|
Plagegeister aller Art und deren Bekämpfung: Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runterWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.07.2012, 23:52 | #1 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Guten Tag, ich habe folgendes Problem: (Zusätzliche Informationen: Betriebssystem: Windows XP SP3 AV: Avast mit Guard, Mbam) Ich habe gestern versucht, die Datei "MechTexturizer.exe" runterzuladen, als mein AV plötzlich Alarm schlug und die Datei direkt in den Viruscontainer verschob. Bei dieser Datei handelt es sich angeblich um ein Mod/Tool für das Spiel Mechwarrior 3, und um sicherzugehen, das es nicht einfach nur um ein False-Positive handelt (wäre nicht das Erste mal, ist mir schon öfters vorgekommen dass eine Datei nur von einem oder zwei AV's als infiziert beschrieben wurde, obwohl dies im Endeffekt nicht der Fall war. Und zusätzlich wurde darauf hingewiesen dass in der Vergangenheit einige AV's diese Datei als "False-Positive" erkannt haben), habe ich: - In Avast's Viruscontainer die Datei ausgewählt, und auf "Aus Container extrahieren..." geklickt und die Datei auf den Desktop kopiert, mit dem Ziel, sie auf Virustotal hochzuladen. Dummerweise hat mein Internet gebockt (macht es manchmal) und ich musste den PC neu starten (Anmerkung: Avast sagte die Datei sei immer noch im Viruscontainer) - Nach dem Neustart habe ich direkt versucht die Datei auf VT hochzuladen, aber als sich das Fenster öffnet und ich auf die Datei klicke, fährt der PC direkt runter und startet neu. (Anmerkung: Avast sagte immer noch die Datei sei im Viruscontainer, habe überprüft bevor ich versucht habe sie hochzuladen: sie ist einmal auf dem Desktop und einmal in Avast's Viruscontainer...) - Nach diesem (dem Zweiten) Neustart habe ich versucht die auf dem Desktop befindliche Datei mit Mbam zu scannen, und der der PC fuhr wieder runter und startet neu. - Nur diesmal waren beide vorher genannten Dateien fort, einfach verschwunden (selbst die in Avast's Viruscontainer). - Habe nun den PC manuell neu gestartet (im abgesicherten Modus) und habe sowohl mit Mbam als Avast einen Komplettscan durchgeführt, wobei nur Avast irgendwas in der Systemwiederherstellung gefunden hat, eine Infektion namens "Win32:Malware-gen", wobei es sich wohl um Überreste der vorher genannten Dateien handelt, die ich auch prompt entfernt habe (anschließend habe ich die Systemwiederherstellung deaktiviert und nach einem Neustart wieder aktiviert) Nun bin ich doch etwas verwirrt ob diese Datei wirklich sicher war (nach 2 shutdowns meines PC's), und was eigentlich mit ihr passiert ist (da ich sie definitiv nicht gelöscht habe, und noch nie gehört habe, dass Avast oder irgendein anderes Antiviren Programm einfach so suspekte Dateien löscht, ohne irgendwie dazu aufgefordert zu werden...) Hoffe ihr könnt mir bei diesem Problem(?) helfen... (ich bin doch sehr verwirrt hier und nicht nur ein bísschen besorgt...) Anbei sind: Screenshot von Avast (Komplettscan) und die Logs von Defogger, OTL, aswMBR, MBR, Catchme.exe, Gmer und Mbam (von gestern)... habe Computer/Benutzername durch * ersetzt. Vielen Dank im Voraus. Edit: Beim Scan von Mbam habe ich die Dateien auf dem unter Desktop im zweiten (eingeschränkten) Benutzerkonto ausgelassen/ausgeschlossen (hauptsächlich Bilder und Videos), weil diese Mbam's Scan doch sehr verlangsamen wenn vom Administrator Konto ausgeführt (aber nicht wenn vom vorher genannten eingeschränkten Konto)... Geändert von Tenreijo (09.07.2012 um 00:07 Uhr) |
12.07.2012, 10:31 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
__________________Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.
__________________ |
12.07.2012, 21:51 | #3 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Habe leider keine älteren Logs mehr, habe aber in der Zwischenzeit noch zweimal mit einer upgedateten Version gescannt (wurde beides mal nichts gefunden)
__________________Anbei sind dei neuen Logs. |
13.07.2012, 11:52 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Führ bitte auch ESET aus, danach sehen wir weiter. Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden. ESET Online Scanner Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
Code:
ATTFilter "%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt" Code:
ATTFilter "%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
__________________ Logfiles bitte immer in CODE-Tags posten |
13.07.2012, 18:42 | #5 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Hier ist das Log von ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=a56c216b71233e4e8002a48358d68438 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-07-13 05:33:53 # local_time=2012-07-13 07:33:53 (+0100, Paris, Madrid (heure d'été)) # country="France" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=768 16777215 100 0 50974567 50974567 0 0 # compatibility_mode=8192 67108863 100 0 328 328 0 0 # scanned=65936 # found=0 # cleaned=0 # scan_time=3713 |
13.07.2012, 21:55 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ --> Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter |
14.07.2012, 00:38 | #7 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Hier ist das Log von AdwCleaner (habe Benutzer/Computernamen mit * editiert) Code:
ATTFilter # AdwCleaner v1.702 - Rapport créé le 14/07/2012 à 01:23:13 # Mis à jour le 13/07/2012 par Xplode # Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits) # Nom d'utilisateur : ****** - *****-37AD7B7B3 # Exécuté depuis : C:\Documents and Settings\******\Bureau\adwcleaner0.exe # Option [Recherche] ***** [Services] ***** ***** [Fichiers / Dossiers] ***** ***** [Registre] ***** Clé Présente : HKLM\SOFTWARE\Canneverbe Limited\OpenCandy Clé Présente : HKLM\SOFTWARE\DT Soft Clé Présente : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 ***** [Registre - GUID] ***** Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1} Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999} ***** [Navigateurs] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Le registre ne contient aucune entrée illégitime. -\\ Mozilla Firefox v13.0.1 (de) Nom du profil : default Fichier : C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\prefs.js [OK] Le fichier ne contient aucune entrée illégitime. -\\ Google Chrome v [Impossible d'obtenir la version] Fichier : C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] Le fichier ne contient aucune entrée illégitime. -\\ Opera v12.0.1467.0 Fichier : C:\Documents and Settings\******\Application Data\Opera\Opera\operaprefs.ini [OK] Le fichier ne contient aucune entrée illégitime. ************************* AdwCleaner[R1].txt - [1633 octets] - [14/07/2012 01:23:13] ########## EOF - C:\AdwCleaner[R1].txt - [1761 octets] ########## |
14.07.2012, 13:42 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
__________________ Logfiles bitte immer in CODE-Tags posten |
14.07.2012, 20:16 | #9 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Hier ist das zweite Log von AdwCleaner Code:
ATTFilter # AdwCleaner v1.702 - Rapport créé le 14/07/2012 à 21:08:21 # Mis à jour le 13/07/2012 par Xplode # Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits) # Nom d'utilisateur : ****** - *****-37AD7B7B3 # Exécuté depuis : C:\Documents and Settings\******\Bureau\adwcleaner0.exe # Option [Suppression] ***** [Services] ***** ***** [Fichiers / Dossiers] ***** ***** [Registre] ***** Clé Supprimée : HKLM\SOFTWARE\Canneverbe Limited\OpenCandy Clé Supprimée : HKLM\SOFTWARE\DT Soft Clé Supprimée : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 ***** [Registre - GUID] ***** Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1} Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999} ***** [Navigateurs] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Le registre ne contient aucune entrée illégitime. -\\ Mozilla Firefox v13.0.1 (de) Nom du profil : default Fichier : C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\prefs.js [OK] Le fichier ne contient aucune entrée illégitime. -\\ Google Chrome v [Impossible d'obtenir la version] Fichier : C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] Le fichier ne contient aucune entrée illégitime. -\\ Opera v12.0.1467.0 Fichier : C:\Documents and Settings\******\Application Data\Opera\Opera\operaprefs.ini [OK] Le fichier ne contient aucune entrée illégitime. ************************* AdwCleaner[R1].txt - [1762 octets] - [14/07/2012 01:23:13] AdwCleaner[S2].txt - [1700 octets] - [14/07/2012 21:08:21] ########## EOF - C:\AdwCleaner[S2].txt - [1828 octets] ########## |
14.07.2012, 22:16 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:
ATTFilter netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start wininit.exe userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT
__________________ Logfiles bitte immer in CODE-Tags posten |
15.07.2012, 07:46 | #11 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Hier ist das zweite Log von OTL OTL Logfile: Code:
ATTFilter OTL logfile created on: 15/07/2012 03:51:00 - Run 2 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\******\Bureau Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 2,00 Gb Total Physical Memory | 1,62 Gb Available Physical Memory | 80,85% Memory free 3,91 Gb Paging File | 3,60 Gb Available in Paging File | 91,89% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 76,68 Gb Total Space | 6,76 Gb Free Space | 8,82% Space Free | Partition Type: NTFS Drive K: | 7,45 Gb Total Space | 3,00 Gb Free Space | 40,28% Space Free | Partition Type: FAT32 Computer Name: *****-37AD7B7B3 | User Name: ****** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012/07/14 23:53:38 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe PRC - [2012/07/03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2012/06/20 00:09:40 | 003,069,752 | ---- | M] (Emsisoft GmbH) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe PRC - [2011/01/05 12:31:34 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe PRC - [2011/01/05 12:31:32 | 000,988,216 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe PRC - [2008/04/14 04:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () -- C:\Program Files\System Control Manager\edd.exe PRC - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\o2flash.exe ========== Modules (No Company Name) ========== MOD - [2012/07/14 22:24:14 | 001,783,296 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071402\algo.dll MOD - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () -- C:\Program Files\System Control Manager\edd.exe MOD - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\o2flash.exe ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/06/20 00:09:40 | 003,069,752 | ---- | M] (Emsisoft GmbH) [Auto | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware) SRV - [2012/06/15 00:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2011/01/05 12:31:34 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent) SRV - [2011/01/05 12:31:32 | 000,988,216 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\psia.exe -- (Secunia PSI Agent) SRV - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files\System Control Manager\edd.exe -- (NishService) SRV - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\o2flash.exe -- (O2Flash) SRV - [2004/10/22 04:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\RtNdPt5x.sys -- (RtNdPt5x) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTLVLAN.SYS -- (RTLVLAN) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTLTEAMING.SYS -- (RTLTEAMING) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ahtbm9tl) DRV - [2012/07/03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/07/03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/07/03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/07/03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/07/03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2012/07/03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/07/03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/06/29 19:39:20 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2012/06/20 00:09:15 | 000,054,072 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Stopped] -- C:\Program Files\Emsisoft Anti-Malware\a2accx86.sys -- (a2acc) DRV - [2012/04/21 12:17:48 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2011/10/17 13:49:49 | 000,078,848 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SSHDRV85.sys -- (SSHDRV85) DRV - [2011/05/19 14:10:34 | 000,017,904 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys -- (A2DDA) DRV - [2010/11/02 20:36:26 | 006,188,648 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2010/09/11 04:19:16 | 005,417,472 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2010/09/01 10:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI) DRV - [2010/07/21 13:30:32 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService) DRV - [2010/07/06 03:13:10 | 000,234,392 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2010/07/04 21:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5) DRV - [2010/05/24 21:09:28 | 004,003,008 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtKHDMI.sys -- (RTHDMIAzAudService) DRV - [2010/03/09 12:09:32 | 000,594,048 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtl8192su.sys -- (RTL8192su) DRV - [2010/02/11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6) DRV - [2009/11/18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009/11/18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2008/10/29 07:34:40 | 000,644,096 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870) DRV - [2008/10/09 15:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER) DRV - [2008/04/13 20:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx) DRV - [2008/04/13 20:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm) DRV - [2008/03/22 23:37:20 | 000,113,896 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\keyscrambler.sys -- (KeyScrambler) DRV - [2006/07/03 11:31:26 | 000,009,088 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MGHwCtrl.sys -- (MGHwCtrl) DRV - [2006/03/01 19:53:54 | 000,032,128 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcandis5.sys -- (PCANDIS5) DRV - [2004/08/05 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb) DRV - [2004/08/05 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx) DRV - [2004/08/03 23:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x) DRV - [2003/09/23 11:38:34 | 000,034,688 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcampr5.sys -- (PCAMPR5) DRV - [2001/08/23 17:59:36 | 000,075,392 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19.1 FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:5.0.1 FF - prefs.js..extensions.enabledItems: de_DE@dicts.j3e.de:20111003 FF - prefs.js..extensions.enabledItems: fr-reforme1990@dictionaries.addons.mozilla.org:4.0.3 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10 FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1.2 FF - prefs.js..extensions.enabledItems: adblockpopups@jessehakanen.net:0.2.9 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.8 FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87 FF - prefs.js..extensions.enabledItems: optimizegoogle@optimizegoogle.com:0.78.2 FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.7 FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4 FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.67 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.6 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2 FF - prefs.js..extensions.enabledItems: keyscrambler@qfx.software.corporation:2.1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: wrc@avast.com:6.0.1289 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/07/09 21:32:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/25 15:27:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/25 15:06:47 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Programme\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/25 14:59:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/11/12 04:37:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Extensions [2010/11/12 04:37:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/07/12 07:24:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions [2010/11/12 05:40:55 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012/04/21 11:56:02 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2012/04/01 14:32:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010/11/12 04:39:37 | 000,000,000 | ---D | M] (Redirect Remover) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9} [2012/06/29 21:13:08 | 000,000,000 | ---D | M] (Wörterbuch Deutsch (de-DE), Hunspell-unterstützt) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\de_DE@dicts.j3e.de [2010/12/12 16:34:32 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\en-GB@dictionaries.addons.mozilla.org [2012/05/26 20:30:36 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\en-US@dictionaries.addons.mozilla.org [2011/11/11 23:30:41 | 000,000,000 | ---D | M] (Dictionnaire français «Réforme 1990») -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\fr-reforme1990@dictionaries.addons.mozilla.org [2010/11/12 04:48:56 | 000,000,000 | ---D | M] (KeyScrambler) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation [2011/03/16 06:10:12 | 000,000,000 | ---D | M] (Personas) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\personas@christopher.beard [2012/06/25 15:27:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/06/25 15:06:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012/07/12 07:24:19 | 000,525,390 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI [2012/07/11 01:06:27 | 000,061,228 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI [2012/01/21 13:52:58 | 000,138,614 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI [2012/06/21 13:31:33 | 000,109,964 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\ADBLOCKPOPUPS@JESSEHAKANEN.NET.XPI [2011/11/11 23:30:35 | 000,236,088 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\OPTIMIZEGOOGLE@OPTIMIZEGOOGLE.COM.XPI [2012/06/15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/06/15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/06/15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/06/15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012/06/15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012/06/15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012/06/15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\pdf.dll CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\gears.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin O1 HOSTS File: ([2012/07/13 18:20:21 | 000,443,529 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 15235 more lines... O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181 O7 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FB FF FF 03 [binary data] O9 - Extra 'Tools' menuitem : &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289332900642 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Ma page d'accueil) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Colline verdoyante.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Colline verdoyante.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/10/26 15:39:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [1996/10/31 19:51:30 | 000,000,047 | R--- | M] () - J:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{58af6740-ff7d-11e0-b98e-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{58af6740-ff7d-11e0-b98e-806d6172696f}\Shell\AutoRun\command - "" = J:\ARUN.EXE -- [1996/11/05 13:04:22 | 000,182,272 | R--- | M] (Microprose) O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (aswBoot.exe /M:d7880c91) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: WmdmPmSp - File not found MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe - (Secunia) MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Sitecom 300N USB Wireless LAN Utility.lnk - C:\Program Files\SITECOM\300N USB Wireless LAN Utility\RtWLan.exe - (Realtek Semiconductor Corp.) MsConfig - StartUpFolder: C:^Documents and Settings^*******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia) MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.4.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia) MsConfig - StartUpFolder: C:^Documents and Settings^*****^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.4.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpFolder: C:^Documents and Settings^*****^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia) MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig - StartUpReg: KernelFaultCheck - hkey= - key= - File not found MsConfig - StartUpReg: MGSysCtrl - hkey= - key= - C:\Program Files\System Control Manager\MGSysCtrl.exe (MSI) MsConfig - StartUpReg: ORAHSSSessionManager - hkey= - key= - C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe (France Telecom SA) MsConfig - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: UnlockerAssistant - hkey= - key= - C:\Program Files\Unlocker\UnlockerAssistant.exe () SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: nm - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) SafeBootNet: nm.sys - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Rendu VML (Vector Graphics Rendering) ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Liaison de données Dynamic HTML pour Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Création avancée ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Classes Java DirectAnimation ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {72AD53CC-CCC0-3757-8480-9EE176866A7C} - .NET Framework ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {9A394342-4A68-4EBA-85A6-55B559F4E700} - .NET Framework ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Planificateur de tâches ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate ActiveX: {F196AC50-7C95-42E1-9947-BDAB18BF3C8C} - .NET Framework ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE ActiveX: Microsoft Base Smart Card Crypto Provider Package - Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012/07/14 23:53:28 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe [2012/07/13 18:26:50 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012/07/08 22:45:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Logs [2012/07/08 01:22:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\******\Recent [2012/07/06 08:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Nouv [2012/07/05 21:42:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Nou [2012/07/02 18:02:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\DOSBox [2012/07/02 17:09:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Local Settings\Application Data\DOSBox [2012/07/02 17:05:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\DOSBox-0.74 [2012/07/02 16:37:39 | 000,000,000 | ---D | C] -- C:\DOS [2012/07/02 01:36:49 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF [2012/07/01 21:08:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Ma [2012/06/29 19:39:20 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2012/06/25 18:10:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\dwhelper [2012/06/16 01:48:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Application Data\PhotoFiltre [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/07/15 03:50:22 | 000,576,084 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat [2012/07/15 03:50:22 | 000,502,718 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/07/15 03:50:22 | 000,104,688 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat [2012/07/15 03:50:22 | 000,088,242 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/07/15 03:46:40 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/07/15 03:45:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/07/14 23:55:27 | 000,113,541 | ---- | M] () -- C:\Documents and Settings\******\Bureau\screen2.png [2012/07/14 23:53:38 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe [2012/07/14 23:47:09 | 000,013,728 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/07/13 18:20:21 | 000,443,529 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012/07/12 03:19:54 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\ Malwarebytes Anti-Malware .lnk [2012/07/11 01:10:07 | 000,196,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/07/11 01:08:22 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012/07/09 21:40:27 | 000,003,121 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012/07/09 21:31:04 | 000,443,055 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120713-182021.backup [2012/07/09 21:30:09 | 000,443,055 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-213104.backup [2012/07/08 20:22:41 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\******\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/07/03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/07/03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/07/03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/07/03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/07/03 18:21:53 | 000,089,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/07/03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/07/03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/07/03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/07/03 18:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/07/03 18:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/07/02 23:30:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\******\peerblock.dmp [2012/07/02 18:18:00 | 000,000,546 | ---- | M] () -- C:\WINDOWS\System32\autoexec2.nt [2012/07/01 21:18:39 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk [2012/06/29 19:46:06 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-213008.backup [2012/06/29 19:39:20 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2012/06/25 15:27:56 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2012/06/25 15:27:56 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Firefox.lnk [2012/06/25 14:59:59 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk [2012/06/25 14:59:58 | 000,001,668 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Thunderbird.lnk [2012/06/25 14:20:00 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120629-194606.backup [2012/06/25 14:19:30 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-142000.backup [2012/06/17 12:26:34 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-141930.backup [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/07/14 23:55:26 | 000,113,541 | ---- | C] () -- C:\Documents and Settings\Ryudo\Bureau\screen2.png [2012/07/11 01:03:55 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK [2012/07/09 21:32:15 | 000,000,318 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/07/02 18:18:00 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\autoexec2.nt [2012/05/31 01:38:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\******\peerblock.dmp [2012/02/15 16:38:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011/12/12 21:20:53 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\******\Application Data\mainhst.zgh [2011/11/09 21:17:29 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2011/10/17 13:49:49 | 000,078,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV85.sys [2011/10/17 09:29:37 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2011/09/29 01:12:24 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll [2011/09/29 01:12:24 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll [2011/09/29 01:12:24 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll [2011/09/28 20:51:00 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2010/12/15 00:39:42 | 000,210,944 | ---- | C] () -- C:\Documents and Settings\******\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/12/01 15:13:49 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe [2010/12/01 15:13:21 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe [2010/11/10 06:02:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin [2010/11/10 06:01:56 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat [2010/11/10 06:01:55 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe [2010/11/10 06:01:55 | 000,224,342 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat [2010/11/10 06:01:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe [2010/11/10 06:01:55 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat [2010/11/10 03:55:43 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010/11/09 21:34:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2010/11/09 21:08:58 | 000,015,312 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat [2010/11/01 14:17:35 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2010/11/01 14:13:12 | 000,196,160 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/11/01 14:07:21 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\MGHwCtrl.dll [2010/11/01 14:07:21 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\MGFPCtrl.dll [2010/11/01 14:07:21 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\MGPwrShm.dll [2010/11/01 13:32:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2010/11/01 13:25:17 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat ========== LOP Check ========== [2010/11/22 03:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2010/11/10 06:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited [2012/06/29 19:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2011/12/15 02:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Beerowser [2010/11/11 00:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Canneverbe Limited [2012/07/09 01:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DAEMON Tools Lite [2010/11/12 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DeviceDoctorSoftware [2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog [2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter [2012/07/15 01:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++ [2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org [2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera [2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre [2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy [2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki [2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird [2012/07/15 03:44:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent [2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius [2012/07/15 03:46:40 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > [2011/06/23 13:13:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe [2010/11/22 03:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2010/11/10 06:04:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI [2010/11/10 06:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited [2012/06/29 19:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2010/11/10 08:33:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2010/11/10 03:41:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee [2011/05/05 00:13:50 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft [2012/05/08 20:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mozilla [2012/07/09 21:27:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2010/11/10 03:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun [2010/11/09 22:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage < %ALLUSERSPROFILE%\Application Data\*.exe /s > [2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AcrobatUpdater.exe [2012/01/03 09:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AdobeARM.exe [2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AdobeARMHelper.exe [2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\ReaderUpdater.exe [2012/07/12 03:19:05 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe < %APPDATA%\*. > [2011/03/25 12:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Adobe [2010/11/11 00:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ATI [2010/11/22 04:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Avira [2011/12/15 02:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Beerowser [2010/11/11 00:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Canneverbe Limited [2012/07/09 01:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DAEMON Tools Lite [2010/11/12 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DeviceDoctorSoftware [2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog [2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter [2011/12/24 09:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Help [2010/11/10 02:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Identities [2012/07/15 03:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Macromedia [2010/11/11 00:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Malwarebytes [2012/07/08 06:02:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Media Player Classic [2012/02/14 17:04:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\******\Application Data\Microsoft [2010/11/11 00:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Mozilla [2012/07/15 01:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++ [2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org [2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera [2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre [2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy [2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki [2011/02/27 14:02:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sun [2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird [2012/07/15 03:44:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent [2012/06/25 20:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\vlc [2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius < %APPDATA%\*.exe /s > [2008/06/02 00:25:02 | 000,737,192 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation\installer\setup.exe < %SYSTEMDRIVE%\*.exe > [2008/04/11 08:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe < MD5 for: AGP440.SYS > [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys [2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys < MD5 for: ATAPI.SYS > [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys [2004/08/05 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys < MD5 for: EVENTLOG.DLL > [2004/08/05 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=21E83876A6287F15538EF187D286FE11 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll [2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: NETLOGON.DLL > [2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\netlogon.dll [2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll [2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll [2004/08/05 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=FAF07FDCDE76000621A28D19F8E2E8EB -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll < MD5 for: SCECLI.DLL > [2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\scecli.dll [2004/08/05 14:00:00 | 000,186,368 | ---- | M] (Microsoft Corporation) MD5=DEC0397F35D027874804EC72979D03CC -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll < MD5 for: USER32.DLL > [2005/03/02 20:10:36 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=0DF75FB73F705B011630159A43D7C354 -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll [2007/03/08 17:50:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=4D88AAF39ADABFE45958EA1384E2C4FF -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll [2007/03/08 17:37:50 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=753354F594809A9B96F73999B435A533 -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll [2005/03/02 20:20:32 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=C34920EB988CE98910BD6B0417F334EB -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll [2004/08/05 14:00:00 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=E46FB493E3B33704F0715020CF52106B -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll [2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\ServicePackFiles\i386\user32.dll [2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\system32\user32.dll < MD5 for: USERINIT.EXE > [2004/08/05 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D6D65EA32B190401B57EDB6706F29669 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe [2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe [2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2004/08/05 14:00:00 | 000,506,368 | ---- | M] (Microsoft Corporation) MD5=D2DE785AEAB0BB8CA4C14A8A199DBE4E -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe [2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys [2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2010/11/01 14:12:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2010/11/01 14:12:00 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2010/11/01 14:11:59 | 000,475,136 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < > < End of report > |
15.07.2012, 16:49 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runterCode:
ATTFilter PRC - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2012/06/20 00:09:40 | 003,069,752 | ---- | M] (Emsisoft GmbH) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe Willst du dein System in die Knie zwingen? Zwei solcher Virenscanner installiert man niemals parallel! Deinstalliere einen der beiden! Am besten behälst du Avast Max. Malwarebytes kann man zu einem installierten Virenscanner benutzen, bei Malwarebytes würde ich aber die reine Free-Variante ohne Hintergrundschutz-Modul verwenden. (die anderen Scanner die ich hier in der Bereinigung/Analyse verwende kommen den anderen auch nichts ins Gehege)
__________________ Logfiles bitte immer in CODE-Tags posten |
15.07.2012, 19:48 | #13 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Ich habe Emsisoft jetzt deinstalliert, hatte immer nur bei Avast den Guard/Hintergrundwächter aktiviert (habe bei Emsisoft nur die normale Scan Funktion benutzt, ohne Hintergrundwächter, selbes gilt für Mbam). Sonst alles in Ordnung? |
15.07.2012, 20:35 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Ok, mach bitte wieder ein neues OTL-Log wie o.g.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.07.2012, 21:32 | #15 |
| Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter Habe OTL nochmal neu heruntergeladen. Hier ist das neue Log: Code:
ATTFilter OTL logfile created on: 15/07/2012 21:53:00 - Run 3 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\******\Bureau Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 2,00 Gb Total Physical Memory | 1,61 Gb Available Physical Memory | 80,78% Memory free 3,91 Gb Paging File | 3,63 Gb Available in Paging File | 92,64% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 76,68 Gb Total Space | 6,35 Gb Free Space | 8,29% Space Free | Partition Type: NTFS Drive K: | 7,45 Gb Total Space | 3,00 Gb Free Space | 40,28% Space Free | Partition Type: FAT32 Computer Name: *****-37AD7B7B3 | User Name: ****** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012/07/15 21:44:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe PRC - [2012/07/03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2011/01/05 12:31:34 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe PRC - [2011/01/05 12:31:32 | 000,988,216 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe PRC - [2008/04/14 04:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () -- C:\Program Files\System Control Manager\edd.exe PRC - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\o2flash.exe ========== Modules (No Company Name) ========== MOD - [2012/07/15 10:56:50 | 001,783,296 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071500\algo.dll MOD - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () -- C:\Program Files\System Control Manager\edd.exe MOD - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\o2flash.exe ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/06/15 00:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2011/01/05 12:31:34 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent) SRV - [2011/01/05 12:31:32 | 000,988,216 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\psia.exe -- (Secunia PSI Agent) SRV - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files\System Control Manager\edd.exe -- (NishService) SRV - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\o2flash.exe -- (O2Flash) SRV - [2004/10/22 04:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\\SystemRoot\System32\Drivers\sptd.sys -- (sptd) DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\RtNdPt5x.sys -- (RtNdPt5x) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTLVLAN.SYS -- (RTLVLAN) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTLTEAMING.SYS -- (RTLTEAMING) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012/07/03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/07/03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/07/03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/07/03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/07/03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2012/07/03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/07/03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/06/29 19:39:20 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011/10/17 13:49:49 | 000,078,848 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SSHDRV85.sys -- (SSHDRV85) DRV - [2010/11/02 20:36:26 | 006,188,648 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2010/09/11 04:19:16 | 005,417,472 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2010/09/01 10:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI) DRV - [2010/07/21 13:30:32 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService) DRV - [2010/07/06 03:13:10 | 000,234,392 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2010/07/04 21:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5) DRV - [2010/05/24 21:09:28 | 004,003,008 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtKHDMI.sys -- (RTHDMIAzAudService) DRV - [2010/03/09 12:09:32 | 000,594,048 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtl8192su.sys -- (RTL8192su) DRV - [2010/02/11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6) DRV - [2009/11/18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009/11/18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2008/10/29 07:34:40 | 000,644,096 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870) DRV - [2008/10/09 15:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER) DRV - [2008/04/13 20:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx) DRV - [2008/04/13 20:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm) DRV - [2008/03/22 23:37:20 | 000,113,896 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\keyscrambler.sys -- (KeyScrambler) DRV - [2006/07/03 11:31:26 | 000,009,088 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MGHwCtrl.sys -- (MGHwCtrl) DRV - [2006/03/01 19:53:54 | 000,032,128 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcandis5.sys -- (PCANDIS5) DRV - [2004/08/05 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb) DRV - [2004/08/05 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx) DRV - [2004/08/03 23:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x) DRV - [2003/09/23 11:38:34 | 000,034,688 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcampr5.sys -- (PCAMPR5) DRV - [2001/08/23 17:59:36 | 000,075,392 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19.1 FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:5.0.1 FF - prefs.js..extensions.enabledItems: de_DE@dicts.j3e.de:20111003 FF - prefs.js..extensions.enabledItems: fr-reforme1990@dictionaries.addons.mozilla.org:4.0.3 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10 FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1.2 FF - prefs.js..extensions.enabledItems: adblockpopups@jessehakanen.net:0.2.9 FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.8 FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87 FF - prefs.js..extensions.enabledItems: optimizegoogle@optimizegoogle.com:0.78.2 FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.7 FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4 FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.67 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.6 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2 FF - prefs.js..extensions.enabledItems: keyscrambler@qfx.software.corporation:2.1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: wrc@avast.com:6.0.1289 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/07/09 21:32:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/25 15:27:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/25 15:06:47 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Programme\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/25 14:59:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/11/12 04:37:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Extensions [2010/11/12 04:37:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/07/12 07:24:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions [2010/11/12 05:40:55 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012/04/21 11:56:02 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2012/04/01 14:32:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010/11/12 04:39:37 | 000,000,000 | ---D | M] (Redirect Remover) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9} [2012/06/29 21:13:08 | 000,000,000 | ---D | M] (Wörterbuch Deutsch (de-DE), Hunspell-unterstützt) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\de_DE@dicts.j3e.de [2010/12/12 16:34:32 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\en-GB@dictionaries.addons.mozilla.org [2012/05/26 20:30:36 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\en-US@dictionaries.addons.mozilla.org [2011/11/11 23:30:41 | 000,000,000 | ---D | M] (Dictionnaire français «Réforme 1990») -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\fr-reforme1990@dictionaries.addons.mozilla.org [2010/11/12 04:48:56 | 000,000,000 | ---D | M] (KeyScrambler) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation [2011/03/16 06:10:12 | 000,000,000 | ---D | M] (Personas) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\personas@christopher.beard [2012/06/25 15:27:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/06/25 15:06:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012/07/12 07:24:19 | 000,525,390 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI [2012/07/11 01:06:27 | 000,061,228 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI [2012/01/21 13:52:58 | 000,138,614 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI [2012/06/21 13:31:33 | 000,109,964 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\ADBLOCKPOPUPS@JESSEHAKANEN.NET.XPI [2011/11/11 23:30:35 | 000,236,088 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\OPTIMIZEGOOGLE@OPTIMIZEGOOGLE.COM.XPI [2012/06/15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/06/15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2012/06/15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/06/15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2012/06/15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2012/06/15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2012/06/15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\pdf.dll CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\gears.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin O1 HOSTS File: ([2012/07/13 18:20:21 | 000,443,529 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 15235 more lines... O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181 O7 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FB FF FF 03 [binary data] O9 - Extra 'Tools' menuitem : &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289332900642 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C4C5D9D8-EF89-402D-AE7C-D249AB041AE4}: DhcpNameServer = 192.168.1.1 192.168.1.1 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Ma page d'accueil) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Colline verdoyante.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Colline verdoyante.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/10/26 15:39:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{58af6740-ff7d-11e0-b98e-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{58af6740-ff7d-11e0-b98e-806d6172696f}\Shell\AutoRun\command - "" = J:\arun.exe O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (aswBoot.exe /M:d7880c91) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: WmdmPmSp - File not found MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe - (Secunia) MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Sitecom 300N USB Wireless LAN Utility.lnk - C:\Program Files\SITECOM\300N USB Wireless LAN Utility\RtWLan.exe - (Realtek Semiconductor Corp.) MsConfig - StartUpFolder: C:^Documents and Settings^*******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia) MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.4.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia) MsConfig - StartUpFolder: C:^Documents and Settings^*****^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.4.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - () MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia) MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) MsConfig - StartUpReg: KernelFaultCheck - hkey= - key= - File not found MsConfig - StartUpReg: MGSysCtrl - hkey= - key= - C:\Program Files\System Control Manager\MGSysCtrl.exe (MSI) MsConfig - StartUpReg: ORAHSSSessionManager - hkey= - key= - C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe (France Telecom SA) MsConfig - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: UnlockerAssistant - hkey= - key= - C:\Program Files\Unlocker\UnlockerAssistant.exe () SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: nm - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) SafeBootNet: nm.sys - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Rendu VML (Vector Graphics Rendering) ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Liaison de données Dynamic HTML pour Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Création avancée ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Classes Java DirectAnimation ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {72AD53CC-CCC0-3757-8480-9EE176866A7C} - .NET Framework ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {9A394342-4A68-4EBA-85A6-55B559F4E700} - .NET Framework ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Planificateur de tâches ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate ActiveX: {F196AC50-7C95-42E1-9947-BDAB18BF3C8C} - .NET Framework ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE ActiveX: Microsoft Base Smart Card Crypto Provider Package - Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012/07/15 21:48:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\******\Recent [2012/07/15 21:43:56 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe [2012/07/13 18:26:50 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012/07/08 22:45:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Logs [2012/07/06 08:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Nouv [2012/07/05 21:42:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Nou [2012/07/02 18:02:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\DOSBox [2012/07/02 17:09:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Local Settings\Application Data\DOSBox [2012/07/02 17:05:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\DOSBox-0.74 [2012/07/02 16:37:39 | 000,000,000 | ---D | C] -- C:\DOS [2012/07/02 01:36:49 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF [2012/07/01 21:08:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Ma [2012/06/29 19:39:20 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2012/06/25 18:10:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\dwhelper [2012/06/16 01:48:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Application Data\PhotoFiltre [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/07/15 21:51:45 | 000,576,084 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat [2012/07/15 21:51:45 | 000,502,718 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/07/15 21:51:45 | 000,104,688 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat [2012/07/15 21:51:45 | 000,088,242 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/07/15 21:49:05 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/07/15 21:47:34 | 000,013,728 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/07/15 21:47:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/07/15 21:44:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe [2012/07/14 23:55:27 | 000,113,541 | ---- | M] () -- C:\Documents and Settings\******\Bureau\screen2.png [2012/07/13 18:20:21 | 000,443,529 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012/07/12 03:19:54 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\ Malwarebytes Anti-Malware .lnk [2012/07/11 01:10:07 | 000,196,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/07/09 21:40:27 | 000,003,121 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012/07/09 21:31:04 | 000,443,055 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120713-182021.backup [2012/07/09 21:30:09 | 000,443,055 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-213104.backup [2012/07/08 20:22:41 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\******\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/07/03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012/07/03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012/07/03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012/07/03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012/07/03 18:21:53 | 000,089,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012/07/03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012/07/03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012/07/03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012/07/03 18:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012/07/03 18:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/07/02 23:30:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\******\peerblock.dmp [2012/07/02 18:18:00 | 000,000,546 | ---- | M] () -- C:\WINDOWS\System32\autoexec2.nt [2012/07/01 21:18:39 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk [2012/06/29 19:46:06 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-213008.backup [2012/06/29 19:39:20 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2012/06/25 15:27:56 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2012/06/25 15:27:56 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Firefox.lnk [2012/06/25 14:59:59 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk [2012/06/25 14:59:58 | 000,001,668 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Thunderbird.lnk [2012/06/25 14:20:00 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120629-194606.backup [2012/06/25 14:19:30 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-142000.backup [2012/06/17 12:26:34 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-141930.backup [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/07/14 23:55:26 | 000,113,541 | ---- | C] () -- C:\Documents and Settings\******\Bureau\screen2.png [2012/07/09 21:32:15 | 000,000,318 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012/07/02 18:18:00 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\autoexec2.nt [2012/05/31 01:38:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\******\peerblock.dmp [2012/02/15 16:38:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011/12/12 21:20:53 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\******\Application Data\mainhst.zgh [2011/11/09 21:17:29 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2011/10/17 13:49:49 | 000,078,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV85.sys [2011/10/17 09:29:37 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2011/09/29 01:12:24 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll [2011/09/29 01:12:24 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll [2011/09/29 01:12:24 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll [2011/09/28 20:51:00 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2010/12/15 00:39:42 | 000,210,944 | ---- | C] () -- C:\Documents and Settings\******\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/12/01 15:13:49 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe [2010/12/01 15:13:21 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe [2010/11/10 06:02:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin [2010/11/10 06:01:56 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat [2010/11/10 06:01:55 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe [2010/11/10 06:01:55 | 000,224,342 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat [2010/11/10 06:01:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe [2010/11/10 06:01:55 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat [2010/11/10 03:55:43 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010/11/09 21:34:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2010/11/09 21:08:58 | 000,015,312 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat [2010/11/01 14:17:35 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2010/11/01 14:13:12 | 000,196,160 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/11/01 14:07:21 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\MGHwCtrl.dll [2010/11/01 14:07:21 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\MGFPCtrl.dll [2010/11/01 14:07:21 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\MGPwrShm.dll [2010/11/01 13:32:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2010/11/01 13:25:17 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat ========== LOP Check ========== [2010/11/22 03:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2010/11/10 06:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited [2012/06/29 19:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2011/12/15 02:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Beerowser [2010/11/11 00:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Canneverbe Limited [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DAEMON Tools Lite [2010/11/12 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DeviceDoctorSoftware [2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog [2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++ [2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org [2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera [2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre [2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy [2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki [2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent [2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius [2012/07/15 21:49:05 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > [2011/06/23 13:13:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe [2010/11/22 03:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2010/11/10 06:04:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI [2010/11/10 06:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited [2012/06/29 19:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2010/11/10 08:33:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2010/11/10 03:41:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee [2011/05/05 00:13:50 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft [2012/05/08 20:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mozilla [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2010/11/10 03:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun [2010/11/09 22:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage < %ALLUSERSPROFILE%\Application Data\*.exe /s > [2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AcrobatUpdater.exe [2012/01/03 09:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AdobeARM.exe [2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AdobeARMHelper.exe [2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\ReaderUpdater.exe [2012/07/12 03:19:05 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe < %APPDATA%\*. > [2011/03/25 12:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Adobe [2010/11/11 00:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ATI [2010/11/22 04:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Avira [2011/12/15 02:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Beerowser [2010/11/11 00:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Canneverbe Limited [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DAEMON Tools Lite [2010/11/12 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DeviceDoctorSoftware [2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog [2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter [2011/12/24 09:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Help [2010/11/10 02:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Identities [2012/07/15 21:24:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Macromedia [2010/11/11 00:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Malwarebytes [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Media Player Classic [2012/02/14 17:04:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\******\Application Data\Microsoft [2010/11/11 00:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Mozilla [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++ [2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org [2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera [2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre [2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy [2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki [2011/02/27 14:02:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sun [2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird [2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent [2012/06/25 20:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\vlc [2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius < %APPDATA%\*.exe /s > [2008/06/02 00:25:02 | 000,737,192 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation\installer\setup.exe < %SYSTEMDRIVE%\*.exe > [2008/04/11 08:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe < MD5 for: AGP440.SYS > [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys [2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys < MD5 for: ATAPI.SYS > [2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys [2004/08/05 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys < MD5 for: EVENTLOG.DLL > [2004/08/05 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=21E83876A6287F15538EF187D286FE11 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll [2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: NETLOGON.DLL > [2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\netlogon.dll [2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll [2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll [2004/08/05 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=FAF07FDCDE76000621A28D19F8E2E8EB -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll < MD5 for: SCECLI.DLL > [2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\scecli.dll [2004/08/05 14:00:00 | 000,186,368 | ---- | M] (Microsoft Corporation) MD5=DEC0397F35D027874804EC72979D03CC -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll < MD5 for: USER32.DLL > [2005/03/02 20:10:36 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=0DF75FB73F705B011630159A43D7C354 -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll [2007/03/08 17:50:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=4D88AAF39ADABFE45958EA1384E2C4FF -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll [2007/03/08 17:37:50 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=753354F594809A9B96F73999B435A533 -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll [2005/03/02 20:20:32 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=C34920EB988CE98910BD6B0417F334EB -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll [2004/08/05 14:00:00 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=E46FB493E3B33704F0715020CF52106B -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll [2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\ServicePackFiles\i386\user32.dll [2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\system32\user32.dll < MD5 for: USERINIT.EXE > [2004/08/05 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D6D65EA32B190401B57EDB6706F29669 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe [2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe [2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [2004/08/05 14:00:00 | 000,506,368 | ---- | M] (Microsoft Corporation) MD5=D2DE785AEAB0BB8CA4C14A8A199DBE4E -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe [2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys [2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2010/11/01 14:12:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav [2010/11/01 14:12:00 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2010/11/01 14:11:59 | 000,475,136 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < > < End of report > |
Themen zu Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter |
aswmbr, avast, datei, dateien, desktop, erste mal, folge, gelöscht, gmer, guard, infektion, infiziert, internet, neu, neustart, problem, programm, scan, screenshot, starten, systemwiederherstellung, virus, virustotal, win32, windows, windows xp, öffnet |