OTL zu gross, daher gleich hier OTL logfile created on: 30.12.2011 20:31:01 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\standard\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19120) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,75 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 70,50% Memory free 5,74 Gb Paging File | 4,93 Gb Available in Paging File | 85,91% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 144,04 Gb Total Space | 86,60 Gb Free Space | 60,12% Space Free | Partition Type: NTFS Drive D: | 144,04 Gb Total Space | 140,23 Gb Free Space | 97,35% Space Free | Partition Type: NTFS Drive F: | 7,46 Gb Total Space | 5,36 Gb Free Space | 71,90% Space Free | Partition Type: FAT32 Computer Name: STANDARD-PC | User Name: standard | Logged in as Administrator. Cannot determine boot mode. | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\standard\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) PRC - C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe (EgisTec Inc.) PRC - C:\ACER\Mobility Center\MobilityService.exe () ========== Modules (No Company Name) ========== MOD - C:\Program Files\WinRAR\RarExt.dll () MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll () ========== Win32 Services (SafeList) ========== SRV - (CPUCooLServer) -- File not found SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone) SRV - (ePowerSvc) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe () SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe () ========== Driver Services (SafeList) ========== DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH) DRV - (ntiopnp) -- C:\Windows\System32\drivers\ntiopnp.sys () DRV - (ntiomin) -- C:\Windows\System32\drivers\ntiomin.sys () DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (SQTECH905C) -- C:\Windows\System32\drivers\Capt905c.sys (Service & Quality Technology.) DRV - (mwlPSDVDisk) -- C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Incorporated.) DRV - (mwlPSDFilter) -- C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Incorporated.) DRV - (mwlPSDNServ) -- C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Incorporated.) DRV - (tcpipBM) -- C:\Windows\System32\drivers\tcpipBM.sys (Bytemobile, Inc.) DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation) DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation) DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0309&m=aspire_5737z IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2010.06.20 19:39:28 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.12 15:16:36 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.15 23:12:45 | 000,000,000 | ---D | M] [2011.08.12 14:12:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\standard\AppData\Roaming\mozilla\Extensions [2011.09.25 09:03:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\standard\AppData\Roaming\mozilla\Firefox\Profiles\l3x08d7v.default\extensions [2011.11.11 10:10:04 | 000,000,000 | ---D | M] (@@toolbarname@@) -- C:\Users\standard\AppData\Roaming\mozilla\Firefox\Profiles\l3x08d7v.default\extensions\toolbar@ask.com [2011.11.12 15:16:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011.12.17 20:34:39 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011.02.23 19:38:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\webbooster@iminent.com [2011.11.12 15:16:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010.07.31 15:42:28 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011.11.12 15:16:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.11.12 15:16:30 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.11.12 15:16:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.11.12 15:16:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.11.12 15:16:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.11.12 15:16:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google: originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms } CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: YouTube = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\ CHR - Extension: Google-Suche = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\ CHR - Extension: Skype Click to Call = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\ CHR - Extension: Google Mail = C:\Users\standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\ O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No CLSID value found. O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found. O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe ({StringFileInfo_CompanyName}) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKCU..\Run: [iexploer.exe] C:\Users\standard\AppData\Roaming\Microsoft\Internet Explorer\iexploer.exe () O4 - HKCU..\Run: [Microsoft® Windows Manager] C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28 O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe File not found O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG) O13 - gopher Prefix: missing O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} hxxp://turnier.freenet.de/ctl/kingcomie.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C136A47-E9CD-412C-BC6E-9263DFF9E91B}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\x-sdch - No CLSID value found O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\standard\Pictures\handybilder\CIMG2977.JPG O24 - Desktop BackupWallPaper: C:\Users\standard\Pictures\handybilder\CIMG2977.JPG O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{080fc061-ab9b-11de-95c5-00235a49e57f}\Shell\AutoRun\command - "" = F:\Menu.exe O33 - MountPoints2\{1d8d9ee4-0ff8-11de-a641-00242b4db9a8}\Shell - "" = AutoRun O33 - MountPoints2\{1d8d9ee4-0ff8-11de-a641-00242b4db9a8}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{5871a5a9-2b26-11de-82b5-00235a49e57f}\Shell - "" = AutoRun O33 - MountPoints2\{5871a5a9-2b26-11de-82b5-00235a49e57f}\Shell\AutoRun\command - "" = G:\VoiceMemoPlayer.exe O33 - MountPoints2\{65bf3f75-e04d-11df-9438-00235a49e57f}\Shell - "" = AutoRun O33 - MountPoints2\{65bf3f75-e04d-11df-9438-00235a49e57f}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta O33 - MountPoints2\{794dd61d-7c9a-11df-8f76-00235a49e57f}\Shell - "" = AutoRun O33 - MountPoints2\{794dd61d-7c9a-11df-8f76-00235a49e57f}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{794dd624-7c9a-11df-8f76-001e101f7fb6}\Shell - "" = AutoRun O33 - MountPoints2\{794dd624-7c9a-11df-8f76-001e101f7fb6}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{aecf2474-f176-11e0-ab1e-001e101f3315}\Shell - "" = AutoRun O33 - MountPoints2\{aecf2474-f176-11e0-ab1e-001e101f3315}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{aecf2480-f176-11e0-ab1e-00235a49e57f}\Shell - "" = AutoRun O33 - MountPoints2\{aecf2480-f176-11e0-ab1e-00235a49e57f}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{cb0ca924-2f98-11e1-8c52-00235a49e57f}\Shell - "" = AutoRun O33 - MountPoints2\{cb0ca924-2f98-11e1-8c52-00235a49e57f}\Shell\AutoRun\command - "" = G:\AP.exe O33 - MountPoints2\{cc26ef88-f255-11e0-a122-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{cc26ef88-f255-11e0-a122-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{cc26efd3-f255-11e0-a122-00242b4db9a8}\Shell - "" = AutoRun O33 - MountPoints2\{cc26efd3-f255-11e0-a122-00242b4db9a8}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.12.30 20:29:20 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\standard\Desktop\OTL.exe [2011.12.27 16:42:39 | 000,000,000 | RHSD | C] -- C:\Users\standard\M-1-25-5432-6437-5685 [2011.12.08 17:25:58 | 000,000,000 | ---D | C] -- C:\Users\standard\AppData\Local\PackageAware [2008.12.12 20:24:21 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll [1 C:\Users\standard\AppData\Local\*.tmp files -> C:\Users\standard\AppData\Local\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.12.30 20:30:13 | 000,028,124 | ---- | M] () -- C:\ProgramData\nvModes.001 [2011.12.30 20:29:21 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\standard\Desktop\OTL.exe [2011.12.30 20:28:26 | 000,618,442 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.12.30 20:28:26 | 000,587,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.12.30 20:28:26 | 000,122,842 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.12.30 20:28:26 | 000,101,250 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.12.30 20:25:06 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{C6F5F648-2C17-4450-981D-FCA22CBD87C9}.job [2011.12.30 20:21:21 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011.12.30 20:21:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.12.30 20:20:50 | 2951,094,272 | -HS- | M] () -- C:\hiberfil.sys [2011.12.30 20:19:56 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.12.30 20:19:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.12.30 20:18:11 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011.12.30 19:38:06 | 000,028,124 | ---- | M] () -- C:\ProgramData\nvModes.dat [2011.12.08 19:17:17 | 000,134,856 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [1 C:\Users\standard\AppData\Local\*.tmp files -> C:\Users\standard\AppData\Local\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.12.29 20:37:36 | 2951,094,272 | -HS- | C] () -- C:\hiberfil.sys [2011.08.13 15:09:24 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini [2011.03.03 08:00:48 | 000,000,361 | ---- | C] () -- C:\Windows\wininit.ini [2011.02.03 09:43:12 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010.11.11 20:19:24 | 000,021,080 | ---- | C] () -- C:\Windows\System32\drivers\ntiopnp.sys [2010.08.10 14:49:36 | 000,011,392 | ---- | C] () -- C:\Windows\System32\drivers\ntiomin.sys [2010.06.12 20:49:51 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2009.12.24 17:32:56 | 000,000,000 | ---- | C] () -- C:\Windows\PTWebCam.INI [2009.10.18 18:28:52 | 000,000,340 | ---- | C] () -- C:\ProgramData\fillup [2009.09.24 06:31:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.09.24 06:31:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009.08.04 18:18:58 | 000,010,938 | ---- | C] () -- C:\Users\standard\AppData\Roaming\antje.xml [2009.08.04 18:15:51 | 000,000,377 | ---- | C] () -- C:\Users\standard\AppData\Roaming\users.xml [2009.07.04 19:33:28 | 000,000,056 | ---- | C] () -- C:\Users\standard\AppData\Roaming\wklnhst.dat [2009.06.25 11:58:49 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat [2009.06.19 16:19:05 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe [2009.06.16 12:25:02 | 000,121,512 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4 [2009.03.06 19:51:04 | 000,026,624 | ---- | C] () -- C:\Users\standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.03.06 14:37:02 | 000,028,124 | ---- | C] () -- C:\ProgramData\nvModes.001 [2009.03.06 14:17:47 | 000,028,124 | ---- | C] () -- C:\ProgramData\nvModes.dat [2009.03.06 13:57:53 | 000,007,592 | ---- | C] () -- C:\Users\standard\AppData\Local\d3d9caps.dat [2009.03.06 13:52:36 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll [2009.03.06 13:52:36 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe [2009.03.06 13:52:36 | 000,009,216 | ---- | C] () -- C:\Windows\usbvideo_reg.exe [2009.03.06 13:52:36 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini [2008.12.12 20:22:50 | 000,014,640 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat [2008.12.12 13:42:34 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll [2008.12.12 13:42:34 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll [2008.12.12 13:02:37 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX2.dat [2008.12.12 13:02:37 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat [2008.12.12 13:02:37 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat [2008.12.12 13:02:37 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat [2008.12.12 12:11:45 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2008.01.21 08:15:58 | 000,618,442 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.01.21 08:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.01.21 08:15:58 | 000,122,842 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.01.21 08:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 13:47:37 | 000,383,720 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 11:33:01 | 000,587,178 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 11:33:01 | 000,101,250 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2001.12.26 16:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll [2001.09.03 23:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll [2001.07.30 16:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll [2001.07.23 22:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll ========== LOP Check ========== [2010.02.15 15:33:50 | 000,000,000 | -HSD | M] -- C:\Users\standard\AppData\Roaming\.# [2010.10.17 12:26:05 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\A Gypsy's Tale - Der Turm des Schicksals [2008.12.12 13:29:07 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Acer GameZone Console [2009.09.20 09:28:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Aisle 5 Games, Inc [2010.02.09 13:30:01 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Alawar [2009.09.13 15:04:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Anabel [2011.03.03 08:01:21 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Artogon [2009.09.13 16:14:31 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Babylonia [2009.11.04 07:16:30 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Batovi [2009.06.19 13:10:47 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\BeachPartyCraze [2009.09.10 10:14:09 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Big Fish [2010.05.20 19:50:40 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Big Fish Games [2009.09.28 20:32:14 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\BlamGames [2010.01.02 20:15:19 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\blg [2009.07.01 11:52:50 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Boolat Games [2011.03.31 10:00:29 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Boomzap [2009.07.29 09:27:42 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\BrandX Games [2009.11.15 14:42:39 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Burdaloo [2010.06.20 19:40:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Bytemobile [2009.09.08 20:07:02 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Camel101 [2011.08.09 20:13:26 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Canneverbe Limited [2009.10.13 09:49:33 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\CasualForge [2009.11.16 19:21:35 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\cerasus.media [2010.08.06 07:41:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\DarkParablesBriarRose_BFG_SE [2010.07.12 09:26:01 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\de.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2009.12.14 19:54:13 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Dekovir [2009.12.09 19:22:04 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\DivoGames [2009.12.30 21:35:31 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\DruidsBattleOfMagic [2009.12.21 19:05:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\EleFun Games [2009.12.28 19:40:04 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ElementalsTheMagicKey [2010.11.20 20:31:56 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Enki Games [2010.01.02 18:30:19 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Enlightenus [2010.10.17 10:34:55 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Enlightenus2SE_BFG [2009.12.02 09:10:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ERS G-Studio [2009.09.20 13:31:10 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\EscapeFromParadise2 [2009.06.18 14:01:48 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\eSobi [2009.10.18 18:28:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\fillup [2009.06.30 09:34:03 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\FirstColony [2009.08.11 07:02:28 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Flood Light Games [2009.12.15 19:09:56 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\FlyWheelGames [2009.12.31 15:06:03 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gaijin Ent [2009.06.29 19:30:44 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\GameInvest [2010.01.25 12:46:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gamelab [2009.09.07 18:04:48 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gamers Digital [2009.08.30 12:08:52 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\GAMESHASTRA [2009.08.30 07:43:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gogii Games [2009.12.02 13:19:51 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Gold Casual Games [2009.12.16 11:54:11 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\GraveyardShift [2009.09.28 07:36:58 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Hidden Island Data [2009.07.30 08:09:27 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\HiT-MM [2011.11.04 18:11:03 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ICQ [2009.10.04 16:09:22 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\IronCode [2009.11.11 13:20:00 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Island [2009.07.18 19:34:50 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Jane s Hotel Family Hero [2009.10.09 17:41:12 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\JewelMatch2 [2009.09.12 12:14:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Little Games Company [2009.08.15 22:42:18 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Lost in the City [2009.12.03 07:21:14 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\MA [2010.08.06 15:25:02 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\MagicIndie [2009.09.12 21:00:30 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Mean Hamster [2009.11.17 21:45:37 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\MegaplexMadnessSummerBlockbuster [2009.06.15 12:06:38 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Meridian93 [2010.02.10 16:07:44 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Merscom [2010.02.08 17:07:58 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Oberon Games [2009.06.29 22:29:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\panoramik [2009.11.23 21:01:04 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Peace Craft [2009.07.21 19:38:51 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\PetShowCraze [2009.12.07 08:49:37 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Ph03nixNewMedia [2011.03.03 12:14:47 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Phantasmat_bf_se1 [2011.12.30 17:36:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\PhotoScape [2010.08.05 11:38:21 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\PlayFirst [2010.01.18 13:42:48 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Playrix Entertainment [2009.10.06 18:45:31 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Princess Isabella [2009.07.07 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\RobinsonCrusoe [2009.07.25 14:28:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\RobinsonCrusoeBFGDE [2009.12.31 14:04:57 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Sanna [2009.10.17 11:07:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\she_is_a_shadow [2009.08.17 20:27:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ShinyTales [2009.07.27 12:36:07 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Skunk Studios [2009.04.23 07:01:39 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SoftDMA [2009.11.04 13:04:26 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SprillRichiGerman [2009.09.21 18:58:30 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SultansLabyrinth [2009.10.16 13:43:08 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\SulusGames [2011.10.07 11:56:58 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\TeamViewer [2009.10.16 18:17:28 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Template [2011.10.03 20:38:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\TuneUp Software [2009.08.22 18:16:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Twintale Entertainment [2009.07.11 13:21:37 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\UClick [2010.01.01 19:29:05 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\URSE Games [2009.09.25 16:09:25 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\V-Games [2009.07.19 20:18:18 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Valusoft [2010.01.19 15:34:24 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\VampireSaga [2009.07.15 14:33:02 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\ViquaSoft [2010.02.12 14:40:49 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Virtual City [2010.06.20 19:40:23 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\Vodafone [2011.03.02 11:04:22 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\WhiteBirdsProductions [2009.06.25 11:58:53 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\World-LooM [2009.09.30 19:37:15 | 000,000,000 | ---D | M] -- C:\Users\standard\AppData\Roaming\YoudaGames [2011.12.30 20:19:55 | 000,032,538 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2011.12.30 20:25:06 | 000,000,432 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{C6F5F648-2C17-4450-981D-FCA22CBD87C9}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp: DAFD38AE @Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:9E3E060F @Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:5D351BC6 @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:B6DD2C7E @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:B2CD146E @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:8CCDAB14 @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:6D635C5B @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:52E1DB1D @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:46700142 @Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:7B52659E @Alternate Data Stream - 201 bytes -> C:\ProgramData\Temp:24FECE50 @Alternate Data Stream - 197 bytes -> C:\ProgramData\Temp:331B76C7 @Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:8C81B36D @Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:966CEAE7 @Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:23834E1E @Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:17F7AEA3 @Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:CEE4A457 @Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:AC73CDCE @Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:22741C1F @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:F43B7E8F @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp: DC0B1070 @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:0BBF232A @Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:EEB25EAE @Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:28CDD861 @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:FB647F34 @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:F78CC2A2 @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:5A27D490 @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:550179F5 @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:178093AE @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:10F6E97E @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:FDAF118C @Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:CBEB737E @Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:A4076A3B @Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:89C28CF6 @Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:02B823FE @Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:981884E7 @Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:5E413CD6 @Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:E14FA16F @Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:9026FFAC @Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp: D0D17155 @Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:74456BF5 @Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:6247E766 @Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:3095BD69 @Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:EDC744FB @Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:EA701346 @Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:C10635F6 @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:F45F3031 @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:55C54F7C @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:4D7FCCD3 @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:1C6CB897 @Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:FED25C29 @Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:A5584049 @Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:88B61AC3 @Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:737160C1 @Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:5425B7F5 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:FF7D915E @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:FDDD8917 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp: DE47A3DA @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:B845F669 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:AD727397 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:943E8182 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:93226FE3 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:697DDE2B @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:43E95997 @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:2AE74FF9 @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp: D31BE97C @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C0A2E219 @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:6FDE1666 @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:69E3AF64 @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:1DEE6B65 @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp: D02FBAEC @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:A561576B @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:101708D3 @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:0DFE2AE1 @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:BE6DC701 @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:A26AFC00 @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:7AF9CAEB @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:5335CE76 @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:45F3AD49 @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:33384BC0 @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:25249477 @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:FEEEFFAD @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:BB71BBA2 @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:4CF76F21 @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:490BCC52 @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:3B4DA230 @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:1B7E2022 @Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:FB97DB91 @Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:AB6E0B6B @Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:85C3B823 @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:E6D148BC @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:CB16385F @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:C74009E5 @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:B6285236 @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:B3942462 @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:A8F2382B @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:89A5891E @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:896E1EFF @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:5C6EBC69 @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:4DCAC4BC @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:41D1C7CB @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:35C78DCC @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:0E22C5DB @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:008586AE @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:957E9765 @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8C6D2EC3 @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:7B2BB690 @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:69AF9D20 @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:615435BE @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:38849DE5 @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:122B409D @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:FECEF728 @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:E91ADC66 @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:A3E39C6A @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:98DFF516 @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:969C0C96 @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:57EE48CA @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:3E06C78F @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:3BF63E4A @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:375FC7E7 @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:30376ACC @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A7B70C4E @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:870649A4 @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:2FC7B9E4 @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:059167AF @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:F986CC21 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:E7C9DAAE @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:CFDE7852 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:CB0FEE2B @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:C0DFB793 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:BD9F7E4E @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:B1FBA7E1 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:5EF1AD34 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:4D066AD2 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:1ECED34B @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:17C48B08 @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0D52F295 @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp: DE9F4320 @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:B6FD7157 @Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:72E6616C @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:E3CEEC4C @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:C3C72D5F @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:9ACE4E8E @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:9ACB70D7 @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:66AA0486 @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:439E3411 @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:2495D97A @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:237E4B91 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:FE66A7BB @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:FC2E567F @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:C22674B6 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B093E177 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:A02025CE @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:8DF68137 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:7C412B92 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:2B1EA607 @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp: D2397415 @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:69FD6BF0 @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:483AC68A @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:3815BC84 @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:0F0A5896 @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:AC116044 @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:6677D85A @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:4A2862FF @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:FC2D0F32 @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:F35AE645 @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:99A29126 @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:7920E530 @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:5E9B629B @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:3FD496E1 @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:109734F6 @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:A0A7408F @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:33611CFB @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:12EA4DC9 @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:AF54CFFD @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A688EF17 @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:8B4B9596 @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:7FCB9D0D @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:6FE17A89 @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:51F17BB8 @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:FDCAE7B5 @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp: D994162E @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:CEF2A14E @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:B12D1A7D @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:73933431 @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:663B62CA @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:4FE30352 @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:4F96D8E6 @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:471AD3D0 @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:3D36932D @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:8BCF4DE2 @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:70E897B5 @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:537E6E55 @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:1A4BF204 @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:097FF903 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:F2AF86D9 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp: DF0BC727 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:C4A1F01E @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:708BB0FA @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:561568A4 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:4A1628E5 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:2F141B68 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:12D2EB9C @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:7A0FEE87 @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:1B927722 @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:0ED4AC2F @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:05113FB9 @Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp: D0668210 @Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:554C6431 @Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:10D98D98 @Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:97C4F81F @Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:8F00BFC0 @Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:6BF0805F @Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:523B97A0 @Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:CC7738DB @Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:52206035 @Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:4FE42FFC @Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp: D8DB81DC @Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:92A815D8 @Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:1CE87230 @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:FFD42BAF @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp: D92485C9 @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:BFAD7A5D @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:B1FCBEB0 @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:569CEE83 @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:9E4F05ED @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:71FA8B7F @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:67BA17B9 @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:5A437AC3 @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:53DF59D1 @Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:5A8F8A0C @Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:213AFE42 @Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:E32966C0 @Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:CF61CE5A @Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:C07A6A6B @Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:BDCD0530 @Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:9C8D5426 @Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:BDF08FAF @Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:A745DB5D @Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:8DA9DB01 < End of report > |
30.12.2011, 23:24 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 blockiert, 50€Zitat:
Abgesicherter Modus zur Bereinigung
__________________ |
02.01.2012, 10:53 | #3 |
| Windows 7 blockiert, 50€ guten morgen und noch ein gesundes neues
__________________abgesicherter modus mit netzwerktreibern funktioniert, bekomme die meldung so nicht angezeigt. wie soll ich weiter verfahren? gruss |
02.01.2012, 11:20 | #4 |
| Windows 7 blockiert, 50€ jetzt kam die meldung auch im abgesicherten modus mit netzwerktreibern. die protokolle wurden im modus verzeichnisdienstwiederherstellung erstellt. bin für jede hilfe dankbar gruss |
02.01.2012, 14:10 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 blockiert, 50€ Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden. Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ Logfiles bitte immer in CODE-Tags posten |
05.01.2012, 13:42 | #6 |
| Windows 7 blockiert, 50€ hallo, malware lief problemlos. hier das log: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.60.0.1800 www.malwarebytes.org Datenbank Version: v2012.01.03.01 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.19120 standard :: STANDARD-PC [Administrator] Schutz: Aktiviert 03.01.2012 15:15:24 mbam-log-2012-01-03 (15-15-24).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 294245 Laufzeit: 1 Stunde(n), 20 Minute(n), 44 Sekunde(n) Infizierte Speicherprozesse: 1 C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe (Trojan.MSIL) -> 2724 -> Löschen bei Neustart. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Microsoft® Windows Manager (Trojan.MSIL) -> Daten: C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\Recycle.Bin (Trojan.Spyeyes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\M-1-25-5432-6437-5685 (Trojan.Agent.Gen) -> Löschen bei Neustart. Infizierte Dateien: 14 C:\Users\standard\M-1-25-5432-6437-5685\winmgr.exe (Trojan.MSIL) -> Löschen bei Neustart. C:\Program Files\CPUCooL\instser.exe (Adware.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1ORBYN5O\fa[2].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H5CGXN6X\b[1].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H5CGXN6X\st[1].exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCIG6OC3\fa[1].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCIG6OC3\fa[2].exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Temp\4160436.exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Temp\4283528.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Temp\0336126.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\AppData\Local\Temp\78673.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\standard\Downloads\IMG28057850.JPEG.scr (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. D:\Downloads\IMG28057850.JPEG.scr (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Recycle.Bin\BAE4C87C70DDC49 (Trojan.Spyeyes) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) hoffe das reicht erstmal, ansonsten versuch ichs nochmal. habe aber wenig hoffnung da er immer ausgeht. gruss |
05.01.2012, 15:08 | #7 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7 blockiert, 50€Zitat:
Anschließend auch sämtliche Passwörter ändern!!! Mit komplett plätten wird gemeint: alle Partitionen auflösen, neu erstellen und formatieren. Helfen kann dabei ein Tool wie DBAN oder die Laufwerksverwaltung in einem Ubuntu im Ausprobiermodus. Praktischerweise kann man mit diesem Live-Linux auch ziemlich gefahrlos all seine wichtigen Daten auf eine externe Platte sichern. kopiere nur persönliche Dateien, Musik, Videos, etc. auf die Backupplatte, KEINE ausführbaren Dateien wie Programme/Spiele/Setups!!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Windows 7 blockiert, 50€ |
.dll, adobe, alternate, antivir, avira, avira searchfree toolbar, bho, blockiert, c:\windows\system32\rundll32.exe, computer, defender, error, explorer, firefox, format, helper, home, locker, logfile, mywinlocker, nvidia, object, opera, plug-in, problem, registry, rundll, scan, sched.exe, software, version=1.0, vista, vodafone, windows, windows 7 blockiert |