Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Browser stürzt ständig ab!

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 26.08.2009, 13:47   #1
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Hallo,

ich habe ein Problem und zwar denke ich habe ich mir iwas eingefangen, Virus oder Trojaner oder ähnliches und hoffe ihr könnt mir weiterhelfen!

Das Problem:
Alles funktioniert normal, AUßER die Internetbrowser: Sie stürzen immer wieder ab! Aber nicht bei allen Seiten! trojaner-board.de z.b. geht, bei google oder t-online.de stürzt der browser (egal ob firefox oder internetexplorer - beide aktuell) sofort ab!

kann mir hier jemand weiterhelfen? wäre unendlich dankbar, weil der internetbrowser für mich natürlich extrem wichtig ist!

Zur besseren hilfe hier ein HijackThis Log-File:

Zitat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:35:15, on 26.08.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Program files\P4G\BatteryLife.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Creative\SB Audigy\Volume Panel\VolPanlu.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.1852\swg.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DisableS3S4] c:\DisableS3S4.cmd
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SB Audigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [RunDLLEntry] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ADSM Service ADSMServiceAeLookupSvc (ADSMServiceAeLookupSvc) - Unknown owner - C:\Windows\TEMP\fcqmuiuqtn.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe

--
End of file - 8763 bytes


Ich wäre für eine schnelle Hilfe unendlich dankbar!

vielen dank schon mal im voraus!

Mit freundlichen Grüßen
King Pin

Alt 26.08.2009, 14:11   #2
Moritz009
 

Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Erstmal Hallo und .hallo.

Bitte klicke auf den Link in meiner Signatur, arbeite die Liste unter Punkt 2 ab und poste die logs hier. Liebe Grüße Moritz009
__________________

__________________

Alt 26.08.2009, 15:36   #3
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Hallo Moritz,

erstmal vielen dank für deine superschnelle Antwort!

Hab die komplette Anleitung unter Punkt 2 befolgt! Hier die loggs: (muss es leider in 4 beiträge teilen, da es viel zu lang ist)



Malwarebytes' Anti-Malware:

Zitat:
Malwarebytes' Anti-Malware 1.40
Datenbank Version: 2697
Windows 6.0.6001 Service Pack 1

26.08.2009 16:08:10
mbam-log-2009-08-26 (16-08-10).txt

Scan-Methode: Vollständiger Scan (C:\|D:\|F:\|G:\|)
Durchsuchte Objekte: 205506
Laufzeit: 33 minute(s), 2 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 7
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 2

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\TypeLib\{86676e13-d6d8-4652-9fcf-f2047f1fb000} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\kt_bho.KettleBho (Trojan.BHO) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\ProgramData\Partner\partner.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\ProgramData\Partner\partner.exe (Trojan.BHO) -> Quarantined and deleted successfully.
__________________

Alt 26.08.2009, 15:39   #4
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



rsit:


log: (der log ist sogar so lang, dass ich 3 teile draus machen muss)

der erste:

[quote]Logfile of random's system information tool 1.06 (written by random/random)
Run by *** at 2009-08-26 16:13:06
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 99 GB (65%) free of 153 GB
Total RAM: 3070 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:13:08, on 26.08.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Program files\P4G\BatteryLife.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Creative\SB Audigy\Volume Panel\VolPanlu.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\***\Desktop\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HijackThis\***.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.1852\swg.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SB Audigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [RunDLLEntry] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ADSM Service ADSMServiceAeLookupSvc (ADSMServiceAeLookupSvc) - Unknown owner - C:\Windows\TEMP\fcqmuiuqtn.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 8620 bytes

======Scheduled tasks folder======

C:\Windows\tasks\ASUS SmartLogon Console Sensor.job
C:\Windows\tasks\User_Feed_Synchronization-{89CD8418-7177-4EDD-9AE6-4A95672ED091}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll [2009-08-04 340848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL [2009-08-04 107896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-08-04 255600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.1852\swg.dll [2009-08-04 651248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll [2009-08-04 340848]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-08-04 255600]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
"P2Go_Menu"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-14 210216]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-05-08 13605408]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-05-08 92704]
"HControlUser"=C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [2008-08-18 98304]
"ATKOSD2"=C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [2009-03-04 8392704]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-05-06 7440928]
"VolPanel"=C:\Program Files\Creative\SB Audigy\Volume Panel\VolPanlu.exe [2008-12-30 237693]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"RunDLLEntry"=C:\Windows\system32\AmbRunE.dll [2009-02-26 14848]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMedia.exe [2008-08-19 159744]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2008-10-01 851968]
"ADSMTray"=C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [2008-04-01 266240]
"ASUS Camera ScreenSaver"=C:\Windows\AsScrProlog.exe [2009-08-04 47672]
"ASUS Screen Saver Protector"=C:\Windows\ASScrPro.exe [2009-08-04 33136]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-04 39408]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
FancyStart daemon.lnk - C:\Windows\Installer\{DC905847-D537-427F-BF91-47CC7ACCDE58}\_DF3A81D17C478A2A6C60A5.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b63ef241-808d-11de-be51-806e6f6e6963}]
shell\AutoRun\command - E:\Autorun.exe

Alt 26.08.2009, 15:43   #5
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



2. Teil:

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-08-26 16:13:06 ----D---- C:\rsit
2009-08-26 15:33:08 ----D---- C:\Users\***\AppData\Roaming\Malwarebytes
2009-08-26 15:33:02 ----D---- C:\ProgramData\Malwarebytes
2009-08-26 15:33:02 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-26 15:23:03 ----D---- C:\Program Files\CCleaner
2009-08-26 14:35:02 ----D---- C:\Program Files\Trend Micro
2009-08-26 12:57:01 ----A---- C:\Windows\system32\tzres.dll
2009-08-26 12:54:13 ----D---- C:\Program Files\Panda Security
2009-08-26 12:38:09 ----A---- C:\Windows\system32\occache.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\wininet.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\msfeeds.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\jsproxy.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\ieui.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\iesetup.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\iernonce.dll
2009-08-26 12:38:08 ----A---- C:\Windows\system32\iepeers.dll
2009-08-26 12:38:07 ----A---- C:\Windows\system32\urlmon.dll
2009-08-26 12:38:07 ----A---- C:\Windows\system32\msfeedssync.exe
2009-08-26 12:38:07 ----A---- C:\Windows\system32\ieUnatt.exe
2009-08-26 12:38:07 ----A---- C:\Windows\system32\iesysprep.dll
2009-08-26 12:38:07 ----A---- C:\Windows\system32\iertutil.dll
2009-08-26 12:38:07 ----A---- C:\Windows\system32\iedkcs32.dll
2009-08-26 12:38:07 ----A---- C:\Windows\system32\ie4uinit.exe
2009-08-26 12:38:06 ----A---- C:\Windows\system32\ieframe.dll
2009-08-26 12:38:05 ----A---- C:\Windows\system32\mshtml.dll
2009-08-26 12:37:18 ----A---- C:\Windows\system32\mshtmler.dll
2009-08-26 12:37:18 ----A---- C:\Windows\system32\mshtmled.dll
2009-08-26 12:37:18 ----A---- C:\Windows\system32\icardie.dll
2009-08-26 12:37:18 ----A---- C:\Windows\system32\admparse.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\msls31.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\licmgr10.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\inseng.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\imgutil.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\ieakeng.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\dxtrans.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\dxtmsft.dll
2009-08-26 12:37:17 ----A---- C:\Windows\system32\corpol.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-08-26 12:37:16 ----A---- C:\Windows\system32\wextract.exe
2009-08-26 12:37:16 ----A---- C:\Windows\system32\webcheck.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\pngfilt.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\mstime.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\msrating.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\ieakui.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\ieaksie.dll
2009-08-26 12:37:16 ----A---- C:\Windows\system32\advpack.dll
2009-08-26 12:37:15 ----A---- C:\Windows\system32\vbscript.dll
2009-08-26 12:37:15 ----A---- C:\Windows\system32\url.dll
2009-08-26 12:37:15 ----A---- C:\Windows\system32\jscript.dll
2009-08-26 12:37:15 ----A---- C:\Windows\system32\ieapfltr.dll
2009-08-26 12:37:14 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-08-26 12:37:14 ----A---- C:\Windows\system32\SetDepNx.exe
2009-08-26 12:37:14 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-08-26 12:37:14 ----A---- C:\Windows\system32\PDMSetup.exe
2009-08-26 12:37:14 ----A---- C:\Windows\system32\mshta.exe
2009-08-26 12:37:14 ----A---- C:\Windows\system32\iexpress.exe
2009-08-26 12:11:22 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-08-26 12:11:21 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-08-26 12:10:48 ----A---- C:\Windows\system32\MRT.INI
2009-08-25 18:43:38 ----D---- C:\Users\***\AppData\Roaming\Vso
2009-08-24 16:09:50 ----D---- C:\Users\***\AppData\Roaming\WinRAR
2009-08-24 16:09:21 ----D---- C:\Program Files\WinRAR
2009-08-24 15:43:02 ----A---- C:\Windows\system32\CmdLineExt.dll
2009-08-24 15:41:52 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-08-24 15:41:51 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-08-24 00:42:44 ----D---- C:\Users\***\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
2009-08-24 00:42:29 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-08-23 19:57:03 ----D---- C:\Program Files\QIP Infium
2009-08-23 19:40:46 ----D---- C:\Program Files\QIP
2009-08-23 13:51:55 ----D---- C:\Users\***\AppData\Roaming\Thunderbird
2009-08-23 13:51:38 ----D---- C:\Program Files\Mozilla Thunderbird
2009-08-23 03:01:40 ----SHD---- C:\System Volume Information
2009-08-22 21:41:37 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-08-22 21:41:37 ----A---- C:\Windows\system32\infocardapi.dll
2009-08-22 21:41:37 ----A---- C:\Windows\system32\icardres.dll
2009-08-22 21:41:37 ----A---- C:\Windows\system32\icardagt.exe
2009-08-22 21:41:36 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-08-22 21:41:35 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-08-22 21:41:34 ----A---- C:\Windows\system32\PresentationHost.exe
2009-08-22 21:37:22 ----A---- C:\Windows\system32\dfshim.dll
2009-08-22 21:37:19 ----A---- C:\Windows\system32\netfxperf.dll
2009-08-22 21:37:19 ----A---- C:\Windows\system32\mscoree.dll
2009-08-22 21:37:14 ----A---- C:\Windows\system32\mscorier.dll
2009-08-22 21:37:11 ----A---- C:\Windows\system32\mscories.dll
2009-08-22 21:12:17 ----D---- C:\ProgramData\ASUS
2009-08-22 21:07:44 ----A---- C:\Windows\ATKPF.ini
2009-08-22 20:14:32 ----A---- C:\Windows\system32\EncDec.dll
2009-08-22 20:14:31 ----A---- C:\Windows\system32\psisdecd.dll
2009-08-22 20:08:41 ----A---- C:\Windows\system32\kerberos.dll
2009-08-22 20:08:40 ----A---- C:\Windows\system32\wdigest.dll
2009-08-22 20:08:40 ----A---- C:\Windows\system32\schannel.dll
2009-08-22 20:08:40 ----A---- C:\Windows\system32\msv1_0.dll
2009-08-22 20:08:40 ----A---- C:\Windows\system32\lsasrv.dll
2009-08-22 20:08:39 ----A---- C:\Windows\system32\secur32.dll
2009-08-22 20:08:39 ----A---- C:\Windows\system32\lsass.exe
2009-08-22 20:06:33 ----A---- C:\Windows\system32\wmp.dll
2009-08-22 20:06:32 ----A---- C:\Windows\system32\wmpdxm.dll
2009-08-22 20:06:32 ----A---- C:\Windows\system32\spwmp.dll
2009-08-22 20:06:31 ----A---- C:\Windows\system32\wmploc.DLL
2009-08-22 20:06:31 ----A---- C:\Windows\system32\dxmasf.dll
2009-08-22 20:06:29 ----A---- C:\Windows\system32\avifil32.dll
2009-08-22 20:04:47 ----A---- C:\Windows\system32\t2embed.dll
2009-08-22 20:04:47 ----A---- C:\Windows\system32\fontsub.dll
2009-08-22 20:04:47 ----A---- C:\Windows\system32\dciman32.dll
2009-08-22 20:04:47 ----A---- C:\Windows\system32\atmfd.dll
2009-08-22 20:04:02 ----A---- C:\Windows\system32\atl.dll
2009-08-22 20:04:01 ----A---- C:\Windows\system32\wersvc.dll
2009-08-22 20:04:01 ----A---- C:\Windows\system32\Faultrep.dll
2009-08-22 20:04:00 ----A---- C:\Windows\system32\wkssvc.dll
2009-08-22 20:03:16 ----A---- C:\Windows\system32\mstscax.dll
2009-08-22 19:47:19 ----A---- C:\Windows\system32\wups2.dll
2009-08-22 19:47:19 ----A---- C:\Windows\system32\wucltux.dll
2009-08-22 19:47:19 ----A---- C:\Windows\system32\wuauclt.exe
2009-08-22 19:47:18 ----A---- C:\Windows\system32\wuaueng.dll
2009-08-22 19:47:11 ----A---- C:\Windows\system32\wups.dll
2009-08-22 19:47:11 ----A---- C:\Windows\system32\wudriver.dll
2009-08-22 19:47:11 ----A---- C:\Windows\system32\wuapi.dll
2009-08-22 19:47:10 ----A---- C:\Windows\system32\wuwebv.dll
2009-08-22 19:47:10 ----A---- C:\Windows\system32\wuapp.exe
2009-08-22 14:37:52 ----D---- C:\Users\Benny\AppData\Roaming\Adobe
2009-08-22 14:10:14 ----D---- C:\Program Files\ICQ6Toolbar
2009-08-22 14:10:12 ----D---- C:\ProgramData\ICQ
2009-08-22 14:08:30 ----D---- C:\Users\Benny\AppData\Roaming\ICQ
2009-08-22 14:08:12 ----D---- C:\Program Files\ICQ6.5
2009-08-22 13:51:49 ----D---- C:\Users\Benny\AppData\Roaming\Winamp
2009-08-22 13:51:49 ----D---- C:\Program Files\Winamp
2009-08-22 12:35:28 ----D---- C:\Users\Benny\AppData\Roaming\Mozilla
2009-08-22 12:35:19 ----D---- C:\Program Files\Mozilla Firefox
2009-08-22 12:21:57 ----D---- C:\Users\Benny\AppData\Roaming\Google
2009-08-22 12:19:19 ----D---- C:\Program Files\Symantec
2009-08-22 12:19:19 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-08-22 12:17:08 ----D---- C:\Users\Benny\AppData\Roaming\Macromedia
2009-08-22 12:16:44 ----D---- C:\Users\Benny\AppData\Roaming\Identities
2009-08-22 12:13:15 ----D---- C:\Program Files\Microsoft Silverlight
2009-08-22 12:13:00 ----D---- C:\Program Files\Microsoft Office Outlook Connector
2009-08-22 12:12:49 ----DC---- C:\Windows\system32\DRVSTORE
2009-08-22 12:12:02 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-08-22 12:11:58 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-08-22 12:11:15 ----D---- C:\Program Files\Microsoft
2009-08-22 12:10:59 ----D---- C:\Program Files\Windows Live SkyDrive
2009-08-22 12:10:42 ----D---- C:\Program Files\Windows Live
2009-08-22 12:09:37 ----D---- C:\Program Files\Common Files\Windows Live
2009-08-22 12:07:58 ----D---- C:\ProgramData\Adobe
2009-08-22 12:07:55 ----D---- C:\Program Files\Common Files\Adobe
2009-08-22 12:07:55 ----D---- C:\Program Files\Adobe
2009-08-22 12:05:26 ----A---- C:\Windows\system32\acovcnt.exe
2009-08-22 12:05:18 ----SD---- C:\Users\Benny\AppData\Roaming\Microsoft
2009-08-22 12:05:18 ----D---- C:\Users\Benny\AppData\Roaming\Media Center Programs
2009-08-22 12:02:23 ----SHD---- C:\ProgramData\Templates
2009-08-22 12:02:23 ----SHD---- C:\ProgramData\Start Menu
2009-08-22 12:02:23 ----SHD---- C:\ProgramData\Favorites
2009-08-22 12:02:23 ----SHD---- C:\ProgramData\Documents
2009-08-22 12:02:23 ----SHD---- C:\ProgramData\Desktop
2009-08-22 12:02:23 ----SHD---- C:\ProgramData\Application Data
2009-08-22 12:02:23 ----SHD---- C:\Documents and Settings
2009-08-04 04:12:25 ----A---- C:\Pass.txt
2009-08-04 03:21:21 ----A---- C:\devlist.txt
2009-08-04 03:13:09 ----HD---- C:\ASUS.SYS
2009-08-04 03:12:48 ----D---- C:\Program Files\Downloaded Installations
2009-08-04 03:05:58 ----A---- C:\Windows\ASScrPro.exe
2009-08-04 03:05:37 ----D---- C:\Windows\system32\Asus_Camera_ScreenSaver dir
2009-08-04 03:05:37 ----A---- C:\Windows\ASUS Camera ScreenSaver.exe
2009-08-04 03:05:37 ----A---- C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe
2009-08-04 03:05:37 ----A---- C:\Windows\AsScrProlog.exe
2009-08-04 03:05:36 ----D---- C:\Windows\system32\Macromed
2009-08-04 03:04:14 ----D---- C:\ADSM_PData_0150
2009-08-04 03:02:28 ----A---- C:\Windows\system32\ACEngSvr.exe
2009-08-04 03:00:45 ----HD---- C:\ASUS.DAT
2009-08-04 03:00:16 ----D---- C:\ProgramData\P4G
2009-08-04 03:00:16 ----D---- C:\Program Files\P4G
2009-08-04 02:58:51 ----D---- C:\Program Files\ATKGFNEX
2009-08-04 02:58:28 ----D---- C:\Program Files\Synaptics
2009-08-04 02:51:27 ----D---- C:\Windows\system32\nn-NO
2009-08-04 02:51:27 ----A---- C:\Windows\system32\S64CPA.exe
2009-08-04 02:51:27 ----A---- C:\Windows\system32\athihvui.dll
2009-08-04 02:51:26 ----A---- C:\Windows\system32\athihvs.dll
2009-08-04 02:51:20 ----D---- C:\Program Files\Atheros
2009-08-04 02:51:19 ----D---- C:\Program Files\Cisco
2009-08-04 02:51:16 ----D---- C:\ProgramData\Atheros
2009-08-04 02:49:11 ----A---- C:\Windows\system32\RtNicProp32.dll
2009-08-04 02:47:49 ----D---- C:\Windows\ITECIR
2009-08-04 02:47:49 ----A---- C:\Windows\system32\CIRCoInst.dll
2009-08-04 02:43:29 ----A---- C:\Windows\system32\BtwRSupport.dll
2009-08-04 02:43:26 ----D---- C:\Windows\system32\es-MX
2009-08-04 02:43:26 ----D---- C:\Windows\system32\es-AR
2009-08-04 02:43:25 ----D---- C:\Program Files\WIDCOMM
2009-08-04 02:42:06 ----D---- C:\Program Files\Wireless Console 2
2009-08-04 02:39:58 ----D---- C:\Program Files\Common Files\Creative
2009-08-04 02:39:56 ----HD---- C:\Program Files\Creative Installation Information
2009-08-04 02:39:41 ----A---- C:\Windows\system32\snymsico.dll
2009-08-04 02:39:41 ----A---- C:\Windows\system32\rixdicon.dll
2009-08-04 02:39:30 ----A---- C:\Windows\Updreg.EXE
2009-08-04 02:39:30 ----A---- C:\Windows\system32\ResDefE.exe
2009-08-04 02:39:30 ----A---- C:\Windows\system32\cfgfx.ini
2009-08-04 02:39:30 ----A---- C:\Windows\system32\cfgChain.exe
2009-08-04 02:39:30 ----A---- C:\Windows\system32\AmbRunE.dll
2009-08-04 02:39:30 ----A---- C:\Windows\FF05_Render_Spk_Hp.ini
2009-08-04 02:39:30 ----A---- C:\Windows\FF05_not_Spk_Hp.ini
2009-08-04 02:39:28 ----A---- C:\Windows\system32\wrap_oal.dll
2009-08-04 02:39:28 ----A---- C:\Windows\system32\Sens_oal.dll
2009-08-04 02:39:28 ----A---- C:\Windows\system32\OpenAL32.dll
2009-08-04 02:39:23 ----A---- C:\Windows\Ctregrun.exe
2009-08-04 02:39:15 ----D---- C:\Program Files\Common Files\Creative Labs Shared
2009-08-04 02:38:43 ----D---- C:\Program Files\Creative
2009-08-04 02:38:38 ----D---- C:\ProgramData\Creative Labs
2009-08-04 02:38:38 ----D---- C:\ProgramData\Creative
2009-08-04 02:38:31 ----A---- C:\Windows\system32\CmdRtr.DLL
2009-08-04 02:38:31 ----A---- C:\Windows\system32\APOMngr.DLL
2009-08-04 02:37:58 ----D---- C:\Windows\system32\RTCOM
2009-08-04 02:37:32 ----A---- C:\Windows\DIFxAPI.dll
2009-08-04 02:37:31 ----A---- C:\Windows\system32\WavesLib.dll
2009-08-04 02:37:31 ----A---- C:\Windows\system32\SRSWOW.dll
2009-08-04 02:37:31 ----A---- C:\Windows\system32\SRSTSXT.dll
2009-08-04 02:37:31 ----A---- C:\Windows\system32\SRSTSHD.dll
2009-08-04 02:37:31 ----A---- C:\Windows\system32\SRSHP360.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\RtkPgExt.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\RtkCoInst.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\RtkApoApi.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\RtkAPO.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\RP3DHT32.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\RP3DAA32.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\MBWrp32.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\MBppld32.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\MBPPCn32.dll
2009-08-04 02:37:30 ----A---- C:\Windows\system32\MBAPO32.dll
2009-08-04 02:37:29 ----HD---- C:\Program Files\Temp
2009-08-04 02:37:29 ----D---- C:\Program Files\Realtek
2009-08-04 02:37:29 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2009-08-04 02:37:29 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2009-08-04 02:37:29 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2009-08-04 02:37:29 ----A---- C:\Windows\system32\FMAPO.dll
2009-08-04 02:37:29 ----A---- C:\Windows\system32\AERTARen.dll
2009-08-04 02:37:29 ----A---- C:\Windows\system32\AERTACap.dll
2009-08-04 02:37:29 ----A---- C:\Windows\RtlExUpd.dll
2009-08-04 02:34:02 ----D---- C:\Windows\asfix
2009-08-04 02:33:45 ----A---- C:\Windows\system32\localspl.dll
2009-08-04 02:32:40 ----A---- C:\Windows\system32\rpcrt4.dll
2009-08-04 02:30:43 ----D---- C:\ProgramData\NVIDIA
2009-08-04 02:30:32 ----A---- C:\Windows\system32\winhttp.dll
2009-08-04 02:30:11 ----A---- C:\Windows\system32\kernel32.dll
2009-08-04 02:30:10 ----A---- C:\Windows\system32\apilogen.dll
2009-08-04 02:30:10 ----A---- C:\Windows\system32\amxread.dll
2009-08-04 02:29:46 ----A---- C:\Windows\system32\rpcss.dll
2009-08-04 02:29:45 ----A---- C:\Windows\system32\sdohlp.dll
2009-08-04 02:29:45 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-08-04 02:29:45 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-08-04 02:29:45 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-08-04 02:29:45 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-08-04 02:29:45 ----A---- C:\Windows\system32\iasrecst.dll
2009-08-04 02:29:45 ----A---- C:\Windows\system32\iashost.exe
2009-08-04 02:29:45 ----A---- C:\Windows\system32\iasdatastore.dll
2009-08-04 02:29:45 ----A---- C:\Windows\system32\iasads.dll
2009-08-04 02:29:18 ----A---- C:\Windows\system32\xolehlp.dll
2009-08-04 02:29:18 ----A---- C:\Windows\system32\msdtcprx.dll
2009-08-04 02:25:03 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-08-04 02:25:03 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-08-04 02:25:03 ----A---- C:\Windows\system32\mf.dll
2009-08-04 02:25:03 ----A---- C:\Windows\system32\logagent.exe
2009-08-04 02:24:23 ----D---- C:\Program Files\ASUS
2009-08-04 02:24:09 ----A---- C:\Windows\system32\gdi32.dll
2009-08-04 02:23:47 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-08-04 02:23:47 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-08-04 02:23:46 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-08-04 02:21:40 ----A---- C:\Windows\system32\shell32.dll
2009-08-04 02:21:10 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-08-04 02:20:52 ----A---- C:\Windows\explorer.exe
2009-08-04 02:20:32 ----A---- C:\Windows\system32\connect.dll
2009-08-04 02:20:14 ----A---- C:\Windows\system32\hidserv.dll
2009-08-04 02:20:14 ----A---- C:\Windows\system32\hid.dll
2009-08-04 02:20:13 ----A---- C:\Windows\system32\netapi32.dll
2009-08-04 02:19:38 ----A---- C:\Windows\system32\msxml3.dll
2009-08-04 02:19:13 ----A---- C:\Windows\system32\msxml6.dll
2009-08-04 02:18:55 ----A---- C:\Windows\system32\win32spl.dll
2009-08-04 02:17:33 ----A---- C:\Windows\system32\fdBth.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\wshbth.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\WscEapPr.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\fundisc.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\fsquirt.exe
2009-08-04 02:17:32 ----A---- C:\Windows\system32\fdProxy.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-08-04 02:17:32 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\DevicePairing.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\bthudtask.exe
2009-08-04 02:17:32 ----A---- C:\Windows\system32\bthserv.dll
2009-08-04 02:17:32 ----A---- C:\Windows\system32\bthci.dll
2009-08-04 02:15:35 ----A---- C:\Windows\system32\wmpeffects.dll
2009-08-04 02:14:55 ----A---- C:\Windows\system32\nvcpluir.dll
2009-08-04 02:14:55 ----A---- C:\Windows\system32\nvcplui.exe
2009-08-04 02:14:55 ----A---- C:\Windows\system32\emdmgmt.dll
2009-08-04 02:14:55 ----A---- C:\Windows\system32\cdd.dll
2009-08-04 02:14:54 ----A---- C:\Windows\system32\dataclen.dll
2009-08-04 02:14:01 ----A---- C:\Windows\system32\NVUNINST.EXE
2009-08-04 02:13:07 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-08-04 02:12:11 ----A---- C:\Windows\system32\inetcomm.dll
2009-08-04 02:11:56 ----A---- C:\Windows\system32\es.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\tquery.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-08-04 02:11:33 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-08-04 02:11:33 ----A---- C:\Windows\system32\msstrc.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\mssprxy.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\mssph.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\mssitlb.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\msshooks.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\msscntrs.dll
2009-08-04 02:11:33 ----A---- C:\Windows\system32\msscb.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\wsepno.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\thawbrkr.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-08-04 02:11:32 ----A---- C:\Windows\system32\propdefs.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\offfilt.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\mssvp.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\mssrch.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\mssphtb.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\chtbrkr.dll
2009-08-04 02:11:32 ----A---- C:\Windows\system32\chsbrkr.dll
2009-08-04 02:11:31 ----A---- C:\Windows\system32\xmlfilter.dll
2009-08-04 02:11:31 ----A---- C:\Windows\system32\rtffilt.dll
2009-08-04 02:11:31 ----A---- C:\Windows\system32\nlhtml.dll
2009-08-04 02:11:31 ----A---- C:\Windows\system32\mimefilt.dll
2009-08-04 02:11:31 ----A---- C:\Windows\system32\korwbrkr.dll
2009-08-04 02:11:30 ----A---- C:\Windows\system32\srchadmin.dll
2009-08-04 02:11:30 ----A---- C:\Windows\system32\propsys.dll
2009-08-04 02:11:30 ----A---- C:\Windows\system32\msshsq.dll
2009-08-04 02:10:51 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-08-04 02:10:51 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-08-04 02:10:51 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-08-04 02:10:25 ----D---- C:\Program Files\Intel
2009-08-04 02:10:25 ----A---- C:\Windows\system32\CSVer.dll
2009-08-04 02:10:16 ----D---- C:\Intel
2009-08-04 02:10:02 ----A---- C:\Windows\system32\pacerprf.dll
2009-08-04 02:09:46 ----A---- C:\Windows\system32\wshext.dll
2009-08-04 02:09:46 ----A---- C:\Windows\system32\wscript.exe
2009-08-04 02:09:46 ----A---- C:\Windows\system32\scrrun.dll
2009-08-04 02:09:46 ----A---- C:\Windows\system32\scrobj.dll
2009-08-04 02:09:46 ----A---- C:\Windows\system32\cscript.exe
2009-08-04 02:08:36 ----A---- C:\Windows\system32\RacEngn.dll
2009-08-04 02:08:25 ----A---- C:\Windows\system32\quartz.dll
2009-08-04 02:06:27 ----A---- C:\Windows\system32\gameux.dll
2009-08-04 02:04:44 ----D---- C:\Windows\Users
2009-08-04 02:04:39 ----A---- C:\Windows\system32\winresume.exe
2009-08-04 02:04:39 ----A---- C:\Windows\system32\winload.exe
2009-08-04 02:04:39 ----A---- C:\Windows\system32\srdelayed.exe
2009-08-04 02:04:39 ----A---- C:\Windows\system32\srcore.dll
2009-08-04 02:04:39 ----A---- C:\Windows\system32\srclient.dll
2009-08-04 02:04:39 ----A---- C:\Windows\system32\setbcdlocale.dll
2009-08-04 02:04:39 ----A---- C:\Windows\system32\rstrui.exe
2009-08-04 02:04:39 ----A---- C:\Windows\system32\kd1394.dll
2009-08-04 02:04:39 ----A---- C:\Windows\system32\kbd106n.dll
2009-08-04 02:04:39 ----A---- C:\Windows\system32\ci.dll
2009-08-04 02:03:54 ----A---- C:\igoogle_log.txt
2009-08-04 02:03:48 ----A---- C:\inject.log.txt
2009-08-04 02:02:41 ----D---- C:\ProgramData\Google
2009-08-04 02:02:39 ----D---- C:\ProgramData\Partner
2009-08-04 02:02:36 ----D---- C:\Program Files\Common Files\PX Storage Engine
2009-08-04 02:02:34 ----D---- C:\Windows\system32\IOSUBSYS
2009-08-04 02:02:31 ----D---- C:\Program Files\Google
2009-08-04 02:01:31 ----A---- C:\Windows\csup.txt
2009-08-04 02:01:30 ----A---- C:\faclog.txt
2009-08-04 01:59:46 ----D---- C:\ProgramData\Symantec
2009-08-04 01:59:31 ----A---- C:\v55.txt
2009-08-04 01:59:26 ----D---- C:\ProgramData\Norton
2009-08-04 01:59:26 ----D---- C:\Program Files\Norton Internet Security
2009-08-04 01:58:57 ----D---- C:\ProgramData\NortonInstaller
2009-08-04 01:58:57 ----D---- C:\Program Files\NortonInstaller
2009-08-04 01:58:45 ----D---- C:\ProgramData\CyberLink
2009-08-04 01:57:55 ----D---- C:\Program Files\Common Files\LightScribe
2009-08-04 01:57:47 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-04 01:57:47 ----A---- C:\Windows\system32\msvcr71.dll
2009-08-04 01:57:47 ----A---- C:\Windows\system32\msvcp71.dll
2009-08-04 01:57:47 ----A---- C:\Windows\system32\MFC71u.dll
2009-08-04 01:57:47 ----A---- C:\Windows\system32\MFC71.dll
2009-08-04 01:57:40 ----D---- C:\Program Files\Common Files\InstallShield
2009-08-04 01:57:39 ----D---- C:\Program Files\CyberLink
2009-08-04 01:57:36 ----D---- C:\ProgramData\Temp
2009-08-04 01:52:58 ----D---- C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}
2009-08-04 01:52:56 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2009-08-04 01:52:30 ----A---- C:\SumHidd.txt
2009-08-04 01:51:59 ----D---- C:\Program Files\Microsoft Works
2009-08-04 01:51:44 ----D---- C:\Program Files\Microsoft Visual Studio
2009-08-04 01:51:44 ----D---- C:\Program Files\Common Files\DESIGNER
2009-08-04 01:51:37 ----A---- C:\SumOS.txt
2009-08-04 01:51:29 ----D---- C:\Windows\PCHEALTH
2009-08-04 01:51:29 ----D---- C:\Program Files\Microsoft.NET
2009-08-04 01:46:41 ----D---- C:\ProgramData\Microsoft Help
2009-08-04 01:46:41 ----D---- C:\Program Files\Microsoft Office
2009-08-04 01:46:34 ----SHD---- C:\Windows\Installer
2009-08-04 01:45:53 ----RHD---- C:\MSOCache
2009-08-04 01:40:05 ----D---- C:\Windows\SoftwareDistribute


Alt 26.08.2009, 15:45   #6
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



3. Teil log:


======List of files/folders modified in the last 1 months======

2009-08-26 16:12:08 ----D---- C:\Windows\Temp
2009-08-26 16:11:06 ----D---- C:\Windows\Tasks
2009-08-26 16:10:49 ----RD---- C:\Program Files
2009-08-26 16:10:49 ----D---- C:\Windows\system32\drivers
2009-08-26 15:33:02 ----HD---- C:\ProgramData
2009-08-26 15:25:11 ----D---- C:\Windows\Debug
2009-08-26 15:25:11 ----D---- C:\Windows
2009-08-26 14:08:41 ----D---- C:\Windows\System32
2009-08-26 14:08:41 ----D---- C:\Windows\inf
2009-08-26 14:08:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-08-26 13:47:09 ----D---- C:\Windows\Microsoft.NET
2009-08-26 13:15:53 ----D---- C:\Windows\rescache
2009-08-26 12:57:27 ----D---- C:\Windows\winsxs
2009-08-26 12:57:27 ----D---- C:\Windows\system32\de-DE
2009-08-26 12:57:24 ----D---- C:\Windows\system32\catroot
2009-08-26 12:56:55 ----D---- C:\Windows\AppPatch
2009-08-26 12:40:10 ----D---- C:\Windows\system32\catroot2
2009-08-26 12:40:00 ----D---- C:\Program Files\Internet Explorer
2009-08-26 12:39:59 ----D---- C:\Windows\system32\migration
2009-08-26 12:39:56 ----D---- C:\Windows\system32\en-US
2009-08-26 12:39:56 ----D---- C:\Windows\PolicyDefinitions
2009-08-26 00:47:08 ----RSD---- C:\Windows\assembly
2009-08-25 18:57:09 ----D---- C:\Windows\system32\nl-NL
2009-08-24 15:33:46 ----D---- C:\Windows\Logs
2009-08-24 00:30:21 ----D---- C:\Windows\system32\WDI
2009-08-23 22:32:24 ----D---- C:\Windows\Prefetch
2009-08-23 20:03:49 ----D---- C:\Windows\system32\Tasks
2009-08-23 03:06:12 ----D---- C:\Windows\system32\it-IT
2009-08-23 03:06:12 ----D---- C:\Windows\system32\fr-FR
2009-08-23 03:06:11 ----D---- C:\Windows\ehome
2009-08-23 03:06:04 ----D---- C:\Program Files\Windows Media Player
2009-08-23 03:05:40 ----D---- C:\Windows\system32\XPSViewer
2009-08-23 03:05:40 ----D---- C:\Windows\system32\wbem
2009-08-22 22:00:03 ----D---- C:\Program Files\Common Files\microsoft shared
2009-08-22 21:54:23 ----RSD---- C:\Windows\Fonts
2009-08-22 21:53:02 ----A---- C:\Windows\win.ini
2009-08-22 21:37:02 ----D---- C:\Program Files\Windows Mail
2009-08-22 12:27:47 ----SD---- C:\ProgramData\Microsoft
2009-08-22 12:23:35 ----D---- C:\Windows\system32\NDF
2009-08-22 12:19:19 ----D---- C:\Program Files\Common Files
2009-08-22 12:17:02 ----SHD---- C:\$RECYCLE.BIN
2009-08-22 12:13:01 ----D---- C:\Program Files\Common Files\System
2009-08-22 12:05:18 ----RD---- C:\Users
2009-08-04 02:51:27 ----D---- C:\Windows\system32\zh-TW
2009-08-04 02:51:27 ----D---- C:\Windows\system32\zh-CN
2009-08-04 02:51:27 ----D---- C:\Windows\system32\tr-TR
2009-08-04 02:51:27 ----D---- C:\Windows\system32\sv-SE
2009-08-04 02:51:27 ----D---- C:\Windows\system32\ru-RU
2009-08-04 02:51:27 ----D---- C:\Windows\system32\pt-PT
2009-08-04 02:51:27 ----D---- C:\Windows\system32\pl-PL
2009-08-04 02:51:27 ----D---- C:\Windows\system32\ko-KR
2009-08-04 02:51:27 ----D---- C:\Windows\system32\ja-JP
2009-08-04 02:51:27 ----D---- C:\Windows\system32\hu-HU
2009-08-04 02:51:27 ----D---- C:\Windows\system32\fi-FI
2009-08-04 02:51:27 ----D---- C:\Windows\system32\es-ES
2009-08-04 02:51:27 ----D---- C:\Windows\system32\el-GR
2009-08-04 02:51:27 ----D---- C:\Windows\system32\da-DK
2009-08-04 02:51:27 ----D---- C:\Windows\system32\cs-CZ
2009-08-04 02:43:29 ----SD---- C:\Windows\system32\Microsoft
2009-08-04 02:43:27 ----D---- C:\Windows\system32\pt-BR
2009-08-04 02:43:27 ----D---- C:\Windows\system32\nb-NO
2009-08-04 02:30:25 ----D---- C:\Windows\system32\manifeststore
2009-08-04 02:27:18 ----D---- C:\Windows\system32\oobe
2009-08-04 02:27:17 ----D---- C:\Windows\system32\WCN
2009-08-04 02:27:17 ----D---- C:\Windows\system32\DriverStore
2009-08-04 02:14:48 ----D---- C:\Windows\Help
2009-08-04 02:04:48 ----D---- C:\Windows\system32\Boot
2009-08-04 01:51:41 ----D---- C:\Windows\ShellNew
2009-08-04 01:43:36 ----D---- C:\Windows\system32\restore
2009-08-03 12:22:50 ----D---- C:\Windows\system32\sysprep
2009-08-03 12:22:50 ----D---- C:\Windows\Panther
2009-07-29 17:49:16 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BHDrvx86;Symantec Heuristics Driver; \??\C:\Windows\system32\drivers\NIS\1000000.07D\BHDrvx86.sys [2009-08-04 254512]
R1 ccHP;Symantec Hash Provider; \??\C:\Windows\system32\drivers\NIS\1000000.07D\ccHPx86.sys [2009-08-04 362544]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2009-08-21 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090810.001\IDSvix86.sys [2009-07-12 293424]
R1 SRTSPX;SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [2009-08-04 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-08-04 25136]
R1 SYMTDI;SYMTDI; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMTDI.SYS [2009-08-04 198192]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2008-06-25 47104]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-07-29 919552]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-04-17 23040]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-17 30208]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-07-10 81960]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2008-05-14 100392]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2008-05-14 17320]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-08-22 101936]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-05-04 2365792]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-12-19 54784]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-06-03 15928]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-05-08 7551200]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-04-17 149504]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-08-07 124928]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-08-11 1752704]
R3 SYMDNS;SYMDNS; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS [2009-08-04 12976]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-08-22 124464]
R3 SYMFW;SYMFW; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMFW.SYS [2009-08-04 89904]
R3 SYMNDISV;SYMNDISV; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMNDISV.SYS [2009-08-04 40496]
R3 SYMREDRV;SYMREDRV; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS [2009-08-04 24752]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-17 507904]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090825.032\NAVENG.SYS [2009-08-25 84912]
S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090825.032\NAVEX15.SYS [2009-08-25 1323568]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 SRTSP;SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [2009-08-04 305712]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R2 ASLDRService;ASLDR Service; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [2008-08-14 100920]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-07-30 522792]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-12-29 307200]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 Norton Internet Security;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [2009-08-04 115560]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-05-08 203296]
S2 ADSMServiceAeLookupSvc;ADSM Service ADSMServiceAeLookupSvc; C:\Windows\TEMP\fcqmuiuqtn.exe service []
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-08-04 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-08-04 79360]
S3 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-04 156656]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Alt 26.08.2009, 15:47   #7
Moritz009
 

Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



EDIT: Mach das erstmal zu ende mit der info.txt
Moritz009
__________________
Grüße,
Moritz

Trojaner-Board Spendenkonto

Alt 26.08.2009, 15:49   #8
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



info: (Teil 1 von 2)




info.txt logfile of random's system information tool 1.06 2009-08-26 16:13:10

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12321490-F573-4815-B6CC-7ABEF18C9AC4}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12321490-F573-4815-B6CC-7ABEF18C9AC4}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAEF329E-F353-46C9-933D-24A571986093}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAEF329E-F353-46C9-933D-24A571986093}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC406C89-7668-46AE-8EFE-75D199C055AB}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC406C89-7668-46AE-8EFE-75D199C055AB}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3455F74-9C96-49F3-9B77-11BB559E513D}\SETUP.EXE"
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x9 /remove
2007 Microsoft Office system-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\UninstFl.exe -q
Adobe Reader 9.0.1 - Deutsch-->MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A90100000001}
ASUS Data Security Manager-->C:\Program Files\InstallShield Installation Information\{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}\SETUP.exe -runfromtemp -l0x0009 -removeonly
ASUS FancyStart-->MsiExec.exe /I{DC905847-D537-427F-BF91-47CC7ACCDE58}
ASUS LifeFrame3-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Live Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\setup.exe" -l0x9
ASUS Power4Gear Hybrid-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS SmartLogon-->MsiExec.exe /I{64452561-169F-4A36-A2FF-B5E118EC65F5}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /I{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS Virtual Camera-->MsiExec.exe /I{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
Asus_Camera_ScreenSaver-->"C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe"
Atheros Client Installation Program-->C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\SETUP.exe -runfromtemp -l0x0009 -removeonly
ATK Generic Function Service-->C:\Program Files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Hotkey-->MsiExec.exe /I{7C05592D-424B-46CB-B505-E0013E8E75C9}
ATK Media-->MsiExec.exe /I{D1E5870E-E3E5-4475-98A6-ADD614524ADF}
ATKOSD2-->MsiExec.exe /I{3B05F2FB-745B-4012-ADF2-439F36B2E70B}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Cisco EAP-FAST Module-->MsiExec.exe /I{415B2719-AD3A-4944-B404-C472DB6085B3}
Cisco LEAP Module-->MsiExec.exe /I{83770D14-21B9-44B3-8689-F7B523F94560}
Cisco PEAP Module-->MsiExec.exe /I{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\setup.exe" -l0x9 /remove
CyberLink LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" -uninstall
CyberLink Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
Die Schlacht um Mittelerde™ II-->D:\Games\Die Schlacht um Mittelerde II\EAUninstall.exe
Express Gate-->MsiExec.exe /X{865CD808-6D31-4269-9D36-693CFE75D26A}
FUSSBALL MANAGER 09-->D:\Games\EA SPORTS\FUSSBALL MANAGER 09\eauninstall.exe
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_D370CDE96771667E.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
ICQ6.5-->"C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
ITECIR-->C:\Program Files\InstallShield Installation Information\{40580068-9B10-40B5-9548-536CE88AB23C}\SETUP.exe -runfromtemp -l0x0009 -removeonly
Junk Mail filter update-->MsiExec.exe /I{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}
LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - deu\setup.exe
Microsoft .NET Framework 3.5 Language Pack SP1 - deu-->MsiExec.exe /I{052FDD78-A6EA-3187-8386-C82F4CA3A929}
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0407-0000-0000000FF1CE} /uninstall {9BD40163-B95D-4B07-8991-0AB775B6D88B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0407-0000-0000000FF1CE} /uninstall {26454C26-D259-4543-AA60-3189E09C5F76}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0410-0000-0000000FF1CE} /uninstall {0A75DA12-55CB-4DE5-8B6A-74D97847204E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0413-0000-0000000FF1CE} /uninstall {89C8E56A-90D8-4598-B0E6-EB28F6270E07}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access MUI (Dutch) 2007-->MsiExec.exe /X{90120000-0015-0413-0000-0000000FF1CE}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Access MUI (German) 2007-->MsiExec.exe /X{90120000-0015-0407-0000-0000000FF1CE}
Microsoft Office Access MUI (Italian) 2007-->MsiExec.exe /X{90120000-0015-0410-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel 2007 Help - Aggiornamento (KB963678)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {9F57BDED-B51B-4D2F-B360-5B4EFAAF0F1A}
Microsoft Office Excel MUI (Dutch) 2007-->MsiExec.exe /X{90120000-0016-0413-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (German) 2007-->MsiExec.exe /X{90120000-0016-0407-0000-0000000FF1CE}
Microsoft Office Excel MUI (Italian) 2007-->MsiExec.exe /X{90120000-0016-0410-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Outlook 2007 Help - Aggiornamento (KB963677)-->msiexec /package {90120000-001A-0410-0000-0000000FF1CE} /uninstall {2278E02A-AB15-4BF7-B2B4-5C0EEB4B7EEB}
Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-0407-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Dutch) 2007-->MsiExec.exe /X{90120000-001A-0413-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (German) 2007-->MsiExec.exe /X{90120000-001A-0407-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Italian) 2007-->MsiExec.exe /X{90120000-001A-0410-0000-0000000FF1CE}
Microsoft Office Powerpoint 2007 Help - Aggiornamento (KB963669)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {C76C02F1-B07F-4974-876A-A18DEC9887C8}
Microsoft Office PowerPoint MUI (Dutch) 2007-->MsiExec.exe /X{90120000-0018-0413-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (German) 2007-->MsiExec.exe /X{90120000-0018-0407-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Italian) 2007-->MsiExec.exe /X{90120000-0018-0410-0000-0000000FF1CE}
Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Italian) 2007-->MsiExec.exe /X{90120000-001F-0410-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (Dutch) 2007-->MsiExec.exe /X{90120000-002C-0413-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Proofing (German) 2007-->MsiExec.exe /X{90120000-002C-0407-0000-0000000FF1CE}
Microsoft Office Proofing (Italian) 2007-->MsiExec.exe /X{90120000-002C-0410-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0410-0000-0000000FF1CE} /uninstall {322296D4-1EAE-4030-9FBC-D2787EB25FA2}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Publisher MUI (Dutch) 2007-->MsiExec.exe /X{90120000-0019-0413-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (German) 2007-->MsiExec.exe /X{90120000-0019-0407-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Italian) 2007-->MsiExec.exe /X{90120000-0019-0410-0000-0000000FF1CE}
Microsoft Office Shared MUI (Dutch) 2007-->MsiExec.exe /X{90120000-006E-0413-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (German) 2007-->MsiExec.exe /X{90120000-006E-0407-0000-0000000FF1CE}
Microsoft Office Shared MUI (Italian) 2007-->MsiExec.exe /X{90120000-006E-0410-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}

Alt 26.08.2009, 15:50   #9
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



so wurden jetzt sogar doch 6 teile!


Hier der 2 Teil vom info:


Microsoft Office Word 2007 Help - Aggiornamento (KB963665)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {E5B82DB3-DD7D-4C45-BC5E-09864B26F9BC}
Microsoft Office Word MUI (Dutch) 2007-->MsiExec.exe /X{90120000-001B-0413-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (German) 2007-->MsiExec.exe /X{90120000-001B-0407-0000-0000000FF1CE}
Microsoft Office Word MUI (Italian) 2007-->MsiExec.exe /X{90120000-001B-0410-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
Mozilla Firefox (3.5.2)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.23)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Norton Internet Security-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\16.0.0.125\InstStub.exe /X
Norton Internet Security-->MsiExec.exe /I{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\SETUP.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.exe" -removeonly
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.03-->"C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\SETUP.EXE" -runfromtemp -l0x0009 anything -removeonly
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Sound Blaster Audigy HD Asus-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{38F8D823-008D-4E5A-BBCE-867A86C2BF2B}\setup.exe" -l0x9 /remove
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office Access 2007 Help (KB963663)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}
Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
Update for Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {0451F231-E3E3-4943-AB9F-58EB96171784}
Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
Update for Microsoft Office Publisher 2007 Help (KB963667)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2E40DE55-B289-4C8B-8901-5D369B16814F}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
Update for Outlook 2007 Junk Email Filter (kb972691)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {AA020E6E-E2FB-45EF-B732-2400E2296742}
Update für Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0407-0000-0000000FF1CE} /uninstall {BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}
Update für Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-0407-0000-0000000FF1CE} /uninstall {F6828576-6F79-470D-AB50-69D1BBADBD30}
Update für Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0407-0000-0000000FF1CE} /uninstall {EA160DA3-E9B5-4D03-A518-21D306665B96}
Update für Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0407-0000-0000000FF1CE} /uninstall {38472199-D7B6-4833-A949-10E4EE6365A1}
Update voor Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0413-0000-0000000FF1CE} /uninstall {5CF7002F-6F49-4482-9564-5614FBE560FA}
Update voor Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0413-0000-0000000FF1CE} /uninstall {15D84E79-1ED7-42C5-B2FD-745C3FBDDDC5}
Update voor Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0413-0000-0000000FF1CE} /uninstall {A66AE6A1-8D8C-4102-BC18-38CBDE40F809}
USB 2.0 2.0M UVC WebCam-->C:\Windows\Uninstuxga.bat
WIDCOMM Bluetooth Software-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Anmelde-Assistent-->MsiExec.exe /I{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}
Windows Live Call-->MsiExec.exe /I{835686C5-8650-49EB-8CA0-4528B4035495}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{DF5F687F-8018-4542-9F98-7084E9022917}
Windows Live Family Safety-->MsiExec.exe /X{3A608351-5980-4A47-AE08-3742C55B4016}
Windows Live Fotogalerie-->MsiExec.exe /X{6B96DADA-1A27-4A04-8CB2-CC45168D05FA}
Windows Live Mail-->MsiExec.exe /I{5A166C0B-9557-4364-A057-F946D674E6AC}
Windows Live Messenger-->MsiExec.exe /X{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}
Windows Live Movie Maker-Betaversion-->MsiExec.exe /X{DC35EF73-C7BD-4452-A793-4269990E1EA3}
Windows Live Sync-->MsiExec.exe /X{8C1E2925-14F8-45AA-B999-1E2A74BF5607}
Windows Live Writer-->MsiExec.exe /X{81821BF8-DA20-4F8C-AA87-F70A274828D4}
Windows Live-Uploadtool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
WinFlash-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.exe" -l0x9
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Wireless Console 2-->C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\SETUP.exe -runfromtemp -l0x0009 -removeonly
======Security center information======

AS: Windows Defender

======System event log======

Computer Name: NB-***
Event Code: 1005
Message: Unable to load settings file. Using default settings for real time protection.
Record Number: 36110
Source Name: SRTSP
Time Written: 20090826141305.810811-000
Event Type: Warnung
User:

Computer Name: NB-***
Event Code: 6
Message: Der Dateisystemfilter "SRTSP" (6.0, 2008-08-19T20:47:50.000Z) wurde erfolgreich geladen und im Filter-Manager registriert.
Record Number: 36111
Source Name: Microsoft-Windows-FilterManager
Time Written: 20090826141305.810811-000
Event Type: Informationen
User: NT-AUTORITÄT\SYSTEM

Computer Name: NB-***
Event Code: 4
Message: Error loading virus definitions.
Record Number: 36112
Source Name: SRTSP
Time Written: 20090826141305.810811-000
Event Type: Fehler
User:

Computer Name: NB-***
Event Code: 1
Message: Der Dateisystemfilter "SRTSP" (Version 6.0, 2008-08-19T20:47:50.000Z) wurde erfolgreich entladen.
Record Number: 36113
Source Name: Microsoft-Windows-FilterManager
Time Written: 20090826141305.810811-000
Event Type: Informationen
User: NT-AUTORITÄT\SYSTEM

Computer Name: NB-***
Event Code: 5
Message: Error loading Symantec real time Anti-Virus driver.
Record Number: 36114
Source Name: SRTSP
Time Written: 20090826141305.810811-000
Event Type: Fehler
User:

=====Application event log=====

Computer Name: NB-***
Event Code: 1003
Message: Der Windows-Suchdienst wurde gestartet.

Record Number: 1639
Source Name: Microsoft-Windows-Search
Time Written: 20090826141147.000000-000
Event Type: Informationen
User:

Computer Name: NB-***
Event Code: 1
Message: Der Zertifikatdiensteclient wurde erfolgreich gestartet.
Record Number: 1640
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20090826141204.670411-000
Event Type: Informationen
User: NT-AUTORITÄT\SYSTEM

Computer Name: NB-***
Event Code: 1
Message: Der Zertifikatdiensteclient wurde erfolgreich gestartet.
Record Number: 1641
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20090826141206.698411-000
Event Type: Informationen
User: NB-***\***

Computer Name: NB-***
Event Code: 10
Message: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.
Record Number: 1642
Source Name: Microsoft-Windows-WMI
Time Written: 20090826141218.000000-000
Event Type: Fehler
User:

Computer Name: NB-***
Event Code: 5
Message: Unsupported service control request (see data below)
Record Number: 1643
Source Name: LightScribeService
Time Written: 20090826141310.000000-000
Event Type: Informationen
User:

=====Security event log=====

Computer Name: NB-***
Event Code: 5038
Message: Die Codeintegrität hat festgestellt, dass der Abbildhash einer Datei nicht gültig ist. Die Datei wurde möglicherweise durch eine nicht autorisierte Änderung beschädigt. Dieses Problem kann auch auf einen potenziellen Fehler des Datenträgergeräts hinweisen.

Dateiname: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 2663
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090826141308.650011-000
Event Type: Überwachung gescheitert
User:

Computer Name: NB-***
Event Code: 5038
Message: Die Codeintegrität hat festgestellt, dass der Abbildhash einer Datei nicht gültig ist. Die Datei wurde möglicherweise durch eine nicht autorisierte Änderung beschädigt. Dieses Problem kann auch auf einen potenziellen Fehler des Datenträgergeräts hinweisen.

Dateiname: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 2664
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090826141308.665611-000
Event Type: Überwachung gescheitert
User:

Computer Name: NB-***
Event Code: 5038
Message: Die Codeintegrität hat festgestellt, dass der Abbildhash einer Datei nicht gültig ist. Die Datei wurde möglicherweise durch eine nicht autorisierte Änderung beschädigt. Dieses Problem kann auch auf einen potenziellen Fehler des Datenträgergeräts hinweisen.

Dateiname: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 2665
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090826141308.696811-000
Event Type: Überwachung gescheitert
User:

Computer Name: NB-***
Event Code: 5038
Message: Die Codeintegrität hat festgestellt, dass der Abbildhash einer Datei nicht gültig ist. Die Datei wurde möglicherweise durch eine nicht autorisierte Änderung beschädigt. Dieses Problem kann auch auf einen potenziellen Fehler des Datenträgergeräts hinweisen.

Dateiname: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 2666
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090826141308.728011-000
Event Type: Überwachung gescheitert
User:

Computer Name: NB-***
Event Code: 5038
Message: Die Codeintegrität hat festgestellt, dass der Abbildhash einer Datei nicht gültig ist. Die Datei wurde möglicherweise durch eine nicht autorisierte Änderung beschädigt. Dieses Problem kann auch auf einen potenziellen Fehler des Datenträgergeräts hinweisen.

Dateiname: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 2667
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090826141308.743611-000
Event Type: Überwachung gescheitert
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=1706
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"configsetroot"=%SystemRoot%\ConfigSetRoot

-----------------EOF-----------------
[/quote]


Mit freundlichen Grüßen
King Pin

Alt 26.08.2009, 15:52   #10
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



so jetzt ist wirklich alles gepostet!

Der Browser stürzt leider immer noch ab! (hab es gerade bei google getestet)

Ich hoffe du kannst mir mit diesen Infos weiterhelfen!


Gruß

Alt 26.08.2009, 15:53   #11
Moritz009
 

Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Jetzt poste bitte noch einen GMER Report. Liebe Grüße Moritz009
__________________
Grüße,
Moritz

Trojaner-Board Spendenkonto

Alt 27.08.2009, 16:43   #12
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



So habe, den GMER durchgeführt, hier der Report: (muss es leider wieder in 3 Beiträge unterteilen:


Hier der erste Teil:

Zitat:
GMER 1.0.15.15077 [3hnjmto1.exe] - http://www.gmer.net
Rootkit scan 2009-08-27 17:31:46
Windows 6.0.6001 Service Pack 1


---- System - GMER 1.0.15 ----

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E3CD0
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E30E8
INT 0x52 ? 85E4FF00
INT 0x72 ? 85E4FF00
INT 0x82 ? 85E4FF00
INT 0x92 ? 85E4FF00
INT 0x92 ? 85E4FF00
INT 0xB2 ? 8499EBF8
INT 0xB2 ? 85E4FF00
INT 0xB2 ? 85E4FF00
INT 0xB2 ? 8499EBF8
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E33D8
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821CFAA4
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821CF01C
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E31C0
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E3B40
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E36D4
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E4100
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 821E436C

Code 87DFBE20 ZwEnumerateKey
Code 87E15CD0 ZwFlushInstructionCache
Code 888F6DEE ZwSaveKey
Code 87D47EA6 ZwSaveKeyEx
Code 8898CD55 IofCallDriver
Code 88977B76 IofCompleteRequest

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!IofCompleteRequest 81E4CFE2 5 Bytes JMP 88977B7B
.text ntkrnlpa.exe!IofCallDriver 81ECEF6F 5 Bytes JMP 8898CD5A
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81FC530B 5 Bytes JMP 87E15CD4
PAGE ntkrnlpa.exe!ZwEnumerateKey 8201ABA2 5 Bytes JMP 87DFBE24
PAGE ntkrnlpa.exe!ZwSaveKey 82068523 5 Bytes JMP 888F6DF2
PAGE ntkrnlpa.exe!ZwSaveKeyEx 8206862A 5 Bytes JMP 87D47EAA
? System32\Drivers\spnw.sys Das System kann den angegebenen Pfad nicht finden. !
.text USBPORT.SYS!DllUnload 8D9314CB 5 Bytes JMP 85E4F4E0

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806956D6] \SystemRoot\System32\Drivers\spnw.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80695042] \SystemRoot\System32\Drivers\spnw.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80695800] \SystemRoot\System32\Drivers\spnw.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806950C0] \SystemRoot\System32\Drivers\spnw.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069513E] \SystemRoot\System32\Drivers\spnw.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 853331F8

AttachedDevice \FileSystem\Ntfs \Ntfs AsDsm.sys (Data Security Manager Driver/Windows (R) Codename Longhorn DDK provider)

Device \FileSystem\fastfat \FatCdrom A346A1F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\sptd \Device\1638828637 spnw.sys

AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 8499C1F8
Device \Driver\usbuhci \Device\USBPDO-0 86C55500
Device \Driver\usbuhci \Device\USBPDO-1 86C55500
Device \Driver\usbuhci \Device\USBPDO-2 86C55500
Device \Driver\usbehci \Device\USBPDO-3 86C0B488
Device \Driver\usbuhci \Device\USBPDO-4 86C55500

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS

Device \Driver\usbuhci \Device\USBPDO-5 86C55500
Device \Driver\usbuhci \Device\USBPDO-6 86C55500
Device \Driver\volmgr \Device\HarddiskVolume1 8499C1F8
Device \Driver\usbehci \Device\USBPDO-7 86C0B488
Device \Driver\volmgr \Device\HarddiskVolume2 8499C1F8
Device \Driver\cdrom \Device\CdRom0 86D051F8
Device \Driver\volmgr \Device\HarddiskVolume3 8499C1F8
Device \Driver\cdrom \Device\CdRom1 86D051F8
Device \Driver\volmgr \Device\HarddiskVolume4 8499C1F8
Device \Driver\volmgr \Device\HarddiskVolume5 8499C1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 87D2D500
Device \Driver\Smb \Device\NetbiosSmb 87D211F8
Device \Driver\PCI_PNP2621 \Device\0000005a spnw.sys
Device \Driver\iScsiPrt \Device\RaidPort0 86D0E1F8
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS

Device \Driver\netbt \Device\NetBT_Tcpip_{40573619-83ED-49EB-BC96-5DF571AFAB38} 87D2D500
Device \Driver\netbt \Device\NetBT_Tcpip_{62990531-752B-4680-A703-F14591E602A1} 87D2D500
Device \Driver\usbuhci \Device\USBFDO-0 86C55500
Device \Driver\usbuhci \Device\USBFDO-1 86C55500
Device \Driver\usbuhci \Device\USBFDO-2 86C55500
Device \Driver\usbehci \Device\USBFDO-3 86C0B488
Device \Driver\usbuhci \Device\USBFDO-4 86C55500
Device \Driver\usbuhci \Device\USBFDO-5 86C55500
Device \Driver\usbuhci \Device\USBFDO-6 86C55500
Device \Driver\usbehci \Device\USBFDO-7 86C0B488
Device \Driver\ab5axl4r \Device\Scsi\ab5axl4r1 86D03500
Device \Driver\ab5axl4r \Device\Scsi\ab5axl4r1Port2Path0Target0Lun0 86D03500
Device \FileSystem\fastfat \Fat A346A1F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

Device \FileSystem\cdfs \Cdfs 80C141F8

---- Services - GMER 1.0.15 ----

Service C:\Windows\system32\drivers\kbiwkmiffydpby.sys (*** hidden *** ) [SYSTEM] kbiwkmbdwkeuwc <-- ROOTKIT !!!
Service C:\Windows\system32\drivers\kbiwkmyvovtcrb.sys (*** hidden *** ) [SYSTEM] kbiwkmplpfvrcr <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002243c94b41
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002243c94b41@0023f189f435 0x63 0x70 0xAA 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x93 0xB5 0x46 0xBE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x42 0x68 0x80 0x81 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x1E 0xAB 0x03 0xB4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main@cmddelay 14400

Alt 27.08.2009, 16:44   #13
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Hier der zweite Teil:

Zitat:
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\main\delete@C:\Users\***\AppData\Local\Temp\kbiwkmtnaqxnwvat.tmp
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet004\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet005\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat

Alt 27.08.2009, 16:45   #14
King_Pin1989
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Hier der dritte und letzte Teil:

Zitat:
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet007\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\002243c94b41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\002243c94b41@0023f189f435 0x63 0x70 0xAA 0x43 ...
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc@imagepath \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main@aid 10438
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmiffydpby.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmexqbnnhk.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmdhxeflfh.dat
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmqorimaeg.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmbdwkeuwc\modules@kbiwkm.dat \systemroot\system32\kbiwkmphxgbexs.dat
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr@imagepath \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main@aid 10438
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmyvovtcrb.sys
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmvtbktqpp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmtjuynfnt.dat
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmnyxmrlqo.dll
Reg HKLM\SYSTEM\ControlSet008\Services\kbiwkmplpfvrcr\modules@kbiwkm.dat \systemroot\system32\kbiwkmfkwcbvpe.dat
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x93 0xB5 0x46 0xBE ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x42 0x68 0x80 0x81 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x1E 0xAB 0x03 0xB4 ...

---- Files - GMER 1.0.15 ----

File C:\Users\***\AppData\Local\Temp\Low\kbiwkmkiwnedvxsx.tmp 196 bytes
File C:\Windows\System32\drivers\kbiwkmiffydpby.sys 69632 bytes <-- ROOTKIT !!!
File C:\Windows\System32\drivers\kbiwkmyvovtcrb.sys 69632 bytes executable <-- ROOTKIT !!!
File C:\Windows\System32\kbiwkmdhxeflfh.dat 1024 bytes
File C:\Windows\System32\kbiwkmexqbnnhk.dll 43520 bytes executable
File C:\Windows\System32\kbiwkmfkwcbvpe.dat 91 bytes
File C:\Windows\System32\kbiwkmnyxmrlqo.dll 20992 bytes executable
File C:\Windows\System32\kbiwkmphxgbexs.dat 91 bytes
File C:\Windows\System32\kbiwkmqorimaeg.dll 20480 bytes executable
File C:\Windows\System32\kbiwkmtjuynfnt.dat 22035 bytes
File C:\Windows\System32\kbiwkmvtbktqpp.dll 43520 bytes executable

---- EOF - GMER 1.0.15 ----

PS: Antivir zeigt ständig Trojaner an (meistens im system)


Hoffe du kannst mir helfen! Danke schonmal!
Weil ich glaube es spinnt nicht nur der Browser sondern auch noch die Videowiedergabe manchmal.

Gruß

Alt 28.08.2009, 15:23   #15
john.doe
 
Browser stürzt ständig ab! - Standard

Browser stürzt ständig ab!



Hallo und

Rootkitwarnung! Du hast eine schwere Infektion die nur mit sehr hohem Zeitaufwand zu bereinigen ist. Deshalb empfehle ich dir die schnelle und sichere Methode => http://www.trojaner-board.de/51262-a...sicherung.html

Solltest du dich für Bereinigen entscheiden, auch wenn es länger dauern wird, dann beginne mit ComboFix.

Solltest du noch irgendetwas mit dem Computer verbinden, wie Memorysticks, Speicherkarten, Digitalkameras, Handy, externe Laufwerke, ... dann stecke vor dem Scan alles an.

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
ciao, andreas
__________________
Kein Support per PN! Das ist hier ein Forum und keine Privatbetreuung!
Privatbetreuung nur gegen Bezahlung und ich koste sehr teuer.
Für alle Neuen
Anleitungen
Virenscanner
Kompromittierung unvermeidbar?

Antwort

Themen zu Browser stürzt ständig ab!
adobe, bho, browser, c:\windows\temp, computer, defender, excel, firefox, google, hijack, hijackthis, immer wieder, internet explorer, internet security, intrusion prevention, logfile, menu.exe, problem, programdata, realtek, rundll, saver, schnelle hilfe, screensaver, security, software, symantec, system, t-online.de, temp, trojaner, virus, vista, windows, windows\temp




Ähnliche Themen: Browser stürzt ständig ab!


  1. Mein Browser stürzt ständig ab / Probleme bei Kaspersky und erstellen der Logs
    Log-Analyse und Auswertung - 02.05.2013 (7)
  2. TR/Kazy.ies in Sytem Volume Information Browser stürzt ständig ab
    Plagegeister aller Art und deren Bekämpfung - 25.03.2012 (4)
  3. Pc stürzt ständig ab!
    Netzwerk und Hardware - 21.01.2012 (1)
  4. Browser stürzt ständig ab
    Plagegeister aller Art und deren Bekämpfung - 27.05.2011 (12)
  5. Explorer stürzt ständig ab / Jegliche Browser öffnen ungewollt Seiten
    Plagegeister aller Art und deren Bekämpfung - 10.11.2010 (8)
  6. Kaspersky stürzt ständig ab!
    Antiviren-, Firewall- und andere Schutzprogramme - 01.09.2009 (2)
  7. Pc stürzt ständig ab!
    Alles rund um Windows - 31.07.2009 (8)
  8. ICQ stürzt ständig ab
    Alles rund um Windows - 06.07.2009 (2)
  9. PC stürzt ständig ab
    Alles rund um Windows - 08.06.2009 (1)
  10. PC stürzt ständig ab
    Netzwerk und Hardware - 30.10.2008 (14)
  11. PC stürzt ständig ab :(
    Log-Analyse und Auswertung - 15.09.2008 (25)
  12. PC stürzt ständig ab
    Alles rund um Windows - 13.09.2008 (4)
  13. PC stürzt ständig ab!
    Mülltonne - 07.08.2008 (0)
  14. PC stürzt ständig ab
    Plagegeister aller Art und deren Bekämpfung - 14.07.2008 (11)
  15. pc stürzt ständig ab.
    Mülltonne - 15.09.2007 (0)
  16. pc stürzt ständig ab
    Mülltonne - 27.10.2006 (2)
  17. PC stürzt ständig ab!!! Warum?
    Alles rund um Windows - 03.07.2006 (16)

Zum Thema Browser stürzt ständig ab! - Hallo, ich habe ein Problem und zwar denke ich habe ich mir iwas eingefangen, Virus oder Trojaner oder ähnliches und hoffe ihr könnt mir weiterhelfen! Das Problem: Alles funktioniert normal, - Browser stürzt ständig ab!...
Archiv
Du betrachtest: Browser stürzt ständig ab! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.