|
Plagegeister aller Art und deren Bekämpfung: Sehr langsame InternetverbindungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.01.2012, 13:19 | #1 |
| Sehr langsame Internetverbindung Hallo liebes Trojaner-Board, ich habe seit einiger Zeit immer größer werdende Probleme mit meiner Internetleitung. Die Geschwindigkeit ist am Deksop-PC, der per Patchkabel an den Router angeschlossen ist, liegt im Downsteam bei ca. 30 kByte/s und im Upstream ca 15 kByte/s. Ich habe eine DSL 2000 Leitung. Mit meinem Netbook, der per WLAN, auf den gleichen Router zugreift erhalte ich deutlich bessere Werte. Downstream 240 kByte/s Upstream 32 kByte/s. Code:
ATTFilter OTL logfile created on: 31.01.2012 12:56:38 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\***\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,98 Gb Total Physical Memory | 2,03 Gb Available Physical Memory | 68,24% Memory free 5,96 Gb Paging File | 4,54 Gb Available in Paging File | 76,19% Paging File free Paging file location(s): c:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 74,50 Gb Total Space | 6,79 Gb Free Space | 9,11% Space Free | Partition Type: NTFS Drive D: | 149,05 Gb Total Space | 20,38 Gb Free Space | 13,67% Space Free | Partition Type: NTFS Drive T: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Drive U: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Drive V: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Drive W: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Drive X: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Drive Y: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Drive Z: | 912,46 Gb Total Space | 424,29 Gb Free Space | 46,50% Space Free | Partition Type: NTFS Computer Name: *****-PC | User Name: **** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.01.31 12:46:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL_1.exe PRC - [2012.01.30 15:32:16 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe PRC - [2012.01.30 15:32:15 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.01.30 15:32:15 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe PRC - [2012.01.08 13:51:04 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe PRC - [2011.12.24 14:24:22 | 001,711,104 | ---- | M] (Curse) -- C:\Users\Kerze\AppData\Local\Apps\2.0\82DB7XM0.DYM\TP71XWZD.NO1\curs..tion_eee711038731a406_0004.0000_2ad57791d5c42008\CurseClient.exe PRC - [2011.06.24 05:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011.06.24 00:44:22 | 001,386,776 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPointP\SetPoint.exe PRC - [2011.06.17 08:35:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\logishrd\KHAL3\KHALMNPR.exe PRC - [2011.04.01 09:31:38 | 007,690,104 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version6\TeamViewer.exe PRC - [2011.04.01 09:31:38 | 002,271,608 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe PRC - [2011.04.01 04:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe PRC - [2011.03.28 19:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE PRC - [2011.03.28 19:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010.12.10 18:30:50 | 000,086,880 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe PRC - [2010.12.10 18:29:30 | 029,293,408 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe PRC - [2010.12.10 18:29:30 | 000,238,944 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe PRC - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe PRC - [2010.11.20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010.11.20 13:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe PRC - [2010.08.26 02:57:32 | 000,380,928 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe PRC - [2010.08.26 02:57:04 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe PRC - [2010.01.14 22:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe PRC - [2009.10.14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Programme\Logitech\Logitech WebCam Software\LWS.exe PRC - [2009.10.14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Programme\Common Files\logishrd\LQCVFX\COCIManager.exe PRC - [2009.10.07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\LVPrcSrv.exe PRC - [2009.07.21 13:40:56 | 002,066,968 | ---- | M] (Intel Corporation) -- C:\Programme\Common Files\Intel\Privacy Icon\UNS\UNS.exe PRC - [2009.07.21 13:40:50 | 000,174,616 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\AMT\LMS.exe PRC - [2009.02.23 11:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Programme\Creative\Shared Files\CTAudSvc.exe ========== Modules (No Company Name) ========== MOD - [2012.01.15 15:53:48 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dd759df05fad8dc6d3404e8e02b40819\Microsoft.VisualBasic.ni.dll MOD - [2012.01.15 15:52:52 | 017,478,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\7bc7e33d4568a214f226cdb6a161a37a\System.ServiceModel.ni.dll MOD - [2012.01.11 23:43:43 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\b41e38edbd6dfe20997f6ea7c080aceb\System.Web.ni.dll MOD - [2012.01.11 23:43:32 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b559a471eef00081f0b5c2719d1d9623\System.Runtime.Remoting.ni.dll MOD - [2012.01.08 13:51:03 | 002,124,760 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll MOD - [2011.12.13 16:57:50 | 000,071,680 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\gecko9\WINNT_x86-msvc\SSSLauncher.dll MOD - [2011.10.19 14:03:46 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\88f32d62a8df469e8b9f12a8d3093627\System.Xml.Linq.ni.dll MOD - [2011.10.19 14:02:54 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dd56ffc9d534de278c79420dcce058a4\System.Core.ni.dll MOD - [2011.10.19 14:01:58 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\2c2215e99c21daeec6bf697cf7bcf103\CustomMarshalers.ni.dll MOD - [2011.10.13 22:10:34 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\76692f411b404f1db0c95d81dd537c37\System.Runtime.Serialization.ni.dll MOD - [2011.10.13 22:10:32 | 000,256,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\6294f61f25c953212b92b7e13a0fd9c1\SMDiagnostics.ni.dll MOD - [2011.10.13 21:12:39 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07cdef1a740151932dcf161f3306bd9c\PresentationFramework.Aero.ni.dll MOD - [2011.10.13 21:12:34 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\70e2ca33ffa52c743285dc5b4910a229\PresentationFramework.ni.dll MOD - [2011.10.13 21:12:14 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7c94a121334aeca7553c7f01290740f0\PresentationCore.ni.dll MOD - [2011.10.13 21:12:03 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll MOD - [2011.10.13 21:11:55 | 001,806,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\dd2070ee8e6e28ac8dc658404c50ebde\System.Deployment.ni.dll MOD - [2011.10.13 21:11:53 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll MOD - [2011.10.13 21:10:59 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll MOD - [2011.10.13 21:10:55 | 000,680,448 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\ccba14fc93de40f4f53d401f07b9bcb8\System.Security.ni.dll MOD - [2011.10.13 21:10:47 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll MOD - [2011.10.13 21:10:41 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll MOD - [2011.10.13 21:10:19 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll MOD - [2011.10.13 21:10:03 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll MOD - [2011.06.24 00:44:34 | 000,877,848 | ---- | M] () -- C:\Programme\Logitech\SetPointP\Macros\MacroCore.dll MOD - [2010.11.13 01:02:21 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2010.11.05 02:57:39 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll MOD - [2010.08.25 20:44:50 | 000,270,336 | ---- | M] () -- C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll MOD - [2010.08.04 14:58:06 | 000,016,384 | R--- | M] () -- C:\Programme\ATI Technologies\ATI.ACE\Branding\Branding.dll MOD - [2009.10.14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Programme\Logitech\Logitech WebCam Software\LWS.exe MOD - [2009.10.14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Programme\Common Files\logishrd\LQCVFX\COCIManager.exe MOD - [2009.08.16 17:06:02 | 000,141,312 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll MOD - [2009.07.14 09:47:20 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll MOD - [2009.07.14 09:47:20 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Serialization.resources\3.0.0.0_de_b77a5c561934e089\System.Runtime.Serialization.resources.dll MOD - [2009.07.14 09:47:16 | 000,397,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Deployment.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Deployment.resources.dll MOD - [2008.03.30 15:22:42 | 000,070,144 | ---- | M] () -- D:\PSPad editor\PSPadShell.dll ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (nosGetPlusHelper) getPlus(R) SRV - [2012.01.30 15:32:16 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.01.30 15:32:15 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.01.03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011.06.17 08:33:46 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2011.04.01 09:31:38 | 002,271,608 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6) SRV - [2011.04.01 04:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv) SRV - [2010.08.26 02:57:04 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility) SRV - [2010.05.04 11:07:22 | 000,503,080 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2010.02.13 16:45:19 | 000,655,624 | ---- | M] (Acresso Software Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010.01.15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2009.12.19 23:00:00 | 006,095,504 | ---- | M] (MySQL AB) [Disabled | Stopped] -- Z:\xampp\mysql\bin\mysqld.exe -- (MySQL) SRV - [2009.12.19 23:00:00 | 000,029,416 | ---- | M] (Apache Software Foundation) [Disabled | Stopped] -- Z:\xampp\apache\bin\httpd.exe -- (Apache2.2) SRV - [2009.12.13 14:29:22 | 000,321,320 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2009.10.27 17:51:10 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service) SRV - [2009.10.07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv) SRV - [2009.07.22 16:54:14 | 000,081,920 | ---- | M] (Firebird Project) [Disabled | Stopped] -- C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance) SRV - [2009.07.22 16:53:44 | 002,736,128 | ---- | M] (Firebird Project) [Disabled | Stopped] -- C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe -- (FirebirdServerDefaultInstance) SRV - [2009.07.21 13:40:56 | 002,066,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\Privacy Icon\UNS\UNS.exe -- (UNS) Intel(R) SRV - [2009.07.21 13:40:50 | 000,174,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\AMT\LMS.exe -- (LMS) Intel(R) SRV - [2009.07.14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009.02.23 11:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Programme\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) ========== Driver Services (SafeList) ========== DRV - [2012.01.30 15:32:16 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2012.01.30 15:32:16 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2011.07.06 10:09:14 | 000,899,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ksaud.sys -- (ksaud) DRV - [2011.05.10 07:06:14 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netaapl.sys -- (Netaapl) DRV - [2011.04.30 13:00:18 | 000,039,064 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2011.04.30 13:00:06 | 000,042,648 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LEqdUsb.sys -- (LEqdUsb) DRV - [2011.04.30 13:00:06 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2011.04.30 13:00:06 | 000,012,184 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidEqd.sys -- (LHidEqd) DRV - [2011.04.01 04:11:10 | 004,333,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 200(UVC) DRV - [2011.04.01 04:09:48 | 000,291,424 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS) DRV - [2010.11.20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus) DRV - [2010.11.20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt) DRV - [2010.11.20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc) DRV - [2010.11.20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010.11.20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010.11.20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010.11.20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap) DRV - [2010.08.26 04:36:28 | 006,380,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2010.08.26 04:36:28 | 006,380,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag) DRV - [2010.08.26 02:20:36 | 000,221,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap) DRV - [2010.08.10 08:45:08 | 000,043,656 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SaiBus.sys -- (SaiNtBus) DRV - [2010.08.10 08:45:08 | 000,020,744 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SaiMini.sys -- (SaiMini) DRV - [2010.07.15 13:47:36 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService) DRV - [2010.05.06 10:21:42 | 000,108,560 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV - [2010.04.01 10:36:35 | 000,229,224 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\VMM.sys -- (vmm) DRV - [2010.02.13 16:36:09 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2009.12.17 15:02:34 | 000,123,280 | ---- | M] (Sun Microsystems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\VBoxDrv.sys -- (VBoxDrv) DRV - [2009.12.17 15:02:34 | 000,110,096 | ---- | M] (Sun Microsystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxNetFlt.sys -- (VBoxNetFlt) DRV - [2009.12.17 15:02:34 | 000,099,152 | ---- | M] (Sun Microsystems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp) DRV - [2009.12.17 15:02:34 | 000,041,616 | ---- | M] (Sun Microsystems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\VBoxUSBMon.sys -- (VBoxUSBMon) DRV - [2009.11.06 00:35:22 | 000,214,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress) Intel(R) DRV - [2009.10.07 08:46:14 | 000,114,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvpopflt.sys -- (lvpopflt) DRV - [2009.10.07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon) DRV - [2009.06.23 14:28:12 | 000,040,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI) Intel(R) DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2008.03.09 15:38:30 | 000,031,616 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\tileproxy.sys -- (Tileproxy) DRV - [2008.02.05 00:50:44 | 000,059,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VMNetSrv.sys -- (VPCNetS2) DRV - [2005.10.31 18:14:22 | 000,327,040 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cinergy.sys -- (CX88VID) DRV - [2005.08.28 21:04:04 | 000,044,032 | ---- | M] (Reality XP) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rxpvbus.sys -- (rxpvbus) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 28 55 C3 A1 56 A3 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Winload Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2 FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:9 FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: twitternotifier@naan.net:2.2.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: prowler@jzlabs.com:1.0.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.7.3 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.92 FF - prefs.js..extensions.enabledItems: stealthyextension@gmail.com:1.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:3.4 FF - prefs.js..network.proxy.type: 4 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.01.08 13:51:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.12 18:52:22 | 000,000,000 | ---D | M] [2009.10.27 16:25:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kerze\AppData\Roaming\mozilla\Extensions [2012.01.31 12:41:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions [2011.12.16 16:19:57 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2011.09.10 11:19:35 | 000,000,000 | ---D | M] (RSS Ticker) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66} [2010.05.26 17:43:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012.01.25 17:38:33 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2011.12.24 12:38:06 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011.01.17 15:19:51 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12} [2010.05.26 17:43:06 | 000,000,000 | ---D | M] (Torbutton) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca} [2010.11.19 13:30:20 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\de-DE@dictionaries.addons.mozilla.org [2011.06.26 14:45:41 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\DTToolbar@toolbarnet.com [2012.01.31 12:41:10 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\fastdial@telega.phpnet.us [2011.12.18 10:17:36 | 000,000,000 | ---D | M] (Fast Dial Fx6) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\fastdialfx6@rouing3.addons.mozilla.org [2009.11.08 16:19:14 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\moveplayer@movenetworks.com [2011.12.11 18:44:35 | 000,000,000 | ---D | M] (OpenMedSpel) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\openmedspel@e-medtools.com [2010.12.06 17:27:26 | 000,000,000 | ---D | M] ("prowler") -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\prowler@jzlabs.com [2012.01.12 18:34:49 | 000,000,000 | ---D | M] (Echofon) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\twitternotifier@naan.net [2010.09.27 13:38:18 | 000,000,000 | ---D | M] (Web Folder) -- C:\Users\Kerze\AppData\Roaming\mozilla\Firefox\Profiles\hyxnhlkx.default\extensions\webfolder@senior_design.jhu [2012.01.02 00:43:06 | 000,001,981 | ---- | M] () -- C:\Users\Kerze\AppData\Roaming\Mozilla\Firefox\Profiles\hyxnhlkx.default\searchplugins\buffed-wow-datenbank.xml [2012.01.08 13:51:26 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2010.03.11 23:54:17 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402} [2010.03.11 23:54:17 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\search@searchsettings.com () (No name found) -- C:\USERS\KERZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HYXNHLKX.DEFAULT\EXTENSIONS\FIREBUG@SOFTWARE.JOEHEWITT.COM.XPI () (No name found) -- C:\USERS\KERZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HYXNHLKX.DEFAULT\EXTENSIONS\STEALTHYEXTENSION@GMAIL.COM.XPI [2012.01.08 13:51:04 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.11.10 05:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2012.01.08 13:51:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.01.08 13:51:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012.01.08 13:51:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012.01.08 13:51:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012.01.08 13:51:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012.01.08 13:51:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.02.13 17:13:43 | 000,000,857 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 activate.adobe.com O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe () O4 - HKLM..\Run: [picon] C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (Intel Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe File not found O4 - Startup: C:\Users\Kerze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe (PokerStars) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{47E30181-D070-4F15-AA2B-2FB2B4D94618}: NameServer = 192.168.1.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{6552f8d2-cbf3-11df-8fc2-0023ae63fe32}\Shell - "" = AutoRun O33 - MountPoints2\{6552f8d2-cbf3-11df-8fc2-0023ae63fe32}\Shell\AutoRun\command - "" = F:\stub.exe O33 - MountPoints2\{c85ba39b-18b5-11df-ab1b-0023ae63fe32}\Shell - "" = AutoRun O33 - MountPoints2\{c85ba39b-18b5-11df-ab1b-0023ae63fe32}\Shell\AutoRun\command - "" = J:\setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F461CEDD-FB1D-923B-EE11-AC0F748FB4BF} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk - C:\Programme\McAfee Security Scan\2.0.181\SSScheduler.exe - (McAfee, Inc.) MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WISO Mein Sparbuch heute.lnk - - File not found MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: AdobeCS4ServiceManager - hkey= - key= - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: ApnUpdater - hkey= - key= - File not found MsConfig - StartUpReg: ApplePhotoStreams - hkey= - key= - File not found MsConfig - StartUpReg: APSDaemon - hkey= - key= - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) MsConfig - StartUpReg: Creative SB Monitoring Utility - hkey= - key= - File not found MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe () MsConfig - StartUpReg: Google Update - hkey= - key= - File not found MsConfig - StartUpReg: iCloudServices - hkey= - key= - File not found MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - State: "services" - 2 MsConfig - State: "startup" - 2 CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.01.31 12:46:44 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Kerze\Desktop\OTL_1.exe [2012.01.31 11:53:06 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012.01.30 14:21:23 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Avira [2012.01.30 10:19:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.01.30 10:19:09 | 000,138,192 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2012.01.30 10:19:09 | 000,066,616 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2012.01.30 10:19:09 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntdd.sys [2012.01.30 10:19:09 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2012.01.30 10:19:09 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntmgr.sys [2012.01.30 10:19:08 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2012.01.26 16:48:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Find [2012.01.26 16:48:28 | 000,000,000 | ---D | C] -- C:\Program Files\MP3Find [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.01.31 12:47:26 | 000,013,248 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.01.31 12:47:26 | 000,013,248 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.01.31 12:46:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL_1.exe [2012.01.31 12:39:01 | 002,281,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.01.31 12:38:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.01.31 12:38:42 | 2401,456,128 | -HS- | M] () -- C:\hiberfil.sys [2012.01.31 12:36:56 | 000,000,020 | ---- | M] () -- C:\Users\Kerze\defogger_reenable [2012.01.31 12:35:44 | 000,050,477 | ---- | M] () -- C:\Users\Kerze\Desktop\Defogger.exe [2012.01.31 11:52:31 | 000,000,422 | ---- | M] () -- C:\Users\Kerze\Documents\cc_20120131_115226.reg [2012.01.31 11:52:15 | 000,050,810 | ---- | M] () -- C:\Users\Kerze\Documents\cc_20120131_115201.reg [2012.01.31 11:51:04 | 000,001,015 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012.01.31 10:43:02 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs [2012.01.30 15:58:33 | 000,000,646 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk [2012.01.30 15:32:16 | 000,138,192 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2012.01.30 15:32:16 | 000,066,616 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2012.01.30 10:19:17 | 000,002,062 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2012.01.30 09:55:14 | 000,007,602 | ---- | M] () -- C:\Users\Kerze\AppData\Local\Resmon.ResmonCfg [2012.01.26 16:48:49 | 000,001,923 | ---- | M] () -- C:\Users\Public\Desktop\MP3Find Aufräumfunktionen.lnk [2012.01.26 16:48:49 | 000,001,879 | ---- | M] () -- C:\Users\Public\Desktop\MP3Find.lnk [2012.01.24 19:23:12 | 000,759,042 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.01.24 19:23:12 | 000,702,490 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.01.24 19:23:12 | 000,173,314 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.01.24 19:23:12 | 000,140,056 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.01.11 23:17:12 | 000,000,600 | ---- | M] () -- C:\Users\Kerze\AppData\Roaming\winscp.rnd [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.01.31 12:36:43 | 000,000,020 | ---- | C] () -- C:\Users\Kerze\defogger_reenable [2012.01.31 12:36:39 | 000,050,477 | ---- | C] () -- C:\Users\Kerze\Desktop\Defogger.exe [2012.01.31 11:52:28 | 000,000,422 | ---- | C] () -- C:\Users\Kerze\Documents\cc_20120131_115226.reg [2012.01.31 11:52:04 | 000,050,810 | ---- | C] () -- C:\Users\Kerze\Documents\cc_20120131_115201.reg [2012.01.30 10:19:17 | 000,002,062 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2012.01.26 16:48:49 | 000,001,923 | ---- | C] () -- C:\Users\Public\Desktop\MP3Find Aufräumfunktionen.lnk [2012.01.26 16:48:49 | 000,001,879 | ---- | C] () -- C:\Users\Public\Desktop\MP3Find.lnk [2011.10.06 16:26:43 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011.07.19 10:13:04 | 000,028,634 | ---- | C] () -- C:\Windows\System32\ksaud.ini [2011.07.03 08:01:43 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011.04.01 04:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll [2011.04.01 04:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe [2011.04.01 04:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll [2011.04.01 03:56:00 | 000,027,872 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [2011.01.04 11:52:10 | 000,012,961 | ---- | C] () -- C:\Users\Kerze\AppData\Roaming\Kommagetrennte Werte (Windows).CAL [2010.10.13 22:36:39 | 000,000,119 | -HS- | C] () -- C:\Windows\cnerolf.bin [2010.09.23 17:56:14 | 000,000,222 | ---- | C] () -- C:\Windows\System32\hrxmsys.drv [2010.09.02 16:59:11 | 000,182,784 | ---- | C] () -- C:\Windows\System32\libspeex.dll [2010.09.02 16:59:10 | 000,057,344 | ---- | C] () -- C:\Windows\System32\Rockey4ND.dll [2010.09.02 16:59:09 | 001,519,616 | ---- | C] () -- C:\Windows\System32\libmySQL.dll [2010.08.25 17:04:45 | 000,007,602 | ---- | C] () -- C:\Users\Kerze\AppData\Local\Resmon.ResmonCfg [2010.08.03 19:15:10 | 000,140,496 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2010.08.03 18:31:03 | 000,138,056 | ---- | C] () -- C:\Users\Kerze\AppData\Roaming\PnkBstrK.sys [2010.08.03 18:15:21 | 000,280,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2010.08.03 18:15:20 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe [2010.08.03 18:15:20 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2010.06.16 14:22:56 | 000,219,348 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2010.06.15 23:28:58 | 000,002,857 | ---- | C] () -- C:\Windows\System32\atipblag.dat [2010.05.08 15:27:00 | 000,038,420 | ---- | C] () -- C:\Users\Kerze\AppData\Roaming\Microsoft Excel 97-2003.ADR [2010.05.03 18:55:14 | 000,002,943 | ---- | C] () -- C:\Windows\System32\Engine.ini [2010.03.27 14:46:09 | 000,000,155 | ---- | C] () -- C:\Windows\ODBC.INI [2010.03.27 14:43:43 | 000,000,232 | ---- | C] () -- C:\Windows\ODBCINST.INI [2010.03.14 16:48:59 | 000,000,600 | ---- | C] () -- C:\Users\Kerze\AppData\Local\PUTTY.RND [2010.03.02 15:42:01 | 000,000,172 | ---- | C] () -- C:\Windows\wiso.ini [2010.01.06 18:12:49 | 000,000,600 | ---- | C] () -- C:\Users\Kerze\AppData\Roaming\winscp.rnd [2009.12.24 00:15:21 | 000,000,119 | -HS- | C] () -- C:\Windows\cnerolf.dat [2009.12.21 18:57:40 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2009.12.19 11:34:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2009.12.15 14:42:20 | 000,004,096 | -H-- | C] () -- C:\Users\Kerze\AppData\Local\keyfile3.drm [2009.12.13 21:25:29 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll [2009.11.08 18:33:36 | 000,003,584 | ---- | C] () -- C:\Users\Kerze\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.10.27 17:52:20 | 000,033,326 | ---- | C] () -- C:\Windows\System32\kschimp.ini [2009.10.27 17:52:16 | 000,177,664 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL [2009.10.27 17:52:16 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL [2009.10.07 01:46:36 | 000,025,752 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys [2009.10.07 01:23:08 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll [2009.08.13 21:45:40 | 000,982,220 | ---- | C] () -- C:\Windows\System32\igkrng500.bin [2009.08.13 21:45:40 | 000,439,300 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin [2009.08.13 21:45:40 | 000,134,592 | ---- | C] () -- C:\Windows\System32\igfcg500.bin [2009.08.13 21:45:40 | 000,092,216 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin [2009.07.14 09:47:43 | 000,759,042 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2009.07.14 09:47:43 | 000,173,314 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 002,281,264 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,702,490 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,140,056 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009.02.24 12:40:02 | 000,001,352 | ---- | C] () -- C:\ProgramData\cfSB1090.ini [2009.02.24 12:40:02 | 000,001,352 | ---- | C] () -- C:\ProgramData\cfSB0910.ini [2009.02.24 12:40:02 | 000,001,346 | ---- | C] () -- C:\ProgramData\cfSB1100.ini [2009.02.24 12:40:02 | 000,001,302 | ---- | C] () -- C:\ProgramData\cfSB0300.ini [2009.02.24 12:40:02 | 000,001,282 | ---- | C] () -- C:\ProgramData\cfSB0471.ini [2009.02.24 12:40:02 | 000,001,208 | ---- | C] () -- C:\ProgramData\cfSB0490.ini [2009.02.24 12:40:02 | 000,001,027 | ---- | C] () -- C:\ProgramData\cfSB0560.ini [2009.02.24 12:40:02 | 000,001,026 | ---- | C] () -- C:\ProgramData\cfSB0271.ini [2009.02.24 12:40:02 | 000,001,026 | ---- | C] () -- C:\ProgramData\cfSB0270.ini [2009.02.24 12:40:02 | 000,000,590 | ---- | C] () -- C:\ProgramData\cfSB0950.ini [2009.02.18 18:55:20 | 000,294,912 | ---- | C] () -- C:\Windows\System32\ATIODE.exe [2009.02.03 21:52:02 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe [2005.08.28 21:04:04 | 000,001,257 | ---- | C] () -- C:\Windows\GARMINWT.INI [2002.02.13 07:00:00 | 000,294,912 | ---- | C] () -- C:\Windows\System32\midas.dll [2002.02.13 07:00:00 | 000,119,808 | ---- | C] () -- C:\Windows\System32\dbexpint.dll ========== LOP Check ========== [2011.02.01 14:47:04 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\.minecraft [2010.05.20 18:41:55 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\.RawTherapee [2010.11.10 20:46:24 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\ASE [2010.12.11 18:26:20 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\BosMon [2010.03.02 15:38:36 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\Buhl Data Service [2011.05.29 16:50:50 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\ChartViewer [2012.01.31 11:51:37 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\DAEMON Tools Lite [2011.09.19 18:00:51 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\FireShot [2010.11.20 19:29:46 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\GrabPro [2011.04.13 14:27:17 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\gtk-2.0 [2011.05.26 19:51:46 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\ICAO Tool [2011.04.25 13:29:06 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\iGrafx [2009.12.29 18:33:05 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\Leadertech [2011.11.13 12:44:24 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\MC-TVConverter [2010.08.25 22:01:26 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\Miranda [2012.01.30 09:41:44 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\Orbit [2011.10.06 16:26:45 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\pdfforge [2010.11.20 15:57:06 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\ProgSense [2010.02.09 18:28:53 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\PureBasic [2010.03.07 16:09:30 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\RawTherapeeAlpha [2011.11.19 15:00:53 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\Scribus [2010.07.26 17:52:46 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\SparweltGutschein [2009.11.16 17:14:53 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\Talkative IRC [2011.03.08 16:22:52 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\TeamViewer [2012.01.31 11:51:35 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\TS3Client [2010.03.27 19:16:36 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\uTorrent [2011.05.07 10:44:14 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\VAT-Spy [2010.10.17 14:44:21 | 000,000,000 | ---D | M] -- C:\Users\Kerze\AppData\Roaming\XMedia Recode [2011.10.07 10:13:42 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.12.16 16:39:51 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2010.08.04 13:14:44 | 000,000,000 | ---D | M] -- C:\ATI [2011.08.15 13:09:24 | 000,000,000 | -HSD | M] -- C:\Boot [2010.12.15 16:16:03 | 000,000,000 | ---D | M] -- C:\BOS-Monitor-0.2.9 [2012.01.31 12:38:38 | 000,000,000 | -HSD | M] -- C:\Config.Msi [2010.08.02 11:14:17 | 000,000,000 | ---D | M] -- C:\dell [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2009.10.25 21:27:31 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2011.01.30 16:04:03 | 000,000,000 | ---D | M] -- C:\Fraps [2011.12.16 16:26:05 | 000,000,000 | ---D | M] -- C:\FS_loeschen [2010.08.02 11:14:20 | 000,000,000 | ---D | M] -- C:\Intel [2011.09.18 18:26:06 | 000,000,000 | ---D | M] -- C:\MicrosoftKB928080 [2011.03.12 17:34:18 | 000,000,000 | ---D | M] -- C:\midi [2009.10.27 16:50:11 | 000,000,000 | RH-D | M] -- C:\MSOCache [2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs [2012.01.31 11:53:09 | 000,000,000 | R--D | M] -- C:\Program Files [2012.01.30 09:56:19 | 000,000,000 | -H-D | M] -- C:\ProgramData [2009.10.25 21:27:31 | 000,000,000 | -HSD | M] -- C:\Programme [2009.10.25 21:27:31 | 000,000,000 | -HSD | M] -- C:\Recovery [2012.01.31 13:09:31 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2009.11.01 15:40:40 | 000,000,000 | ---D | M] -- C:\TerraTec [2011.12.17 11:07:58 | 000,000,000 | R--D | M] -- C:\Users [2012.01.31 12:39:10 | 000,000,000 | ---D | M] -- C:\Windows < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.manifest /3 > < MD5 for: AFD.SYS > [2011.04.25 03:35:40 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=0DB7A48388D54D154EBEC120461A0FCD -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_d81220b5bf827af7\afd.sys [2010.11.20 09:40:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=1151FD4FB0216CFED887BFDE29EBD516 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b\afd.sys [2011.04.25 03:18:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=9EBBBA55060F786F0FCAA3893BFA2806 -- C:\Windows\System32\drivers\afd.sys [2011.04.25 03:18:03 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=9EBBBA55060F786F0FCAA3893BFA2806 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_d9f97e05bca8003a\afd.sys [2011.04.25 03:27:23 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C114AB7A1550D42EA1700FFD4179CF5A -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys [2011.04.25 04:24:09 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=C427F91A748CD342A2B3F9278D9FD6A5 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_da774a9ad5cea29e\afd.sys [2009.07.14 00:12:38 | 000,338,944 | ---- | M] (Microsoft Corporation) MD5=DDC040FDB01EF1712A6B13E52AFB104C -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys < MD5 for: EXPLORER.EXE > [2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe [2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe [2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe [2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe [2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe [2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe [2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe [2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe < MD5 for: REGEDIT.EXE > [2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe [2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe < MD5 for: USERINIT.EXE > [2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe [2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe < MD5 for: WININIT.EXE > [2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe [2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe < MD5 for: WINLOGON.EXE > [2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe [2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe [2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe [2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe [2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-31 09:53:06 < > < End of report > Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 12:36 on 31/01/2012 (Kerze) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... Unable to read sptd.sys SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- Gruß Kerze Geändert von Kerze (31.01.2012 um 13:22 Uhr) Grund: Defogger & Gruß |
31.01.2012, 15:17 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Sehr langsame InternetverbindungZitat:
Das OTL-Log stammt vom Desktop-PC? Versuch mal rauszufinden, ob das nur unter Windows so ist, oder auch mit anderen Betriebssystemen. Lad dir mal sowas wie Knoppix oder Ubuntu herunter, brenn die iso Datei per Imagebrennfunktion auf eine CD und boote den Rechner davon. Teste dann mal ausgiebig die Internetverbindung unter Linux und berichte ob die Verbindung und das System dort normal schnell oder auch langsam ist. (Speedtest wie speed.io oder wieistmeineip.de kann hilfreich sein)
__________________ |
31.01.2012, 15:28 | #3 |
| Sehr langsame Internetverbindung Hallo cosinus,
__________________da das OTL-Log stammt von dem Desktop-PC. Ich habe gerade dazu noch festgestellt, das es am Netzwerk liegen kann (Muss). Die Verbindungsgeschwindigkeit zu meiner NAS (Synolog DS107+) ist auch sehr langsam. Mein Router ist ein Siemens ADSL SL2-141-I. Ich werde es mit einem Linux ausprobieren. Danke für den Tipp! Gruß Kerze |
31.01.2012, 16:43 | #4 |
| Sehr langsame Internetverbindung Mahlzeit nochmal, Ich habe nun ein Linux Live Ubuntu vom USB-Stick laufen. Damit komme ich auf Geschwindigkeiten Down: 83 kByte/sec, Up: 32kByte/sec. Dies ist meiner Ansicht nach immernoch zu gering. Ich weiß auch mittlerweile nicht mehr was ich da noch machen kann... |
31.01.2012, 20:42 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Sehr langsame Internetverbindung Router mal neu gestartet? Anderen LAN-Port probiert? An Windows selbst liegt es offenbar ja nicht, vllt hat auch deine Netzwerkkarte ne Macke
__________________ Logfiles bitte immer in CODE-Tags posten |
01.02.2012, 16:13 | #6 |
| Sehr langsame Internetverbindung Router hatte ich schon neu gestartet. LAN-Port habe ich mal gewechselt, Lan-Kabel gewechselt. Keine Besserung... Nun habe ich mein Laptop gerade per Lankabel (wlan aus) getestet => langsame Geschwindigkeit Lankabel raus. Wlan an. => top Geschwindigkeit. Ich vermute das es am Router liegt. |
02.02.2012, 09:51 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Sehr langsame Internetverbindung Schon merkwürdig. Vllt hat der Router ja echt ne Macke. Was für ein Router ist das, genaues Modell von welchem Hersteller? Firmware ist aktuell? Notfalls müsstest du den mal in Werkeinstellungen zurücksetzen, dann sind aber alle Einstellungen wie zB Zugangsdaten, eingens definierter WLAN-Schlüssel, Portweiterleitungen etc. auch weg bzw. zurückgesetzt. Spinnt der Router auch bei Werkseinstellungen wird das Teil wohl defekt sein.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Sehr langsame Internetverbindung |
.com, adobe, antivir, avg, avira, bho, branding, curse, defender, dsl, excel.exe, explorer, firefox, format, internet, langs, langsam, logfile, mozilla, plug-in, programme, registry, required, rundll, scan, security scan, server, software, sparbuch, trojaner-board, ups, version=1.0, webcheck, windows, winlogon.exe, wiso, wlan |